|
Plagegeister aller Art und deren Bekämpfung: zilliontoolkitusa.info versehentlich installiert - was nun?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
09.04.2014, 00:08 | #1 |
| zilliontoolkitusa.info versehentlich installiert - was nun? Hallo, ich war für eine Hausarbeit auf der Suche nach Artikeln zu meinem Thema "NS in Würzburg". Da fand ich einen interessanten Download. Als ich bemerkte, was es war, schien es schon zu spät zu sein. Nun habe ich eine verlangsamte Leistung meines PC's und ständig auf allen Seiten diese Werbe Pop-ups. Ich las auch schon etwas von CouponDropDown oder etwas ähnliches. Was mache ich nun? Danke schon mal! Lieber Gruß abimama |
09.04.2014, 00:46 | #2 |
Ruhe in Frieden † 2019 | zilliontoolkitusa.info versehentlich installiert - was nun?Mein Name ist Sandra und ich werde Dir bei Deinem Problem behilflich sein.
Hinweis: Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist meist der schnellere und bei einem Befall durch Malware immer der sicherste Weg. Adware lässt sich in den allermeisten Fällen problemlos entfernen. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Dir jemand vom Team sagt, dass Du clean bist. Posten in Code Tags Bitte füge die Logs immer in Code-Tags ein. Wenn Du das nicht machst, erschwert es mir sehr das Auswerten. Danke. Dazu:
Schritt 1 Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
09.04.2014, 09:46 | #3 |
| zilliontoolkitusa.info versehentlich installiert - was nun? FRST Logfile:
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 (ATTENTION: ====> FRST version is 27 days old and could be outdated) Ran by studentin mama (administrator) on STUDENTINMAMA on 09-04-2014 10:39:03 Running from C:\Users\studentin mama\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Hewlett-Packard) C:\Windows\system32\Hpservice.exe (AMD) C:\Windows\system32\atieclxx.exe (Cisco Systems, Inc.) C:\PROGRAM FILES (X86)\CISCO\CISCO ANYCONNECT SECURE MOBILITY CLIENT\VPNAGENT.EXE (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE (EasyBits Software AS) C:\WINDOWS\SYSWOW64\EZSHAREDSVCHOST.EXE () C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (IObit) C:\PROGRAM FILES (X86)\IOBIT\LIVEUPDATE\LIVEUPDATE.EXE (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe (Crawler.com) C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Crawler.com) C:\PROGRAM FILES (X86)\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (TomTom) C:\PROGRAM FILES (X86)\MYTOMTOM 3\MYTOMTOMSA.EXE (Microsoft Corporation) C:\PROGRAM FILES\WINDOWS SIDEBAR\SIDEBAR.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Crawler.com) C:\PROGRAM FILES (X86)\SPYWARE TERMINATOR\SPYWARETERMINATORUPDATE.EXE (Hewlett-Packard Company) C:\PROGRAM FILES (X86)\HEWLETT-PACKARD\HP QUICK LAUNCH\HPMSGSVC.EXE (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Advanced Micro Devices Inc.) C:\PROGRAM FILES (X86)\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\MOM.EXE () C:\Windows\Samsung\PanelMgr\SSMMgr.exe () C:\PROGRAM FILES (X86)\DIVX\DIVX UPDATE\DIVXUPDATE.EXE () C:\Windows\Samsung\PanelMgr\caller64.exe (Apple Inc.) C:\PROGRAM FILES (X86)\ITUNES\ITUNESHELPER.EXE (Easybits) C:\PROGRAMDATA\EASYBITS MAGIC DESKTOP FOR HP\MDHPSUN.EXE (Cisco Systems, Inc.) C:\PROGRAM FILES (X86)\CISCO\CISCO ANYCONNECT SECURE MOBILITY CLIENT\VPNUI.EXE (ATI Technologies Inc.) C:\PROGRAM FILES (X86)\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\CCC.EXE (Hewlett-Packard Company) C:\PROGRAM FILES (X86)\HEWLETT-PACKARD\SHARED\HPQWMIEX.EXE (Apple Inc.) C:\PROGRAM FILES\IPOD\BIN\IPODSERVICE.EXE (Mozilla Corporation) C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE (CyberLink) C:\PROGRAM FILES (X86)\HEWLETT-PACKARD\MEDIA\WEBCAM\YCMMIRAGE.EXE (Hewlett-Packard Company) C:\PROGRAM FILES (X86)\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK\HPSA_SERVICE.EXE (Hewlett-Packard Company) C:\PROGRAM FILES\HEWLETT-PACKARD\HP WIRELESS ASSISTANT\HPWA_SERVICE.EXE (Hewlett-Packard Company) C:\PROGRAM FILES\HEWLETT-PACKARD\HP WIRELESS ASSISTANT\HPWA_MAIN.EXE (Crawler.com) C:\PROGRAM FILES (X86)\SPYWARE TERMINATOR\SPYWARETERMINATOR.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2281256 2011-10-30] (Synaptics Incorporated) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-06-09] (IDT, Inc.) HKLM\...\Run: [HPWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-06-18] (Hewlett-Packard Company) HKLM\...\Run: [SpywareTerminatorShield] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com) HKLM\...\Run: [SpywareTerminatorUpdater] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-04-16] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [602168 2010-06-29] (Hewlett-Packard Company) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe HKLM-x32\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [548864 2009-02-04] () HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] () HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKLM-x32\...\Run: [Magic Desktop for HP notification] - C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1258504 2013-12-30] (Easybits) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707472 2013-12-13] (Cisco Systems, Inc.) HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-03-25] (Hewlett-Packard) HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2010-05-19] (Hewlett-Packard Company) HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [MyTomTomSA.exe] - C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe [434168 2012-05-18] (TomTom) HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [EPSON Stylus DX5000 Series] - C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIBVE.EXE [139264 2006-09-22] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Policies\system: [DisableChangePassword] 0 HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\MountPoints2: G - G:\pushinst.exe HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\MountPoints2: {2c95361d-2ce3-11e1-9892-f1a06df124b6} - G:\Setup.exe AppInit_DLLs: C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL => C:\Program Files (x86)\SW-Booster\Assistant_x64.dll [4210176 2014-04-02] () Startup: C:\Users\studentin mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4 SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {19089719-9401-4468-AE0B-8104E8D0D9EF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM - {654B965E-3DF5-6EBF-25F2-16047A3CEE0A} URL = SearchScopes: HKLM - {E81CDADA-1F06-414B-A58F-396B22D1CAFD} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM-x32 - {19089719-9401-4468-AE0B-8104E8D0D9EF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM-x32 - {1B9EB9F7-E37A-84D5-8074-2983B2C5FBE0} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dstrmsd&cd=2XzuyEtN2Y1L1Qzu0E0CyDyD0FzytAyE0AyBzy0F0CtD0DyEtN0D0Tzu0CyCzztAtN1L2XzutBtFtBtFzztFtCtByEyBtN1L1Czu1Q1B2Z1C1H1B1Q&cr=49275907&ir= SearchScopes: HKLM-x32 - {E81CDADA-1F06-414B-A58F-396B22D1CAFD} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKCU - {19089719-9401-4468-AE0B-8104E8D0D9EF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKCU - {22BC9D89-4AFD-4FD9-93D7-FDC19F581E42} URL = hxxp://searchya.com/?chnl=ft-102&s=1&cr=1395955839&cd=2XzutAtN2Y1L1Qzu0E0CyDyD0FzytAyE0AyBzy0FyD0CtD0DyEtN0D0TzutBtDtCtBtDtAtDyB&q={searchTerms} SearchScopes: HKCU - {654B965E-3DF5-6EBF-25F2-16047A3CEE0A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dstrmsd&cd=2XzuyEtN2Y1L1Qzu0E0CyDyD0FzytAyE0AyBzy0F0CtD0DyEtN0D0Tzu0CyCzztAtN1L2XzutBtFtBtFzztFtCtByEyBtN1L1Czu1Q1B2Z1C1H1B1Q&cr=49275907&ir= SearchScopes: HKCU - {E81CDADA-1F06-414B-A58F-396B22D1CAFD} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {538793D5-659C-4639-A56C-A179AD87ED44} Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 - C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: safewaebu - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\eiy.3h2a3@csrpxoeu.com [2014-04-02] FF Extension: YoutubeAdblocker - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\mriqu@dpfrjfc.com [2014-04-02] FF Extension: No Name - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\staged [2014-04-09] FF Extension: SNT - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\xmjope9q@pkajbtag-y.co.uk [2014-04-02] FF Extension: WEB.DE MailCheck - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\toolbar@web.de.xpi [2013-11-25] FF Extension: Adblock Plus - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-09-24] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-03-29] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-03-29] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-03-29] FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-04-27] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR Extension: (No Name) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\gladcbhcbkdeddbidiblppadjdjalidb [2012-11-17] CHR Extension: (SNT) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\jipdpdgjdgibngmaockoaenedejjnkgk [2014-04-02] CHR Extension: (tinyFilter) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlfgnnlnfbpcammlnibfkplpnbbbdeli [2014-04-02] CHR Extension: (YoutubeAdblocker) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\olodkgeocddnmkokdmamjnjdkdijnkgm [2014-04-02] CHR Extension: (safewaebu) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\ophckemjgdhcaemfcpnjdfnooiflpbdl [2014-04-02] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE [102400 2006-04-18] (SEIKO EPSON CORPORATION) R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [27192 2010-06-29] () R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151744 2014-01-11] (IObit) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) R2 ST2012_Svc; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [1149104 2013-04-03] (Crawler.com) S2 d0e87c27; "C:\Windows\system32\rundll32.exe" "c:\progra~2\sw-boo~1\AssistantSvc.dll",service ==================== Drivers (Whitelisted) ==================== R2 sp_rsdrv2; C:\Windows\System32\DRIVERS\stflt.sys [51496 2014-04-05] (Windows (R) Win 7 DDK provider) S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52080 2013-12-13] (Cisco Systems, Inc.) S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-09 10:39 - 2014-04-09 10:39 - 00021449 _____ () C:\Users\studentin mama\Downloads\FRST.txt 2014-04-09 10:38 - 2014-04-09 10:39 - 00000000 ____D () C:\FRST 2014-04-09 10:33 - 2014-04-09 10:33 - 02157056 _____ (Farbar) C:\Users\studentin mama\Downloads\FRST64.exe 2014-04-09 10:18 - 2014-03-28 22:37 - 00002676 _____ () C:\Windows\system32\Drivers\etc\hosts.ac 2014-04-07 21:55 - 2014-04-07 21:55 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\studentin mama\Downloads\SpyHunter-Installer(3).exe 2014-04-07 13:55 - 2014-04-07 14:04 - 10995296 _____ (Deutsche Telekom AG, Marmiko IT-Solutions GmbH ) C:\Users\studentin mama\Downloads\netzmanager_setup.exe 2014-04-05 22:42 - 2014-04-05 22:42 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000(1).exe 2014-04-05 22:27 - 2014-04-05 22:27 - 02347384 _____ (ESET) C:\Users\studentin mama\Downloads\esetsmartinstaller_enu.exe 2014-04-05 22:27 - 2014-04-05 22:27 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-05 08:36 - 2014-04-08 17:56 - 00000000 ____D () C:\ProgramData\Spyware Terminator 2014-04-05 08:36 - 2014-04-05 08:36 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-04-05 08:36 - 2014-04-05 08:36 - 00001002 _____ () C:\Users\Public\Desktop\Spyware Terminator 2012.lnk 2014-04-05 08:36 - 2014-04-05 08:36 - 00000000 ____D () C:\Users\studentin mama\AppData\Roaming\Spyware Terminator 2014-04-05 08:36 - 2014-04-05 08:36 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator 2014-04-05 08:30 - 2014-04-05 08:30 - 05049344 _____ (Crawler.com ) C:\Users\studentin mama\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2014-04-05 00:10 - 2014-04-05 00:10 - 00003372 _____ () C:\Windows\System32\Tasks\SpyHunter4Startup 2014-04-05 00:10 - 2014-04-05 00:10 - 00002276 _____ () C:\Users\studentin mama\Desktop\SpyHunter.lnk 2014-04-05 00:10 - 2014-04-05 00:10 - 00000000 ____D () C:\sh4ldr 2014-04-05 00:09 - 2014-04-05 08:29 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP 2014-04-05 00:08 - 2014-04-05 00:08 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\studentin mama\Downloads\SpyHunter-Installer(2).exe 2014-04-04 23:56 - 2014-04-04 23:57 - 00613200 _____ (Chip Digital GmbH) C:\Users\studentin mama\Downloads\AdwCleaner - CHIP-Downloader.exe 2014-04-04 23:07 - 2014-04-06 00:20 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-04 23:06 - 2014-04-05 22:43 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-04 23:06 - 2014-04-05 22:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-04 23:06 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-04 23:06 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-04 23:06 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-04 23:05 - 2014-04-04 23:06 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000.exe 2014-04-04 23:00 - 2014-04-04 23:04 - 00001420 _____ () C:\Users\studentin mama\Desktop\Rkill.txt 2014-04-04 22:59 - 2014-04-04 22:59 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\studentin mama\Downloads\wObiA.exe 2014-04-04 16:16 - 2014-04-04 16:20 - 00000000 ____D () C:\Users\studentin mama\Desktop\Documents\KWB 2014 2014-04-03 21:35 - 2014-04-04 16:08 - 00012603 _____ () C:\Users\studentin mama\Desktop\Documents\Bewertungsbögen Spezialaufgabe KWB 2014.xlsx 2014-04-02 20:02 - 2014-04-09 10:18 - 00000462 ____H () C:\Windows\Tasks\SW.Booster-S-4606583622.job 2014-04-02 20:02 - 2014-04-02 20:02 - 12400098 _____ () C:\Users\studentin mama\Desktop\Die Machtergreifung in Würzburg 1933, PDF.zip 2014-04-02 20:02 - 2014-04-02 20:02 - 00002708 _____ () C:\Windows\System32\Tasks\SW.Booster-S-4606583622 2014-04-02 20:02 - 2014-04-02 20:02 - 00000000 ____D () C:\ProgramData\GreenApp 2014-04-02 20:01 - 2014-04-05 00:02 - 00000000 ____D () C:\Program Files (x86)\SW-Booster 2014-04-02 20:01 - 2014-04-04 23:55 - 00000000 ____D () C:\ProgramData\siaafEweB 2014-04-02 20:01 - 2014-04-04 23:55 - 00000000 ____D () C:\Program Files (x86)\siaafEweB 2014-04-02 20:01 - 2014-04-02 20:02 - 00000000 ____D () C:\ProgramData\8fba3f8d18b65f94 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Packages 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator 2014-04-02 20:00 - 2014-04-02 20:02 - 00000000 ____D () C:\ProgramData\InstallMate 2014-03-29 20:33 - 2014-03-29 20:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-13 23:53 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-13 23:53 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-13 23:53 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-13 23:53 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-13 23:53 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-13 23:53 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-13 23:53 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-13 23:53 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-13 23:53 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-13 23:53 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-13 23:53 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-13 23:53 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-13 23:53 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-13 23:53 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-13 23:53 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-13 23:53 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-13 23:53 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-13 23:53 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-13 23:53 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-13 23:53 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-13 23:53 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-13 23:53 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-13 23:53 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-13 23:53 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-13 23:53 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-13 23:53 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-13 23:53 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-13 23:53 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-13 23:53 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-13 23:53 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-13 23:53 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-13 23:53 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-13 23:53 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-13 23:53 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-13 23:53 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-13 23:53 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-13 23:53 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-13 23:53 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-13 23:53 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-13 23:53 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-13 23:53 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-13 23:53 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-13 23:52 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-13 23:52 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-13 23:52 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-13 23:52 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-13 23:52 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-13 23:52 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll ==================== One Month Modified Files and Folders ======= 2014-04-09 10:39 - 2014-04-09 10:39 - 00021449 _____ () C:\Users\studentin mama\Downloads\FRST.txt 2014-04-09 10:39 - 2014-04-09 10:38 - 00000000 ____D () C:\FRST 2014-04-09 10:33 - 2014-04-09 10:33 - 02157056 _____ (Farbar) C:\Users\studentin mama\Downloads\FRST64.exe 2014-04-09 10:25 - 2009-07-14 06:45 - 00023024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-09 10:25 - 2009-07-14 06:45 - 00023024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-09 10:23 - 2011-03-10 02:07 - 01712592 _____ () C:\Windows\WindowsUpdate.log 2014-04-09 10:18 - 2014-04-02 20:02 - 00000462 ____H () C:\Windows\Tasks\SW.Booster-S-4606583622.job 2014-04-09 10:18 - 2012-02-26 15:04 - 00001122 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-09 10:17 - 2013-09-24 08:09 - 00028712 _____ () C:\Windows\setupact.log 2014-04-09 10:17 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-09 00:57 - 2013-05-28 01:13 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-09 00:54 - 2011-10-31 17:48 - 00000356 _____ () C:\Windows\Tasks\HP Photo Creations Communicator.job 2014-04-09 00:43 - 2012-02-26 15:04 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-08 23:12 - 2013-06-14 08:24 - 00000000 ____D () C:\Program Files (x86)\Windows Phone 2014-04-08 17:56 - 2014-04-05 08:36 - 00000000 ____D () C:\ProgramData\Spyware Terminator 2014-04-08 10:14 - 2013-01-09 20:35 - 00003986 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{D3FEFDA5-19CA-46DA-9710-E509D83A4478} 2014-04-08 02:35 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-04-08 02:25 - 2014-02-13 17:40 - 00000368 _____ () C:\Windows\Tasks\HPCeeScheduleForstudentin mama.job 2014-04-08 00:34 - 2013-09-24 08:09 - 01357614 _____ () C:\Windows\PFRO.log 2014-04-07 21:55 - 2014-04-07 21:55 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\studentin mama\Downloads\SpyHunter-Installer(3).exe 2014-04-07 14:04 - 2014-04-07 13:55 - 10995296 _____ (Deutsche Telekom AG, Marmiko IT-Solutions GmbH ) C:\Users\studentin mama\Downloads\netzmanager_setup.exe 2014-04-07 07:40 - 2010-07-31 19:11 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-04-07 07:40 - 2010-07-31 19:11 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-04-07 07:40 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-06 00:33 - 2011-10-20 06:57 - 00000000 ____D () C:\Users\studentin mama\Desktop\Studium Lehramt an Gymnasien Deutsch und Geschichte 2014-04-06 00:20 - 2014-04-04 23:07 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-05 22:43 - 2014-04-04 23:06 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-05 22:43 - 2014-04-04 23:06 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-05 22:42 - 2014-04-05 22:42 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000(1).exe 2014-04-05 22:27 - 2014-04-05 22:27 - 02347384 _____ (ESET) C:\Users\studentin mama\Downloads\esetsmartinstaller_enu.exe 2014-04-05 22:27 - 2014-04-05 22:27 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-05 08:36 - 2014-04-05 08:36 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-04-05 08:36 - 2014-04-05 08:36 - 00001002 _____ () C:\Users\Public\Desktop\Spyware Terminator 2012.lnk 2014-04-05 08:36 - 2014-04-05 08:36 - 00000000 ____D () C:\Users\studentin mama\AppData\Roaming\Spyware Terminator 2014-04-05 08:36 - 2014-04-05 08:36 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator 2014-04-05 08:30 - 2014-04-05 08:30 - 05049344 _____ (Crawler.com ) C:\Users\studentin mama\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2014-04-05 08:30 - 2011-10-07 23:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\CrashDumps 2014-04-05 08:29 - 2014-04-05 00:09 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP 2014-04-05 00:10 - 2014-04-05 00:10 - 00003372 _____ () C:\Windows\System32\Tasks\SpyHunter4Startup 2014-04-05 00:10 - 2014-04-05 00:10 - 00002276 _____ () C:\Users\studentin mama\Desktop\SpyHunter.lnk 2014-04-05 00:10 - 2014-04-05 00:10 - 00000000 ____D () C:\sh4ldr 2014-04-05 00:10 - 2014-01-31 23:38 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-04-05 00:08 - 2014-04-05 00:08 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\studentin mama\Downloads\SpyHunter-Installer(2).exe 2014-04-05 00:02 - 2014-04-02 20:01 - 00000000 ____D () C:\Program Files (x86)\SW-Booster 2014-04-05 00:02 - 2011-10-04 14:15 - 00000000 ____D () C:\Windows\SHELLNEW 2014-04-05 00:01 - 2013-09-22 13:51 - 00000000 ____D () C:\AdwCleaner 2014-04-04 23:57 - 2014-04-04 23:56 - 00613200 _____ (Chip Digital GmbH) C:\Users\studentin mama\Downloads\AdwCleaner - CHIP-Downloader.exe 2014-04-04 23:55 - 2014-04-02 20:01 - 00000000 ____D () C:\ProgramData\siaafEweB 2014-04-04 23:55 - 2014-04-02 20:01 - 00000000 ____D () C:\Program Files (x86)\siaafEweB 2014-04-04 23:06 - 2014-04-04 23:05 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000.exe 2014-04-04 23:06 - 2012-10-08 11:49 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-04 23:04 - 2014-04-04 23:00 - 00001420 _____ () C:\Users\studentin mama\Desktop\Rkill.txt 2014-04-04 22:59 - 2014-04-04 22:59 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\studentin mama\Downloads\wObiA.exe 2014-04-04 16:20 - 2014-04-04 16:16 - 00000000 ____D () C:\Users\studentin mama\Desktop\Documents\KWB 2014 2014-04-04 16:08 - 2014-04-03 21:35 - 00012603 _____ () C:\Users\studentin mama\Desktop\Documents\Bewertungsbögen Spezialaufgabe KWB 2014.xlsx 2014-04-04 00:50 - 2014-01-11 23:00 - 00000000 ____D () C:\ProgramData\ProductData 2014-04-02 20:02 - 2014-04-02 20:02 - 12400098 _____ () C:\Users\studentin mama\Desktop\Die Machtergreifung in Würzburg 1933, PDF.zip 2014-04-02 20:02 - 2014-04-02 20:02 - 00002708 _____ () C:\Windows\System32\Tasks\SW.Booster-S-4606583622 2014-04-02 20:02 - 2014-04-02 20:02 - 00000000 ____D () C:\ProgramData\GreenApp 2014-04-02 20:02 - 2014-04-02 20:01 - 00000000 ____D () C:\ProgramData\8fba3f8d18b65f94 2014-04-02 20:02 - 2014-04-02 20:00 - 00000000 ____D () C:\ProgramData\InstallMate 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Packages 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator 2014-04-02 20:01 - 2012-02-26 15:04 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Google 2014-04-02 14:25 - 2014-02-13 17:40 - 00003240 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForstudentin mama 2014-04-02 14:24 - 2011-11-09 22:07 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-04-02 14:24 - 2011-10-05 12:45 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-03-31 07:02 - 2013-09-24 08:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-30 09:57 - 2014-02-15 10:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak 2014-03-29 20:33 - 2014-03-29 20:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-28 23:38 - 2012-02-26 15:04 - 00004122 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-28 23:38 - 2012-02-26 15:04 - 00003870 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-28 22:37 - 2014-04-09 10:18 - 00002676 _____ () C:\Windows\system32\Drivers\etc\hosts.ac 2014-03-23 12:02 - 2014-01-29 20:56 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-03-22 12:02 - 2013-06-16 17:42 - 00000000 ____D () C:\ProgramData\Origin 2014-03-22 12:01 - 2013-06-16 17:41 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-03-18 00:27 - 2013-09-25 21:32 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-18 00:22 - 2011-10-17 22:46 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-15 22:51 - 2014-02-27 22:02 - 00000000 ____D () C:\Program Files (x86)\MediaViewV1 2014-03-14 16:50 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-03-14 10:36 - 2009-07-14 06:45 - 00397528 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-14 10:32 - 2011-10-04 14:15 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-03-14 00:23 - 2012-08-25 16:29 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-14 00:23 - 2012-08-25 16:29 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-12 23:57 - 2013-05-28 01:13 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-12 23:57 - 2013-04-24 09:56 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 23:57 - 2013-04-24 09:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl Some content of TEMP: ==================== C:\Users\Gast\AppData\Local\Temp\AskSLib.dll C:\Users\Gast\AppData\Local\Temp\DivXSetup.exe C:\Users\Gast\AppData\Local\Temp\drm_dyndata_7400009.dll C:\Users\Kinder\AppData\Local\Temp\AskSLib.dll C:\Users\Kinder\AppData\Local\Temp\DivXSetup.exe C:\Users\Kinder\AppData\Local\Temp\drm_dyndata_7400009.dll C:\Users\Kinder\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Kinder\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\studentin mama\AppData\Local\Temp\20130925093117132jniverify.dll C:\Users\studentin mama\AppData\Local\Temp\20130928053820767jniverify.dll C:\Users\studentin mama\AppData\Local\Temp\20131006115056931jniverify.dll C:\Users\studentin mama\AppData\Local\Temp\2013100611513910jniverify.dll C:\Users\studentin mama\AppData\Local\Temp\20131006120140377jniverify.dll C:\Users\studentin mama\AppData\Local\Temp\20131111094438637jniverify.dll C:\Users\studentin mama\AppData\Local\Temp\2013111211514868jniverify.dll C:\Users\studentin mama\AppData\Local\Temp\57629uninstall.exe C:\Users\studentin mama\AppData\Local\Temp\BackupSetup.exe C:\Users\studentin mama\AppData\Local\Temp\DivXSetup.exe C:\Users\studentin mama\AppData\Local\Temp\FileSystemView.dll C:\Users\studentin mama\AppData\Local\Temp\ICReinstall_SkypeSetup.exe C:\Users\studentin mama\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\studentin mama\AppData\Local\Temp\LiveSupport_setup.exe C:\Users\studentin mama\AppData\Local\Temp\NOSEventMessages.dll C:\Users\studentin mama\AppData\Local\Temp\promote-upx.exe C:\Users\studentin mama\AppData\Local\Temp\Quarantine.exe C:\Users\studentin mama\AppData\Local\Temp\secuniasi2594068627806590653.dll C:\Users\studentin mama\AppData\Local\Temp\SHSetup.exe C:\Users\studentin mama\AppData\Local\Temp\sp64126.exe C:\Users\studentin mama\AppData\Local\Temp\Sqlite3.dll C:\Users\studentin mama\AppData\Local\Temp\sSetup-se.exe C:\Users\studentin mama\AppData\Local\Temp\switchsetup.exe C:\Users\studentin mama\AppData\Local\Temp\uninst1.exe C:\Users\studentin mama\AppData\Local\Temp\UninstallHPSA.exe C:\Users\studentin mama\AppData\Local\Temp\wjeqmq53.gsp.exe C:\Users\studentin mama\AppData\Local\Temp\WZCPlugin_VISTA.exe C:\Users\studentin mama\AppData\Local\Temp\xwqqwfzwckbrtgh.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-02 21:36 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014 Ran by studentin mama at 2014-04-09 10:41:43 Running from C:\Users\studentin mama\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.9.0.1030 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.9.0.1030 - Adobe Systems Incorporated) Hidden Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Adobe Shockwave Player 11.5 (HKLM-x32\...\{9ECF7817-DB11-4FBA-9DF1-296A578D513A}) (Version: 11.5.7.609 - Adobe Systems, Inc) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.) AMD USB Filter Driver (x32 Version: 1.0.15.94 - Advanced Micro Devices, Inc.) Hidden Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros) ATI Catalyst Install Manager (HKLM\...\{11A4D79B-672C-7FFF-B5F7-B4409B1194EF}) (Version: 3.0.765.0 - ATI Technologies, Inc.) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Core Implementation (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Full New (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Light (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center InstallProxy (x32 Version: 2010.0416.541.8279 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2010.0416.541.8279 - ATI) Hidden CCC Help Chinese Standard (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Chinese Traditional (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Czech (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Danish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Dutch (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help English (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Finnish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help French (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help German (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Greek (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Hungarian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Italian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Japanese (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Korean (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Norwegian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Polish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Portuguese (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Russian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Spanish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Swedish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Thai (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Turkish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden ccc-core-static (x32 Version: 2010.0416.541.8279 - Ihr Firmenname) Hidden ccc-utility64 (Version: 2010.0416.541.8279 - ATI) Hidden Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.05152 - Cisco Systems, Inc.) Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.05152 - Cisco Systems, Inc.) Hidden CyberLink DVD Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.3003 - CyberLink Corp.) CyberLink DVD Suite (x32 Version: 7.0.3003 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{92C42EDD-6524-4577-B2EB-6C68C63B6D4A}) (Version: - Microsoft) Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts) Diercke Globus Online (HKLM-x32\...\Diercke Globus Online) (Version: 3.1.0 - Imagon GmbH) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.90 - DivX, LLC) DVD Menu Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}) (Version: 4.1.4121 - Hewlett-Packard) DVD Menu Pack for HP MediaSmart Video (x32 Version: 4.1.4121 - Hewlett-Packard) Hidden EPSON File Manager (HKLM-x32\...\{D02F30FB-0BC4-419A-9B9C-ADC610029B50}) (Version: 1.3.2.0 - ) EPSON Scan Assistant (HKLM-x32\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - ) EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version: - SEIKO EPSON Corporation) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) ESU for Microsoft Windows 7 (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard) Free YouTube to MP3 Converter version 3.11.35.1031 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.35.1031 - DVDVideoSoft Ltd.) Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Customer Experience Enhancements (x32 Version: 6.0.1.4 - Hewlett-Packard) Hidden HP Documentation (HKLM-x32\...\{E5AE53A7-1A79-4840-998F-A18042A2F568}) (Version: 1.1.1.0 - Hewlett-Packard) HP MediaSmart Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 4.1.3024 - Hewlett-Packard) HP MediaSmart Webcam (x32 Version: 4.1.3024 - Hewlett-Packard) Hidden HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.12412 - HP Photo Creations Powered by RocketLife) HP Photosmart Plus B210 series - Grundlegende Software für das Gerät (HKLM\...\{7578548C-6F40-4CBE-B5CF-9310E66557FA}) (Version: 22.50.231.0 - Hewlett-Packard Co.) HP Photosmart Plus B210 series Hilfe (HKLM-x32\...\{7F5FDEA1-D0AC-4D80-9D95-59775FCCFA40}) (Version: 140.0.54.54 - Hewlett Packard) HP Power Manager (HKLM-x32\...\{4B156358-CE9C-4E9F-8CAD-79AE86A68C60}) (Version: 1.0.3 - Hewlett-Packard Company) HP Quick Launch (HKLM-x32\...\{E342D296-DB9D-4FC7-ACB0-39926C0BFA16}) (Version: 2.1.5 - Hewlett-Packard Company) HP Setup (HKLM-x32\...\{72D90DB3-A16A-4545-B555-868471101833}) (Version: 8.1.4186.3400 - Hewlett-Packard) HP Software Framework (HKLM-x32\...\{B446137B-18A1-4FAE-B0E4-ABE8F09705F1}) (Version: 4.1.6.1 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company) HP Update (HKLM-x32\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard) HP Wireless Assistant (HKLM\...\{E342EC6B-5F25-47FE-B92C-DE616149B430}) (Version: 4.0.9.0 - Hewlett-Packard) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6288.0 - IDT) IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 3.0.4.922 - IObit) iTunes (HKLM\...\{D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0}) (Version: 11.1.3.8 - Apple Inc.) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden LightScribe System Software (HKLM-x32\...\{46BA053F-57B3-4153-BDB6-D37EEC8B12D7}) (Version: 1.18.15.1 - LightScribe) Malwarebytes Anti-Malware Version 2.00.0.1000 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.00.0.1000 - Malwarebytes Corporation) MarkSpace Outlook Server Version 1.0 (HKLM-x32\...\{050F5BE0-A8F6-48E1-9815-97322C1C1DC5}_is1) (Version: 1.0 - Mark/Space, Inc.) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1 - Nokia) Hidden Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1 - Nokia) Hidden Movie Theme Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}) (Version: 4.1.4030 - Hewlett-Packard) Movie Theme Pack for HP MediaSmart Video (x32 Version: 4.1.4030 - Hewlett-Packard) Hidden Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MyTomTom 3.2.0.700 (HKLM-x32\...\MyTomTom) (Version: 3.2.0.700 - TomTom) Nokia Connectivity Cable Driver (HKLM-x32\...\{29373274-977E-413C-A4DE-DC0F8E80C429}) (Version: 7.1.172.0 - Nokia) OpenTTD 1.1.5 (HKLM-x32\...\OpenTTD) (Version: 1.1.5 - OpenTTD) Origin (HKLM-x32\...\Origin) (Version: 9.0.14.2148 - Electronic Arts, Inc.) PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia) PDF Architect (HKLM-x32\...\{064A929A-4DE8-40CF-A901-BD40C14E4D25}) (Version: 1.1.83.9982 - pdfforge GmbH) PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.0 - pdfforge) Photo to Movie 5.0 (HKLM-x32\...\{FA166F42-B86E-437A-9AC3-87FCC351973C}) (Version: 5.0.704 - LQ Graphics, Inc.) PhotoPad Foto-Editor (HKLM-x32\...\PhotoPad) (Version: - NCH Software) PhotoScape (HKLM-x32\...\PhotoScape) (Version: - ) Pixillion Imagedatei-Konverter (HKLM-x32\...\Pixillion) (Version: - NCH Software) PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3003 - CyberLink Corp.) PowerDirector (x32 Version: 8.0.3003 - CyberLink Corp.) Hidden QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.11.1127.2009 - Realtek) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30113 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.3023 - CyberLink Corp.) Hidden RuntimeLibsVC90 (HKLM-x32\...\{F000DE4C-B6CB-4181-BAFF-EC5DA2A9C156}) (Version: 1.1.0 - Microsoft) Samsung Universal Print Driver (HKLM-x32\...\Samsung Universal Print Driver) (Version: - Samsung Electronics CO.,LTD) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Spyware Terminator 2012 (HKLM-x32\...\{56736259-613E-4A3B-B428-6235F2E76F44}_is1) (Version: 3.0.0.82 - Crawler.com) StreamTransport version: 1.0.2.2171 (HKLM-x32\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version: - ) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden SW-Sustainer 1.80 (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}) (Version: - Certified Publisher) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.1.6.64 - Synaptics Incorporated) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{81812245-FC84-426A-BC02-6659C88CC7B2}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2775360) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{80F56E3F-1D47-4E45-B6E0-FEF4E919F4F9}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2878227) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5D357893-40BA-4323-86BA-D97C66CD72F4}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft) Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{E78E2B68-8FD1-42EE-BB74-99A4D9E6222D}) (Version: - Microsoft) Usenet.nl (HKLM-x32\...\Usenet.nl_is1) (Version: - ) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.) VLC media player 2.1.0 (HKLM-x32\...\VLC media player) (Version: 2.1.0 - VideoLAN) Welcome Home To Windows Phone Version 2.0 (HKLM-x32\...\{4B5EBB2A-A55C-40E9-A48F-AEBFBAA90EC1}_is1) (Version: 2.0 - ) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Sync (HKLM-x32\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation) Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) Windows Phone app for desktop (HKLM-x32\...\{19773614-FC22-4ACC-AAA3-E6BDA81ACF92}) (Version: 1.1.2726.0 - Microsoft Corporation) Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia) WinRAR 5.00 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) YTD Video Downloader 4.0 (HKLM-x32\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.0 - GreenTree Applications SRL) ==================== Restore Points ========================= 09-03-2014 19:57:45 Windows-Sicherung 13-03-2014 21:48:47 Windows Update 13-03-2014 23:12:51 Windows Update 14-03-2014 08:25:34 Windows Update 16-03-2014 19:46:45 Windows-Sicherung 17-03-2014 22:21:58 Windows Update 23-03-2014 18:00:21 Windows-Sicherung 30-03-2014 18:13:33 Windows-Sicherung 04-04-2014 22:09:15 Installed SpyHunter 05-04-2014 06:29:17 Removed SpyHunter 07-04-2014 05:46:26 Windows-Sicherung 08-04-2014 21:10:33 Installed Windows Phone app for desktop ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-04-09 10:18 - 00002828 ____A C:\Windows\system32\Drivers\etc\hosts 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de There are 17 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {084C9023-C4A7-4FF3-AC7B-6DD84D7E3F8F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {1790A716-CE1A-400C-A0F4-691BBA163103} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-02-10] (Hewlett-Packard) Task: {1A9ADBAE-BD1E-4D74-A1D6-D8B26DA8A90F} - \dsmonitor No Task File Task: {1E9E1EA8-2B15-4F53-BA87-FD866FE299C1} - \MySearchDial No Task File Task: {279B66BC-725F-4DD9-8E70-48F6DC9D57F7} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-23] () Task: {32EAA0C2-9B22-4459-86FD-707257B9EA9A} - \Jjjuxgi No Task File Task: {3B35629C-4734-47CB-8F43-965CC631670F} - System32\Tasks\ServicePlan => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-23] () Task: {515FE178-4D0C-4794-AD74-D406592B788D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-12-12] (Hewlett-Packard Company) Task: {54698719-893F-4237-98B9-4A4218ED7E51} - System32\Tasks\HPCeeScheduleForstudentin mama => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05] (Hewlett-Packard) Task: {6C768DA6-4B42-42E4-AB1C-61431C712A8B} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe [2010-06-24] (CyberLink) Task: {6CCC4DF5-B34D-4EE5-9CB4-7FC8F60576DD} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe Task: {70AAF0CA-45FA-4555-97CA-0C3C48B42415} - System32\Tasks\RunAsStdUser Task for VeohWebPlayer => C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe <==== ATTENTION Task: {71906D7C-D3F3-4602-8E27-BFF3A331D87D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {77E4D3A2-5FE6-49D7-AE63-4605C32FAD15} - System32\Tasks\{2803D596-E189-426E-830F-D9729361D990} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.114/de/abandoninstall?page=tsProgressBar Task: {86FD4AF1-FE07-45E5-B7E8-1FCEE2AB8E8D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {A5622CED-0E8F-469A-A502-D665DC62DE9D} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\Communicator.exe [2013-04-22] () Task: {A7F5448C-DB93-4167-AF41-27EDC213AF63} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {BA793CA6-9407-45A2-AA1A-CD3DD810E037} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-26] (Google Inc.) Task: {BC8B6A7F-5C42-40B6-966C-3B9B360260EA} - \ProtectedSearch\Protected Search No Task File Task: {C2041413-7C59-4CFA-A827-93F2AEA95932} - System32\Tasks\SW.Booster-S-4606583622 => c:\programdata\greenapp\sw.booster\SW.Booster.exe Task: {C4D720E6-5B65-4B8C-91D7-22D95A4175F0} - System32\Tasks\{565485B0-CE07-4A43-8ADE-E590F93FC96D} => C:\Program Files (x86)\Windows Phone\WindowsPhone.exe [2014-03-26] (Microsoft Corporation) Task: {C8644006-2FB9-4705-82B8-D73432D7CC54} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe Task: {D5830753-8EB7-4505-8DBA-181401A67B2C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: {EF1AFC9F-1B9A-46C4-A996-A26D6A5EE20E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-26] (Google Inc.) Task: {FF3357F9-381F-425E-BAD5-C2D0DE84CF99} - \UpdaterEX No Task File Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\Communicator.exe Task: C:\Windows\Tasks\HPCeeScheduleForstudentin mama.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe Task: C:\Windows\Tasks\SW.Booster-S-4606583622.job => c:\programdata\greenapp\sw.booster\SW.Booster.exe ==================== Loaded Modules (whitelisted) ============= 2013-04-19 16:52 - 2008-06-04 15:53 - 00027648 _____ () C:\Windows\System32\spd__l6.dll 2010-06-29 19:00 - 2010-06-29 19:00 - 00027192 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe 2013-04-19 16:53 - 2009-02-04 18:55 - 00548864 _____ () C:\Windows\Samsung\PanelMgr\SSMMgr.exe 2013-08-29 02:23 - 2013-08-29 02:23 - 01861968 _____ () C:\PROGRAM FILES (X86)\DIVX\DIVX UPDATE\DIVXUPDATE.EXE 2013-04-19 16:53 - 2008-07-22 10:00 - 00306688 _____ () C:\Windows\Samsung\PanelMgr\caller64.exe 2010-03-09 15:34 - 2010-03-09 15:34 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2011-03-10 02:06 - 2011-03-10 02:06 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2010-06-18 16:26 - 2010-06-18 16:26 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll 2010-06-18 16:26 - 2010-06-18 16:26 - 00030264 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_LogicLayer.dll 2010-06-18 16:26 - 2010-06-18 16:26 - 00052280 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HardwareAccess.dll 2013-12-13 00:36 - 2013-12-13 00:36 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll 2013-09-13 20:51 - 2013-09-13 20:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-09-13 20:51 - 2013-09-13 20:51 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2010-05-19 11:05 - 2010-05-19 11:05 - 02121728 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll 2010-05-19 11:05 - 2010-05-19 11:05 - 07745536 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll 2010-05-19 11:05 - 2010-05-19 11:05 - 00135168 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00019456 _____ () C:\Program Files (x86)\MyTomTom 3\DeviceDetection.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00067576 _____ () C:\Program Files (x86)\MyTomTom 3\TomTomSupporterBase.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 02302464 _____ () C:\Program Files (x86)\MyTomTom 3\QtCore4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00252408 _____ () C:\Program Files (x86)\MyTomTom 3\TomTomSupporterProxy.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00980480 _____ () C:\Program Files (x86)\MyTomTom 3\QtNetwork4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00357888 _____ () C:\Program Files (x86)\MyTomTom 3\QtXml4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 07964160 _____ () C:\Program Files (x86)\MyTomTom 3\QtGui4.dll 2013-08-29 02:23 - 2013-08-29 02:23 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 2013-08-29 02:25 - 2013-08-29 02:25 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2014-03-29 20:33 - 2014-03-29 20:33 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2012-01-16 21:06 - 2012-01-16 21:06 - 00577621 _____ () C:\Program Files (x86)\Spyware Terminator\sqlite3.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\studentin mama\Downloads\StudiSoft_ Bestaetigung der Bestellung 0-00001349.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (04/08/2014 10:34:45 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 7145 Error: (04/08/2014 10:34:45 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 7145 Error: (04/08/2014 10:34:45 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/08/2014 10:34:44 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6084 Error: (04/08/2014 10:34:44 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 6084 Error: (04/08/2014 10:34:44 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/08/2014 10:34:42 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5039 Error: (04/08/2014 10:34:42 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 5039 Error: (04/08/2014 10:34:42 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/08/2014 10:34:41 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 4025 System errors: ============= Error: (04/09/2014 10:18:13 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/09/2014 10:18:13 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SW-Sustainer erreicht. Error: (04/08/2014 09:17:51 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/08/2014 09:17:51 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SW-Sustainer erreicht. Error: (04/08/2014 05:55:42 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/08/2014 05:55:42 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SW-Sustainer erreicht. Error: (04/08/2014 10:08:56 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/08/2014 10:08:56 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SW-Sustainer erreicht. Error: (04/08/2014 00:35:39 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/08/2014 00:35:39 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SW-Sustainer erreicht. Microsoft Office Sessions: ========================= Error: (04/08/2014 10:34:45 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 7145 Error: (04/08/2014 10:34:45 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 7145 Error: (04/08/2014 10:34:45 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/08/2014 10:34:44 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6084 Error: (04/08/2014 10:34:44 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 6084 Error: (04/08/2014 10:34:44 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/08/2014 10:34:42 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5039 Error: (04/08/2014 10:34:42 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 5039 Error: (04/08/2014 10:34:42 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/08/2014 10:34:41 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 4025 ==================== Memory info =========================== Percentage of memory in use: 41% Total physical RAM: 3834.9 MB Available physical RAM: 2243.8 MB Total Pagefile: 7667.98 MB Available Pagefile: 5682.34 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:576.02 GB) (Free:443.66 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:19.86 GB) (Free:2.89 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 596 GB) (Disk ID: 7C5910A0) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=576 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=20 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=103 MB) - (Type=0C) ==================== End Of Log ============================ |
09.04.2014, 21:18 | #4 |
Ruhe in Frieden † 2019 | zilliontoolkitusa.info versehentlich installiert - was nun? Hallo abimama, bitte sehr. Wie ist es nach diesem Fix? Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter GroupPolicy: Group Policy on Chrome detected <======= ATTENTION SearchScopes: HKLM-x32 - {1B9EB9F7-E37A-84D5-8074-2983B2C5FBE0} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dstrmsd&cd=2XzuyEtN2Y1L1Qzu0E0CyDyD0FzytAyE0AyBzy0F0CtD0DyEtN0D0Tzu0CyCzztAtN1L2XzutBtFtBtFzztFtCtByEyBtN1L1Czu1Q1B2Z1C1H1B1Q&cr=49275907&ir= SearchScopes: HKCU - {22BC9D89-4AFD-4FD9-93D7-FDC19F581E42} URL = hxxp://searchya.com/?chnl=ft-102&s=1&cr=1395955839&cd=2XzutAtN2Y1L1Qzu0E0CyDyD0FzytAyE0AyBzy0FyD0CtD0DyEtN0D0TzutBtDtCtBtDtAtDyB&q={searchTerms} SearchScopes: HKCU - {654B965E-3DF5-6EBF-25F2-16047A3CEE0A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dstrmsd&cd=2XzuyEtN2Y1L1Qzu0E0CyDyD0FzytAyE0AyBzy0F0CtD0DyEtN0D0Tzu0CyCzztAtN1L2XzutBtFtBtFzztFtCtByEyBtN1L1Czu1Q1B2Z1C1H1B1Q&cr=49275907&ir= FF Extension: safewaebu - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\eiy.3h2a3@csrpxoeu.com [2014-04-02] FF Extension: SNT - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\xmjope9q@pkajbtag-y.co.uk [2014-04-02] CHR Extension: (safewaebu) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\ophckemjgdhcaemfcpnjdfnooiflpbdl [2014-04-02] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S2 d0e87c27; "C:\Windows\system32\rundll32.exe" "c:\progra~2\sw-boo~1\AssistantSvc.dll",service Task: {1A9ADBAE-BD1E-4D74-A1D6-D8B26DA8A90F} - \dsmonitor No Task File Task: {1E9E1EA8-2B15-4F53-BA87-FD866FE299C1} - \MySearchDial No Task File Task: {32EAA0C2-9B22-4459-86FD-707257B9EA9A} - \Jjjuxgi No Task File Task: {BC8B6A7F-5C42-40B6-966C-3B9B360260EA} - \ProtectedSearch\Protected Search No Task File Task: {C2041413-7C59-4CFA-A827-93F2AEA95932} - System32\Tasks\SW.Booster- S-4606583622 => c:\programdata\greenapp\sw.booster\SW.Booster.exe Task: {C8644006-2FB9-4705-82B8-D73432D7CC54} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe Task: C:\Windows\Tasks\SW.Booster-S-4606583622.job => c:\programdata\greenapp\sw.booster\SW.Booster.exe Task: {FF3357F9-381F-425E-BAD5-C2D0DE84CF99} - \UpdaterEX No Task File C:\Users\studentin mama\Downloads\SpyHunter-Installer.exe C:\Program Files\Enigma Software Group c:\progra~2\sw-boo~1\AssistantSvc.dll C:\Users\studentin mama\Downloads\SpyHunter-Installer(3).exe C:\Windows\System32\Tasks\SpyHunter4Startup C:\Users\studentin mama\Desktop\SpyHunter.lnk C:\sh4ldr C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP C:\Users\studentin mama\Downloads\SpyHunter-Installer(2).exe C:\Windows\Tasks\SW.Booster-S-4606583622.job C:\Windows\System32\Tasks\SW.Booster-S-4606583622 C:\Program Files (x86)\SW-Booster C:\ProgramData\siaafEweB C:\Program Files (x86)\siaafEweB c:\programdata\greenapp C:\Users\studentin mama\AppData\Local\Temp\*.exe C:\Users\studentin mama\AppData\Local\Temp\*.dll cmd: dir C:\ProgramData\8fba3f8d18b65f94 /s Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Starte noch einmal FRST.
|
09.04.2014, 22:44 | #5 |
| zilliontoolkitusa.info versehentlich installiert - was nun? sorry, es funktioniert nicht. ich habe bei Schritt 1 alles unter Fixlist.txt abgespeichert und ich bekomme angezeigt, dass es nicht in der selben Ebene wie das tool abgespeichert ist. ich habe dann das FRST gesucht und die neue Datei Fixlist.txt dort hineingeschoben, ging wieder nicht. Nun habe ich alle Datein auf den Desktop gezogen und trotzdem bekomme ich die gleiche Nachricht. Tut mir leid! |
09.04.2014, 23:23 | #6 |
Ruhe in Frieden † 2019 | zilliontoolkitusa.info versehentlich installiert - was nun? Hallo abimama, hast du die Fixlist unter C:\Users\studentin mama\Downloads gespeichert? Dort liegt FRST.exe, das sollte dann eigentlich problemlos funktionieren.
__________________ --> zilliontoolkitusa.info versehentlich installiert - was nun? |
09.04.2014, 23:47 | #7 |
| zilliontoolkitusa.info versehentlich installiert - was nun?Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014 Ran by studentin mama at 2014-04-10 00:35:30 Run:1 Running from C:\Users\studentin mama\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** GroupPolicy: Group Policy on Chrome detected <======= ATTENTION SearchScopes: HKLM-x32 - {1B9EB9F7-E37A-84D5-8074-2983B2C5FBE0} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dstrmsd&cd=2XzuyEtN2Y1L1Qzu0E0CyDyD0FzytAyE0AyBzy0F0CtD0DyEtN0D0Tzu0CyCzztAtN1L2XzutBtFtBtFzztFtCtByEyBtN1L1Czu1Q1B2Z1C1H1B1Q&cr=49275907&ir= SearchScopes: HKCU - {22BC9D89-4AFD-4FD9-93D7-FDC19F581E42} URL = hxxp://searchya.com/?chnl=ft-102&s=1&cr=1395955839&cd=2XzutAtN2Y1L1Qzu0E0CyDyD0FzytAyE0AyBzy0FyD0CtD0DyEtN0D0TzutBtDtCtBtDtAtDyB&q={searchTerms} SearchScopes: HKCU - {654B965E-3DF5-6EBF-25F2-16047A3CEE0A} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=dstrmsd&cd=2XzuyEtN2Y1L1Qzu0E0CyDyD0FzytAyE0AyBzy0F0CtD0DyEtN0D0Tzu0CyCzztAtN1L2XzutBtFtBtFzztFtCtByEyBtN1L1Czu1Q1B2Z1C1H1B1Q&cr=49275907&ir= FF Extension: safewaebu - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\eiy.3h2a3@csrpxoeu.com [2014-04-02] FF Extension: SNT - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\xmjope9q@pkajbtag-y.co.uk [2014-04-02] CHR Extension: (safewaebu) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\ophckemjgdhcaemfcpnjdfnooiflpbdl [2014-04-02] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION S2 d0e87c27; "C:\Windows\system32\rundll32.exe" "c:\progra~2\sw-boo~1\AssistantSvc.dll",service Task: {1A9ADBAE-BD1E-4D74-A1D6-D8B26DA8A90F} - \dsmonitor No Task File Task: {1E9E1EA8-2B15-4F53-BA87-FD866FE299C1} - \MySearchDial No Task File Task: {32EAA0C2-9B22-4459-86FD-707257B9EA9A} - \Jjjuxgi No Task File Task: {BC8B6A7F-5C42-40B6-966C-3B9B360260EA} - \ProtectedSearch\Protected Search No Task File Task: {C2041413-7C59-4CFA-A827-93F2AEA95932} - System32\Tasks\SW.Booster- S-4606583622 => c:\programdata\greenapp\sw.booster\SW.Booster.exe Task: {C8644006-2FB9-4705-82B8-D73432D7CC54} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe Task: C:\Windows\Tasks\SW.Booster-S-4606583622.job => c:\programdata\greenapp\sw.booster\SW.Booster.exe Task: {FF3357F9-381F-425E-BAD5-C2D0DE84CF99} - \UpdaterEX No Task File C:\Users\studentin mama\Downloads\SpyHunter-Installer.exe C:\Program Files\Enigma Software Group c:\progra~2\sw-boo~1\AssistantSvc.dll C:\Users\studentin mama\Downloads\SpyHunter-Installer(3).exe C:\Windows\System32\Tasks\SpyHunter4Startup C:\Users\studentin mama\Desktop\SpyHunter.lnk C:\sh4ldr C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP C:\Users\studentin mama\Downloads\SpyHunter-Installer(2).exe C:\Windows\Tasks\SW.Booster-S-4606583622.job C:\Windows\System32\Tasks\SW.Booster-S-4606583622 C:\Program Files (x86)\SW-Booster C:\ProgramData\siaafEweB C:\Program Files (x86)\siaafEweB c:\programdata\greenapp C:\Users\studentin mama\AppData\Local\Temp\*.exe C:\Users\studentin mama\AppData\Local\Temp\*.dll cmd: dir C:\ProgramData\8fba3f8d18b65f94 /s ***************** C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{1B9EB9F7-E37A-84D5-8074-2983B2C5FBE0} => Key deleted successfully. HKCR\Wow6432Node\CLSID\{1B9EB9F7-E37A-84D5-8074-2983B2C5FBE0} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{22BC9D89-4AFD-4FD9-93D7-FDC19F581E42} => Key deleted successfully. HKCR\CLSID\{22BC9D89-4AFD-4FD9-93D7-FDC19F581E42} => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{654B965E-3DF5-6EBF-25F2-16047A3CEE0A} => Key deleted successfully. HKCR\CLSID\{654B965E-3DF5-6EBF-25F2-16047A3CEE0A} => Key not found. C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\eiy.3h2a3@csrpxoeu.com => Moved successfully. C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\xmjope9q@pkajbtag-y.co.uk => Moved successfully. C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\ophckemjgdhcaemfcpnjdfnooiflpbdl => Moved successfully. HKLM\SOFTWARE\Policies\Google => Key deleted successfully. d0e87c27 => Service deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1A9ADBAE-BD1E-4D74-A1D6-D8B26DA8A90F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1A9ADBAE-BD1E-4D74-A1D6-D8B26DA8A90F} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\dsmonitor => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1E9E1EA8-2B15-4F53-BA87-FD866FE299C1} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1E9E1EA8-2B15-4F53-BA87-FD866FE299C1} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MySearchDial => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{32EAA0C2-9B22-4459-86FD-707257B9EA9A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{32EAA0C2-9B22-4459-86FD-707257B9EA9A} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Jjjuxgi => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BC8B6A7F-5C42-40B6-966C-3B9B360260EA} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BC8B6A7F-5C42-40B6-966C-3B9B360260EA} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ProtectedSearch\Protected Search => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C2041413-7C59-4CFA-A827-93F2AEA95932} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2041413-7C59-4CFA-A827-93F2AEA95932} => Key deleted successfully. C:\Windows\System32\Tasks\SW.Booster- not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SW.Booster- => Key not found. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C8644006-2FB9-4705-82B8-D73432D7CC54} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C8644006-2FB9-4705-82B8-D73432D7CC54} => Key deleted successfully. C:\Windows\System32\Tasks\SpyHunter4Startup => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SpyHunter4Startup => Key deleted successfully. C:\Windows\Tasks\SW.Booster-S-4606583622.job => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FF3357F9-381F-425E-BAD5-C2D0DE84CF99} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FF3357F9-381F-425E-BAD5-C2D0DE84CF99} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UpdaterEX => Key deleted successfully. C:\Users\studentin mama\Downloads\SpyHunter-Installer.exe => Moved successfully. C:\Program Files\Enigma Software Group => Moved successfully. "c:\progra~2\sw-boo~1\AssistantSvc.dll" => File/Directory not found. C:\Users\studentin mama\Downloads\SpyHunter-Installer(3).exe => Moved successfully. "C:\Windows\System32\Tasks\SpyHunter4Startup" => File/Directory not found. C:\Users\studentin mama\Desktop\SpyHunter.lnk => Moved successfully. C:\sh4ldr => Moved successfully. C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP => Moved successfully. C:\Users\studentin mama\Downloads\SpyHunter-Installer(2).exe => Moved successfully. "C:\Windows\Tasks\SW.Booster-S-4606583622.job" => File/Directory not found. C:\Windows\System32\Tasks\SW.Booster-S-4606583622 => Moved successfully. C:\Program Files (x86)\SW-Booster => Moved successfully. C:\ProgramData\siaafEweB => Moved successfully. C:\Program Files (x86)\siaafEweB => Moved successfully. C:\ProgramData\GreenApp => Moved successfully. C:\Users\studentin mama\AppData\Local\Temp\*.exe => Moved successfully. C:\Users\studentin mama\AppData\Local\Temp\*.dll => Moved successfully. ========= dir C:\ProgramData\8fba3f8d18b65f94 /s ========= Volume in Laufwerk C: hat keine Bezeichnung. Volumeseriennummer: C6C5-C0D4 Verzeichnis von C:\ProgramData\8fba3f8d18b65f94 02.04.2014 20:02 <DIR> . 02.04.2014 20:02 <DIR> .. 02.04.2014 20:01 38.690 {4820778D-AB0D-6D18-C316-52A6A0E1D507} 02.04.2014 20:01 2.692 {497C131E-2032-051B-B32A-C69A960FBB13} 02.04.2013 20:01 37.038 {497C131E-2032-051B-B32A-C69A960FBB13}.old 02.04.2014 20:01 30.118 {AD11DADE-C597-45D9-D8C5-1D2EB0B89613} 02.04.2014 20:02 38.814 {C670DCAE-E392-AA32-6F42-143C7FC4BDFD} 5 Datei(en), 147.352 Bytes Anzahl der angezeigten Dateien: 5 Datei(en), 147.352 Bytes 2 Verzeichnis(se), 475.971.465.216 Bytes frei ========= End of CMD: ========= The system needed a reboot. ==== End of Fixlog ==== FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 (ATTENTION: ====> FRST version is 28 days old and could be outdated) Ran by studentin mama (administrator) on STUDENTINMAMA on 10-04-2014 00:41:55 Running from C:\Users\studentin mama\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Hewlett-Packard) C:\Windows\system32\Hpservice.exe (AMD) C:\Windows\system32\atieclxx.exe (Cisco Systems, Inc.) C:\PROGRAM FILES (X86)\CISCO\CISCO ANYCONNECT SECURE MOBILITY CLIENT\VPNAGENT.EXE (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe () C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (IObit) C:\PROGRAM FILES (X86)\IOBIT\LIVEUPDATE\LIVEUPDATE.EXE (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe (Crawler.com) C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Crawler.com) C:\PROGRAM FILES (X86)\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (TomTom) C:\PROGRAM FILES (X86)\MYTOMTOM 3\MYTOMTOMSA.EXE (Microsoft Corporation) C:\PROGRAM FILES\WINDOWS SIDEBAR\SIDEBAR.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Advanced Micro Devices Inc.) C:\PROGRAM FILES (X86)\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\MOM.EXE () C:\Windows\Samsung\PanelMgr\SSMMgr.exe (Microsoft Corporation) C:\WINDOWS\SYSTEM32\DEVICEDISPLAYOBJECTPROVIDER.EXE () C:\PROGRAM FILES (X86)\DIVX\DIVX UPDATE\DIVXUPDATE.EXE () C:\Windows\Samsung\PanelMgr\caller64.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Easybits) C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe (Cisco Systems, Inc.) C:\PROGRAM FILES (X86)\CISCO\CISCO ANYCONNECT SECURE MOBILITY CLIENT\VPNUI.EXE (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (ATI Technologies Inc.) C:\PROGRAM FILES (X86)\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\CCC.EXE (Mozilla Corporation) C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE (Microsoft Corporation) C:\WINDOWS\SYSTEM32\DXPSERVER.EXE (CyberLink) C:\PROGRAM FILES (X86)\HEWLETT-PACKARD\MEDIA\WEBCAM\YCMMIRAGE.EXE (Adobe Systems, Inc.) C:\WINDOWS\SYSWOW64\MACROMED\FLASH\FLASHPLAYERPLUGIN_12_0_0_77.EXE (Adobe Systems, Inc.) C:\WINDOWS\SYSWOW64\MACROMED\FLASH\FLASHPLAYERPLUGIN_12_0_0_77.EXE (Hewlett-Packard Company) C:\PROGRAM FILES (X86)\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK\HPSA_SERVICE.EXE (Hewlett-Packard Company) C:\PROGRAM FILES\HEWLETT-PACKARD\HP WIRELESS ASSISTANT\HPWA_SERVICE.EXE (Hewlett-Packard Company) C:\PROGRAM FILES\HEWLETT-PACKARD\HP WIRELESS ASSISTANT\HPWA_MAIN.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2281256 2011-10-30] (Synaptics Incorporated) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-06-09] (IDT, Inc.) HKLM\...\Run: [HPWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-06-18] (Hewlett-Packard Company) HKLM\...\Run: [SpywareTerminatorShield] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com) HKLM\...\Run: [SpywareTerminatorUpdater] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-04-16] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [602168 2010-06-29] (Hewlett-Packard Company) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe HKLM-x32\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [548864 2009-02-04] () HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] () HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKLM-x32\...\Run: [Magic Desktop for HP notification] - C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1258504 2013-12-30] (Easybits) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707472 2013-12-13] (Cisco Systems, Inc.) HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-04-08] (Hewlett-Packard) HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2010-05-19] (Hewlett-Packard Company) HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [MyTomTomSA.exe] - C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe [434168 2012-05-18] (TomTom) HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [EPSON Stylus DX5000 Series] - C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIBVE.EXE [139264 2006-09-22] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Policies\system: [DisableChangePassword] 0 HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\MountPoints2: G - G:\pushinst.exe HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\MountPoints2: {2c95361d-2ce3-11e1-9892-f1a06df124b6} - G:\Setup.exe AppInit_DLLs: C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL => C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL File Not Found Startup: C:\Users\studentin mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4 SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {19089719-9401-4468-AE0B-8104E8D0D9EF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM - {654B965E-3DF5-6EBF-25F2-16047A3CEE0A} URL = SearchScopes: HKLM - {E81CDADA-1F06-414B-A58F-396B22D1CAFD} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM-x32 - {19089719-9401-4468-AE0B-8104E8D0D9EF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM-x32 - {E81CDADA-1F06-414B-A58F-396B22D1CAFD} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKCU - {19089719-9401-4468-AE0B-8104E8D0D9EF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKCU - {E81CDADA-1F06-414B-A58F-396B22D1CAFD} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {538793D5-659C-4639-A56C-A179AD87ED44} Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 - C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: YoutubeAdblocker - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\mriqu@dpfrjfc.com [2014-04-02] FF Extension: WEB.DE MailCheck - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\toolbar@web.de.xpi [2013-11-25] FF Extension: Adblock Plus - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-09-24] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-03-29] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-03-29] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-03-29] FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-04-27] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR Extension: (No Name) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\gladcbhcbkdeddbidiblppadjdjalidb [2012-11-17] CHR Extension: (SNT) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\jipdpdgjdgibngmaockoaenedejjnkgk [2014-04-02] CHR Extension: (tinyFilter) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlfgnnlnfbpcammlnibfkplpnbbbdeli [2014-04-02] CHR Extension: (YoutubeAdblocker) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\olodkgeocddnmkokdmamjnjdkdijnkgm [2014-04-02] ==================== Services (Whitelisted) ================= R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE [102400 2006-04-18] (SEIKO EPSON CORPORATION) R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [27192 2010-06-29] () R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151744 2014-01-11] (IObit) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) R2 ST2012_Svc; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [1149104 2013-04-03] (Crawler.com) ==================== Drivers (Whitelisted) ==================== R2 sp_rsdrv2; C:\Windows\System32\DRIVERS\stflt.sys [51496 2014-04-05] (Windows (R) Win 7 DDK provider) S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52080 2013-12-13] (Cisco Systems, Inc.) S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-09 10:43 - 2014-04-09 10:43 - 00046375 _____ () C:\Users\studentin mama\Desktop\FRST_09-04-2014_10-43-38.txt 2014-04-09 10:43 - 2014-04-09 10:43 - 00043264 _____ () C:\Users\studentin mama\Desktop\Addition.txt 2014-04-09 10:41 - 2014-04-09 10:43 - 00044391 _____ () C:\Users\studentin mama\Downloads\Addition.txt 2014-04-09 10:39 - 2014-04-10 00:42 - 00019972 _____ () C:\Users\studentin mama\Downloads\FRST.txt 2014-04-09 10:38 - 2014-04-10 00:41 - 00000000 ____D () C:\FRST 2014-04-09 10:33 - 2014-04-09 10:33 - 02157056 _____ (Farbar) C:\Users\studentin mama\Downloads\FRST64.exe 2014-04-07 13:55 - 2014-04-07 14:04 - 10995296 _____ (Deutsche Telekom AG, Marmiko IT-Solutions GmbH ) C:\Users\studentin mama\Downloads\netzmanager_setup.exe 2014-04-05 22:42 - 2014-04-05 22:42 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000(1).exe 2014-04-05 22:27 - 2014-04-05 22:27 - 02347384 _____ (ESET) C:\Users\studentin mama\Downloads\esetsmartinstaller_enu.exe 2014-04-05 22:27 - 2014-04-05 22:27 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-05 08:36 - 2014-04-08 17:56 - 00000000 ____D () C:\ProgramData\Spyware Terminator 2014-04-05 08:36 - 2014-04-05 08:36 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-04-05 08:36 - 2014-04-05 08:36 - 00001002 _____ () C:\Users\Public\Desktop\Spyware Terminator 2012.lnk 2014-04-05 08:36 - 2014-04-05 08:36 - 00000000 ____D () C:\Users\studentin mama\AppData\Roaming\Spyware Terminator 2014-04-05 08:36 - 2014-04-05 08:36 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator 2014-04-05 08:30 - 2014-04-05 08:30 - 05049344 _____ (Crawler.com ) C:\Users\studentin mama\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2014-04-04 23:56 - 2014-04-04 23:57 - 00613200 _____ (Chip Digital GmbH) C:\Users\studentin mama\Downloads\AdwCleaner - CHIP-Downloader.exe 2014-04-04 23:07 - 2014-04-06 00:20 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-04 23:06 - 2014-04-05 22:43 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-04 23:06 - 2014-04-05 22:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-04 23:06 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-04 23:06 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-04 23:06 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-04 23:05 - 2014-04-04 23:06 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000.exe 2014-04-04 23:00 - 2014-04-04 23:04 - 00001420 _____ () C:\Users\studentin mama\Desktop\Rkill.txt 2014-04-04 22:59 - 2014-04-04 22:59 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\studentin mama\Downloads\wObiA.exe 2014-04-04 16:16 - 2014-04-04 16:20 - 00000000 ____D () C:\Users\studentin mama\Desktop\Documents\KWB 2014 2014-04-03 21:35 - 2014-04-04 16:08 - 00012603 _____ () C:\Users\studentin mama\Desktop\Documents\Bewertungsbögen Spezialaufgabe KWB 2014.xlsx 2014-04-02 20:02 - 2014-04-02 20:02 - 12400098 _____ () C:\Users\studentin mama\Desktop\Die Machtergreifung in Würzburg 1933, PDF.zip 2014-04-02 20:01 - 2014-04-02 20:02 - 00000000 ____D () C:\ProgramData\8fba3f8d18b65f94 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Packages 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator 2014-04-02 20:00 - 2014-04-02 20:02 - 00000000 ____D () C:\ProgramData\InstallMate 2014-03-29 20:33 - 2014-03-29 20:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-13 23:53 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-13 23:53 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-13 23:53 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-13 23:53 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-13 23:53 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-13 23:53 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-13 23:53 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-13 23:53 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-13 23:53 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-13 23:53 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-13 23:53 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-13 23:53 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-13 23:53 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-13 23:53 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-13 23:53 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-13 23:53 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-13 23:53 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-13 23:53 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-13 23:53 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-13 23:53 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-13 23:53 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-13 23:53 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-13 23:53 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-13 23:53 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-13 23:53 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-13 23:53 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-13 23:53 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-13 23:53 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-13 23:53 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-13 23:53 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-13 23:53 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-13 23:53 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-13 23:53 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-13 23:53 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-13 23:53 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-13 23:53 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-13 23:53 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-13 23:53 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-13 23:53 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-13 23:53 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-13 23:53 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-13 23:53 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-13 23:52 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-13 23:52 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-13 23:52 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-13 23:52 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-13 23:52 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-13 23:52 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll ==================== One Month Modified Files and Folders ======= 2014-04-10 00:43 - 2012-02-26 15:04 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-10 00:42 - 2014-04-09 10:39 - 00019972 _____ () C:\Users\studentin mama\Downloads\FRST.txt 2014-04-10 00:41 - 2014-04-09 10:38 - 00000000 ____D () C:\FRST 2014-04-10 00:41 - 2011-03-10 02:07 - 01814457 _____ () C:\Windows\WindowsUpdate.log 2014-04-10 00:38 - 2014-01-29 20:56 - 00000008 __RSH () C:\ProgramData\ntuser.pol 2014-04-10 00:38 - 2012-02-26 15:04 - 00001122 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-10 00:37 - 2014-02-13 17:40 - 00000368 _____ () C:\Windows\Tasks\HPCeeScheduleForstudentin mama.job 2014-04-10 00:37 - 2013-09-24 08:09 - 00028824 _____ () C:\Windows\setupact.log 2014-04-10 00:37 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-10 00:35 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-04-09 23:57 - 2013-05-28 01:13 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-09 23:54 - 2011-10-31 17:48 - 00000356 _____ () C:\Windows\Tasks\HP Photo Creations Communicator.job 2014-04-09 20:30 - 2014-02-13 17:40 - 00003240 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForstudentin mama 2014-04-09 20:30 - 2011-11-09 22:07 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-04-09 20:30 - 2011-10-05 12:45 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-04-09 20:27 - 2009-07-14 06:45 - 00023024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-09 20:27 - 2009-07-14 06:45 - 00023024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-09 20:22 - 2013-01-09 20:35 - 00003986 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{D3FEFDA5-19CA-46DA-9710-E509D83A4478} 2014-04-09 10:43 - 2014-04-09 10:43 - 00046375 _____ () C:\Users\studentin mama\Desktop\FRST_09-04-2014_10-43-38.txt 2014-04-09 10:43 - 2014-04-09 10:43 - 00043264 _____ () C:\Users\studentin mama\Desktop\Addition.txt 2014-04-09 10:43 - 2014-04-09 10:41 - 00044391 _____ () C:\Users\studentin mama\Downloads\Addition.txt 2014-04-09 10:33 - 2014-04-09 10:33 - 02157056 _____ (Farbar) C:\Users\studentin mama\Downloads\FRST64.exe 2014-04-08 23:12 - 2013-06-14 08:24 - 00000000 ____D () C:\Program Files (x86)\Windows Phone 2014-04-08 17:56 - 2014-04-05 08:36 - 00000000 ____D () C:\ProgramData\Spyware Terminator 2014-04-08 02:35 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-04-08 00:34 - 2013-09-24 08:09 - 01357614 _____ () C:\Windows\PFRO.log 2014-04-07 14:04 - 2014-04-07 13:55 - 10995296 _____ (Deutsche Telekom AG, Marmiko IT-Solutions GmbH ) C:\Users\studentin mama\Downloads\netzmanager_setup.exe 2014-04-07 07:40 - 2010-07-31 19:11 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-04-07 07:40 - 2010-07-31 19:11 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-04-07 07:40 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-06 00:33 - 2011-10-20 06:57 - 00000000 ____D () C:\Users\studentin mama\Desktop\Studium Lehramt an Gymnasien Deutsch und Geschichte 2014-04-06 00:20 - 2014-04-04 23:07 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-05 22:43 - 2014-04-04 23:06 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-05 22:43 - 2014-04-04 23:06 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-05 22:42 - 2014-04-05 22:42 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000(1).exe 2014-04-05 22:27 - 2014-04-05 22:27 - 02347384 _____ (ESET) C:\Users\studentin mama\Downloads\esetsmartinstaller_enu.exe 2014-04-05 22:27 - 2014-04-05 22:27 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-05 08:36 - 2014-04-05 08:36 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-04-05 08:36 - 2014-04-05 08:36 - 00001002 _____ () C:\Users\Public\Desktop\Spyware Terminator 2012.lnk 2014-04-05 08:36 - 2014-04-05 08:36 - 00000000 ____D () C:\Users\studentin mama\AppData\Roaming\Spyware Terminator 2014-04-05 08:36 - 2014-04-05 08:36 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator 2014-04-05 08:30 - 2014-04-05 08:30 - 05049344 _____ (Crawler.com ) C:\Users\studentin mama\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2014-04-05 08:30 - 2011-10-07 23:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\CrashDumps 2014-04-05 00:02 - 2011-10-04 14:15 - 00000000 ____D () C:\Windows\SHELLNEW 2014-04-05 00:01 - 2013-09-22 13:51 - 00000000 ____D () C:\AdwCleaner 2014-04-04 23:57 - 2014-04-04 23:56 - 00613200 _____ (Chip Digital GmbH) C:\Users\studentin mama\Downloads\AdwCleaner - CHIP-Downloader.exe 2014-04-04 23:06 - 2014-04-04 23:05 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000.exe 2014-04-04 23:06 - 2012-10-08 11:49 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-04 23:04 - 2014-04-04 23:00 - 00001420 _____ () C:\Users\studentin mama\Desktop\Rkill.txt 2014-04-04 22:59 - 2014-04-04 22:59 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\studentin mama\Downloads\wObiA.exe 2014-04-04 16:20 - 2014-04-04 16:16 - 00000000 ____D () C:\Users\studentin mama\Desktop\Documents\KWB 2014 2014-04-04 16:08 - 2014-04-03 21:35 - 00012603 _____ () C:\Users\studentin mama\Desktop\Documents\Bewertungsbögen Spezialaufgabe KWB 2014.xlsx 2014-04-04 00:50 - 2014-01-11 23:00 - 00000000 ____D () C:\ProgramData\ProductData 2014-04-02 20:02 - 2014-04-02 20:02 - 12400098 _____ () C:\Users\studentin mama\Desktop\Die Machtergreifung in Würzburg 1933, PDF.zip 2014-04-02 20:02 - 2014-04-02 20:01 - 00000000 ____D () C:\ProgramData\8fba3f8d18b65f94 2014-04-02 20:02 - 2014-04-02 20:00 - 00000000 ____D () C:\ProgramData\InstallMate 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Packages 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator 2014-04-02 20:01 - 2012-02-26 15:04 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Google 2014-03-31 07:02 - 2013-09-24 08:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-30 09:57 - 2014-02-15 10:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak 2014-03-29 20:33 - 2014-03-29 20:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-28 23:38 - 2012-02-26 15:04 - 00004122 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-28 23:38 - 2012-02-26 15:04 - 00003870 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-22 12:02 - 2013-06-16 17:42 - 00000000 ____D () C:\ProgramData\Origin 2014-03-22 12:01 - 2013-06-16 17:41 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-03-18 00:27 - 2013-09-25 21:32 - 00000000 ____D () C:\Windows\system32\MRT 2014-03-18 00:22 - 2011-10-17 22:46 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-03-15 22:51 - 2014-02-27 22:02 - 00000000 ____D () C:\Program Files (x86)\MediaViewV1 2014-03-14 16:50 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-03-14 10:36 - 2009-07-14 06:45 - 00397528 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-14 10:32 - 2011-10-04 14:15 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-03-14 00:23 - 2012-08-25 16:29 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-14 00:23 - 2012-08-25 16:29 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-03-12 23:57 - 2013-05-28 01:13 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-03-12 23:57 - 2013-04-24 09:56 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-03-12 23:57 - 2013-04-24 09:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl Some content of TEMP: ==================== C:\Users\Gast\AppData\Local\Temp\AskSLib.dll C:\Users\Gast\AppData\Local\Temp\DivXSetup.exe C:\Users\Gast\AppData\Local\Temp\drm_dyndata_7400009.dll C:\Users\Kinder\AppData\Local\Temp\AskSLib.dll C:\Users\Kinder\AppData\Local\Temp\DivXSetup.exe C:\Users\Kinder\AppData\Local\Temp\drm_dyndata_7400009.dll C:\Users\Kinder\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Kinder\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 21:16 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014 Ran by studentin mama at 2014-04-10 00:43:59 Running from C:\Users\studentin mama\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.9.0.1030 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.9.0.1030 - Adobe Systems Incorporated) Hidden Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Adobe Shockwave Player 11.5 (HKLM-x32\...\{9ECF7817-DB11-4FBA-9DF1-296A578D513A}) (Version: 11.5.7.609 - Adobe Systems, Inc) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.) AMD USB Filter Driver (x32 Version: 1.0.15.94 - Advanced Micro Devices, Inc.) Hidden Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros) ATI Catalyst Install Manager (HKLM\...\{11A4D79B-672C-7FFF-B5F7-B4409B1194EF}) (Version: 3.0.765.0 - ATI Technologies, Inc.) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Core Implementation (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Full New (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Light (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center InstallProxy (x32 Version: 2010.0416.541.8279 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2010.0416.541.8279 - ATI) Hidden CCC Help Chinese Standard (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Chinese Traditional (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Czech (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Danish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Dutch (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help English (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Finnish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help French (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help German (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Greek (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Hungarian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Italian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Japanese (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Korean (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Norwegian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Polish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Portuguese (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Russian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Spanish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Swedish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Thai (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Turkish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden ccc-core-static (x32 Version: 2010.0416.541.8279 - Ihr Firmenname) Hidden ccc-utility64 (Version: 2010.0416.541.8279 - ATI) Hidden Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.05152 - Cisco Systems, Inc.) Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.05152 - Cisco Systems, Inc.) Hidden CyberLink DVD Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.3003 - CyberLink Corp.) CyberLink DVD Suite (x32 Version: 7.0.3003 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{92C42EDD-6524-4577-B2EB-6C68C63B6D4A}) (Version: - Microsoft) Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts) Diercke Globus Online (HKLM-x32\...\Diercke Globus Online) (Version: 3.1.0 - Imagon GmbH) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.90 - DivX, LLC) DVD Menu Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}) (Version: 4.1.4121 - Hewlett-Packard) DVD Menu Pack for HP MediaSmart Video (x32 Version: 4.1.4121 - Hewlett-Packard) Hidden EPSON File Manager (HKLM-x32\...\{D02F30FB-0BC4-419A-9B9C-ADC610029B50}) (Version: 1.3.2.0 - ) EPSON Scan Assistant (HKLM-x32\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - ) EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version: - SEIKO EPSON Corporation) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) ESU for Microsoft Windows 7 (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard) Free YouTube to MP3 Converter version 3.11.35.1031 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.35.1031 - DVDVideoSoft Ltd.) Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Customer Experience Enhancements (x32 Version: 6.0.1.4 - Hewlett-Packard) Hidden HP Documentation (HKLM-x32\...\{E5AE53A7-1A79-4840-998F-A18042A2F568}) (Version: 1.1.1.0 - Hewlett-Packard) HP MediaSmart Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 4.1.3024 - Hewlett-Packard) HP MediaSmart Webcam (x32 Version: 4.1.3024 - Hewlett-Packard) Hidden HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.12412 - HP Photo Creations Powered by RocketLife) HP Photosmart Plus B210 series - Grundlegende Software für das Gerät (HKLM\...\{7578548C-6F40-4CBE-B5CF-9310E66557FA}) (Version: 22.50.231.0 - Hewlett-Packard Co.) HP Photosmart Plus B210 series Hilfe (HKLM-x32\...\{7F5FDEA1-D0AC-4D80-9D95-59775FCCFA40}) (Version: 140.0.54.54 - Hewlett Packard) HP Power Manager (HKLM-x32\...\{4B156358-CE9C-4E9F-8CAD-79AE86A68C60}) (Version: 1.0.3 - Hewlett-Packard Company) HP Quick Launch (HKLM-x32\...\{E342D296-DB9D-4FC7-ACB0-39926C0BFA16}) (Version: 2.1.5 - Hewlett-Packard Company) HP Setup (HKLM-x32\...\{72D90DB3-A16A-4545-B555-868471101833}) (Version: 8.1.4186.3400 - Hewlett-Packard) HP Software Framework (HKLM-x32\...\{B446137B-18A1-4FAE-B0E4-ABE8F09705F1}) (Version: 4.1.6.1 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company) HP Update (HKLM-x32\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard) HP Wireless Assistant (HKLM\...\{E342EC6B-5F25-47FE-B92C-DE616149B430}) (Version: 4.0.9.0 - Hewlett-Packard) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6288.0 - IDT) IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 3.0.4.922 - IObit) iTunes (HKLM\...\{D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0}) (Version: 11.1.3.8 - Apple Inc.) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden LightScribe System Software (HKLM-x32\...\{46BA053F-57B3-4153-BDB6-D37EEC8B12D7}) (Version: 1.18.15.1 - LightScribe) Malwarebytes Anti-Malware Version 2.00.0.1000 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.00.0.1000 - Malwarebytes Corporation) MarkSpace Outlook Server Version 1.0 (HKLM-x32\...\{050F5BE0-A8F6-48E1-9815-97322C1C1DC5}_is1) (Version: 1.0 - Mark/Space, Inc.) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1 - Nokia) Hidden Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1 - Nokia) Hidden Movie Theme Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}) (Version: 4.1.4030 - Hewlett-Packard) Movie Theme Pack for HP MediaSmart Video (x32 Version: 4.1.4030 - Hewlett-Packard) Hidden Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MyTomTom 3.2.0.700 (HKLM-x32\...\MyTomTom) (Version: 3.2.0.700 - TomTom) Nokia Connectivity Cable Driver (HKLM-x32\...\{29373274-977E-413C-A4DE-DC0F8E80C429}) (Version: 7.1.172.0 - Nokia) OpenTTD 1.1.5 (HKLM-x32\...\OpenTTD) (Version: 1.1.5 - OpenTTD) Origin (HKLM-x32\...\Origin) (Version: 9.0.14.2148 - Electronic Arts, Inc.) PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia) PDF Architect (HKLM-x32\...\{064A929A-4DE8-40CF-A901-BD40C14E4D25}) (Version: 1.1.83.9982 - pdfforge GmbH) PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.0 - pdfforge) Photo to Movie 5.0 (HKLM-x32\...\{FA166F42-B86E-437A-9AC3-87FCC351973C}) (Version: 5.0.704 - LQ Graphics, Inc.) PhotoPad Foto-Editor (HKLM-x32\...\PhotoPad) (Version: - NCH Software) PhotoScape (HKLM-x32\...\PhotoScape) (Version: - ) Pixillion Imagedatei-Konverter (HKLM-x32\...\Pixillion) (Version: - NCH Software) PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3003 - CyberLink Corp.) PowerDirector (x32 Version: 8.0.3003 - CyberLink Corp.) Hidden QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.11.1127.2009 - Realtek) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30113 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.3023 - CyberLink Corp.) Hidden RuntimeLibsVC90 (HKLM-x32\...\{F000DE4C-B6CB-4181-BAFF-EC5DA2A9C156}) (Version: 1.1.0 - Microsoft) Samsung Universal Print Driver (HKLM-x32\...\Samsung Universal Print Driver) (Version: - Samsung Electronics CO.,LTD) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Spyware Terminator 2012 (HKLM-x32\...\{56736259-613E-4A3B-B428-6235F2E76F44}_is1) (Version: 3.0.0.82 - Crawler.com) StreamTransport version: 1.0.2.2171 (HKLM-x32\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version: - ) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden SW-Sustainer 1.80 (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}) (Version: - Certified Publisher) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.1.6.64 - Synaptics Incorporated) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{81812245-FC84-426A-BC02-6659C88CC7B2}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2775360) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{80F56E3F-1D47-4E45-B6E0-FEF4E919F4F9}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2878227) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5D357893-40BA-4323-86BA-D97C66CD72F4}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft) Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{E78E2B68-8FD1-42EE-BB74-99A4D9E6222D}) (Version: - Microsoft) Usenet.nl (HKLM-x32\...\Usenet.nl_is1) (Version: - ) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.) VLC media player 2.1.0 (HKLM-x32\...\VLC media player) (Version: 2.1.0 - VideoLAN) Welcome Home To Windows Phone Version 2.0 (HKLM-x32\...\{4B5EBB2A-A55C-40E9-A48F-AEBFBAA90EC1}_is1) (Version: 2.0 - ) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Sync (HKLM-x32\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation) Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) Windows Phone app for desktop (HKLM-x32\...\{19773614-FC22-4ACC-AAA3-E6BDA81ACF92}) (Version: 1.1.2726.0 - Microsoft Corporation) Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia) WinRAR 5.00 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) YTD Video Downloader 4.0 (HKLM-x32\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.0 - GreenTree Applications SRL) ==================== Restore Points ========================= 09-03-2014 19:57:45 Windows-Sicherung 13-03-2014 21:48:47 Windows Update 13-03-2014 23:12:51 Windows Update 14-03-2014 08:25:34 Windows Update 16-03-2014 19:46:45 Windows-Sicherung 17-03-2014 22:21:58 Windows Update 23-03-2014 18:00:21 Windows-Sicherung 30-03-2014 18:13:33 Windows-Sicherung 04-04-2014 22:09:15 Installed SpyHunter 05-04-2014 06:29:17 Removed SpyHunter 07-04-2014 05:46:26 Windows-Sicherung 08-04-2014 21:10:33 Installed Windows Phone app for desktop ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-03-28 22:37 - 00002676 ____A C:\Windows\system32\Drivers\etc\hosts 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de There are 16 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {084C9023-C4A7-4FF3-AC7B-6DD84D7E3F8F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {1790A716-CE1A-400C-A0F4-691BBA163103} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-03-21] (Hewlett-Packard) Task: {279B66BC-725F-4DD9-8E70-48F6DC9D57F7} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-23] () Task: {3B35629C-4734-47CB-8F43-965CC631670F} - System32\Tasks\ServicePlan => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-23] () Task: {515FE178-4D0C-4794-AD74-D406592B788D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-12-12] (Hewlett-Packard Company) Task: {5DD226C6-5D9F-4C8F-9EE9-9DBFE719B87D} - System32\Tasks\HPCeeScheduleForstudentin mama => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05] (Hewlett-Packard) Task: {6C768DA6-4B42-42E4-AB1C-61431C712A8B} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe [2010-06-24] (CyberLink) Task: {6CCC4DF5-B34D-4EE5-9CB4-7FC8F60576DD} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe Task: {70AAF0CA-45FA-4555-97CA-0C3C48B42415} - System32\Tasks\RunAsStdUser Task for VeohWebPlayer => C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe <==== ATTENTION Task: {71906D7C-D3F3-4602-8E27-BFF3A331D87D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {77E4D3A2-5FE6-49D7-AE63-4605C32FAD15} - System32\Tasks\{2803D596-E189-426E-830F-D9729361D990} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.114/de/abandoninstall?page=tsProgressBar Task: {86FD4AF1-FE07-45E5-B7E8-1FCEE2AB8E8D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {A5622CED-0E8F-469A-A502-D665DC62DE9D} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\Communicator.exe [2013-04-22] () Task: {A7F5448C-DB93-4167-AF41-27EDC213AF63} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {BA793CA6-9407-45A2-AA1A-CD3DD810E037} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-26] (Google Inc.) Task: {C4D720E6-5B65-4B8C-91D7-22D95A4175F0} - System32\Tasks\{565485B0-CE07-4A43-8ADE-E590F93FC96D} => C:\Program Files (x86)\Windows Phone\WindowsPhone.exe [2014-03-26] (Microsoft Corporation) Task: {D5830753-8EB7-4505-8DBA-181401A67B2C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: {EF1AFC9F-1B9A-46C4-A996-A26D6A5EE20E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-26] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\Communicator.exe Task: C:\Windows\Tasks\HPCeeScheduleForstudentin mama.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Loaded Modules (whitelisted) ============= 2013-04-19 16:52 - 2008-06-04 15:53 - 00027648 _____ () C:\Windows\System32\spd__l6.dll 2010-06-29 19:00 - 2010-06-29 19:00 - 00027192 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe 2013-04-19 16:53 - 2009-02-04 18:55 - 00548864 _____ () C:\Windows\Samsung\PanelMgr\SSMMgr.exe 2013-08-29 02:23 - 2013-08-29 02:23 - 01861968 _____ () C:\PROGRAM FILES (X86)\DIVX\DIVX UPDATE\DIVXUPDATE.EXE 2013-04-19 16:53 - 2008-07-22 10:00 - 00306688 _____ () C:\Windows\Samsung\PanelMgr\caller64.exe 2010-03-09 15:34 - 2010-03-09 15:34 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2011-03-10 02:06 - 2011-03-10 02:06 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2010-06-18 16:26 - 2010-06-18 16:26 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll 2010-06-18 16:26 - 2010-06-18 16:26 - 00030264 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_LogicLayer.dll 2010-06-18 16:26 - 2010-06-18 16:26 - 00052280 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HardwareAccess.dll 2013-12-13 00:36 - 2013-12-13 00:36 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll 2013-09-13 20:51 - 2013-09-13 20:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-09-13 20:51 - 2013-09-13 20:51 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2010-05-19 11:05 - 2010-05-19 11:05 - 02121728 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll 2010-05-19 11:05 - 2010-05-19 11:05 - 07745536 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll 2010-05-19 11:05 - 2010-05-19 11:05 - 00135168 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00019456 _____ () C:\Program Files (x86)\MyTomTom 3\DeviceDetection.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00067576 _____ () C:\Program Files (x86)\MyTomTom 3\TomTomSupporterBase.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 02302464 _____ () C:\Program Files (x86)\MyTomTom 3\QtCore4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00252408 _____ () C:\Program Files (x86)\MyTomTom 3\TomTomSupporterProxy.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00980480 _____ () C:\Program Files (x86)\MyTomTom 3\QtNetwork4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00357888 _____ () C:\Program Files (x86)\MyTomTom 3\QtXml4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 07964160 _____ () C:\Program Files (x86)\MyTomTom 3\QtGui4.dll 2013-08-29 02:23 - 2013-08-29 02:23 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 2013-08-29 02:25 - 2013-08-29 02:25 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2014-03-29 20:33 - 2014-03-29 20:33 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\studentin mama\Downloads\StudiSoft_ Bestaetigung der Bestellung 0-00001349.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: RM-892|Nokia Lumia 925 Description: RM-892|Nokia Lumia 925 Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: RM-892|Nokia Lumia 925 Description: RM-892|Nokia Lumia 925 Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (04/10/2014 00:34:35 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/09/2014 11:30:08 PM) (Source: Application Hang) (User: ) Description: Programm FRST64.EXE, Version 3.3.10.2 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 12e8 Startzeit: 01cf543ab63667d9 Endzeit: 6 Anwendungspfad: C:\USERS\STUDENTIN MAMA\DOWNLOADS\FRST64.EXE Berichts-ID: Error: (04/09/2014 10:24:24 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 13369 Error: (04/09/2014 10:24:24 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 13369 Error: (04/09/2014 10:24:24 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/09/2014 10:24:23 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 12371 Error: (04/09/2014 10:24:23 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 12371 Error: (04/09/2014 10:24:23 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/09/2014 10:24:20 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 10124 Error: (04/09/2014 10:24:20 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 10124 System errors: ============= Error: (04/10/2014 00:37:57 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/09/2014 08:18:57 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/09/2014 08:18:57 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SW-Sustainer erreicht. Error: (04/09/2014 10:18:13 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/09/2014 10:18:13 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SW-Sustainer erreicht. Error: (04/08/2014 09:17:51 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/08/2014 09:17:51 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SW-Sustainer erreicht. Error: (04/08/2014 05:55:42 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/08/2014 05:55:42 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SW-Sustainer erreicht. Error: (04/08/2014 10:08:56 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Microsoft Office Sessions: ========================= Error: (04/10/2014 00:34:35 AM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\studentin mama\Downloads\esetsmartinstaller_enu.exe Error: (04/09/2014 11:30:08 PM) (Source: Application Hang)(User: ) Description: FRST64.EXE3.3.10.212e801cf543ab63667d96C:\USERS\STUDENTIN MAMA\DOWNLOADS\FRST64.EXE Error: (04/09/2014 10:24:24 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 13369 Error: (04/09/2014 10:24:24 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 13369 Error: (04/09/2014 10:24:24 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/09/2014 10:24:23 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 12371 Error: (04/09/2014 10:24:23 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 12371 Error: (04/09/2014 10:24:23 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/09/2014 10:24:20 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 10124 Error: (04/09/2014 10:24:20 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 10124 ==================== Memory info =========================== Percentage of memory in use: 44% Total physical RAM: 3834.9 MB Available physical RAM: 2138.51 MB Total Pagefile: 7667.98 MB Available Pagefile: 5737.51 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:576.02 GB) (Free:443.57 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:19.86 GB) (Free:2.89 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 596 GB) (Disk ID: 7C5910A0) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=576 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=20 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=103 MB) - (Type=0C) ==================== End Of Log ============================ |
10.04.2014, 09:40 | #8 |
Ruhe in Frieden † 2019 | zilliontoolkitusa.info versehentlich installiert - was nun? Hallo abimama, beantworte mir bitte noch die Frage nach zilliontoolkit. Ist es noch da? Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\ProgramData\8fba3f8d18b65f94 Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Downloade Dir bitte Malwarebytes Anti-Malware
Schritt 3 Da der Scan mit Eset sehr gründlich ist, kann er unter Umständen mehrere Stunden dauern ESET Online Scanner
Schritt 4 Starte noch einmal FRST.
|
10.04.2014, 15:31 | #9 |
| zilliontoolkitusa.info versehentlich installiert - was nun? achso, also ich weiß gar nicht, wo ich schauen kann, ob es noch da ist. Allerdings sind diese Werbepop-ups von Coupon... aller Art noch da und die sind erst nach der versehentlichen Installation von zillion... aufgetaucht. Sorry! Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014 Ran by studentin mama at 2014-04-10 14:10:12 Run:2 Running from C:\Users\studentin mama\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\ProgramData\8fba3f8d18b65f94 ***************** C:\ProgramData\8fba3f8d18b65f94 => Moved successfully. ==== End of Fixlog ==== Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 10.04.2014 Suchlauf-Zeit: 16:18:45 Logdatei: mbam.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.10.04 Rootkit Datenbank: v2014.03.27.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: studentin mama Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 337161 Verstrichene Zeit: 2 Std, 4 Min, 33 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 1 PUP.Optional.Somoto.A, C:\Users\studentin mama\Local Settings\Application Data\Bundled software uninstaller\biclient.exe, In Quarantäne, [ec14c937a759a060f93661b060a111ef], Physische Sektoren: 0 (No malicious items detected) (end) |
10.04.2014, 21:30 | #10 |
Ruhe in Frieden † 2019 | zilliontoolkitusa.info versehentlich installiert - was nun? So seh ich da nichts mehr in den Logs, sind alle Browser betroffen? Schritt 1 Downloade Dir bitte AdwCleaner auf deinen Desktop.
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden. Bitte lade Junkware Removal Tool auf Deinen Desktop.
Schritt 3 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\Gast\AppData\Local\Temp\*.dll C:\Users\Gast\AppData\Local\Temp\*.exe C:\Users\Kinder\AppData\Local\Temp\*.dll C:\Users\Kinder\AppData\Local\Temp\*.exe Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
|
11.04.2014, 05:57 | #11 |
| zilliontoolkitusa.info versehentlich installiert - was nun? hallo, ich werde erst wieder am Dienstag online sein, da ich gerade umziehe. Ich werde bis dahin die Sache mit Eset fertig kriegen, hoffe ich. Lieber Gruß abimama |
12.04.2014, 20:33 | #13 |
| zilliontoolkitusa.info versehentlich installiert - was nun?Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a1f5d95c2216544fb18c8e08c476d302 # engine=17835 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-10 10:03:42 # local_time=2014-04-11 12:03:42 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 17510714 148797272 0 0 # scanned=171405 # found=11 # cleaned=0 # scan_time=26255 sh=FDF652F803592E6840E076A89A19BF655686B8A8 ft=1 fh=de76e936397b25d2 vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setupx.dll.vir" sh=DCA031CCCD3513AF593688567E9A3F756E5077A9 ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-0507.DI trojan" ac=I fn="C:\Users\Gast\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\24dfd73e-66316722" sh=CA1E4D93CD990D7DFCA2DF924DAF7A80EF843936 ft=1 fh=7bc484465cd05020 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B0PZCN4F\laP2[1].exe" sh=3B2C90B0A0AF44B405D746E437ACBE2DA1E5E741 ft=1 fh=d0e8a9f046f91a20 vn="Win32/TrojanDownloader.Agent.AFD trojan" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C287NNXV\agup[1].exe" sh=E9E7EA2050CFA72869A01CFB9FAF114017EF7B3D ft=1 fh=533e37724d6c2993 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C287NNXV\g7k[1].exe" sh=606855FE0D4B22E39AFAEA7DB624E047226766C8 ft=1 fh=2f9b5bcf22757698 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C287NNXV\jP[1].exe" sh=4429F11FA3C7C6E412513C7C98A3378BF10726DF ft=1 fh=3542d40051fae3a3 vn="Win32/SpeedingUpMyPC.I application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E53KL4MD\OptimizerPro[1].exe" sh=8FBA22A5E4AA86D5CA80F41581E2760E6BBBACD9 ft=1 fh=c8344a20fb6fafb4 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E53KL4MD\TczzWYPZ3n[1].exe" sh=70A353D429725AF6A0FC4D8281463FB1532D874A ft=1 fh=7f1080b46eaed078 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N4DT5K2C\N[1].exe" sh=A87B7647DC34B5B6186209377786E946B677C574 ft=1 fh=c2834f18f25710d9 vn="multiple threats" ac=I fn="C:\Users\studentin mama\AppData\Local\Temp\{54F4A8AF-B61B-4054-956C-468B169B64BA}\setup.exe" sh=B7850E1015E19B1C857A15BD431F7DB04284BA9D ft=1 fh=7c08556eb62c5e16 vn="multiple threats" ac=I fn="C:\Users\studentin mama\AppData\Local\Temp\{8E4403EA-594F-4FA4-9C86-F601CEA292B9}\setup.exe" ESETSmartInstaller@High as downloader log: Can not read file from internet.ESETSmartInstaller@High as downloader log: Can not read file from internet.ESETSmartInstaller@High as downloader log: Can not read file from internet.ESETSmartInstaller@High as downloader log: Can not read file from internet.# version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a1f5d95c2216544fb18c8e08c476d302 # engine=17859 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-12 04:15:24 # local_time=2014-04-12 06:15:24 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 17662616 148949174 0 0 # scanned=242265 # found=11 # cleaned=0 # scan_time=19508 sh=FDF652F803592E6840E076A89A19BF655686B8A8 ft=1 fh=de76e936397b25d2 vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setupx.dll.vir" sh=DCA031CCCD3513AF593688567E9A3F756E5077A9 ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-0507.DI trojan" ac=I fn="C:\Users\Gast\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\24dfd73e-66316722" sh=CA1E4D93CD990D7DFCA2DF924DAF7A80EF843936 ft=1 fh=7bc484465cd05020 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B0PZCN4F\laP2[1].exe" sh=3B2C90B0A0AF44B405D746E437ACBE2DA1E5E741 ft=1 fh=d0e8a9f046f91a20 vn="Win32/TrojanDownloader.Agent.AFD trojan" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C287NNXV\agup[1].exe" sh=E9E7EA2050CFA72869A01CFB9FAF114017EF7B3D ft=1 fh=533e37724d6c2993 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C287NNXV\g7k[1].exe" sh=606855FE0D4B22E39AFAEA7DB624E047226766C8 ft=1 fh=2f9b5bcf22757698 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C287NNXV\jP[1].exe" sh=4429F11FA3C7C6E412513C7C98A3378BF10726DF ft=1 fh=3542d40051fae3a3 vn="Win32/SpeedingUpMyPC.I application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E53KL4MD\OptimizerPro[1].exe" sh=8FBA22A5E4AA86D5CA80F41581E2760E6BBBACD9 ft=1 fh=c8344a20fb6fafb4 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E53KL4MD\TczzWYPZ3n[1].exe" sh=70A353D429725AF6A0FC4D8281463FB1532D874A ft=1 fh=7f1080b46eaed078 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N4DT5K2C\N[1].exe" sh=A87B7647DC34B5B6186209377786E946B677C574 ft=1 fh=c2834f18f25710d9 vn="multiple threats" ac=I fn="C:\Users\studentin mama\AppData\Local\Temp\{54F4A8AF-B61B-4054-956C-468B169B64BA}\setup.exe" sh=B7850E1015E19B1C857A15BD431F7DB04284BA9D ft=1 fh=7c08556eb62c5e16 vn="multiple threats" ac=I fn="C:\Users\studentin mama\AppData\Local\Temp\{8E4403EA-594F-4FA4-9C86-F601CEA292B9}\setup.exe" FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-04-2014 01 Ran by studentin mama (administrator) on STUDENTINMAMA on 12-04-2014 18:41:03 Running from C:\Users\studentin mama\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Hewlett-Packard) C:\Windows\system32\Hpservice.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (AMD) C:\Windows\system32\atieclxx.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe () C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (TomTom) C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe () C:\Windows\Samsung\PanelMgr\SSMMgr.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Easybits) C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe () C:\Windows\Samsung\PanelMgr\caller64.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (CyberLink) C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\system32\msiexec.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2281256 2011-10-30] (Synaptics Incorporated) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-06-09] (IDT, Inc.) HKLM\...\Run: [HPWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-06-18] (Hewlett-Packard Company) HKLM\...\Run: [SpywareTerminatorShield] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe HKLM\...\Run: [SpywareTerminatorUpdater] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-04-16] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [602168 2010-06-29] (Hewlett-Packard Company) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe HKLM-x32\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [548864 2009-02-04] () HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] () HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKLM-x32\...\Run: [Magic Desktop for HP notification] - C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1258504 2013-12-30] (Easybits) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707472 2013-12-13] (Cisco Systems, Inc.) HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-04-08] (Hewlett-Packard) HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2010-05-19] (Hewlett-Packard Company) HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [MyTomTomSA.exe] - C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe [434168 2012-05-18] (TomTom) HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [EPSON Stylus DX5000 Series] - C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIBVE.EXE [139264 2006-09-22] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Policies\system: [DisableChangePassword] 0 HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\MountPoints2: G - G:\pushinst.exe HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\MountPoints2: {2c95361d-2ce3-11e1-9892-f1a06df124b6} - G:\Setup.exe AppInit_DLLs: C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL => C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL File Not Found Startup: C:\Users\studentin mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4 SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {19089719-9401-4468-AE0B-8104E8D0D9EF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM - {654B965E-3DF5-6EBF-25F2-16047A3CEE0A} URL = SearchScopes: HKLM - {E81CDADA-1F06-414B-A58F-396B22D1CAFD} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM-x32 - {19089719-9401-4468-AE0B-8104E8D0D9EF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM-x32 - {E81CDADA-1F06-414B-A58F-396B22D1CAFD} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKCU - {19089719-9401-4468-AE0B-8104E8D0D9EF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKCU - {E81CDADA-1F06-414B-A58F-396B22D1CAFD} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {538793D5-659C-4639-A56C-A179AD87ED44} Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.137.1 FireFox: ======== FF ProfilePath: C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 - C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: YoutubeAdblocker - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\mriqu@dpfrjfc.com [2014-04-02] FF Extension: WEB.DE MailCheck - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\toolbar@web.de.xpi [2013-11-25] FF Extension: Adblock Plus - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-09-24] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-03-29] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-03-29] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-03-29] FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-04-27] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR Extension: (No Name) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\gladcbhcbkdeddbidiblppadjdjalidb [2012-11-17] CHR Extension: (SNT) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\jipdpdgjdgibngmaockoaenedejjnkgk [2014-04-02] CHR Extension: (tinyFilter) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlfgnnlnfbpcammlnibfkplpnbbbdeli [2014-04-02] CHR Extension: (YoutubeAdblocker) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\olodkgeocddnmkokdmamjnjdkdijnkgm [2014-04-02] ==================== Services (Whitelisted) ================= R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE [102400 2006-04-18] (SEIKO EPSON CORPORATION) R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [27192 2010-06-29] () R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151744 2014-01-11] (IObit) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) ==================== Drivers (Whitelisted) ==================== R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-12] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52080 2013-12-13] (Cisco Systems, Inc.) S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-12 18:37 - 2014-04-12 18:40 - 02157568 _____ (Farbar) C:\Users\studentin mama\Downloads\FRST64.exe 2014-04-10 16:44 - 2014-04-10 16:44 - 02347384 _____ (ESET) C:\Users\studentin mama\Downloads\esetsmartinstaller_enu(1).exe 2014-04-10 16:29 - 2014-04-10 16:29 - 00001306 _____ () C:\Users\studentin mama\Desktop\mbam.txt 2014-04-10 14:11 - 2014-04-10 14:11 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-09 21:46 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 21:46 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 21:46 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 21:46 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 21:46 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 21:46 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 21:46 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 21:46 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 21:46 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 21:46 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 21:46 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 21:46 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 21:46 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 21:46 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 21:46 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-09 21:46 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 21:46 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 21:46 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 21:46 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 21:46 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-09 21:45 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-09 10:43 - 2014-04-09 10:43 - 00046375 _____ () C:\Users\studentin mama\Desktop\FRST_09-04-2014_10-43-38.txt 2014-04-09 10:43 - 2014-04-09 10:43 - 00043264 _____ () C:\Users\studentin mama\Desktop\Addition.txt 2014-04-09 10:41 - 2014-04-10 00:45 - 00045602 _____ () C:\Users\studentin mama\Downloads\Addition.txt 2014-04-09 10:39 - 2014-04-12 18:41 - 00020050 _____ () C:\Users\studentin mama\Downloads\FRST.txt 2014-04-09 10:38 - 2014-04-12 18:41 - 00000000 ____D () C:\FRST 2014-04-07 13:55 - 2014-04-07 14:04 - 10995296 _____ (Deutsche Telekom AG, Marmiko IT-Solutions GmbH ) C:\Users\studentin mama\Downloads\netzmanager_setup.exe 2014-04-05 22:42 - 2014-04-05 22:42 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000(1).exe 2014-04-05 22:27 - 2014-04-05 22:27 - 02347384 _____ (ESET) C:\Users\studentin mama\Downloads\esetsmartinstaller_enu.exe 2014-04-05 08:36 - 2014-04-05 08:36 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-04-05 08:30 - 2014-04-05 08:30 - 05049344 _____ (Crawler.com ) C:\Users\studentin mama\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2014-04-04 23:56 - 2014-04-04 23:57 - 00613200 _____ (Chip Digital GmbH) C:\Users\studentin mama\Downloads\AdwCleaner - CHIP-Downloader.exe 2014-04-04 23:07 - 2014-04-12 18:01 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-04 23:06 - 2014-04-10 14:12 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-04 23:06 - 2014-04-10 14:12 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-04 23:06 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-04 23:06 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-04 23:06 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-04 23:05 - 2014-04-04 23:06 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000.exe 2014-04-04 23:00 - 2014-04-04 23:04 - 00001420 _____ () C:\Users\studentin mama\Desktop\Rkill.txt 2014-04-04 22:59 - 2014-04-04 22:59 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\studentin mama\Downloads\wObiA.exe 2014-04-04 16:16 - 2014-04-04 16:20 - 00000000 ____D () C:\Users\studentin mama\Desktop\Documents\KWB 2014 2014-04-03 21:35 - 2014-04-04 16:08 - 00012603 _____ () C:\Users\studentin mama\Desktop\Documents\Bewertungsbögen Spezialaufgabe KWB 2014.xlsx 2014-04-02 20:02 - 2014-04-02 20:02 - 12400098 _____ () C:\Users\studentin mama\Desktop\Die Machtergreifung in Würzburg 1933, PDF.zip 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Packages 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator 2014-04-02 20:00 - 2014-04-02 20:02 - 00000000 ____D () C:\ProgramData\InstallMate 2014-03-29 20:33 - 2014-03-29 20:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-13 23:53 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-13 23:53 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-13 23:53 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-13 23:53 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-13 23:53 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-13 23:53 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-13 23:53 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-13 23:53 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-13 23:53 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-13 23:53 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-13 23:53 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-13 23:53 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-13 23:53 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-13 23:53 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-13 23:53 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-13 23:53 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-13 23:53 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-13 23:53 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-13 23:53 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-13 23:53 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-13 23:53 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-13 23:53 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-13 23:53 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-13 23:53 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-13 23:53 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-13 23:53 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-13 23:53 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-13 23:53 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-13 23:53 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-13 23:53 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-13 23:53 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-13 23:53 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-13 23:53 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-13 23:53 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-13 23:53 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-13 23:53 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-13 23:53 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-13 23:53 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-13 23:53 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-13 23:52 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-13 23:52 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-13 23:52 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-13 23:52 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-13 23:52 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll ==================== One Month Modified Files and Folders ======= 2014-04-12 18:41 - 2014-04-09 10:39 - 00020050 _____ () C:\Users\studentin mama\Downloads\FRST.txt 2014-04-12 18:41 - 2014-04-09 10:38 - 00000000 ____D () C:\FRST 2014-04-12 18:40 - 2014-04-12 18:37 - 02157568 _____ (Farbar) C:\Users\studentin mama\Downloads\FRST64.exe 2014-04-12 18:01 - 2014-04-04 23:07 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-12 17:57 - 2013-05-28 01:13 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-12 17:54 - 2011-10-31 17:48 - 00000356 _____ () C:\Windows\Tasks\HP Photo Creations Communicator.job 2014-04-12 17:43 - 2012-02-26 15:04 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-12 17:41 - 2011-03-10 02:07 - 01198799 _____ () C:\Windows\WindowsUpdate.log 2014-04-12 12:16 - 2009-07-14 06:45 - 00023024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-12 12:16 - 2009-07-14 06:45 - 00023024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-12 12:10 - 2012-02-26 15:04 - 00001122 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-12 12:09 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-12 12:08 - 2013-09-24 08:09 - 00029272 _____ () C:\Windows\setupact.log 2014-04-11 22:00 - 2013-01-09 20:35 - 00003986 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{D3FEFDA5-19CA-46DA-9710-E509D83A4478} 2014-04-11 06:31 - 2014-01-11 23:00 - 00000000 ____D () C:\ProgramData\ProductData 2014-04-10 16:44 - 2014-04-10 16:44 - 02347384 _____ (ESET) C:\Users\studentin mama\Downloads\esetsmartinstaller_enu(1).exe 2014-04-10 16:38 - 2013-09-24 08:09 - 01358410 _____ () C:\Windows\PFRO.log 2014-04-10 16:29 - 2014-04-10 16:29 - 00001306 _____ () C:\Users\studentin mama\Desktop\mbam.txt 2014-04-10 16:20 - 2013-06-14 10:08 - 00000000 ___HD () C:\Windows\msdownld.tmp 2014-04-10 14:12 - 2014-04-04 23:06 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-10 14:12 - 2014-04-04 23:06 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-10 14:11 - 2014-04-10 14:11 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-10 07:18 - 2011-10-20 06:57 - 00000000 ____D () C:\Users\studentin mama\Desktop\Studium Lehramt an Gymnasien Deutsch und Geschichte 2014-04-10 01:00 - 2011-10-04 14:15 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-10 00:58 - 2013-09-25 21:32 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 00:54 - 2011-10-17 22:46 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-10 00:45 - 2014-04-09 10:41 - 00045602 _____ () C:\Users\studentin mama\Downloads\Addition.txt 2014-04-10 00:38 - 2014-01-29 20:56 - 00000008 __RSH () C:\ProgramData\ntuser.pol 2014-04-10 00:37 - 2014-02-13 17:40 - 00000368 _____ () C:\Windows\Tasks\HPCeeScheduleForstudentin mama.job 2014-04-10 00:35 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-04-09 20:30 - 2014-02-13 17:40 - 00003240 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForstudentin mama 2014-04-09 20:30 - 2011-11-09 22:07 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-04-09 20:30 - 2011-10-05 12:45 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-04-09 10:43 - 2014-04-09 10:43 - 00046375 _____ () C:\Users\studentin mama\Desktop\FRST_09-04-2014_10-43-38.txt 2014-04-09 10:43 - 2014-04-09 10:43 - 00043264 _____ () C:\Users\studentin mama\Desktop\Addition.txt 2014-04-08 23:12 - 2013-06-14 08:24 - 00000000 ____D () C:\Program Files (x86)\Windows Phone 2014-04-08 02:35 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-04-07 14:04 - 2014-04-07 13:55 - 10995296 _____ (Deutsche Telekom AG, Marmiko IT-Solutions GmbH ) C:\Users\studentin mama\Downloads\netzmanager_setup.exe 2014-04-07 07:40 - 2010-07-31 19:11 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-04-07 07:40 - 2010-07-31 19:11 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-04-07 07:40 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-05 22:42 - 2014-04-05 22:42 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000(1).exe 2014-04-05 22:27 - 2014-04-05 22:27 - 02347384 _____ (ESET) C:\Users\studentin mama\Downloads\esetsmartinstaller_enu.exe 2014-04-05 08:36 - 2014-04-05 08:36 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-04-05 08:30 - 2014-04-05 08:30 - 05049344 _____ (Crawler.com ) C:\Users\studentin mama\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2014-04-05 08:30 - 2011-10-07 23:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\CrashDumps 2014-04-05 00:02 - 2011-10-04 14:15 - 00000000 ____D () C:\Windows\SHELLNEW 2014-04-05 00:01 - 2013-09-22 13:51 - 00000000 ____D () C:\AdwCleaner 2014-04-04 23:57 - 2014-04-04 23:56 - 00613200 _____ (Chip Digital GmbH) C:\Users\studentin mama\Downloads\AdwCleaner - CHIP-Downloader.exe 2014-04-04 23:06 - 2014-04-04 23:05 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000.exe 2014-04-04 23:06 - 2012-10-08 11:49 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-04 23:04 - 2014-04-04 23:00 - 00001420 _____ () C:\Users\studentin mama\Desktop\Rkill.txt 2014-04-04 22:59 - 2014-04-04 22:59 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\studentin mama\Downloads\wObiA.exe 2014-04-04 16:20 - 2014-04-04 16:16 - 00000000 ____D () C:\Users\studentin mama\Desktop\Documents\KWB 2014 2014-04-04 16:08 - 2014-04-03 21:35 - 00012603 _____ () C:\Users\studentin mama\Desktop\Documents\Bewertungsbögen Spezialaufgabe KWB 2014.xlsx 2014-04-03 09:51 - 2014-04-04 23:06 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-04 23:06 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-04 23:06 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-02 20:02 - 2014-04-02 20:02 - 12400098 _____ () C:\Users\studentin mama\Desktop\Die Machtergreifung in Würzburg 1933, PDF.zip 2014-04-02 20:02 - 2014-04-02 20:00 - 00000000 ____D () C:\ProgramData\InstallMate 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Packages 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator 2014-04-02 20:01 - 2012-02-26 15:04 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Google 2014-03-31 07:02 - 2013-09-24 08:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-31 03:16 - 2014-04-09 21:46 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-09 21:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-09 21:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-09 21:46 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-30 09:57 - 2014-02-15 10:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak 2014-03-29 20:33 - 2014-03-29 20:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-28 23:38 - 2012-02-26 15:04 - 00004122 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-28 23:38 - 2012-02-26 15:04 - 00003870 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-22 12:02 - 2013-06-16 17:42 - 00000000 ____D () C:\ProgramData\Origin 2014-03-22 12:01 - 2013-06-16 17:41 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-03-15 22:51 - 2014-02-27 22:02 - 00000000 ____D () C:\Program Files (x86)\MediaViewV1 2014-03-14 16:50 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-03-14 10:36 - 2009-07-14 06:45 - 00397528 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-14 00:23 - 2012-08-25 16:29 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-14 00:23 - 2012-08-25 16:29 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight Some content of TEMP: ==================== C:\Users\Gast\AppData\Local\Temp\AskSLib.dll C:\Users\Gast\AppData\Local\Temp\DivXSetup.exe C:\Users\Gast\AppData\Local\Temp\drm_dyndata_7400009.dll C:\Users\Kinder\AppData\Local\Temp\AskSLib.dll C:\Users\Kinder\AppData\Local\Temp\DivXSetup.exe C:\Users\Kinder\AppData\Local\Temp\drm_dyndata_7400009.dll C:\Users\Kinder\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Kinder\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 21:16 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-04-2014 01 Ran by studentin mama at 2014-04-12 18:42:39 Running from C:\Users\studentin mama\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.9.0.1030 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.9.0.1030 - Adobe Systems Incorporated) Hidden Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Adobe Shockwave Player 11.5 (HKLM-x32\...\{9ECF7817-DB11-4FBA-9DF1-296A578D513A}) (Version: 11.5.7.609 - Adobe Systems, Inc) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.) AMD USB Filter Driver (x32 Version: 1.0.15.94 - Advanced Micro Devices, Inc.) Hidden Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros) ATI Catalyst Install Manager (HKLM\...\{11A4D79B-672C-7FFF-B5F7-B4409B1194EF}) (Version: 3.0.765.0 - ATI Technologies, Inc.) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Core Implementation (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Full New (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Light (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center InstallProxy (x32 Version: 2010.0416.541.8279 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2010.0416.541.8279 - ATI) Hidden CCC Help Chinese Standard (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Chinese Traditional (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Czech (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Danish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Dutch (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help English (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Finnish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help French (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help German (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Greek (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Hungarian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Italian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Japanese (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Korean (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Norwegian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Polish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Portuguese (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Russian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Spanish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Swedish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Thai (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Turkish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden ccc-core-static (x32 Version: 2010.0416.541.8279 - Ihr Firmenname) Hidden ccc-utility64 (Version: 2010.0416.541.8279 - ATI) Hidden Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.05152 - Cisco Systems, Inc.) Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.05152 - Cisco Systems, Inc.) Hidden CyberLink DVD Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.3003 - CyberLink Corp.) CyberLink DVD Suite (x32 Version: 7.0.3003 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5971CA1F-6BDE-498F-952C-9F2BF94070A4}) (Version: - Microsoft) Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts) Diercke Globus Online (HKLM-x32\...\Diercke Globus Online) (Version: 3.1.0 - Imagon GmbH) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.90 - DivX, LLC) DVD Menu Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}) (Version: 4.1.4121 - Hewlett-Packard) DVD Menu Pack for HP MediaSmart Video (x32 Version: 4.1.4121 - Hewlett-Packard) Hidden EPSON File Manager (HKLM-x32\...\{D02F30FB-0BC4-419A-9B9C-ADC610029B50}) (Version: 1.3.2.0 - ) EPSON Scan Assistant (HKLM-x32\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - ) EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version: - SEIKO EPSON Corporation) ESU for Microsoft Windows 7 (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard) Free YouTube to MP3 Converter version 3.11.35.1031 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.35.1031 - DVDVideoSoft Ltd.) Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Customer Experience Enhancements (x32 Version: 6.0.1.4 - Hewlett-Packard) Hidden HP Documentation (HKLM-x32\...\{E5AE53A7-1A79-4840-998F-A18042A2F568}) (Version: 1.1.1.0 - Hewlett-Packard) HP MediaSmart Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 4.1.3024 - Hewlett-Packard) HP MediaSmart Webcam (x32 Version: 4.1.3024 - Hewlett-Packard) Hidden HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.12412 - HP Photo Creations Powered by RocketLife) HP Photosmart Plus B210 series - Grundlegende Software für das Gerät (HKLM\...\{7578548C-6F40-4CBE-B5CF-9310E66557FA}) (Version: 22.50.231.0 - Hewlett-Packard Co.) HP Photosmart Plus B210 series Hilfe (HKLM-x32\...\{7F5FDEA1-D0AC-4D80-9D95-59775FCCFA40}) (Version: 140.0.54.54 - Hewlett Packard) HP Power Manager (HKLM-x32\...\{4B156358-CE9C-4E9F-8CAD-79AE86A68C60}) (Version: 1.0.3 - Hewlett-Packard Company) HP Quick Launch (HKLM-x32\...\{E342D296-DB9D-4FC7-ACB0-39926C0BFA16}) (Version: 2.1.5 - Hewlett-Packard Company) HP Setup (HKLM-x32\...\{72D90DB3-A16A-4545-B555-868471101833}) (Version: 8.1.4186.3400 - Hewlett-Packard) HP Software Framework (HKLM-x32\...\{B446137B-18A1-4FAE-B0E4-ABE8F09705F1}) (Version: 4.1.6.1 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company) HP Update (HKLM-x32\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard) HP Wireless Assistant (HKLM\...\{E342EC6B-5F25-47FE-B92C-DE616149B430}) (Version: 4.0.9.0 - Hewlett-Packard) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6288.0 - IDT) IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 3.0.4.922 - IObit) iTunes (HKLM\...\{D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0}) (Version: 11.1.3.8 - Apple Inc.) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden LightScribe System Software (HKLM-x32\...\{46BA053F-57B3-4153-BDB6-D37EEC8B12D7}) (Version: 1.18.15.1 - LightScribe) Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) MarkSpace Outlook Server Version 1.0 (HKLM-x32\...\{050F5BE0-A8F6-48E1-9815-97322C1C1DC5}_is1) (Version: 1.0 - Mark/Space, Inc.) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1 - Nokia) Hidden Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1 - Nokia) Hidden Movie Theme Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}) (Version: 4.1.4030 - Hewlett-Packard) Movie Theme Pack for HP MediaSmart Video (x32 Version: 4.1.4030 - Hewlett-Packard) Hidden Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MyTomTom 3.2.0.700 (HKLM-x32\...\MyTomTom) (Version: 3.2.0.700 - TomTom) Nokia Connectivity Cable Driver (HKLM-x32\...\{29373274-977E-413C-A4DE-DC0F8E80C429}) (Version: 7.1.172.0 - Nokia) OpenTTD 1.1.5 (HKLM-x32\...\OpenTTD) (Version: 1.1.5 - OpenTTD) Origin (HKLM-x32\...\Origin) (Version: 9.0.14.2148 - Electronic Arts, Inc.) PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia) PDF Architect (HKLM-x32\...\{064A929A-4DE8-40CF-A901-BD40C14E4D25}) (Version: 1.1.83.9982 - pdfforge GmbH) PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.0 - pdfforge) Photo to Movie 5.0 (HKLM-x32\...\{FA166F42-B86E-437A-9AC3-87FCC351973C}) (Version: 5.0.704 - LQ Graphics, Inc.) PhotoPad Foto-Editor (HKLM-x32\...\PhotoPad) (Version: - NCH Software) PhotoScape (HKLM-x32\...\PhotoScape) (Version: - ) Pixillion Imagedatei-Konverter (HKLM-x32\...\Pixillion) (Version: - NCH Software) PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3003 - CyberLink Corp.) PowerDirector (x32 Version: 8.0.3003 - CyberLink Corp.) Hidden QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.11.1127.2009 - Realtek) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30113 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.3023 - CyberLink Corp.) Hidden RuntimeLibsVC90 (HKLM-x32\...\{F000DE4C-B6CB-4181-BAFF-EC5DA2A9C156}) (Version: 1.1.0 - Microsoft) Samsung Universal Print Driver (HKLM-x32\...\Samsung Universal Print Driver) (Version: - Samsung Electronics CO.,LTD) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) StreamTransport version: 1.0.2.2171 (HKLM-x32\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version: - ) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden SW-Sustainer 1.80 (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}) (Version: - Certified Publisher) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.1.6.64 - Synaptics Incorporated) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{799005D3-9B70-4219-AFE0-BC479614CC4D}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft) Usenet.nl (HKLM-x32\...\Usenet.nl_is1) (Version: - ) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.) VLC media player 2.1.0 (HKLM-x32\...\VLC media player) (Version: 2.1.0 - VideoLAN) Welcome Home To Windows Phone Version 2.0 (HKLM-x32\...\{4B5EBB2A-A55C-40E9-A48F-AEBFBAA90EC1}_is1) (Version: 2.0 - ) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Sync (HKLM-x32\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation) Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) Windows Phone app for desktop (HKLM-x32\...\{19773614-FC22-4ACC-AAA3-E6BDA81ACF92}) (Version: 1.1.2726.0 - Microsoft Corporation) Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia) WinRAR 5.00 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) YTD Video Downloader 4.0 (HKLM-x32\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.0 - GreenTree Applications SRL) ==================== Restore Points ========================= 13-03-2014 23:12:51 Windows Update 14-03-2014 08:25:34 Windows Update 16-03-2014 19:46:45 Windows-Sicherung 17-03-2014 22:21:58 Windows Update 23-03-2014 18:00:21 Windows-Sicherung 30-03-2014 18:13:33 Windows-Sicherung 04-04-2014 22:09:15 Installed SpyHunter 05-04-2014 06:29:17 Removed SpyHunter 07-04-2014 05:46:26 Windows-Sicherung 08-04-2014 21:10:33 Installed Windows Phone app for desktop 09-04-2014 22:52:10 Windows Update 12-04-2014 16:34:58 Removed MSXML 4.0 SP3 Parser (KB2758694) ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-03-28 22:37 - 00002676 ____A C:\Windows\system32\Drivers\etc\hosts 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de There are 16 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {084C9023-C4A7-4FF3-AC7B-6DD84D7E3F8F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {1790A716-CE1A-400C-A0F4-691BBA163103} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-03-21] (Hewlett-Packard) Task: {279B66BC-725F-4DD9-8E70-48F6DC9D57F7} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-23] () Task: {3B35629C-4734-47CB-8F43-965CC631670F} - System32\Tasks\ServicePlan => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-23] () Task: {515FE178-4D0C-4794-AD74-D406592B788D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-12-12] (Hewlett-Packard Company) Task: {5DD226C6-5D9F-4C8F-9EE9-9DBFE719B87D} - System32\Tasks\HPCeeScheduleForstudentin mama => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05] (Hewlett-Packard) Task: {6C768DA6-4B42-42E4-AB1C-61431C712A8B} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe [2010-06-24] (CyberLink) Task: {6CCC4DF5-B34D-4EE5-9CB4-7FC8F60576DD} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe Task: {70AAF0CA-45FA-4555-97CA-0C3C48B42415} - System32\Tasks\RunAsStdUser Task for VeohWebPlayer => C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe <==== ATTENTION Task: {71906D7C-D3F3-4602-8E27-BFF3A331D87D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {77E4D3A2-5FE6-49D7-AE63-4605C32FAD15} - System32\Tasks\{2803D596-E189-426E-830F-D9729361D990} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.114/de/abandoninstall?page=tsProgressBar Task: {86FD4AF1-FE07-45E5-B7E8-1FCEE2AB8E8D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {A5622CED-0E8F-469A-A502-D665DC62DE9D} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\Communicator.exe [2013-04-22] () Task: {A7F5448C-DB93-4167-AF41-27EDC213AF63} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {BA793CA6-9407-45A2-AA1A-CD3DD810E037} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-26] (Google Inc.) Task: {C4D720E6-5B65-4B8C-91D7-22D95A4175F0} - System32\Tasks\{565485B0-CE07-4A43-8ADE-E590F93FC96D} => C:\Program Files (x86)\Windows Phone\WindowsPhone.exe [2014-03-26] (Microsoft Corporation) Task: {D5830753-8EB7-4505-8DBA-181401A67B2C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: {EF1AFC9F-1B9A-46C4-A996-A26D6A5EE20E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-26] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\Communicator.exe Task: C:\Windows\Tasks\HPCeeScheduleForstudentin mama.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Loaded Modules (whitelisted) ============= 2013-04-19 16:52 - 2008-06-04 15:53 - 00027648 _____ () C:\Windows\System32\spd__l6.dll 2010-06-29 19:00 - 2010-06-29 19:00 - 00027192 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe 2013-04-19 16:53 - 2009-02-04 18:55 - 00548864 _____ () C:\Windows\Samsung\PanelMgr\SSMMgr.exe 2013-08-29 02:23 - 2013-08-29 02:23 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 2013-04-19 16:53 - 2008-07-22 10:00 - 00306688 _____ () C:\Windows\Samsung\PanelMgr\caller64.exe 2010-03-09 15:34 - 2010-03-09 15:34 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2011-03-10 02:06 - 2011-03-10 02:06 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2010-06-18 16:26 - 2010-06-18 16:26 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll 2010-06-18 16:26 - 2010-06-18 16:26 - 00030264 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_LogicLayer.dll 2010-06-18 16:26 - 2010-06-18 16:26 - 00052280 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HardwareAccess.dll 2013-12-13 00:36 - 2013-12-13 00:36 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll 2013-09-13 20:51 - 2013-09-13 20:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-09-13 20:51 - 2013-09-13 20:51 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2010-05-19 11:05 - 2010-05-19 11:05 - 02121728 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll 2010-05-19 11:05 - 2010-05-19 11:05 - 07745536 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll 2010-05-19 11:05 - 2010-05-19 11:05 - 00135168 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00019456 _____ () C:\Program Files (x86)\MyTomTom 3\DeviceDetection.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00067576 _____ () C:\Program Files (x86)\MyTomTom 3\TomTomSupporterBase.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 02302464 _____ () C:\Program Files (x86)\MyTomTom 3\QtCore4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00252408 _____ () C:\Program Files (x86)\MyTomTom 3\TomTomSupporterProxy.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00980480 _____ () C:\Program Files (x86)\MyTomTom 3\QtNetwork4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00357888 _____ () C:\Program Files (x86)\MyTomTom 3\QtXml4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 07964160 _____ () C:\Program Files (x86)\MyTomTom 3\QtGui4.dll 2013-08-29 02:25 - 2013-08-29 02:25 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2014-03-29 20:33 - 2014-03-29 20:33 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\studentin mama\Downloads\StudiSoft_ Bestaetigung der Bestellung 0-00001349.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (04/12/2014 06:21:33 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/12/2014 00:18:18 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/12/2014 00:18:12 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/11/2014 08:37:50 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 659370 Error: (04/11/2014 08:37:50 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 659370 Error: (04/11/2014 08:37:50 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/11/2014 06:59:11 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/11/2014 06:59:03 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/11/2014 06:56:59 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/10/2014 09:59:03 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 21840 System errors: ============= Error: (04/12/2014 00:09:13 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/11/2014 11:56:44 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (04/11/2014 10:06:48 PM) (Source: WMPNetworkSvc) (User: ) Description: 0x80004004-1 Error: (04/11/2014 08:37:51 PM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (04/11/2014 08:37:48 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst IPBusEnum erreicht. Error: (04/11/2014 06:52:41 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/11/2014 06:30:04 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/10/2014 10:30:24 PM) (Source: WMPNetworkSvc) (User: ) Description: 0x80004004-1 Error: (04/10/2014 10:30:24 PM) (Source: WMPNetworkSvc) (User: ) Description: 0x80004004-1 Error: (04/10/2014 04:39:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Microsoft Office Sessions: ========================= Error: (04/12/2014 06:21:33 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (04/12/2014 00:18:18 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\studentin mama\Downloads\esetsmartinstaller_enu(1).exe Error: (04/12/2014 00:18:12 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\studentin mama\Downloads\esetsmartinstaller_enu(1).exe Error: (04/11/2014 08:37:50 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 659370 Error: (04/11/2014 08:37:50 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 659370 Error: (04/11/2014 08:37:50 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/11/2014 06:59:11 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\studentin mama\Downloads\esetsmartinstaller_enu(1).exe Error: (04/11/2014 06:59:03 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\studentin mama\Downloads\esetsmartinstaller_enu(1).exe Error: (04/11/2014 06:56:59 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\studentin mama\Downloads\esetsmartinstaller_enu(1).exe Error: (04/10/2014 09:59:03 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 21840 ==================== Memory info =========================== Percentage of memory in use: 54% Total physical RAM: 3834.9 MB Available physical RAM: 1733.86 MB Total Pagefile: 7667.98 MB Available Pagefile: 5418.89 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:576.02 GB) (Free:442.88 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:19.86 GB) (Free:2.89 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 596 GB) (Disk ID: 7C5910A0) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=576 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=20 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=103 MB) - (Type=0C) ==================== End Of Log ============================ Code:
ATTFilter # AdwCleaner v3.023 - Bericht erstellt am 12/04/2014 um 18:54:48 # Aktualisiert 01/04/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : studentin mama - STUDENTINMAMA # Gestartet von : C:\Users\studentin mama\Downloads\adwcleaner(1).exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gelöscht : C:\Windows\System32\Tasks\ProtectedSearch ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B} ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 -\\ Mozilla Firefox v28.0 (de) [ Datei : C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\prefs.js ] Zeile gelöscht : user_pref("extensions.3Abd.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumoro[...] Zeile gelöscht : user_pref("extensions.uzAWXR.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumo[...] Zeile gelöscht : user_pref("extensions.vEWkc.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumor[...] [ Datei : C:\Users\Kinder\AppData\Roaming\Mozilla\Firefox\Profiles\4p3g7r0l.default\prefs.js ] [ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\pen71xce.default\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [40059 octets] - [22/09/2013 13:51:27] AdwCleaner[R1].txt - [21700 octets] - [24/09/2013 13:19:07] AdwCleaner[R2].txt - [2224 octets] - [12/04/2014 18:50:02] AdwCleaner[S0].txt - [36277 octets] - [22/09/2013 13:53:19] AdwCleaner[S1].txt - [21032 octets] - [24/09/2013 13:21:06] AdwCleaner[S2].txt - [2145 octets] - [12/04/2014 18:54:48] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2205 octets] ########## |
13.04.2014, 10:56 | #14 |
| zilliontoolkitusa.info versehentlich installiert - was nun?Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by studentin mama on 12.04.2014 at 21:37:20,78 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1183461899-3623103710-1707053119-1001\Software\sweetim Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011501160} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011501160} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E81CDADA-1F06-414B-A58F-396B22D1CAFD} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{E81CDADA-1F06-414B-A58F-396B22D1CAFD} ~~~ Files Successfully deleted: [File] "C:\Users\studentin mama\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\driverscanner.lnk" ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\ytd video downloader" Successfully deleted: [Folder] "C:\Users\studentin mama\appdata\locallow\datamngr" Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader" Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{02A0E2FD-A310-4EB1-A0DB-07E258CAAB0F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{038E352E-EFED-4562-B97F-9CD13A2ABC8C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{0459E172-8264-402D-A4B1-5FAC3844274D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{08BB199F-F43E-445D-A2D1-FFE13603EA1C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{0AA19462-F4EE-41CD-81E9-8A82D6495F40} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{0BBE864E-7E95-4B59-8E1D-8C946D21CF60} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{0E55CCEF-862F-4E35-8C38-46067900A56D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{0EC19D43-26BE-4839-9A69-D89AA53E0745} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{0F66DD41-50AD-45EE-B7F6-00AEAC990859} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{0FBE695B-07E6-4CC1-8224-73A1D01E4654} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{115B93AE-D4C7-4CE9-ACDD-889F06292755} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{124C58BF-BCA3-4A32-92D9-8ACA4AE04837} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{12BF63A4-0B7E-4EBA-997B-99419DFE0816} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{12DB6CBB-5F41-41CD-93D1-F81D1C3AD6AE} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{137CB873-9C52-41DC-A7CD-80CD0B9525E3} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{13AEFA96-D383-4BAE-94C2-3668C69A857C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{14193BA7-9F61-418F-AE3C-9A73B89BEAC6} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{14298F3E-DCEA-42BD-B4F0-8AB1B8D88246} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{145FA6F7-574A-4D08-B397-88D941C9C51A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{14D14741-B2E9-4F84-A743-618B15EB3D3F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{154488A0-16F5-46B2-BA18-D5594CC6E3BB} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{158C76A5-C728-4DD6-97C3-96594401667F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{15D9E4AE-BF26-409C-AE28-30370CE7F873} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1663ED33-550A-40D3-86CF-1A39AB2C6B69} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1809A831-FA33-4F9D-8830-8F9CE85273FA} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1844DCFC-B4C9-404B-B6E1-D5E7A3A56F1E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{19D8068A-356B-47C2-A0B8-133075653A17} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1A262435-1415-41F8-8A21-B6732B761425} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1B24C57E-5C33-47D4-80EF-F9B37AE47A36} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1BCF7838-7C43-4BDC-B6D5-67C073C0728C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1CFA2F24-0EDF-4F24-A495-FD216AAC40FE} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1D3BA977-7F5A-4DAC-B9FC-728C704B5DD0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2002B22C-BD3F-4ADE-B78F-91975215B45C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2077872F-9C35-4149-BFA0-9D653E4FA5F4} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{21C31B97-01F3-41A9-81CC-03057152A7D9} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{223D7EEF-4ECB-402D-8CBF-DE13621491B8} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{22CC8BA1-B7D6-4878-97A3-38A7AB353509} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{22CDA7E1-7129-480F-B038-94C24B71F34C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{22E4537F-3466-4202-8499-3C0670BB088A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{23B5B82D-E260-4C4F-BADF-EAAA770402F8} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{254F2DE0-F6F5-4450-AF64-14D85DD6585E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{25659C91-7858-48DE-817C-847391CD4A9A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{274D4365-B6DB-4B1B-9DB0-071785E7345A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2A046954-44ED-418A-93AB-1766F926D4C4} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2AC54E9B-6B5B-4A43-9B28-22476D93E88B} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2B4A4A9A-F8BD-4932-92AB-CFF9E3623FE5} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2B7EE89F-63CD-4D04-955F-DF4E6329A0C8} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2EA98E38-F89B-4139-8D02-5CFB3B7968F0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2EBD99FA-4483-4646-8A5D-1CB855957ACA} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{31001556-9167-4283-BDAF-F07686B72613} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{327F59A6-A909-4143-8826-5A26D6AC0A5C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{330AE5B8-3049-4B8C-9557-EBCB9FC5160D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{33C55794-13A3-4631-B163-B495D15AE4B0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{33D258DB-820C-43C1-82D6-FFAA98CE334A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{34C19671-09C4-46AE-8DB8-DBAC1017B506} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{35ACE5E6-7CE7-45F9-BBDA-7D0769DF7ABF} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{36582EFF-9905-49B3-B222-B15121ADDD6F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{38812673-0E74-40A2-B161-D419B04D58F6} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{3A3F9720-D3FC-459A-B602-14C5BE39E721} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{3B8CD7E5-F96F-41F7-BCCC-D19C4E946A14} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{3D0230D6-E83F-4D29-A20D-B42C5FF7C665} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{3DFF0888-4201-4B12-A0F6-D73435939B9B} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{3E9389C5-B4CB-4C01-B347-A21B00CEB235} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{407ECB6F-9715-4292-A68E-EC14CD7E48EB} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{4113995C-829C-4486-B56E-0F53C1364E8E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{44A6E5FC-1AA0-4B53-9C87-FB562484E267} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{45B08BB4-C984-4C09-84EE-263768CF0541} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{46414FE2-4EFA-4601-A0C1-542E27367C84} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{46DDB271-1251-4BD3-82B0-8D971D83F3C5} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{49546540-E605-4BD4-9FBF-47AD9FCC5604} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{49C16653-4443-4A9B-BFCF-AB87B51B71CB} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{4B5247BF-6523-4218-B892-05B4C86423A0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{4C49CE8F-38AE-454C-B4F5-FCCE284CB015} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{4DEFFDBE-1AE3-4C3F-9D79-2D35B88DFD83} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{50387911-095A-4EFC-AE43-7164F7FABBD1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{506F2D8D-94B3-4E69-83B1-59B7B591E3FC} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5122E9B6-E1E9-4931-A1D5-26F83E1022FB} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{52B0D05F-F06B-4C55-AA97-F8730DBB88BF} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{52C45D17-89F4-465B-96F1-FBB0BC949ABC} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{52DEB93C-28A1-4A1C-A9EE-F7F8C76B86A2} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{52ED5A83-6385-4822-9FA3-FF9A3DF14720} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5566D6C1-3058-41AD-A7B5-F6D12D37D9B0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{55D17FCD-59F0-46F1-90F7-85F31231ADCB} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{565BD5A8-EAED-4522-9AFC-F2E1FD68A250} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{580D68A1-965E-4189-A03D-EF22EC847AEE} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{58C6B8CC-B0DF-4947-9CA2-EE5E4E6F032B} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5A480E58-A1E5-4E43-8994-1D5279CCF09F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5B56935D-C196-4519-859D-078D6AAF6242} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5B7553B0-0574-4200-A858-DB1364057AE3} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5C71CDE5-BA88-4CD0-B23F-665FB922CFED} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5E3A47FB-7C22-40DF-8E79-26C5AFCA1961} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5E6B9490-737A-4E0F-B72D-ADC40C4BC65F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5EC4FF61-C9C8-4AB0-AB7B-4D806936D7CD} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5F8A15DB-FF6E-45CC-9F37-3323BBA6D49A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5FC4C0D4-9C25-4573-B0A4-FB4C817F0BB3} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{60A3B26E-00A4-4042-B044-124A06D39CB0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{629B7CBA-CEDF-4AC0-8883-8ED642971DC8} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{639B705E-D174-4841-B77C-C90970F29A16} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6796CB4F-C2F8-473C-8C5F-19C078AF0966} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6A31ECAB-E935-45D1-AE22-9A53263BF020} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6A9C5F5E-049F-4143-B4F2-BE5BB1998A6A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6AE66D5E-148B-4C9A-9AD9-FB67DC4487B8} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6B9FDA6C-258E-4CEE-A0CC-20293BB7C0E2} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6BC8C02A-DFEB-4635-BE28-B11708A66DAD} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6BDE077C-9A68-401E-A811-61B90590B687} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6C00FB44-BC3D-4BEC-9529-AD39E2BD48D9} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6C3A5C48-D0F0-414A-B9AF-0DEB35003616} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6D5FBFA2-737E-45FC-B819-746837EF742D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6E44101C-4ED1-4BE5-9614-8BA815E4524A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6E6DBAD1-46DA-4C73-96D3-0F2F087B8521} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6E964D5B-CF32-4836-B598-EE75AFF6B598} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6F07E6FB-A92D-4F0D-BAC2-CC825154CB46} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7191B4E7-AB25-49AE-9DC6-4A331A866206} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{71C51E57-B346-4C08-B4D2-FD335157D788} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{728C6A12-7B95-4D69-8106-B7053556DB32} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{73263724-E0D0-4B35-ADFC-A6BE6107587C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{736F297C-8746-44EC-85B1-22F3B9F46D9E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{73769986-53CB-4B9A-BC5D-693C903743EC} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{748A3FD6-DA69-42E2-BFBB-FEDFED0C13B1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{74AA5D76-0EC3-4637-B7E6-120F4EA2B824} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{74BBC947-ACFB-4CDC-9989-690F10A87BA2} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{754D9B32-2248-473B-A73E-C0120280F572} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{75727CA4-BFC0-4FA6-AC98-D9C6D2059C8D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{75B05ECE-E789-4594-BC3B-5EBA3D1BAE1A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{76ADDD4F-0825-4146-9149-69022CA1CA6C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{76C0292A-B588-4D12-B082-5F25046F4E6F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7A7F0878-F329-4E8D-9102-9006C9F0B744} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7AAFD400-7F61-494C-AB23-EBA50B26C224} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7ABE28A7-3AC7-4BBC-9784-5CDD884D6522} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7ADE89F6-F720-4125-9F3A-0E9E3B11783B} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7B2AA8F2-3D67-43BD-AB4A-6B9A56923FFC} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7CA82CFF-D981-43A2-A364-B75170DCA2F1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7CB7C89A-B1E5-464E-990C-F493784205B3} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7D6903CA-0425-43DD-8650-1CA1579EF048} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7DB602D4-9062-4122-AE5C-723BAF695EE9} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7E31A761-892A-4C59-962F-8A6CC19FD6CD} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7E894F2F-78DC-47EC-9F4C-A8C9F757B71C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{803AB659-4DEA-4887-A9B8-DB55EE2ED92F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{80D9608E-97F3-4E0E-8C48-6C362EA5BEF1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{80FE4996-7969-4AE2-8666-F65DB2B276A0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{81485EF3-68CE-43B8-8911-4D012856839F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{821573C8-0871-4837-9B7A-A4D0817B5267} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{8226F4A4-2F5C-44BA-80CF-C79BE4801CFE} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{82C5F99B-D5B4-4368-B33D-28911247A16F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{84C00263-8699-490D-A4DA-CA2BAC6880DD} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{85F8B740-30FD-4EAF-AFA3-BBA3EA2AAB6F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{86B6A188-7D8C-4D44-B407-0701619C1055} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{87BCC59D-CCB3-41EE-A013-9377CFDE5F25} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{87E1EF1D-A9F4-4168-8CC5-33D176F1195C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{88115DB5-01AC-4FF3-B31B-FB79DE72E0A4} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{88BC7322-5DC2-4C67-A4F4-F290BEF1982F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{8BCC869A-C323-458B-9953-C3C79E153184} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{8C3F52D3-4559-4C42-9E8F-F7476B6715A9} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{8FEBEFCA-3232-439A-87F9-62BCEBBAA968} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{91DCF8C3-4631-483E-9E6B-2DFCBFCCE68E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{953D727A-C101-497C-AC50-24E09E797F94} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{9557C4CB-EC45-4951-8177-F504C7FA4C2E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{991A6FF8-90C4-4F50-B2C7-D7E5432B7A22} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{9AAC90E4-43E4-4333-93E4-E761F5A4FC25} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{9AB525C4-9D32-4F61-98E0-BA063D96FA94} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{9AD7A3AB-A716-4D2E-938A-8F648157464A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{9BFBCB0B-0F7B-4C87-81C1-E1F8BC5AEF03} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{9DEDA339-B889-47AE-8B8A-568B0A285AAE} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{9FE94E91-5057-42C7-B96A-F13D83033D78} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A0DAC39B-C5BF-4BA5-AFBE-17D5770CF505} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A1F104E4-FBF4-4965-A9D3-BA1740DAC031} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A247E458-54E5-4272-A219-FBA50267A102} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A3E0D435-B2DB-499F-B1B6-9DDC3D2D0E4D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A589CD22-F599-4F81-85F7-4CF53B56097A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A5DF7341-AA00-48CC-9AB8-7221E3835E52} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A67328F8-4208-4FEA-9321-29787BA1339B} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A7B5E627-55A0-4211-B858-C3C2B549F016} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A85A055A-F017-4319-BA17-B9CACB38E3CA} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{AB1BEFA7-B565-49C2-9435-321DEF704E81} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{AB41E802-1C4C-48AD-B482-953835BAC953} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{AC3F2F35-0173-4484-BA1D-A0721A760977} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{AE99CF63-F540-41DB-9324-73366D4A1701} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{AEF90276-7783-4CA8-B726-DDA709E4D9A3} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{AFA9614B-EA8B-47C4-B1D5-EDB135D776A5} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B0E55AC7-268A-4C3D-9179-CC75F5B25C23} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B1282970-6AFF-47A8-91A6-9E926E2657C5} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B2C75DF7-46E8-4078-A69E-FD1A44113D97} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B2EEFE88-BC64-4B38-AC83-39640755BC47} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B3069F9F-1731-4CA0-833C-7545CADA13A6} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B484F107-E67A-4874-AEE4-9A20DA0C01ED} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B4BC29A8-C84F-4383-9A32-EF4095B62C3B} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B6C5887D-F2EB-4F22-8514-A43DB64AC68B} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B74AA794-0632-4398-B88B-61CD5515AFE4} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B8442B68-A350-4AB7-BCD2-2382C340B826} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B900F55F-5987-490E-9AE8-EF3AE57EF89C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B92F3265-DE88-49FC-B184-8B02A330991C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B9918CFD-5E70-44A9-917D-69063B9A6A4D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{BC7747C9-15F9-4321-B1A7-F920DDF233E1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{BC7ACC2F-A2C7-47DC-B322-ABE91B6AC213} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{BDAB9038-1824-4A19-A97D-34A740C34B54} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{BED48F10-DEBA-431F-A5C4-E91D8E6ABC53} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{BEE49CD9-0450-497B-AAD4-3B0636297BE7} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C03FA0C9-A9B6-43DD-AC61-79FA9F6F380D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C0F774B2-1EC2-47C3-B5CA-4B3924CF1968} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C1860320-4BC2-4B99-A2C6-F2FC55EB96ED} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C22B5086-4FCF-48E5-9076-986B5940BE46} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C2C35CD3-ECF5-42EF-818D-FBB473EBCF03} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C49B20F0-36A6-436D-BDA7-BEAC94FD15DB} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C4E24861-1FBC-4C65-B9EB-225DF82589B6} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C688C20D-6691-47CB-BAF4-A24A7C560F44} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C74DFEED-C73D-4BAC-B1B3-55734A42C0CF} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C7CA48DA-2F73-4D68-93D2-96C44A3ADB24} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C7DE8EA8-8214-4847-9D45-60AAF555179D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C8DFDBC5-4BE7-4F24-9E23-2C1D25EF3C89} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C923D22B-B996-4125-BFA5-D71F2FB2F295} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C9B3C4B4-875A-401D-A667-2F6F825E3431} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{CC967126-8568-42DC-B734-ED9992CDBA9D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{CCAC6FBE-2349-4852-94AC-CE97248EF43E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{CD44FC9A-7526-4F94-B1FF-89F7E9734A91} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{CD8A824F-5132-497E-B346-0F5010AA78AD} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D0124D1E-5208-4A9E-8446-13D29EE8D7D7} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D15EDB03-9D47-4D90-AB61-D778E1CAE01E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D16A4ABD-6303-4E77-9ABA-9F33AEB59B1F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D255EE71-44F4-4D2B-B9D3-3AA32BE0900A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D2821E09-6000-47CE-AFE4-27F827FE5DD0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D2E979E3-FC3E-4E4A-9A82-58ED89B8ED84} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D3DC96CC-BBA0-42EE-8D8C-C363C1BDF588} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D3FE2AD2-53CF-4E82-B70B-08ED387457C7} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D5510D9F-E135-475A-8AB5-6E8D5CEBD94A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D7002B5B-A424-43CE-8269-7235C73ACC83} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D7ADE70E-4B1F-4E21-B985-563A6B687029} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D81CC346-7B35-476B-80FE-1F687B6B57A8} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D882DF63-3ECC-4065-A349-C3EF5EA07BF6} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D8A634B2-6242-4072-881E-D8B204E8B4A6} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D90C6C0E-5810-401E-A4F9-00E7FB540727} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{DDF05AA6-A609-4593-ABED-604DA996FF6F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{DE8DBC05-9AAD-4EDB-AD0E-160BFA873C07} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{DED6F034-621A-4799-B454-FDA0AF89007F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E126D59D-1C09-46F2-B03D-098C7595E931} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E2489F9E-1D7A-4DFF-B41A-304D73D0D34E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E2871B5F-8575-4324-883F-7B6AB331BC85} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E35496F9-AA69-4BAE-A025-7F734227BDFB} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E3B4A5AD-873D-4C81-A2A1-5F0C13F7FA9C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E4DE8E9F-A924-4E0E-BD81-D0C91F402C9D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E519E993-47BA-470F-8A8D-65610E69C1B5} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E51A4CB6-6961-4C2D-8441-8B37F17315F1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E5F29B34-1747-49B0-A976-45794FEB613C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E71569F7-5188-4DB9-A8F9-EF818F211230} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EA5C46AF-7E1F-45AF-801B-2DA5B0868644} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EA70C13E-B584-4F34-B52E-E72D837D5171} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EAA90C41-BC3D-4FA4-A05C-CAF79B9EA992} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EB39CAE6-81F8-43C6-A61C-D20E55D4B5C5} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EB893632-DE1B-46FF-B555-490CD9DDEEF5} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EC24284C-4D8A-4D27-9473-43C6DAB4EB78} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EC2F779B-88F2-44CE-9966-DED19F640DAF} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{ECD9A9E4-58A2-4C45-BD8F-389A5642A922} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{ED2B2E79-B397-47DE-B549-6BE1DA6ACA3C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{ED2D7ACB-CA41-4F78-A111-B2EE213F1341} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EEC7C8BC-DC28-472E-AA65-CDA79888B227} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EFC00404-CF81-4C59-9C14-1037FD45FA8F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{F0959AE0-BA81-42ED-8409-F3F26C37EF09} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{F1359D8F-C0C3-44EF-B153-664959D148C1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{F5DC86FB-0B74-4065-B9CD-16D2ED8AEDC8} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{F8365730-0C35-4F57-B18D-A6C91F739919} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{F83A9603-589D-4E29-8E91-4EB910089A5D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{F84C2BD8-2347-4D57-8366-F4CDFCF74CF1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{F9892F2E-E098-415F-87C8-208665DA6504} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{FB6B4857-D8BD-4D7B-9974-32A7AAB447DC} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{FDDE9C7D-6631-4C06-A56E-4E21CBAAD39A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{FEA3D5A6-E1F4-4121-B8D5-8AEF5EDB6A91} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{FEB72F40-1E51-451F-ACBE-1E9B98E23F18} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{FF2B0749-5296-46E9-9446-7E162D8F12A0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{FF3C4137-DB0F-467F-B430-5044C15FE7BE} ~~~ FireFox Successfully deleted: [File] C:\user.js Successfully deleted the following from C:\Users\studentin mama\AppData\Roaming\mozilla\firefox\profiles\cknca95t.default\prefs.js user_pref("extensions.3Abd.url", "hxxp://getjpi2.info/sync2/?q=hfZ9ofV9CShEAen0rjn5rihTB6lKDzt4okmxtNtVh7n0rjnEqdaGrjYErjr8tMFHhd9Fqda9rjsFqTw5rHrMDMlGojUMAe4Uojr4qjU9pjg6qHsF Emptied folder: C:\Users\studentin mama\AppData\Roaming\mozilla\firefox\profiles\cknca95t.default\minidumps [153 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 12.04.2014 at 21:59:19,19 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-04-2014 01 Ran by studentin mama at 2014-04-12 22:18:49 Run:3 Running from C:\Users\studentin mama\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\Gast\AppData\Local\Temp\*.dll C:\Users\Gast\AppData\Local\Temp\*.exe C:\Users\Kinder\AppData\Local\Temp\*.dll C:\Users\Kinder\AppData\Local\Temp\*.exe ***************** C:\Users\Gast\AppData\Local\Temp\*.dll => Moved successfully. C:\Users\Gast\AppData\Local\Temp\*.exe => Moved successfully. C:\Users\Kinder\AppData\Local\Temp\*.dll => Moved successfully. C:\Users\Kinder\AppData\Local\Temp\*.exe => Moved successfully. ==== End of Fixlog ==== |
13.04.2014, 20:21 | #15 |
Ruhe in Frieden † 2019 | zilliontoolkitusa.info versehentlich installiert - was nun? Hallo abimama, nach diesem Fix immer noch? Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter FF Extension: YoutubeAdblocker - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\mriqu@dpfrjfc.com [2014-04-02] CHR Extension: (YoutubeAdblocker) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\olodkgeocddnmkokdmamjnjdkdijnkgm [2014-04-02] Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
|
Themen zu zilliontoolkitusa.info versehentlich installiert - was nun? |
artikel, coupondropdown, installier, installiert, interessante, leistung, pup.optional.somoto.a, seite, seiten, spyhunter, spyhunter entfernen, suche, thema, versehentlich, virus, werbe, werbung auf jeder internetseite |