|
Plagegeister aller Art und deren Bekämpfung: TR/BProtector.GenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
27.05.2014, 01:22 | #1 |
| TR/BProtector.Gen Beim durchscannen von Avira wurde mir Dieser "Trojaner" angezeit: TR/BProtector.Gen Daraufhin wollte ich ihn löschen worauf mein Computer Abstürtze u. ich neu starten musste. Hab mir HijackThis heruntergeladen und das versucht. Brachte nichts weiteres.. Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 02:20:00, on 27.05.2014 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v11.0 (11.00.9600.17041) Boot mode: Normal Running processes: C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe C:\Windows\AsScrPro.exe C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe C:\Users\Christof\AppData\Local\Pokki\Engine\pokki.exe C:\Program Files (x86)\Skype\Phone\Skype.exe C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\PROGRA~2\SearchProtect\SearchProtect\bin\cltmng.exe C:\PROGRA~2\SearchProtect\UI\bin\cltmngui.exe C:\Users\Christof\AppData\Local\Pokki\Engine\pokki.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Christof\AppData\Local\Temp\OCS\Downloads\fc14996dfa99adfc7baae624196888c5\7b4e384f5b096b9656fee276ba88bb81\HiJackThis204.exe C:\Windows\SysWOW64\NOTEPAD.EXE C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\SysWOW64\NOTEPAD.EXE C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Christof\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe C:\Windows\SysWOW64\DllHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.at/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - (no file) O2 - BHO: Funmoods Helper Object - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\Program Files (x86)\Funmoods\1.5.23.22\bh\escort.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O2 - BHO: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.10.0\bh\delta.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O2 - BHO: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files (x86)\Softonic\softonic\1.5.11.5\bh\softonic.dll O3 - Toolbar: Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files (x86)\Softonic\softonic\1.5.11.5\softonicTlbr.dll O3 - Toolbar: Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.10.0\deltaTlbr.dll O4 - HKLM\..\Run: [Nuance PDF Reader-reminder] "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini" O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE" O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe /S O4 - HKLM\..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe O4 - HKLM\..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [Google Update] "C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_9DC73BAD139DCCFFA56EA65F10CB0EF3] "C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-window O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver O4 - HKCU\..\Run: [Pokki] C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun O4 - HKCU\..\RunOnce: [Application Restart #3] C:\Users\Christof\AppData\Local\Pokki\Engine\pokki.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend="C:\Users\Christof\AppData\Local\Pokki\Engine\inspector" --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --flag-switches-begin --flag-switches-end --restore-last-session O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-21-2465417766-3482814047-1650821192-1000\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser') O4 - HKUS\S-1-5-21-2465417766-3482814047-1650821192-1000\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser') O4 - HKUS\S-1-5-18\..\RunOnce: [SpUninstallDeleteDir] rmdir /s /q "\SearchProtect" (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [SpUninstallDeleteDir] rmdir /s /q "\SearchProtect" (User 'Default user') O4 - Global Startup: AsusVibeLauncher.lnk = C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Christof\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (file missing) O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\SPVC32~1.DLL O23 - Service: AFBAgent - Unknown owner - C:\Windows\system32\FBAgent.exe (file missing) O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Trend Micro Solution Platform (Amsp) - Trend Micro Inc. - C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe O23 - Service: Avira Planer (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira Echtzeit-Scanner (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Search Protect Service (CltMngSvc) - Client Connect LTD - C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - Unknown owner - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (file missing) O23 - Service: HitmanPro.Alert Service (hmpalertsvc) - SurfRight B.V. - C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe (file missing) O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe O23 - Service: System Store (SystemStoreService) - Unknown owner - C:\Program Files (x86)\SoftwareUpdater\SystemStore.exe O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - Unknown owner - C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (file missing) O23 - Service: Intel(R) Turbo Boost Technology Monitor (TurboBoost) - Intel(R) Corporation - C:\Program Files\Intel\TurboBoost\TurboBoost.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 17912 bytes Kann mir wer helfen?! Und Sorry finde Foren immer unübersichtlich u kapier die nicht. ;D Hoffe jedoch auf eine antwort und Hoffe mein Thema ist hier nicht Falsch?! LG |
27.05.2014, 06:56 | #2 |
/// the machine /// TB-Ausbilder | TR/BProtector.Gen hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
27.05.2014, 16:09 | #3 |
| TR/BProtector.Gen FRST.txt:
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02 Ran by Christof (administrator) on CHRISTOF-PC on 27-05-2014 17:03:42 Running from C:\Users\Christof\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (SurfRight B.V.) C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (ASUS) C:\Windows\AsScrPro.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Pokki) C:\Users\Christof\AppData\Local\Pokki\Engine\pokki.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Client Connect LTD) C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe (Client Connect LTD) C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (Client Connect LTD) C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Pokki) C:\Users\Christof\AppData\Local\Pokki\Engine\pokki.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google) C:\Users\Christof\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe () C:\Users\Christof\AppData\Roaming\BabSolution\Shared\BabMaint.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [VizorHtmlDialog.exe] => C:\Program Files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe [1123664 2010-10-08] (Trend Micro Inc.) HKLM\...\Run: [Trend Micro Client Framework] => C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [192520 2010-10-12] (Trend Micro Inc.) HKLM\...\Run: [Trend Micro Titanium] => C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe [322384 2010-09-17] (Trend Micro Inc.) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-05-17] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2785064 2011-05-05] (Synaptics Incorporated) HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation) HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [97064 2011-05-05] (Synaptics Incorporated) HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" HKLM\...\Run: [Setwallpaper] => c:\programdata\SetWallpaper.cmd HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-03-15] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Nuance PDF Reader-reminder] => C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe [328992 2008-11-03] (Nuance Communications, Inc.) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme) HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] () HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-09] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] - rmdir /s /q "\SearchProtect" HKU\S-1-5-21-2465417766-3482814047-1650821192-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-06] (Acresso Corporation) HKU\S-1-5-21-2465417766-3482814047-1650821192-1001\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-2465417766-3482814047-1650821192-1001\...\Run: [Google Update] => C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-10] (Google Inc.) HKU\S-1-5-21-2465417766-3482814047-1650821192-1001\...\Run: [GoogleChromeAutoLaunch_9DC73BAD139DCCFFA56EA65F10CB0EF3] => C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe [841032 2014-05-08] (Google Inc.) HKU\S-1-5-21-2465417766-3482814047-1650821192-1001\...\Run: [Facebook Update] => C:\Users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-09-28] (Facebook Inc.) HKU\S-1-5-21-2465417766-3482814047-1650821192-1001\...\Run: [Pokki] => C:\Windows\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform HKU\S-1-5-21-2465417766-3482814047-1650821192-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) HKU\S-1-5-21-2465417766-3482814047-1650821192-1001\...\RunOnce: [Application Restart #3] - C:\Users\Christof\AppData\Local\Pokki\Engine\pokki.exe [8252744 2013-11-01] (Pokki) HKU\S-1-5-21-2465417766-3482814047-1650821192-1001\...\MountPoints2: {51c0bea7-226c-11e1-87e4-5404a635c2fa} - G:\AutoRun.exe HKU\S-1-5-21-2465417766-3482814047-1650821192-1001\...\MountPoints2: {58d5eed4-21a1-11e1-be8f-5404a635c2fa} - F:\AutoRun.exe HKU\S-1-5-21-2465417766-3482814047-1650821192-1001\...\MountPoints2: {58d5eee3-21a1-11e1-be8f-5404a635c2fa} - F:\AutoRun.exe HKU\S-1-5-21-2465417766-3482814047-1650821192-1001\...\MountPoints2: {8bf1135b-80ee-11e2-81d5-5404a635c2fa} - F:\HTC_Sync_Manager_PC.exe AppInit_DLLs: c:\progra~2\search~1\search~1\bin\spvc64~2.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [202560 2014-05-14] (Client Connect LTD) AppInit_DLLs: c:\windows\system32\nvinitx.dll => c:\windows\system32\nvinitx.dll [226920 2011-05-10] (NVIDIA Corporation) AppInit_DLLs-x32: C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\SPVC32~1.DLL => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll [171840 2014-05-14] (Client Connect LTD) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.at/ HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://isearch.babylon.com/?babsrc=HP_def_gr2&affID=119776 HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/androidnews/ URLSearchHook: HKLM-x32 - (No Name) - {942cd1d4-9cc1-4d31-876a-ea8f489f7a59} - No File URLSearchHook: HKCU - (No Name) - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - No File SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_def_gr2&affID=119776 SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = SearchScopes: HKCU - {0D7562AE-8EF6-416d-A838-AB665251703A} URL = hxxp://start.facemoods.com/?a=gppc&s={searchTerms}&f=4 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://isearch.babylon.com/?q={searchTerms}&babsrc=SP_def_gr2&affID=119776 SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg.dll (Trend Micro Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: TmBpIeBHO Class - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe64.dll (Trend Micro Inc.) BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll No File BHO-x32: Funmoods Helper Object - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\Program Files (x86)\Funmoods\1.5.23.22\bh\escort.dll (Funmoods BHO) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: delta Helper Object - {C1AF5FA5-852C-4C90-812E-A7F75E011D87} - C:\Program Files (x86)\Delta\delta\1.8.10.0\bh\delta.dll (Delta-search.com) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Softonic Helper Object - {E87806B5-E908-45FD-AF5E-957D83E58E68} - C:\Program Files (x86)\Softonic\softonic\1.5.11.5\bh\softonic.dll (Softonic.com) Toolbar: HKLM-x32 - Softonic Toolbar - {5018CFD2-804D-4C99-9F81-25EAEA2769DE} - C:\Program Files (x86)\Softonic\softonic\1.5.11.5\softonicTlbr.dll (Softonic.com) Toolbar: HKLM-x32 - Delta Toolbar - {82E1477C-B154-48D3-9891-33D83C26BCD3} - C:\Program Files (x86)\Delta\delta\1.8.10.0\deltaTlbr.dll (Delta-search.com) Toolbar: HKCU - No Name - {942CD1D4-9CC1-4D31-876A-EA8F489F7A59} - No File Toolbar: HKCU - No Name - {C95A4E8E-816D-4655-8C79-D736DA1ADB6D} - No File Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.254 FireFox: ======== FF ProfilePath: C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default FF NewTab: user_pref("browser.newtab.url", ""); FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Keyword.URL: hxxp://search.babylon.com/?AF=109992&babsrc=adbartrp&mntrId=dcc9ff5c00000000000078929c45f955&q= FF Homepage: about:home|hxxp://www.giga.de/androidnews/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) FF Plugin HKCU: @greentube.com/GreenWebPlayer - C:\Games\GreenWebPlayer\npgreenwebplayer.dll (Greentube Internet Entertainment Solutions GmbH) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Christof\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Christof\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Christof\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Christof\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Christof\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Christof\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: thehappycloud.com/HappyCloudPlugin - C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud) FF user.js: detected! => C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js FF Plugin ProgramFiles/Appdata: C:\Users\Christof\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google) FF Plugin ProgramFiles/Appdata: C:\Users\Christof\AppData\Roaming\mozilla\plugins\npo1d.dll (Google) FF SearchPlugin: C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\searchplugins\BrowserProtect.xml FF SearchPlugin: C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\searchplugins\delta.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Battlefield Heroes Updater - C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\Extensions\battlefieldheroespatcher@ea.com [2012-02-19] FF Extension: Delta Toolbar - C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\Extensions\ffxtlbr@delta.com [2013-02-21] FF Extension: Funmoods.com - C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\Extensions\ffxtlbr@funmoods.com [2012-12-27] FF Extension: Softonic Toolbar - C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\Extensions\ffxtlbra@softonic.com [2012-02-25] FF Extension: Movie2kDownloader - C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\Extensions\movie2kdownloader@movie2kdownloader.com.xpi [2012-12-13] FF Extension: Hotspot Shield Extension - C:\Program Files (x86)\Mozilla Firefox\extensions\afproxy@anchorfree.com [2014-01-10] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2012-06-25] FF HKLM-x32\...\Firefox\Extensions: [{22C7F6C6-8D67-4534-92B5-529A0EC09405}] - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\firefoxextension\ FF Extension: Trend Micro NSC Firefox Extension - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\firefoxextension\ [] FF HKCU\...\Firefox\Extensions: [{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}] - C:\Users\Christof\AppData\Roaming\13001.027 FF Extension: Java Link Helper - C:\Users\Christof\AppData\Roaming\13001.027 [2012-07-18] Chrome: ======= CHR HomePage: https://www.google.at/ CHR StartupUrls: "https://www.google.at/" CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Christof\AppData\Local\Google\Chrome\Application\34.0.1847.137\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Christof\AppData\Local\Google\Chrome\Application\34.0.1847.137\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Christof\AppData\Local\Google\Chrome\Application\34.0.1847.137\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll No File CHR Plugin: (GreenWebPlayer) - C:\Games\GreenWebPlayer\npgreenwebplayer.dll (Greentube Internet Entertainment Solutions GmbH) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Zeon Plus) - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Users\Christof\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Extension: (Funmoods Chat) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh [2014-02-05] CHR Extension: (YouTube) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-07-10] CHR Extension: (Adblock Plus) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-03-22] CHR Extension: (Google-Suche) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-07-10] CHR Extension: (Dark Vibe) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkckeanhmkjaechlhllmapjaaglgpcbj [2012-07-11] CHR Extension: (Google Wallet) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-27] CHR Extension: (Google Mail) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-07-10] CHR HKLM\...\Chrome\Extension: [bbjciahceamgodcoidkjpchnokgfpphh] - C:\Users\Christof\AppData\Local\funmoods.crx [2012-12-12] CHR HKCU\...\Chrome\Extension: [bbjciahceamgodcoidkjpchnokgfpphh] - C:\Users\Christof\AppData\Local\funmoods.crx [2012-12-12] CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\Christof\AppData\Roaming\DVDVideoSoft\dvsYoutubeDownload.crx [2012-09-15] CHR HKCU\...\Chrome\Extension: [nipcdlfhdehdhmajficeeocjdbdhacdn] - C:\Users\Christof\AppData\Local\CRE\nipcdlfhdehdhmajficeeocjdbdhacdn.crx [2013-04-25] CHR HKLM-x32\...\Chrome\Extension: [bbjciahceamgodcoidkjpchnokgfpphh] - C:\Users\Christof\AppData\Local\funmoods.crx [2012-12-12] CHR HKLM-x32\...\Chrome\Extension: [blaofbhgbmeikidhlkmjhbkbfohpgekf] - C:\Program Files (x86)\Movie2KDownloader.com\Movie2KDownloader10.crx [2012-12-12] CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Christof\AppData\Roaming\Delta\delta.crx [2012-11-25] CHR HKLM-x32\...\Chrome\Extension: [nipcdlfhdehdhmajficeeocjdbdhacdn] - C:\Users\Christof\AppData\Local\CRE\nipcdlfhdehdhmajficeeocjdbdhacdn.crx [2013-04-25] CHR StartMenuInternet: Google Chrome - C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG) R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [2496832 2014-05-14] (Client Connect LTD) R2 hmpalertsvc; C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1876816 2014-04-16] (SurfRight B.V.) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2012-02-04] () S2 SystemStoreService; C:\Program Files (x86)\SoftwareUpdater\SystemStore.exe [297984 2014-04-05] () S4 TiMiniService; C:\Program Files\Trend Micro\Titanium\TiMiniService.exe [241488 2010-09-17] (Trend Micro Inc.) S3 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 [X] S2 Hamachi2Svc; "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s [X] S2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [X] S2 TuneUp.UtilitiesSvc; "C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe" [X] ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-08-22] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-05-09] (Avira Operations GmbH & Co. KG) R2 hmpalert; C:\Windows\system32\drivers\hmpalert.sys [93144 2014-04-16] () R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [44744 2013-11-13] (AnchorFree Inc.) S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114560 2009-07-24] (Huawei Technologies Co., Ltd.) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-08-22] () R2 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [90704 2010-09-17] (Trend Micro Inc.) R2 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [144464 2010-09-17] (Trend Micro Inc.) R2 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [67664 2010-09-17] (Trend Micro Inc.) R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [105552 2010-09-17] (Trend Micro Inc.) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-17] () S3 TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-27 17:03 - 2014-05-27 17:05 - 00030983 _____ () C:\Users\Christof\Downloads\FRST.txt 2014-05-27 17:03 - 2014-05-27 17:03 - 00000000 ____D () C:\FRST 2014-05-27 17:00 - 2014-05-27 17:01 - 02066944 _____ (Farbar) C:\Users\Christof\Downloads\FRST64.exe 2014-05-27 02:03 - 2014-05-27 02:20 - 00017914 _____ () C:\Users\Christof\Documents\hijackthis.log 2014-05-27 01:59 - 2014-05-27 01:59 - 00961360 _____ (Chip Digital GmbH) C:\Users\Christof\Downloads\HijackThis - CHIP-Installer.exe 2014-05-27 01:43 - 2014-05-27 01:43 - 755762801 _____ () C:\Windows\MEMORY.DMP 2014-05-27 01:36 - 2014-05-27 01:36 - 00002072 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-05-27 01:36 - 2014-05-27 01:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-05-27 01:35 - 2014-05-09 11:16 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-05-27 01:35 - 2014-05-09 11:16 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-27 01:35 - 2014-05-09 11:16 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-05-27 01:27 - 2014-05-27 01:33 - 137314600 _____ () C:\Users\Christof\Downloads\avira_free_antivirus_de_642.exe 2014-05-27 01:19 - 2014-05-27 01:19 - 00003420 _____ () C:\Windows\System32\Tasks\BitGuard 2014-05-27 00:56 - 2014-05-27 00:56 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Avira 2014-05-27 00:54 - 2014-05-27 00:54 - 00000000 ____D () C:\ProgramData\Avira 2014-05-27 00:54 - 2014-05-27 00:54 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-05-15 21:46 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 21:46 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-15 21:46 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-15 21:46 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-15 21:46 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 21:46 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-14 22:59 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-14 22:59 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-14 22:59 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-14 22:59 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-14 22:58 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-14 22:58 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-14 22:58 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-14 22:58 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-14 22:58 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-14 22:58 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-14 22:58 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-14 22:58 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-14 22:58 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-14 22:58 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-14 22:58 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-14 22:58 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-14 22:58 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-14 22:58 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-14 22:58 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-14 22:58 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-05-14 22:42 - 2014-05-27 01:43 - 00100342 _____ () C:\Windows\PFRO.log 2014-05-13 00:34 - 2014-05-27 01:43 - 00002296 _____ () C:\Windows\setupact.log 2014-05-13 00:34 - 2014-05-13 00:34 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-07 03:01 - 2014-05-18 03:02 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-30 13:19 - 2014-03-31 09:35 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== One Month Modified Files and Folders ======= 2014-05-27 17:05 - 2014-05-27 17:03 - 00030983 _____ () C:\Users\Christof\Downloads\FRST.txt 2014-05-27 17:03 - 2014-05-27 17:03 - 00000000 ____D () C:\FRST 2014-05-27 17:03 - 2014-02-15 11:03 - 00000304 _____ () C:\Windows\Tasks\Funmoods.job 2014-05-27 17:01 - 2014-05-27 17:00 - 02066944 _____ (Farbar) C:\Users\Christof\Downloads\FRST64.exe 2014-05-27 17:01 - 2011-11-30 14:42 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Skype 2014-05-27 17:01 - 2011-02-19 06:24 - 16519040 _____ () C:\Windows\system32\perfh007.dat 2014-05-27 17:01 - 2011-02-19 06:24 - 05288614 _____ () C:\Windows\system32\perfc007.dat 2014-05-27 17:01 - 2009-07-14 07:13 - 00006780 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-27 16:58 - 2014-02-05 23:08 - 00000304 _____ () C:\Windows\Tasks\Funmoods Chat.job 2014-05-27 16:58 - 2013-05-04 13:39 - 00000000 ____D () C:\Users\Christof\AppData\Local\Pokki 2014-05-27 16:58 - 2012-09-28 17:38 - 00000940 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA.job 2014-05-27 16:58 - 2012-07-10 21:49 - 00001132 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA.job 2014-05-27 16:58 - 2011-11-04 09:14 - 01969740 _____ () C:\Windows\WindowsUpdate.log 2014-05-27 02:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing 2014-05-27 02:20 - 2014-05-27 02:03 - 00017914 _____ () C:\Users\Christof\Documents\hijackthis.log 2014-05-27 01:59 - 2014-05-27 01:59 - 00961360 _____ (Chip Digital GmbH) C:\Users\Christof\Downloads\HijackThis - CHIP-Installer.exe 2014-05-27 01:55 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-27 01:55 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-27 01:43 - 2014-05-27 01:43 - 755762801 _____ () C:\Windows\MEMORY.DMP 2014-05-27 01:43 - 2014-05-14 22:42 - 00100342 _____ () C:\Windows\PFRO.log 2014-05-27 01:43 - 2014-05-13 00:34 - 00002296 _____ () C:\Windows\setupact.log 2014-05-27 01:43 - 2012-04-07 16:42 - 00000000 ____D () C:\Windows\Minidump 2014-05-27 01:43 - 2011-11-30 14:27 - 00045056 _____ () C:\Windows\system32\acovcnt.exe 2014-05-27 01:43 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-27 01:41 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-05-27 01:36 - 2014-05-27 01:36 - 00002072 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-05-27 01:36 - 2014-05-27 01:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-05-27 01:33 - 2014-05-27 01:27 - 137314600 _____ () C:\Users\Christof\Downloads\avira_free_antivirus_de_642.exe 2014-05-27 01:19 - 2014-05-27 01:19 - 00003420 _____ () C:\Windows\System32\Tasks\BitGuard 2014-05-27 01:19 - 2011-11-30 14:26 - 00000000 ____D () C:\Users\Christof 2014-05-27 01:18 - 2012-07-10 21:50 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-05-27 01:18 - 2011-11-04 09:31 - 00000000 ____D () C:\ProgramData\P4G 2014-05-27 01:18 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-05-27 01:17 - 2009-07-14 09:44 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-05-27 01:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-05-27 01:10 - 2012-07-01 21:29 - 00683008 ___SH () C:\Users\Christof\Desktop\Thumbs.db 2014-05-27 00:56 - 2014-05-27 00:56 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Avira 2014-05-27 00:54 - 2014-05-27 00:54 - 00000000 ____D () C:\ProgramData\Avira 2014-05-27 00:54 - 2014-05-27 00:54 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-05-22 18:22 - 2012-09-28 17:38 - 00000918 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core.job 2014-05-22 18:15 - 2012-07-10 21:49 - 00001080 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core.job 2014-05-21 17:39 - 2012-02-18 17:39 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Mozilla 2014-05-21 17:36 - 2014-01-01 23:36 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\.minecraft 2014-05-19 23:29 - 2012-02-19 22:00 - 00000000 ____D () C:\Users\Christof\Documents\VirtualDJ 2014-05-19 18:03 - 2013-05-04 13:41 - 00000000 ____D () C:\Program Files (x86)\SearchProtect 2014-05-18 03:06 - 2011-11-30 14:28 - 00000000 ___RD () C:\Users\Christof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-18 03:06 - 2011-11-30 14:28 - 00000000 ___RD () C:\Users\Christof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-18 03:02 - 2014-05-07 03:01 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-15 21:52 - 2012-07-10 21:50 - 00002382 _____ () C:\Users\Christof\Desktop\Google Chrome.lnk 2014-05-15 21:46 - 2012-02-15 23:30 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-05-13 06:35 - 2013-06-14 13:13 - 00002292 _____ () C:\Users\Christof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Little Alchemy.lnk 2014-05-13 02:43 - 2014-04-16 18:13 - 00000000 ____D () C:\Users\Christof\Desktop\Hamburger City Girls 2014-05-13 02:09 - 2012-09-06 14:33 - 00000000 ____D () C:\Users\Christof\Documents\ANNO 2070 Demo 2014-05-13 02:09 - 2012-08-22 15:02 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Ubisoft 2014-05-13 02:09 - 2011-11-04 09:25 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-05-13 00:34 - 2014-05-13 00:34 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-13 00:18 - 2012-04-04 11:34 - 00000000 ____D () C:\Users\Christof\AppData\Local\LogMeIn Hamachi 2014-05-13 00:05 - 2009-07-29 08:03 - 00000000 ____D () C:\Windows\Panther 2014-05-09 11:16 - 2014-05-27 01:35 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-05-09 11:16 - 2014-05-27 01:35 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-09 11:16 - 2014-05-27 01:35 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-05-09 08:14 - 2014-05-14 22:59 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-09 08:11 - 2014-05-14 22:59 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-07 06:13 - 2012-07-10 21:49 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA 2014-05-07 06:13 - 2012-07-10 21:49 - 00003712 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core 2014-05-06 06:40 - 2014-05-15 21:46 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-06 06:17 - 2014-05-15 21:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-06 05:25 - 2014-05-15 21:46 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-06 05:07 - 2014-05-15 21:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-06 05:00 - 2014-05-15 21:46 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-06 04:10 - 2014-05-15 21:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll Files to move or delete: ==================== C:\ProgramData\23lldnur.pad C:\ProgramData\ras_0oed.pad Some content of TEMP: ==================== C:\Users\Christof\AppData\Local\Temp\avgnt.exe C:\Users\Christof\AppData\Local\Temp\oct8227.tmp.exe C:\Users\Christof\AppData\Local\Temp\octC94D.tmp.exe C:\Users\Christof\AppData\Local\Temp\SPSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-23 01:46 ==================== End Of Log ============================ Addition.txt: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-05-2014 02 Ran by Christof at 2014-05-27 17:05:54 Running from C:\Users\Christof\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Trend Micro Titanium Internet Security (Disabled - Up to date) {68F968AC-2AA0-091D-848C-803E83E35902} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Trend Micro Titanium Internet Security (Disabled - Up to date) {D3988948-0C9A-0693-BE3C-BB4CF86413BF} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft) 3D Pinball from Plus! for Windows 95 (HKLM-x32\...\Pinball) (Version: - ) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.2.0.2070 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.2.0.2070 - Adobe Systems Incorporated) Hidden Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.4.980 - Adobe Systems Incorporated.) Adobe Community Help (x32 Version: 3.4.980 - Adobe Systems Incorporated.) Hidden Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.0.6 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.0.6 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Photoshop CS5.1 (HKLM-x32\...\{9158FF30-78D7-40EF-B83E-451AC5334640}) (Version: 12.1 - Adobe Systems Incorporated) ANNO 1404 (HKLM-x32\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 1.02.0000 - Ubisoft) Anno 1404 (x32 Version: 1.00.0000 - Ubisoft) Hidden Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.12.5.0 - Asmedia Technology) ASUS AI Recovery (HKLM-x32\...\{38253529-D97D-4901-AE53-5CC9736D3A2E}) (Version: 1.0.13 - ASUS) ASUS FancyStart (HKLM-x32\...\{2B81872B-A054-48DA-BE3B-FA5C164C303A}) (Version: 1.0.8 - ASUSTeK Computer Inc.) ASUS K3 Series ScreenSaver (HKLM-x32\...\ASUS K3 Series ScreenSaver) (Version: 1.0.0002 - ASUS) ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.20 - ASUS) ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.0.6 - ASUS) ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.1.43 - ASUS) ASUS SmartLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0011 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0030 - ASUS) ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.21 - asus) ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.84.161 - eCareme Technologies, Inc.) AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.7.146 - ASUSTEK) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0010 - ASUS) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.642 - Avira) Babylon toolbar on IE (HKLM-x32\...\BabylonToolbar) (Version: - ) <==== ATTENTION Battlefield Heroes (HKLM-x32\...\{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}) (Version: - EA Digital illusions) Bing Bar (HKLM-x32\...\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}) (Version: 7.0.610.0 - Microsoft Corporation) BitGuard (HKLM-x32\...\{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}) (Version: - MediaTechSoft Inc.) <==== ATTENTION Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Bookworm Deluxe (HKLM-x32\...\Bookworm Deluxe) (Version: - Oberon Media Inc.) Cinema 4D version R12 (HKLM-x32\...\{7D9D8134-9FA3-4FFF-ADA1-BF609F29997A}_is1) (Version: R12 - Salat Production) Complément Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Complemento Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation) Cooking Dash (HKLM-x32\...\Cooking Dash) (Version: - Oberon Media Inc.) CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1908 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.1908 - CyberLink Corp.) Hidden CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3602c - CyberLink Corp.) CyberLink Power2Go (x32 Version: 6.1.3602c - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Delta Chrome Toolbar (HKLM-x32\...\{177586E7-E42E-4F38-83D1-D15B4AF5B714}) (Version: 1.0.0.0 - DeltaInstaller) <==== ATTENTION Delta toolbar (HKLM-x32\...\delta) (Version: 1.8.10.0 - Delta) <==== ATTENTION Diner Dash 2 (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111212843}) (Version: - Oberon Media) Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited) Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.10 - ASUS) Fiesta Online DE 1.04.095 (HKLM-x32\...\Fiesta Online DE) (Version: 1.04.095 - Gamigo Games) Fiesta Online(EU_German) 1.04.000 (HKLM-x32\...\Fiesta Online(EU_German)) (Version: 1.04.000 - gamigo Games) Free System Utilities (HKLM-x32\...\{ee9b54a6-93dd-4070-80ae-743f58319407}) (Version: 1.0.0 - Covus Freemium GmbH) Free SystemUtilities (x32 Version: 1.0.0 - Covus Freemium GmbH) Hidden Free YouTube to MP3 Converter version 3.12.2.426 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.2.426 - DVDVideoSoft Ltd.) Funmoods (HKLM-x32\...\funmoods) (Version: - ) <==== ATTENTION Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Game Park Console (HKLM-x32\...\{E71E60C1-533E-45A5-8D80-E475E88D2B17}_is1) (Version: 6.2.1.1 - Oberon Media, Inc.) Google Chrome (HKCU\...\Google Chrome) (Version: 34.0.1847.137 - Google Inc.) Google Talk Plugin (HKLM-x32\...\{217CEB43-6D22-3E1F-A311-DC0D7BFEE0A2}) (Version: 5.4.1.18709 - Google) Governor of Poker (HKLM-x32\...\Governor of Poker) (Version: - Oberon Media Inc.) GreenWebPlayer (HKCU\...\gwp-DEFAULT) (Version: - ) <==== ATTENTION Happy Cloud Client (HKCU\...\HappyCloud) (Version: 4.28 - Happy Cloud, Inc.) HitmanPro.Alert (HKLM\...\HitmanPro.Alert) (Version: 2.6.5.77 - SurfRight B.V.) Hotel Dash Suite Success (HKLM-x32\...\Hotel Dash Suite Success) (Version: - Oberon Media Inc.) Hotspot Shield 3.20 (HKLM-x32\...\HotspotShield) (Version: 3.20 - AnchorFree Inc.) InnoGames International Toolbar (HKLM-x32\...\InnoGames_International Toolbar) (Version: 6.8.5.1 - InnoGames International) Intel PROSet Wireless (Version: - ) Hidden Intel PROSet Wireless (x32 Version: - ) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation) Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{3C41721F-AF0F-4086-AA1C-4C7F29076228}) (Version: 14.01.1000 - Intel Corporation) Intel(R) Turbo Boost Technology Monitor (HKLM\...\{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}) (Version: 1.0.400.4 - Intel) iTunes (HKLM\...\{D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0}) (Version: 11.1.3.8 - Apple Inc.) Java 7 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.250 - Oracle) Java Auto Updater (x32 Version: 2.1.9.5 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216031FF}) (Version: 6.0.310 - Oracle) JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) Jewel Quest 3 (HKLM-x32\...\Jewel Quest 3) (Version: - Oberon Media Inc.) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Landwirtschafts Simulator 2013 (HKLM-x32\...\FarmingSimulator2013DE_is1) (Version: 1.0 - GIANTS Software) League of Legends (HKLM-x32\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games) Little Alchemy (HKCU\...\Pokki_faeb52fe0fea61b95b0070adc5264fa86cc0757f) (Version: 0.23.0 - Pokki) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.1.0.294 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.1.0.294 - LogMeIn, Inc.) Hidden Luxor 3 (HKLM-x32\...\Luxor 3) (Version: - Oberon Media Inc.) Mahjongg dimensions (HKLM-x32\...\Mahjongg dimensions) (Version: - Oberon Media Inc.) MaintenanceService-Funmoods (HKCU\...\Funmoods) (Version: - ) <==== ATTENTION Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger 分享元件 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation) Hidden Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Mobile Partner (HKLM-x32\...\Mobile Partner) (Version: 11.300.05.05.47 - Huawei Technologies Co.,Ltd) Movie2KDownloader (HKLM-x32\...\1ClickDownload) (Version: 2.1 Build 26473 - Movie2KDownloader.com) Mozilla Firefox 13.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 13.0.1 (x86 de)) (Version: 13.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 13.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT Redists (x32 Version: 1.0 - Sony Creative Software Inc.) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MySQL Connector/ODBC 5.1 (HKLM-x32\...\{29042B1C-0713-4575-B7CA-5C8E7B0899D4}) (Version: 5.1.5 - MySQL AB) Nuance PDF Reader (HKLM-x32\...\{B480904D-F73F-4673-B034-8A5F492C9184}) (Version: 6.00.0041 - Nuance Communications, Inc.) NVIDIA Control Panel 268.56 (Version: 268.56 - NVIDIA Corporation) Hidden NVIDIA Graphics Driver 268.56 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 268.56 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.265.41.0 - NVIDIA Corporation) Hidden NVIDIA Optimus 1.0.22 (Version: 1.0.22 - NVIDIA Corporation) Hidden NVIDIA Update Components (Version: 1.0.22 - NVIDIA Corporation) Hidden PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.) Plants vs Zombies (HKLM-x32\...\Plants vs Zombies) (Version: - Oberon Media Inc.) Pokki (HKCU\...\Pokki) (Version: 0.266.1.172 - Pokki) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.990 - Even Balance, Inc.) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.38.113.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6373 - Realtek Semiconductor Corp.) Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10001 - Realtek Semiconductor Corp.) Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.13.2.14 - Client Connect LTD) <==== ATTENTION Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.1.10441 - Skype Technologies S.A.) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Softonic toolbar on IE and Chrome (HKLM-x32\...\softonic) (Version: - ) <==== ATTENTION Sonic Focus (HKLM-x32\...\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: 1.0.0.4 - Synopsys ) Stormblade Launcher 1.1 (HKLM-x32\...\{D84EA2B7-F65E-43F3-9FB5-18B2162DBFA2}}_is1) (Version: - Stormblade.org) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.6.0 - Synaptics Incorporated) syncables desktop SE (HKLM-x32\...\{341697D8-9923-445E-B42A-529E5A99CB7A}) (Version: 5.5.746.11492 - syncables) System Requirements Lab for Intel (HKLM-x32\...\{C7CA731B-BF9A-46D9-92CF-8A8737AE9240}) (Version: 4.5.13.0 - Husdawg, LLC) TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.13.1 - TeamSpeak Systems GmbH) TeamViewer 7 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.13989 - TeamViewer) Trend Micro Titanium Internet Security (HKLM\...\{ABBD4BA8-6703-40D2-AB1E-5BB1F7DB49A4}) (Version: 3.0 - Trend Micro Inc.) Trend Micro Titanium Internet Security (Version: 3.00 - Trend Micro Inc.) Hidden TubeBox (HKLM-x32\...\{c5b74464-3a04-417c-9eee-d0dc7d6af196}) (Version: 4.1.0.0 - Freetec) TubeBox (x32 Version: 4.1.0.0 - Freetec) Hidden TubeBox! (HKLM-x32\...\{A78A5C61-2397-407E-A41F-0A0FFAD2572F}) (Version: 3.4.9 - Jens Lorek) TuneUp Utilities 2012 (HKLM-x32\...\TuneUp Utilities 2012) (Version: 12.0.3600.73 - TuneUp Software) TuneUp Utilities 2012 (x32 Version: 12.0.3600.73 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.73 - TuneUp Software) Hidden UltraStar 1.0.2 (HKLM-x32\...\UltraStar) (Version: 1.0.2 - SterGames) Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Funmoods Chat (HKCU\...\Funmoods Chat) (Version: - Update for Funmoods Chat) <==== ATTENTION Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Vegas Pro 10.0 (HKLM-x32\...\{6E0E4D61-11EC-11E0-B454-0013D3D69929}) (Version: 10.0.469 - Sony) Virtual Audio Cable 4.10 (HKLM\...\Virtual Audio Cable 4.10) (Version: - ) VirtualDJ Home FREE (HKLM-x32\...\{A6AC699F-8315-40CA-8F70-E917494978AB}) (Version: 7.4 - Atomix Productions) VirtualDJ PRO Full (HKLM-x32\...\{4769E972-2E92-49C5-B6F9-465EFD0C4D94}) (Version: 7.0.5 - Atomix Productions) VLC media player 2.1.0 (HKLM\...\VLC media player) (Version: 2.1.0 - VideoLAN) War Thunder Launcher 1.0.1.252 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version: - 2013 Gaijin Entertainment Corporation) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.31.0 - ASUS) WinRAR 4.10 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.10.0 - win.rar GmbH) Wireless Console 3 (HKLM-x32\...\{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}) (Version: 3.0.19 - ASUS) World of Goo (HKLM-x32\...\World of Goo) (Version: - Oberon Media Inc.) World of Tanks - Common Test (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812CT}_is1) (Version: - Wargaming.net) World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812}_is1) (Version: - Wargaming.net) Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Компаньон Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2-8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation) גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden מסייע Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (HKLM-x32\...\{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}) (Version: 15.4.5722.2 - Microsoft Corporation) بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\...\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 - Microsoft Corporation) معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden 適用遠端連線的 Windows Live Mesh ActiveX 控制項 (HKLM-x32\...\{622DE1BE-9EDE-49D3-B349-29D64760342A}) (Version: 15.4.5722.2 - Microsoft Corporation) ==================== Restore Points ========================= 03-05-2014 13:35:09 Windows Update 06-05-2014 18:20:48 Windows Update 07-05-2014 01:00:23 Windows Update 10-05-2014 01:15:15 Windows Update 14-05-2014 20:51:16 Windows Update 15-05-2014 19:44:45 Windows Modules Installer 22-05-2014 16:22:50 Windows Update 26-05-2014 23:34:17 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {08B3AC75-315C-4200-B48E-F5487B7775A8} - System32\Tasks\Software Updater Ui => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Ui.exe [2013-12-28] () Task: {0A324023-A490-4F18-AC05-F3389C59CA23} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe Task: {14BD47B8-3C90-474F-8BCE-E3A36A64333A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA => C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-10] (Google Inc.) Task: {305613CB-9467-47E6-ABBD-6CF9B2F3EA13} - System32\Tasks\Software Updater => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe [2013-12-24] () Task: {36E3F646-2ADE-4E55-958E-2DE9B5D35486} - System32\Tasks\Funmoods => C:\Users\Christof\AppData\Roaming\Funmoods\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {38BCBE7F-4350-4D89-B5ED-3CFBDDE3FEF1} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-08-31] (ASUSTeK Computer Inc.) Task: {44F84D1D-BC08-4902-B944-283B60961319} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION Task: {46B1A0E5-1F8C-4724-8A6C-B30B4288C378} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2010-08-02] (ASUS) Task: {528B427F-F855-439A-A47E-8DFCC6587779} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA => C:\Users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-28] (Facebook Inc.) Task: {54C92ACB-03D0-4B1F-8F36-FF39DADEB6A5} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS) Task: {6C6A8579-8CF2-445B-A7A9-BC21E849CE38} - System32\Tasks\EPUpdater => C:\Users\Christof\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-06-06] () <==== ATTENTION Task: {7F8DDFFF-4721-4D33-898A-031679957DA3} - System32\Tasks\AIRecoveryRemind => C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryRemind.exe [2010-12-18] (ASUSTek Computer Inc.) Task: {884FF545-7FAB-455B-8A88-12EA4873BCC7} - System32\Tasks\Audio Performer => C:\Users\Christof\AppData\Local\Temp\Audio Performer53412.exe <==== ATTENTION Task: {A5F799F2-B796-4048-AB70-F08B27DB2A5E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core => C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-10] (Google Inc.) Task: {A73C4B6B-AEE9-4035-8357-30EC38D0A0C4} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION Task: {BD47C0B0-5BDB-4979-B058-10B6F669F213} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS) Task: {BEA4571B-7F2E-4605-BA57-1378CAA98AD6} - System32\Tasks\Funmoods Chat => C:\Users\Christof\AppData\Roaming\FunmoodsChat\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {C3A9702F-5672-4B6F-9D04-189326B5D246} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {D4632569-0F66-4C76-ADAB-D3AD6884D06C} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-12-02] (ASUS) Task: {E3716629-CF68-4C81-B9AA-1432405CFF1D} - System32\Tasks\BitGuard => Sc.exe start BitGuard <==== ATTENTION Task: {FA25F409-1B67-4A6B-8C09-766B2C3D7905} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core => C:\Users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-28] (Facebook Inc.) Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core.job => C:\Users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA.job => C:\Users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\Funmoods Chat.job => C:\Users\Christof\AppData\Roaming\FUNMOO~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\Funmoods.job => C:\Users\Christof\AppData\Roaming\Funmoods\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core.job => C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA.job => C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll 2012-02-04 13:01 - 2012-02-04 13:01 - 00075136 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2010-04-03 04:21 - 2008-10-01 08:08 - 00011264 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll 2013-11-01 07:31 - 2013-11-01 07:31 - 02329928 _____ () C:\Users\Christof\AppData\Local\Pokki\ocdeskband_0.dll 2010-01-02 16:42 - 2010-01-02 16:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2012-01-21 04:49 - 2012-01-09 20:44 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll 2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll 2011-07-07 08:12 - 2011-01-27 02:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2011-07-07 08:10 - 2011-05-05 14:30 - 00057640 _____ () C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll 2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll 2010-09-24 01:53 - 2010-09-24 01:53 - 01601536 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe 2013-06-21 13:07 - 2013-06-06 11:23 - 00004608 _____ () C:\Users\Christof\AppData\Roaming\BabSolution\Shared\BabMaint.exe 2013-09-13 19:51 - 2013-09-13 19:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-09-13 19:51 - 2013-09-13 19:51 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2011-08-31 15:33 - 2011-08-31 15:33 - 00208384 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll 2009-11-02 23:20 - 2009-11-02 23:20 - 00619816 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2009-11-02 23:23 - 2009-11-02 23:23 - 00013096 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2013-09-07 04:11 - 2013-09-07 04:11 - 00569856 _____ () C:\Users\Christof\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll 2013-09-07 04:11 - 2013-09-07 04:11 - 01400846 _____ () C:\Users\Christof\AppData\Local\Pokki\Engine\avcodec-54.dll 2013-09-07 04:11 - 2013-09-07 04:11 - 00151054 _____ () C:\Users\Christof\AppData\Local\Pokki\Engine\avutil-51.dll 2013-09-07 04:11 - 2013-09-07 04:11 - 00222734 _____ () C:\Users\Christof\AppData\Local\Pokki\Engine\avformat-54.dll 2014-05-15 21:52 - 2014-05-08 01:29 - 00065352 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\34.0.1847.137\chrome_elf.dll 2012-01-08 15:41 - 2012-01-08 15:41 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2014-05-15 21:52 - 2014-05-08 01:29 - 00674632 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\34.0.1847.137\libglesv2.dll 2014-05-15 21:52 - 2014-05-08 01:29 - 00093000 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\34.0.1847.137\libegl.dll 2014-05-15 21:52 - 2014-05-08 01:29 - 04081480 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\34.0.1847.137\pdf.dll 2014-05-15 21:52 - 2014-05-08 01:29 - 00390472 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\34.0.1847.137\ppGoogleNaClPluginChrome.dll 2014-05-15 21:52 - 2014-05-08 01:29 - 01647432 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\34.0.1847.137\ffmpegsumo.dll 2014-05-15 21:52 - 2014-05-08 01:29 - 13695816 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\34.0.1847.137\PepperFlash\pepflashplayer.dll 2013-02-25 19:08 - 2013-09-03 12:45 - 00431696 _____ () C:\Users\Christof\AppData\Roaming\BabSolution\Shared\BUSolution.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:3CF2806E ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/27/2014 05:01:30 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT-AUTORITÄT) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst "WmiApRpl" (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (05/27/2014 05:01:30 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (05/27/2014 05:01:30 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT-AUTORITÄT) Description: Die Zeichenfolgen der Leistungsindikatoren in der Leistungsindikatorenregistrierung werden beschädigt wenn der Prozess "Performance" auf dem Erweiterungsleistungsindikator-Anbieter ausgeführt wird. Der Wert "BaseIndex" aus der Leistungsregistrierung ist das erste DWORD im Datenbereich, der Wert "LastCounter" ist das zweite DWORD im Datenbereich und der Werte "LastHelp" ist das dritte DWORD im Datenbereich. Error: (05/27/2014 02:30:49 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 22635 Error: (05/27/2014 02:30:49 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 22635 Error: (05/27/2014 02:30:49 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (05/27/2014 02:30:48 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 21637 Error: (05/27/2014 02:30:48 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 21637 Error: (05/27/2014 02:30:48 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (05/27/2014 02:30:47 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 20639 System errors: ============= Error: (05/27/2014 01:47:28 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Microsoft .NET Framework NGEN v4.0.30319_X86 erreicht. Error: (05/27/2014 01:44:05 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "TuneUp Utilities Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (05/27/2014 01:43:36 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Hotspot Shield Monitoring Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (05/27/2014 01:43:36 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "LogMeIn Hamachi Tunneling Engine" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (05/27/2014 01:43:13 AM) (Source: BugCheck) (EventID: 1001) (User: ) Description: 0x000000f4 (0x0000000000000003, 0xfffffa8008685920, 0xfffffa8008685c00, 0xfffff800035e3270)C:\Windows\MEMORY.DMP Error: (05/27/2014 01:43:13 AM) (Source: BugCheck) (EventID: 1005) (User: ) Description: Error: (05/27/2014 01:43:11 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 27.05.2014 um 01:40:38 unerwartet heruntergefahren. Error: (05/27/2014 01:19:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "TuneUp Utilities Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (05/27/2014 01:19:03 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Hotspot Shield Monitoring Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (05/27/2014 01:19:03 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "LogMeIn Hamachi Tunneling Engine" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Microsoft Office Sessions: ========================= Error: (04/03/2013 07:05:03 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1832 seconds with 660 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-05-27 01:35:21.058 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-26 15:21:12.242 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-26 00:53:18.079 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 19:47:25.380 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 12:16:31.177 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 09:56:11.614 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 09:49:53.332 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 09:21:02.958 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 09:07:32.588 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-25 08:15:20.779 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 53% Total physical RAM: 6054.7 MB Available physical RAM: 2796.2 MB Total Pagefile: 12107.57 MB Available Pagefile: 8278.79 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:279.45 GB) (Free:93.15 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (DATA) (Fixed) (Total:394.18 GB) (Free:393.86 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 496B9619) Partition 1: (Not Active) - (Size=25 GB) - (Type=1C) Partition 2: (Active) - (Size=279 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=394 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
28.05.2014, 11:40 | #4 |
/// the machine /// TB-Ausbilder | TR/BProtector.Gen Adware & Co. deinstallieren
Solltest Du ein Programm nicht finden oder nicht deinstallieren können, mache bitte mit dem nächsten Schritt weiter: Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
28.05.2014, 21:00 | #5 |
| TR/BProtector.Gen Vielen Dank für die Schnelle Antwort! Kann es nicht sagen ob es jetzt der Trojaner ist oder nicht, aber beim letzten mal als ich durch Zeitgründen abgemeldet wurde & mich einloggen wollte konnte ich das Üasswort noch so oft eingeben und nicht einloggen.(Obwohl ich auf Großstelltaste achtete) Musste ihn abstürzen und neu hochfahren danach ging es wieder. Als ich RevoUninstaller Herunterlud u. Startete kam diese Meldung: Und konnte nichts finden. Darauf hin installierte ich ComboFix & Startete es: Das Ergebniss: Code:
ATTFilter ComboFix 14-05-27.02 - Christof 28.05.2014 18:50:03.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.43.1031.18.6055.3912 [GMT 2:00] ausgeführt von:: c:\users\Christof\Downloads\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} AV: Trend Micro Titanium Internet Security *Disabled/Updated* {68F968AC-2AA0-091D-848C-803E83E35902} SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Trend Micro Titanium Internet Security *Disabled/Updated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Microsoft c:\program files (x86)\Funmoods c:\program files (x86)\Funmoods\1.5.23.22\bh\escort.dll c:\program files (x86)\Funmoods\1.5.23.22\escortApp.dll c:\program files (x86)\Funmoods\1.5.23.22\escortEng.dll c:\program files (x86)\Funmoods\1.5.23.22\escortShld.dll c:\program files (x86)\Funmoods\1.5.23.22\FavIcon.ico c:\program files (x86)\Funmoods\1.5.23.22\funmoodssrv.exe c:\program files (x86)\Funmoods\1.5.23.22\Sqlite3.dll c:\program files (x86)\Funmoods\1.5.23.22\uninst.dat c:\program files (x86)\Funmoods\1.5.23.22\uninstall.exe c:\program files (x86)\SearchProtect c:\program files (x86)\SearchProtect\EULA.txt c:\program files (x86)\SearchProtect\Main\bin\CltMngSvc.exe c:\program files (x86)\SearchProtect\Main\bin\SPTool.dll c:\program files (x86)\SearchProtect\Main\bin\SPtool.dll_1389820509773 c:\program files (x86)\SearchProtect\Main\bin\SPtool.dll_1390837242531 c:\program files (x86)\SearchProtect\Main\bin\SPtool.dll_1391024340860 c:\program files (x86)\SearchProtect\Main\bin\SPtool.dll_1391024341304 c:\program files (x86)\SearchProtect\Main\bin\SPtool.dll_1391448126769 c:\program files (x86)\SearchProtect\Main\bin\uninstall.exe c:\program files (x86)\SearchProtect\Main\rep\SystemRepository.dat c:\program files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe c:\program files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe c:\program files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll c:\program files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll c:\program files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll c:\program files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll c:\program files (x86)\SearchProtect\UI\bin\cltmngui.exe c:\program files (x86)\SearchProtect\UI\dialogs\bubble\bubble.css c:\program files (x86)\SearchProtect\UI\dialogs\bubble\bubble.html c:\program files (x86)\SearchProtect\UI\dialogs\bubble\bubble.js c:\program files (x86)\SearchProtect\UI\dialogs\bubble\defaults.js c:\program files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\bg-uninstall.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\bg.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\bgSettingsDS.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\button-bg.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\hez.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\text-field.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\v.png c:\program files (x86)\SearchProtect\UI\dialogs\Images\x.png c:\program files (x86)\SearchProtect\UI\dialogs\libs\defaults.js c:\program files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js c:\program files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js c:\program files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js c:\program files (x86)\SearchProtect\UI\dialogs\libs\main.js c:\program files (x86)\SearchProtect\UI\dialogs\libs\SPDialogAPI.js c:\program files (x86)\SearchProtect\UI\dialogs\protection\defaults.js c:\program files (x86)\SearchProtect\UI\dialogs\protection\protection.css c:\program files (x86)\SearchProtect\UI\dialogs\protection\protection.html c:\program files (x86)\SearchProtect\UI\dialogs\protection\protection.js c:\program files (x86)\SearchProtect\UI\dialogs\protectionDS\defaults.js c:\program files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.css c:\program files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.html c:\program files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.js c:\program files (x86)\SearchProtect\UI\dialogs\settings.html c:\program files (x86)\SearchProtect\UI\dialogs\settings\defaults.js c:\program files (x86)\SearchProtect\UI\dialogs\settings\settings.css c:\program files (x86)\SearchProtect\UI\dialogs\settings\settings.html c:\program files (x86)\SearchProtect\UI\dialogs\settings\settings.js c:\program files (x86)\SearchProtect\UI\dialogs\style.css c:\program files (x86)\SearchProtect\UI\dialogs\uninstall\defaults.js c:\program files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.css c:\program files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.html c:\program files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.js c:\programdata\23lldnur.pad c:\programdata\ras_0oed.pad c:\programdata\Roaming c:\users\Christof\AppData\Roaming\13001.017 c:\users\Christof\AppData\Roaming\13001.017\chrome.manifest c:\users\Christof\AppData\Roaming\13001.017\components\AcroFF.txt c:\users\Christof\AppData\Roaming\13001.017\install.rdf c:\users\Christof\AppData\Roaming\13001.018 c:\users\Christof\AppData\Roaming\13001.018\chrome.manifest c:\users\Christof\AppData\Roaming\13001.018\components\AcroFF.txt c:\users\Christof\AppData\Roaming\13001.018\install.rdf c:\users\Christof\AppData\Roaming\13001.019 c:\users\Christof\AppData\Roaming\13001.019\chrome.manifest c:\users\Christof\AppData\Roaming\13001.019\components\AcroFF.txt c:\users\Christof\AppData\Roaming\13001.019\install.rdf c:\users\Christof\AppData\Roaming\13001.020 c:\users\Christof\AppData\Roaming\13001.020\chrome.manifest c:\users\Christof\AppData\Roaming\13001.020\components\AcroFF.txt c:\users\Christof\AppData\Roaming\13001.020\install.rdf c:\users\Christof\AppData\Roaming\13001.021 c:\users\Christof\AppData\Roaming\13001.021\chrome.manifest c:\users\Christof\AppData\Roaming\13001.021\components\AcroFF.txt c:\users\Christof\AppData\Roaming\13001.021\install.rdf c:\users\Christof\AppData\Roaming\13001.022 c:\users\Christof\AppData\Roaming\13001.022\chrome.manifest c:\users\Christof\AppData\Roaming\13001.022\components\AcroFF.txt c:\users\Christof\AppData\Roaming\13001.022\install.rdf c:\users\Christof\AppData\Roaming\13001.023 c:\users\Christof\AppData\Roaming\13001.023\chrome.manifest c:\users\Christof\AppData\Roaming\13001.023\components\AcroFF.txt c:\users\Christof\AppData\Roaming\13001.023\install.rdf c:\users\Christof\AppData\Roaming\13001.027 c:\users\Christof\AppData\Roaming\13001.027\chrome.manifest c:\users\Christof\AppData\Roaming\13001.027\components\AcroFF.txt c:\users\Christof\AppData\Roaming\13001.027\install.rdf c:\users\Christof\AppData\Roaming\AcroIEHelpe.txt c:\users\Christof\AppData\Roaming\BabMaint.exe c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\chrome.manifest c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\funmoods.css c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\funmoods.xul c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\images\pref.jpg c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\arwDwn.gif c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ae.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\bg.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ch.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\cn.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\cz.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\de.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\eg.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\en.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\es.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\fr.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\gr.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\he.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\il.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\it.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ja.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\jp.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\nl.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\no.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\pl.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\pt.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ro.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ru.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\sa.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\se.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\sv.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\tr.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ua.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\us.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\help_16.gif c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\home.gif c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\logo.png c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\privecy_16_hot.gif c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\imgs\tellafriend.gif c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\loader.xul c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\mtstart.js c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\preferences.xul c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\content\tmplt.js c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\install.rdf c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.rsa c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.sf c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@funmoods.com\META-INF\manifest.mf c:\users\Christof\AppData\Roaming\srvblck5.tmp c:\windows\SysWow64\Dump c:\windows\SysWow64\Dump\MiniDump.dmp . . ((((((((((((((((((((((( Dateien erstellt von 2014-04-28 bis 2014-05-28 )))))))))))))))))))))))))))))) . . 2014-05-28 17:03 . 2014-05-28 17:03 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2014-05-28 17:03 . 2014-05-28 17:03 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-05-28 16:21 . 2014-05-28 16:21 -------- d-----w- c:\program files (x86)\VS Revo Group 2014-05-27 15:03 . 2014-05-27 15:11 -------- d-----w- C:\FRST 2014-05-26 23:35 . 2014-05-09 09:16 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2014-05-26 23:35 . 2014-05-09 09:16 130584 ----a-w- c:\windows\system32\drivers\avipbb.sys 2014-05-26 23:35 . 2014-05-09 09:16 112080 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2014-05-26 23:34 . 2014-05-19 23:26 10702536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{99E68B69-D86A-4812-8A52-8F85FAE46A95}\mpengine.dll 2014-05-26 22:56 . 2014-05-26 22:56 -------- d-----w- c:\users\Christof\AppData\Roaming\Avira 2014-05-26 22:54 . 2014-05-26 22:54 -------- d-----w- c:\programdata\Avira 2014-05-26 22:54 . 2014-05-26 22:54 -------- d-----w- c:\program files (x86)\Avira 2014-05-15 19:46 . 2014-05-06 04:40 23544320 ----a-w- c:\windows\system32\mshtml.dll 2014-05-15 19:46 . 2014-05-06 03:00 84992 ----a-w- c:\windows\system32\mshtmled.dll 2014-05-15 19:46 . 2014-05-06 04:17 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2014-05-15 19:46 . 2014-05-06 03:07 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2014-05-14 20:59 . 2014-03-25 02:43 14175744 ----a-w- c:\windows\system32\shell32.dll 2014-05-14 20:59 . 2014-05-09 06:14 477184 ----a-w- c:\windows\system32\aepdu.dll 2014-05-14 20:59 . 2014-05-09 06:11 424448 ----a-w- c:\windows\system32\aeinv.dll 2014-05-07 01:01 . 2014-05-18 01:02 -------- d-s---w- c:\windows\system32\CompatTel 2014-04-30 11:19 . 2014-03-31 07:35 270496 ------w- c:\windows\system32\MpSigStub.exe . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-05-28 16:15 . 2011-11-30 12:27 45056 ----a-w- c:\windows\system32\acovcnt.exe 2014-04-16 12:52 . 2013-11-17 20:30 93144 ----a-w- c:\windows\system32\drivers\hmpalert.sys 2014-04-16 12:52 . 2013-11-17 20:30 548424 ----a-w- c:\windows\system32\hmpalert.dll 2014-04-16 12:52 . 2013-11-17 20:30 477008 ----a-w- c:\windows\SysWow64\hmpalert.dll 2014-03-31 20:46 . 2014-03-31 20:46 130712 ----a-w- c:\windows\SysWow64\MSSTDFMT.DLL 2014-03-31 20:46 . 2014-03-31 20:46 1070232 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX 2014-03-06 09:31 . 2014-04-17 01:02 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2014-03-06 08:59 . 2014-04-17 01:02 66048 ----a-w- c:\windows\system32\iesetup.dll 2014-03-06 08:57 . 2014-04-17 01:02 548352 ----a-w- c:\windows\system32\vbscript.dll 2014-03-06 08:57 . 2014-04-17 01:02 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2014-03-06 08:53 . 2014-04-17 01:02 2767360 ----a-w- c:\windows\system32\iertutil.dll 2014-03-06 08:40 . 2014-04-17 01:02 51200 ----a-w- c:\windows\system32\jsproxy.dll 2014-03-06 08:39 . 2014-04-17 01:02 33792 ----a-w- c:\windows\system32\iernonce.dll 2014-03-06 08:32 . 2014-04-17 01:02 574976 ----a-w- c:\windows\system32\ieui.dll 2014-03-06 08:29 . 2014-04-17 01:02 139264 ----a-w- c:\windows\system32\ieUnatt.exe 2014-03-06 08:29 . 2014-04-17 01:02 111616 ----a-w- c:\windows\system32\ieetwcollector.exe 2014-03-06 08:28 . 2014-04-17 01:02 752640 ----a-w- c:\windows\system32\jscript9diag.dll 2014-03-06 08:15 . 2014-04-17 01:02 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2014-03-06 08:11 . 2014-04-17 01:02 5784064 ----a-w- c:\windows\system32\jscript9.dll 2014-03-06 08:09 . 2014-04-17 01:02 453120 ----a-w- c:\windows\system32\dxtmsft.dll 2014-03-06 08:03 . 2014-04-17 01:02 586240 ----a-w- c:\windows\system32\ie4uinit.exe 2014-03-06 08:02 . 2014-04-17 01:02 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2014-03-06 08:02 . 2014-04-17 01:02 455168 ----a-w- c:\windows\SysWow64\vbscript.dll 2014-03-06 08:01 . 2014-04-17 01:02 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2014-03-06 07:56 . 2014-04-17 01:02 38400 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2014-03-06 07:48 . 2014-04-17 01:02 195584 ----a-w- c:\windows\system32\msrating.dll 2014-03-06 07:46 . 2014-04-17 01:02 4254720 ----a-w- c:\windows\SysWow64\jscript9.dll 2014-03-06 07:42 . 2014-04-17 01:02 296960 ----a-w- c:\windows\system32\dxtrans.dll 2014-03-06 07:38 . 2014-04-17 01:02 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2014-03-06 07:36 . 2014-04-17 01:02 592896 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2014-03-06 07:21 . 2014-04-17 01:02 628736 ----a-w- c:\windows\system32\msfeeds.dll 2014-03-06 07:13 . 2014-04-17 01:02 32256 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2014-03-06 07:11 . 2014-04-17 01:02 2043904 ----a-w- c:\windows\system32\inetcpl.cpl 2014-03-06 06:53 . 2014-04-17 01:02 13551104 ----a-w- c:\windows\system32\ieframe.dll 2014-03-06 06:40 . 2014-04-17 01:02 1967104 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2014-03-06 06:22 . 2014-04-17 01:02 2260480 ----a-w- c:\windows\system32\wininet.dll 2014-03-06 05:58 . 2014-04-17 01:02 1400832 ----a-w- c:\windows\system32\urlmon.dll 2014-03-06 05:50 . 2014-04-17 01:02 846336 ----a-w- c:\windows\system32\ieapfltr.dll 2014-03-06 05:41 . 2014-04-17 01:02 1789440 ----a-w- c:\windows\SysWow64\wininet.dll 2014-03-04 09:44 . 2014-04-16 04:16 243712 ----a-w- c:\windows\system32\wow64.dll 2014-03-04 09:44 . 2014-04-16 04:16 362496 ----a-w- c:\windows\system32\wow64win.dll 2014-03-04 09:44 . 2014-04-16 04:16 13312 ----a-w- c:\windows\system32\wow64cpu.dll 2014-03-04 09:44 . 2014-04-16 04:16 16384 ----a-w- c:\windows\system32\ntvdm64.dll 2014-03-04 09:44 . 2014-04-16 04:16 1163264 ----a-w- c:\windows\system32\kernel32.dll 2014-03-04 09:17 . 2014-04-16 04:16 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2014-03-04 09:17 . 2014-04-16 04:16 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2014-03-04 09:16 . 2014-04-16 04:16 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2014-03-04 09:16 . 2014-04-16 04:16 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2014-03-04 08:09 . 2014-04-16 04:16 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2014-03-04 08:09 . 2014-04-16 04:16 2048 ----a-w- c:\windows\SysWow64\user.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}] 2013-01-23 12:24 247704 ----a-w- c:\program files (x86)\Delta\delta\1.8.10.0\bh\delta.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{E87806B5-E908-45FD-AF5E-957D83E58E68}] 2012-01-11 14:29 241872 ----a-w- c:\program files (x86)\Softonic\softonic\1.5.11.5\bh\softonic.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{5018CFD2-804D-4C99-9F81-25EAEA2769DE}"= "c:\program files (x86)\Softonic\softonic\1.5.11.5\softonicTlbr.dll" [2012-01-11 250064] "{82E1477C-B154-48D3-9891-33D83C26BCD3}"= "c:\program files (x86)\Delta\delta\1.8.10.0\deltaTlbr.dll" [2013-01-23 321944] . [HKEY_CLASSES_ROOT\clsid\{5018cfd2-804d-4c99-9f81-25eaea2769de}] [HKEY_CLASSES_ROOT\Softonic.dskBnd.1] [HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] [HKEY_CLASSES_ROOT\Softonic.dskBnd] . [HKEY_CLASSES_ROOT\clsid\{82e1477c-b154-48d3-9891-33d83c26bcd3}] [HKEY_CLASSES_ROOT\delta.deltadskBnd.1] [HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] [HKEY_CLASSES_ROOT\delta.deltadskBnd] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] "GoogleChromeAutoLaunch_9DC73BAD139DCCFFA56EA65F10CB0EF3"="c:\users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe" [2014-05-13 860488] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-02-10 20922016] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" [2008-11-03 328992] "ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2011-04-13 2018032] "ASUSWebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe" [2011-02-23 731472] "SonicMasterTray"="c:\program files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe" [2010-07-10 984400] "ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992] "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624] "HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-23 1601536] "UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-11-01 152392] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-05-09 737872] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SpUninstallDeleteDir"="rmdir" [X] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe /start [2011-4-13 549040] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x] R2 HssWd;Hotspot Shield Monitoring Service;c:\program files (x86)\Hotspot Shield\bin\hsswd.exe;c:\program files (x86)\Hotspot Shield\bin\hsswd.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R2 SystemStoreService;System Store;c:\program files (x86)\SoftwareUpdater\SystemStore.exe -displayname System Store -servicename SystemStoreService;c:\program files (x86)\SoftwareUpdater\SystemStore.exe -displayname System Store -servicename SystemStoreService [x] R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [x] R3 Amsp;Trend Micro Solution Platform;c:\program files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe;c:\program files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe [x] R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x] R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys;c:\windows\SYSNATIVE\DRIVERS\ewusbdev.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x] R4 TiMiniService;TiMiniService;c:\program files\Trend Micro\Titanium\TiMiniService.exe;c:\program files\Trend Micro\Titanium\TiMiniService.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x] S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S1 HssDRV6;Hotspot Shield Routing Driver 6;c:\windows\system32\DRIVERS\hssdrv6.sys;c:\windows\SYSNATIVE\DRIVERS\hssdrv6.sys [x] S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] S2 CltMngSvc;Search Protect Service;c:\progra~2\SearchProtect\Main\bin\CltMngSvc.exe;c:\progra~2\SearchProtect\Main\bin\CltMngSvc.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 hmpalert;HitmanPro.Alert Support Driver;c:\windows\system32\drivers\hmpalert.sys;c:\windows\SYSNATIVE\drivers\hmpalert.sys [x] S2 hmpalertsvc;HitmanPro.Alert Service;c:\program files (x86)\HitmanPro.Alert\hmpalert.exe;c:\program files (x86)\HitmanPro.Alert\hmpalert.exe [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [x] S2 tmevtmgr;tmevtmgr;c:\windows\system32\DRIVERS\tmevtmgr.sys;c:\windows\SYSNATIVE\DRIVERS\tmevtmgr.sys [x] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x] S2 TurboBoost;Intel(R) Turbo Boost Technology Monitor;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x] S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x] S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x] S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys;c:\windows\SYSNATIVE\DRIVERS\vrtaucbl.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] . . Inhalt des "geplante Tasks" Ordners . 2014-05-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core.job - c:\users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-28 15:38] . 2014-05-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA.job - c:\users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-28 15:38] . 2014-05-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core.job - c:\users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-10 19:49] . 2014-05-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA.job - c:\users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-10 19:49] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B] @="{6D4133E5-0742-4ADC-8A8C-9303440F7190}" [HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}] 2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O] @="{64174815-8D98-4CE6-8646-4C039977D808}" [HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}] 2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "VizorHtmlDialog.exe"="c:\program files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe" [2010-10-08 1123664] "Trend Micro Client Framework"="c:\program files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe" [2010-10-12 192520] "Trend Micro Titanium"="c:\program files\Trend Micro\Titanium\VizorShortCut.exe" [2010-09-17 322384] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-10 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-10 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-10 418328] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-05-17 2226280] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-05-02 1935120] "IntelTBRunOnce"="wscript.exe" [2013-10-12 168960] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uDefault_Search_URL = hxxp://www.google.com/ie uStart Page = https://www.google.at/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Free YouTube to MP3 Converter - c:\users\Christof\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.0.254 FF - ProfilePath - c:\users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\ FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?AF=109992&babsrc=adbartrp&mntrId=dcc9ff5c00000000000078929c45f955&q= FF - prefs.js: browser.startup.homepage - about:home|hxxp://www.giga.de/androidnews/ FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109992 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ss FF - user.js: extensions.BabylonToolbar_i.id - dcc9ff5c00000000000078929c45f955 FF - user.js: extensions.BabylonToolbar_i.hardId - dcc9ff5c00000000000078929c45f955 FF - user.js: extensions.BabylonToolbar_i.instlDay - 15409 FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.178:33 FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar_i.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9 FF - user.js: extensions.BabylonToolbar_i.instlRef - sst FF - user.js: extensions.softonic_i.newTab - false FF - user.js: extensions.softonic_i.tlbrSrchUrl - hxxp://search.softonic.com/MON00001/tb_v1?SearchSource=1&cc=&q= FF - user.js: extensions.softonic_i.id - dcc9ff5c00000000000078929c45f954 FF - user.js: extensions.softonic_i.instlDay - 15562 FF - user.js: extensions.softonic_i.vrsn - 1.5.11.5 FF - user.js: extensions.softonic_i.vrsni - 1.5.11.5 FF - user.js: extensions.softonic_i.vrsnTs - 1.5.11.516:14 FF - user.js: extensions.softonic_i.prtnrId - softonic FF - user.js: extensions.softonic_i.prdct - softonic FF - user.js: extensions.softonic_i.aflt - orgnl FF - user.js: extensions.softonic_i.smplGrp - eng7 FF - user.js: extensions.softonic_i.tlbrId - eng7 FF - user.js: extensions.softonic_i.instlRef - MON00001 FF - user.js: extensions.softonic_i.dfltLng - FF - user.js: extensions.softonic_i.excTlbr - false FF - user.js: extensions.funmoods.hmpg - false FF - user.js: extensions.funmoods.hmpgUrl - hxxp://searchfunmoods.com/?f=1&a=orgnl&chnl=&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzytB0E0EtAtAtA0F0FyD0CtN0D0Tzu0CtAyEyBtN1L2XzutBtFtBtFtDtFtAyEyE&cr=949259982 FF - user.js: extensions.funmoods.dfltSrch - false FF - user.js: extensions.funmoods.srchPrvdr - Search FF - user.js: extensions.funmoods.dnsErr - true FF - user.js: extensions.funmoods_i.newTab - false FF - user.js: extensions.funmoods.newTabUrl - hxxp://searchfunmoods.com/?f=2&a=orgnl&chnl=&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzytB0E0EtAtAtA0F0FyD0CtN0D0Tzu0CtAyEyBtN1L2XzutBtFtBtFtDtFtAyEyE&cr=949259982 FF - user.js: extensions.funmoods.tlbrSrchUrl - hxxp://searchfunmoods.com/?f=3&a=orgnl&chnl=&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzytB0E0EtAtAtA0F0FyD0CtN0D0Tzu0CtAyEyBtN1L2XzutBtFtBtFtDtFtAyEyE&cr=949259982&q= FF - user.js: extensions.funmoods.id - 7A79192EE333FF5C FF - user.js: extensions.funmoods.instlDay - 15686 FF - user.js: extensions.funmoods.vrsn - 1.5.23.22 FF - user.js: extensions.funmoods.vrsni - 1.5.23.22 FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2215:27 FF - user.js: extensions.funmoods.prtnrId - funmoods FF - user.js: extensions.funmoods.prdct - funmoods FF - user.js: extensions.funmoods.aflt - orgnl FF - user.js: extensions.funmoods_i.smplGrp - none FF - user.js: extensions.funmoods.tlbrId - base FF - user.js: extensions.funmoods.instlRef - FF - user.js: extensions.funmoods.dfltLng - FF - user.js: extensions.funmoods.excTlbr - true FF - user.js: extensions.funmoods.autoRvrt - false FF - user.js: extensions.funmoods.envrmnt - production FF - user.js: extensions.funmoods.isdcmntcmplt - true FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0 FF - user.js: extensions.delta.tlbrSrchUrl - FF - user.js: extensions.delta.id - dcc9ff5c00000000000078929c45f955 FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} FF - user.js: extensions.delta.instlDay - 15757 FF - user.js: extensions.delta.vrsn - 1.8.10.0 FF - user.js: extensions.delta.vrsni - 1.8.10.0 FF - user.js: extensions.delta.vrsnTs - 1.8.10.022:58 FF - user.js: extensions.delta.prtnrId - delta FF - user.js: extensions.delta.prdct - delta FF - user.js: extensions.delta.aflt - babsst FF - user.js: extensions.delta.smplGrp - none FF - user.js: extensions.delta.tlbrId - base FF - user.js: extensions.delta.instlRef - sst FF - user.js: extensions.delta.dfltLng - en FF - user.js: extensions.delta.excTlbr - false FF - user.js: extensions.delta.admin - false FF - user.js: extensions.delta.autoRvrt - false FF - user.js: extensions.delta.rvrt - false FF - user.js: extensions.delta.newTab - false . - - - - Entfernte verwaiste Registrierungseinträge - - - - . BHO-{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - c:\program files (x86)\Funmoods\1.5.23.22\bh\escort.dll Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-AdobeBridge - (no file) Wow6432Node-HKCU-Run-Pokki - %LOCALAPPDATA%\Pokki\Engine\Launcher.dll Wow6432Node-HKLM-Run-LogMeIn Hamachi Ui - c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start BHO-{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - c:\program files (x86)\Hotspot Shield\HssIE\HssIE_64.dll Toolbar-Locked - (no file) WebBrowser-{942CD1D4-9CC1-4D31-876A-EA8F489F7A59} - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe HKLM-Run-SynAsusAcpi - c:\program files (x86)\Synaptics\SynTP\SynAsusAcpi.exe HKLM-Run-Setwallpaper - c:\programdata\SetWallpaper.cmd AddRemove-1ClickDownload - c:\program files (x86)\Movie2KDownloader.com\uninst.exe AddRemove-funmoods - c:\program files (x86)\Funmoods\1.5.23.22\uninstall.exe AddRemove-SearchProtect - c:\progra~2\SearchProtect\Main\bin\uninstall.exe AddRemove-TuneUp Utilities 2012 - c:\program files (x86)\TuneUp Utilities 2012\TUInstallHelper.exe AddRemove-UltraStar - c:\program files (x86)\UltraStar\uninstall.exe AddRemove-{D84EA2B7-F65E-43F3-9FB5-18B2162DBFA2}}_is1 - c:\stormblade\unins000.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-05-28 19:43:47 ComboFix-quarantined-files.txt 2014-05-28 17:43 . Vor Suchlauf: 16 Verzeichnis(se), 99.618.209.792 Bytes frei Nach Suchlauf: 22 Verzeichnis(se), 100.495.601.664 Bytes frei . - - End Of File - - E60EAC98B6D46F7F89A0A29581EF0D9D Geändert von Gytoro (28.05.2014 um 21:29 Uhr) |
29.05.2014, 21:00 | #6 |
/// the machine /// TB-Ausbilder | TR/BProtector.Gen Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> TR/BProtector.Gen |
30.05.2014, 00:35 | #7 |
| TR/BProtector.Gen Ganz schön viel was man sich hier für ein Trojaner herunterladen muss! ;D Als Dieses MBAM am laufen war wurde auf einmal rechts diese Meldung gezeit: und dies Meldung folgte zugleich darauf: Soo MBAM.TXT: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 30.05.2014 Suchlauf-Zeit: 00:11:12 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.05.29.12 Rootkit Datenbank: v2014.05.21.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Christof Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 322605 Verstrichene Zeit: 20 Min, 57 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 194 PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\APPID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}, In Quarantäne, [60d095c2d3a880b638de98cf48ba30d0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{35C1605E-438B-4D64-AAB1-8885F097A9B1}, In Quarantäne, [60d095c2d3a880b638de98cf48ba30d0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{35C1605E-438B-4D64-AAB1-8885F097A9B1}, In Quarantäne, [60d095c2d3a880b638de98cf48ba30d0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}, In Quarantäne, [60d095c2d3a880b638de98cf48ba30d0], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [f838e17646351d191618f76fbd451ae6], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [f838e17646351d191618f76fbd451ae6], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}, In Quarantäne, [4de347100c6f5fd7b6c22e05e31f2bd5], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{291BCCC1-6890-484a-89D3-318C928DAC1B}, In Quarantäne, [d65a8acd4b30ed49ec29a7c0c141b848], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\esrv.BabylonESrvc.1, In Quarantäne, [d65a8acd4b30ed49ec29a7c0c141b848], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\esrv.BabylonESrvc, In Quarantäne, [d65a8acd4b30ed49ec29a7c0c141b848], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.BabylonESrvc, In Quarantäne, [d65a8acd4b30ed49ec29a7c0c141b848], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.BabylonESrvc.1, In Quarantäne, [d65a8acd4b30ed49ec29a7c0c141b848], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, In Quarantäne, [e050cd8aabd049ed8a4f52dddf23b34d], PUP.Optional.Softonic.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, Löschen bei Neustart, [e050cd8aabd049ed8a4f52dddf23b34d], PUP.Optional.Softonic.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, Löschen bei Neustart, [e050cd8aabd049ed8a4f52dddf23b34d], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{75A4D144-506D-4BE5-81DB-EC7DA1E7F840}, In Quarantäne, [49e7a0b7700b4ee8e57d4f135fa345bb], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}, In Quarantäne, [49e7a0b7700b4ee8e57d4f135fa345bb], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}, In Quarantäne, [49e7a0b7700b4ee8e57d4f135fa345bb], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\esrv.funmoodsESrvc.1, In Quarantäne, [49e7a0b7700b4ee8e57d4f135fa345bb], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\esrv.funmoodsESrvc, In Quarantäne, [49e7a0b7700b4ee8e57d4f135fa345bb], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.funmoodsESrvc, In Quarantäne, [49e7a0b7700b4ee8e57d4f135fa345bb], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.funmoodsESrvc.1, In Quarantäne, [49e7a0b7700b4ee8e57d4f135fa345bb], PUP.Optional.FunMoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}, In Quarantäne, [a88894c3cfaca591888b231e2ad89967], PUP.Optional.FunMoods.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}, In Quarantäne, [a88894c3cfaca591888b231e2ad89967], PUP.Optional.FunMoods.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}, Löschen bei Neustart, [a88894c3cfaca591888b231e2ad89967], PUP.Optional.FunMoods.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}, Löschen bei Neustart, [a88894c3cfaca591888b231e2ad89967], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}, In Quarantäne, [4ae67fd84338c373a7871b4a7a88d12f], PUP.Optional.Delta.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, Löschen bei Neustart, [4ae67fd84338c373a7871b4a7a88d12f], PUP.Optional.Delta.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, Löschen bei Neustart, [4ae67fd84338c373a7871b4a7a88d12f], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{965B9DBE-B104-44AC-950A-8A5F97AFF439}, In Quarantäne, [d759183f7605de582e32fe648e74768a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\escort.escortIEPane.1, In Quarantäne, [d759183f7605de582e32fe648e74768a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\escort.escortIEPane, In Quarantäne, [d759183f7605de582e32fe648e74768a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\escort.escortIEPane, In Quarantäne, [d759183f7605de582e32fe648e74768a], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A9DB719C-7156-415E-B49D-BAD039DE4F13}, In Quarantäne, [65cb4a0d661586b0b3b13a28679bd030], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\funmoodsApp.appCore.1, In Quarantäne, [65cb4a0d661586b0b3b13a28679bd030], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\funmoodsApp.appCore, In Quarantäne, [65cb4a0d661586b0b3b13a28679bd030], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\funmoodsApp.appCore, In Quarantäne, [65cb4a0d661586b0b3b13a28679bd030], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\funmoodsApp.appCore.1, In Quarantäne, [65cb4a0d661586b0b3b13a28679bd030], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}, In Quarantäne, [da5679deb2c9ab8b1afff275bc4640c0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\b, In Quarantäne, [da5679deb2c9ab8b1afff275bc4640c0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\b, In Quarantäne, [da5679deb2c9ab8b1afff275bc4640c0], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, In Quarantäne, [230d2f280b70310538f5c3a27a88b44c], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}, In Quarantäne, [230d2f280b70310538f5c3a27a88b44c], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\escort.escortIEPane.1, In Quarantäne, [230d2f280b70310538f5c3a27a88b44c], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, In Quarantäne, [230d2f280b70310538f5c3a27a88b44c], PUP.Optional.Delta.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, Löschen bei Neustart, [230d2f280b70310538f5c3a27a88b44c], PUP.Optional.Delta.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, Löschen bei Neustart, [230d2f280b70310538f5c3a27a88b44c], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E87806B5-E908-45FD-AF5E-957D83E58E68}, In Quarantäne, [e44c34230f6c0135439737f844be6f91], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CA0167C2-6295-41B8-9BDA-704B2F5E4CD9}, In Quarantäne, [e44c34230f6c0135439737f844be6f91], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E87806B5-E908-45FD-AF5E-957D83E58E68}, In Quarantäne, [e44c34230f6c0135439737f844be6f91], PUP.Optional.Softonic.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E87806B5-E908-45FD-AF5E-957D83E58E68}, Löschen bei Neustart, [e44c34230f6c0135439737f844be6f91], PUP.Optional.Softonic.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{E87806B5-E908-45FD-AF5E-957D83E58E68}, Löschen bei Neustart, [e44c34230f6c0135439737f844be6f91], PUP.Optional.Softonic.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{E87806B5-E908-45FD-AF5E-957D83E58E68}, Löschen bei Neustart, [e44c34230f6c0135439737f844be6f91], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F03FD9D0-4F2B-497C-8A71-DD41D70B07D9}, In Quarantäne, [f937b4a35427e94d2a3bcd954bb744bc], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\f, In Quarantäne, [f937b4a35427e94d2a3bcd954bb744bc], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\f, In Quarantäne, [f937b4a35427e94d2a3bcd954bb744bc], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0D80F1C5-D17B-4177-AC68-955F3EF9F191}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{23C70BCA-6E23-4A65-AD2E-1389062074F1}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{295CACB4-51F5-46FD-914E-C72BAAE1B672}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C0585B2F-74D7-4734-88DE-6C150C5D4036}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EF0588D6-1621-4A75-B8BE-F4BC34794136}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0D80F1C5-D17B-4177-AC68-955F3EF9F191}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{23C70BCA-6E23-4A65-AD2E-1389062074F1}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{295CACB4-51F5-46FD-914E-C72BAAE1B672}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C0585B2F-74D7-4734-88DE-6C150C5D4036}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EF0588D6-1621-4A75-B8BE-F4BC34794136}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3}, In Quarantäne, [9a963e19bdbe1e189f5d0b3213efdd23], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{4599D05A-D545-4069-BB42-5895B4EAE05B}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1231839B-064E-4788-B865-465A1B5266FD}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2DAC2231-CC35-482B-97C5-CED1D4185080}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{57C91446-8D81-4156-A70E-624551442DE9}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{97DD820D-2E20-40AD-B01E-6730B2FCE630}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B177446D-54A4-4869-BABC-8566110B4BE0}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F05B12E1-ADE8-4485-B45B-898748B53C37}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1231839B-064E-4788-B865-465A1B5266FD}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2DAC2231-CC35-482B-97C5-CED1D4185080}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{57C91446-8D81-4156-A70E-624551442DE9}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{97DD820D-2E20-40AD-B01E-6730B2FCE630}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B177446D-54A4-4869-BABC-8566110B4BE0}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F05B12E1-ADE8-4485-B45B-898748B53C37}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{4599D05A-D545-4069-BB42-5895B4EAE05B}, In Quarantäne, [7db3e6712e4da19529047cea3ec4d52b], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{6E8BF012-2C85-4834-B10A-1B31AF173D70}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{706D4A4B-184A-4434-B331-296B07493D2D}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8BE10F21-185F-4CA0-B789-9921674C3993}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{94C0B25D-3359-4B10-B227-F96A77DB773F}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B173667F-8395-4317-8DD6-45AD1FE00047}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B32672B3-F656-46E0-B584-FE61C0BB6037}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{BFE569F7-646C-4512-969B-9BE3E580D393}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{C2996524-2187-441F-A398-CD6CB6B3D020}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E047E227-5342-4D94-80F7-CFB154BF55BD}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{706D4A4B-184A-4434-B331-296B07493D2D}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8BE10F21-185F-4CA0-B789-9921674C3993}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{94C0B25D-3359-4B10-B227-F96A77DB773F}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B173667F-8395-4317-8DD6-45AD1FE00047}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B32672B3-F656-46E0-B584-FE61C0BB6037}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{BFE569F7-646C-4512-969B-9BE3E580D393}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C2996524-2187-441F-A398-CD6CB6B3D020}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E047E227-5342-4D94-80F7-CFB154BF55BD}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{6E8BF012-2C85-4834-B10A-1B31AF173D70}, In Quarantäne, [959bdc7b89f2cc6a61b6fd6a60a260a0], PUP.Optional.FaceMoods.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0D7562AE-8EF6-416d-A838-AB665251703A}, Löschen bei Neustart, [2c042b2c5b20ef475497969947bb817f], PUP.Optional.FaceMoods.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{64182481-4F71-486b-A045-B233BD0DA8FC}, Löschen bei Neustart, [84acec6bd1aa3ef854956fc0ae54e020], Trojan.Banker, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{DD31495E-290C-41CF-8C66-7415383F82DE}, Löschen bei Neustart, [63cdfc5bfe7d7cbad26c221baa58cc34], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}, In Quarantäne, [111ff661a0db80b6de44fe68f1117090], PUP.Optional.BabylonToolBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}, In Quarantäne, [67c9193ed5a694a2001889de57abb050], PUP.Optional.Funmoods.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C87FC351-A80D-43E9-9A86-CF1E29DC443A}, In Quarantäne, [66ca0057324970c6293860024eb4f20e], PUP.Optional.FunMoods.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Funmoods, Löschen bei Neustart, [eb456dea4a3186b091feb4f8946ecb35], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\srv.SoftonicSrvc, In Quarantäne, [8da3c09738431620cadc930929d9e21e], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\srv.SoftonicSrvc.1, In Quarantäne, [8ca45ff846352c0aefb7207cd62c7888], PUP.Funmoods, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\bbjciahceamgodcoidkjpchnokgfpphh, In Quarantäne, [5bd5e473e7943bfb23312f869969e31d], PUP.Optional.Babylon.A, HKLM\SOFTWARE\WOW6432NODE\BabylonToolbar, In Quarantäne, [f7394d0a89f28fa7e78b05bd5ea5f20e], PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\DataMngr, In Quarantäne, [e34dacab621954e29e0feba14eb4d828], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\srv.SoftonicSrvc, In Quarantäne, [4ee20354abd037ff990d2a7231d1b848], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\srv.SoftonicSrvc.1, In Quarantäne, [2c045bfc8bf0c3737531029a34ceb34d], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\DELTA\DELTA\Instl, In Quarantäne, [a888a1b6295203333bcba620f50e9a66], PUP.Funmoods, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\bbjciahceamgodcoidkjpchnokgfpphh, In Quarantäne, [b67ae671cead44f2a9ab397c7b87d22e], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\eooncjejnppfjjklapaamhcdmjbilmde, In Quarantäne, [0b25b6a198e39b9b4f945c64867d768a], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\SOFTONIC\softonic, In Quarantäne, [d65a0c4b7efd41f5c6e48913fd059a66], PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM, In Quarantäne, [d858acabed8e20164d80358cbb48f709], PUP.Optional.ConduitSearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, In Quarantäne, [092783d4d8a379bd15ceeecfe61d16ea], PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, Löschen bei Neustart, [5ed291c63e3d43f3d167bc06fa0921df], PUP.Optional.BabylonToolBar.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BabylonToolbar, Löschen bei Neustart, [57d9a0b7daa16acc7c156064659e44bc], PUP.Optional.DataMngr.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, Löschen bei Neustart, [2e028bccbfbc171f2199437d15ee4eb2], PUP.FunMoods, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Funmoods, Löschen bei Neustart, [7bb5d582bfbc5bdb36a44c66877bcd33], PUP.Optional.PriceGong.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, Löschen bei Neustart, [45ebdb7cadce092d1920723343bf728e], PUP.Optional.Babylon.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, Löschen bei Neustart, [a38dfa5d18636fc7457c8e338e75629e], PUP.Optional.Delta.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DELTA\DELTA, Löschen bei Neustart, [d25ec2951f5c8da91d3bfcc3d23157a9], PUP.Funmoods, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\bbjciahceamgodcoidkjpchnokgfpphh, Löschen bei Neustart, [10204a0d63188babeb68447145bd9a66], PUP.Optional.InstallCore.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Löschen bei Neustart, [8fa1eb6c2655f73f57880bb5b74c8779], PUP.Optional.BProtector.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, Löschen bei Neustart, [fc3473e4a2d91f17d93accf816ed5ba5], PUP.Optional.Softonic.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\softonic, Löschen bei Neustart, [27091b3c3546ae88a700cdcf8e746997], PUP.Optional.Softonic.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Löschen bei Neustart, [8ba5f166c7b4df57115c88118a7812ee], PUP.Optional.SweetIM.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, Löschen bei Neustart, [3cf491c68fec2a0c4a8213ae9370649c], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}, In Quarantäne, [a68a461105764ee8eb0d79ff03ff728e], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\delta.deltaappCore.1, In Quarantäne, [a68a461105764ee8eb0d79ff03ff728e], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\delta.deltaappCore, In Quarantäne, [a68a461105764ee8eb0d79ff03ff728e], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\delta.deltaappCore, In Quarantäne, [a68a461105764ee8eb0d79ff03ff728e], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\delta.deltaappCore.1, In Quarantäne, [a68a461105764ee8eb0d79ff03ff728e], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}, In Quarantäne, [a68a461105764ee8eb0d79ff03ff728e], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\delta, In Quarantäne, [a68a461105764ee8eb0d79ff03ff728e], PUP.Optional.FunMoods.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Funmoods Chat, Löschen bei Neustart, [7fb1b89f18637bbb721a59277a889967], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{44B50C01-4993-48E2-ADEE-D812BAE2E9A2}, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\SoftonicApp.appCore.1, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\SoftonicApp.appCore, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SoftonicApp.appCore, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SoftonicApp.appCore.1, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A5679AB0-C59E-49E7-83C4-5289F844A6E0}, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], PUP.Optional.Softonic.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B15F118E-AF21-45E8-A809-29FDD7362565}, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{B15F118E-AF21-45E8-A809-29FDD7362565}, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\softonic, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], Registrierungswerte: 10 PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, Softonic Toolbar, In Quarantäne, [e050cd8aabd049ed8a4f52dddf23b34d] PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{82E1477C-B154-48D3-9891-33D83C26BCD3}, Delta Toolbar, In Quarantäne, [4ae67fd84338c373a7871b4a7a88d12f] PUP.Optional.Softonic.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{5018CFD2-804D-4C99-9F81-25EAEA2769DE}, In Quarantäne, [f13fef682e4d3bfb5e7b1f1016ec9769], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{82E1477C-B154-48D3-9891-33D83C26BCD3}, In Quarantäne, [e64aadaac5b6f541101ec69f03ffe917], PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM|simapp_id, 11111111, In Quarantäne, [d858acabed8e20164d80358cbb48f709] PUP.Optional.Delta.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DELTA\DELTA|tlbrSrchUrl, Löschen bei Neustart, [d25ec2951f5c8da91d3bfcc3d23157a9], PUP.Optional.InstallCore.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0F1R1N2V1M1H1JtI0E0T, Löschen bei Neustart, [8fa1eb6c2655f73f57880bb5b74c8779] PUP.BProtector, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, hxxp://isearch.babylon.com/?babsrc=HP_def_gr2&affID=119776, Löschen bei Neustart, [a987a0b75b20fa3c605c536dd62db44c] PUP.BProtector, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, Löschen bei Neustart, [c96795c27407d1658439caf631d27c84] PUP.Optional.SweetIM.A, HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, 11111111, Löschen bei Neustart, [3cf491c68fec2a0c4a8213ae9370649c] Registrierungsdaten: 0 (No malicious items detected) Ordner: 36 PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Roaming\Funmoods\UpdateProc, In Quarantäne, [eb456dea4a3186b091feb4f8946ecb35], Adware.InstallBrain, C:\ProgramData\IBUpdaterService, In Quarantäne, [6ec22b2cb2c9d363bff26535eb18847c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Delta, In Quarantäne, [38f873e42e4d7cba4b0e259aa360e917], PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.10.0, In Quarantäne, [a68a461105764ee8eb0d79ff03ff728e], PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.10.0\bh, In Quarantäne, [a68a461105764ee8eb0d79ff03ff728e], PUP.Optional.OpenCandy, C:\Users\Christof\AppData\Roaming\OpenCandy, In Quarantäne, [181833244338e74fc6660b6eb34f03fd], PUP.Optional.OpenCandy, C:\Users\Christof\AppData\Roaming\OpenCandy\2BFE7A6CE6F94D6D89C8303FAD05917E, In Quarantäne, [181833244338e74fc6660b6eb34f03fd], PUP.Optional.OpenCandy, C:\Users\Christof\AppData\Roaming\OpenCandy\6BC6529DFEAD44F29836574108E24A8E, In Quarantäne, [181833244338e74fc6660b6eb34f03fd], PUP.Optional.OpenCandy, C:\Users\Christof\AppData\Roaming\OpenCandy\B34BF1AEEF6E4366BAD86B972900A185, In Quarantäne, [181833244338e74fc6660b6eb34f03fd], PUP.Optional.OpenCandy, C:\Users\Christof\AppData\Roaming\OpenCandy\CAAA7B30768C463B8465320075898064, In Quarantäne, [181833244338e74fc6660b6eb34f03fd], PUP.Optional.FileScout.A, C:\Users\Christof\AppData\Roaming\File Scout, In Quarantäne, [37f93c1bf388a88e083c7dfc5aa82dd3], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\img, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\js, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\style, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\components, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\META-INF, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.FaceMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ihflimipbcaljfnojhhknppphnnciiif, In Quarantäne, [68c8bc9b07746ec8beb9d8a8dd259a66], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Roaming\FunmoodsChat\UpdateProc, In Quarantäne, [7fb1b89f18637bbb721a59277a889967], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\softonic, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\softonic\1.5.11.5, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\softonic\1.5.11.5\bh, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], PUP.Optional.Softonic.A, C:\Users\Christof\AppData\Local\Temp\mt_ffx\Softonic, In Quarantäne, [bc7461f647342f07a1213b45867c728e], PUP.Optional.Softonic.A, C:\Users\Christof\AppData\Local\Temp\mt_ffx\Softonic\softonic, In Quarantäne, [bc7461f647342f07a1213b45867c728e], PUP.Optional.Softonic.A, C:\Users\Christof\AppData\Local\Temp\mt_ffx\Softonic\softonic\1.5.11.5, In Quarantäne, [bc7461f647342f07a1213b45867c728e], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\flgs, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\defaults, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\defaults\preferences, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], Dateien: 235 PUP.Optional.BabylonToolBar.A, C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarsrv.exe, In Quarantäne, [60d095c2d3a880b638de98cf48ba30d0], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\softonic\1.5.11.5\softonicTlbr.dll, In Quarantäne, [e050cd8aabd049ed8a4f52dddf23b34d], PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.10.0\deltaTlbr.dll, In Quarantäne, [4ae67fd84338c373a7871b4a7a88d12f], PUP.Optional.BabylonToolBar.A, C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarEng.dll, In Quarantäne, [da5679deb2c9ab8b1afff275bc4640c0], PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.10.0\bh\delta.dll, In Quarantäne, [230d2f280b70310538f5c3a27a88b44c], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\softonic\1.5.11.5\bh\softonic.dll, In Quarantäne, [e44c34230f6c0135439737f844be6f91], PUP.Optional.Conduit.A, C:\Users\Christof\AppData\Roaming\OpenCandy\2BFE7A6CE6F94D6D89C8303FAD05917E\mconduitinstaller.exe, In Quarantäne, [39f76bec99e2d85ebde5ae7035cb30d0], PUP.Optional.FileScout.A, C:\Users\Christof\AppData\Roaming\File Scout\filescout.exe, In Quarantäne, [c66a8acdaad1d6605b89d335a45d5aa6], PUP.Optional.SoftonicTB.A, C:\Users\Christof\Desktop\softonic_ggl_1.5.11.5.exe, In Quarantäne, [56da0057e695092d730c13658f72c739], PUP.Optional.Iminent.A, C:\Users\Christof\AppData\Local\DownloadGuide\Offers\iminent.exe, In Quarantäne, [52de51063b40ec4a61493df1b8499967], PUP.Optional.PriceGong.A, C:\Users\Christof\AppData\Local\DownloadGuide\Offers\pricegong.exe, In Quarantäne, [ac849abd7605d5612512461aa25f8c74], Backdoor.Bot, C:\Windows\Installer\114dafb.msi, In Quarantäne, [c0704e097ffcc76f2a263fee5aa8ee12], PUP.Optional.Conduit.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage, In Quarantäne, [bc74dc7bbac1d16531610f8241c101ff], PUP.Optional.Conduit.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage-journal, In Quarantäne, [5cd485d2f487e650bcd68f02927005fb], PUP.Optional.FaceMoods.A, C:\Program Files (x86)\Mozilla Firefox\searchplugins\fcmdSrch.xml, In Quarantäne, [39f7312608732c0a9c4a1d7f01015aa6], PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\searchplugins\babylon.xml, In Quarantäne, [161a3a1d3f3cc86e20a7118e000260a0], PUP.Optional.BProtector.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\bProtector_extensions.sqlite, In Quarantäne, [f13f391ec2b9320465705b442dd50000], PUP.Optional.BProtector.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\bprotector_prefs.js, In Quarantäne, [8da3193eb3c8989e5185fea10bf7d030], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\searchplugins\delta.xml, In Quarantäne, [3df36aed67145fd70af4ccd34db5857b], PUP.Optional.Babylon.A, C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml, In Quarantäne, [4de3ff58afcc74c2de23b3f20002a25e], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Roaming\Funmoods\UpdateProc\config.dat, In Quarantäne, [eb456dea4a3186b091feb4f8946ecb35], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Roaming\Funmoods\UpdateProc\info.dat, In Quarantäne, [eb456dea4a3186b091feb4f8946ecb35], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Roaming\Funmoods\UpdateProc\STTL.DAT, In Quarantäne, [eb456dea4a3186b091feb4f8946ecb35], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Roaming\Funmoods\UpdateProc\TTL.DAT, In Quarantäne, [eb456dea4a3186b091feb4f8946ecb35], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Roaming\Funmoods\UpdateProc\UpdateTask.exe, In Quarantäne, [eb456dea4a3186b091feb4f8946ecb35], PUP.Funmoods, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bbjciahceamgodcoidkjpchnokgfpphh_0.localstorage, Löschen bei Neustart, [ed43a7b0b6c50333e8685d58857d04fc], PUP.Funmoods, C:\Users\Christof\AppData\Local\funmoods.crx, In Quarantäne, [e44c104784f7bd79f55cd9dc30d29967], Adware.InstallBrain, C:\ProgramData\IBUpdaterService\repository.xml, In Quarantäne, [6ec22b2cb2c9d363bff26535eb18847c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Delta\sqlite3.dll, In Quarantäne, [38f873e42e4d7cba4b0e259aa360e917], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Delta\delta.crx, In Quarantäne, [38f873e42e4d7cba4b0e259aa360e917], PUP.Optional.BProtector.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\bprotector web data, In Quarantäne, [7fb175e24e2d8fa734e0a81cce353fc1], PUP.Optional.BProtector.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences, In Quarantäne, [48e86dea5c1fcd69e134cff561a2e11f], PUP.Optional.Funmoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bbjciahceamgodcoidkjpchnokgfpphh_0.localstorage-journal, Löschen bei Neustart, [ff310b4c3645bb7bba628c52e023be42], PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.10.0\deltaApp.dll, In Quarantäne, [a68a461105764ee8eb0d79ff03ff728e], PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.10.0\deltaEng.dll, In Quarantäne, [a68a461105764ee8eb0d79ff03ff728e], PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.10.0\deltasrv.exe, In Quarantäne, [a68a461105764ee8eb0d79ff03ff728e], PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.10.0\escortShld.dll, In Quarantäne, [a68a461105764ee8eb0d79ff03ff728e], PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.10.0\GUninstaller.exe, In Quarantäne, [a68a461105764ee8eb0d79ff03ff728e], PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.10.0\uninstall.exe, In Quarantäne, [a68a461105764ee8eb0d79ff03ff728e], PUP.Optional.OpenCandy, C:\Users\Christof\AppData\Roaming\OpenCandy\2BFE7A6CE6F94D6D89C8303FAD05917E\5545.ico, In Quarantäne, [181833244338e74fc6660b6eb34f03fd], PUP.Optional.OpenCandy, C:\Users\Christof\AppData\Roaming\OpenCandy\2BFE7A6CE6F94D6D89C8303FAD05917E\EBB77268-338F-4C6A-8590-AD88FED26F4A, In Quarantäne, [181833244338e74fc6660b6eb34f03fd], PUP.Optional.OpenCandy, C:\Users\Christof\AppData\Roaming\OpenCandy\2BFE7A6CE6F94D6D89C8303FAD05917E\OCBrowserHelper_1.0.6.124.exe, In Quarantäne, [181833244338e74fc6660b6eb34f03fd], PUP.Optional.OpenCandy, C:\Users\Christof\AppData\Roaming\OpenCandy\2BFE7A6CE6F94D6D89C8303FAD05917E\version512e990dafdb7.exe, In Quarantäne, [181833244338e74fc6660b6eb34f03fd], PUP.Optional.OpenCandy, C:\Users\Christof\AppData\Roaming\OpenCandy\6BC6529DFEAD44F29836574108E24A8E\PCSU_SL_3.1.2.exe, In Quarantäne, [181833244338e74fc6660b6eb34f03fd], PUP.Optional.OpenCandy, C:\Users\Christof\AppData\Roaming\OpenCandy\B34BF1AEEF6E4366BAD86B972900A185\driverscannerROE.exe, In Quarantäne, [181833244338e74fc6660b6eb34f03fd], PUP.Optional.OpenCandy, C:\Users\Christof\AppData\Roaming\OpenCandy\CAAA7B30768C463B8465320075898064\TuneUpUtilities2012_de-DE.exe, In Quarantäne, [181833244338e74fc6660b6eb34f03fd], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\background.html, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\bg.html, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\dropdown.html, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\manifest.json, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\img\128.png, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\img\16.png, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\img\32.png, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\img\48.png, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\img\64.png, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\img\ajax-loader.gif, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\js\bg.js, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\js\chapi.js, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\js\dropdown.js, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\js\easyXDM.min.js, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\js\FMLoader.js, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\js\greetingmoods.js, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\js\jquery-1.8.3.min.js, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\js\json2.min.js, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\js\rp.min.js, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\2.3.8_0\style\funmoods_chrome_1.0.1.css, In Quarantäne, [18186ee9f4875cdaf5d1bbc259a9fc04], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\chrome.manifest, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\install.rdf, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\components\FFDisp.dll, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\delta.css, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\delta.xul, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\dpk.htm, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\hlprs.js, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\loader.xul, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\mtstart.js, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\serp.js, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\tmplt.js, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\arwDwn.gif, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\closeo.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\help_16.gif, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\home.gif, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\icon_seperator.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\logo.PNG, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\privecy_16_hot.gif, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\sign.jpg, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\specialoffer.gif, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\tellafriend.gif, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\uninstall.gif, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\ae.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\bg.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\ch.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\cn.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\cz.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\de.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\eg.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\en.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\es.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\fr.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\gr.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\he.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\il.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\it.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\ja.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\jp.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\nl.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\no.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\pl.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\pt.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\ro.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\ru.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\sa.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\se.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\sv.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\tr.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\ua.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\content\imgs\flgs\us.png, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\META-INF\manifest.mf, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\META-INF\zigbert.rsa, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbr@delta.com\META-INF\zigbert.sf, In Quarantäne, [57d92f286f0cf34325b5205ed82ae41c], PUP.Optional.FaceMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ihflimipbcaljfnojhhknppphnnciiif\000005.sst, In Quarantäne, [68c8bc9b07746ec8beb9d8a8dd259a66], PUP.Optional.FaceMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ihflimipbcaljfnojhhknppphnnciiif\000008.sst, In Quarantäne, [68c8bc9b07746ec8beb9d8a8dd259a66], PUP.Optional.FaceMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ihflimipbcaljfnojhhknppphnnciiif\000009.log, In Quarantäne, [68c8bc9b07746ec8beb9d8a8dd259a66], PUP.Optional.FaceMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ihflimipbcaljfnojhhknppphnnciiif\CURRENT, In Quarantäne, [68c8bc9b07746ec8beb9d8a8dd259a66], PUP.Optional.FaceMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ihflimipbcaljfnojhhknppphnnciiif\LOCK, In Quarantäne, [68c8bc9b07746ec8beb9d8a8dd259a66], PUP.Optional.FaceMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ihflimipbcaljfnojhhknppphnnciiif\LOG, In Quarantäne, [68c8bc9b07746ec8beb9d8a8dd259a66], PUP.Optional.FaceMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ihflimipbcaljfnojhhknppphnnciiif\LOG.old, In Quarantäne, [68c8bc9b07746ec8beb9d8a8dd259a66], PUP.Optional.FaceMoods.A, C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ihflimipbcaljfnojhhknppphnnciiif\MANIFEST-000007, In Quarantäne, [68c8bc9b07746ec8beb9d8a8dd259a66], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Roaming\FunmoodsChat\UpdateProc\config.dat, In Quarantäne, [7fb1b89f18637bbb721a59277a889967], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Roaming\FunmoodsChat\UpdateProc\info.dat, In Quarantäne, [7fb1b89f18637bbb721a59277a889967], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Roaming\FunmoodsChat\UpdateProc\src.dat, In Quarantäne, [7fb1b89f18637bbb721a59277a889967], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Roaming\FunmoodsChat\UpdateProc\STTL.DAT, In Quarantäne, [7fb1b89f18637bbb721a59277a889967], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Roaming\FunmoodsChat\UpdateProc\TTL.DAT, In Quarantäne, [7fb1b89f18637bbb721a59277a889967], PUP.Optional.FunMoods.A, C:\Users\Christof\AppData\Roaming\FunmoodsChat\UpdateProc\UpdateTask.exe, In Quarantäne, [7fb1b89f18637bbb721a59277a889967], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\softonic\1.5.11.5\softonicApp.dll, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\softonic\1.5.11.5\softonicEng.dll, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\softonic\1.5.11.5\softonicsrv.exe, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], PUP.Optional.Softonic.A, C:\Program Files (x86)\Softonic\softonic\1.5.11.5\uninstall.exe, In Quarantäne, [e0501146c5b63501bc057a0662a0629e], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\chrome.manifest, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\install.rdf, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\mtstart.js, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\softonic.css, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\softonic.xul, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\tmplt.js, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\location_combo.png, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\09.png, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\amazon.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\arwDwn.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\bg_temprature_frame.png, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\bg_window.jpg, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\cancel.png, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\change_location_icon.png, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\dic.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\fcbk.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\flicker.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\googletranslate.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\help_16.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\home.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\images.png, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\location_dropdown.png, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\logo.PNG, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\music.png, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\news.png, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\onsoftware.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\privecy_16_hot.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\radio.png, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\save.png, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\search.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\search.PNG, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\shopping.png, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\srch.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\srch.png, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\stat.png, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\tellafriend.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\Thumbs.db, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\twitter.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\uninstall.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\video.bmp, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\web.png, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\wiki.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\wthrclose.jpg, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\content\imgs\youtube.gif, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.SoftTonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\extensions\ffxtlbra@softonic.com\defaults\preferences\instlPref.js, In Quarantäne, [6ac63e19d3a82d09487bfc845aa823dd], PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://search.babylon.com/?AF=109992&babsrc=adbartrp&mntrId=dcc9ff5c00000000000078929c45f955&q=");), Ersetzt,[ae824017e794b28436d3434728dcce32] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.aflt", "babsst");), Ersetzt,[ee422136483339fd6bd06e1c9e66df21] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babExt", "");), Ersetzt,[de52b2a59ae15fd7d269f1992bd97b85] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babTrack", "affID=109992");), Ersetzt,[5ad6b89f22599e98c3786c1e6f9513ed] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.hardId", "dcc9ff5c00000000000078929c45f955");), Ersetzt,[89a7b2a55f1c1125ce6d3c4e0103f50b] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.id", "dcc9ff5c00000000000078929c45f955");), Ersetzt,[53dd0c4b80fb9d9996a5c9c1d82c02fe] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.instlDay", "15409");), Ersetzt,[003075e280fb63d3cd6e7e0c5ca88b75] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.instlRef", "sst");), Ersetzt,[fa365ff85e1da591d962bfcb40c43ec2] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.newTab", true);), Ersetzt,[ab858fc81d5eed4946f56f1b26de19e7] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://www.delta-search.com/?affID=119776&babsrc=NT_ss&mntrId=dcc9ff5c00000000000078929c45f955");), Ersetzt,[e848ea6dfb8076c067d46e1ca75d3ec2] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");), Ersetzt,[8fa1ef6853282e08d5665a300ff544bc] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");), Ersetzt,[07293d1aabd061d551ea7d0d84807f81] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.smplGrp", "none");), Ersetzt,[c16fd87f5d1e92a445f690fad62efd03] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.srcExt", "ss");), Ersetzt,[e54b3b1ccdae6ec823184347f410bc44] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9");), Ersetzt,[e64a5403dba03cfab18aeb9fa0648080] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");), Ersetzt,[8ca42c2ba6d52d098ab157331de7ef11] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.178:33:09");), Ersetzt,[9f913324de9daf872c0f6e1c3dc7e020] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");), Ersetzt,[3000cb8c5c1fcd6946f5b3d74aba4cb4] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.admin", false);), Ersetzt,[dc546bec2c4fa98dfb47256528dca15f] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.aflt", "babsst");), Ersetzt,[f33d12450c6f092db48eb0da14f054ac] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");), Ersetzt,[6cc4db7c9eddd561bf83bcce4cb832ce] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.autoRvrt", "false");), Ersetzt,[e54b451289f2ab8bc979cfbb986c8e72] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.dfltLng", "en");), Ersetzt,[7eb21c3b96e53afc5ae85238aa5ac739] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.excTlbr", false);), Ersetzt,[d7597bdcbfbc0135be84305a9272d729] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.id", "dcc9ff5c00000000000078929c45f955");), Ersetzt,[8ea2a3b49cdf2b0bbd85becc0ff5d12f] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.instlDay", "15757");), Ersetzt,[64ccde79d8a3221470d236542cd8c43c] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.instlRef", "sst");), Ersetzt,[fa3684d3a1da0b2bd66cc9c146be8779] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.newTab", false);), Ersetzt,[bb75da7d93e88caaf74bfa90ba4aa858] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.prdct", "delta");), Ersetzt,[69c7c394a3d8e254e2608ffb6c98639d] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.prtnrId", "delta");), Ersetzt,[30007ed92853da5c00424c3e2cd8ad53] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.rvrt", "false");), Ersetzt,[6dc31e399cdfec4a8cb6d6b408fc57a9] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.smplGrp", "none");), Ersetzt,[62cee67198e37db98bb792f8b64e6997] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.tlbrId", "base");), Ersetzt,[34fcabac1b60ee48bd85b0da19ebe61a] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.tlbrSrchUrl", "");), Ersetzt,[4ae6aaadf58651e50a38008a1ce81de3] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsn", "1.8.10.0");), Ersetzt,[230d54035d1ea78f053d7c0e34d0758b] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsnTs", "1.8.10.022:58:29");), Ersetzt,[c56b7addbbc0db5b80c22169c1438f71] PUP.Optional.Delta.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsni", "1.8.10.0");), Ersetzt,[6cc45502c3b848ee1230bcce4bb9ae52] PUP.Optional.Softonic.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.softonic_i.tlbrSrchUrl", "hxxp://search.softonic.com/MON00001/tb_v1?SearchSource=1&cc=&q=");), Ersetzt,[c36da9aefa81013579cd751553b19c64] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babTrack", "affID=109992");), Ersetzt,[67c974e3cbb07db98d288900a36159a7] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babExt", "");), Ersetzt,[40f0b5a2fc7f999dc2f3abde17ed34cc] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.srcExt", "ss");), Ersetzt,[e749c4932655082eded70188709444bc] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.id", "dcc9ff5c00000000000078929c45f955");), Ersetzt,[28081245255637ff0ca9a4e5f212a25e] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.hardId", "dcc9ff5c00000000000078929c45f955");), Ersetzt,[8ba5d681304b31057342771244c02ad6] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.instlDay", "15409");), Ersetzt,[e34d282f017a3ff730857f0ace3638c8] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");), Ersetzt,[ca6696c13645f93d268fcebbf80c02fe] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");), Ersetzt,[2c043c1ba3d85bdbe8cdd8b128dcbe42] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.178:33:09");), Ersetzt,[f83865f29cdf40f6f7be1178ea1a6d93] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");), Ersetzt,[34fc2f28b0cbb581ad08701941c305fb] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");), Ersetzt,[68c8d285ef8cf640e5d08ffa2dd76c94] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.aflt", "babsst");), Ersetzt,[70c0f4638fec86b0338240497490f808] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.smplGrp", "none");), Ersetzt,[e54b6dea651650e6c4f1513862a225db] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9");), Ersetzt,[40f09eb9017a82b45362e1a83cc845bb] PUP.Optional.Babylon.A, C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.instlRef", "sst");), Ersetzt,[a9876aedb8c3a294e1d44c3d08fc6898] Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.211 - Bericht erstellt am 30/05/2014 um 00:57:34 # Aktualisiert 26/05/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Christof - CHRISTOF-PC # Gestartet von : C:\Users\Christof\Downloads\adwcleaner_3.211.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : hsswd [#] Dienst Gelöscht : SystemStoreService ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\SearchProtect Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\BitGuard Ordner Gelöscht : C:\ProgramData\hotspot shield Ordner Gelöscht : C:\ProgramData\Partner Ordner Gelöscht : C:\ProgramData\Tarma Installer Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\hotspot shield Ordner Gelöscht : C:\Program Files (x86)\BabylonToolbar Ordner Gelöscht : C:\Program Files (x86)\Delta Ordner Gelöscht : C:\Program Files (x86)\Softonic Ordner Gelöscht : C:\Program Files (x86)\SoftwareUpdater Ordner Gelöscht : C:\Program Files (x86)\InnoGames_International Ordner Gelöscht : C:\Windows\SysWOW64\SearchProtect Ordner Gelöscht : C:\Users\Christof\AppData\Local\Conduit Ordner Gelöscht : C:\Users\Christof\AppData\Local\DownloadGuide Ordner Gelöscht : C:\Users\Christof\AppData\Local\Pokki Ordner Gelöscht : C:\Users\Christof\AppData\Local\PutLockerDownloader Ordner Gelöscht : C:\Users\Christof\AppData\Local\SearchProtect Ordner Gelöscht : C:\Users\Christof\AppData\Local\Software_Updater Ordner Gelöscht : C:\Users\Christof\AppData\Local\SoftwareUpdater Ordner Gelöscht : C:\Users\Christof\AppData\Local\Temp\mt_ffx Ordner Gelöscht : C:\Users\Christof\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\Christof\AppData\LocalLow\PriceGong Ordner Gelöscht : C:\Users\Christof\AppData\LocalLow\InnoGames_International Ordner Gelöscht : C:\Users\Christof\AppData\Roaming\BabSolution Ordner Gelöscht : C:\Users\Christof\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\Christof\AppData\Roaming\dvdvideosoftiehelpers Ordner Gelöscht : C:\Users\Christof\AppData\Roaming\Funmoods Ordner Gelöscht : C:\Users\Christof\AppData\Roaming\hotspot shield Ordner Gelöscht : C:\Users\Christof\AppData\Roaming\Software Updater Ordner Gelöscht : C:\Users\Christof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard Ordner Gelöscht : C:\Users\Christof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movie2KDownloader.com Ordner Gelöscht : C:\Users\Christof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Datei Gelöscht : C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\Extensions\movie2kdownloader@movie2kdownloader.com.xpi Datei Gelöscht : C:\END Datei Gelöscht : C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\searchplugins\BrowserProtect.xml Datei Gelöscht : C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\user.js Datei Gelöscht : C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.delta-search.com_0.localstorage Datei Gelöscht : C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.delta-search.com_0.localstorage-journal Datei Gelöscht : C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.triple-search.com_0.localstorage Datei Gelöscht : C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.triple-search.com_0.localstorage-journal Datei Gelöscht : C:\Windows\System32\Tasks\BitGuard Datei Gelöscht : C:\Windows\System32\Tasks\EPUpdater Datei Gelöscht : C:\Windows\System32\Tasks\Software Updater Ui Datei Gelöscht : C:\Windows\System32\Tasks\Software Updater ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\blaofbhgbmeikidhlkmjhbkbfohpgekf Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp Schlüssel Gelöscht : HKCU\Software\Classes\*\shell\pokki Schlüssel Gelöscht : HKCU\Software\Classes\AllFileSystemObjects\shell\pokki Schlüssel Gelöscht : HKCU\Software\Classes\Directory\shell\pokki Schlüssel Gelöscht : HKCU\Software\Classes\Drive\shell\pokki Schlüssel Gelöscht : HKCU\Software\Classes\Folder\shell\pokki Schlüssel Gelöscht : HKCU\Software\Classes\lnkfile\shell\pokki Schlüssel Gelöscht : HKCU\Software\Classes\pokki Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Babylon.dskBnd Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylnApp.appCore Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\driverscanner Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escrtBtn.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Movie2KDownloader Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitUninstaller_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitUninstaller_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoods_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoods_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsLatest_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsLatest_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\mconduitinstaller_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\mconduitinstaller_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Movie2KDownloader_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Movie2KDownloader_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\softonic_ggl_1_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\softonic_ggl_1_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftwareUpdater_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftwareUpdater_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS Schlüssel Gelöscht : HKCU\Software\f558dd0e26ae912 Schlüssel Gelöscht : HKLM\SOFTWARE\f558dd0e26ae912 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT1561552 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2832595 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_mousometer-gadget_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_mousometer-gadget_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B15F118E-AF21-45E8-A809-29FDD7362565} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A3E2F089-DDBB-4CBF-B06C-5D44DA316ED3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11D9E165-B8C1-4734-A56C-BC4FCACA966B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E69D4A59-73DE-4E38-9FB3-740EC4D9060D} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{58275C71-6CC8-47FC-93E0-B91379D40A80} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CF034EA-7B46-48D3-8895-8A14B32AE445} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16B19B8D-79BE-4101-A222-531AB4993225} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D45C11E1-7E4E-43D6-971C-21B5164BF0AB} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{942CD1D4-9CC1-4D31-876A-EA8F489F7A59}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{942CD1D4-9CC1-4D31-876A-EA8F489F7A59}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} Schlüssel Gelöscht : HKCU\Software\APN PIP Schlüssel Gelöscht : HKCU\Software\BabSolution Schlüssel Gelöscht : HKCU\Software\Delta Schlüssel Gelöscht : HKCU\Software\filescout Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\Pokki Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\Software\covus freemium gmbh Schlüssel Gelöscht : HKLM\Software\Delta Schlüssel Gelöscht : HKLM\Software\PIP Schlüssel Gelöscht : HKLM\Software\SearchProtect Schlüssel Gelöscht : HKLM\Software\Softonic Schlüssel Gelöscht : HKLM\Software\systweak Schlüssel Gelöscht : HKLM\Software\Uniblue Schlüssel Gelöscht : HKLM\Software\InnoGames_International Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{177586E7-E42E-4F38-83D1-D15B4AF5B714} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1ClickDownload Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Funmoods Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hotspotshield Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InnoGames_International Toolbar Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Speedchecker Limited Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17041 -\\ Mozilla Firefox v13.0.1 (de) [ Datei : C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\prefs.js ] Zeile gelöscht : user_pref("avg.install.userHPSettings", "hxxp://isearch.babylon.com/?babsrc=HP_def_gr2&affID=119776"); Zeile gelöscht : user_pref("avg.install.userSPSettings", "Delta Search"); Zeile gelöscht : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com"); Zeile gelöscht : user_pref("extensions.enabledAddons", "battlefieldheroespatcher@ea.com:5.0.127.0,{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}:1.0,ffxtlbr@funmoods.com:1.5.1,{972ce4c6-7e08-4474-a285-3208198ce6fd}:13.0.1"); Zeile gelöscht : user_pref("extensions.funmoods.aflt", "orgnl"); Zeile gelöscht : user_pref("extensions.funmoods.autoRvrt", false); Zeile gelöscht : user_pref("extensions.funmoods.dfltLng", ""); Zeile gelöscht : user_pref("extensions.funmoods.dfltSrch", false); Zeile gelöscht : user_pref("extensions.funmoods.dnsErr", true); Zeile gelöscht : user_pref("extensions.funmoods.envrmnt", "production"); Zeile gelöscht : user_pref("extensions.funmoods.excTlbr", true); Zeile gelöscht : user_pref("extensions.funmoods.fmupdtFirst", false); Zeile gelöscht : user_pref("extensions.funmoods.hmpg", false); Zeile gelöscht : user_pref("extensions.funmoods.hmpgUrl", "hxxp://searchfunmoods.com/?f=1&a=orgnl&chnl=&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzytB0E0EtAtAtA0F0FyD0CtN0D0Tzu0CtAyEyBtN1L2XzutBtFtBtFtDtFtAyEyE&cr=949259982"); Zeile gelöscht : user_pref("extensions.funmoods.id", "7A79192EE333FF5C"); Zeile gelöscht : user_pref("extensions.funmoods.instlDay", "15686"); Zeile gelöscht : user_pref("extensions.funmoods.instlRef", ""); Zeile gelöscht : user_pref("extensions.funmoods.isdcmntcmplt", true); Zeile gelöscht : user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2215:27:28"); Zeile gelöscht : user_pref("extensions.funmoods.mntrvrsn", "1.3.0"); Zeile gelöscht : user_pref("extensions.funmoods.newTab", false); Zeile gelöscht : user_pref("extensions.funmoods.newTabUrl", "hxxp://searchfunmoods.com/?f=2&a=orgnl&chnl=&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzytB0E0EtAtAtA0F0FyD0CtN0D0Tzu0CtAyEyBtN1L2XzutBtFtBtFtDtFtAyEyE&cr=949259982"); Zeile gelöscht : user_pref("extensions.funmoods.prdct", "funmoods"); Zeile gelöscht : user_pref("extensions.funmoods.prtnrId", "funmoods"); Zeile gelöscht : user_pref("extensions.funmoods.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.funmoods.srchPrvdr", "Search"); Zeile gelöscht : user_pref("extensions.funmoods.tlbrId", "base"); Zeile gelöscht : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://searchfunmoods.com/?f=3&a=orgnl&chnl=&cd=2XzuyEtN2Y1L1QzuyB0AyBzytCzytB0E0EtAtAtA0F0FyD0CtN0D0Tzu0CtAyEyBtN1L2XzutBtFtBtFtDtFtAyEyE&cr=949259982&q=[...] Zeile gelöscht : user_pref("extensions.funmoods.vrsn", "1.5.23.22"); Zeile gelöscht : user_pref("extensions.funmoods.vrsnTs", "1.5.23.2215:27:28"); Zeile gelöscht : user_pref("extensions.funmoods.vrsni", "1.5.23.22"); Zeile gelöscht : user_pref("extensions.funmoods_i.newTab", false); Zeile gelöscht : user_pref("extensions.funmoods_i.smplGrp", "none"); Zeile gelöscht : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2215:27:28"); Zeile gelöscht : user_pref("extensions.softonic_i.aflt", "orgnl"); Zeile gelöscht : user_pref("extensions.softonic_i.dfltLng", ""); Zeile gelöscht : user_pref("extensions.softonic_i.excTlbr", false); Zeile gelöscht : user_pref("extensions.softonic_i.id", "dcc9ff5c00000000000078929c45f954"); Zeile gelöscht : user_pref("extensions.softonic_i.instlDay", "15562"); Zeile gelöscht : user_pref("extensions.softonic_i.instlRef", "MON00001"); Zeile gelöscht : user_pref("extensions.softonic_i.newTab", false); Zeile gelöscht : user_pref("extensions.softonic_i.prdct", "softonic"); Zeile gelöscht : user_pref("extensions.softonic_i.prtnrId", "softonic"); Zeile gelöscht : user_pref("extensions.softonic_i.smplGrp", "eng7"); Zeile gelöscht : user_pref("extensions.softonic_i.tlbrId", "eng7"); Zeile gelöscht : user_pref("extensions.softonic_i.vrsn", "1.5.11.5"); Zeile gelöscht : user_pref("extensions.softonic_i.vrsnTs", "1.5.11.516:14:59"); Zeile gelöscht : user_pref("extensions.softonic_i.vrsni", "1.5.11.5"); -\\ Google Chrome v [ Datei : C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN23629055511649226&ctid=CT3290520&UM=2 Gelöscht [Search Provider] : hxxp://en.softonic.com/s/{searchTerms} Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&affID=119776&babsrc=SP_ss&mntrId=dcc9ff5c00000000000078929c45f955 Gelöscht [Extension] : blaofbhgbmeikidhlkmjhbkbfohpgekf Gelöscht [Extension] : booedmolknjekdopkepjjeckmjkdpfgl Gelöscht [Extension] : eooncjejnppfjjklapaamhcdmjbilmde Gelöscht [Extension] : flpcjncodpafbgdpnkljologafpionhb Gelöscht [Extension] : nikpibnbobmbdbheedjfogjlikpgpnhp ************************* AdwCleaner[R0].txt - [22498 octets] - [30/05/2014 00:56:45] AdwCleaner[S0].txt - [21410 octets] - [30/05/2014 00:57:34] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [21471 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Christof on 30.05.2014 at 1:10:23,71 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2465417766-3482814047-1650821192-1001\Software\sweetim ~~~ Files Successfully deleted: [File] C:\Windows\syswow64\sho5043.tmp Successfully deleted: [File] C:\Windows\syswow64\sho72F0.tmp Successfully deleted: [File] C:\Windows\syswow64\sho7DF2.tmp Successfully deleted: [File] C:\Windows\syswow64\shoDC66.tmp ~~~ Folders Successfully deleted: [Folder] "C:\Users\Christof\AppData\Roaming\getrighttogo" Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{032EF450-0800-4437-A0DB-76D5F0D0A048} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{03CEF9D9-0510-4D23-AE61-56191F33B634} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{04BF4C1A-8D58-402D-A763-A84153C42834} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{050F00ED-EC50-49FC-8163-3BB038D5E2C9} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{0A71039C-D0CB-4F65-8164-871AB067B037} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{0AB8010D-64A8-487B-8EB0-F2DCDFD6834B} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{18122ADF-5E2F-4FBC-99B6-0933929ED417} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{24ED6AAB-4D7F-4C19-890F-C42BD01F1F88} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{2A0772AC-ED74-47A0-A19A-9D189920F4C7} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{2D8B2C0D-F2BC-4260-AFEA-098F2890DA5E} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{374A9441-1D47-400D-A353-082D702507A7} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{3B33B4CF-469F-4E6F-80AD-C73A142F8A2E} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{41B1A28D-6CB5-484E-A434-7548B4BF7688} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{424A0319-2E22-4374-9B5C-C9605BAFB59F} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{44B504D3-9B31-43FE-96E3-C27821E3B0A3} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{4661E909-CADB-4358-83D0-240923766A5B} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{47645969-2242-4D1F-A6C7-D58BE8E522BC} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{476E054B-8BFC-4D7A-AC38-7490FAAC4F29} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{4C99D847-831E-40EB-B7F0-AB94F8289A97} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{4DD10AFD-6857-450B-98DA-043801F699A3} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{59956CE5-9281-4942-A8A9-10F6ACEE8F93} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{5A4C70AC-EA15-439F-9089-1858D77A3E0F} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{5AA1B7E1-DE9B-4083-958E-A90E4039E058} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{5ACBD650-7E8D-4268-BF1B-1FF677CED884} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{5EF8157F-040B-4FBE-B401-DB42146D99E7} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{6198C887-A84D-4F48-BE82-F28D8A8C0051} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{68D6ED16-5572-452F-971F-9627780D5F81} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{6FC2C791-D778-4A7F-8CC5-72DBAECCE7F4} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{72E73856-5AD1-48EE-A148-F3BE5E579F98} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{7530EB09-C1AA-4E25-98F1-9E635A733E2D} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{761ADBD7-E201-486D-B37E-411AE192E398} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{7A6AFB71-753F-4CFC-8BB9-6A706227949E} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{7B6E0692-EDD0-4DEF-8F08-006738EA13D3} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{7DBB2BCE-13EE-4AEF-82F6-96DEB75A37C0} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{8A4C93EB-5B50-446C-B974-1912E107E6AF} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{8AD92C75-FA87-4B75-AFF5-D1BC2BEE790F} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{8EBA62CC-6147-4CED-ACA9-87A4C1CB8ACF} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{9ABC21D6-06D2-4BCF-8A76-864CA6235329} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{9BBDE844-85D4-467D-AD9E-8F05F6A87CEF} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{A1A071DA-978D-4EA4-9B84-7673342C49CF} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{A84812A4-E07E-45D7-BB01-8783C4EEB1F3} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{A89C91AC-4F7C-4C6D-A090-ADE271E032E9} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{AD04A2CC-29A8-4674-93F1-F059B3C6AA52} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{AE8BC3B8-5FBE-49E6-B2B7-C00CCA43B6AE} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{B22434A8-A5A7-4270-BE7E-CBC08D4206FC} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{B3F45D0E-7C87-447C-8D83-EF9FA3F192CA} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{B588DCA9-73E3-45BF-8AC4-A6B7F585826C} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{B5C32B2F-26F9-4665-98AD-33722A0B65C9} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{B6ECDAA7-8643-401E-B1A5-3ADFCE94DCF1} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{C1E016B3-9B50-4BCB-83AF-648F629EAA61} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{C542B765-ECA0-4513-9DF7-AD5DD29A92AB} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{CBF58E48-A219-4B49-A8C4-71AABE87B681} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{D1908A67-A0B0-44C6-B26A-52C2AF0C032E} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{E03F3A2A-5D41-4C7D-A04D-CE4F6E9F3EF9} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{E2BE421E-6A31-40DF-ADF6-001278DC609F} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{E355E46E-AB21-400D-938F-F859788B6B16} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{E71B9F14-EF26-4D5C-A979-E0739FFDEAF1} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{EAEA23D9-82E2-408E-A3E0-6A01D412956C} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{EBB33F22-4949-4270-8F6A-D3BEE55C8B62} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{EF187BD4-48C8-46CB-B5A1-5511D5F5894A} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{F4827740-AE1A-4DEF-BA76-9BFE80B818A3} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{FD69A622-E076-49FE-B092-D30ED605795F} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{FF645675-F27E-4B38-969F-AF4B7E9500E5} ~~~ FireFox Successfully deleted: [File] C:\user.js Emptied folder: C:\Users\Christof\AppData\Roaming\mozilla\firefox\profiles\oud4yekh.default\minidumps [5 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 30.05.2014 at 1:32:28,06 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Geändert von Gytoro (30.05.2014 um 00:06 Uhr) |
30.05.2014, 00:36 | #8 |
| TR/BProtector.Gen Ergebniss des JRT: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Christof on 30.05.2014 at 1:10:23,71 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2465417766-3482814047-1650821192-1001\Software\sweetim ~~~ Files Successfully deleted: [File] C:\Windows\syswow64\sho5043.tmp Successfully deleted: [File] C:\Windows\syswow64\sho72F0.tmp Successfully deleted: [File] C:\Windows\syswow64\sho7DF2.tmp Successfully deleted: [File] C:\Windows\syswow64\shoDC66.tmp ~~~ Folders Successfully deleted: [Folder] "C:\Users\Christof\AppData\Roaming\getrighttogo" Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{032EF450-0800-4437-A0DB-76D5F0D0A048} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{03CEF9D9-0510-4D23-AE61-56191F33B634} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{04BF4C1A-8D58-402D-A763-A84153C42834} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{050F00ED-EC50-49FC-8163-3BB038D5E2C9} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{0A71039C-D0CB-4F65-8164-871AB067B037} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{0AB8010D-64A8-487B-8EB0-F2DCDFD6834B} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{18122ADF-5E2F-4FBC-99B6-0933929ED417} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{24ED6AAB-4D7F-4C19-890F-C42BD01F1F88} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{2A0772AC-ED74-47A0-A19A-9D189920F4C7} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{2D8B2C0D-F2BC-4260-AFEA-098F2890DA5E} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{374A9441-1D47-400D-A353-082D702507A7} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{3B33B4CF-469F-4E6F-80AD-C73A142F8A2E} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{41B1A28D-6CB5-484E-A434-7548B4BF7688} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{424A0319-2E22-4374-9B5C-C9605BAFB59F} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{44B504D3-9B31-43FE-96E3-C27821E3B0A3} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{4661E909-CADB-4358-83D0-240923766A5B} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{47645969-2242-4D1F-A6C7-D58BE8E522BC} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{476E054B-8BFC-4D7A-AC38-7490FAAC4F29} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{4C99D847-831E-40EB-B7F0-AB94F8289A97} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{4DD10AFD-6857-450B-98DA-043801F699A3} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{59956CE5-9281-4942-A8A9-10F6ACEE8F93} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{5A4C70AC-EA15-439F-9089-1858D77A3E0F} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{5AA1B7E1-DE9B-4083-958E-A90E4039E058} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{5ACBD650-7E8D-4268-BF1B-1FF677CED884} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{5EF8157F-040B-4FBE-B401-DB42146D99E7} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{6198C887-A84D-4F48-BE82-F28D8A8C0051} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{68D6ED16-5572-452F-971F-9627780D5F81} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{6FC2C791-D778-4A7F-8CC5-72DBAECCE7F4} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{72E73856-5AD1-48EE-A148-F3BE5E579F98} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{7530EB09-C1AA-4E25-98F1-9E635A733E2D} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{761ADBD7-E201-486D-B37E-411AE192E398} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{7A6AFB71-753F-4CFC-8BB9-6A706227949E} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{7B6E0692-EDD0-4DEF-8F08-006738EA13D3} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{7DBB2BCE-13EE-4AEF-82F6-96DEB75A37C0} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{8A4C93EB-5B50-446C-B974-1912E107E6AF} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{8AD92C75-FA87-4B75-AFF5-D1BC2BEE790F} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{8EBA62CC-6147-4CED-ACA9-87A4C1CB8ACF} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{9ABC21D6-06D2-4BCF-8A76-864CA6235329} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{9BBDE844-85D4-467D-AD9E-8F05F6A87CEF} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{A1A071DA-978D-4EA4-9B84-7673342C49CF} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{A84812A4-E07E-45D7-BB01-8783C4EEB1F3} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{A89C91AC-4F7C-4C6D-A090-ADE271E032E9} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{AD04A2CC-29A8-4674-93F1-F059B3C6AA52} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{AE8BC3B8-5FBE-49E6-B2B7-C00CCA43B6AE} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{B22434A8-A5A7-4270-BE7E-CBC08D4206FC} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{B3F45D0E-7C87-447C-8D83-EF9FA3F192CA} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{B588DCA9-73E3-45BF-8AC4-A6B7F585826C} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{B5C32B2F-26F9-4665-98AD-33722A0B65C9} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{B6ECDAA7-8643-401E-B1A5-3ADFCE94DCF1} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{C1E016B3-9B50-4BCB-83AF-648F629EAA61} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{C542B765-ECA0-4513-9DF7-AD5DD29A92AB} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{CBF58E48-A219-4B49-A8C4-71AABE87B681} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{D1908A67-A0B0-44C6-B26A-52C2AF0C032E} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{E03F3A2A-5D41-4C7D-A04D-CE4F6E9F3EF9} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{E2BE421E-6A31-40DF-ADF6-001278DC609F} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{E355E46E-AB21-400D-938F-F859788B6B16} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{E71B9F14-EF26-4D5C-A979-E0739FFDEAF1} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{EAEA23D9-82E2-408E-A3E0-6A01D412956C} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{EBB33F22-4949-4270-8F6A-D3BEE55C8B62} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{EF187BD4-48C8-46CB-B5A1-5511D5F5894A} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{F4827740-AE1A-4DEF-BA76-9BFE80B818A3} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{FD69A622-E076-49FE-B092-D30ED605795F} Successfully deleted: [Empty Folder] C:\Users\Christof\appdata\local\{FF645675-F27E-4B38-969F-AF4B7E9500E5} ~~~ FireFox Successfully deleted: [File] C:\user.js Emptied folder: C:\Users\Christof\AppData\Roaming\mozilla\firefox\profiles\oud4yekh.default\minidumps [5 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 30.05.2014 at 1:32:28,06 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02 Ran by Christof (administrator) on CHRISTOF-PC on 30-05-2014 01:42:51 Running from C:\Users\Christof\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (SurfRight B.V.) C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (ASUS) C:\Windows\AsScrPro.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryRemind.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe () C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== - HKLM\...\Run: [VizorHtmlDialog.exe] => C:\Program Files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe [1123664 2010-10-08] (Trend Micro Inc.) HKLM\...\Run: [Trend Micro Client Framework] => C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [192520 2010-10-12] (Trend Micro Inc.) HKLM\...\Run: [Trend Micro Titanium] => C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe [322384 2010-09-17] (Trend Micro Inc.) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-05-17] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2785064 2011-05-05] (Synaptics Incorporated) HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation) HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [97064 2011-05-05] (Synaptics Incorporated) HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" HKLM\...\Run: [Setwallpaper] => c:\programdata\SetWallpaper.cmd HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-03-15] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Nuance PDF Reader-reminder] => C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe [328992 2008-11-03] (Nuance Communications, Inc.) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme) HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] () HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-09] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] - rmdir /s /q "\SearchProtect" HKU\S-1-5-21-2465417766-3482814047-1650821192-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-06] (Acresso Corporation) HKU\S-1-5-21-2465417766-3482814047-1650821192-1001\...\Run: [GoogleChromeAutoLaunch_9DC73BAD139DCCFFA56EA65F10CB0EF3] => C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe [860488 2014-05-14] (Google Inc.) HKU\S-1-5-21-2465417766-3482814047-1650821192-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) AppInit_DLLs: c:\Windows\System32\nvinitx.dll => c:\Windows\System32\nvinitx.dll [226920 2011-05-10] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.at/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg.dll (Trend Micro Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: TmBpIeBHO Class - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe64.dll (Trend Micro Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.254 FireFox: ======== FF ProfilePath: C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default FF NewTab: user_pref("browser.newtab.url", ""); FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: about:home|hxxp://www.giga.de/androidnews/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) FF Plugin HKCU: @greentube.com/GreenWebPlayer - C:\Games\GreenWebPlayer\npgreenwebplayer.dll (Greentube Internet Entertainment Solutions GmbH) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Christof\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Christof\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Christof\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Christof\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Christof\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Christof\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: thehappycloud.com/HappyCloudPlugin - C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud) FF Plugin ProgramFiles/Appdata: C:\Users\Christof\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google) FF Plugin ProgramFiles/Appdata: C:\Users\Christof\AppData\Roaming\mozilla\plugins\npo1d.dll (Google) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Battlefield Heroes Updater - C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\Extensions\battlefieldheroespatcher@ea.com [2012-02-19] FF Extension: Hotspot Shield Extension - C:\Program Files (x86)\Mozilla Firefox\extensions\afproxy@anchorfree.com [2014-01-10] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2012-06-25] FF HKLM-x32\...\Firefox\Extensions: [{22C7F6C6-8D67-4534-92B5-529A0EC09405}] - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\firefoxextension\ FF Extension: Trend Micro NSC Firefox Extension - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\firefoxextension\ [] FF HKCU\...\Firefox\Extensions: [{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}] - C:\Users\Christof\AppData\Roaming\13001.027 Chrome: ======= CHR HomePage: https://www.google.at/ CHR StartupUrls: "https://www.google.at/" CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll No File CHR Plugin: (GreenWebPlayer) - C:\Games\GreenWebPlayer\npgreenwebplayer.dll (Greentube Internet Entertainment Solutions GmbH) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Zeon Plus) - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Users\Christof\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Extension: (YouTube) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-07-10] CHR Extension: (Adblock Plus) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-03-22] CHR Extension: (Google-Suche) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-07-10] CHR Extension: (Dark Vibe) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkckeanhmkjaechlhllmapjaaglgpcbj [2012-07-11] CHR Extension: (Google Wallet) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-27] CHR Extension: (Google Mail) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-07-10] CHR HKCU\...\Chrome\Extension: [nipcdlfhdehdhmajficeeocjdbdhacdn] - C:\Users\Christof\AppData\Local\CRE\nipcdlfhdehdhmajficeeocjdbdhacdn.crx [2013-04-25] CHR HKLM-x32\...\Chrome\Extension: [nipcdlfhdehdhmajficeeocjdbdhacdn] - C:\Users\Christof\AppData\Local\CRE\nipcdlfhdehdhmajficeeocjdbdhacdn.crx [2013-04-25] CHR StartMenuInternet: Google Chrome - C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG) R2 hmpalertsvc; C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1876816 2014-04-16] (SurfRight B.V.) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2012-02-04] () S4 TiMiniService; C:\Program Files\Trend Micro\Titanium\TiMiniService.exe [241488 2010-09-17] (Trend Micro Inc.) S3 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 [X] S2 Hamachi2Svc; "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s [X] S2 TuneUp.UtilitiesSvc; "C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe" [X] ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-08-22] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-05-09] (Avira Operations GmbH & Co. KG) R2 hmpalert; C:\Windows\system32\drivers\hmpalert.sys [93144 2014-04-16] () R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [44744 2013-11-13] (AnchorFree Inc.) S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114560 2009-07-24] (Huawei Technologies Co., Ltd.) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-08-22] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-05-30] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R2 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [90704 2010-09-17] (Trend Micro Inc.) R2 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [144464 2010-09-17] (Trend Micro Inc.) R2 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [67664 2010-09-17] (Trend Micro Inc.) R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [105552 2010-09-17] (Trend Micro Inc.) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-17] () S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-30 01:32 - 2014-05-30 01:32 - 00008193 _____ () C:\Users\Christof\Desktop\JRT.txt 2014-05-30 01:10 - 2014-05-30 01:10 - 00000000 ____D () C:\Windows\ERUNT 2014-05-30 01:08 - 2014-05-30 01:08 - 01016261 _____ (Thisisu) C:\Users\Christof\Downloads\JRT.exe 2014-05-30 01:07 - 2014-05-30 01:07 - 00000000 ____D () C:\Users\Christof\Desktop\Troja-Borard 2014-05-30 00:57 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-05-30 00:56 - 2014-05-30 01:00 - 00000000 ____D () C:\AdwCleaner 2014-05-30 00:55 - 2014-05-30 00:55 - 01327971 _____ () C:\Users\Christof\Downloads\adwcleaner_3.211.exe 2014-05-30 00:10 - 2014-05-30 01:06 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-30 00:09 - 2014-05-30 00:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-30 00:09 - 2014-05-30 00:09 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-30 00:09 - 2014-05-30 00:09 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-30 00:09 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-30 00:09 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-30 00:09 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-30 00:06 - 2014-05-30 00:06 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Christof\Downloads\mbam-setup-2.0.2.1012.exe 2014-05-28 19:43 - 2014-05-28 19:43 - 00048461 _____ () C:\ComboFix.txt 2014-05-28 18:47 - 2014-05-28 19:43 - 00000000 ____D () C:\Qoobox 2014-05-28 18:47 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-05-28 18:47 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-05-28 18:47 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-05-28 18:47 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-05-28 18:47 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-05-28 18:47 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-05-28 18:47 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-05-28 18:47 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-05-28 18:46 - 2014-05-28 19:05 - 00000000 ____D () C:\Windows\erdnt 2014-05-28 18:45 - 2014-05-30 01:02 - 00065536 _____ () C:\Windows\system32\Ikeext.etl 2014-05-28 18:35 - 2014-05-28 18:35 - 05203612 _____ (Swearware) C:\Users\Christof\Downloads\ComboFix (1).exe 2014-05-28 18:34 - 2014-05-28 18:35 - 05203612 ____R (Swearware) C:\Users\Christof\Downloads\ComboFix.exe 2014-05-28 18:33 - 2014-05-28 18:33 - 00003274 _____ () C:\Windows\System32\Tasks\{E9277147-9DFA-4584-ACC7-2601BC6B2844} 2014-05-28 18:21 - 2014-05-28 18:21 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-05-28 18:19 - 2014-05-28 18:19 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Christof\Downloads\revosetup95.exe 2014-05-27 17:05 - 2014-05-27 17:11 - 00045760 _____ () C:\Users\Christof\Downloads\Addition.txt 2014-05-27 17:03 - 2014-05-30 01:42 - 00024046 _____ () C:\Users\Christof\Downloads\FRST.txt 2014-05-27 17:03 - 2014-05-30 01:42 - 00000000 ____D () C:\FRST 2014-05-27 17:00 - 2014-05-27 17:01 - 02066944 _____ (Farbar) C:\Users\Christof\Downloads\FRST64.exe 2014-05-27 02:03 - 2014-05-27 02:20 - 00017914 _____ () C:\Users\Christof\Documents\hijackthis.log 2014-05-27 01:59 - 2014-05-27 01:59 - 00961360 _____ (Chip Digital GmbH) C:\Users\Christof\Downloads\HijackThis - CHIP-Installer.exe 2014-05-27 01:43 - 2014-05-27 01:43 - 755762801 _____ () C:\Windows\MEMORY.DMP 2014-05-27 01:36 - 2014-05-27 01:36 - 00002072 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-05-27 01:36 - 2014-05-27 01:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-05-27 01:35 - 2014-05-09 11:16 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-05-27 01:35 - 2014-05-09 11:16 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-27 01:35 - 2014-05-09 11:16 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-05-27 01:27 - 2014-05-27 01:33 - 137314600 _____ () C:\Users\Christof\Downloads\avira_free_antivirus_de_642.exe 2014-05-27 00:56 - 2014-05-27 00:56 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Avira 2014-05-27 00:54 - 2014-05-27 00:54 - 00000000 ____D () C:\ProgramData\Avira 2014-05-27 00:54 - 2014-05-27 00:54 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-05-15 21:46 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 21:46 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-15 21:46 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-15 21:46 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-15 21:46 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 21:46 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-14 22:59 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-14 22:59 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-14 22:59 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-14 22:59 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-14 22:58 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-14 22:58 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-14 22:58 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-14 22:58 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-14 22:58 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-14 22:58 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-14 22:58 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-14 22:58 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-14 22:58 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-14 22:58 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-14 22:58 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-14 22:58 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-14 22:58 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-14 22:58 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-14 22:58 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-14 22:58 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-05-14 22:42 - 2014-05-30 01:02 - 00178966 _____ () C:\Windows\PFRO.log 2014-05-13 00:34 - 2014-05-30 01:02 - 00002856 _____ () C:\Windows\setupact.log 2014-05-13 00:34 - 2014-05-13 00:34 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-07 03:01 - 2014-05-18 03:02 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-30 13:19 - 2014-03-31 09:35 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== One Month Modified Files and Folders ======= 2014-05-30 01:42 - 2014-05-27 17:03 - 00024046 _____ () C:\Users\Christof\Downloads\FRST.txt 2014-05-30 01:42 - 2014-05-27 17:03 - 00000000 ____D () C:\FRST 2014-05-30 01:32 - 2014-05-30 01:32 - 00008193 _____ () C:\Users\Christof\Desktop\JRT.txt 2014-05-30 01:27 - 2011-11-30 14:42 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Skype 2014-05-30 01:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing 2014-05-30 01:18 - 2012-07-10 21:49 - 00001132 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA.job 2014-05-30 01:12 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-30 01:12 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-30 01:10 - 2014-05-30 01:10 - 00000000 ____D () C:\Windows\ERUNT 2014-05-30 01:08 - 2014-05-30 01:08 - 01016261 _____ (Thisisu) C:\Users\Christof\Downloads\JRT.exe 2014-05-30 01:07 - 2014-05-30 01:07 - 00000000 ____D () C:\Users\Christof\Desktop\Troja-Borard 2014-05-30 01:06 - 2014-05-30 00:10 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-30 01:03 - 2011-11-30 14:27 - 00045056 _____ () C:\Windows\system32\acovcnt.exe 2014-05-30 01:02 - 2014-05-28 18:45 - 00065536 _____ () C:\Windows\system32\Ikeext.etl 2014-05-30 01:02 - 2014-05-14 22:42 - 00178966 _____ () C:\Windows\PFRO.log 2014-05-30 01:02 - 2014-05-13 00:34 - 00002856 _____ () C:\Windows\setupact.log 2014-05-30 01:02 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-30 01:01 - 2011-11-04 09:14 - 02045173 _____ () C:\Windows\WindowsUpdate.log 2014-05-30 01:00 - 2014-05-30 00:56 - 00000000 ____D () C:\AdwCleaner 2014-05-30 00:55 - 2014-05-30 00:55 - 01327971 _____ () C:\Users\Christof\Downloads\adwcleaner_3.211.exe 2014-05-30 00:45 - 2011-02-19 06:24 - 16534012 _____ () C:\Windows\system32\perfh007.dat 2014-05-30 00:45 - 2011-02-19 06:24 - 05293530 _____ () C:\Windows\system32\perfc007.dat 2014-05-30 00:45 - 2009-07-14 07:13 - 00006780 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-30 00:39 - 2011-11-04 09:35 - 00001616 _____ () C:\Windows\system32\ServiceFilter.ini 2014-05-30 00:38 - 2012-07-05 14:31 - 00000000 ____D () C:\Windows\el 2014-05-30 00:34 - 2014-02-05 23:08 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\FunmoodsChat 2014-05-30 00:09 - 2014-05-30 00:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-30 00:09 - 2014-05-30 00:09 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-30 00:09 - 2014-05-30 00:09 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-30 00:06 - 2014-05-30 00:06 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Christof\Downloads\mbam-setup-2.0.2.1012.exe 2014-05-29 20:43 - 2012-09-28 17:38 - 00000940 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA.job 2014-05-29 17:43 - 2012-09-28 17:38 - 00000918 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core.job 2014-05-29 12:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-05-29 02:32 - 2011-12-15 22:52 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\SoftGrid Client 2014-05-28 19:43 - 2014-05-28 19:43 - 00048461 _____ () C:\ComboFix.txt 2014-05-28 19:43 - 2014-05-28 18:47 - 00000000 ____D () C:\Qoobox 2014-05-28 19:43 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-05-28 19:05 - 2014-05-28 18:46 - 00000000 ____D () C:\Windows\erdnt 2014-05-28 19:03 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-05-28 18:39 - 2012-03-28 19:47 - 00000432 _____ () C:\Windows\BRWMARK.INI 2014-05-28 18:35 - 2014-05-28 18:35 - 05203612 _____ (Swearware) C:\Users\Christof\Downloads\ComboFix (1).exe 2014-05-28 18:35 - 2014-05-28 18:34 - 05203612 ____R (Swearware) C:\Users\Christof\Downloads\ComboFix.exe 2014-05-28 18:33 - 2014-05-28 18:33 - 00003274 _____ () C:\Windows\System32\Tasks\{E9277147-9DFA-4584-ACC7-2601BC6B2844} 2014-05-28 18:21 - 2014-05-28 18:21 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-05-28 18:19 - 2014-05-28 18:19 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Christof\Downloads\revosetup95.exe 2014-05-27 17:11 - 2014-05-27 17:05 - 00045760 _____ () C:\Users\Christof\Downloads\Addition.txt 2014-05-27 17:07 - 2012-07-10 21:50 - 00002382 _____ () C:\Users\Christof\Desktop\Google Chrome.lnk 2014-05-27 17:01 - 2014-05-27 17:00 - 02066944 _____ (Farbar) C:\Users\Christof\Downloads\FRST64.exe 2014-05-27 02:20 - 2014-05-27 02:03 - 00017914 _____ () C:\Users\Christof\Documents\hijackthis.log 2014-05-27 01:59 - 2014-05-27 01:59 - 00961360 _____ (Chip Digital GmbH) C:\Users\Christof\Downloads\HijackThis - CHIP-Installer.exe 2014-05-27 01:43 - 2014-05-27 01:43 - 755762801 _____ () C:\Windows\MEMORY.DMP 2014-05-27 01:43 - 2012-04-07 16:42 - 00000000 ____D () C:\Windows\Minidump 2014-05-27 01:41 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-05-27 01:36 - 2014-05-27 01:36 - 00002072 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-05-27 01:36 - 2014-05-27 01:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-05-27 01:33 - 2014-05-27 01:27 - 137314600 _____ () C:\Users\Christof\Downloads\avira_free_antivirus_de_642.exe 2014-05-27 01:19 - 2011-11-30 14:26 - 00000000 ____D () C:\Users\Christof 2014-05-27 01:18 - 2012-07-10 21:50 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-05-27 01:18 - 2011-11-04 09:31 - 00000000 ____D () C:\ProgramData\P4G 2014-05-27 01:17 - 2009-07-14 09:44 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-05-27 01:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-05-27 01:10 - 2012-07-01 21:29 - 00683008 ___SH () C:\Users\Christof\Desktop\Thumbs.db 2014-05-27 00:56 - 2014-05-27 00:56 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Avira 2014-05-27 00:54 - 2014-05-27 00:54 - 00000000 ____D () C:\ProgramData\Avira 2014-05-27 00:54 - 2014-05-27 00:54 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-05-22 18:15 - 2012-07-10 21:49 - 00001080 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core.job 2014-05-21 17:39 - 2012-02-18 17:39 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Mozilla 2014-05-21 17:36 - 2014-01-01 23:36 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\.minecraft 2014-05-19 23:29 - 2012-02-19 22:00 - 00000000 ____D () C:\Users\Christof\Documents\VirtualDJ 2014-05-18 03:06 - 2011-11-30 14:28 - 00000000 ___RD () C:\Users\Christof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-18 03:06 - 2011-11-30 14:28 - 00000000 ___RD () C:\Users\Christof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-18 03:02 - 2014-05-07 03:01 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-15 21:46 - 2012-02-15 23:30 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-05-13 06:35 - 2013-06-14 13:13 - 00002292 _____ () C:\Users\Christof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Little Alchemy.lnk 2014-05-13 02:43 - 2014-04-16 18:13 - 00000000 ____D () C:\Users\Christof\Desktop\Hamburger City Girls 2014-05-13 02:09 - 2012-09-06 14:33 - 00000000 ____D () C:\Users\Christof\Documents\ANNO 2070 Demo 2014-05-13 02:09 - 2012-08-22 15:02 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Ubisoft 2014-05-13 02:09 - 2011-11-04 09:25 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-05-13 00:34 - 2014-05-13 00:34 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-13 00:18 - 2012-04-04 11:34 - 00000000 ____D () C:\Users\Christof\AppData\Local\LogMeIn Hamachi 2014-05-13 00:05 - 2009-07-29 08:03 - 00000000 ____D () C:\Windows\Panther 2014-05-12 07:26 - 2014-05-30 00:09 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:26 - 2014-05-30 00:09 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-05-30 00:09 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-09 11:16 - 2014-05-27 01:35 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-05-09 11:16 - 2014-05-27 01:35 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-09 11:16 - 2014-05-27 01:35 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-05-09 08:14 - 2014-05-14 22:59 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-09 08:11 - 2014-05-14 22:59 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-07 06:13 - 2012-07-10 21:49 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA 2014-05-07 06:13 - 2012-07-10 21:49 - 00003712 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core 2014-05-06 06:40 - 2014-05-15 21:46 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-06 06:17 - 2014-05-15 21:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-06 05:25 - 2014-05-15 21:46 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-06 05:07 - 2014-05-15 21:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-06 05:00 - 2014-05-15 21:46 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-06 04:10 - 2014-05-15 21:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll Some content of TEMP: ==================== C:\Users\Christof\AppData\Local\Temp\avgnt.exe C:\Users\Christof\AppData\Local\Temp\pid16.dll C:\Users\Christof\AppData\Local\Temp\pid32.dll C:\Users\Christof\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-23 01:46 ==================== End Of Log ============================ --- --- --- Addition.txt: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-05-2014 02 Ran by Christof at 2014-05-30 01:45:51 Running from C:\Users\Christof\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Trend Micro Titanium Internet Security (Disabled - Up to date) {68F968AC-2AA0-091D-848C-803E83E35902} AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Trend Micro Titanium Internet Security (Disabled - Up to date) {D3988948-0C9A-0693-BE3C-BB4CF86413BF} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft) 3D Pinball from Plus! for Windows 95 (HKLM-x32\...\Pinball) (Version: - ) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.2.0.2070 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.2.0.2070 - Adobe Systems Incorporated) Hidden Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.4.980 - Adobe Systems Incorporated.) Adobe Community Help (x32 Version: 3.4.980 - Adobe Systems Incorporated.) Hidden Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.0.6 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.0.6 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Photoshop CS5.1 (HKLM-x32\...\{9158FF30-78D7-40EF-B83E-451AC5334640}) (Version: 12.1 - Adobe Systems Incorporated) ANNO 1404 (HKLM-x32\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 1.02.0000 - Ubisoft) Anno 1404 (x32 Version: 1.00.0000 - Ubisoft) Hidden Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.12.5.0 - Asmedia Technology) ASUS AI Recovery (HKLM-x32\...\{38253529-D97D-4901-AE53-5CC9736D3A2E}) (Version: 1.0.13 - ASUS) ASUS FancyStart (HKLM-x32\...\{2B81872B-A054-48DA-BE3B-FA5C164C303A}) (Version: 1.0.8 - ASUSTeK Computer Inc.) ASUS K3 Series ScreenSaver (HKLM-x32\...\ASUS K3 Series ScreenSaver) (Version: 1.0.0002 - ASUS) ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.20 - ASUS) ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.0.6 - ASUS) ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.1.43 - ASUS) ASUS SmartLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0011 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0030 - ASUS) ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.21 - asus) ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.84.161 - eCareme Technologies, Inc.) AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.7.146 - ASUSTEK) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0010 - ASUS) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.642 - Avira) Battlefield Heroes (HKLM-x32\...\{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}) (Version: - EA Digital illusions) Bing Bar (HKLM-x32\...\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}) (Version: 7.0.610.0 - Microsoft Corporation) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Bookworm Deluxe (HKLM-x32\...\Bookworm Deluxe) (Version: - Oberon Media Inc.) Cinema 4D version R12 (HKLM-x32\...\{7D9D8134-9FA3-4FFF-ADA1-BF609F29997A}_is1) (Version: R12 - Salat Production) Complément Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Complemento Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation) Cooking Dash (HKLM-x32\...\Cooking Dash) (Version: - Oberon Media Inc.) CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1908 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.1908 - CyberLink Corp.) Hidden CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3602c - CyberLink Corp.) CyberLink Power2Go (x32 Version: 6.1.3602c - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Diner Dash 2 (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111212843}) (Version: - Oberon Media) Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited) Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.10 - ASUS) Fiesta Online DE 1.04.095 (HKLM-x32\...\Fiesta Online DE) (Version: 1.04.095 - Gamigo Games) Fiesta Online(EU_German) 1.04.000 (HKLM-x32\...\Fiesta Online(EU_German)) (Version: 1.04.000 - gamigo Games) Free System Utilities (HKLM-x32\...\{ee9b54a6-93dd-4070-80ae-743f58319407}) (Version: 1.0.0 - Covus Freemium GmbH) Free SystemUtilities (x32 Version: 1.0.0 - Covus Freemium GmbH) Hidden Free YouTube to MP3 Converter version 3.12.2.426 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.2.426 - DVDVideoSoft Ltd.) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Game Park Console (HKLM-x32\...\{E71E60C1-533E-45A5-8D80-E475E88D2B17}_is1) (Version: 6.2.1.1 - Oberon Media, Inc.) Google Chrome (HKCU\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.) Google Talk Plugin (HKLM-x32\...\{217CEB43-6D22-3E1F-A311-DC0D7BFEE0A2}) (Version: 5.4.1.18709 - Google) Governor of Poker (HKLM-x32\...\Governor of Poker) (Version: - Oberon Media Inc.) GreenWebPlayer (HKCU\...\gwp-DEFAULT) (Version: - ) <==== ATTENTION Happy Cloud Client (HKCU\...\HappyCloud) (Version: 4.28 - Happy Cloud, Inc.) HitmanPro.Alert (HKLM\...\HitmanPro.Alert) (Version: 2.6.5.77 - SurfRight B.V.) Hotel Dash Suite Success (HKLM-x32\...\Hotel Dash Suite Success) (Version: - Oberon Media Inc.) Intel PROSet Wireless (Version: - ) Hidden Intel PROSet Wireless (x32 Version: - ) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation) Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{3C41721F-AF0F-4086-AA1C-4C7F29076228}) (Version: 14.01.1000 - Intel Corporation) Intel(R) Turbo Boost Technology Monitor (HKLM\...\{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}) (Version: 1.0.400.4 - Intel) iTunes (HKLM\...\{D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0}) (Version: 11.1.3.8 - Apple Inc.) Java 7 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.250 - Oracle) Java Auto Updater (x32 Version: 2.1.9.5 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216031FF}) (Version: 6.0.310 - Oracle) JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) Jewel Quest 3 (HKLM-x32\...\Jewel Quest 3) (Version: - Oberon Media Inc.) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Landwirtschafts Simulator 2013 (HKLM-x32\...\FarmingSimulator2013DE_is1) (Version: 1.0 - GIANTS Software) League of Legends (HKLM-x32\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games) Little Alchemy (HKCU\...\Pokki_faeb52fe0fea61b95b0070adc5264fa86cc0757f) (Version: 0.23.0 - Pokki) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.1.0.294 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.1.0.294 - LogMeIn, Inc.) Hidden Luxor 3 (HKLM-x32\...\Luxor 3) (Version: - Oberon Media Inc.) Mahjongg dimensions (HKLM-x32\...\Mahjongg dimensions) (Version: - Oberon Media Inc.) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger 分享元件 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation) Hidden Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Mobile Partner (HKLM-x32\...\Mobile Partner) (Version: 11.300.05.05.47 - Huawei Technologies Co.,Ltd) Mozilla Firefox 13.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 13.0.1 (x86 de)) (Version: 13.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 13.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT Redists (x32 Version: 1.0 - Sony Creative Software Inc.) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MySQL Connector/ODBC 5.1 (HKLM-x32\...\{29042B1C-0713-4575-B7CA-5C8E7B0899D4}) (Version: 5.1.5 - MySQL AB) Nuance PDF Reader (HKLM-x32\...\{B480904D-F73F-4673-B034-8A5F492C9184}) (Version: 6.00.0041 - Nuance Communications, Inc.) NVIDIA Control Panel 268.56 (Version: 268.56 - NVIDIA Corporation) Hidden NVIDIA Graphics Driver 268.56 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 268.56 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.265.41.0 - NVIDIA Corporation) Hidden NVIDIA Optimus 1.0.22 (Version: 1.0.22 - NVIDIA Corporation) Hidden NVIDIA Update Components (Version: 1.0.22 - NVIDIA Corporation) Hidden PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.) Plants vs Zombies (HKLM-x32\...\Plants vs Zombies) (Version: - Oberon Media Inc.) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.990 - Even Balance, Inc.) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.38.113.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6373 - Realtek Semiconductor Corp.) Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10001 - Realtek Semiconductor Corp.) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.1.10441 - Skype Technologies S.A.) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Sonic Focus (HKLM-x32\...\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: 1.0.0.4 - Synopsys ) Stormblade Launcher 1.1 (HKLM-x32\...\{D84EA2B7-F65E-43F3-9FB5-18B2162DBFA2}}_is1) (Version: - Stormblade.org) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.6.0 - Synaptics Incorporated) syncables desktop SE (HKLM-x32\...\{341697D8-9923-445E-B42A-529E5A99CB7A}) (Version: 5.5.746.11492 - syncables) System Requirements Lab for Intel (HKLM-x32\...\{C7CA731B-BF9A-46D9-92CF-8A8737AE9240}) (Version: 4.5.13.0 - Husdawg, LLC) TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.13.1 - TeamSpeak Systems GmbH) TeamViewer 7 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.13989 - TeamViewer) Trend Micro Titanium Internet Security (HKLM\...\{ABBD4BA8-6703-40D2-AB1E-5BB1F7DB49A4}) (Version: 3.0 - Trend Micro Inc.) Trend Micro Titanium Internet Security (Version: 3.00 - Trend Micro Inc.) Hidden TubeBox (HKLM-x32\...\{c5b74464-3a04-417c-9eee-d0dc7d6af196}) (Version: 4.1.0.0 - Freetec) TubeBox (x32 Version: 4.1.0.0 - Freetec) Hidden TubeBox! (HKLM-x32\...\{A78A5C61-2397-407E-A41F-0A0FFAD2572F}) (Version: 3.4.9 - Jens Lorek) TuneUp Utilities 2012 (HKLM-x32\...\TuneUp Utilities 2012) (Version: 12.0.3600.73 - TuneUp Software) TuneUp Utilities 2012 (x32 Version: 12.0.3600.73 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.73 - TuneUp Software) Hidden UltraStar 1.0.2 (HKLM-x32\...\UltraStar) (Version: 1.0.2 - SterGames) Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Vegas Pro 10.0 (HKLM-x32\...\{6E0E4D61-11EC-11E0-B454-0013D3D69929}) (Version: 10.0.469 - Sony) Virtual Audio Cable 4.10 (HKLM\...\Virtual Audio Cable 4.10) (Version: - ) VirtualDJ Home FREE (HKLM-x32\...\{A6AC699F-8315-40CA-8F70-E917494978AB}) (Version: 7.4 - Atomix Productions) VirtualDJ PRO Full (HKLM-x32\...\{4769E972-2E92-49C5-B6F9-465EFD0C4D94}) (Version: 7.0.5 - Atomix Productions) VLC media player 2.1.0 (HKLM\...\VLC media player) (Version: 2.1.0 - VideoLAN) War Thunder Launcher 1.0.1.252 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version: - 2013 Gaijin Entertainment Corporation) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.31.0 - ASUS) WinRAR 4.10 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.10.0 - win.rar GmbH) Wireless Console 3 (HKLM-x32\...\{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}) (Version: 3.0.19 - ASUS) World of Goo (HKLM-x32\...\World of Goo) (Version: - Oberon Media Inc.) World of Tanks - Common Test (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812CT}_is1) (Version: - Wargaming.net) World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812}_is1) (Version: - Wargaming.net) Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Компаньон Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2-8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation) גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden מסייע Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (HKLM-x32\...\{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}) (Version: 15.4.5722.2 - Microsoft Corporation) بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\...\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 - Microsoft Corporation) معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden 適用遠端連線的 Windows Live Mesh ActiveX 控制項 (HKLM-x32\...\{622DE1BE-9EDE-49D3-B349-29D64760342A}) (Version: 15.4.5722.2 - Microsoft Corporation) ==================== Restore Points ========================= 10-05-2014 01:15:15 Windows Update 14-05-2014 20:51:16 Windows Update 15-05-2014 19:44:45 Windows Modules Installer 22-05-2014 16:22:50 Windows Update 26-05-2014 23:34:17 Windows Update 28-05-2014 16:47:25 ComboFix created restore point ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-05-28 19:03 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {08B3AC75-315C-4200-B48E-F5487B7775A8} - \Software Updater Ui No Task File <==== ATTENTION Task: {0A324023-A490-4F18-AC05-F3389C59CA23} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe Task: {14BD47B8-3C90-474F-8BCE-E3A36A64333A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA => C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-10] (Google Inc.) Task: {305613CB-9467-47E6-ABBD-6CF9B2F3EA13} - \Software Updater No Task File <==== ATTENTION Task: {38BCBE7F-4350-4D89-B5ED-3CFBDDE3FEF1} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-08-31] (ASUSTeK Computer Inc.) Task: {44F84D1D-BC08-4902-B944-283B60961319} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION Task: {46B1A0E5-1F8C-4724-8A6C-B30B4288C378} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2010-08-02] (ASUS) Task: {528B427F-F855-439A-A47E-8DFCC6587779} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA => C:\Users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-28] (Facebook Inc.) Task: {54C92ACB-03D0-4B1F-8F36-FF39DADEB6A5} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS) Task: {6C6A8579-8CF2-445B-A7A9-BC21E849CE38} - \EPUpdater No Task File <==== ATTENTION Task: {7F8DDFFF-4721-4D33-898A-031679957DA3} - System32\Tasks\AIRecoveryRemind => C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryRemind.exe [2010-12-18] (ASUSTek Computer Inc.) Task: {884FF545-7FAB-455B-8A88-12EA4873BCC7} - System32\Tasks\Audio Performer => C:\Users\Christof\AppData\Local\Temp\Audio Performer53412.exe <==== ATTENTION Task: {A5F799F2-B796-4048-AB70-F08B27DB2A5E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core => C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-10] (Google Inc.) Task: {A73C4B6B-AEE9-4035-8357-30EC38D0A0C4} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION Task: {BD47C0B0-5BDB-4979-B058-10B6F669F213} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS) Task: {C3A9702F-5672-4B6F-9D04-189326B5D246} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {D4632569-0F66-4C76-ADAB-D3AD6884D06C} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-12-02] (ASUS) Task: {E3716629-CF68-4C81-B9AA-1432405CFF1D} - \BitGuard No Task File <==== ATTENTION Task: {FA25F409-1B67-4A6B-8C09-766B2C3D7905} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core => C:\Users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-28] (Facebook Inc.) Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core.job => C:\Users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA.job => C:\Users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core.job => C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA.job => C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll 2012-02-04 13:01 - 2012-02-04 13:01 - 00075136 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2010-04-03 04:21 - 2008-10-01 08:08 - 00011264 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll 2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll 2011-07-07 08:12 - 2011-01-27 02:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2011-07-07 08:10 - 2011-05-05 14:30 - 00057640 _____ () C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll 2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll 2010-09-24 01:53 - 2010-09-24 01:53 - 01601536 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe 2011-05-02 23:13 - 2011-05-02 23:13 - 00340240 _____ () C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe 2010-01-02 16:42 - 2010-01-02 16:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2012-01-21 04:49 - 2012-01-09 20:44 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll 2013-09-13 19:51 - 2013-09-13 19:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-09-13 19:51 - 2013-09-13 19:51 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2011-08-31 15:33 - 2011-08-31 15:33 - 00208384 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll 2009-11-02 23:20 - 2009-11-02 23:20 - 00619816 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2009-11-02 23:23 - 2009-11-02 23:23 - 00013096 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2010-12-18 02:54 - 2010-12-18 02:54 - 00049792 _____ () C:\Program Files (x86)\ASUS\AI Recovery\RecoveryDVDLang.dll 2012-01-08 15:41 - 2012-01-08 15:41 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2014-05-27 17:07 - 2014-05-14 01:40 - 00716616 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\libglesv2.dll 2014-05-27 17:07 - 2014-05-14 01:40 - 00126280 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\libegl.dll 2014-05-27 17:07 - 2014-05-14 01:40 - 04217672 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\pdf.dll 2014-05-27 17:07 - 2014-05-14 01:40 - 00414536 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll 2014-05-27 17:07 - 2014-05-14 01:40 - 01732424 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:3CF2806E ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= Error: (04/03/2013 07:05:03 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1832 seconds with 660 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-05-30 00:56:11.878 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-30 00:28:46.114 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-30 00:09:00.176 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-29 23:50:12.223 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-29 23:43:25.026 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-29 20:23:25.046 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-29 13:08:18.133 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-29 13:02:06.894 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-29 11:53:38.756 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-29 01:30:32.284 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 47% Total physical RAM: 6054.7 MB Available physical RAM: 3198.84 MB Total Pagefile: 12107.57 MB Available Pagefile: 8691.02 MB Total Virtual: 8192 MB Available Virtual: 8191.87 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:279.45 GB) (Free:92.05 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (DATA) (Fixed) (Total:394.18 GB) (Free:393.86 GB) NTFS Drive e: (CTH_V800C) (CDROM) (Total:0.42 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 496B9619) Partition 1: (Not Active) - (Size=25 GB) - (Type=1C) Partition 2: (Active) - (Size=279 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=394 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Geändert von Gytoro (30.05.2014 um 00:49 Uhr) |
30.05.2014, 22:09 | #9 |
/// the machine /// TB-Ausbilder | TR/BProtector.GenESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
01.06.2014, 23:37 | #10 |
| TR/BProtector.Gen Ergebniss ESET: Code:
ATTFilter C:\AdwCleaner\Quarantine\C\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarApp.dll.vir Variante von Win32/Toolbar.Montiera.A evtl. unerwünschte Anwendung C:\AdwCleaner\Quarantine\C\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll.vir Win32/Toolbar.Babylon evtl. unerwünschte Anwendung C:\AdwCleaner\Quarantine\C\Program Files (x86)\InnoGames_International\InnoGames_InternationalToolbarHelper.exe.vir Win32/Toolbar.Conduit.Q evtl. unerwünschte Anwendung C:\AdwCleaner\Quarantine\C\Program Files (x86)\InnoGames_International\ldrtbInno.dll.vir Variante von Win32/Toolbar.Conduit.P evtl. unerwünschte Anwendung C:\AdwCleaner\Quarantine\C\Program Files (x86)\InnoGames_International\tbInno.dll.vir Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll.vir Variante von Win32/Adware.Yontoo.B Anwendung C:\AdwCleaner\Quarantine\C\Users\Christof\AppData\Local\Conduit\CT2832595\InnoGames_InternationalAutoUpdateHelper.exe.vir Win32/Toolbar.Conduit.Q evtl. unerwünschte Anwendung C:\AdwCleaner\Quarantine\C\Users\Christof\AppData\Local\DownloadGuide\Offers\autocompletepro.exe.vir Variante von Win32/Complitly.A evtl. unerwünschte Anwendung C:\AdwCleaner\Quarantine\C\Users\Christof\AppData\LocalLow\InnoGames_International\ldrtbInno.dll.vir Variante von Win32/Toolbar.Conduit.P evtl. unerwünschte Anwendung C:\AdwCleaner\Quarantine\C\Users\Christof\AppData\LocalLow\InnoGames_International\tbInno.dll.vir Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung C:\AdwCleaner\Quarantine\C\Users\Christof\AppData\Roaming\BabSolution\Shared\BabMaint.exe.vir Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\Funmoods\1.5.23.22\escortApp.dll.vir Win32/Toolbar.Funmoods evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\Funmoods\1.5.23.22\escortEng.dll.vir Win32/Toolbar.Funmoods evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\Funmoods\1.5.23.22\escortShld.dll.vir Win32/Toolbar.Funmoods evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\Funmoods\1.5.23.22\funmoodssrv.exe.vir Win32/Toolbar.Funmoods evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\Funmoods\1.5.23.22\bh\escort.dll.vir Win32/Toolbar.Funmoods evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe.vir Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll.vir Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\SPtool.dll_1389820509773.vir Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\SPtool.dll_1390837242531.vir Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\SPtool.dll_1391024340860.vir Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\SPtool.dll_1391024341304.vir Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\SPtool.dll_1391448126769.vir Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe.vir Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe.vir Variante von Win32/Conduit.SearchProtect.I evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll.vir Variante von Win32/Conduit.SearchProtect.H evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll.vir Variante von Win64/Conduit.SearchProtect.A evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe.vir Variante von Win32/Conduit.SearchProtect.I evtl. unerwünschte Anwendung C:\Qoobox\Quarantine\C\Users\Christof\AppData\Roaming\BabMaint.exe.vir Win32/Toolbar.Babylon.P evtl. unerwünschte Anwendung C:\Users\Christof\AppData\Local\CRE\nipcdlfhdehdhmajficeeocjdbdhacdn.crx Variante von Win32/Toolbar.Conduit.AH evtl. unerwünschte Anwendung C:\Users\Christof\Downloads\HijackThis - CHIP-Installer.exe Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung C:\Users\Christof\Downloads\SingStar-Vol.-3-Setup.exe Variante von Win32/WinloadSDA.D evtl. unerwünschte Anwendung Code:
ATTFilter Results of screen317's Security Check version 0.99.83 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Trend Micro Titanium Internet Security Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` TuneUp Utilities 2012 TuneUp Utilities Language Pack (de-DE) JavaFX 2.1.1 Java(TM) 6 Update 31 Java 7 Update 25 Java version out of Date! Adobe Flash Player 11.9.900.117 Flash Player out of Date! Mozilla Firefox 13.0.1 Firefox out of Date! Google Chrome 34.0.1847.137 Google Chrome 35.0.1916.114 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-06-2014 01 Ran by Christof (administrator) on CHRISTOF-PC on 02-06-2014 00:45:38 Running from C:\Users\Christof\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (SurfRight B.V.) C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (ASUS) C:\Windows\AsScrPro.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe (Adobe Systems, Incorporated) C:\Program Files\Adobe\Adobe Photoshop CS5.1 (64 Bit)\Photoshop.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Google Inc.) C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe () C:\Users\Christof\Downloads\SecurityCheck.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [VizorHtmlDialog.exe] => C:\Program Files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe [1123664 2010-10-08] (Trend Micro Inc.) HKLM\...\Run: [Trend Micro Client Framework] => C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [192520 2010-10-12] (Trend Micro Inc.) HKLM\...\Run: [Trend Micro Titanium] => C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe [322384 2010-09-17] (Trend Micro Inc.) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-05-17] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2785064 2011-05-05] (Synaptics Incorporated) HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation) HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [97064 2011-05-05] (Synaptics Incorporated) HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" HKLM\...\Run: [Setwallpaper] => c:\programdata\SetWallpaper.cmd HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-03-15] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Nuance PDF Reader-reminder] => C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe [328992 2008-11-03] (Nuance Communications, Inc.) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme) HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] () HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-09] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] - rmdir /s /q "\SearchProtect" HKU\S-1-5-21-2465417766-3482814047-1650821192-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-06] (Acresso Corporation) HKU\S-1-5-21-2465417766-3482814047-1650821192-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-06] (Acresso Corporation) HKU\S-1-5-21-2465417766-3482814047-1650821192-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-06] (Acresso Corporation) HKU\S-1-5-21-2465417766-3482814047-1650821192-1001\...\Run: [GoogleChromeAutoLaunch_9DC73BAD139DCCFFA56EA65F10CB0EF3] => C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe [860488 2014-05-14] (Google Inc.) HKU\S-1-5-21-2465417766-3482814047-1650821192-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GoogleChromeAutoLaunch_9DC73BAD139DCCFFA56EA65F10CB0EF3] => C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe [860488 2014-05-14] (Google Inc.) HKU\S-1-5-21-2465417766-3482814047-1650821192-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.) AppInit_DLLs: c:\Windows\System32\nvinitx.dll => c:\Windows\System32\nvinitx.dll [226920 2011-05-10] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.at/ StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: TmIEPlugInBHO Class - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\TmIEPlg.dll (Trend Micro Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: TmBpIeBHO Class - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\Module\20002\6.5.1234\6.5.1234\TmBpIe64.dll (Trend Micro Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.254 FireFox: ======== FF ProfilePath: C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default FF NewTab: user_pref("browser.newtab.url", ""); FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: about:home|hxxp://www.giga.de/androidnews/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) FF Plugin HKCU: @greentube.com/GreenWebPlayer - C:\Games\GreenWebPlayer\npgreenwebplayer.dll (Greentube Internet Entertainment Solutions GmbH) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Christof\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Christof\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google) FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Christof\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Christof\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Christof\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Christof\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: thehappycloud.com/HappyCloudPlugin - C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud) FF Plugin ProgramFiles/Appdata: C:\Users\Christof\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google) FF Plugin ProgramFiles/Appdata: C:\Users\Christof\AppData\Roaming\mozilla\plugins\npo1d.dll (Google) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Battlefield Heroes Updater - C:\Users\Christof\AppData\Roaming\Mozilla\Firefox\Profiles\oud4yekh.default\Extensions\battlefieldheroespatcher@ea.com [2012-02-19] FF Extension: Hotspot Shield Extension - C:\Program Files (x86)\Mozilla Firefox\extensions\afproxy@anchorfree.com [2014-01-10] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2012-06-25] FF HKLM-x32\...\Firefox\Extensions: [{22C7F6C6-8D67-4534-92B5-529A0EC09405}] - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\firefoxextension\ FF Extension: Trend Micro NSC Firefox Extension - C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1381\6.5.1234\firefoxextension\ [] FF HKCU\...\Firefox\Extensions: [{9A207F60-3F1C-4ED0-972D-0A4CDFBFF803}] - C:\Users\Christof\AppData\Roaming\13001.027 Chrome: ======= CHR HomePage: https://www.google.at/ CHR StartupUrls: "https://www.google.at/" CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll No File CHR Plugin: (GreenWebPlayer) - C:\Games\GreenWebPlayer\npgreenwebplayer.dll (Greentube Internet Entertainment Solutions GmbH) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Zeon Plus) - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Users\Christof\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Extension: (YouTube) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-07-10] CHR Extension: (Adblock Plus) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-03-22] CHR Extension: (Google-Suche) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-07-10] CHR Extension: (Dark Vibe) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkckeanhmkjaechlhllmapjaaglgpcbj [2012-07-11] CHR Extension: (Google Wallet) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-27] CHR Extension: (Google Mail) - C:\Users\Christof\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-07-10] CHR HKCU\...\Chrome\Extension: [nipcdlfhdehdhmajficeeocjdbdhacdn] - C:\Users\Christof\AppData\Local\CRE\nipcdlfhdehdhmajficeeocjdbdhacdn.crx [2013-04-25] CHR HKLM-x32\...\Chrome\Extension: [nipcdlfhdehdhmajficeeocjdbdhacdn] - C:\Users\Christof\AppData\Local\CRE\nipcdlfhdehdhmajficeeocjdbdhacdn.crx [2013-04-25] CHR StartMenuInternet: Google Chrome - C:\Users\Christof\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-09] (Avira Operations GmbH & Co. KG) R2 hmpalertsvc; C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1876816 2014-04-16] (SurfRight B.V.) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2012-02-04] () S4 TiMiniService; C:\Program Files\Trend Micro\Titanium\TiMiniService.exe [241488 2010-09-17] (Trend Micro Inc.) S3 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 [X] S2 Hamachi2Svc; "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s [X] S2 TuneUp.UtilitiesSvc; "C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe" [X] ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-08-22] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-05-09] (Avira Operations GmbH & Co. KG) R2 hmpalert; C:\Windows\system32\drivers\hmpalert.sys [93144 2014-04-16] () R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [44744 2013-11-13] (AnchorFree Inc.) S3 hwusbdev; C:\Windows\System32\DRIVERS\ewusbdev.sys [114560 2009-07-24] (Huawei Technologies Co., Ltd.) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-08-22] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-02] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R2 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [90704 2010-09-17] (Trend Micro Inc.) R2 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [144464 2010-09-17] (Trend Micro Inc.) R2 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [67664 2010-09-17] (Trend Micro Inc.) R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [105552 2010-09-17] (Trend Micro Inc.) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-17] () S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-02 00:45 - 2014-06-02 00:45 - 00000000 ____D () C:\Users\Christof\Downloads\FRST-OlderVersion 2014-06-02 00:37 - 2014-06-02 00:37 - 00854367 _____ () C:\Users\Christof\Downloads\SecurityCheck.exe 2014-06-02 00:35 - 2014-06-02 00:35 - 00004920 _____ () C:\Users\Christof\Desktop\ergebnis eset.txt 2014-05-30 23:52 - 2014-05-30 23:52 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-05-30 23:19 - 2014-05-30 23:19 - 02347384 _____ (ESET) C:\Users\Christof\Downloads\esetsmartinstaller_deu.exe 2014-05-30 01:32 - 2014-05-30 01:32 - 00008193 _____ () C:\Users\Christof\Desktop\JRT.txt 2014-05-30 01:10 - 2014-05-30 01:10 - 00000000 ____D () C:\Windows\ERUNT 2014-05-30 01:08 - 2014-05-30 01:08 - 01016261 _____ (Thisisu) C:\Users\Christof\Downloads\JRT.exe 2014-05-30 01:07 - 2014-05-30 01:07 - 00000000 ____D () C:\Users\Christof\Desktop\Troja-Borard 2014-05-30 00:57 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-05-30 00:56 - 2014-05-30 01:00 - 00000000 ____D () C:\AdwCleaner 2014-05-30 00:55 - 2014-05-30 00:55 - 01327971 _____ () C:\Users\Christof\Downloads\adwcleaner_3.211.exe 2014-05-30 00:10 - 2014-06-02 00:19 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-30 00:09 - 2014-05-30 00:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-30 00:09 - 2014-05-30 00:09 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-30 00:09 - 2014-05-30 00:09 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-30 00:09 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-30 00:09 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-30 00:09 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-30 00:06 - 2014-05-30 00:06 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Christof\Downloads\mbam-setup-2.0.2.1012.exe 2014-05-28 19:43 - 2014-05-30 21:57 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\temp 2014-05-28 19:43 - 2014-05-28 19:43 - 00048461 _____ () C:\ComboFix.txt 2014-05-28 19:43 - 2014-05-28 19:43 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-05-28 19:43 - 2014-05-28 19:43 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-05-28 19:43 - 2014-05-28 19:43 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-05-28 18:47 - 2014-05-28 19:43 - 00000000 ____D () C:\Qoobox 2014-05-28 18:47 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-05-28 18:47 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-05-28 18:47 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-05-28 18:47 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-05-28 18:47 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-05-28 18:47 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-05-28 18:47 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-05-28 18:47 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-05-28 18:46 - 2014-05-28 19:05 - 00000000 ____D () C:\Windows\erdnt 2014-05-28 18:45 - 2014-05-30 16:35 - 00262144 _____ () C:\Windows\system32\Ikeext.etl 2014-05-28 18:35 - 2014-05-28 18:35 - 05203612 _____ (Swearware) C:\Users\Christof\Downloads\ComboFix (1).exe 2014-05-28 18:34 - 2014-05-28 18:35 - 05203612 ____R (Swearware) C:\Users\Christof\Downloads\ComboFix.exe 2014-05-28 18:33 - 2014-05-28 18:33 - 00003274 _____ () C:\Windows\System32\Tasks\{E9277147-9DFA-4584-ACC7-2601BC6B2844} 2014-05-28 18:21 - 2014-05-28 18:21 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-05-28 18:19 - 2014-05-28 18:19 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Christof\Downloads\revosetup95.exe 2014-05-27 17:05 - 2014-05-30 01:46 - 00038875 _____ () C:\Users\Christof\Downloads\Addition.txt 2014-05-27 17:03 - 2014-06-02 00:46 - 00025391 _____ () C:\Users\Christof\Downloads\FRST.txt 2014-05-27 17:03 - 2014-06-02 00:45 - 00000000 ____D () C:\FRST 2014-05-27 17:00 - 2014-06-02 00:45 - 02067456 _____ (Farbar) C:\Users\Christof\Downloads\FRST64.exe 2014-05-27 02:03 - 2014-05-27 02:20 - 00017914 _____ () C:\Users\Christof\Documents\hijackthis.log 2014-05-27 01:59 - 2014-05-27 01:59 - 00961360 _____ (Chip Digital GmbH) C:\Users\Christof\Downloads\HijackThis - CHIP-Installer.exe 2014-05-27 01:43 - 2014-05-27 01:43 - 755762801 _____ () C:\Windows\MEMORY.DMP 2014-05-27 01:36 - 2014-05-27 01:36 - 00002072 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-05-27 01:36 - 2014-05-27 01:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-05-27 01:35 - 2014-05-09 11:16 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-05-27 01:35 - 2014-05-09 11:16 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-27 01:35 - 2014-05-09 11:16 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-05-27 01:27 - 2014-05-27 01:33 - 137314600 _____ () C:\Users\Christof\Downloads\avira_free_antivirus_de_642.exe 2014-05-27 00:56 - 2014-05-27 00:56 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Avira 2014-05-27 00:54 - 2014-05-27 00:54 - 00000000 ____D () C:\ProgramData\Avira 2014-05-27 00:54 - 2014-05-27 00:54 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-05-15 21:46 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 21:46 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-15 21:46 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-15 21:46 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-15 21:46 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 21:46 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-14 22:59 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-14 22:59 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-14 22:59 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-14 22:59 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-14 22:58 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-14 22:58 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-14 22:58 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-14 22:58 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-14 22:58 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-14 22:58 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-14 22:58 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-14 22:58 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-14 22:58 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-14 22:58 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-14 22:58 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-14 22:58 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-14 22:58 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-14 22:58 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-14 22:58 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-14 22:58 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-14 22:58 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-14 22:58 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-14 22:58 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-05-14 22:42 - 2014-05-30 01:02 - 00178966 _____ () C:\Windows\PFRO.log 2014-05-13 00:34 - 2014-06-01 23:25 - 00003080 _____ () C:\Windows\setupact.log 2014-05-13 00:34 - 2014-05-13 00:34 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-07 03:01 - 2014-05-18 03:02 - 00000000 ___SD () C:\Windows\system32\CompatTel ==================== One Month Modified Files and Folders ======= 2014-06-02 00:46 - 2014-05-27 17:03 - 00025391 _____ () C:\Users\Christof\Downloads\FRST.txt 2014-06-02 00:46 - 2011-11-30 14:26 - 00000000 ____D () C:\Users\Christof\AppData\Local\Temp 2014-06-02 00:45 - 2014-06-02 00:45 - 00000000 ____D () C:\Users\Christof\Downloads\FRST-OlderVersion 2014-06-02 00:45 - 2014-05-27 17:03 - 00000000 ____D () C:\FRST 2014-06-02 00:45 - 2014-05-27 17:00 - 02067456 _____ (Farbar) C:\Users\Christof\Downloads\FRST64.exe 2014-06-02 00:39 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing 2014-06-02 00:37 - 2014-06-02 00:37 - 00854367 _____ () C:\Users\Christof\Downloads\SecurityCheck.exe 2014-06-02 00:35 - 2014-06-02 00:35 - 00004920 _____ () C:\Users\Christof\Desktop\ergebnis eset.txt 2014-06-02 00:35 - 2011-11-30 14:42 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Skype 2014-06-02 00:19 - 2014-05-30 00:10 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-02 00:18 - 2012-07-10 21:49 - 00001132 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA.job 2014-06-01 23:43 - 2012-09-28 17:38 - 00000940 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA.job 2014-06-01 23:25 - 2014-05-13 00:34 - 00003080 _____ () C:\Windows\setupact.log 2014-06-01 19:21 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-01 19:21 - 2009-07-14 06:45 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-01 19:05 - 2012-09-28 17:38 - 00000918 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core.job 2014-06-01 13:42 - 2012-07-05 14:17 - 00000000 ____D () C:\Users\Christof\Desktop\Jugnd 2014-05-30 23:52 - 2014-05-30 23:52 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-05-30 23:19 - 2014-05-30 23:19 - 02347384 _____ (ESET) C:\Users\Christof\Downloads\esetsmartinstaller_deu.exe 2014-05-30 21:58 - 2011-02-19 06:24 - 16563956 _____ () C:\Windows\system32\perfh007.dat 2014-05-30 21:58 - 2011-02-19 06:24 - 05303362 _____ () C:\Windows\system32\perfc007.dat 2014-05-30 21:58 - 2009-07-14 07:13 - 00006780 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-30 21:57 - 2014-05-28 19:43 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\temp 2014-05-30 16:35 - 2014-05-28 18:45 - 00262144 _____ () C:\Windows\system32\Ikeext.etl 2014-05-30 16:35 - 2011-11-30 14:27 - 00045056 _____ () C:\Windows\system32\acovcnt.exe 2014-05-30 16:34 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-30 01:55 - 2011-11-04 09:14 - 02091891 _____ () C:\Windows\WindowsUpdate.log 2014-05-30 01:46 - 2014-05-27 17:05 - 00038875 _____ () C:\Users\Christof\Downloads\Addition.txt 2014-05-30 01:32 - 2014-05-30 01:32 - 00008193 _____ () C:\Users\Christof\Desktop\JRT.txt 2014-05-30 01:10 - 2014-05-30 01:10 - 00000000 ____D () C:\Windows\ERUNT 2014-05-30 01:08 - 2014-05-30 01:08 - 01016261 _____ (Thisisu) C:\Users\Christof\Downloads\JRT.exe 2014-05-30 01:07 - 2014-05-30 01:07 - 00000000 ____D () C:\Users\Christof\Desktop\Troja-Borard 2014-05-30 01:02 - 2014-05-14 22:42 - 00178966 _____ () C:\Windows\PFRO.log 2014-05-30 01:00 - 2014-05-30 00:56 - 00000000 ____D () C:\AdwCleaner 2014-05-30 00:55 - 2014-05-30 00:55 - 01327971 _____ () C:\Users\Christof\Downloads\adwcleaner_3.211.exe 2014-05-30 00:39 - 2011-11-04 09:35 - 00001616 _____ () C:\Windows\system32\ServiceFilter.ini 2014-05-30 00:38 - 2012-07-05 14:31 - 00000000 ____D () C:\Windows\el 2014-05-30 00:34 - 2014-02-05 23:08 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\FunmoodsChat 2014-05-30 00:09 - 2014-05-30 00:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-30 00:09 - 2014-05-30 00:09 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-30 00:09 - 2014-05-30 00:09 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-05-30 00:06 - 2014-05-30 00:06 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Christof\Downloads\mbam-setup-2.0.2.1012.exe 2014-05-29 12:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-05-29 02:32 - 2011-12-15 22:52 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\SoftGrid Client 2014-05-28 19:43 - 2014-05-28 19:43 - 00048461 _____ () C:\ComboFix.txt 2014-05-28 19:43 - 2014-05-28 19:43 - 00000000 ____D () C:\Users\Public\AppData\Local\temp 2014-05-28 19:43 - 2014-05-28 19:43 - 00000000 ____D () C:\Users\Default\AppData\Local\temp 2014-05-28 19:43 - 2014-05-28 19:43 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp 2014-05-28 19:43 - 2014-05-28 18:47 - 00000000 ____D () C:\Qoobox 2014-05-28 19:43 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2014-05-28 19:05 - 2014-05-28 18:46 - 00000000 ____D () C:\Windows\erdnt 2014-05-28 19:03 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-05-28 18:39 - 2012-03-28 19:47 - 00000432 _____ () C:\Windows\BRWMARK.INI 2014-05-28 18:35 - 2014-05-28 18:35 - 05203612 _____ (Swearware) C:\Users\Christof\Downloads\ComboFix (1).exe 2014-05-28 18:35 - 2014-05-28 18:34 - 05203612 ____R (Swearware) C:\Users\Christof\Downloads\ComboFix.exe 2014-05-28 18:33 - 2014-05-28 18:33 - 00003274 _____ () C:\Windows\System32\Tasks\{E9277147-9DFA-4584-ACC7-2601BC6B2844} 2014-05-28 18:21 - 2014-05-28 18:21 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-05-28 18:19 - 2014-05-28 18:19 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Christof\Downloads\revosetup95.exe 2014-05-27 17:07 - 2012-07-10 21:50 - 00002382 _____ () C:\Users\Christof\Desktop\Google Chrome.lnk 2014-05-27 02:20 - 2014-05-27 02:03 - 00017914 _____ () C:\Users\Christof\Documents\hijackthis.log 2014-05-27 01:59 - 2014-05-27 01:59 - 00961360 _____ (Chip Digital GmbH) C:\Users\Christof\Downloads\HijackThis - CHIP-Installer.exe 2014-05-27 01:43 - 2014-05-27 01:43 - 755762801 _____ () C:\Windows\MEMORY.DMP 2014-05-27 01:43 - 2012-04-07 16:42 - 00000000 ____D () C:\Windows\Minidump 2014-05-27 01:41 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-05-27 01:36 - 2014-05-27 01:36 - 00002072 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-05-27 01:36 - 2014-05-27 01:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-05-27 01:33 - 2014-05-27 01:27 - 137314600 _____ () C:\Users\Christof\Downloads\avira_free_antivirus_de_642.exe 2014-05-27 01:19 - 2011-11-30 14:26 - 00000000 ____D () C:\Users\Christof 2014-05-27 01:18 - 2012-07-10 21:50 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-05-27 01:18 - 2011-11-04 09:31 - 00000000 ____D () C:\ProgramData\P4G 2014-05-27 01:17 - 2009-07-14 09:44 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-05-27 01:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-05-27 01:10 - 2012-07-01 21:29 - 00683008 ___SH () C:\Users\Christof\Desktop\Thumbs.db 2014-05-27 00:56 - 2014-05-27 00:56 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Avira 2014-05-27 00:54 - 2014-05-27 00:54 - 00000000 ____D () C:\ProgramData\Avira 2014-05-27 00:54 - 2014-05-27 00:54 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-05-22 18:15 - 2012-07-10 21:49 - 00001080 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core.job 2014-05-21 17:39 - 2012-02-18 17:39 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Mozilla 2014-05-21 17:36 - 2014-01-01 23:36 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\.minecraft 2014-05-19 23:29 - 2012-02-19 22:00 - 00000000 ____D () C:\Users\Christof\Documents\VirtualDJ 2014-05-18 03:06 - 2011-11-30 14:28 - 00000000 ___RD () C:\Users\Christof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-18 03:06 - 2011-11-30 14:28 - 00000000 ___RD () C:\Users\Christof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-18 03:02 - 2014-05-07 03:01 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-15 21:46 - 2012-02-15 23:30 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-05-13 06:35 - 2013-06-14 13:13 - 00002292 _____ () C:\Users\Christof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Little Alchemy.lnk 2014-05-13 02:43 - 2014-04-16 18:13 - 00000000 ____D () C:\Users\Christof\Desktop\Hamburger City Girls 2014-05-13 02:09 - 2012-09-06 14:33 - 00000000 ____D () C:\Users\Christof\Documents\ANNO 2070 Demo 2014-05-13 02:09 - 2012-08-22 15:02 - 00000000 ____D () C:\Users\Christof\AppData\Roaming\Ubisoft 2014-05-13 02:09 - 2011-11-04 09:25 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-05-13 00:34 - 2014-05-13 00:34 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-13 00:18 - 2012-04-04 11:34 - 00000000 ____D () C:\Users\Christof\AppData\Local\LogMeIn Hamachi 2014-05-13 00:05 - 2009-07-29 08:03 - 00000000 ____D () C:\Windows\Panther 2014-05-12 07:26 - 2014-05-30 00:09 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:26 - 2014-05-30 00:09 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-05-30 00:09 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-09 11:16 - 2014-05-27 01:35 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-05-09 11:16 - 2014-05-27 01:35 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-05-09 11:16 - 2014-05-27 01:35 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-05-09 08:14 - 2014-05-14 22:59 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-09 08:11 - 2014-05-14 22:59 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-07 06:13 - 2012-07-10 21:49 - 00004108 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA 2014-05-07 06:13 - 2012-07-10 21:49 - 00003712 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core 2014-05-06 06:40 - 2014-05-15 21:46 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-06 06:17 - 2014-05-15 21:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-06 05:25 - 2014-05-15 21:46 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-06 05:07 - 2014-05-15 21:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-06 05:00 - 2014-05-15 21:46 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-06 04:10 - 2014-05-15 21:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll Some content of TEMP: ==================== C:\Users\Christof\AppData\Local\Temp\avgnt.exe C:\Users\Christof\AppData\Local\Temp\pid16.dll C:\Users\Christof\AppData\Local\Temp\pid32.dll C:\Users\Christof\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-23 01:46 ==================== End Of Log ============================ --- --- --- Addition.txt: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-06-2014 01 Ran by Christof at 2014-06-02 00:46:35 Running from C:\Users\Christof\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Trend Micro Titanium Internet Security (Disabled - Up to date) {68F968AC-2AA0-091D-848C-803E83E35902} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Trend Micro Titanium Internet Security (Disabled - Up to date) {D3988948-0C9A-0693-BE3C-BB4CF86413BF} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version: - Microsoft) 3D Pinball from Plus! for Windows 95 (HKLM-x32\...\Pinball) (Version: - ) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.2.0.2070 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.2.0.2070 - Adobe Systems Incorporated) Hidden Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.4.980 - Adobe Systems Incorporated.) Adobe Community Help (x32 Version: 3.4.980 - Adobe Systems Incorporated.) Hidden Adobe Download Assistant (HKLM-x32\...\com.adobe.downloadassistant.AdobeDownloadAssistant) (Version: 1.0.6 - Adobe Systems Incorporated) Adobe Download Assistant (x32 Version: 1.0.6 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.9.900.117 - Adobe Systems Incorporated) Adobe Photoshop CS5.1 (HKLM-x32\...\{9158FF30-78D7-40EF-B83E-451AC5334640}) (Version: 12.1 - Adobe Systems Incorporated) ANNO 1404 (HKLM-x32\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 1.02.0000 - Ubisoft) Anno 1404 (x32 Version: 1.00.0000 - Ubisoft) Hidden Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.12.5.0 - Asmedia Technology) ASUS AI Recovery (HKLM-x32\...\{38253529-D97D-4901-AE53-5CC9736D3A2E}) (Version: 1.0.13 - ASUS) ASUS FancyStart (HKLM-x32\...\{2B81872B-A054-48DA-BE3B-FA5C164C303A}) (Version: 1.0.8 - ASUSTeK Computer Inc.) ASUS K3 Series ScreenSaver (HKLM-x32\...\ASUS K3 Series ScreenSaver) (Version: 1.0.0002 - ASUS) ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.20 - ASUS) ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.0.6 - ASUS) ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.1.43 - ASUS) ASUS SmartLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0011 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0030 - ASUS) ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.21 - asus) ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.84.161 - eCareme Technologies, Inc.) AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.7.146 - ASUSTEK) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0010 - ASUS) Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.4.642 - Avira) Battlefield Heroes (HKLM-x32\...\{8DC910CD-8EE3-4ffc-A4EB-9B02701059C4}) (Version: - EA Digital illusions) Bing Bar (HKLM-x32\...\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}) (Version: 7.0.610.0 - Microsoft Corporation) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Bookworm Deluxe (HKLM-x32\...\Bookworm Deluxe) (Version: - Oberon Media Inc.) Cinema 4D version R12 (HKLM-x32\...\{7D9D8134-9FA3-4FFF-ADA1-BF609F29997A}_is1) (Version: R12 - Salat Production) Complément Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Complemento Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation) Cooking Dash (HKLM-x32\...\Cooking Dash) (Version: - Oberon Media Inc.) CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.1908 - CyberLink Corp.) CyberLink LabelPrint (x32 Version: 2.5.1908 - CyberLink Corp.) Hidden CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3602c - CyberLink Corp.) CyberLink Power2Go (x32 Version: 6.1.3602c - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Diner Dash 2 (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111212843}) (Version: - Oberon Media) Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited) Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.10 - ASUS) Fiesta Online DE 1.04.095 (HKLM-x32\...\Fiesta Online DE) (Version: 1.04.095 - Gamigo Games) Fiesta Online(EU_German) 1.04.000 (HKLM-x32\...\Fiesta Online(EU_German)) (Version: 1.04.000 - gamigo Games) Free System Utilities (HKLM-x32\...\{ee9b54a6-93dd-4070-80ae-743f58319407}) (Version: 1.0.0 - Covus Freemium GmbH) Free SystemUtilities (x32 Version: 1.0.0 - Covus Freemium GmbH) Hidden Free YouTube to MP3 Converter version 3.12.2.426 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.2.426 - DVDVideoSoft Ltd.) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Game Park Console (HKLM-x32\...\{E71E60C1-533E-45A5-8D80-E475E88D2B17}_is1) (Version: 6.2.1.1 - Oberon Media, Inc.) Google Chrome (HKCU\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.) Google Talk Plugin (HKLM-x32\...\{217CEB43-6D22-3E1F-A311-DC0D7BFEE0A2}) (Version: 5.4.1.18709 - Google) Governor of Poker (HKLM-x32\...\Governor of Poker) (Version: - Oberon Media Inc.) GreenWebPlayer (HKCU\...\gwp-DEFAULT) (Version: - ) <==== ATTENTION Happy Cloud Client (HKCU\...\HappyCloud) (Version: 4.28 - Happy Cloud, Inc.) HitmanPro.Alert (HKLM\...\HitmanPro.Alert) (Version: 2.6.5.77 - SurfRight B.V.) Hotel Dash Suite Success (HKLM-x32\...\Hotel Dash Suite Success) (Version: - Oberon Media Inc.) Intel PROSet Wireless (Version: - ) Hidden Intel PROSet Wireless (x32 Version: - ) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation) Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{3C41721F-AF0F-4086-AA1C-4C7F29076228}) (Version: 14.01.1000 - Intel Corporation) Intel(R) Turbo Boost Technology Monitor (HKLM\...\{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}) (Version: 1.0.400.4 - Intel) iTunes (HKLM\...\{D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0}) (Version: 11.1.3.8 - Apple Inc.) Java 7 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.250 - Oracle) Java Auto Updater (x32 Version: 2.1.9.5 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216031FF}) (Version: 6.0.310 - Oracle) JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation) Jewel Quest 3 (HKLM-x32\...\Jewel Quest 3) (Version: - Oberon Media Inc.) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Landwirtschafts Simulator 2013 (HKLM-x32\...\FarmingSimulator2013DE_is1) (Version: 1.0 - GIANTS Software) League of Legends (HKLM-x32\...\{92606477-9366-4D3B-8AE3-6BE4B29727AB}) (Version: 1.3 - Riot Games) Little Alchemy (HKCU\...\Pokki_faeb52fe0fea61b95b0070adc5264fa86cc0757f) (Version: 0.23.0 - Pokki) LogMeIn Hamachi (HKLM-x32\...\LogMeIn Hamachi) (Version: 2.1.0.294 - LogMeIn, Inc.) LogMeIn Hamachi (x32 Version: 2.1.0.294 - LogMeIn, Inc.) Hidden Luxor 3 (HKLM-x32\...\Luxor 3) (Version: - Oberon Media Inc.) Mahjongg dimensions (HKLM-x32\...\Mahjongg dimensions) (Version: - Oberon Media Inc.) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Messenger 分享元件 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192 - Microsoft Corporation) Hidden Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden Microsoft_VC90_MFCLOC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden Mobile Partner (HKLM-x32\...\Mobile Partner) (Version: 11.300.05.05.47 - Huawei Technologies Co.,Ltd) Mozilla Firefox 13.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 13.0.1 (x86 de)) (Version: 13.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 13.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT Redists (x32 Version: 1.0 - Sony Creative Software Inc.) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MySQL Connector/ODBC 5.1 (HKLM-x32\...\{29042B1C-0713-4575-B7CA-5C8E7B0899D4}) (Version: 5.1.5 - MySQL AB) Nuance PDF Reader (HKLM-x32\...\{B480904D-F73F-4673-B034-8A5F492C9184}) (Version: 6.00.0041 - Nuance Communications, Inc.) NVIDIA Control Panel 268.56 (Version: 268.56 - NVIDIA Corporation) Hidden NVIDIA Graphics Driver 268.56 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 268.56 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.265.41.0 - NVIDIA Corporation) Hidden NVIDIA Optimus 1.0.22 (Version: 1.0.22 - NVIDIA Corporation) Hidden NVIDIA Update Components (Version: 1.0.22 - NVIDIA Corporation) Hidden PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.) Plants vs Zombies (HKLM-x32\...\Plants vs Zombies) (Version: - Oberon Media Inc.) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.990 - Even Balance, Inc.) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.38.113.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6373 - Realtek Semiconductor Corp.) Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10001 - Realtek Semiconductor Corp.) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.1.10441 - Skype Technologies S.A.) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Sonic Focus (HKLM-x32\...\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: 1.0.0.4 - Synopsys ) Stormblade Launcher 1.1 (HKLM-x32\...\{D84EA2B7-F65E-43F3-9FB5-18B2162DBFA2}}_is1) (Version: - Stormblade.org) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.6.0 - Synaptics Incorporated) syncables desktop SE (HKLM-x32\...\{341697D8-9923-445E-B42A-529E5A99CB7A}) (Version: 5.5.746.11492 - syncables) System Requirements Lab for Intel (HKLM-x32\...\{C7CA731B-BF9A-46D9-92CF-8A8737AE9240}) (Version: 4.5.13.0 - Husdawg, LLC) TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.13.1 - TeamSpeak Systems GmbH) TeamViewer 7 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.13989 - TeamViewer) Trend Micro Titanium Internet Security (HKLM\...\{ABBD4BA8-6703-40D2-AB1E-5BB1F7DB49A4}) (Version: 3.0 - Trend Micro Inc.) Trend Micro Titanium Internet Security (Version: 3.00 - Trend Micro Inc.) Hidden TubeBox (HKLM-x32\...\{c5b74464-3a04-417c-9eee-d0dc7d6af196}) (Version: 4.1.0.0 - Freetec) TubeBox (x32 Version: 4.1.0.0 - Freetec) Hidden TubeBox! (HKLM-x32\...\{A78A5C61-2397-407E-A41F-0A0FFAD2572F}) (Version: 3.4.9 - Jens Lorek) TuneUp Utilities 2012 (HKLM-x32\...\TuneUp Utilities 2012) (Version: 12.0.3600.73 - TuneUp Software) TuneUp Utilities 2012 (x32 Version: 12.0.3600.73 - TuneUp Software) Hidden TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.3600.73 - TuneUp Software) Hidden UltraStar 1.0.2 (HKLM-x32\...\UltraStar) (Version: 1.0.2 - SterGames) Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) Vegas Pro 10.0 (HKLM-x32\...\{6E0E4D61-11EC-11E0-B454-0013D3D69929}) (Version: 10.0.469 - Sony) Virtual Audio Cable 4.10 (HKLM\...\Virtual Audio Cable 4.10) (Version: - ) VirtualDJ Home FREE (HKLM-x32\...\{A6AC699F-8315-40CA-8F70-E917494978AB}) (Version: 7.4 - Atomix Productions) VirtualDJ PRO Full (HKLM-x32\...\{4769E972-2E92-49C5-B6F9-465EFD0C4D94}) (Version: 7.0.5 - Atomix Productions) VLC media player 2.1.0 (HKLM\...\VLC media player) (Version: 2.1.0 - VideoLAN) War Thunder Launcher 1.0.1.252 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version: - 2013 Gaijin Entertainment Corporation) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.31.0 - ASUS) WinRAR 4.10 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.10.0 - win.rar GmbH) Wireless Console 3 (HKLM-x32\...\{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}) (Version: 3.0.19 - ASUS) World of Goo (HKLM-x32\...\World of Goo) (Version: - Oberon Media Inc.) World of Tanks - Common Test (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812CT}_is1) (Version: - Wargaming.net) World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812}_is1) (Version: - Wargaming.net) Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Компаньон Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2-8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation) גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden מסייע Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (HKLM-x32\...\{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}) (Version: 15.4.5722.2 - Microsoft Corporation) بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\...\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 - Microsoft Corporation) معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden 適用遠端連線的 Windows Live Mesh ActiveX 控制項 (HKLM-x32\...\{622DE1BE-9EDE-49D3-B349-29D64760342A}) (Version: 15.4.5722.2 - Microsoft Corporation) ==================== Restore Points ========================= 10-05-2014 01:15:15 Windows Update 14-05-2014 20:51:16 Windows Update 15-05-2014 19:44:45 Windows Modules Installer 22-05-2014 16:22:50 Windows Update 26-05-2014 23:34:17 Windows Update 28-05-2014 16:47:25 ComboFix created restore point ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-05-28 19:03 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {08B3AC75-315C-4200-B48E-F5487B7775A8} - \Software Updater Ui No Task File <==== ATTENTION Task: {0A324023-A490-4F18-AC05-F3389C59CA23} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe Task: {14BD47B8-3C90-474F-8BCE-E3A36A64333A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA => C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-10] (Google Inc.) Task: {305613CB-9467-47E6-ABBD-6CF9B2F3EA13} - \Software Updater No Task File <==== ATTENTION Task: {38BCBE7F-4350-4D89-B5ED-3CFBDDE3FEF1} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-08-31] (ASUSTeK Computer Inc.) Task: {44F84D1D-BC08-4902-B944-283B60961319} - \AdobeFlashPlayerUpdate 2 No Task File <==== ATTENTION Task: {46B1A0E5-1F8C-4724-8A6C-B30B4288C378} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2010-08-02] (ASUS) Task: {528B427F-F855-439A-A47E-8DFCC6587779} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA => C:\Users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-28] (Facebook Inc.) Task: {54C92ACB-03D0-4B1F-8F36-FF39DADEB6A5} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS) Task: {6C6A8579-8CF2-445B-A7A9-BC21E849CE38} - \EPUpdater No Task File <==== ATTENTION Task: {7F8DDFFF-4721-4D33-898A-031679957DA3} - System32\Tasks\AIRecoveryRemind => C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryRemind.exe [2010-12-18] (ASUSTek Computer Inc.) Task: {884FF545-7FAB-455B-8A88-12EA4873BCC7} - System32\Tasks\Audio Performer => C:\Users\Christof\AppData\Local\Temp\Audio Performer53412.exe <==== ATTENTION Task: {A5F799F2-B796-4048-AB70-F08B27DB2A5E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core => C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-10] (Google Inc.) Task: {A73C4B6B-AEE9-4035-8357-30EC38D0A0C4} - \AdobeFlashPlayerUpdate No Task File <==== ATTENTION Task: {BD47C0B0-5BDB-4979-B058-10B6F669F213} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS) Task: {C3A9702F-5672-4B6F-9D04-189326B5D246} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {D4632569-0F66-4C76-ADAB-D3AD6884D06C} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-12-02] (ASUS) Task: {E3716629-CF68-4C81-B9AA-1432405CFF1D} - \BitGuard No Task File <==== ATTENTION Task: {FA25F409-1B67-4A6B-8C09-766B2C3D7905} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core => C:\Users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-28] (Facebook Inc.) Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core.job => C:\Users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA.job => C:\Users\Christof\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001Core.job => C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2465417766-3482814047-1650821192-1001UA.job => C:\Users\Christof\AppData\Local\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll 2010-04-03 04:21 - 2008-10-01 08:08 - 00011264 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll 2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll 2012-02-04 13:01 - 2012-02-04 13:01 - 00075136 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2010-01-02 16:42 - 2010-01-02 16:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2011-07-07 08:12 - 2011-01-27 02:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2011-07-07 08:10 - 2011-05-05 14:30 - 00057640 _____ () C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll 2011-05-02 22:41 - 2011-05-02 22:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll 2010-09-24 01:53 - 2010-09-24 01:53 - 01601536 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe 2011-03-28 11:03 - 2011-03-28 11:03 - 00050176 _____ () C:\Program Files\Adobe\Adobe Photoshop CS5.1 (64 Bit)\QuickTimeGlue.dll 2014-06-02 00:37 - 2014-06-02 00:37 - 00854367 _____ () C:\Users\Christof\Downloads\SecurityCheck.exe 2013-09-13 19:51 - 2013-09-13 19:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-09-13 19:51 - 2013-09-13 19:51 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2011-08-31 15:33 - 2011-08-31 15:33 - 00208384 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll 2009-11-02 23:20 - 2009-11-02 23:20 - 00619816 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2009-11-02 23:23 - 2009-11-02 23:23 - 00013096 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2012-01-08 15:41 - 2012-01-08 15:41 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2014-05-27 17:07 - 2014-05-14 01:40 - 00716616 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\libglesv2.dll 2014-05-27 17:07 - 2014-05-14 01:40 - 00126280 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\libegl.dll 2014-05-27 17:07 - 2014-05-14 01:40 - 04217672 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\pdf.dll 2014-05-27 17:07 - 2014-05-14 01:40 - 00414536 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll 2014-05-27 17:07 - 2014-05-14 01:40 - 01732424 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\ffmpegsumo.dll 2014-05-27 17:07 - 2014-05-14 01:40 - 13695816 _____ () C:\Users\Christof\AppData\Local\Google\Chrome\Application\35.0.1916.114\PepperFlash\pepflashplayer.dll 2011-01-12 07:08 - 2011-01-12 07:08 - 00060416 _____ () C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\zlib1.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:3CF2806E ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service" ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/01/2014 04:13:37 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 11388 Error: (06/01/2014 04:13:37 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 11388 Error: (06/01/2014 04:13:37 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/01/2014 04:13:36 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 10390 Error: (06/01/2014 04:13:36 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 10390 Error: (06/01/2014 04:13:36 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/01/2014 04:13:35 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9360 Error: (06/01/2014 04:13:35 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9360 Error: (06/01/2014 04:13:35 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/01/2014 04:13:34 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 8315 System errors: ============= Error: (06/01/2014 01:06:46 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst AntiVirSchedulerService erreicht. Error: (05/31/2014 10:18:44 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst RasMan erreicht. Error: (05/31/2014 10:18:22 PM) (Source: Server) (EventID: 2505) (User: ) Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{47CE57E1-00DD-4149-B51B-B23F9E190A5A} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden. Error: (05/30/2014 04:40:21 PM) (Source: WMPNetworkSvc) (EventID: 14332) (User: ) Description: WMPNetworkSvc0x80070420 Error: (05/30/2014 04:38:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (05/30/2014 04:38:22 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Presentation Foundation-Schriftartcache 3.0.0.0 erreicht. Error: (05/30/2014 04:37:27 PM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Avira Echtzeit-Scanner" wurde nicht richtig gestartet. Error: (05/30/2014 04:35:08 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "TuneUp Utilities Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (05/30/2014 04:35:01 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "LogMeIn Hamachi Tunneling Engine" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (05/30/2014 01:55:06 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Microsoft Office Sessions: ========================= Error: (04/03/2013 07:05:03 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 3, Application Name: Microsoft Office PowerPoint, Application Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1832 seconds with 660 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-06-01 13:07:02.343 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-01 02:47:24.502 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-01 02:41:00.478 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-01 02:24:12.832 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-31 22:18:26.949 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-31 02:20:32.307 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-31 01:17:47.683 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-30 21:57:09.855 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-30 01:55:12.798 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-30 00:56:11.878 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\hmpalert.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 63% Total physical RAM: 6054.7 MB Available physical RAM: 2222.25 MB Total Pagefile: 12107.57 MB Available Pagefile: 5911.57 MB Total Virtual: 8192 MB Available Virtual: 8191.86 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:279.45 GB) (Free:90.87 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (DATA) (Fixed) (Total:394.18 GB) (Free:393.86 GB) NTFS Drive e: (CTH_V800C) (CDROM) (Total:0.42 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 699 GB) (Disk ID: 496B9619) Partition 1: (Not Active) - (Size=25 GB) - (Type=1C) Partition 2: (Active) - (Size=279 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=394 GB) - (Type=07 NTFS) ==================== End Of Log ============================ So weit schein Alles Gut zu sein, würde gerne erfahren was mir bzw. dir/ihnen die einzelnen programme gebracht haben und wie er jetzt beseitigt wurde. Durch welches Programm davon? Welche Programme davon kann ich jetzt wieder Deinstallieren usw.? :l Vielen Lieben Dank für die Hilfe! (: Geändert von Gytoro (02.06.2014 um 00:12 Uhr) Grund: Logfile. |
02.06.2014, 19:03 | #11 |
/// the machine /// TB-Ausbilder | TR/BProtector.Gen Java, Flash und Firefox updaten. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\Christof\AppData\Local\CRE HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] - rmdir /s /q "\SearchProtect" Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Kein einzelnes, das Zusammensiel aller mit den händischen Arbeiten hat es gebracht. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.06.2014, 23:00 | #12 |
| TR/BProtector.Gen Fixlog.txt Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-06-2014 Ran by Christof at 2014-06-03 23:01:42 Run:1 Running from C:\Users\Christof\Downloads\FRST-OlderVersion Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\Christof\AppData\Local\CRE HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] - rmdir /s /q "\SearchProtect" ***************** "C:\Users\Christof\AppData\Local\CRE HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] - rmdir /s /q \SearchProtect"" => File/Directory not found. ==== End of Fixlog ==== Bedanke mich hiermit erstmal und werde die weiteren schritte anwendern, werde mich auf jeden fall nochmals melden. Danke! Habe jetzt IE u. Mozilla Aktualisiert (benütze es jedoch eig. nicht) u. all andere Anti Viren Programme Installiert, vielen Danke! Benutze jedoch Google Chrome, gibts es dafür auch nützliche AddOns? Weiterhin Passt alles, Viele Dank, werde ein natürlich sobald ich mir dafür Zeit nehmen kann ein Lob schreiben, Danke!. |
04.06.2014, 18:59 | #13 |
/// the machine /// TB-Ausbilder | TR/BProtector.Gen Die Addons solltest du auch bei Chrome finden. Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |