Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Sicheres Löschen von "PSHD-9.9"

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 10.06.2014, 11:35   #16
Goodfell
 
Sicheres Löschen von "PSHD-9.9" - Standard

Sicheres Löschen von "PSHD-9.9"



Ohje, jetzt verunsicherst du mich ob ich alles richtig gemacht habe
ich lad dir mal ein screenshot hoch, wundert mich nämlich das da steht keine aktion durch den benutzer.
Soll ich mbam lieber nochmal drüber laufen lassen ?




Code:
ATTFilter


Zoek.exe v5.0.0.0 Updated 02-June-2014
Tool run by Sven on 10.06.2014 at 12:01:03,82.
Microsoft Windows 7 Home Premium  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Sven\Downloads\zoek.exe [Scan all users] [Script inserted] 

==== System Restore Info ======================

10.06.2014 12:05:19 Zoek.exe System Restore Point Created Succesfully.

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ceefadbd-a0ce-4422-a760-3b9167344e06} deleted successfully
HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ceefadbd-a0ce-4422-a760-3b9167344e06} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{ceefadbd-a0ce-4422-a760-3b9167344e06} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ceefadbd-a0ce-4422-a760-3b9167344e06} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{ceefadbd-a0ce-4422-a760-3b9167344e06} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\op2zog0l.default\prefs.js:

Added to C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\op2zog0l.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

Deleted from C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\prefs.js:
user_pref("browser.search.suggest.enabled", false);
user_pref("browser.search.useDBForOrder", false);

Added to C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\prefs.js:
user_pref("browser.startup.homepage", "hxxp://www.google.com");
user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "hxxp://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\op2zog0l.default

user.js not found
---- FireFox user.js and prefs.js backups ---- 

prefs__1222_.backup

ProfilePath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default

user.js not found
---- Lines aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916 removed from prefs.js ----
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.active", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.addressbar", "NA");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.addressbarenhanced", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncdb.was_copied", "true");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncdb_dbWasSet", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncinternaldb.was_copied", "true");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncinternaldb_dbWasSet", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.backgroundver", 2);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.certdomaininstaller", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.changeprevious", false);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.InstallationTime.value", "%221401873642%2
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.InstallerParams.expiration", "Fri Feb 01 
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.InstallerParams.value", "%7B%22source_id%
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.description", "Turn YouTube videos to High Defin
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.domain", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.enablesearch", false);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.homepage", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.iframe", false);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.InstallationThankYouPage", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.InstallationTime", 1401873642);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.__defualt_browser__.expiration", "Fri
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.__defualt_browser__.value", "%22ch%22
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb._installer_additional_info.expiration
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb._installer_additional_info.value", "%
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.installer.expiration", "Fri Feb 01 20
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.installer.value", "%7B%22InstallerIde
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerParams.expiration", "Fri Feb
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerParams.value", "%7B%22source
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerParamsCache.expiration", "Fr
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerUserIdentifiersCache.expirat
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerUserIdentifiersCache.value",
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_bundledUrls.expir
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_bundledWithHash.e
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_bundledWithHash.v
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_notBundledArr_.ex
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_notBundledArr_.va
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_remote_resources.expiration
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_remote_resources.value", "%
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.lastDailyReport", "1401930857390");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.lastUpdate", "1401930836376");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.manifesturl", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.name", "PSHD-9.9");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.newtab", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.opensearch", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.pluginsurl", "hxxp://js.datademoserv.com/plugin/
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.pluginsversion", 45);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.publisher", "PlusVHD");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.searchstatus", 0);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.setnewtab", false);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.thankyou", "");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.updateinterval", 360);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.ver", 52);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.apps", "52916");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.bic", "1466996dea30ea4dd107112a5d7842b3");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.cid", 52916);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.firstrun", false);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.hadappinstalled", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.installationdate", 1401930834);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.modetype", "production");
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.reportInstall", true);
user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.statsDailyCounter", 1);
---- FireFox user.js and prefs.js backups ---- 

prefs__1222_.backup

==== Deleting Files \ Folders ======================

C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
C:\found.000 deleted
C:\found.001 deleted
C:\found.002 deleted
C:\Users\Sven\AppData\Roaming\GetRightToGo deleted
C:\PROGRA~3\ICQ deleted
C:\PROGRA~3\InstallMate deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Gast\AppData\Local\avgchrome deleted
C:\Users\Sven\AppData\Local\avgchrome deleted
C:\Users\Gast\AppData\LocalLow\store-pp.jbs deleted
C:\Users\Sven\AppData\LocalLow\store-pp.jbs deleted
C:\Windows\Launcher.exe deleted
C:\Windows\Syswow64\tmp561E.tmp deleted
C:\Windows\Syswow64\tmp564E.tmp deleted
C:\Windows\Syswow64\tmp86CF.tmp deleted
C:\Windows\Syswow64\tmp878B.tmp deleted
C:\Windows\Syswow64\tmpDC75.tmp deleted
C:\Windows\Syswow64\tmpDCE3.tmp deleted
C:\Windows\SysWow64\searchplugins deleted
C:\Windows\SysWow64\Extensions deleted
C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\extensions\firefox@ravingreyven.mobi.xpi deleted
C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\foxydeal.sqlite deleted
C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\CT2269050 deleted
C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\CT2431245 deleted
C:\Users\Sven\Desktop\Datein\pkm\SoftonicDownloader_fuer_visualboyadvance.exe deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [05.06.2014 06:15]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"{B64D9B05-48E1-4CEB-BF58-E0643994E900}"="C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff" [18.05.2014 11:29]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default
- ProxTube - Gesperrte YouTube Videos entsperren - %ProfilePath%\extensions\ich@maltegoetz.de
- Protegere - %ProfilePath%\extensions\security@protegere.org
- OutBrowse Toolbar - %ProfilePath%\extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc}
- TrashMail.net - %ProfilePath%\extensions\spam@trashmail.net.xpi
- FoxBox - %ProfilePath%\extensions\{df4e4df5-5cb7-46b0-9aef-6c784c3249f8}.xpi
- User Agent Switcher - %ProfilePath%\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default
A58DE0A570148AF5FF3512B2A340D09F	- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll -	Shockwave Flash
FF0D6F82A0EC13952E83B9439100E45D	- C:\Users\Sven\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll -	Facebook Video Calling Plugin
2BF85B6162528E0635DD8D632EB975C8	- C:\Users\Sven\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll -	Facebook Desktop
546A28FBC44B984FD92530227BF6F5C2	- C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll -	Shockwave for Director / Shockwave for Director
905FD4EF56FCFD83D51FFA15E3FCE51E	- C:\Users\Sven\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll -	Move Media Player 7


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
daanglpcpkjjlkhcbladppjphglbigam - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[05.06.2014 06:14]


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
"Start Default_Page_URL"="hxxp://www.google.com"
"Default_Search_URL"="hxxp://www.google.com"
"Search Bar"="hxxp://www.google.com"
"ICQ Search"="hxxp://www.google.com"
"Use Search Asst"="yes"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Default_Search_URL"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Bar"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Page"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Default_Search_URL"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Bar"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Page"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
"Start Default_Page_URL"="hxxp://www.google.com"
"Search Bar"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
"Start Default_Page_URL"="hxxp://www.google.com"
"Search Bar"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://www.google.com"
"Default"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://www.google.com"
"Default"="hxxp://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://www.google.com"
"Default"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search]
"Start Page"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Default_Search_URL"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Bar"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Page"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Search]
"Start Page"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876"
"Default_Search_URL"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Bar"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
"Search Page"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q="
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Start Page"="hxxp://www.google.com"
"Start Default_Page_URL"="hxxp://www.google.com"
"Default_Search_URL"="hxxp://www.google.com"
"Search Bar"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"Start Page"="hxxp://www.google.com"
"Start Default_Page_URL"="hxxp://www.google.com"
"Default_Search_URL"="hxxp://www.google.com"
"Search Bar"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Start Page"="hxxp://www.google.com"
"Start Default_Page_URL"="hxxp://www.google.com"
"Default_Search_URL"="hxxp://www.google.com"
"Search Bar"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
"SearchAssistant"="hxxp://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"ICQ Search"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="hxxp://www.google.com"
"Use Search Asst"="no"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="hxxp://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"
"Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google  Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Reset Google Chrome ======================

C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Reset IE Proxy ======================

Value(s) before fix:
"ProxyServer"="http=;ftp=;https=;"
"ProxyEnable"=dword:00000000

Value(s) after fix:
"ProxyEnable"=dword:00000000

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DF1ECEF5-E5DC-7381-F153-A1348E310A5B} deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeCall deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlusLiveUninstall deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Gast\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Sven\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Gast\AppData\Local\Mozilla\Firefox\Profiles\op2zog0l.default\Cache emptied successfully
C:\Users\Sven\AppData\Local\Mozilla\Firefox\Profiles\p4ytj1qg.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=296 folders=71 77935732 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Gast\AppData\Local\Temp emptied successfully
C:\Users\Sven\AppData\Local\Temp will be emptied at reboot
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Sven\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on 10.06.2014 at 12:30:43,39 ======================
         
Miniaturansicht angehängter Grafiken
-cats.jpg  

Alt 10.06.2014, 11:37   #17
M-K-D-B
/// TB-Ausbilder
 
Sicheres Löschen von "PSHD-9.9" - Standard

Sicheres Löschen von "PSHD-9.9"



Zitat:
Zitat von Goodfell Beitrag anzeigen
Soll ich mbam lieber nochmal drüber laufen lassen ?
Ja bitte... dauert ja nur ein paar Minuten.

Am besten währenddessen nichts am Rechner machen.
__________________


Alt 10.06.2014, 11:59   #18
Goodfell
 
Sicheres Löschen von "PSHD-9.9" - Standard

Sicheres Löschen von "PSHD-9.9"



Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 10.06.2014
Suchlauf-Zeit: 12:38:50
Logdatei: MBAM 2.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.06.10.02
Rootkit Datenbank: v2014.06.02.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Sven

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 383357
Verstrichene Zeit: 12 Min, 35 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Warnen
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 12
PUP.Optional.OutBrowse, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{CEEFADBD-A0CE-4422-A760-3B9167344E06}, In Quarantäne, [5c6e0e685823ef473a62a797c939f50b], 
PUP.Optional.OutBrowse, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{CEEFADBD-A0CE-4422-A760-3B9167344E06}, In Quarantäne, [5c6e0e685823ef473a62a797c939f50b], 
PUP.Optional.PricePeep.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}, In Quarantäne, [07c3a1d5c4b71521e88fc7aa07fbb848], 
PUP.Optional.PricePeep.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}, In Quarantäne, [07c3a1d5c4b71521e88fc7aa07fbb848], 
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\PSHD-9.9, In Quarantäne, [1fab7105097275c1e2046e3518ea24dc], 
PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PSHD-9.9, In Quarantäne, [4288373f3f3c2c0a25bfc5de3ac8916f], 
PUP.Optional.OutBrowse, HKU\S-1-5-21-1098949856-1301053314-1890294551-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Outbrowsetoolbar, In Quarantäne, [d1f9e591205bc076c3677969a063dc24], 
PUP.Optional.PlusHD.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PSHD-9.9, In Quarantäne, [8743e690bbc07abcde06d6cd33cfd927], 
PUP.Optional.PricePeep.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PricePeep, In Quarantäne, [48820b6b8af1c86e94abd9e561a1e31d], 
PUP.Optional.Babylon.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, In Quarantäne, [16b47ff74f2ceb4bb27f0bc745be1fe1], 
PUP.Optional.BProtector.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\BPROTECTSETTINGS, In Quarantäne, [2b9fb8be4a3184b251326272e91a4ab6], 
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PSHD-9.9, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 6
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh0HHLt9EvHpdsBSNIcEGIjdmo8CMRkTrkziZb8t8ApvoxKHNUP2bzDfHfGP57oCmfu, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh0HHLt9EvHpdsBSNIcEGIjdmo8CMRkTrkziZb8t8ApvoxKHNUP2bzDfHfGP57oCmfu),Ersetzt,[676385f12b503afc0fb1b3bc7c88f808]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Ersetzt,[c00aa1d5314a181e8f2ffb740df7827e]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Ersetzt,[ebdfd1a55c1f90a61aa579f6ba4a48b8]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Ersetzt,[9139fa7c0c6f1a1cc9f8df908f757f81]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Ersetzt,[af1b4630cbb064d200c2aec155afa957]
PUP.Optional.SnapDo.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Ersetzt,[4a807ff7304bb97ddc7e8bdb976d9b65]

Ordner: 4
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe, In Quarantäne, [b9113b3b8af113232d795338a55d8878], 
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], 
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0, In Quarantäne, [18b26610d8a383b36d663d4fc63ce917], 
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 

Dateien: 34
PUP.Optional.SnapDo.A, C:\Windows\Installer\17f2707.msi, In Quarantäne, [5b6f9dd93348b18509de483dfc05a65a], 
PUP.Optional.SmartBar, C:\Windows\Installer\MSI6E5.tmp, In Quarantäne, [7e4c1a5cef8cda5c77a58ea0b64a4cb4], 
PUP.Optional.SmartBar, C:\Windows\Installer\MSI999F.tmp-\Smartbar.Installer.CustomActions.dll, In Quarantäne, [5377d0a67ffc0333b16b35f957a9a25e], 
PUP.Optional.SmartBar, C:\Windows\Installer\MSI6E5.tmp-\Smartbar.Installer.CustomActions.dll, In Quarantäne, [14b6b6c08af1181eda4288a6b44cdf21], 
PUP.Optional.Ciuvo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage, In Quarantäne, [7654096d304bba7c8f483664936fbf41], 
PUP.Optional.Ciuvo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage-journal, In Quarantäne, [0dbd2056077463d34e8993071be7df21], 
PUP.Optional.SelectNGo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage, In Quarantäne, [ecdee096097270c669609e00c2403cc4], 
PUP.Optional.SelectNGo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage-journal, In Quarantäne, [1baf591d6e0d2e0824a5c3db8c76b749], 
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0.localstorage, In Quarantäne, [56740a6c156623137b893b72e022ad53], 
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0.localstorage-journal, In Quarantäne, [d7f3284ec1baec4a669ebcf18979956b], 
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000005.ldb, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], 
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000013.ldb, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], 
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000016.ldb, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], 
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000020.log, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], 
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\CURRENT, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], 
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\LOCK, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], 
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\LOG, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], 
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\LOG.old, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], 
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\MANIFEST-000018, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], 
PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0\3, In Quarantäne, [18b26610d8a383b36d663d4fc63ce917], 
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bho64.dll, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\1293297481.mxaddon, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\360-52916.crx, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\41220790-4b35-4753-91f3-94289344bd48-3.exe, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\52916.crx, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\52916.xpi, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\background.html, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\bgNova.html, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bg.exe, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bho.dll, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-nova.dll, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9.ico, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\Uninstall.exe, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\utils.exe, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], 

Physische Sektoren: 0
(No malicious items detected)


(end)
         
__________________

Alt 10.06.2014, 12:00   #19
M-K-D-B
/// TB-Ausbilder
 
Sicheres Löschen von "PSHD-9.9" - Standard

Sicheres Löschen von "PSHD-9.9"



Gut gemacht.


Jetzt weiter mit Zoek bitte.

Alt 10.06.2014, 12:00   #20
Goodfell
 
Sicheres Löschen von "PSHD-9.9" - Standard

Sicheres Löschen von "PSHD-9.9"



FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-06-2014 01
Ran by Sven (administrator) on SVEN-PC on 10-06-2014 12:56:42
Running from C:\Users\Sven\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\System32\audiodg.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(NVIDIA) C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Winstep Software Technologies) C:\Program Files (x86)\Winstep\WsxService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Dropbox, Inc.) C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
() C:\Program Files (x86)\Opera\22.0.1471.50\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe


==================== Registry (Whitelisted) ==================

HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2245120 2009-07-15] (VIA)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NextSTART] => [X]
HKLM-x32\...\Run: [Workshelf] => [X]
HKLM-x32\...\Run: [G Data AntiVirus Tray Application] => C:\Program Files (x86)\G Data\TotalProtection\AVKTray\AVKTray.exe
HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G Data\TotalProtection\Firewall\GDFirewallTray.exe
HKLM-x32\...\Run: [NPSStartup] => [X]
HKLM-x32\...\Run: [avgnt] => "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3859320 2014-06-05] (AVAST Software)
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Pando Media Booster] => C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2937528 2010-05-02] ()
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Upgrade] => C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F}\Upgrade.exe
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [NVIDIA nTune] => C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe [98304 2007-09-04] (NVIDIA)
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Auto KTR] => C:\Users\Sven\Downloads\Dm.De.M.C.Co.Edit-PROP\Kaspersky Internet Security 2014 + Trial + Kaspersky World\Kaspersky_Internet_Security_Trial_Reset_2.1_by_Humschi_1857\KIS14 TrialReset.exe -silent
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\MountPoints2: {732ced11-838c-11df-934f-002618bca0f6} - E:\raf-skyrim.exe
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\MountPoints2: {c6647fc0-dbee-11e1-b1d5-806e6f6e6963} - E:\setup.exe
Startup: C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x27BB72947FE9CA01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU -  {6552C7DD-90A4-4387-B795-F8F96747DE19}
SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP80B4BA23-BA51-47B6-A18B-B617C84C81FE&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF ProfilePath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF NetworkProxy: "autoconfig_url", "64.85.181.46"
FF NetworkProxy: "http", "64.85.181.46"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "type", 1
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @movenetworks.com/Quantum Media Player - C:\Users\Sven\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Sven\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Sven\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPandoWebInst.dll (Pando Networks)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Unblock YouTube - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\ich@maltegoetz.de [2014-05-20]
FF Extension: Protegere - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\security@protegere.org [2014-06-05]
FF Extension: OutBrowse Toolbar - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc} [2013-04-17]
FF Extension: TrashMail.net - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\spam@trashmail.net.xpi [2011-10-11]
FF Extension: Fox!Box - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{df4e4df5-5cb7-46b0-9aef-6c784c3249f8}.xpi [2011-04-03]
FF Extension: User Agent Switcher - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2011-12-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-06-05]
FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\
FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ []

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Google Drive) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-05]
CHR Extension: (YouTube) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-05]
CHR Extension: (Google Search) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-05]
CHR Extension: (Google Wallet) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-05]
CHR Extension: (Gmail) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-05]
CHR HKLM-x32\...\Chrome\Extension: [daanglpcpkjjlkhcbladppjphglbigam] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-06-05]

==================== Services (Whitelisted) =================

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-06-05] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-10-01] () [File not signed]
S4 DlProtectSvc; C:\Windows\System32\DlProtectSvc.exe [123392 2014-06-04] () [File not signed]
R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3772784 2010-05-10] (INCA Internet Co., Ltd.) [File not signed]
R2 nTuneService; C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe [180224 2007-09-04] (NVIDIA) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-12] ()
S2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [97552 2012-03-22] (SANDBOXIE L.T.D)
S3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [430592 2008-04-07] (Nokia.) [File not signed]
S3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [821720 2012-08-21] (Mister Group)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [738152 2012-07-19] (Tunngle.net GmbH) [File not signed]
S2 KMService; C:\Windows\system32\srvany.exe [X]
R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X]

==================== Drivers (Whitelisted) ====================

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-06-05] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-06-05] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-06-05] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-06-05] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-06-05] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-06-05] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-06-05] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [84816 2014-06-05] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-06-05] ()
R2 DRHARD64; C:\Windows\system32\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software)
R2 DRHARD64; C:\Windows\SysWOW64\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software)
R2 DRHMSR64; C:\Windows\system32\drivers\DRHMSR64.sys [14760 2011-12-06] ()
R2 DRHMSR64; C:\Windows\SysWOW64\drivers\DRHMSR64.sys [14760 2011-12-06] ()
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [65912 2012-03-08] (G Data Software AG)
R3 KMWDFILTERV1; C:\Windows\System32\DRIVERS\RPGMOUSEV1.sys [24576 2009-06-10] (Windows (R) Codename Longhorn DDK provider)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
S3 nocashio; C:\Windows\SysWOW64\drivers\nocashio.sys [4096 2010-08-18] () [File not signed]
S3 NPPTNT2; C:\Windows\SysWOW64\npptNT2.sys [4682 2005-01-04] (INCA Internet Co., Ltd.) [File not signed]
R3 NVR0Dev; C:\Windows\nvoclk64.sys [39968 2007-09-04] (NVidia Corp.)
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [13368 2013-01-23] ()
S3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [155136 2012-05-08] (SANDBOXIE L.T.D) [File not signed]
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-10-10] (Duplex Secure Ltd.)
S3 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2007-10-25] () [File not signed]
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) [File not signed]
R2 WinRing0_1_2_0; C:\Users\Sven\AppData\Local\Microsoft\Windows Sidebar\Gadgets\IntelCoreSeries24.gadget\WinRing0x64.sys [14544 2010-05-02] (OpenLibSys.org)
R3 wod0205; C:\Windows\System32\DRIVERS\wod0205.sys [33160 2011-04-23] (WeOnlyDo Software)
U3 ar90ehyq; C:\Windows\System32\Drivers\ar90ehyq.sys [0 ] (Advanced Micro Devices)
S3 DRHARD; \??\C:\Windows\system32\DRIVERS\DRHARD.SYS [X]
S3 dump_wmimmc; \??\C:\Program Files (x86)\Gameforge4D\CABAL Online\GameGuard\dump_wmimmc.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 X6va003; \??\C:\Users\Sven\AppData\Local\Temp\0035BEA.tmp [X]
S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X]
S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-10 12:55 - 2014-06-10 12:55 - 00014016 _____ () C:\Users\Sven\Desktop\MBAM 2.txt
2014-06-10 12:29 - 2014-06-10 12:58 - 00000000 ____D () C:\Users\Sven\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Gast\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default User\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:00 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-06-10 12:23 - 2014-06-10 12:23 - 00017954 _____ () C:\Users\Sven\Desktop\MMBAM TEXT.txt
2014-06-10 12:04 - 2014-06-10 12:30 - 00032826 _____ () C:\zoek-results.log
2014-06-10 12:04 - 2014-06-10 12:04 - 00003180 _____ () C:\Windows\System32\Tasks\{7D573011-FC61-42C2-A61F-1E0B7044A895}
2014-06-10 12:03 - 2014-05-21 08:31 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.scr
2014-06-10 12:03 - 2014-05-21 08:31 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.com
2014-06-10 12:02 - 2014-06-10 12:02 - 04235784 _____ () C:\Users\Sven\Downloads\zoek.rar
2014-06-10 12:00 - 2014-06-10 12:22 - 00000000 ____D () C:\zoek_backup
2014-06-10 11:58 - 2014-06-10 11:58 - 00000886 _____ () C:\Users\Sven\Desktop\mbam.txt
2014-06-10 11:56 - 2014-06-10 11:56 - 00000652 _____ () C:\Users\Sven\Desktop\MAAABM.txt
2014-06-10 11:49 - 2014-06-10 11:49 - 00016076 _____ () C:\Users\Sven\Desktop\teeext.txt
2014-06-10 11:35 - 2014-06-10 11:36 - 04094386 _____ () C:\Users\Sven\Downloads\zoek.zip
2014-06-10 11:35 - 2014-06-10 11:35 - 01285120 _____ () C:\Users\Sven\Downloads\zoek.exe
2014-06-10 11:28 - 2014-06-10 12:54 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-10 11:28 - 2014-06-10 11:28 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-10 11:28 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-10 11:28 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-10 11:26 - 2014-06-10 11:27 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (2).exe
2014-06-10 11:18 - 2014-06-10 11:19 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (1).exe
2014-06-10 11:07 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-10 11:02 - 2014-06-10 11:11 - 00000000 ____D () C:\AdwCleaner
2014-06-10 11:01 - 2014-06-10 11:01 - 01333465 _____ () C:\Users\Sven\Downloads\adwcleaner_3.212.exe
2014-06-10 01:28 - 2014-06-10 01:28 - 00000042 _____ () C:\Users\Sven\Downloads\sl.dta
2014-06-10 01:11 - 2014-06-10 02:09 - 00000000 ____D () C:\Users\Sven\Downloads\NextChaos
2014-06-10 00:01 - 2014-06-10 01:10 - 1956407488 _____ () C:\Users\Sven\Downloads\NextChaos.zip
2014-06-09 18:17 - 2014-06-09 18:22 - 149696637 _____ () C:\Users\Sven\Downloads\uiii.rar
2014-06-09 15:56 - 2014-06-09 15:56 - 00090241 _____ () C:\Users\Sven\Downloads\Addition.txt
2014-06-09 15:04 - 2014-06-10 12:57 - 00020788 _____ () C:\Users\Sven\Downloads\FRST.txt
2014-06-09 15:04 - 2014-06-10 12:56 - 00000000 ____D () C:\FRST
2014-06-09 15:03 - 2014-06-09 15:04 - 02080768 _____ (Farbar) C:\Users\Sven\Downloads\FRST64.exe
2014-06-09 15:00 - 2014-06-09 15:01 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-09 04:51 - 2014-06-09 04:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_MijXfilt_01009.Wdf
2014-06-09 04:44 - 2014-06-09 04:44 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000883 _____ () C:\Users\Public\Desktop\DS3 Tool.lnk
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\Program Files\MotioninJoy
2014-06-09 04:43 - 2012-05-12 12:31 - 00121416 _____ (MotioninJoy) C:\Windows\system32\Drivers\MijXfilt.sys
2014-06-09 04:43 - 2011-12-07 19:42 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2014-06-09 04:43 - 2011-12-07 19:42 - 00328712 _____ (Logitech Inc.) C:\Windows\system32\MijFrc.dll
2014-06-09 04:43 - 2011-12-07 19:42 - 00074960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xusb21.sys
2014-06-09 04:39 - 2014-06-09 04:40 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed.zip
2014-06-09 04:39 - 2014-06-09 04:40 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed (1).zip
2014-06-07 05:44 - 2014-06-08 06:33 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Tropico 4
2014-06-07 05:42 - 2014-06-07 05:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tropico 4 Collectors Bundle
2014-06-07 05:38 - 2014-06-07 05:44 - 00000000 ____D () C:\Program Files (x86)\Tropico 4 Collectors Bundle
2014-06-06 01:14 - 2014-06-06 01:27 - 00000000 ____D () C:\Users\Sven\Downloads\Manuellsen-MB3 (Premium Edition)
2014-06-05 22:54 - 2014-06-10 12:03 - 00000000 ____D () C:\Users\Sven\Downloads\C&A Akup
2014-06-05 07:34 - 2014-06-05 07:34 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dvdcss
2014-06-05 06:51 - 2014-06-05 06:51 - 00000402 _____ () C:\Users\Sven\Downloads\CD-Laufwerk - Verknüpfung.lnk
2014-06-05 06:43 - 2014-06-05 06:43 - 00000000 ____D () C:\Program Files (x86)\G DATA Software
2014-06-05 06:20 - 2014-06-05 06:20 - 01180529 _____ () C:\Windows\unins000.exe
2014-06-05 06:20 - 2014-06-05 06:20 - 00001229 _____ () C:\Windows\unins000.dat
2014-06-05 06:17 - 2014-06-05 06:17 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\AVAST Software
2014-06-05 06:16 - 2014-06-10 11:51 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-05 06:16 - 2014-06-05 06:16 - 00001984 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00001924 _____ () C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-06-05 06:16 - 2014-06-05 06:14 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-06-05 06:16 - 2014-06-05 06:14 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-06-05 06:15 - 2014-06-05 06:14 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-06-05 06:15 - 2014-06-05 06:14 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-06-05 06:14 - 2014-06-05 06:14 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-05 06:13 - 2014-06-05 06:13 - 00000000 ____D () C:\Program Files\AVAST Software
2014-06-05 06:12 - 2014-06-05 06:12 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00003836 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401931354
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Local\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-05 03:13 - 2014-06-05 03:13 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-05 02:05 - 2014-06-10 11:49 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\KW
2014-06-05 01:52 - 2014-06-05 02:06 - 00000021 _____ () C:\AKTR.timestamp
2014-06-05 01:46 - 2014-06-05 04:55 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-04 15:13 - 2014-06-06 01:23 - 00000000 ____D () C:\Users\Sven\Downloads\_n`y1B_X$-
2014-06-04 11:49 - 2014-06-10 12:53 - 00045793 _____ () C:\Windows\setupact.log
2014-06-04 11:49 - 2014-06-04 11:49 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-04 11:48 - 2014-06-10 12:53 - 00019442 _____ () C:\Windows\PFRO.log
2014-06-04 11:22 - 2014-06-04 11:22 - 00001021 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-06-04 11:22 - 2014-06-04 11:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dlg
2014-06-04 11:21 - 2014-06-04 11:21 - 00123392 _____ () C:\Windows\system32\DlProtectSvc.exe
2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Security System 2
2014-06-03 10:13 - 2014-06-03 10:13 - 00003092 _____ () C:\Windows\System32\Tasks\{107A92FE-4711-4473-8E02-B7C9963E7371}
2014-05-30 20:17 - 2014-05-30 20:17 - 00003112 _____ () C:\Windows\System32\Tasks\{F83E546C-96CD-4EB6-8305-C82BC2EE455A}
2014-05-30 20:13 - 2014-05-30 20:13 - 00003112 _____ () C:\Windows\System32\Tasks\{11911F7C-AFE3-47ED-9FF5-A0B6F51AB520}
2014-05-29 20:03 - 2014-05-29 20:03 - 00000000 ____D () C:\ProgramData\Orbit
2014-05-29 19:43 - 2014-05-29 19:43 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (incl. 3 Bonustracks) (DE, 2014, VOiCE)
2014-05-29 19:24 - 2014-05-28 23:52 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (Premium Edition)
2014-05-29 19:13 - 2014-05-29 19:13 - 00000000 ____D () C:\Program Files\Ubisoft
2014-05-29 08:38 - 2014-05-29 19:51 - 00001205 _____ () C:\Users\Sven\Desktop\Uplay.lnk
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Local\Ubisoft Game Launcher
2014-05-29 01:48 - 2014-06-04 22:12 - 00000000 ____D () C:\Users\Sven\Downloads\GZ-LC EP3
2014-05-24 19:23 - 2014-06-09 15:37 - 00000000 ____D () C:\Users\Sven\Downloads\Al-Gear - Wieder Mal Angeklagt (Milfhunter Edition) (2014) 1
2014-05-22 07:09 - 2014-05-22 07:10 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00001044 _____ () C:\Users\Public\Desktop\MAGIX Video Pro X6.lnk
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\Documents\MAGIX_MusicEditor
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Xara
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Magix
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Public\Documents\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2014-05-22 07:08 - 2014-05-22 07:08 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Shared
2014-05-22 07:06 - 2014-05-22 07:10 - 00000000 ___RD () C:\Users\Sven\Documents\MAGIX
2014-05-22 07:06 - 2014-05-22 07:10 - 00000000 ____D () C:\ProgramData\MAGIX
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\MAGIX
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Services
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files (x86)\MAGIX
2014-05-22 03:19 - 2014-05-22 03:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2014-05-22 03:11 - 2014-05-22 03:12 - 00000000 ____D () C:\Users\Sven\Documents\My CamStudio Temp Files
2014-05-22 03:10 - 2014-05-22 03:13 - 00004535 _____ () C:\Users\Sven\AppData\Roaming\CamStudio.cfg
2014-05-22 03:10 - 2014-05-22 03:13 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamShapes.ini
2014-05-22 03:10 - 2014-05-22 03:13 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamLayout.ini
2014-05-22 03:10 - 2014-05-22 03:13 - 00000124 _____ () C:\Users\Sven\AppData\Roaming\Camdata.ini
2014-05-22 03:09 - 2014-05-22 03:10 - 00000096 _____ () C:\Users\Sven\AppData\Roaming\version2.xml
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\Program Files\CamStudio 2.7
2014-05-22 03:02 - 2014-05-22 03:21 - 00000738 _____ () C:\Users\Public\Desktop\Fraps.lnk
2014-05-20 02:04 - 2014-05-20 02:04 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-05-20 02:04 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-20 02:04 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-05-20 02:04 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-05-20 02:04 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-05-20 01:47 - 2014-05-20 01:47 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\InstallShield
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide IP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Program Files (x86)\FreeHideIP
2014-05-17 02:34 - 2014-06-09 15:41 - 00000000 ____D () C:\Users\Sven\Downloads\GalaxyLC
2014-05-16 18:58 - 2014-05-27 03:58 - 00000000 ____D () C:\Users\Sven\Downloads\Vorms EP3(projet)
2014-05-15 12:42 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 12:42 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 12:42 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-15 12:42 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-15 12:42 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 12:42 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-14 21:46 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 21:45 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-14 21:45 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-14 21:45 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-14 21:45 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-14 21:45 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-14 21:45 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-14 21:45 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-14 21:45 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-14 21:45 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-14 21:45 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-05-14 21:45 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-14 21:45 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-14 21:45 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-14 21:45 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-14 21:45 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-14 21:45 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-14 21:45 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 21:45 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-05-14 21:45 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-05-14 21:45 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll
2014-05-14 21:45 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-14 21:45 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-13 21:12 - 2014-05-13 21:12 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-05-13 16:44 - 2014-05-27 02:29 - 00000000 ____D () C:\Users\Sven\Downloads\Phoenix LC EP II
2014-05-12 11:48 - 2014-05-27 02:27 - 00000000 ____D () C:\Users\Sven\Downloads\Danaria Last Chaos

==================== One Month Modified Files and Folders =======

2014-06-10 12:58 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Sven\AppData\Local\Temp
2014-06-10 12:58 - 2010-05-02 11:53 - 00000000 ____D () C:\Users\Sven\AppData\Local\PMB Files
2014-06-10 12:57 - 2014-06-09 15:04 - 00020788 _____ () C:\Users\Sven\Downloads\FRST.txt
2014-06-10 12:57 - 2012-05-30 00:00 - 01050021 _____ () C:\Windows\WindowsUpdate.log
2014-06-10 12:56 - 2014-06-09 15:04 - 00000000 ____D () C:\FRST
2014-06-10 12:55 - 2014-06-10 12:55 - 00014016 _____ () C:\Users\Sven\Desktop\MBAM 2.txt
2014-06-10 12:54 - 2014-06-10 11:28 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-10 12:54 - 2014-05-07 00:52 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DropboxMaster
2014-06-10 12:54 - 2012-08-20 16:47 - 00000000 ___RD () C:\Users\Sven\Dropbox
2014-06-10 12:54 - 2012-02-27 23:38 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Dropbox
2014-06-10 12:53 - 2014-06-04 11:49 - 00045793 _____ () C:\Windows\setupact.log
2014-06-10 12:53 - 2014-06-04 11:48 - 00019442 _____ () C:\Windows\PFRO.log
2014-06-10 12:53 - 2013-04-03 00:13 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-10 12:53 - 2010-05-02 00:55 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-06-10 12:53 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-10 12:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Resources
2014-06-10 12:38 - 2009-07-14 06:45 - 00014608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-10 12:38 - 2009-07-14 06:45 - 00014608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-10 12:35 - 2010-08-25 16:11 - 08027136 ___SH () C:\Users\Sven\Desktop\Thumbs.db
2014-06-10 12:30 - 2014-06-10 12:04 - 00032826 _____ () C:\zoek-results.log
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Gast\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default\AppData\Local\Temp
2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default User\AppData\Local\Temp
2014-06-10 12:23 - 2014-06-10 12:23 - 00017954 _____ () C:\Users\Sven\Desktop\MMBAM TEXT.txt
2014-06-10 12:22 - 2014-06-10 12:00 - 00000000 ____D () C:\zoek_backup
2014-06-10 12:12 - 2012-07-12 11:08 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-10 12:04 - 2014-06-10 12:04 - 00003180 _____ () C:\Windows\System32\Tasks\{7D573011-FC61-42C2-A61F-1E0B7044A895}
2014-06-10 12:03 - 2014-06-05 22:54 - 00000000 ____D () C:\Users\Sven\Downloads\C&A Akup
2014-06-10 12:02 - 2014-06-10 12:02 - 04235784 _____ () C:\Users\Sven\Downloads\zoek.rar
2014-06-10 12:02 - 2013-04-03 00:13 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-10 12:00 - 2014-06-10 12:29 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-06-10 11:58 - 2014-06-10 11:58 - 00000886 _____ () C:\Users\Sven\Desktop\mbam.txt
2014-06-10 11:56 - 2014-06-10 11:56 - 00000652 _____ () C:\Users\Sven\Desktop\MAAABM.txt
2014-06-10 11:51 - 2014-06-05 06:16 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-10 11:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PLA
2014-06-10 11:49 - 2014-06-10 11:49 - 00016076 _____ () C:\Users\Sven\Desktop\teeext.txt
2014-06-10 11:49 - 2014-06-05 02:05 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\KW
2014-06-10 11:36 - 2014-06-10 11:35 - 04094386 _____ () C:\Users\Sven\Downloads\zoek.zip
2014-06-10 11:35 - 2014-06-10 11:35 - 01285120 _____ () C:\Users\Sven\Downloads\zoek.exe
2014-06-10 11:28 - 2014-06-10 11:28 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-10 11:28 - 2012-03-08 00:36 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Malwarebytes
2014-06-10 11:28 - 2012-03-08 00:36 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-10 11:27 - 2014-06-10 11:26 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (2).exe
2014-06-10 11:19 - 2014-06-10 11:18 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (1).exe
2014-06-10 11:12 - 2009-07-14 06:45 - 00554864 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-10 11:11 - 2014-06-10 11:02 - 00000000 ____D () C:\AdwCleaner
2014-06-10 11:01 - 2014-06-10 11:01 - 01333465 _____ () C:\Users\Sven\Downloads\adwcleaner_3.212.exe
2014-06-10 10:42 - 2011-12-22 15:59 - 00001134 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001UA.job
2014-06-10 03:38 - 2013-04-12 12:21 - 00000000 ____D () C:\Users\Sven\Downloads\01AlpaGun
2014-06-10 03:36 - 2010-05-02 01:31 - 00166832 _____ () C:\Users\Sven\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-10 03:33 - 2012-06-15 00:56 - 00211968 ___SH () C:\Users\Sven\Thumbs.db
2014-06-10 02:09 - 2014-06-10 01:11 - 00000000 ____D () C:\Users\Sven\Downloads\NextChaos
2014-06-10 01:42 - 2011-12-22 15:59 - 00001112 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001Core.job
2014-06-10 01:28 - 2014-06-10 01:28 - 00000042 _____ () C:\Users\Sven\Downloads\sl.dta
2014-06-10 01:10 - 2014-06-10 00:01 - 1956407488 _____ () C:\Users\Sven\Downloads\NextChaos.zip
2014-06-09 18:26 - 2013-04-30 15:36 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2
2014-06-09 18:22 - 2014-06-09 18:17 - 149696637 _____ () C:\Users\Sven\Downloads\uiii.rar
2014-06-09 15:56 - 2014-06-09 15:56 - 00090241 _____ () C:\Users\Sven\Downloads\Addition.txt
2014-06-09 15:54 - 2010-05-26 00:11 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-09 15:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-06-09 15:51 - 2009-07-14 20:18 - 00000000 ____D () C:\Windows\ShellNew
2014-06-09 15:51 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-06-09 15:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-06-09 15:49 - 2009-07-14 04:34 - 00000387 _____ () C:\Windows\win.ini
2014-06-09 15:41 - 2014-05-17 02:34 - 00000000 ____D () C:\Users\Sven\Downloads\GalaxyLC
2014-06-09 15:37 - 2014-05-24 19:23 - 00000000 ____D () C:\Users\Sven\Downloads\Al-Gear - Wieder Mal Angeklagt (Milfhunter Edition) (2014) 1
2014-06-09 15:04 - 2014-06-09 15:03 - 02080768 _____ (Farbar) C:\Users\Sven\Downloads\FRST64.exe
2014-06-09 15:01 - 2014-06-09 15:00 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-09 04:51 - 2014-06-09 04:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_MijXfilt_01009.Wdf
2014-06-09 04:44 - 2014-06-09 04:44 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000883 _____ () C:\Users\Public\Desktop\DS3 Tool.lnk
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy
2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\Program Files\MotioninJoy
2014-06-09 04:40 - 2014-06-09 04:39 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed.zip
2014-06-09 04:40 - 2014-06-09 04:39 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed (1).zip
2014-06-09 01:35 - 2010-06-20 16:07 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Skype
2014-06-08 06:33 - 2014-06-07 05:44 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Tropico 4
2014-06-07 22:56 - 2010-05-02 00:42 - 00000000 ___RD () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-06-07 21:03 - 2010-08-01 05:36 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\vlc
2014-06-07 20:12 - 2014-06-09 18:22 - 149696502 _____ () C:\Users\Sven\Downloads\Lucy-Cat - MAGICPOINT MIT ZUNGE - geht das überhaupt 05.06.14.flv
2014-06-07 05:44 - 2014-06-07 05:38 - 00000000 ____D () C:\Program Files (x86)\Tropico 4 Collectors Bundle
2014-06-07 05:42 - 2014-06-07 05:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tropico 4 Collectors Bundle
2014-06-07 05:38 - 2010-05-23 16:08 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DAEMON Tools Lite
2014-06-06 06:32 - 2009-07-14 19:58 - 00717506 _____ () C:\Windows\system32\perfh007.dat
2014-06-06 06:32 - 2009-07-14 19:58 - 00155122 _____ () C:\Windows\system32\perfc007.dat
2014-06-06 06:32 - 2009-07-14 07:13 - 01657416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-06 01:27 - 2014-06-06 01:14 - 00000000 ____D () C:\Users\Sven\Downloads\Manuellsen-MB3 (Premium Edition)
2014-06-06 01:23 - 2014-06-04 15:13 - 00000000 ____D () C:\Users\Sven\Downloads\_n`y1B_X$-
2014-06-05 23:01 - 2014-04-04 10:42 - 00000000 ____D () C:\Users\Sven\Downloads\Animus
2014-06-05 10:13 - 2012-03-07 22:30 - 00000000 ____D () C:\ProgramData\G DATA
2014-06-05 09:54 - 2012-08-20 23:32 - 00000000 ____D () C:\Users\Sven\Downloads\thc-ssl-dos
2014-06-05 07:34 - 2014-06-05 07:34 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dvdcss
2014-06-05 07:00 - 2012-10-31 02:28 - 00000000 ____D () C:\Users\Sven\Downloads\GTA 4
2014-06-05 06:56 - 2013-05-09 01:56 - 00000000 ____D () C:\Users\Sven\Downloads\DVD1
2014-06-05 06:54 - 2013-10-04 00:55 - 00000000 ____D () C:\Users\Sven\Downloads\Capo - Hallo Monaco (Fan Edition)
2014-06-05 06:53 - 2012-03-04 22:38 - 00000000 ____D () C:\Users\Sven\Downloads\Bigger.Stronger.Faster.2008.German.AC3.BRRip.Xvid-HOR
2014-06-05 06:52 - 2013-04-19 14:24 - 00000000 ____D () C:\Users\Sven\Downloads\5fu54ggrt
2014-06-05 06:51 - 2014-06-05 06:51 - 00000402 _____ () C:\Users\Sven\Downloads\CD-Laufwerk - Verknüpfung.lnk
2014-06-05 06:43 - 2014-06-05 06:43 - 00000000 ____D () C:\Program Files (x86)\G DATA Software
2014-06-05 06:43 - 2010-05-02 01:01 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-06-05 06:20 - 2014-06-05 06:20 - 01180529 _____ () C:\Windows\unins000.exe
2014-06-05 06:20 - 2014-06-05 06:20 - 00001229 _____ () C:\Windows\unins000.dat
2014-06-05 06:17 - 2014-06-05 06:17 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\AVAST Software
2014-06-05 06:16 - 2014-06-05 06:16 - 00001984 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00001924 _____ () C:\Users\Public\Desktop\avast! Pro Antivirus.lnk
2014-06-05 06:16 - 2014-06-05 06:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-06-05 06:14 - 2014-06-05 06:16 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-06-05 06:14 - 2014-06-05 06:16 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-06-05 06:14 - 2014-06-05 06:15 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-06-05 06:14 - 2014-06-05 06:15 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-06-05 06:14 - 2014-06-05 06:14 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-06-05 06:13 - 2014-06-05 06:13 - 00000000 ____D () C:\Program Files\AVAST Software
2014-06-05 06:12 - 2014-06-05 06:12 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-06-05 04:55 - 2014-06-05 01:46 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-06-05 03:22 - 2014-06-05 03:22 - 00003836 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401931354
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Local\Opera Software
2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-05 03:13 - 2014-06-05 03:13 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-05 03:13 - 2011-04-02 01:40 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-05 03:13 - 2010-05-02 01:17 - 00000000 ____D () C:\Users\Sven\AppData\Local\Mozilla
2014-06-05 03:13 - 2010-05-02 01:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-05 03:04 - 2013-04-03 00:14 - 00002251 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-05 02:06 - 2014-06-05 01:52 - 00000021 _____ () C:\AKTR.timestamp
2014-06-05 01:30 - 2014-03-09 11:59 - 00000000 ____D () C:\Users\Sven\AppData\Local\JDownloader 2.0
2014-06-05 00:36 - 2012-05-25 07:38 - 00000000 ____D () C:\Users\Sven\Downloads\Celo & Abdi - Hinterhofjargon
2014-06-04 22:12 - 2014-05-29 01:48 - 00000000 ____D () C:\Users\Sven\Downloads\GZ-LC EP3
2014-06-04 11:49 - 2014-06-04 11:49 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-04 11:24 - 2010-05-02 11:10 - 00000000 ____D () C:\Windows\pss
2014-06-04 11:22 - 2014-06-04 11:22 - 00001021 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-06-04 11:22 - 2014-06-04 11:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dlg
2014-06-04 11:22 - 2010-05-02 01:22 - 00000000 ____D () C:\Program Files (x86)\CCleaner
2014-06-04 11:21 - 2014-06-04 11:21 - 00123392 _____ () C:\Windows\system32\DlProtectSvc.exe
2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Security System 2
2014-06-03 10:13 - 2014-06-03 10:13 - 00003092 _____ () C:\Windows\System32\Tasks\{107A92FE-4711-4473-8E02-B7C9963E7371}
2014-05-31 18:15 - 2013-08-31 20:27 - 00000000 ____D () C:\Users\UpdatusUser.Sven-PC
2014-05-31 18:15 - 2013-01-23 23:29 - 00000000 ____D () C:\Users\Gast
2014-05-31 09:42 - 2014-06-09 18:09 - 97747333 _____ () C:\Users\Sven\Downloads\Lucy-Cat - 100-SEKUNDEN-ARSCHFICKWETTE! Wieviel Stöße schaffst du 31.05.14.flv
2014-05-30 20:17 - 2014-05-30 20:17 - 00003112 _____ () C:\Windows\System32\Tasks\{F83E546C-96CD-4EB6-8305-C82BC2EE455A}
2014-05-30 20:13 - 2014-05-30 20:13 - 00003112 _____ () C:\Windows\System32\Tasks\{11911F7C-AFE3-47ED-9FF5-A0B6F51AB520}
2014-05-30 20:02 - 2010-06-20 16:07 - 00000000 ____D () C:\ProgramData\Skype
2014-05-29 20:03 - 2014-05-29 20:03 - 00000000 ____D () C:\ProgramData\Orbit
2014-05-29 20:03 - 2010-07-18 18:57 - 00000000 ____D () C:\Users\Sven\Documents\My Games
2014-05-29 19:52 - 2010-05-02 14:47 - 00000000 ____D () C:\Program Files (x86)\Ubisoft
2014-05-29 19:51 - 2014-05-29 08:38 - 00001205 _____ () C:\Users\Sven\Desktop\Uplay.lnk
2014-05-29 19:51 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-05-29 19:43 - 2014-05-29 19:43 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (incl. 3 Bonustracks) (DE, 2014, VOiCE)
2014-05-29 19:13 - 2014-05-29 19:13 - 00000000 ____D () C:\Program Files\Ubisoft
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Local\Ubisoft Game Launcher
2014-05-29 03:49 - 2013-05-09 06:45 - 00000000 ____D () C:\Program Files (x86)\War Thunder
2014-05-28 23:52 - 2014-05-29 19:24 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (Premium Edition)
2014-05-28 15:51 - 2012-08-20 16:45 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-28 00:55 - 2014-05-07 14:55 - 00000000 ____D () C:\Program Files (x86)\LCGenericName02
2014-05-28 00:28 - 2013-10-01 14:36 - 00000000 ____D () C:\Users\Sven\AppData\Local\ArmA 2 OA
2014-05-27 05:00 - 2012-08-21 07:08 - 00000000 ____D () C:\Users\Sven\AppData\Local\Trainer
2014-05-27 03:58 - 2014-05-16 18:58 - 00000000 ____D () C:\Users\Sven\Downloads\Vorms EP3(projet)
2014-05-27 02:29 - 2014-05-13 16:44 - 00000000 ____D () C:\Users\Sven\Downloads\Phoenix LC EP II
2014-05-27 02:27 - 2014-05-12 11:48 - 00000000 ____D () C:\Users\Sven\Downloads\Danaria Last Chaos
2014-05-22 18:43 - 2011-09-22 15:23 - 00000000 ____D () C:\Fraps
2014-05-22 07:10 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MAGIX
2014-05-22 07:10 - 2014-05-22 07:06 - 00000000 ___RD () C:\Users\Sven\Documents\MAGIX
2014-05-22 07:10 - 2014-05-22 07:06 - 00000000 ____D () C:\ProgramData\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00001044 _____ () C:\Users\Public\Desktop\MAGIX Video Pro X6.lnk
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\Documents\MAGIX_MusicEditor
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Xara
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Magix
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Public\Documents\MAGIX
2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2014-05-22 07:08 - 2014-05-22 07:08 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Shared
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\MAGIX
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Services
2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files (x86)\MAGIX
2014-05-22 07:05 - 2011-12-29 22:25 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-05-22 05:55 - 2013-09-05 05:41 - 00000000 ____D () C:\Users\Sven\Downloads\4ZuDer9
2014-05-22 03:21 - 2014-05-22 03:02 - 00000738 _____ () C:\Users\Public\Desktop\Fraps.lnk
2014-05-22 03:21 - 2012-05-07 06:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastChaosGER
2014-05-22 03:19 - 2014-05-22 03:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2014-05-22 03:13 - 2014-05-22 03:10 - 00004535 _____ () C:\Users\Sven\AppData\Roaming\CamStudio.cfg
2014-05-22 03:13 - 2014-05-22 03:10 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamShapes.ini
2014-05-22 03:13 - 2014-05-22 03:10 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamLayout.ini
2014-05-22 03:13 - 2014-05-22 03:10 - 00000124 _____ () C:\Users\Sven\AppData\Roaming\Camdata.ini
2014-05-22 03:12 - 2014-05-22 03:11 - 00000000 ____D () C:\Users\Sven\Documents\My CamStudio Temp Files
2014-05-22 03:10 - 2014-05-22 03:09 - 00000096 _____ () C:\Users\Sven\AppData\Roaming\version2.xml
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7
2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\Program Files\CamStudio 2.7
2014-05-21 08:31 - 2014-06-10 12:03 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.scr
2014-05-21 08:31 - 2014-06-10 12:03 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.com
2014-05-20 02:05 - 2014-03-09 11:51 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-20 02:04 - 2014-05-20 02:04 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-05-20 02:04 - 2010-05-02 14:59 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-20 01:49 - 2012-08-19 02:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2014-05-20 01:49 - 2012-08-19 02:55 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-05-20 01:47 - 2014-05-20 01:47 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\InstallShield
2014-05-20 01:47 - 2012-08-21 02:26 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Wippien
2014-05-20 01:47 - 2012-08-21 02:26 - 00000000 ____D () C:\Program Files\Wippien
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide IP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\FreeHideIP
2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Program Files (x86)\FreeHideIP
2014-05-18 11:29 - 2013-06-07 06:32 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-05-18 11:29 - 2011-07-16 21:42 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DVDVideoSoft
2014-05-18 11:29 - 2010-05-02 01:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-05-17 03:21 - 2012-07-12 11:08 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-17 03:21 - 2012-07-12 11:08 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-17 03:21 - 2011-10-10 11:10 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-17 03:20 - 2010-05-02 01:24 - 00000000 ____D () C:\Users\Sven\AppData\Local\Adobe
2014-05-15 14:14 - 2010-05-02 00:42 - 00000000 ___RD () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 14:10 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-05-15 13:31 - 2014-05-07 03:01 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-15 12:48 - 2013-08-14 04:10 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-15 12:37 - 2010-05-02 11:19 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-13 21:12 - 2014-05-13 21:12 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-05-13 20:30 - 2014-05-08 18:29 - 00000000 ____D () C:\Users\Sven\Downloads\RapidLC
2014-05-12 20:46 - 2010-11-07 21:40 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-05-12 10:29 - 2013-09-30 15:57 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-05-12 10:29 - 2010-10-03 14:41 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\TS3Client
2014-05-12 10:29 - 2010-05-02 01:37 - 00000000 ____D () C:\Users\Sven\Tracing
2014-05-12 10:29 - 2010-05-02 01:34 - 00000000 ____D () C:\Windows\Panther
2014-05-12 07:26 - 2014-06-10 11:28 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-06-10 11:28 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2012-03-08 00:36 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys

Files to move or delete:
====================
C:\Users\Sven\AppData\Roaming\CamLayout.ini
C:\Users\Sven\AppData\Roaming\CamShapes.ini


Some content of TEMP:
====================
C:\Users\Sven\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp4f7lre.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-08 00:01

==================== End Of Log ============================
         
--- --- ---

--- --- ---


Alt 10.06.2014, 12:01   #21
M-K-D-B
/// TB-Ausbilder
 
Sicheres Löschen von "PSHD-9.9" - Standard

Sicheres Löschen von "PSHD-9.9"



Vergiss meinen letzten Beitrag....

Alt 10.06.2014, 12:02   #22
Goodfell
 
Sicheres Löschen von "PSHD-9.9" - Standard

Sicheres Löschen von "PSHD-9.9"



Code:
ATTFilter

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-06-2014 01
Ran by Sven at 2014-06-10 12:58:38
Running from C:\Users\Sven\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

7-Zip 4.65 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0465-000001000000}) (Version: 4.65.00.0 - Igor Pavlov)
Adobe Acrobat 4.0 (HKLM-x32\...\Adobe Acrobat 4.0) (Version:  - )
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.7.0.19530 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 2.7.0.19530 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader 9.4.1 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.0.112 - Adobe Systems, Inc.)
Alarm für Cobra 11 - Das Syndikat - DEMO (HKLM-x32\...\Alarm für Cobra 11 - Das Syndikat - DEMO_is1) (Version:  - dtp)
Angry Birds (HKLM-x32\...\{61637194-D4E8-45CB-8619-23CE7B637FCF}) (Version: 2.0.2 - Rovio)
Angry Birds Space (HKLM-x32\...\{40044440-4ED4-4792-8417-5EE6374F001C}) (Version: 1.1.0 - Rovio)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArmA 2 Free Uninstall (HKLM-x32\...\ArmA 2) (Version:  - )
ARMA 2 Operation Arrowhead Uninstall (HKLM-x32\...\ARMA 2 Operation Arrowhead) (Version:  - )
ARMA 3 (HKLM-x32\...\QVJNQTM=_is1) (Version: 1 - )
Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.01 - Ubisoft)
Audacity 2.0.3 (HKLM-x32\...\Audacity_is1) (Version: 2.0.3 - Audacity Team)
AutoHotkey 1.0.48.05 (HKLM-x32\...\AutoHotkey) (Version: 1.0.48.05 - Chris Mallett)
AutoIt v3.3.8.0 (HKLM-x32\...\AutoItv3) (Version:  - AutoIt Team)
Avast License by ZeNiX [2014-03-14] (HKLM-x32\...\Avast_2050_ZeNiX [2014-03-14]_is1) (Version:  - )
avast! Pro Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2017 - Avast Software)
Avidemux 2.5 (32-bit) (HKLM-x32\...\Avidemux 2.5) (Version: 2.5.4.7200 - )
AwesomiumSetup (HKLM-x32\...\{19EF99D1-7EE6-4B5E-ABEE-0B3825F703B0}) (Version: 1.00.0000 - SIX Networks GmbH)
Axife Mouse Recorder DEMO 5.01 (HKLM-x32\...\Axife Mouse Recorder DEMO_is1) (Version:  - Axife Software)
Batman Arkham City version 1.0 (HKLM-x32\...\{B531E735-8ED5-4270-ACCE-3809086FBD02}_is1) (Version: 1.0 - WB Games)
Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.0.0.0 - Electronic Arts)
Battlefield 4™ Beta (HKLM-x32\...\{CFAB3721-549D-4827-A4E8-7F90192114AB}) (Version: 1.0.0.0 - Electronic Arts)
Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB)
BattlEye (A2Free) Uninstall (HKLM-x32\...\BattlEye A2 Free) (Version:  - )
BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version:  - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CamStudio 2.7.2 (HKLM\...\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7.2 - CamStudio Open Source)
CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform)
CPUID HWMonitor 1.21 (HKLM\...\CPUID HWMonitor_is1) (Version:  - )
Crysis® 2 (HKLM-x32\...\{6033673D-2530-4587-8AD0-EB059FC263F9}) (Version: 1.0.0.0 - Electronic Arts)
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.1.0.0 - Electronic Arts)
Cuttermaran 1.70 (HKLM-x32\...\{5F499D33-546A-442B-B0F9-4C58F3B5B6E3}) (Version: 1.7.0 - toarnold)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.47.1.0337 - Disc Soft Ltd)
Dark Souls Prepare to Die Edition (HKLM-x32\...\GFWL_{4E4D0FA1-F880-4CCB-999A-501000008200}) (Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.)
Dark Souls Prepare to Die Edition (x32 Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.) Hidden
DayZ Commander (HKLM-x32\...\{99C28455-E285-4639-B4C6-9F747C0C3D4C}) (Version: 0.92.90 - Dotjosh Studios)
DayZero Launcher (HKLM-x32\...\{121CAAD8-0CD7-48CC-A3E1-A1AB8C0B1086}) (Version: 01.00.004 - ZOMBIES.NU)
Der Herr der Ringe Der Krieg im Norden Version v1.0 (HKLM-x32\...\{4F7F52F2-DFD5-4FE3-8D24-2B7CEB9980C8}_is1) (Version: v1.0 - )
DiRT 3 (HKLM-x32\...\GFWL_{434D0FA0-1558-4D8E-AC3D-BD1000008200}) (Version: 1.0.0000.130 - Codemasters)
DiRT 3 (x32 Version: 1.0.0000.130 - Codemasters) Hidden
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.100 - DivX, LLC)
Download Protect (HKCU\...\{132401a7-2006-4342-b43c-ccf5f02c2b01}) (Version:  - Download Protect)
Dr. Hardware 2013 13.0d (HKLM-x32\...\Dr. Hardware 2013_is1) (Version:  - Peter A. Gebhard)
Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.)
DVD Architect Studio 5.0 (HKLM-x32\...\{04DF4A51-DE2A-11E0-9AB5-F04DA23A5C58}) (Version: 5.0.156 - Sony)
ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc)
F1 2010 (x32 Version: 1.0.0001.132 - Codemasters) Hidden
F1 2010 AI Settings (HKLM-x32\...\{C0EBA426-3C37-4DFC-B96C-1AE9263E720D}_is1) (Version: 1.0 - )
F1 2011 (HKLM-x32\...\GFWL_{434D0FA1-3E0C-4D03-A5D4-5E1000008100}) (Version: 1.0.0000.129 - Codemasters)
F1 2011 (x32 Version: 1.0.0000.129 - Codemasters) Hidden
F1 2013 German (HKLM-x32\...\RjEyMDEz_is1) (Version: 1 - )
Facebook Messenger 2.1.4814.0 (HKLM-x32\...\{7204BDEE-1A48-4D95-A964-44A9250B439E}) (Version: 2.1.4814.0 - Facebook)
Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited)
FIFA 13 (HKLM-x32\...\{A29E18C2-7AB1-4b6b-848C-5D5E2C85F0C0}) (Version: 1.5.0.0 - Electronic Arts)
Fraps (remove only) (HKLM-x32\...\Fraps) (Version:  - )
Free Hide IP (HKLM-x32\...\FreeHideIP) (Version: 3.9.6.6 - )
Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com)
Free YouTube Download version 3.2.2.430 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.2.430 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.12.35.514 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.35.514 - DVDVideoSoft Ltd.)
Freemake Audio Converter Version 1.1.0 (HKLM-x32\...\Freemake Audio Converter_is1) (Version: 1.1.0 - Ellora Assets Corporation)
Freemake Video Converter Version 3.0.1 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 3.0.1 - Ellora Assets Corporation)
German Truck Simulator 1.00 (HKLM-x32\...\German Truck Simulator) (Version: 1.00 - )
GhostMouse (HKLM-x32\...\GhostMouse_is1) (Version: Free V3.2 - ghost-mouse.com)
GIMP 2.6.8 (HKLM\...\WinGimp-2.0_is1) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.0 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
Google+ RegHelper (HKLM-x32\...\de.txptr.googleplus) (Version: 1.4.0 - UNKNOWN)
Google+ RegHelper (x32 Version: 1.4.0 - UNKNOWN) Hidden
Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
Grand Theft Auto IV (x32 Version: 1.0.0011.131 - Rockstar Games Inc.) Hidden
Grand Theft Auto IV (x32 Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden
Grand Theft Auto IV v1.0 Eng (HKLM-x32\...\Grand Theft Auto IV_is1) (Version:  - )
GSview 4.9 (HKLM-x32\...\GSview 4.9) (Version:  - )
Gunblade Saga (HKLM-x32\...\{0AC07A77-0511-4904-9FA1-616DC9BEF50D}) (Version: 11.09.30 - Mail.Ru Games GmbH)
HyperCam 3 (HKLM-x32\...\HyperCam 3) (Version: 3.4.1205.14 - Solveig Multimedia)
IL-2 Sturmovik 1946 (HKLM-x32\...\InstallShield_{79438F1E-DEC3-443D-9DCD-FECE2D68C605}) (Version: 1.00.0000 - Ihr Firmenname)
IL-2 Sturmovik 1946 (x32 Version: 1.00.0000 - Ihr Firmenname) Hidden
IL-2 Sturmovik Cliffs of Dover (HKLM-x32\...\IL-2 Sturmovik Cliffs of Dover_is1) (Version:  - )
Java 7 Update 21 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417021FF}) (Version: 7.0.210 - Oracle)
Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.550 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 27 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216020FF}) (Version: 6.0.270 - Sun Microsystems, Inc.)
JDownloader (HKLM-x32\...\JDownloader) (Version: 0.89 - AppWork UG (haftungsbeschränkt))
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
JDownloader 2 (HKLM-x32\...\0630-0716-3135-7887) (Version: 2 - AppWork GmbH)
KaloMa 4.76 (HKLM-x32\...\KaloMa_is1) (Version:  - Frank Böpple)
LastChaosGER (HKLM-x32\...\{A86A50FC-7C22-478B-BAEF-82393328825F}) (Version: 1.00.000 - Barunsongames CO., LTD.)
LCGenericName02 Version 1 (HKLM-x32\...\{4AA19E32-8010-477A-8FC3-B6C1691174AD}_is1) (Version: 1 - LCGenericName02)
Macro Recorder (HKCU\...\2a7a433177cfa3a6) (Version: 5.0.0.156 - Jitbit Macro Recorder)
MAGIX Speed burnR (MSI) (HKLM-x32\...\MX.{368FDD4C-1D79-44B6-9E86-6A1FF6D1496E}) (Version: 7.0.2.6 - MAGIX AG)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden
MAGIX Video Pro X6 (HKLM\...\MX.{CBC84EDA-E830-4240-9392-325C3E6D5DCA}) (Version: 13.0.3.24 - MAGIX AG)
MAGIX Video Pro X6 (Version: 13.0.3.24 - MAGIX AG) Hidden
MAGIX Video Pro X6 64 bit Update (Version: 13.0.4.2 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Hidden
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{F2508213-9989-4E85-A078-72BE483917EF}) (Version: 3.5.88.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Train Simulator (HKLM-x32\...\Train Simulator 1.0) (Version:  - )
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{09298F26-A95C-31E2-9D95-2C60F586F075}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
Minecraft Beta 1.8.1 Version v1.0 (HKLM-x32\...\{1753427B-E948-4E5B-B4A1-1E7959AD9BDA}_is1) (Version: v1.0 - Godslayers)
Minecraft Cracked (HKLM-x32\...\Minecraft Cracked) (Version:  - )
MotioninJoy Gamepad tool 0.7.1001 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.7.1001 - www.motioninjoy.com)
Mount&Blade With Fire and Sword (HKLM-x32\...\Mount&Blade With Fire and Sword) (Version:  - )
Mouse Recorder Pro 2.0.7.4 (HKLM-x32\...\{889E44CE-435C-4D37-B302-A7E43339E5FA}_is1) (Version:  - Nemex Studios)
Move Media Player (HKCU\...\Move Media Player) (Version:  - Move Networks)
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 13.0.1 - Mozilla)
MSI Afterburner 2.3.1 (HKLM-x32\...\Afterburner) (Version: 2.3.1 - MSI Co., LTD)
MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden
MSVCRT Redists (x32 Version: 1.0 - Sony Creative Software Inc.) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Need for Speed(TM) Hot Pursuit (HKLM-x32\...\{83A606F5-BF6F-42ED-9F33-B9F74297CDED}) (Version: 1.0.0.0 - Electronic Arts)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.43.2 - Black Tree Gaming)
NVIDIA 3D Vision Controller Driver (x32 Version: 275.33 - NVIDIA Corporation) Hidden
NVIDIA 3D Vision Controller-Treiber 326.80 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 326.80 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 326.80 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 326.80 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
NVIDIA Grafiktreiber 326.80 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 326.80 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden
NVIDIA nTune (HKLM-x32\...\InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}) (Version: 1.00.0000 - NVIDIA Corporation)
NVIDIA nTune (x32 Version: 1.00.0000 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2680 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 326.80 (Version: 326.80 - NVIDIA Corporation) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Opera Next 12.01 internal build 1491 (HKLM\...\Opera 12.01.1491) (Version: 12.01.1491 - Opera Software ASA)
Opera Stable 22.0.1471.50 (HKLM-x32\...\Opera 22.0.1471.50) (Version: 22.0.1471.50 - Opera Software ASA)
Origin (HKLM-x32\...\Origin) (Version: 9.3.7.2735 - Electronic Arts, Inc.)
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.3.3.6 - Pando Networks Inc.)
PC Connectivity Solution (HKLM-x32\...\{AC599724-5755-48C1-ABE7-ABB857652930}) (Version: 8.15.0.0 - Nokia)
PC Inspector File Recovery (HKLM-x32\...\{0DD140D3-9563-481E-AA75-BA457CBDAEF2}) (Version: 4.0 - )
Perfect Effects 3 Free (HKLM-x32\...\{B8D92680-34AC-4B76-8D95-7E95B11B5121}) (Version: 3.0.2 - onOne Software)
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Pinnacle VideoSpin (HKLM-x32\...\{FEB15887-0932-4D2D-BB85-6AC03FBF1AA8}) (Version: 2.0.0.669 - Pinnacle Systems)
Platform (x32 Version: 1.34 - VIA Technologies, Inc.) Hidden
Pro Evolution Soccer 2010 (HKLM-x32\...\{283FFB23-8751-4B08-ACB8-5E0F8BCF7727}) (Version: 1.03.0000 - KONAMI)
Pro Evolution Soccer 2011 (HKLM-x32\...\{1148E85C-E1AF-48E0-A29C-68DACE07E054}) (Version: 1.00.0000 - KONAMI)
Pro Evolution Soccer 2014 (HKLM-x32\...\{5EFD3544-2371-4900-8ACA-F157BA80FB0C}) (Version: 1.01.0000 - KONAMI)
Process Hacker 2.30 (r5267) (HKLM\...\Process_Hacker2_is1) (Version: 2.30.0.5267 - wj32)
Project64 1.6 (HKLM-x32\...\{9559F7CA-5E34-4237-A2D9-D856464AD727}) (Version: 1.6 - Project64)
Protegere (HKLM-x32\...\Protegere) (Version:  - )
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
PVSonyDll (Version: 1.00.0001 - NVIDIA Corporation) Hidden
QuickTime (HKLM-x32\...\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.)
Rainmeter (HKLM-x32\...\Rainmeter) (Version:  - )
Rapture3D 2.4.9 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version:  - Blue Ripple Sound)
raving reyven (HKLM\...\raving reyven) (Version: 2014.03.27.174842 - raving reyven)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6029 - Realtek Semiconductor Corp.)
Samsung Mobile phone USB driver Drive Software (HKLM\...\Samsung Mobile phone USB driver Drive) (Version:  - )
Samsung New PC Studio (HKLM-x32\...\InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.)
Samsung New PC Studio (x32 Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.650.0 - SAMSUNG Electronics Co., Ltd.)
SamsungConnectivityCableDriver (HKLM-x32\...\{7E84FAC8-C518-40F9-9807-7455301D6D25}) (Version: 6.83.6.2.1 - Samsung)
Sandboxie 3.66 (64-bit) (HKLM\...\Sandboxie) (Version: 3.66 - SANDBOXIE L.T.D)
Ship Simulator Extremes (HKLM-x32\...\Ship Simulator Extremes_is1) (Version:  - )
shopping-preise.de - AddOn für Firefox (HKLM-x32\...\{2B11BA9C-7F97-4C16-970F-1491FD77969B}_is1) (Version: 2.81 - shopping-preise.de)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Sound Forge Audio Studio 10.0 (HKLM-x32\...\{0AA0DA00-A1D3-11E0-B9A9-005056C00008}) (Version: 10.0.176 - Sony)
StarCraft II (HKLM-x32\...\StarCraft II) (Version: 1.0.0.16117 - Blizzard Entertainment)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Strike Suit Zero (HKLM-x32\...\Strike Suit Zero) (Version:  - )
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
System Explorer 3.9.8 (HKLM-x32\...\{40F485F7-6478-4896-B0D5-F94BE677EB78}_is1) (Version:  - Mister Group)
System Requirements Lab (HKLM-x32\...\{9E1BAB75-EB78-440D-94C0-A3857BE2E733}) (Version: 4.1.71.0 - Husdawg, LLC)
System Requirements Lab (HKLM-x32\...\SystemRequirementsLab) (Version:  - )
System Requirements Lab CYRI (HKLM-x32\...\{E362724E-9320-4946-AF34-874E7B6B2927}) (Version: 6.0.7.0 - Husdawg, LLC)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.13 - TeamSpeak Systems GmbH)
The Elder Scrolls V Skyrim Update 11 (1.8.151.0.7) Deutsche Version 1.00 (HKLM-x32\...\The Elder Scrolls V Skyrim Update 11 (1.8.151.0.7) Deutsche Version 1.00) (Version:  - )
The Elder Scrolls V: Skyrim (HKLM-x32\...\{3844035A-9429-4E54-86B0-6EE3778BA3FB}_is1) (Version: 1.1.21.0 - RAF)
The Last Remnant (HKLM-x32\...\The Last Remnant_is1) (Version:  - )
The Walking Dead: Episode 1 and 2 (HKLM-x32\...\{26B906EC-2979-4936-AED1-30CB96927F64}_is1) (Version: 1.0 - RAF)
TopSecret Biometrics Components (HKLM-x32\...\{C8BCC14C-2807-4C2D-A659-843427BF82E2}) (Version: 1.00.0000 - G DATA Software)
Tropico 4 Collectors Bundle (HKLM-x32\...\Tropico 4 Collectors Bundle_is1) (Version: 1.0 - ADDONiA)
Tunngle beta (HKLM-x32\...\Tunngle beta_is1) (Version:  - Tunngle.net GmbH)
Uninstall 1.0.0.1 (HKLM-x32\...\Uninstall_is1) (Version:  - )
Uplay (HKLM-x32\...\Uplay) (Version: 4.3 - Ubisoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.)
War Thunder Launcher 1.0.1.199 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version:  - 2012 Gaijin Entertainment Corporation)
WATCH_DOGS (HKLM-x32\...\Uplay Install 274) (Version:  - Ubisoft)
Watson (HKLM-x32\...\{9B88DD94-1AAE-41C4-BD95-2D8737D5E9E2}) (Version: 1.0.0 - Windows Live Safety Center)
Windows Live Call (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live Communications Platform (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden
Windows Live OneCare safety scanner (HKLM-x32\...\Windows Live OneCare safety scanner) (Version:  - Microsoft Corporation)
Windows Live OneCare safety scanner (x32 Version: 1.0.0.0 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM-x32\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation)
Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
Windows-Treiberpaket - Nokia pccsmcfd  (10/12/2007 6.85.4.0) (HKLM\...\BC15EA930074932BB2C4B4493C9FD4EA95087D1A) (Version: 10/12/2007 6.85.4.0 - Nokia)
WinRAR (HKLM\...\WinRAR archiver) (Version:  - )

==================== Restore Points  =========================

09-06-2014 13:45:59 Removed Microsoft Office Professional Plus 2010
10-06-2014 10:04:54 zoek.exe restore point

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {00206791-3604-49AF-A7B6-6F9F96435F75} - System32\Tasks\{48D33453-E9D9-469F-849D-160A78897C05} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0060DF2D-C334-4E56-AC85-3BA0B4BB8C19} - System32\Tasks\{0482E8F0-DC94-4116-82C3-A524AA6EDD56} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {00DE4891-4768-4781-B8F9-D3BACDC71C60} - System32\Tasks\{5FC532AA-6E13-40F5-B394-1335CB2802E7} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {01543BE2-B3C2-432D-8625-B3E687D20ECC} - System32\Tasks\{6EA1C590-18CC-4242-A3EE-D4D863F62C44} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {028BF155-0170-4774-A4CC-20D842C89A45} - System32\Tasks\{42382861-E829-44D8-82CA-CAEE691391DD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {047FB690-D3B8-4407-BC58-CF1BEAAA9109} - System32\Tasks\{5DB0F65E-BA72-42BD-9F77-902282F494D5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {04CDF2BE-9C9E-496F-B957-1C56120C5971} - System32\Tasks\{FB0C5B4B-828E-4A3A-8E3E-5CF0415AC411} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {05290312-83EB-408E-B517-6FACAF272D54} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001UA => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.)
Task: {05768801-9C10-4797-BA90-B0C2AFE28B74} - System32\Tasks\{3B811B6B-73E2-4C71-900E-DDFD4DF79ACD} => E:\AutoRun.exe
Task: {059CDD4F-B16C-43B6-B938-D9B530A62A51} - System32\Tasks\{9AC660E1-E379-48DA-A67E-E8AAD6BFC56E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {07DCA1A2-0AD2-4B86-B2FD-715C05CCA7AB} - System32\Tasks\{0BDE8801-35E5-4CD1-B357-8B6E6DF01DCC} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {09240454-01FE-4102-9921-BBDA41827BDE} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001Core => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.)
Task: {0A4CE36B-9B12-4B1E-B540-CA6072A90AEE} - System32\Tasks\{46F5B8DA-D479-487D-A2CB-ED1923FB1373} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0A6C2D4D-1161-4D27-B474-59BAAE8F27FB} - System32\Tasks\{531E50E7-B9D2-4660-95F5-9641C3586AAC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0A6C8C93-F7AB-43F6-A0CC-281D24D3CF72} - System32\Tasks\{E47A74B7-37CB-40DE-8AF4-D63E9E1F8C1A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0BD63AAF-49E0-4A9A-BDEF-BD66D87211E1} - System32\Tasks\{EBFB120D-5756-4184-8E28-539FF3975ED0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0C06DDDD-3F65-4B71-B0F6-EAB79FA8F6E0} - System32\Tasks\{16D23950-57D0-4260-A83C-7A9EF3BA8B10} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0D011E81-3D76-44F3-8626-D2750C23ED12} - System32\Tasks\{56327058-6A18-428D-8411-A8D80E3FD0DC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0DADA3D1-96FD-46DA-A2EE-5F7F740710A8} - System32\Tasks\{C10B0F16-9D9E-44BE-B53F-2A79DD22417C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0DC20443-9129-4C90-9D0B-469A0FE8065F} - System32\Tasks\{1AD275C9-3DEC-44AE-9C34-FF6453D7FDCB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0EC1E659-64D9-4CC9-813C-2B19E5FECBF7} - System32\Tasks\{1808866F-9A73-4701-B5B8-92DDDCA1A936} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0EF04926-207E-445D-96F6-71F7BFB973C7} - System32\Tasks\{9FFEA193-9C5E-42FB-A13A-3C45B191659E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {0F8CC94F-048A-4366-8240-9F01292E5C25} - System32\Tasks\{BC26F19E-C830-4EA2-85AE-3D5AA929C880} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {108C58DC-9854-44E7-A15A-E8D4A2CC38BD} - System32\Tasks\{716EAD2A-A1E3-4E82-9C02-36776753AE4D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1313A74E-8497-4CCC-B653-3430D26F947D} - System32\Tasks\{6136571D-6365-4A71-800A-9C16B89DC946} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {14CCF703-5440-4955-AE87-C0BEC0BCDF82} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-06-05] (AVAST Software)
Task: {151F64D7-9CE9-4B1E-B0B6-12A82939FAF7} - System32\Tasks\{8ECB201E-0FC2-497B-8C23-F10C1A93DA27} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {15666D0F-7586-4000-9932-149CDA127E6F} - System32\Tasks\{C43090F5-62C8-42D4-BADF-150BBF0A3F2B} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.114/de/go/help.faq.installer?LastError=1603
Task: {1591003B-2F48-465D-981B-7B8A41007100} - System32\Tasks\{3113EAE0-844D-46F8-A4E2-97BCA735D923} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {15CC64F6-C57C-4E1B-B266-D0FAEB366850} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {1646E41A-0620-458D-9842-6A07C0AA33EE} - System32\Tasks\{F92CFB9A-E557-47B1-A8A8-D48BF88C12E5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1670DFB5-521E-472F-84EF-3AE74946A37A} - System32\Tasks\{CE9CC2D0-7509-4B2D-A43D-5BB9A1710D03} => C:\Program Files (x86)\Team17\Worms Reloaded\WormsReloaded.exe
Task: {17BB7FAD-D2FC-49F3-AE14-A4225B06B8E3} - System32\Tasks\{28AB3BCF-EE50-484F-BE21-F66EF3461957} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {18A75256-BA65-4CDA-AB02-9A1FBCA6AC0E} - System32\Tasks\{FE6DADBB-DE8F-4BDC-87FD-D36DB2CEEAA9} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {18FD2294-3EDF-4904-AA67-94057FBF0BA2} - System32\Tasks\{A7523CFB-164F-4EAB-B8CC-4CADB4D534DC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1B2FEB5E-2676-43C1-908A-4B640D75A679} - System32\Tasks\{86A0D00A-38FF-4988-B2A3-31B1F266576E} => C:\Program Files (x86)\Railworks 2010\RailWorks.exe
Task: {1D1F8052-52AC-44ED-B134-C4C689E7AB48} - System32\Tasks\{81E83BD6-E3AC-4909-9EAF-74158FB16614} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1D782067-0E4C-41F2-91EC-51C1CBA0F339} - System32\Tasks\{9F2389C9-E0A7-477B-9909-F031582AD6F5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1DD72608-CFA6-4AD2-B913-E3B6831F2464} - System32\Tasks\{72826905-205B-4821-8621-1D8C8E08F2BC} => C:\Users\Sven\Downloads\PortableZombie Driver1.0.4\Zombie Driver.exe
Task: {1DF7B898-5E91-4ED8-90F1-B725BE742DCA} - System32\Tasks\{6F286A32-34B2-4E27-AF82-2D838BCB3012} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {1E503B2C-0E1A-4C72-965A-09996706192C} - System32\Tasks\{4DBAEF55-EF8E-4852-B9F5-AFB4ED2630A1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2199FF4C-C031-4D14-BF52-F596A11DCA8B} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe
Task: {23941C5E-F5AF-4F47-ADF6-E326297ADA8A} - System32\Tasks\{F3092C73-8B09-4013-ADED-52F3D3F4B852} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {248467D6-6AE9-474E-B9D8-C2B325203880} - System32\Tasks\{C5CC5AE2-842A-40F2-BED4-FDD2C8FBED5A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {258C4939-0DEC-4711-8B26-F2DAFEE63003} - System32\Tasks\{3DFE2278-9A94-4095-A89F-8E4DB9B77C0C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {25FCB770-2B27-43F5-82C6-9A99F7CF951C} - System32\Tasks\{33702D64-5E9F-4E66-B15D-57A6C7753CF1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {264FE3BF-A728-4ED0-8784-485E95EB9332} - System32\Tasks\{4DF0AC0C-7E9F-476A-812D-66F469EB75C5} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {26AFDCE2-62B0-4A72-9BF5-46014D9C84FE} - System32\Tasks\{C14816C9-AC1D-44B3-A1B4-2D930E834141} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {26F96DDC-18B4-4D1E-AD74-F4D4F74ABE9F} - System32\Tasks\{10C1E1CD-1BAF-4D59-A603-08BFCA24646D} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {2A71016B-03C8-4233-B859-2F22E75C79F5} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1098949856-1301053314-1890294551-1001
Task: {2C83876C-E904-40A0-BC07-504872AE2B1D} - System32\Tasks\{61B863D1-021C-4E73-897A-46FF41577FBD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2CA817F9-FBB1-494E-B5BA-1A78D6C7033D} - System32\Tasks\{EF0E0319-3DD7-45C8-86EB-15DFE8C8BCDC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2D6CAF9A-1CD9-4364-988E-B477F7EF5522} - System32\Tasks\{734FA937-B120-4B5C-A837-2088381DA3D1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2D991809-8C7D-40DD-BDC7-D5C5636BB74C} - System32\Tasks\{48E2514F-1BB2-4C45-A316-4FBC8FD30901} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2EEFA68F-9662-4975-B6F9-786821AA4B7D} - System32\Tasks\{CBA16325-3343-4E45-8DB1-EA6FD9411E8E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2F1602D8-2D54-4CE8-AA5A-5EEF7E2A858E} - System32\Tasks\{D21EA65A-44EB-464A-9DE2-146F048CA557} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {2F94047F-3A85-4824-B184-84E692DD8FDC} - System32\Tasks\{8AAC4425-84C7-473A-9176-7CDC1B945E17} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3024CA3C-1A96-4627-9537-ED118A186E67} - System32\Tasks\{E2F5210F-2631-4D91-846F-19297E04B896} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3032538E-C43C-4D03-9188-6A4F0549E71B} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {30568D3D-7971-4F36-81FD-E61631C4BB57} - System32\Tasks\{7A87D65E-FDC1-4CB9-90D4-D12D3FA46EBD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {327DE954-86CA-4727-BEDB-3D552CE75DC2} - System32\Tasks\{B2F079F0-A5EA-4E87-8D44-B8520B2B3744} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe
Task: {34B0DB67-D565-4912-B698-F6A3820BB42E} - System32\Tasks\{326BB3CB-2AA7-409F-8145-AE956B1109A2} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {34DC50F6-70ED-48F6-9E59-E47E80C5F6C5} - System32\Tasks\{81F3A03F-A984-4D44-8C6E-481C91E702C2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {38033478-0F98-4B7F-9FE4-F40D65526668} - System32\Tasks\{A285C147-7F6E-460C-8794-6453B4B02DDE} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {38596C41-5023-4B7B-A97A-FFCFB4638D5B} - System32\Tasks\{56D14608-B485-45C4-AFA3-D4697153A8EB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3896DA66-668F-4E13-8D8B-14701CA38B7A} - System32\Tasks\{02976DCA-3D64-4818-8AB2-D452E2EDBD39} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {3AAFDACA-05D8-49D7-A834-1DBEB4447E00} - \41220790-4b35-4753-91f3-94289344bd48-3 No Task File <==== ATTENTION
Task: {3BA6A538-EDC3-42E7-B0DC-94555326A0E0} - System32\Tasks\{F599B4D3-A939-427B-BFAD-41215FFA4B06} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3BB70042-89B5-4A30-AC51-AB0D69BB4B48} - System32\Tasks\{3A87CEDE-5E99-4260-A802-4AA83B8A0AD3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3BC27ED0-6484-4FF7-A68A-D54328294275} - System32\Tasks\{0FEA611C-B1BF-4668-9918-41A30DF48CC3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3D42ADE7-E1E6-4302-8844-122441F4B904} - System32\Tasks\{76D5F951-BF21-4A9D-8603-7AE010F98315} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.)
Task: {3F5B5D63-9908-4BA1-8C99-A3C1718E5EE9} - System32\Tasks\{DBC5E996-473B-425F-9DB0-97B88D1C9349} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {3FDBAE0C-A108-4561-BFDD-89C3C2F3D570} - System32\Tasks\{0BD20564-C544-4345-A074-D421C4CC49E0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {415EAC50-7423-4ECB-B27D-1D20376B9A4F} - System32\Tasks\{362EC899-4A81-4D93-96BA-13249EE94512} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {41F754B4-BA61-4685-AE07-6402385F6933} - System32\Tasks\{8AEB40A7-FA35-48F5-82EB-EA0819FB326B} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {422EB8B1-2BD7-4FF0-A55D-6A3F7EBE8EDF} - System32\Tasks\{4A347536-E75E-4196-AB34-F33A32433986} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4350EF98-4350-4E0F-98FD-C4EB6ED33391} - System32\Tasks\{11911F7C-AFE3-47ED-9FF5-A0B6F51AB520} => Chrome.exe hxxp://ui.skype.com/ui/0/6.16.0.105/de/go/help.faq.installer?LastError=1618
Task: {45DC1622-0863-4EC2-8060-B48745AA713B} - System32\Tasks\{EAC80C87-0609-4B31-966F-868E17803A7B} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {4737680D-7D41-4EDD-89C7-3608C0004939} - System32\Tasks\{C8071675-FABC-45F3-BF98-E3D37474BB4E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {475F81D7-458B-41BC-8A3D-9C3162F60648} - System32\Tasks\{D7CDC2B5-4F80-47C5-B6DD-1D8018821633} => C:\Program Files (x86)\Team17\Worms Reloaded\WormsReloaded.exe
Task: {4770E7B8-7CFF-493C-9976-C434C787CD0B} - System32\Tasks\{8F1ECE0A-1A81-48B5-85BC-2B7D41547151} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {47D83C6B-CF1E-4562-96CA-C7D25840572B} - System32\Tasks\{0AA5EC75-C091-44FA-82A9-44BC0DDA59E3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4A9A003A-7665-4B9E-B336-A56DE8E8789B} - System32\Tasks\{BE4896D2-6869-4B2B-8F8D-BCA1F61A2487} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4B2BDB10-32EF-4B37-9AA1-B15CAD2A48F6} - System32\Tasks\{887B7566-0AAF-435D-B5EB-86E215D22677} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4B437054-DE44-423D-8381-6D09430DFFA9} - System32\Tasks\{CD46C27E-3FC1-4211-920C-E8A7F411CF5A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4B64318D-5F94-4677-BDEF-13D5B6FDFB73} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-03] (Google Inc.)
Task: {4C482DEE-9E14-4738-A2C6-84243B47285E} - System32\Tasks\{65FE692F-FAE1-4833-A4E3-5B91189BDA71} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4CE83691-0839-4DF7-BB2D-16C096CA1DD9} - System32\Tasks\{DCB5B081-0D7D-4A9D-BFB6-F75BA6B4FFE4} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {4D272B4D-0F7B-4149-96B7-E92D0CE78840} - System32\Tasks\{179B45CD-DEC5-4ED2-A215-93FE8E3A3B52} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {4E55A326-7F9C-456A-B061-F773C26BB4B9} - System32\Tasks\{C287E2B1-6EFF-4D09-9101-EAD7B150CB7B} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/abandoninstall?page=tsProgressBar
Task: {4F9E67CB-A23E-4973-85EA-DC854F0C5049} - System32\Tasks\{115DA74C-5B2D-40DA-947B-BAEDFEA6A8E2} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {521EC980-CAC6-4F1D-B6FA-C7BC3A98441F} - System32\Tasks\{81DCE1C0-894D-4779-A1BB-70EE95F4E4B2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {55FEEF07-8E10-45F7-85F6-11C4D8959BF6} - System32\Tasks\{B37F681A-EF3E-45CC-9F17-864119A91E65} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {56C4AFB3-803E-46C9-8C94-ACC9588F0452} - System32\Tasks\{C694B19B-E147-4FDB-9837-2D8A57B43CD8} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {57D5AA40-981A-438F-B928-D3733FD29B8D} - System32\Tasks\{0D35558A-B8E3-478D-92C2-CB6CAF71D82C} => C:\Program Files (x86)\Team17\Worms Reloaded\WormsReloaded.exe
Task: {585C0F3C-AD7C-494C-95AB-929FC93FD477} - System32\Tasks\{7D4A2968-2466-423B-8693-D892F5770BC2} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {59201B3B-2CF8-44D3-BA51-AA71F9BD925B} - System32\Tasks\{2A7E476D-1AB7-4688-A479-ED4CB5FE309C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5A19A249-F795-411F-B1A5-22070127E4D8} - System32\Tasks\{3D7F2444-BC97-4FC1-A3AD-2050924AB4E4} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5A75A413-5A4D-47D6-B08F-3A09AF467BA6} - System32\Tasks\{126D53C6-D39A-48FE-87A3-BE39FECA82A3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5B55648B-938F-4098-AA57-C551B3F04294} - System32\Tasks\{BA7A9134-7D67-401C-8D4C-39B014EC993C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5BC20421-CD55-437D-B993-7ED3F777584D} - System32\Tasks\{92825E9C-7F09-4EF5-A901-8D20AB4C1CED} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5BF5E050-9C81-448E-B218-B99FBEE1D85B} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {5D2C9C91-EBBD-4630-BE2B-DDB3E6EB314E} - System32\Tasks\{5CE6AC57-2F71-4A9C-B339-34847941A456} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {5F627168-4146-41EC-A6E7-4139910834F3} - System32\Tasks\{0498C35C-C89F-4EDA-BA65-F25B08667C06} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {63385CAB-C77F-4D19-8E64-56010138AA02} - System32\Tasks\{F9D4650D-451C-4CF7-AF96-55C9D5512DF6} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {6508B54E-7342-451D-B651-920729BB2E43} - System32\Tasks\{E2A806C7-3C0D-402F-ACE6-28E8CB964BE2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {65DDD6CA-9B68-44C9-B4BC-B2360B7CB949} - System32\Tasks\{C8F7C6D2-FC04-41A4-AB21-AF4830FD735C} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe
Task: {685EC281-E83D-41DF-A5CC-91A8925976AC} - System32\Tasks\{F4948F46-A30B-4C1A-B276-7F5EC91174F1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {687804B6-E9CD-4E37-9D92-D197693B397E} - System32\Tasks\{0EECE376-7CDE-44E3-84E0-72D5A5ED585D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {6A8E2C17-BAEB-4DC8-A342-84DF6286A844} - System32\Tasks\{6EFAE2C9-AE73-4A53-B318-92B8924F73F6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {6B8374AE-0ECA-4D2D-BB9A-45344C01B9C5} - System32\Tasks\{9325521E-959B-40C0-AE8A-DE5FABB2B06F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {6BA32B1F-4293-4074-BD78-CE1A5F17ED99} - System32\Tasks\{8E72C766-9BB4-4166-9866-76139173268C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {6C1979F1-AB41-4EC0-944E-0D16797FF4FD} - System32\Tasks\{454F111B-9668-405C-9D32-5B05FDF5731F} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe
Task: {7250271B-F6A2-470A-85A2-0168259D90A8} - System32\Tasks\{E4F229CC-7F16-4DC9-A408-AAB6CAC3F797} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {73D95EE9-648D-4C8F-8911-6B63E0A22F04} - System32\Tasks\{3E98FF82-D955-45DF-983A-3EFBA31786F9} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {757946F4-35A8-4AEC-B087-00F90BFC2B01} - System32\Tasks\{7B88D895-FA14-4844-A488-041B3EAA833E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {76212287-AAC0-4420-A612-24FD8A9DA5F9} - System32\Tasks\{A2D10B81-B079-4BC6-987C-A19BF3AF4496} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {7916DCDF-AC27-4A62-892F-9DE2BAADE7BB} - System32\Tasks\{0DBAD5B0-D837-4E82-8270-D732E84B8997} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {79F6D2E3-BB87-4B16-A090-9A6AA4E273DA} - System32\Tasks\{0C33B5D8-227A-489D-9DC7-201BDC56A2CB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {7A79C6A3-E123-4706-990B-7FA2A25E8334} - System32\Tasks\{C77745DF-3ABE-49EA-84BB-ACDF2CB0C172} => C:\Users\Sven\Desktop\GBA\Gamboy Advance\VisualBoyAdvance.exe
Task: {7EDE632F-8D75-4EDA-8D30-5F6D6E0DE3F0} - System32\Tasks\{0F216DE1-10A4-4121-9354-94F1FCAE0BA7} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {7FA4FAB4-B29B-46CB-A242-E31BD6102BC8} - System32\Tasks\{6F643769-F667-45A7-89A3-EFB78BAD30D2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {805A90DD-4661-4FA4-ACC5-9746B1FD37E9} - System32\Tasks\{899D1CD0-E191-4706-820D-6FCC78860A5D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {812EA991-4051-4066-8F6D-7657E59F6F13} - System32\Tasks\{13CC1F28-B809-4E6A-92F6-050867303E38} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {8432A04B-4B1C-4DF7-88E8-D224B18E0864} - System32\Tasks\{7D8FC48F-F5D5-41C9-A0C7-46FFDB261DF9} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {843DBDDA-40BA-402E-BA69-2271D24F05F8} - System32\Tasks\{C6726A3E-D031-4D25-A625-2FB541085294} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {846792F6-E344-4F5C-8269-35876689B894} - System32\Tasks\{722EE7AC-CBDE-41B1-A4FB-3996382D0916} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {85198C15-CF04-4EB5-8361-B1B6A57279E2} - System32\Tasks\{C6F24B23-E357-414F-8A77-F68FAC2F537E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {85B0D0F1-A5E5-4225-91A2-6AE76820489D} - System32\Tasks\{B1D3638D-7AC5-4FDE-B0B3-8646717611E3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {85B242CA-8635-4CE5-8A89-BC0B930AFB26} - System32\Tasks\{3438563C-BDA2-4240-86FE-C250087D876B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {860D5616-C807-42E4-9471-34492936869C} - System32\Tasks\{0C52ACFB-76D7-4572-AC1F-5C817BC6F9B7} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {89C98CDB-86B4-4B1E-83FE-3BFDA3BBA61B} - System32\Tasks\{85CA7BEC-BAC3-4039-951D-6DD6897DA82A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8BDBE9D0-F1E1-4282-8D2C-595C2EB28B92} - System32\Tasks\{82A89D01-11E0-4CC3-80AE-23A6B6E0FC61} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8CB35F7E-5585-4B14-8711-11D6FAC29378} - System32\Tasks\{D2A2BD67-9A7E-4D6F-BE2C-6A8B2D0F1BA1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8D8F82B8-57B8-4BFE-A952-D123EFC13ECC} - System32\Tasks\{203C25BA-F232-4421-B3DA-A376B3774516} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8D97D69A-AD7F-493C-8DCC-7CB007C6A8F2} - System32\Tasks\{9C7168A6-031A-469A-AA01-62138FAD5C64} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8DF97B81-3559-47F4-9420-360B447E1FD0} - System32\Tasks\{FECF6647-C213-4C31-93D8-DA36CEF2D2E5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8E04509E-7AFC-454D-841A-708BB706F7DC} - System32\Tasks\{3E9663A7-8201-4FF2-B1EB-833DE8AD30E6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {8FA91399-CE12-4FBD-A967-DFD7D9109D84} - System32\Tasks\{9D64689E-0BD4-4A36-BD88-4A0E50CDC83F} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe
Task: {903E2695-1203-484C-B1FB-D551272A2574} - System32\Tasks\{8DB1831F-D69A-4DDE-831A-FAA560851E70} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {904FCA34-E617-4024-8059-1269ADC0C47F} - System32\Tasks\{4C21C9AE-2772-474A-A218-F693E2CF602B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {931B5588-6B96-408B-B873-41412BFE2B8E} - System32\Tasks\{C7652E09-4AA0-4B7F-94CB-751180B2AC84} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {9879350E-87CA-40F0-964A-DFC97AB3BC30} - System32\Tasks\{41A7B7D7-A9E8-4FDD-AB09-12810CB9DE9C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {98AF9170-2913-4F80-95D2-95B7477DE797} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-17] (Adobe Systems Incorporated)
Task: {9974FA93-556E-4FDD-ABA7-D41F1D4176D6} - System32\Tasks\{0BE877C9-7403-4859-BB65-3F99D03088A8} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9ADA0808-016F-4483-B32E-F4712A3C1511} - System32\Tasks\{31210AE0-BEE0-48B0-AD32-F3DFF7AF8585} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {9B469F57-8F99-42A1-8801-E8E97EC4CDD1} - System32\Tasks\{F66DE0CE-872C-44E9-AD32-7E45842B895C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9BA28B79-CD14-416E-9A76-1B33558AAB10} - System32\Tasks\{AB2ECB65-FA3E-40E1-A023-0E8D5E03A224} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9DBF7F80-5E83-4F91-91D2-32FA850EF84F} - System32\Tasks\{3CCABE20-2386-4504-81C4-4235BAAC31B7} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9DFAF053-ECF1-4951-B8B9-D566381CF17E} - System32\Tasks\{12CBB338-12C1-4249-84A2-07241A16A2D6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {9E7E9471-FE25-4DB0-99FC-8E598F78A02E} - System32\Tasks\{DE3AD989-7BFD-4AD9-8EDC-6F505EB64364} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {A1B61844-B80C-4D9A-94F1-4645C98FC2B8} - System32\Tasks\{75FCFCA1-F6E7-4195-8FDB-205A363174BD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {A212F777-60F2-4D21-AE31-7D8EDE725661} - System32\Tasks\{107A92FE-4711-4473-8E02-B7C9963E7371} => Chrome.exe hxxp://ui.skype.com/ui/0/6.16.0.105/de/abandoninstall?page=tsMain
Task: {A2ED97D9-08BE-45A0-8F5E-DF79EE68E5EA} - System32\Tasks\{E792460F-EDFC-488E-8731-0BBFB1110EB6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {A6B88D73-C7CC-4AC8-9868-003E3D1A6117} - System32\Tasks\{123ECB18-D866-4EAF-A87C-2B532824BBFF} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {A88B4C8C-9BCA-4F56-B093-7BB101C93929} - System32\Tasks\{88F50087-6CF7-4A6A-B06F-AD288A88A6DA} => E:\AutoRun.exe
Task: {A97D22B7-423F-439C-9A10-3C6091CA5D1A} - System32\Tasks\{1BFCBFF7-66FB-4E87-81A8-FB7CF75207DE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {AA445193-1181-4478-AEF2-B0ED5C6C2E97} - System32\Tasks\{2FFB54D9-0F45-4439-A0AB-B2246A92D499} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {ACFC14E5-8848-4358-90F5-8817059D3A5E} - System32\Tasks\{537B3161-6C44-4CA2-94A2-5BDB3B8C8D3E} => C:\Users\Sven\Downloads\PortableZombie Driver1.0.4\Zombie Driver.exe
Task: {ADC16C61-80CB-4175-BEB7-3723F4552311} - System32\Tasks\{65BF13AD-A284-4838-9987-577314060DB0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {ADCB1719-67BA-4895-9D04-8A1A0C26DEB7} - System32\Tasks\{697D2AB0-4D70-40B2-BA95-E58EF151514D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {AE410752-87F2-492D-9D1A-6D81D53BAF55} - System32\Tasks\{20EE37CD-2303-4DD3-97A5-61226D364CF1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B01A395C-1E4E-4257-A8F2-51DC50233552} - System32\Tasks\{A772563F-BDDC-463B-99F1-C77841420332} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B1CD2103-56BA-4745-9177-223FFDD53ADC} - System32\Tasks\{470BF604-D7FC-467D-A26E-CF0F03148BEC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B26A8951-5FE0-4FB7-873E-A0D132A2025F} - System32\Tasks\{98160B25-2EF3-494D-855C-85407974E878} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {B39BD072-35FE-4CC5-A530-A8909B6872D3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-03] (Google Inc.)
Task: {B408996C-AB90-4D16-848B-E5C3A70821D8} - System32\Tasks\{667B8D52-5E64-4C4A-9884-01C81DCCA5A8} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {B40A4AAC-C52E-47C0-8860-D0D8CFBF36B3} - System32\Tasks\{8528129B-330F-4FB9-BD05-0B63A185738C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B46D754A-55E2-4756-BC53-3885E70D6472} - System32\Tasks\{A379F55A-1CF2-4571-AACC-0F2431A98E00} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B5F85DB4-3143-4086-91FA-2D4D1E3681FC} - System32\Tasks\{73E77971-0011-4D43-AD03-9117C0D1EFDC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B6A0B547-231E-4DD7-90D8-4EED1969E049} - System32\Tasks\{51ABC066-D83B-4170-8165-07805CC167F0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {B6BFFAAD-9659-42EF-AA02-57D301DBA5A3} - System32\Tasks\{6C2FFB99-7192-428B-B38C-1D8F0B6F7FC6} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe
Task: {BA9030C6-4777-4D8C-AB61-76025BFA120F} - System32\Tasks\{313997D6-C748-4720-826F-E7E9A6BC21CC} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {BCFF6A0A-67BC-421B-A03C-20012560E161} - System32\Tasks\{7AB46240-BDE2-4A4F-919C-21CFD95DEB91} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {BD78545A-B9EB-4AF6-AE31-BDA236D2BAE8} - System32\Tasks\{B315BDCA-1064-453A-A6CC-C79F19F7D016} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C0FF2097-FA54-4970-ABCC-D3C6970BDB8F} - System32\Tasks\{909D4AED-895C-4B2A-96DD-6CA6D80B3960} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] ()
Task: {C1130E74-46A9-4A07-855A-CDF608DEBBF8} - System32\Tasks\{83AAA377-4550-4890-81AB-EABAA6D54F2F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C1992231-5AD6-4DEB-9429-A822E9B6459F} - System32\Tasks\{73E2DA90-10C9-4FEB-8303-D06CFBA64319} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C2180CA4-8AED-48C7-A2E9-F6AE7C2EA254} - System32\Tasks\{68575AA0-FDE2-4EFD-9481-ECADE3C34DA9} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C4CD2A1C-B81A-4DF8-A06D-66F8EE0C9E08} - System32\Tasks\{4954985C-7557-42F2-9DA3-44DAB4B574EA} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C6B28C1E-EB4C-49E1-9C0B-AB8E2704CBA2} - System32\Tasks\{F92A9599-40B3-4A4D-AC6B-DB14C925E677} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C70B179E-12FD-4FA2-9ADF-F9B845F76EBE} - System32\Tasks\{7B61AC9C-9B02-4800-95D6-DC4C2193ECA4} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C956224D-737E-44AC-A135-B8A291573F99} - System32\Tasks\{C5CECD65-EFFE-4679-8ED8-9083413AF641} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {C9C1E1CF-9F4F-4893-8DF5-FFD570756159} - System32\Tasks\{1F69CD65-61D9-472C-95EE-8793CAB2098E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {CD835294-0684-4E85-93D7-57FA3413500A} - System32\Tasks\{7AD6CBE5-95F9-4616-B6CE-1FBF3ACBB0D1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {CD878935-40AC-4D8D-8C98-045CA41BB390} - System32\Tasks\{F83E546C-96CD-4EB6-8305-C82BC2EE455A} => Chrome.exe hxxp://ui.skype.com/ui/0/6.16.0.105/de/go/help.faq.installer?LastError=1618
Task: {CDAC83D4-811F-4165-8722-856EAE3449B3} - System32\Tasks\{E0B10180-47E9-4AB1-9FE0-6C44B2EF97A1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {CE724C0F-EA35-4437-9D30-1113211B6A09} - System32\Tasks\{4C940F41-C0B3-4969-884C-E442672E162D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {CF2606A0-ACA7-45F9-AD40-268630067DC0} - System32\Tasks\{96124692-6A3C-4996-8C1C-D5A23375B7EE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {D21F7BE1-05EB-44B3-BAA5-9BCD4AE31875} - System32\Tasks\{901FF9AA-59B7-48DE-82FE-581B7F599280} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {D264BCEC-BABB-4C67-AB5E-F518C830438A} - System32\Tasks\{F600C80E-888F-4E6B-9B51-FEB3021CC358} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {D360F099-830B-49E3-8626-6FA307F5DDE8} - System32\Tasks\{BC56BB0E-CC7A-4E3C-BAA7-76686DE08AC6} => C:\Program Files (x86)\il-2 sturmovik cliffs of dover\Launcher.exe [2011-04-03] (1C:SoftClub)
Task: {D4A58010-4058-414F-B75C-F534647CCADE} - System32\Tasks\{60083AE6-8669-4F76-A8C9-EC5394929A9B} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {D652DAE9-1CF0-45B1-BB5B-73CBD75E3D7A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files (x86)\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd)
Task: {D71B37E9-5FF9-4CDC-8C10-90DBE9D9D2C7} - System32\Tasks\{A08D600B-BB0B-4BB7-B7E5-EFA9DBA72624} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {D84CF91D-4A8A-4C38-8808-78F24EEA7D00} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {D92C729A-F461-430D-9536-06B0A6EEF5D5} - System32\Tasks\Opera scheduled Autoupdate 1401931354 => C:\Program Files (x86)\Opera\launcher.exe [2014-05-27] (Opera Software)
Task: {D934BBFE-2B1B-462F-B25C-A7FC1696106C} - System32\Tasks\{B83314D1-CE37-47EB-93D3-5F69CE06C9BE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {DA5E0905-D48D-4F65-A292-DCE54E3DF4DE} - System32\Tasks\{48B23608-CF81-40DF-866F-E9149F931791} => C:\Program Files (x86)\English Bid for Power Final 4.0\EBFPF 4.0.exe
Task: {DCB6E2F6-56D1-4247-8394-3366B53DBE91} - System32\Tasks\{D0C97849-AFD1-450D-A83D-E2ABAF26C11D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {DD54C13C-6AA2-45C9-98FB-4F3C4F706776} - System32\Tasks\{D636E579-ECC1-48E6-8D34-0898C8B8AB88} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {DF3520E2-5C0C-45C7-9E29-C0A3CF6624CD} - System32\Tasks\{F9064DAF-E8C8-42B4-872B-CF84AEB8A5A1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {DFDC1780-CB4B-49C6-9D0C-6A307018E041} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated)
Task: {E06029EB-0DB6-46F4-8D96-010660E515F6} - System32\Tasks\{6D9D7339-3B94-4B93-A4D6-B3152EBECD01} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E069F814-CBF7-4E4F-9793-7A842132DBBA} - System32\Tasks\{373EABBD-53C5-4E40-898F-4C5069D8A499} => C:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe [2009-06-28] (Sony DADC Austria AG)
Task: {E13EACA4-DC9F-4ADC-9A68-67B64DFE23B6} - System32\Tasks\{DEF987AD-81AC-42EB-B412-5A8403716DDA} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E1C1E3A3-A460-421D-A2A3-CD52241FD7D5} - System32\Tasks\{C0F296D8-C7D3-40E7-BE16-E643CDDEC0BC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E2191329-4BE6-4CFE-A6D1-734AF9A17EFA} - System32\Tasks\{3BA18019-EAF4-452D-A4A2-3E20F326FC0D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E3C57322-4D59-48CE-9D42-CC0D884733F7} - System32\Tasks\{BA768B60-C681-4E86-B54D-B818BB13C841} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E44DAC2B-B71A-4537-A501-996802E1A023} - System32\Tasks\{03B26415-BC1D-4284-9D4A-A178EB9B3EB6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E4508BB6-1429-49BD-BCBA-083AAA7E5AA8} - System32\Tasks\{BC238E47-DE85-42C8-A42A-5CAEAE4649FB} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {E4FA1C11-710B-467C-8C5B-869390DF8A61} - System32\Tasks\{699BB15C-2884-457A-BA98-A4B8698C652A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E6A13448-9338-473B-BAA0-23B9F616B6D0} - System32\Tasks\{775735C3-BC90-4F41-82D2-6C5EE14FD15A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E712900C-C47E-492D-BF1A-DE095C31D309} - System32\Tasks\{3A9C2093-CDC6-4117-A344-E59636C8D654} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {E92D78D6-0882-4D25-8296-F91672232EC3} - System32\Tasks\{0B804F92-4E06-4F0B-8398-FBFF1770A638} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {EAD179B7-8EFB-4C37-A13B-DAA71D740E0D} - System32\Tasks\{CEDABE9A-9564-465A-B4B1-1257AC1B2C43} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {EB6B115F-67DB-4599-B4F8-8766B8ED346F} - \41220790-4b35-4753-91f3-94289344bd48-5 No Task File <==== ATTENTION
Task: {ED37749E-137A-4F1C-9FD0-3DCF709567E5} - System32\Tasks\{A4B072C7-A2B2-4870-8C3F-6B6324B02FBB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {EF1BD8C8-A15F-4BC6-AD60-672E42A93C49} - System32\Tasks\{A6450515-09C9-444A-B374-6304A0A11E67} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {EFC87779-05F4-4C10-8880-71EAEBE1391F} - System32\Tasks\{8A126FB2-9DF1-40B6-BF29-94BC77C74FAB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {F0108CE8-B277-4C4D-BEB9-83F45F46F170} - System32\Tasks\{6E35942B-EC74-4C6C-8ECD-5787FEE77389} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {F11AE687-5F0D-4509-9E7D-904D61C5BA98} - System32\Tasks\{177FAF9C-8814-4261-A21C-CA7506F2B82F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {F28B5784-80AB-4325-8C31-358E7215BB3C} - System32\Tasks\{6F04151D-6AB6-4AD1-AD9E-5AE5BB416094} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {F62B21A2-FAEC-44BA-93B9-C1AE49234444} - System32\Tasks\{11514906-B372-4DBD-B566-488DF1E6F029} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {F800F910-22FD-49C7-938B-A6C0AD765100} - System32\Tasks\{88CE8631-1046-44CF-88EE-4849D81EE9E3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {F875476F-7142-4F9D-812C-13343492E7A1} - System32\Tasks\{D9DFF9E6-6D3B-4AE0-9D39-D0AC25C7B9BE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {F89D7FAD-847B-495E-B7A9-1102853A0B96} - System32\Tasks\{B518FFEB-D63F-452B-82E4-F45EF890BC97} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe
Task: {F8E344A2-D4C9-4CE7-98BB-521D2CA6A434} - System32\Tasks\{D691C721-D450-4C82-B4C4-495A1B64DBD3} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe
Task: {F91D746E-4CF8-41DE-83CB-31432B4543D9} - System32\Tasks\{DCEAF480-641F-4ACD-A325-BDBA0CCC540B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {FA2B38D9-60DC-455F-BB4A-D4810EB33769} - System32\Tasks\{0A9C2DB2-D33D-4DE9-A45C-528B8C1AEE1B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {FA31A522-796E-426B-848D-E9077313AD8A} - System32\Tasks\{A0DA316A-D472-444F-A426-D6D46912C19F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {FBFCFB6D-C9AD-4075-A58D-ADD617EF8D2B} - System32\Tasks\{45962B83-FB74-456E-BE05-674FB7E57069} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: {FCE91E30-A0CA-4991-A909-F7CF995FB676} - System32\Tasks\{B8DE84ED-80C7-4218-A29E-5B4B9E36DDAA} => C:\Users\Sven\Desktop\GBA\Gamboy Advance\VisualBoyAdvance.exe
Task: {FE3ECFB4-5ADB-4B7C-92C9-E7F27D53C159} - System32\Tasks\{08AF28EA-188F-4A3C-AA80-C8A5DC185025} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001Core.job => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001UA.job => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-10-26 03:31 - 2013-08-18 21:34 - 00097568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2013-10-12 04:11 - 2013-10-12 04:11 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2010-05-02 11:53 - 2010-05-02 11:53 - 02937528 _____ () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
2010-05-02 01:13 - 2009-05-07 16:51 - 00071680 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
2010-05-02 01:13 - 2009-05-07 16:53 - 00379392 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
2010-05-02 01:13 - 2008-01-18 14:50 - 00098816 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\VMicApi.dll
2010-05-02 01:13 - 2009-07-10 10:48 - 47601664 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Skin.dll
2014-06-05 03:22 - 2014-05-27 12:00 - 01396344 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\opera_crashreporter.exe
2014-06-05 06:20 - 2014-03-14 08:00 - 00695808 _____ () C:\Program Files\AVAST Software\Avast\VERSION.dll
2014-06-10 11:51 - 2014-06-10 11:51 - 02775040 _____ () C:\Program Files\AVAST Software\Avast\defs\14061001\algo.dll
2011-09-27 08:23 - 2011-09-27 08:23 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2011-09-27 08:22 - 2011-09-27 08:22 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-06-05 06:14 - 2014-06-05 06:14 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-06-05 06:20 - 2014-03-14 08:00 - 00695808 _____ () C:\Program Files\AVAST Software\Avast\version.DLL
2014-06-10 12:53 - 2014-06-10 12:53 - 00043008 _____ () c:\users\sven\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp4f7lre.dll
2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Sven\AppData\Roaming\Dropbox\bin\libcef.dll
2014-06-05 03:22 - 2014-05-27 12:00 - 00877176 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\libglesv2.dll
2014-06-05 03:22 - 2014-05-27 12:00 - 00135800 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\libegl.dll
2014-06-05 03:22 - 2014-05-27 12:00 - 00957048 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== Disabled items from MSCONFIG ==============

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GamersFirst LIVE!.lnk => C:\Windows\pss\GamersFirst LIVE!.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Rainmeter.lnk => C:\Windows\pss\Rainmeter.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Sven^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Sven^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Facebook Messenger.lnk => C:\Windows\pss\Facebook Messenger.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Sven^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^regsvr43.lnk => C:\Windows\pss\regsvr43.lnk.Startup
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: AutoStartNPSAgent => C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: DivXMediaServer => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
MSCONFIG\startupreg: Facebook Update => "C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: SandboxieControl => "C:\Program Files\Sandboxie\SbieCtrl.exe"
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent

==================== Faulty Device Manager Devices =============

Name: SbieDrv
Description: SbieDrv
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: SbieDrv
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/10/2014 11:08:28 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: adwcleaner_3.212.exe, Version: 3.2.1.2, Zeitstempel: 0x4f25baec
Name des fehlerhaften Moduls: adwcleaner_3.212.exe, Version: 3.2.1.2, Zeitstempel: 0x4f25baec
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000111c9
ID des fehlerhaften Prozesses: 0x13c8
Startzeit der fehlerhaften Anwendung: 0xadwcleaner_3.212.exe0
Pfad der fehlerhaften Anwendung: adwcleaner_3.212.exe1
Pfad des fehlerhaften Moduls: adwcleaner_3.212.exe2
Berichtskennung: adwcleaner_3.212.exe3

Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9999

Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9999

Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9001

Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9001

Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8003

Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8003

Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


System errors:
=============
Error: (06/10/2014 00:53:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "KMService" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (06/10/2014 00:53:30 PM) (Source: SbieSvc) (EventID: 9153) (User: )
Description: SBIE9153 Treiber kann nicht gestartet werden (SbieDrv)

Error: (06/10/2014 00:31:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "KMService" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (06/10/2014 00:30:50 PM) (Source: SbieSvc) (EventID: 9153) (User: )
Description: SBIE9153 Treiber kann nicht gestartet werden (SbieDrv)

Error: (06/10/2014 00:22:23 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.

Error: (06/10/2014 00:22:22 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.

Error: (06/10/2014 00:22:21 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.

Error: (06/10/2014 00:22:21 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.

Error: (06/10/2014 00:22:20 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.

Error: (06/10/2014 11:50:57 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "KMService" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2


Microsoft Office Sessions:
=========================
Error: (06/10/2014 11:08:28 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: adwcleaner_3.212.exe3.2.1.24f25baecadwcleaner_3.212.exe3.2.1.24f25baecc0000005000111c913c801cf848aa06ca209C:\Users\Sven\Downloads\adwcleaner_3.212.exeC:\Users\Sven\Downloads\adwcleaner_3.212.exec8693396-f07e-11e3-95c1-002618bca0f6

Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9999

Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9999

Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9001

Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9001

Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8003

Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8003

Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


CodeIntegrity Errors:
===================================
  Date: 2014-06-10 12:57:09.216
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-10 12:57:08.175
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-10 12:57:07.156
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-10 12:57:05.415
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-10 12:53:30.820
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-06-10 12:53:30.414
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-06-10 12:39:35.652
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-10 12:39:34.877
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2014-06-10 12:30:50.021
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-06-10 12:30:49.693
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info =========================== 

Percentage of memory in use: 56%
Total physical RAM: 4095.18 MB
Available physical RAM: 1766.4 MB
Total Pagefile: 8188.54 MB
Available Pagefile: 5871.79 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:229.38 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 3AC77A71)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
hab nichts gesehen

Alt 10.06.2014, 12:05   #23
M-K-D-B
/// TB-Ausbilder
 
Sicheres Löschen von "PSHD-9.9" - Standard

Sicheres Löschen von "PSHD-9.9"



Zitat:
Zitat von Goodfell Beitrag anzeigen
hab nichts gesehen
ok


bevor es weitergeht, habe ich eine Frage:

Zitat:
FF NetworkProxy: "autoconfig_url", "64.85.181.46"
FF NetworkProxy: "http", "64.85.181.46"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "type", 1
Hast du diesen Proxy-Server in firefox gesetzt?

Alt 10.06.2014, 12:07   #24
Goodfell
 
Sicheres Löschen von "PSHD-9.9" - Standard

Sicheres Löschen von "PSHD-9.9"



Zitat:
Zitat von M-K-D-B Beitrag anzeigen
ok


bevor es weitergeht, habe ich eine Frage:


Hast du diesen Proxy-Server in firefox gesetzt?
Nein habe ich nicht.. benutze Firefox schon länger nicht mehr, weil sich mit ihm keine websiten mehr laden lassen.

Alt 10.06.2014, 12:14   #25
M-K-D-B
/// TB-Ausbilder
 
Sicheres Löschen von "PSHD-9.9" - Standard

Sicheres Löschen von "PSHD-9.9"



Zitat:
Zitat von Goodfell Beitrag anzeigen
Nein habe ich nicht.. benutze Firefox schon länger nicht mehr
Dachte ich mir... dann geht es so weiter:





Wir entfernen die letzten Reste und kontrollieren nochmal alles. ESET kann länger (> 3 h) dauern.
Im Anschluss entfernen wir alle verwendeten Tools und ich gebe dir noch ein paar Tipps mit auf den Weg.




Schritt 1
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument


Code:
ATTFilter
start
S4 DlProtectSvc; C:\Windows\System32\DlProtectSvc.exe [123392 2014-06-04] () [File not signed]
C:\Windows\System32\DlProtectSvc.exe
HKLM-x32\...\Run: [NextSTART] => [X]
HKLM-x32\...\Run: [Workshelf] => [X]
HKLM-x32\...\Run: [NPSStartup] => [X]
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Upgrade] => C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F}\Upgrade.exe
C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F}
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU -  {6552C7DD-90A4-4387-B795-F8F96747DE19}
SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP80B4BA23-BA51-47B6-A18B-B617C84C81FE&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
FF NetworkProxy: "autoconfig_url", "64.85.181.46"
FF NetworkProxy: "http", "64.85.181.46"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "type", 1
FF Extension: OutBrowse Toolbar - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc} [2013-04-17]
S2 KMService; C:\Windows\system32\srvany.exe [X]
R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X]
S3 X6va003; \??\C:\Users\Sven\AppData\Local\Temp\0035BEA.tmp [X]
S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X]
S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [X]
C:\Users\Sven\AppData\Roaming\CamLayout.ini
C:\Users\Sven\AppData\Roaming\CamShapes.ini
Task: {15CC64F6-C57C-4E1B-B266-D0FAEB366850} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {3AAFDACA-05D8-49D7-A834-1DBEB4447E00} - \41220790-4b35-4753-91f3-94289344bd48-3 No Task File <==== ATTENTION
Task: {5BF5E050-9C81-448E-B218-B99FBEE1D85B} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {EB6B115F-67DB-4599-B4F8-8766B8ED346F} - \41220790-4b35-4753-91f3-94289344bd48-5 No Task File <==== ATTENTION
Reboot:
end
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.






Schritt 2
Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop:
SystemLook (32 bit) | SystemLook (64 bit)
  • Doppelklicke auf die SystemLook.exe, um das Tool zu starten.
  • Kopiere den Inhalt der folgenden Codebox in das Textfeld des Tools:

    Code:
    ATTFilter
    :folderfind
    *PSHD-9.9*
    
    :regfind
    PSHD-9.9
             
  • Klicke nun auf den Button Look, um den Scan zu starten.
  • Der Suchlauf kann einige Zeit dauern.
  • Wenn der Suchlauf beendet ist, wird sich dein Editor mit den Ergebnissen öffnen, poste diese in deinen Thread.
  • Die Ergebnisse werden auch auf dem Desktop als SystemLook.txt gespeichert.







Schritt 3

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset







Schritt 4
Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.






Bitte poste mit deiner nächsten Antwort
  • die Logdatei von FRST,
  • die Logdatei von SystemLook,
  • die Logdatei von ESET,
  • die Logdatei von SecurityCheck.

Alt 10.06.2014, 12:25   #26
Goodfell
 
Sicheres Löschen von "PSHD-9.9" - Standard

Sicheres Löschen von "PSHD-9.9"



Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-06-2014 01
Ran by Sven at 2014-06-10 13:18:36 Run:1
Running from C:\Users\Sven\Downloads
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
S4 DlProtectSvc; C:\Windows\System32\DlProtectSvc.exe [123392 2014-06-04] () [File not signed]
C:\Windows\System32\DlProtectSvc.exe
HKLM-x32\...\Run: [NextSTART] => [X]
HKLM-x32\...\Run: [Workshelf] => [X]
HKLM-x32\...\Run: [NPSStartup] => [X]
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Upgrade] => C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F}\Upgrade.exe
C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F}
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
SearchScopes: HKCU -  {6552C7DD-90A4-4387-B795-F8F96747DE19}
SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP80B4BA23-BA51-47B6-A18B-B617C84C81FE&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
FF NetworkProxy: "autoconfig_url", "64.85.181.46"
FF NetworkProxy: "http", "64.85.181.46"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "type", 1
FF Extension: OutBrowse Toolbar - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc} [2013-04-17]
S2 KMService; C:\Windows\system32\srvany.exe [X]
R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X]
S3 X6va003; \??\C:\Users\Sven\AppData\Local\Temp\0035BEA.tmp [X]
S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X]
S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [X]
C:\Users\Sven\AppData\Roaming\CamLayout.ini
C:\Users\Sven\AppData\Roaming\CamShapes.ini
Task: {15CC64F6-C57C-4E1B-B266-D0FAEB366850} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {3AAFDACA-05D8-49D7-A834-1DBEB4447E00} - \41220790-4b35-4753-91f3-94289344bd48-3 No Task File <==== ATTENTION
Task: {5BF5E050-9C81-448E-B218-B99FBEE1D85B} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {EB6B115F-67DB-4599-B4F8-8766B8ED346F} - \41220790-4b35-4753-91f3-94289344bd48-5 No Task File <==== ATTENTION
Reboot:
end
*****************

DlProtectSvc => Service deleted successfully.
C:\Windows\System32\DlProtectSvc.exe => Moved successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NextSTART => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Workshelf => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NPSStartup => value deleted successfully.
HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Upgrade => value deleted successfully.
C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F} => Moved successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SearchScopes: HKCU -  {6552C7DD-90A4-4387-B795-F8F96747DE19} => Value not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL => value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SuggestionsURL_JSON => value deleted successfully.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc} => Moved successfully.
KMService => Service deleted successfully.
Winstep Xtreme Service => Service stopped successfully.
Winstep Xtreme Service => Service deleted successfully.
X6va003 => Service deleted successfully.
X6va011 => Service deleted successfully.
X6va012 => Service deleted successfully.
C:\Users\Sven\AppData\Roaming\CamLayout.ini => Moved successfully.
C:\Users\Sven\AppData\Roaming\CamShapes.ini => Moved successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{15CC64F6-C57C-4E1B-B266-D0FAEB366850}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15CC64F6-C57C-4E1B-B266-D0FAEB366850}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3AAFDACA-05D8-49D7-A834-1DBEB4447E00}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3AAFDACA-05D8-49D7-A834-1DBEB4447E00}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\41220790-4b35-4753-91f3-94289344bd48-3' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5BF5E050-9C81-448E-B218-B99FBEE1D85B}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5BF5E050-9C81-448E-B218-B99FBEE1D85B}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EB6B115F-67DB-4599-B4F8-8766B8ED346F}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB6B115F-67DB-4599-B4F8-8766B8ED346F}' => Key deleted successfully.
'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\41220790-4b35-4753-91f3-94289344bd48-5' => Key deleted successfully.


The system needed a reboot. 

==== End of Fixlog ====
         

Also haben wir es bald ja geschafft, danke dir für deine Geduld und Hilfe nochmals

Alt 10.06.2014, 12:26   #27
M-K-D-B
/// TB-Ausbilder
 
Sicheres Löschen von "PSHD-9.9" - Standard

Sicheres Löschen von "PSHD-9.9"



Gut gemacht.


Immer weiter, eins nach dem anderen.

Alt 10.06.2014, 12:35   #28
Goodfell
 
Sicheres Löschen von "PSHD-9.9" - Standard

Sicheres Löschen von "PSHD-9.9"



Code:
ATTFilter
SystemLook 30.07.11 by jpshortstuff
Log created at 13:27 on 10/06/2014 by Sven
Administrator - Elevation successful

========== folderfind ==========

Searching for "*PSHD-9.9*"
No folders found.

========== regfind ==========

Searching for "PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppName"="PSHD-9.9-codedownloader.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{19E6B430-8939-486D-A9B4-C81AB83A54B0}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{204114BF-9D1E-4F5C-95A2-5D7FC75C5553}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{225A1E1C-39C6-4FEA-807B-65C050E34218}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2522F635-E0DA-40E7-80E0-1957BDFF1224}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{28E606E4-13F1-45BF-80DA-AE5153B162AD}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2937F19F-FBEA-46E1-A843-3194414595}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{295B128F-80B8-4C89-A9E2-419A42803738}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2B5C22CF-8368-4D4F-8CA9-E17917EC9EF}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{34C62A0B-9CE6-4130-8361-AA4A7FE5F3}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{354CFB61-739B-4CCD-9D14-23224A32A4AE}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3AD62C28-6327-47C0-BB18-974F2A5BD248}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{41536BE9-239A-4B2D-A82C-88DB5AA6C192}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{43773D51-CA30-48E7-A36-4F322D8DBEA}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{460211B7-E7FA-430C-8C33-1698A338DF50}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56ABEB18-6BD3-496D-96E9-7938C3BB3D6B}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56CE1A96-624-42A0-9BEC-144E78DB565F}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{57D55C1E-BEDE-4058-992B-9B6543F1BE7}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E5132D9-76B3-4080-91A9-59D1AD1E7448}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61FD3EAB-F4A7-4B49-A44E-84CA4BC2DA8}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6278C536-F890-4B7E-A242-19F4CCA9D9C9}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{645607EE-466D-40C4-901A-B65848C4EFD5}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65D2E6F9-1396-4430-93EC-9BFF6107156}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6A200C98-6B0A-4715-ADDD-3E241B5E201D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6BAAA66-D001-4031-8358-16BFBCDA154}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E4D2BE9-46C2-424E-B00-96E2CFB71D49}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6F3CBD17-1AD5-4CE7-B721-E2376EBCE732}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{718E603-1AAC-40E9-8915-24E69CC6778E}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{720A7F6C-4CB0-4225-AE1E-D4FC62BE3355}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{75AA3E2D-E831-4A39-8F68-33133DE982C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78020622-6B73-4B60-816C-85CBDE4232A}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7840DA43-E56D-47D9-96D3-C37DB97F2E2B}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79C744DB-1C9B-4DBC-B3BD-E8A5A5C8BEE5}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F516459-6056-4106-A3E2-6715AE811D65}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{924E1C60-F131-4EED-8FD2-247BBC4568D8}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppName"="PSHD-9.9-bg.exe"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93500650-CFBE-4ECE-AC59-7138B4EC79E6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{950588AC-4F98-4479-89A4-7813AF1D477D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95CCA599-BDB3-4909-AAAD-372958F767A}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CBE1CD3-99B-4E61-BE25-A7111D511A6D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9EB3D095-A184-44BE-8B28-47582431D2B}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9F8CE472-726E-4126-B3A7-8E1932E3183}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2BFADEF-2DD0-45B2-9C33-C5311158FF9}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4384461-4B10-4BD8-B6CC-CCE6DF618E6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5039154-BAB-4409-9AA8-B45E6981EA11}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A88AC80E-1AD4-4C4E-90D9-2F76678F1DF}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A984BA40-EB90-455E-A61A-5C865AC25E7D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC476297-55E3-43EF-8DE2-B3EB1E41D02}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF4CAA4C-4EE1-4C8C-A784-16CACE8494F6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B3406F8A-99CD-48E9-B82A-A22B44565E0}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B787AF2A-EB75-402D-8E66-C0A33BABD89F}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BA89C16-B97D-4DD8-8B24-D47F167712B2}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C1609283-FD8A-4317-B9DE-4ECC199E24F}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C2ED9D17-6923-4087-99B3-C7D261D99E71}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3FC765B-13EE-4B5E-B540-E3A472461532}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C576D330-6FE0-4695-9778-D04A32E35C3D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C80C0F4-D216-4B33-A058-604AD982A773}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D099CE66-920D-4D91-8BAB-ED3C3D3342E6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D249689B-4959-496F-B97C-4E59F88688C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6BAF6EC-C708-4C00-A9A4-90F23BAC8AFB}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB3DC33D-829D-404E-81F6-05C99BED2D2}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD22B052-D0F2-4C8F-87F4-3C1E52D82CB}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD282AA7-652B-41CB-91A1-57F0A1477865}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE94E69-980A-4CC4-B8A-F2738BA2AE4C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E58E90C6-ED93-4E5E-95F-B82224899C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7808D13-3A9D-4531-B3A4-C57D5C889773}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E84EB0FA-DDEF-47D3-8AB4-1EB8804ED159}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EA1E5BDE-F92B-46B7-8683-2E192D126CA}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC1B7EA3-73C0-4C83-A944-2BE27ADC0DB}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEFD29F8-7061-4EDC-A723-5D302AADFD4A}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EF4840EB-E2A7-4F36-B635-5361678D4A4}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFBF6720-F576-4C15-A829-83B9E4E66199}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA150BE7-B443-434A-9184-C8497414A257}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FB009888-631A-4BD0-BBBF-B73AA1E42C5D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\PSHD-9.9]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppName"="PSHD-9.9-codedownloader.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppName"="PSHD-9.9-bg.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppName"="PSHD-9.9-codedownloader.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppName"="PSHD-9.9-bg.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\PSHD-9.9]
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppName"="PSHD-9.9-codedownloader.exe"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{19E6B430-8939-486D-A9B4-C81AB83A54B0}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{204114BF-9D1E-4F5C-95A2-5D7FC75C5553}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{225A1E1C-39C6-4FEA-807B-65C050E34218}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2522F635-E0DA-40E7-80E0-1957BDFF1224}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{28E606E4-13F1-45BF-80DA-AE5153B162AD}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2937F19F-FBEA-46E1-A843-3194414595}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{295B128F-80B8-4C89-A9E2-419A42803738}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2B5C22CF-8368-4D4F-8CA9-E17917EC9EF}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{34C62A0B-9CE6-4130-8361-AA4A7FE5F3}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{354CFB61-739B-4CCD-9D14-23224A32A4AE}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3AD62C28-6327-47C0-BB18-974F2A5BD248}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{41536BE9-239A-4B2D-A82C-88DB5AA6C192}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{43773D51-CA30-48E7-A36-4F322D8DBEA}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{460211B7-E7FA-430C-8C33-1698A338DF50}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56ABEB18-6BD3-496D-96E9-7938C3BB3D6B}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56CE1A96-624-42A0-9BEC-144E78DB565F}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{57D55C1E-BEDE-4058-992B-9B6543F1BE7}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E5132D9-76B3-4080-91A9-59D1AD1E7448}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61FD3EAB-F4A7-4B49-A44E-84CA4BC2DA8}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6278C536-F890-4B7E-A242-19F4CCA9D9C9}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{645607EE-466D-40C4-901A-B65848C4EFD5}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65D2E6F9-1396-4430-93EC-9BFF6107156}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6A200C98-6B0A-4715-ADDD-3E241B5E201D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6BAAA66-D001-4031-8358-16BFBCDA154}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E4D2BE9-46C2-424E-B00-96E2CFB71D49}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6F3CBD17-1AD5-4CE7-B721-E2376EBCE732}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{718E603-1AAC-40E9-8915-24E69CC6778E}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{720A7F6C-4CB0-4225-AE1E-D4FC62BE3355}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{75AA3E2D-E831-4A39-8F68-33133DE982C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78020622-6B73-4B60-816C-85CBDE4232A}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7840DA43-E56D-47D9-96D3-C37DB97F2E2B}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79C744DB-1C9B-4DBC-B3BD-E8A5A5C8BEE5}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F516459-6056-4106-A3E2-6715AE811D65}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{924E1C60-F131-4EED-8FD2-247BBC4568D8}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppName"="PSHD-9.9-bg.exe"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93500650-CFBE-4ECE-AC59-7138B4EC79E6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{950588AC-4F98-4479-89A4-7813AF1D477D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95CCA599-BDB3-4909-AAAD-372958F767A}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CBE1CD3-99B-4E61-BE25-A7111D511A6D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9EB3D095-A184-44BE-8B28-47582431D2B}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9F8CE472-726E-4126-B3A7-8E1932E3183}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2BFADEF-2DD0-45B2-9C33-C5311158FF9}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4384461-4B10-4BD8-B6CC-CCE6DF618E6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5039154-BAB-4409-9AA8-B45E6981EA11}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A88AC80E-1AD4-4C4E-90D9-2F76678F1DF}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A984BA40-EB90-455E-A61A-5C865AC25E7D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC476297-55E3-43EF-8DE2-B3EB1E41D02}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF4CAA4C-4EE1-4C8C-A784-16CACE8494F6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B3406F8A-99CD-48E9-B82A-A22B44565E0}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B787AF2A-EB75-402D-8E66-C0A33BABD89F}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BA89C16-B97D-4DD8-8B24-D47F167712B2}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C1609283-FD8A-4317-B9DE-4ECC199E24F}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C2ED9D17-6923-4087-99B3-C7D261D99E71}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3FC765B-13EE-4B5E-B540-E3A472461532}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C576D330-6FE0-4695-9778-D04A32E35C3D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C80C0F4-D216-4B33-A058-604AD982A773}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D099CE66-920D-4D91-8BAB-ED3C3D3342E6}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D249689B-4959-496F-B97C-4E59F88688C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6BAF6EC-C708-4C00-A9A4-90F23BAC8AFB}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB3DC33D-829D-404E-81F6-05C99BED2D2}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD22B052-D0F2-4C8F-87F4-3C1E52D82CB}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD282AA7-652B-41CB-91A1-57F0A1477865}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE94E69-980A-4CC4-B8A-F2738BA2AE4C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E58E90C6-ED93-4E5E-95F-B82224899C}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7808D13-3A9D-4531-B3A4-C57D5C889773}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E84EB0FA-DDEF-47D3-8AB4-1EB8804ED159}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EA1E5BDE-F92B-46B7-8683-2E192D126CA}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC1B7EA3-73C0-4C83-A944-2BE27ADC0DB}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEFD29F8-7061-4EDC-A723-5D302AADFD4A}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EF4840EB-E2A7-4F36-B635-5361678D4A4}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFBF6720-F576-4C15-A829-83B9E4E66199}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA150BE7-B443-434A-9184-C8497414A257}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FB009888-631A-4BD0-BBBF-B73AA1E42C5D}]
"AppPath"="C:\Program Files (x86)\PSHD-9.9"
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\PSHD-9.9]
[HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\PSHD-9.9]
[HKEY_USERS\S-1-5-18\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\PSHD-9.9]

-= EOF =-
         

Alt 10.06.2014, 13:37   #29
M-K-D-B
/// TB-Ausbilder
 
Sicheres Löschen von "PSHD-9.9" - Standard

Sicheres Löschen von "PSHD-9.9"



Gut, fehlen nur noch 2 Schritte.

Alt 10.06.2014, 13:57   #30
Goodfell
 
Sicheres Löschen von "PSHD-9.9" - Standard

Sicheres Löschen von "PSHD-9.9"



Ja bin gerade dabei, ESET läuft.
Miniaturansicht angehängter Grafiken
-screen.jpg  

Antwort

Themen zu Sicheres Löschen von "PSHD-9.9"
dont.steal.our.software, js/toolbar.crossrider.b, pup.optional.babylon.a, pup.optional.bprotector.a, pup.optional.ciuvo.a, pup.optional.crossrider.a, pup.optional.outbrowse, pup.optional.plushd.a, pup.optional.pricepeep.a, pup.optional.ravingreyven.a, pup.optional.searchcertifiedtb.a, pup.optional.selectngo.a, pup.optional.smartbar, pup.optional.snapdo, pup.optional.snapdo.a, riskware.tool.hck, trojan.agent.ck, trojan.agent.pecb, win32/browsefox.c, win32/browsefox.f, win32/toolbar.babylon.y, win32/toolbar.escort.a, win32/toolbar.montiera.a, win32/toolbar.montiera.b, win32/toolbar.montiera.f




Ähnliche Themen: Sicheres Löschen von "PSHD-9.9"


  1. Diverse Malware ("CoolSaleCoupon", "ddownlloaditkeep", "omiga-plus", "SaveSense", "SaleItCoupon"); lahmer PC & viel Werbung!
    Plagegeister aller Art und deren Bekämpfung - 11.01.2015 (16)
  2. Wie deinstalliere ich "PSHD-9.9"?
    Plagegeister aller Art und deren Bekämpfung - 03.06.2014 (11)
  3. Windows7: Datei "dwm.exe" im Ordner "iswizard05" lässt sich nicht löschen
    Log-Analyse und Auswertung - 20.02.2014 (19)
  4. "monstermarketplace.com" Infektion und ihre Folgen; "Anti-Virus-Blocker"," unsichtbare Toolbars" + "Browser-Hijacker" von selbst installiert
    Log-Analyse und Auswertung - 16.11.2013 (21)
  5. "Antiviren Werbung" "Langsamer PC" "PC stürzt ab" Banner und Popups beim surfen
    Plagegeister aller Art und deren Bekämpfung - 05.11.2013 (28)
  6. "Deutsche Post(eMail-Anhang)" Alle "EXE(Programme)" werden blockiert "WIN 7 Defender"
    Plagegeister aller Art und deren Bekämpfung - 27.12.2012 (3)
  7. "The document has moved. Redirecting"+"Popup unten rechts"+"Nicht alle Links anklickbar"
    Plagegeister aller Art und deren Bekämpfung - 24.10.2012 (38)
  8. Malwarereinigung: "TR/Kazy.25747.40", "Trojan.Downloader..." und "Backdoor: Win32Cycbot.B"
    Log-Analyse und Auswertung - 09.06.2011 (1)
  9. Öffentliches Netzwerk: Opera sendet/empfängt Daten an/von "Dani-PC", "Anne-PC", "PAULA-HP"...
    Netzwerk und Hardware - 02.05.2011 (14)
  10. Mein kleiner Artikel über ein "sicheres System"
    Diskussionsforum - 25.04.2011 (1)
  11. Netzwerk: Opera sendet/empfängt Daten an/von "Dani-PC", "Anne-PC", "PAULA-HP"...
    Alles rund um Windows - 16.04.2011 (0)
  12. "SuperantiSpyware" erkennt "Adware.tracking cookie" kann aber das nicht löschen
    Plagegeister aller Art und deren Bekämpfung - 20.12.2010 (21)
  13. "Adware.Virtumonde"/"Downloader.MisleadApp"/"TR/VB.agt.4"/"NewDotNet.A.1350"/"Fakerec
    Plagegeister aller Art und deren Bekämpfung - 22.08.2008 (6)
  14. "error cleaner" "privacy protector" "spyware&malware protection"
    Plagegeister aller Art und deren Bekämpfung - 28.06.2008 (7)
  15. Beheben des Problems "kein Internet"/"rsvp32_2.dll"/"Can't load library from memory"
    Plagegeister aller Art und deren Bekämpfung - 25.03.2007 (22)
  16. ">"">><meta http-equiv="Refresh" content="0;url=http://askimizsonsuza.com/code/">"">
    Plagegeister aller Art und deren Bekämpfung - 04.09.2006 (4)
  17. Symantec´s "sicheres" Aktive X Control *g*
    Plagegeister aller Art und deren Bekämpfung - 23.06.2003 (0)

Zum Thema Sicheres Löschen von "PSHD-9.9" - Ohje, jetzt verunsicherst du mich ob ich alles richtig gemacht habe ich lad dir mal ein screenshot hoch, wundert mich nämlich das da steht keine aktion durch den benutzer. Soll - Sicheres Löschen von "PSHD-9.9"...
Archiv
Du betrachtest: Sicheres Löschen von "PSHD-9.9" auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.