|
Log-Analyse und Auswertung: Sicheres Löschen von "PSHD-9.9"Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
10.06.2014, 11:35 | #16 |
| Sicheres Löschen von "PSHD-9.9" Ohje, jetzt verunsicherst du mich ob ich alles richtig gemacht habe ich lad dir mal ein screenshot hoch, wundert mich nämlich das da steht keine aktion durch den benutzer. Soll ich mbam lieber nochmal drüber laufen lassen ? Code:
ATTFilter Zoek.exe v5.0.0.0 Updated 02-June-2014 Tool run by Sven on 10.06.2014 at 12:01:03,82. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Sven\Downloads\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 10.06.2014 12:05:19 Zoek.exe System Restore Point Created Succesfully. ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{ceefadbd-a0ce-4422-a760-3b9167344e06} deleted successfully HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{ceefadbd-a0ce-4422-a760-3b9167344e06} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{ceefadbd-a0ce-4422-a760-3b9167344e06} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ceefadbd-a0ce-4422-a760-3b9167344e06} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{ceefadbd-a0ce-4422-a760-3b9167344e06} deleted successfully ==== Deleting Services ====================== ==== FireFox Fix ====================== Deleted from C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\op2zog0l.default\prefs.js: Added to C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\op2zog0l.default\prefs.js: user_pref("browser.startup.homepage", "hxxp://www.google.com"); user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.newtab.url", "hxxp://www.google.com/"); user_pref("browser.search.defaultengine", "Google"); user_pref("browser.search.defaultenginename", "Google"); user_pref("browser.search.selectedEngine", "Google"); user_pref("browser.search.order.1", "Google"); user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.search.suggest.enabled", true); user_pref("browser.search.useDBForOrder", true); Deleted from C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\prefs.js: user_pref("browser.search.suggest.enabled", false); user_pref("browser.search.useDBForOrder", false); Added to C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\prefs.js: user_pref("browser.startup.homepage", "hxxp://www.google.com"); user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.newtab.url", "hxxp://www.google.com/"); user_pref("browser.search.defaultengine", "Google"); user_pref("browser.search.defaultenginename", "Google"); user_pref("browser.search.selectedEngine", "Google"); user_pref("browser.search.order.1", "Google"); user_pref("keyword.URL", "hxxp://www.google.com/search?btnG=Google+Search&q="); user_pref("browser.search.suggest.enabled", true); user_pref("browser.search.useDBForOrder", true); ProfilePath: C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\op2zog0l.default user.js not found ---- FireFox user.js and prefs.js backups ---- prefs__1222_.backup ProfilePath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default user.js not found ---- Lines aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916 removed from prefs.js ---- user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.active", true); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.addressbar", "NA"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.addressbarenhanced", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncdb.was_copied", "true"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncdb_dbWasSet", true); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncdb_dbWasSet_FF25_FIX", true); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncinternaldb.was_copied", "true"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncinternaldb_dbWasSet", true); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.asyncinternaldb_dbWasSet_FF25_FIX", true); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.backgroundver", 2); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.certdomaininstaller", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.changeprevious", false); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.InstallationTime.expiration", "Fri Feb 01 user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.InstallationTime.value", "%221401873642%2 user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.InstallerParams.expiration", "Fri Feb 01 user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.cookie.InstallerParams.value", "%7B%22source_id% user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.description", "Turn YouTube videos to High Defin user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.domain", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.enablesearch", false); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.homepage", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.iframe", false); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.InstallationThankYouPage", true); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.InstallationTime", 1401873642); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.__defualt_browser__.expiration", "Fri user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.__defualt_browser__.value", "%22ch%22 user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb._installer_additional_info.expiration user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb._installer_additional_info.value", "% user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.installer.expiration", "Fri Feb 01 20 user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.installer.value", "%7B%22InstallerIde user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerIdentifiers.expiration", "Fr user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerIdentifiers.value", "%7B%22i user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerParams.expiration", "Fri Feb user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerParams.value", "%7B%22source user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerParamsCache.expiration", "Fr user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerParamsCache.value", "%7B%22s user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerUserIdentifiersCache.expirat user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.InstallerUserIdentifiersCache.value", user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_bundledUrls.expir user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_bundledWithHash.e user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_bundledWithHash.v user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_notBundledArr_.ex user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.monetization_plugin_notBundledArr_.va user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_remote_resources.expiration user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.internaldb.Resources_remote_resources.value", "% user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.lastDailyReport", "1401930857390"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.lastUpdate", "1401930836376"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.manifesturl", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.name", "PSHD-9.9"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.newtab", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.opensearch", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.pluginsurl", "hxxp://js.datademoserv.com/plugin/ user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.pluginsversion", 45); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.publisher", "PlusVHD"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.searchstatus", 0); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.setnewtab", false); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.thankyou", ""); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.updateinterval", 360); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.52916.ver", 52); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.apps", "52916"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.bic", "1466996dea30ea4dd107112a5d7842b3"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.cid", 52916); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.firstrun", false); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.hadappinstalled", true); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.installationdate", 1401930834); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.modetype", "production"); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.reportInstall", true); user_pref("extensions.aa54e453c130a47699333c5ec2aa914c59bd7cc899c7c44e9a03b042b92d363f0com52916.statsDailyCounter", 1); ---- FireFox user.js and prefs.js backups ---- prefs__1222_.backup ==== Deleting Files \ Folders ====================== C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted C:\found.000 deleted C:\found.001 deleted C:\found.002 deleted C:\Users\Sven\AppData\Roaming\GetRightToGo deleted C:\PROGRA~3\ICQ deleted C:\PROGRA~3\InstallMate deleted C:\PROGRA~3\Package Cache deleted C:\Users\Gast\AppData\Local\avgchrome deleted C:\Users\Sven\AppData\Local\avgchrome deleted C:\Users\Gast\AppData\LocalLow\store-pp.jbs deleted C:\Users\Sven\AppData\LocalLow\store-pp.jbs deleted C:\Windows\Launcher.exe deleted C:\Windows\Syswow64\tmp561E.tmp deleted C:\Windows\Syswow64\tmp564E.tmp deleted C:\Windows\Syswow64\tmp86CF.tmp deleted C:\Windows\Syswow64\tmp878B.tmp deleted C:\Windows\Syswow64\tmpDC75.tmp deleted C:\Windows\Syswow64\tmpDCE3.tmp deleted C:\Windows\SysWow64\searchplugins deleted C:\Windows\SysWow64\Extensions deleted C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\extensions\firefox@ravingreyven.mobi.xpi deleted C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\foxydeal.sqlite deleted C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\CT2269050 deleted C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\CT2431245 deleted C:\Users\Sven\Desktop\Datein\pkm\SoftonicDownloader_fuer_visualboyadvance.exe deleted ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [05.06.2014 06:15] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "{B64D9B05-48E1-4CEB-BF58-E0643994E900}"="C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff" [18.05.2014 11:29] ==== Firefox Extensions ====================== ProfilePath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default - ProxTube - Gesperrte YouTube Videos entsperren - %ProfilePath%\extensions\ich@maltegoetz.de - Protegere - %ProfilePath%\extensions\security@protegere.org - OutBrowse Toolbar - %ProfilePath%\extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc} - TrashMail.net - %ProfilePath%\extensions\spam@trashmail.net.xpi - FoxBox - %ProfilePath%\extensions\{df4e4df5-5cb7-46b0-9aef-6c784c3249f8}.xpi - User Agent Switcher - %ProfilePath%\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ==== Firefox Plugins ====================== Profilepath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default A58DE0A570148AF5FF3512B2A340D09F - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll - Shockwave Flash FF0D6F82A0EC13952E83B9439100E45D - C:\Users\Sven\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin 2BF85B6162528E0635DD8D632EB975C8 - C:\Users\Sven\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll - Facebook Desktop 546A28FBC44B984FD92530227BF6F5C2 - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll - Shockwave for Director / Shockwave for Director 905FD4EF56FCFD83D51FFA15E3FCE51E - C:\Users\Sven\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll - Move Media Player 7 ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions daanglpcpkjjlkhcbladppjphglbigam - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[05.06.2014 06:14] ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://www.google.com" "Search Page"="hxxp://www.google.com" "Start Default_Page_URL"="hxxp://www.google.com" "Default_Search_URL"="hxxp://www.google.com" "Search Bar"="hxxp://www.google.com" "ICQ Search"="hxxp://www.google.com" "Use Search Asst"="yes" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876" "Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876" "Default_Search_URL"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=" "Search Bar"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=" "Search Page"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Main] "Start Page"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876" "Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876" "Default_Search_URL"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=" "Search Bar"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=" "Search Page"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://www.google.com" "Search Page"="hxxp://www.google.com" "Start Default_Page_URL"="hxxp://www.google.com" "Search Bar"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://www.google.com" "Search Page"="hxxp://www.google.com" "Start Default_Page_URL"="hxxp://www.google.com" "Search Bar"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://www.google.com" "Default"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://www.google.com" "Default"="hxxp://www.google.com" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.certified-toolbar.com?si=42102&bs=true&tid=2876&q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://www.google.com" "Default"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search] "Start Page"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876" "Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876" "Default_Search_URL"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=" "Search Bar"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=" "Search Page"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Search] "Start Page"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876" "Start Default_Page_URL"="hxxp://search.certified-toolbar.com?si=42102&home=true&tid=2876" "Default_Search_URL"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=" "Search Bar"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=" "Search Page"="hxxp://search.certified-toolbar.com?si=42102&tid=2876&bs=true&q=" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search] "Start Page"="hxxp://www.google.com" "Start Default_Page_URL"="hxxp://www.google.com" "Default_Search_URL"="hxxp://www.google.com" "Search Bar"="hxxp://www.google.com" "Search Page"="hxxp://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search] "Start Page"="hxxp://www.google.com" "Start Default_Page_URL"="hxxp://www.google.com" "Default_Search_URL"="hxxp://www.google.com" "Search Bar"="hxxp://www.google.com" "Search Page"="hxxp://www.google.com" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Start Page"="hxxp://www.google.com" "Start Default_Page_URL"="hxxp://www.google.com" "Default_Search_URL"="hxxp://www.google.com" "Search Bar"="hxxp://www.google.com" "Search Page"="hxxp://www.google.com" "SearchAssistant"="hxxp://www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] No DefaultScope Set For HKCU New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "ICQ Search"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Page"="hxxp://www.google.com" "Use Search Asst"="no" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURI] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl] "(Default)"="hxxp://search.msn.com/results.asp?q=%s" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search] "Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Bar"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896" "SearchAssistant"="hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm" "Start Page"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" "Start Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC" {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}" ==== Reset Google Chrome ====================== C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully ==== Reset IE Proxy ====================== Value(s) before fix: "ProxyServer"="http=;ftp=;https=;" "ProxyEnable"=dword:00000000 Value(s) after fix: "ProxyEnable"=dword:00000000 ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DF1ECEF5-E5DC-7381-F153-A1348E310A5B} deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeCall deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware deleted successfully HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlusLiveUninstall deleted successfully ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\Gast\AppData\Local\Temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Sven\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\Gast\AppData\Local\Mozilla\Firefox\Profiles\op2zog0l.default\Cache emptied successfully C:\Users\Sven\AppData\Local\Mozilla\Firefox\Profiles\p4ytj1qg.default\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache Emptied Successfully ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== C:\zoek_backup (files=296 folders=71 77935732 bytes) ==== Empty Temp Folders ====================== C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Users\Gast\AppData\Local\Temp emptied successfully C:\Users\Sven\AppData\Local\Temp will be emptied at reboot C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\Sven\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on 10.06.2014 at 12:30:43,39 ====================== |
10.06.2014, 11:37 | #17 |
/// TB-Ausbilder | Sicheres Löschen von "PSHD-9.9" Ja bitte... dauert ja nur ein paar Minuten.
__________________Am besten währenddessen nichts am Rechner machen. |
10.06.2014, 11:59 | #18 |
| Sicheres Löschen von "PSHD-9.9"Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 10.06.2014 Suchlauf-Zeit: 12:38:50 Logdatei: MBAM 2.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.06.10.02 Rootkit Datenbank: v2014.06.02.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Sven Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 383357 Verstrichene Zeit: 12 Min, 35 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Warnen PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 12 PUP.Optional.OutBrowse, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{CEEFADBD-A0CE-4422-A760-3B9167344E06}, In Quarantäne, [5c6e0e685823ef473a62a797c939f50b], PUP.Optional.OutBrowse, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{CEEFADBD-A0CE-4422-A760-3B9167344E06}, In Quarantäne, [5c6e0e685823ef473a62a797c939f50b], PUP.Optional.PricePeep.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}, In Quarantäne, [07c3a1d5c4b71521e88fc7aa07fbb848], PUP.Optional.PricePeep.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FD6D90C0-E6EE-4BC6-B9F7-9ED319698007}, In Quarantäne, [07c3a1d5c4b71521e88fc7aa07fbb848], PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\PSHD-9.9, In Quarantäne, [1fab7105097275c1e2046e3518ea24dc], PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PSHD-9.9, In Quarantäne, [4288373f3f3c2c0a25bfc5de3ac8916f], PUP.Optional.OutBrowse, HKU\S-1-5-21-1098949856-1301053314-1890294551-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Outbrowsetoolbar, In Quarantäne, [d1f9e591205bc076c3677969a063dc24], PUP.Optional.PlusHD.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PSHD-9.9, In Quarantäne, [8743e690bbc07abcde06d6cd33cfd927], PUP.Optional.PricePeep.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PricePeep, In Quarantäne, [48820b6b8af1c86e94abd9e561a1e31d], PUP.Optional.Babylon.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, In Quarantäne, [16b47ff74f2ceb4bb27f0bc745be1fe1], PUP.Optional.BProtector.A, HKU\S-1-5-21-1098949856-1301053314-1890294551-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\BPROTECTSETTINGS, In Quarantäne, [2b9fb8be4a3184b251326272e91a4ab6], PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PSHD-9.9, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 6 PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh0HHLt9EvHpdsBSNIcEGIjdmo8CMRkTrkziZb8t8ApvoxKHNUP2bzDfHfGP57oCmfu, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh0HHLt9EvHpdsBSNIcEGIjdmo8CMRkTrkziZb8t8ApvoxKHNUP2bzDfHfGP57oCmfu),Ersetzt,[676385f12b503afc0fb1b3bc7c88f808] PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Ersetzt,[c00aa1d5314a181e8f2ffb740df7827e] PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Ersetzt,[ebdfd1a55c1f90a61aa579f6ba4a48b8] PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Ersetzt,[9139fa7c0c6f1a1cc9f8df908f757f81] PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Ersetzt,[af1b4630cbb064d200c2aec155afa957] PUP.Optional.SnapDo.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtbwnztdp5nXPZvpzCX4E2FcmauFZv-hjtt6EuXWPQ6bNIAL1jNtGcHHJJE6s07KRRX2Jcu_7ZNWVJWV0sjSh4lJuywJmF6S0DNScJPJDnoiorRgNegpDPaio-iqvxrZ1ZxkKNJjJqP48t1-GYrQzm&q={searchTerms}),Ersetzt,[4a807ff7304bb97ddc7e8bdb976d9b65] Ordner: 4 PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaipilfmheplbcghignccoiiebekkdhe, In Quarantäne, [b9113b3b8af113232d795338a55d8878], PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0, In Quarantäne, [18b26610d8a383b36d663d4fc63ce917], PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], Dateien: 34 PUP.Optional.SnapDo.A, C:\Windows\Installer\17f2707.msi, In Quarantäne, [5b6f9dd93348b18509de483dfc05a65a], PUP.Optional.SmartBar, C:\Windows\Installer\MSI6E5.tmp, In Quarantäne, [7e4c1a5cef8cda5c77a58ea0b64a4cb4], PUP.Optional.SmartBar, C:\Windows\Installer\MSI999F.tmp-\Smartbar.Installer.CustomActions.dll, In Quarantäne, [5377d0a67ffc0333b16b35f957a9a25e], PUP.Optional.SmartBar, C:\Windows\Installer\MSI6E5.tmp-\Smartbar.Installer.CustomActions.dll, In Quarantäne, [14b6b6c08af1181eda4288a6b44cdf21], PUP.Optional.Ciuvo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage, In Quarantäne, [7654096d304bba7c8f483664936fbf41], PUP.Optional.Ciuvo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage-journal, In Quarantäne, [0dbd2056077463d34e8993071be7df21], PUP.Optional.SelectNGo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage, In Quarantäne, [ecdee096097270c669609e00c2403cc4], PUP.Optional.SelectNGo.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage-journal, In Quarantäne, [1baf591d6e0d2e0824a5c3db8c76b749], PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0.localstorage, In Quarantäne, [56740a6c156623137b893b72e022ad53], PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0.localstorage-journal, In Quarantäne, [d7f3284ec1baec4a669ebcf18979956b], PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000005.ldb, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000013.ldb, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000016.ldb, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\000020.log, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\CURRENT, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\LOCK, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\LOG, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\LOG.old, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aaipilfmheplbcghignccoiiebekkdhe\MANIFEST-000018, In Quarantäne, [5b6fbabcec8f989e448ee7a5ed157789], PUP.Optional.CrossRider.A, C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_aaipilfmheplbcghignccoiiebekkdhe_0\3, In Quarantäne, [18b26610d8a383b36d663d4fc63ce917], PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bho64.dll, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\1293297481.mxaddon, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\360-52916.crx, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\41220790-4b35-4753-91f3-94289344bd48-3.exe, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\52916.crx, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\52916.xpi, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\background.html, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\bgNova.html, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bg.exe, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bho.dll, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-nova.dll, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9.ico, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\Uninstall.exe, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\utils.exe, In Quarantäne, [f4d645314f2c3ff70d4a840f4ab88f71], Physische Sektoren: 0 (No malicious items detected) (end) |
10.06.2014, 12:00 | #19 |
/// TB-Ausbilder | Sicheres Löschen von "PSHD-9.9" Gut gemacht. Jetzt weiter mit Zoek bitte. |
10.06.2014, 12:00 | #20 |
| Sicheres Löschen von "PSHD-9.9" FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-06-2014 01 Ran by Sven (administrator) on SVEN-PC on 10-06-2014 12:56:42 Running from C:\Users\Sven\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (NVIDIA) C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Winstep Software Technologies) C:\Program Files (x86)\Winstep\WsxService.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Dropbox, Inc.) C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe () C:\Program Files (x86)\Opera\22.0.1471.50\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe (Opera Software) C:\Program Files (x86)\Opera\22.0.1471.50\opera.exe ==================== Registry (Whitelisted) ================== HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2245120 2009-07-15] (VIA) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [NextSTART] => [X] HKLM-x32\...\Run: [Workshelf] => [X] HKLM-x32\...\Run: [G Data AntiVirus Tray Application] => C:\Program Files (x86)\G Data\TotalProtection\AVKTray\AVKTray.exe HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G Data\TotalProtection\Firewall\GDFirewallTray.exe HKLM-x32\...\Run: [NPSStartup] => [X] HKLM-x32\...\Run: [avgnt] => "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3859320 2014-06-05] (AVAST Software) HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Pando Media Booster] => C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [2937528 2010-05-02] () HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Upgrade] => C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F}\Upgrade.exe HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [NVIDIA nTune] => C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe [98304 2007-09-04] (NVIDIA) HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Auto KTR] => C:\Users\Sven\Downloads\Dm.De.M.C.Co.Edit-PROP\Kaspersky Internet Security 2014 + Trial + Kaspersky World\Kaspersky_Internet_Security_Trial_Reset_2.1_by_Humschi_1857\KIS14 TrialReset.exe -silent HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\MountPoints2: {732ced11-838c-11df-934f-002618bca0f6} - E:\raf-skyrim.exe HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\MountPoints2: {c6647fc0-dbee-11e1-b1d5-806e6f6e6963} - E:\setup.exe Startup: C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Sven\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x27BB72947FE9CA01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP80B4BA23-BA51-47B6-A18B-B617C84C81FE&q={searchTerms}&SSPV= SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: HKLM-x32 {C3F79A2B-B9B4-4A66-B012-3EE46475B072} hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default FF NewTab: hxxp://www.google.com/ FF DefaultSearchEngine: Google FF SearchEngineOrder.1: Google FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.com FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q= FF NetworkProxy: "autoconfig_url", "64.85.181.46" FF NetworkProxy: "http", "64.85.181.46" FF NetworkProxy: "http_port", 8080 FF NetworkProxy: "type", 1 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.) FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB) FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @movenetworks.com/Quantum Media Player - C:\Users\Sven\AppData\Roaming\Move Networks\plugins\071802000001\npqmp071802000001.dll (Move Networks) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Sven\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: facebook.com/fbDesktopPlugin - C:\Users\Sven\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPandoWebInst.dll (Pando Networks) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: ProxTube - Unblock YouTube - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\ich@maltegoetz.de [2014-05-20] FF Extension: Protegere - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\security@protegere.org [2014-06-05] FF Extension: OutBrowse Toolbar - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc} [2013-04-17] FF Extension: TrashMail.net - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\spam@trashmail.net.xpi [2011-10-11] FF Extension: Fox!Box - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{df4e4df5-5cb7-46b0-9aef-6c784c3249f8}.xpi [2011-04-03] FF Extension: User Agent Switcher - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2011-12-25] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-06-05] FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ [] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (Google Drive) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-05] CHR Extension: (YouTube) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-05] CHR Extension: (Google Search) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-05] CHR Extension: (Google Wallet) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-05] CHR Extension: (Gmail) - C:\Users\Sven\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-05] CHR HKLM-x32\...\Chrome\Extension: [daanglpcpkjjlkhcbladppjphglbigam] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-06-05] ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-06-05] (AVAST Software) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-10-01] () [File not signed] S4 DlProtectSvc; C:\Windows\System32\DlProtectSvc.exe [123392 2014-06-04] () [File not signed] R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation) S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3772784 2010-05-10] (INCA Internet Co., Ltd.) [File not signed] R2 nTuneService; C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe [180224 2007-09-04] (NVIDIA) [File not signed] R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-12] () S2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [97552 2012-03-22] (SANDBOXIE L.T.D) S3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [430592 2008-04-07] (Nokia.) [File not signed] S3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [821720 2012-08-21] (Mister Group) S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [738152 2012-07-19] (Tunngle.net GmbH) [File not signed] S2 KMService; C:\Windows\system32\srvany.exe [X] R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X] ==================== Drivers (Whitelisted) ==================== R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-06-05] () R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-06-05] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-06-05] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-06-05] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-06-05] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-06-05] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-06-05] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [84816 2014-06-05] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-06-05] () R2 DRHARD64; C:\Windows\system32\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software) R2 DRHARD64; C:\Windows\SysWOW64\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software) R2 DRHMSR64; C:\Windows\system32\drivers\DRHMSR64.sys [14760 2011-12-06] () R2 DRHMSR64; C:\Windows\SysWOW64\drivers\DRHMSR64.sys [14760 2011-12-06] () R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [65912 2012-03-08] (G Data Software AG) R3 KMWDFILTERV1; C:\Windows\System32\DRIVERS\RPGMOUSEV1.sys [24576 2009-06-10] (Windows (R) Codename Longhorn DDK provider) R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] () S3 nocashio; C:\Windows\SysWOW64\drivers\nocashio.sys [4096 2010-08-18] () [File not signed] S3 NPPTNT2; C:\Windows\SysWOW64\npptNT2.sys [4682 2005-01-04] (INCA Internet Co., Ltd.) [File not signed] R3 NVR0Dev; C:\Windows\nvoclk64.sys [39968 2007-09-04] (NVidia Corp.) S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [13368 2013-01-23] () S3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [155136 2012-05-08] (SANDBOXIE L.T.D) [File not signed] R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-10-10] (Duplex Secure Ltd.) S3 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2007-10-25] () [File not signed] R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net) [File not signed] R2 WinRing0_1_2_0; C:\Users\Sven\AppData\Local\Microsoft\Windows Sidebar\Gadgets\IntelCoreSeries24.gadget\WinRing0x64.sys [14544 2010-05-02] (OpenLibSys.org) R3 wod0205; C:\Windows\System32\DRIVERS\wod0205.sys [33160 2011-04-23] (WeOnlyDo Software) U3 ar90ehyq; C:\Windows\System32\Drivers\ar90ehyq.sys [0 ] (Advanced Micro Devices) S3 DRHARD; \??\C:\Windows\system32\DRIVERS\DRHARD.SYS [X] S3 dump_wmimmc; \??\C:\Program Files (x86)\Gameforge4D\CABAL Online\GameGuard\dump_wmimmc.sys [X] S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X] S3 X6va003; \??\C:\Users\Sven\AppData\Local\Temp\0035BEA.tmp [X] S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X] S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-10 12:55 - 2014-06-10 12:55 - 00014016 _____ () C:\Users\Sven\Desktop\MBAM 2.txt 2014-06-10 12:29 - 2014-06-10 12:58 - 00000000 ____D () C:\Users\Sven\AppData\Local\Temp 2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Temp 2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Gast\AppData\Local\Temp 2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default\AppData\Local\Temp 2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default User\AppData\Local\Temp 2014-06-10 12:29 - 2014-06-10 12:00 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-06-10 12:23 - 2014-06-10 12:23 - 00017954 _____ () C:\Users\Sven\Desktop\MMBAM TEXT.txt 2014-06-10 12:04 - 2014-06-10 12:30 - 00032826 _____ () C:\zoek-results.log 2014-06-10 12:04 - 2014-06-10 12:04 - 00003180 _____ () C:\Windows\System32\Tasks\{7D573011-FC61-42C2-A61F-1E0B7044A895} 2014-06-10 12:03 - 2014-05-21 08:31 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.scr 2014-06-10 12:03 - 2014-05-21 08:31 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.com 2014-06-10 12:02 - 2014-06-10 12:02 - 04235784 _____ () C:\Users\Sven\Downloads\zoek.rar 2014-06-10 12:00 - 2014-06-10 12:22 - 00000000 ____D () C:\zoek_backup 2014-06-10 11:58 - 2014-06-10 11:58 - 00000886 _____ () C:\Users\Sven\Desktop\mbam.txt 2014-06-10 11:56 - 2014-06-10 11:56 - 00000652 _____ () C:\Users\Sven\Desktop\MAAABM.txt 2014-06-10 11:49 - 2014-06-10 11:49 - 00016076 _____ () C:\Users\Sven\Desktop\teeext.txt 2014-06-10 11:35 - 2014-06-10 11:36 - 04094386 _____ () C:\Users\Sven\Downloads\zoek.zip 2014-06-10 11:35 - 2014-06-10 11:35 - 01285120 _____ () C:\Users\Sven\Downloads\zoek.exe 2014-06-10 11:28 - 2014-06-10 12:54 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-10 11:28 - 2014-06-10 11:28 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-10 11:28 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-06-10 11:28 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-06-10 11:26 - 2014-06-10 11:27 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (2).exe 2014-06-10 11:18 - 2014-06-10 11:19 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (1).exe 2014-06-10 11:07 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-06-10 11:02 - 2014-06-10 11:11 - 00000000 ____D () C:\AdwCleaner 2014-06-10 11:01 - 2014-06-10 11:01 - 01333465 _____ () C:\Users\Sven\Downloads\adwcleaner_3.212.exe 2014-06-10 01:28 - 2014-06-10 01:28 - 00000042 _____ () C:\Users\Sven\Downloads\sl.dta 2014-06-10 01:11 - 2014-06-10 02:09 - 00000000 ____D () C:\Users\Sven\Downloads\NextChaos 2014-06-10 00:01 - 2014-06-10 01:10 - 1956407488 _____ () C:\Users\Sven\Downloads\NextChaos.zip 2014-06-09 18:17 - 2014-06-09 18:22 - 149696637 _____ () C:\Users\Sven\Downloads\uiii.rar 2014-06-09 15:56 - 2014-06-09 15:56 - 00090241 _____ () C:\Users\Sven\Downloads\Addition.txt 2014-06-09 15:04 - 2014-06-10 12:57 - 00020788 _____ () C:\Users\Sven\Downloads\FRST.txt 2014-06-09 15:04 - 2014-06-10 12:56 - 00000000 ____D () C:\FRST 2014-06-09 15:03 - 2014-06-09 15:04 - 02080768 _____ (Farbar) C:\Users\Sven\Downloads\FRST64.exe 2014-06-09 15:00 - 2014-06-09 15:01 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012.exe 2014-06-09 04:51 - 2014-06-09 04:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_MijXfilt_01009.Wdf 2014-06-09 04:44 - 2014-06-09 04:44 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MotioninJoy 2014-06-09 04:43 - 2014-06-09 04:43 - 00000883 _____ () C:\Users\Public\Desktop\DS3 Tool.lnk 2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy 2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\Program Files\MotioninJoy 2014-06-09 04:43 - 2012-05-12 12:31 - 00121416 _____ (MotioninJoy) C:\Windows\system32\Drivers\MijXfilt.sys 2014-06-09 04:43 - 2011-12-07 19:42 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2014-06-09 04:43 - 2011-12-07 19:42 - 00328712 _____ (Logitech Inc.) C:\Windows\system32\MijFrc.dll 2014-06-09 04:43 - 2011-12-07 19:42 - 00074960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xusb21.sys 2014-06-09 04:39 - 2014-06-09 04:40 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed.zip 2014-06-09 04:39 - 2014-06-09 04:40 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed (1).zip 2014-06-07 05:44 - 2014-06-08 06:33 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Tropico 4 2014-06-07 05:42 - 2014-06-07 05:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tropico 4 Collectors Bundle 2014-06-07 05:38 - 2014-06-07 05:44 - 00000000 ____D () C:\Program Files (x86)\Tropico 4 Collectors Bundle 2014-06-06 01:14 - 2014-06-06 01:27 - 00000000 ____D () C:\Users\Sven\Downloads\Manuellsen-MB3 (Premium Edition) 2014-06-05 22:54 - 2014-06-10 12:03 - 00000000 ____D () C:\Users\Sven\Downloads\C&A Akup 2014-06-05 07:34 - 2014-06-05 07:34 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dvdcss 2014-06-05 06:51 - 2014-06-05 06:51 - 00000402 _____ () C:\Users\Sven\Downloads\CD-Laufwerk - Verknüpfung.lnk 2014-06-05 06:43 - 2014-06-05 06:43 - 00000000 ____D () C:\Program Files (x86)\G DATA Software 2014-06-05 06:20 - 2014-06-05 06:20 - 01180529 _____ () C:\Windows\unins000.exe 2014-06-05 06:20 - 2014-06-05 06:20 - 00001229 _____ () C:\Windows\unins000.dat 2014-06-05 06:17 - 2014-06-05 06:17 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\AVAST Software 2014-06-05 06:16 - 2014-06-10 11:51 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-06-05 06:16 - 2014-06-05 06:16 - 00001984 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-06-05 06:16 - 2014-06-05 06:16 - 00001924 _____ () C:\Users\Public\Desktop\avast! Pro Antivirus.lnk 2014-06-05 06:16 - 2014-06-05 06:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast 2014-06-05 06:16 - 2014-06-05 06:14 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-06-05 06:16 - 2014-06-05 06:14 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-06-05 06:16 - 2014-06-05 06:14 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-06-05 06:16 - 2014-06-05 06:14 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-06-05 06:16 - 2014-06-05 06:14 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2014-06-05 06:16 - 2014-06-05 06:14 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-06-05 06:16 - 2014-06-05 06:14 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-06-05 06:16 - 2014-06-05 06:14 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-06-05 06:15 - 2014-06-05 06:14 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-06-05 06:15 - 2014-06-05 06:14 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2014-06-05 06:14 - 2014-06-05 06:14 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-06-05 06:13 - 2014-06-05 06:13 - 00000000 ____D () C:\Program Files\AVAST Software 2014-06-05 06:12 - 2014-06-05 06:12 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-06-05 03:22 - 2014-06-05 03:22 - 00003836 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401931354 2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\Users\Public\Desktop\Opera.lnk 2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Opera Software 2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Local\Opera Software 2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-06-05 03:13 - 2014-06-05 03:13 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-05 02:05 - 2014-06-10 11:49 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\KW 2014-06-05 01:52 - 2014-06-05 02:06 - 00000021 _____ () C:\AKTR.timestamp 2014-06-05 01:46 - 2014-06-05 04:55 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-06-04 15:13 - 2014-06-06 01:23 - 00000000 ____D () C:\Users\Sven\Downloads\_n`y1B_X$- 2014-06-04 11:49 - 2014-06-10 12:53 - 00045793 _____ () C:\Windows\setupact.log 2014-06-04 11:49 - 2014-06-04 11:49 - 00000000 _____ () C:\Windows\setuperr.log 2014-06-04 11:48 - 2014-06-10 12:53 - 00019442 _____ () C:\Windows\PFRO.log 2014-06-04 11:22 - 2014-06-04 11:22 - 00001021 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-06-04 11:22 - 2014-06-04 11:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dlg 2014-06-04 11:21 - 2014-06-04 11:21 - 00123392 _____ () C:\Windows\system32\DlProtectSvc.exe 2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Security System 2 2014-06-03 10:13 - 2014-06-03 10:13 - 00003092 _____ () C:\Windows\System32\Tasks\{107A92FE-4711-4473-8E02-B7C9963E7371} 2014-05-30 20:17 - 2014-05-30 20:17 - 00003112 _____ () C:\Windows\System32\Tasks\{F83E546C-96CD-4EB6-8305-C82BC2EE455A} 2014-05-30 20:13 - 2014-05-30 20:13 - 00003112 _____ () C:\Windows\System32\Tasks\{11911F7C-AFE3-47ED-9FF5-A0B6F51AB520} 2014-05-29 20:03 - 2014-05-29 20:03 - 00000000 ____D () C:\ProgramData\Orbit 2014-05-29 19:43 - 2014-05-29 19:43 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (incl. 3 Bonustracks) (DE, 2014, VOiCE) 2014-05-29 19:24 - 2014-05-28 23:52 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (Premium Edition) 2014-05-29 19:13 - 2014-05-29 19:13 - 00000000 ____D () C:\Program Files\Ubisoft 2014-05-29 08:38 - 2014-05-29 19:51 - 00001205 _____ () C:\Users\Sven\Desktop\Uplay.lnk 2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft 2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Local\Ubisoft Game Launcher 2014-05-29 01:48 - 2014-06-04 22:12 - 00000000 ____D () C:\Users\Sven\Downloads\GZ-LC EP3 2014-05-24 19:23 - 2014-06-09 15:37 - 00000000 ____D () C:\Users\Sven\Downloads\Al-Gear - Wieder Mal Angeklagt (Milfhunter Edition) (2014) 1 2014-05-22 07:09 - 2014-05-22 07:10 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MAGIX 2014-05-22 07:09 - 2014-05-22 07:09 - 00001044 _____ () C:\Users\Public\Desktop\MAGIX Video Pro X6.lnk 2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\Documents\MAGIX_MusicEditor 2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Xara 2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Magix 2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Public\Documents\MAGIX 2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX 2014-05-22 07:08 - 2014-05-22 07:08 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Shared 2014-05-22 07:06 - 2014-05-22 07:10 - 00000000 ___RD () C:\Users\Sven\Documents\MAGIX 2014-05-22 07:06 - 2014-05-22 07:10 - 00000000 ____D () C:\ProgramData\MAGIX 2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\MAGIX 2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Services 2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files (x86)\MAGIX 2014-05-22 03:19 - 2014-05-22 03:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps 2014-05-22 03:11 - 2014-05-22 03:12 - 00000000 ____D () C:\Users\Sven\Documents\My CamStudio Temp Files 2014-05-22 03:10 - 2014-05-22 03:13 - 00004535 _____ () C:\Users\Sven\AppData\Roaming\CamStudio.cfg 2014-05-22 03:10 - 2014-05-22 03:13 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamShapes.ini 2014-05-22 03:10 - 2014-05-22 03:13 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamLayout.ini 2014-05-22 03:10 - 2014-05-22 03:13 - 00000124 _____ () C:\Users\Sven\AppData\Roaming\Camdata.ini 2014-05-22 03:09 - 2014-05-22 03:10 - 00000096 _____ () C:\Users\Sven\AppData\Roaming\version2.xml 2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7 2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\Program Files\CamStudio 2.7 2014-05-22 03:02 - 2014-05-22 03:21 - 00000738 _____ () C:\Users\Public\Desktop\Fraps.lnk 2014-05-20 02:04 - 2014-05-20 02:04 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log 2014-05-20 02:04 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-05-20 02:04 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-05-20 02:04 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-05-20 02:04 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-05-20 01:47 - 2014-05-20 01:47 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\InstallShield 2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\FreeHideIP 2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide IP 2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\FreeHideIP 2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Program Files (x86)\FreeHideIP 2014-05-17 02:34 - 2014-06-09 15:41 - 00000000 ____D () C:\Users\Sven\Downloads\GalaxyLC 2014-05-16 18:58 - 2014-05-27 03:58 - 00000000 ____D () C:\Users\Sven\Downloads\Vorms EP3(projet) 2014-05-15 12:42 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 12:42 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-15 12:42 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-15 12:42 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-15 12:42 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 12:42 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-14 21:46 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-14 21:45 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-14 21:45 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-14 21:45 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-14 21:45 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-14 21:45 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-14 21:45 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-14 21:45 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-14 21:45 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-14 21:45 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-14 21:45 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-14 21:45 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-14 21:45 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-14 21:45 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-14 21:45 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-14 21:45 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-14 21:45 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-14 21:45 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-14 21:45 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-14 21:45 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-14 21:45 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-14 21:45 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-14 21:45 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-14 21:45 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-14 21:45 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-14 21:45 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-14 21:45 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-14 21:45 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-14 21:45 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-14 21:45 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-14 21:45 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-14 21:45 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-14 21:45 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-14 21:45 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-14 21:45 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-14 21:45 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-14 21:45 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-14 21:45 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-14 21:45 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-14 21:45 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-14 21:45 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-14 21:45 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-14 21:45 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-14 21:45 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-14 21:45 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-05-13 21:12 - 2014-05-13 21:12 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-05-13 16:44 - 2014-05-27 02:29 - 00000000 ____D () C:\Users\Sven\Downloads\Phoenix LC EP II 2014-05-12 11:48 - 2014-05-27 02:27 - 00000000 ____D () C:\Users\Sven\Downloads\Danaria Last Chaos ==================== One Month Modified Files and Folders ======= 2014-06-10 12:58 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Sven\AppData\Local\Temp 2014-06-10 12:58 - 2010-05-02 11:53 - 00000000 ____D () C:\Users\Sven\AppData\Local\PMB Files 2014-06-10 12:57 - 2014-06-09 15:04 - 00020788 _____ () C:\Users\Sven\Downloads\FRST.txt 2014-06-10 12:57 - 2012-05-30 00:00 - 01050021 _____ () C:\Windows\WindowsUpdate.log 2014-06-10 12:56 - 2014-06-09 15:04 - 00000000 ____D () C:\FRST 2014-06-10 12:55 - 2014-06-10 12:55 - 00014016 _____ () C:\Users\Sven\Desktop\MBAM 2.txt 2014-06-10 12:54 - 2014-06-10 11:28 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-06-10 12:54 - 2014-05-07 00:52 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DropboxMaster 2014-06-10 12:54 - 2012-08-20 16:47 - 00000000 ___RD () C:\Users\Sven\Dropbox 2014-06-10 12:54 - 2012-02-27 23:38 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Dropbox 2014-06-10 12:53 - 2014-06-04 11:49 - 00045793 _____ () C:\Windows\setupact.log 2014-06-10 12:53 - 2014-06-04 11:48 - 00019442 _____ () C:\Windows\PFRO.log 2014-06-10 12:53 - 2013-04-03 00:13 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-06-10 12:53 - 2010-05-02 00:55 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-06-10 12:53 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-10 12:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Resources 2014-06-10 12:38 - 2009-07-14 06:45 - 00014608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-10 12:38 - 2009-07-14 06:45 - 00014608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-10 12:35 - 2010-08-25 16:11 - 08027136 ___SH () C:\Users\Sven\Desktop\Thumbs.db 2014-06-10 12:30 - 2014-06-10 12:04 - 00032826 _____ () C:\zoek-results.log 2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Temp 2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Gast\AppData\Local\Temp 2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default\AppData\Local\Temp 2014-06-10 12:29 - 2014-06-10 12:29 - 00000000 ____D () C:\Users\Default User\AppData\Local\Temp 2014-06-10 12:23 - 2014-06-10 12:23 - 00017954 _____ () C:\Users\Sven\Desktop\MMBAM TEXT.txt 2014-06-10 12:22 - 2014-06-10 12:00 - 00000000 ____D () C:\zoek_backup 2014-06-10 12:12 - 2012-07-12 11:08 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-10 12:04 - 2014-06-10 12:04 - 00003180 _____ () C:\Windows\System32\Tasks\{7D573011-FC61-42C2-A61F-1E0B7044A895} 2014-06-10 12:03 - 2014-06-05 22:54 - 00000000 ____D () C:\Users\Sven\Downloads\C&A Akup 2014-06-10 12:02 - 2014-06-10 12:02 - 04235784 _____ () C:\Users\Sven\Downloads\zoek.rar 2014-06-10 12:02 - 2013-04-03 00:13 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-06-10 12:00 - 2014-06-10 12:29 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-06-10 11:58 - 2014-06-10 11:58 - 00000886 _____ () C:\Users\Sven\Desktop\mbam.txt 2014-06-10 11:56 - 2014-06-10 11:56 - 00000652 _____ () C:\Users\Sven\Desktop\MAAABM.txt 2014-06-10 11:51 - 2014-06-05 06:16 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-06-10 11:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PLA 2014-06-10 11:49 - 2014-06-10 11:49 - 00016076 _____ () C:\Users\Sven\Desktop\teeext.txt 2014-06-10 11:49 - 2014-06-05 02:05 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\KW 2014-06-10 11:36 - 2014-06-10 11:35 - 04094386 _____ () C:\Users\Sven\Downloads\zoek.zip 2014-06-10 11:35 - 2014-06-10 11:35 - 01285120 _____ () C:\Users\Sven\Downloads\zoek.exe 2014-06-10 11:28 - 2014-06-10 11:28 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-06-10 11:28 - 2014-06-10 11:28 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-06-10 11:28 - 2012-03-08 00:36 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Malwarebytes 2014-06-10 11:28 - 2012-03-08 00:36 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-06-10 11:27 - 2014-06-10 11:26 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (2).exe 2014-06-10 11:19 - 2014-06-10 11:18 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012 (1).exe 2014-06-10 11:12 - 2009-07-14 06:45 - 00554864 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-06-10 11:11 - 2014-06-10 11:02 - 00000000 ____D () C:\AdwCleaner 2014-06-10 11:01 - 2014-06-10 11:01 - 01333465 _____ () C:\Users\Sven\Downloads\adwcleaner_3.212.exe 2014-06-10 10:42 - 2011-12-22 15:59 - 00001134 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001UA.job 2014-06-10 03:38 - 2013-04-12 12:21 - 00000000 ____D () C:\Users\Sven\Downloads\01AlpaGun 2014-06-10 03:36 - 2010-05-02 01:31 - 00166832 _____ () C:\Users\Sven\AppData\Local\GDIPFONTCACHEV1.DAT 2014-06-10 03:33 - 2012-06-15 00:56 - 00211968 ___SH () C:\Users\Sven\Thumbs.db 2014-06-10 02:09 - 2014-06-10 01:11 - 00000000 ____D () C:\Users\Sven\Downloads\NextChaos 2014-06-10 01:42 - 2011-12-22 15:59 - 00001112 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001Core.job 2014-06-10 01:28 - 2014-06-10 01:28 - 00000042 _____ () C:\Users\Sven\Downloads\sl.dta 2014-06-10 01:10 - 2014-06-10 00:01 - 1956407488 _____ () C:\Users\Sven\Downloads\NextChaos.zip 2014-06-09 18:26 - 2013-04-30 15:36 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2 2014-06-09 18:22 - 2014-06-09 18:17 - 149696637 _____ () C:\Users\Sven\Downloads\uiii.rar 2014-06-09 15:56 - 2014-06-09 15:56 - 00090241 _____ () C:\Users\Sven\Downloads\Addition.txt 2014-06-09 15:54 - 2010-05-26 00:11 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-06-09 15:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-06-09 15:51 - 2009-07-14 20:18 - 00000000 ____D () C:\Windows\ShellNew 2014-06-09 15:51 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild 2014-06-09 15:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\System 2014-06-09 15:49 - 2009-07-14 04:34 - 00000387 _____ () C:\Windows\win.ini 2014-06-09 15:41 - 2014-05-17 02:34 - 00000000 ____D () C:\Users\Sven\Downloads\GalaxyLC 2014-06-09 15:37 - 2014-05-24 19:23 - 00000000 ____D () C:\Users\Sven\Downloads\Al-Gear - Wieder Mal Angeklagt (Milfhunter Edition) (2014) 1 2014-06-09 15:04 - 2014-06-09 15:03 - 02080768 _____ (Farbar) C:\Users\Sven\Downloads\FRST64.exe 2014-06-09 15:01 - 2014-06-09 15:00 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sven\Downloads\mbam-setup-2.0.2.1012.exe 2014-06-09 04:51 - 2014-06-09 04:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_MijXfilt_01009.Wdf 2014-06-09 04:44 - 2014-06-09 04:44 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MotioninJoy 2014-06-09 04:43 - 2014-06-09 04:43 - 00000883 _____ () C:\Users\Public\Desktop\DS3 Tool.lnk 2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy 2014-06-09 04:43 - 2014-06-09 04:43 - 00000000 ____D () C:\Program Files\MotioninJoy 2014-06-09 04:40 - 2014-06-09 04:39 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed.zip 2014-06-09 04:40 - 2014-06-09 04:39 - 04117346 _____ () C:\Users\Sven\Downloads\MotioninJoy_071001_signed (1).zip 2014-06-09 01:35 - 2010-06-20 16:07 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Skype 2014-06-08 06:33 - 2014-06-07 05:44 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Tropico 4 2014-06-07 22:56 - 2010-05-02 00:42 - 00000000 ___RD () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-06-07 21:03 - 2010-08-01 05:36 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\vlc 2014-06-07 20:12 - 2014-06-09 18:22 - 149696502 _____ () C:\Users\Sven\Downloads\Lucy-Cat - MAGICPOINT MIT ZUNGE - geht das überhaupt 05.06.14.flv 2014-06-07 05:44 - 2014-06-07 05:38 - 00000000 ____D () C:\Program Files (x86)\Tropico 4 Collectors Bundle 2014-06-07 05:42 - 2014-06-07 05:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tropico 4 Collectors Bundle 2014-06-07 05:38 - 2010-05-23 16:08 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DAEMON Tools Lite 2014-06-06 06:32 - 2009-07-14 19:58 - 00717506 _____ () C:\Windows\system32\perfh007.dat 2014-06-06 06:32 - 2009-07-14 19:58 - 00155122 _____ () C:\Windows\system32\perfc007.dat 2014-06-06 06:32 - 2009-07-14 07:13 - 01657416 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-06-06 01:27 - 2014-06-06 01:14 - 00000000 ____D () C:\Users\Sven\Downloads\Manuellsen-MB3 (Premium Edition) 2014-06-06 01:23 - 2014-06-04 15:13 - 00000000 ____D () C:\Users\Sven\Downloads\_n`y1B_X$- 2014-06-05 23:01 - 2014-04-04 10:42 - 00000000 ____D () C:\Users\Sven\Downloads\Animus 2014-06-05 10:13 - 2012-03-07 22:30 - 00000000 ____D () C:\ProgramData\G DATA 2014-06-05 09:54 - 2012-08-20 23:32 - 00000000 ____D () C:\Users\Sven\Downloads\thc-ssl-dos 2014-06-05 07:34 - 2014-06-05 07:34 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dvdcss 2014-06-05 07:00 - 2012-10-31 02:28 - 00000000 ____D () C:\Users\Sven\Downloads\GTA 4 2014-06-05 06:56 - 2013-05-09 01:56 - 00000000 ____D () C:\Users\Sven\Downloads\DVD1 2014-06-05 06:54 - 2013-10-04 00:55 - 00000000 ____D () C:\Users\Sven\Downloads\Capo - Hallo Monaco (Fan Edition) 2014-06-05 06:53 - 2012-03-04 22:38 - 00000000 ____D () C:\Users\Sven\Downloads\Bigger.Stronger.Faster.2008.German.AC3.BRRip.Xvid-HOR 2014-06-05 06:52 - 2013-04-19 14:24 - 00000000 ____D () C:\Users\Sven\Downloads\5fu54ggrt 2014-06-05 06:51 - 2014-06-05 06:51 - 00000402 _____ () C:\Users\Sven\Downloads\CD-Laufwerk - Verknüpfung.lnk 2014-06-05 06:43 - 2014-06-05 06:43 - 00000000 ____D () C:\Program Files (x86)\G DATA Software 2014-06-05 06:43 - 2010-05-02 01:01 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-06-05 06:20 - 2014-06-05 06:20 - 01180529 _____ () C:\Windows\unins000.exe 2014-06-05 06:20 - 2014-06-05 06:20 - 00001229 _____ () C:\Windows\unins000.dat 2014-06-05 06:17 - 2014-06-05 06:17 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\AVAST Software 2014-06-05 06:16 - 2014-06-05 06:16 - 00001984 _____ () C:\Users\Public\Desktop\avast! SafeZone.lnk 2014-06-05 06:16 - 2014-06-05 06:16 - 00001924 _____ () C:\Users\Public\Desktop\avast! Pro Antivirus.lnk 2014-06-05 06:16 - 2014-06-05 06:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast 2014-06-05 06:14 - 2014-06-05 06:16 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2014-06-05 06:14 - 2014-06-05 06:16 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2014-06-05 06:14 - 2014-06-05 06:16 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-06-05 06:14 - 2014-06-05 06:16 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-06-05 06:14 - 2014-06-05 06:16 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2014-06-05 06:14 - 2014-06-05 06:16 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-06-05 06:14 - 2014-06-05 06:16 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-06-05 06:14 - 2014-06-05 06:16 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-06-05 06:14 - 2014-06-05 06:15 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-06-05 06:14 - 2014-06-05 06:15 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2014-06-05 06:14 - 2014-06-05 06:14 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-06-05 06:13 - 2014-06-05 06:13 - 00000000 ____D () C:\Program Files\AVAST Software 2014-06-05 06:12 - 2014-06-05 06:12 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-06-05 04:55 - 2014-06-05 01:46 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-06-05 03:22 - 2014-06-05 03:22 - 00003836 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401931354 2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\Users\Public\Desktop\Opera.lnk 2014-06-05 03:22 - 2014-06-05 03:22 - 00001133 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Opera Software 2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Users\Sven\AppData\Local\Opera Software 2014-06-05 03:22 - 2014-06-05 03:22 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-06-05 03:13 - 2014-06-05 03:13 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-06-05 03:13 - 2011-04-02 01:40 - 00001163 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-06-05 03:13 - 2010-05-02 01:17 - 00000000 ____D () C:\Users\Sven\AppData\Local\Mozilla 2014-06-05 03:13 - 2010-05-02 01:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-05 03:04 - 2013-04-03 00:14 - 00002251 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-06-05 02:06 - 2014-06-05 01:52 - 00000021 _____ () C:\AKTR.timestamp 2014-06-05 01:30 - 2014-03-09 11:59 - 00000000 ____D () C:\Users\Sven\AppData\Local\JDownloader 2.0 2014-06-05 00:36 - 2012-05-25 07:38 - 00000000 ____D () C:\Users\Sven\Downloads\Celo & Abdi - Hinterhofjargon 2014-06-04 22:12 - 2014-05-29 01:48 - 00000000 ____D () C:\Users\Sven\Downloads\GZ-LC EP3 2014-06-04 11:49 - 2014-06-04 11:49 - 00000000 _____ () C:\Windows\setuperr.log 2014-06-04 11:24 - 2010-05-02 11:10 - 00000000 ____D () C:\Windows\pss 2014-06-04 11:22 - 2014-06-04 11:22 - 00001021 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-06-04 11:22 - 2014-06-04 11:22 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\dlg 2014-06-04 11:22 - 2010-05-02 01:22 - 00000000 ____D () C:\Program Files (x86)\CCleaner 2014-06-04 11:21 - 2014-06-04 11:21 - 00123392 _____ () C:\Windows\system32\DlProtectSvc.exe 2014-06-04 11:20 - 2014-06-04 11:20 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Security System 2 2014-06-03 10:13 - 2014-06-03 10:13 - 00003092 _____ () C:\Windows\System32\Tasks\{107A92FE-4711-4473-8E02-B7C9963E7371} 2014-05-31 18:15 - 2013-08-31 20:27 - 00000000 ____D () C:\Users\UpdatusUser.Sven-PC 2014-05-31 18:15 - 2013-01-23 23:29 - 00000000 ____D () C:\Users\Gast 2014-05-31 09:42 - 2014-06-09 18:09 - 97747333 _____ () C:\Users\Sven\Downloads\Lucy-Cat - 100-SEKUNDEN-ARSCHFICKWETTE! Wieviel Stöße schaffst du 31.05.14.flv 2014-05-30 20:17 - 2014-05-30 20:17 - 00003112 _____ () C:\Windows\System32\Tasks\{F83E546C-96CD-4EB6-8305-C82BC2EE455A} 2014-05-30 20:13 - 2014-05-30 20:13 - 00003112 _____ () C:\Windows\System32\Tasks\{11911F7C-AFE3-47ED-9FF5-A0B6F51AB520} 2014-05-30 20:02 - 2010-06-20 16:07 - 00000000 ____D () C:\ProgramData\Skype 2014-05-29 20:03 - 2014-05-29 20:03 - 00000000 ____D () C:\ProgramData\Orbit 2014-05-29 20:03 - 2010-07-18 18:57 - 00000000 ____D () C:\Users\Sven\Documents\My Games 2014-05-29 19:52 - 2010-05-02 14:47 - 00000000 ____D () C:\Program Files (x86)\Ubisoft 2014-05-29 19:51 - 2014-05-29 08:38 - 00001205 _____ () C:\Users\Sven\Desktop\Uplay.lnk 2014-05-29 19:51 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-05-29 19:43 - 2014-05-29 19:43 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (incl. 3 Bonustracks) (DE, 2014, VOiCE) 2014-05-29 19:13 - 2014-05-29 19:13 - 00000000 ____D () C:\Program Files\Ubisoft 2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft 2014-05-29 08:38 - 2014-05-29 08:38 - 00000000 ____D () C:\Users\Sven\AppData\Local\Ubisoft Game Launcher 2014-05-29 03:49 - 2013-05-09 06:45 - 00000000 ____D () C:\Program Files (x86)\War Thunder 2014-05-28 23:52 - 2014-05-29 19:24 - 00000000 ____D () C:\Users\Sven\Downloads\KC Rebell - Rebellution (Premium Edition) 2014-05-28 15:51 - 2012-08-20 16:45 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-05-28 00:55 - 2014-05-07 14:55 - 00000000 ____D () C:\Program Files (x86)\LCGenericName02 2014-05-28 00:28 - 2013-10-01 14:36 - 00000000 ____D () C:\Users\Sven\AppData\Local\ArmA 2 OA 2014-05-27 05:00 - 2012-08-21 07:08 - 00000000 ____D () C:\Users\Sven\AppData\Local\Trainer 2014-05-27 03:58 - 2014-05-16 18:58 - 00000000 ____D () C:\Users\Sven\Downloads\Vorms EP3(projet) 2014-05-27 02:29 - 2014-05-13 16:44 - 00000000 ____D () C:\Users\Sven\Downloads\Phoenix LC EP II 2014-05-27 02:27 - 2014-05-12 11:48 - 00000000 ____D () C:\Users\Sven\Downloads\Danaria Last Chaos 2014-05-22 18:43 - 2011-09-22 15:23 - 00000000 ____D () C:\Fraps 2014-05-22 07:10 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\MAGIX 2014-05-22 07:10 - 2014-05-22 07:06 - 00000000 ___RD () C:\Users\Sven\Documents\MAGIX 2014-05-22 07:10 - 2014-05-22 07:06 - 00000000 ____D () C:\ProgramData\MAGIX 2014-05-22 07:09 - 2014-05-22 07:09 - 00001044 _____ () C:\Users\Public\Desktop\MAGIX Video Pro X6.lnk 2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\Documents\MAGIX_MusicEditor 2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Xara 2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Sven\AppData\Local\Magix 2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\Users\Public\Documents\MAGIX 2014-05-22 07:09 - 2014-05-22 07:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX 2014-05-22 07:08 - 2014-05-22 07:08 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Shared 2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\MAGIX 2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files\Common Files\MAGIX Services 2014-05-22 07:06 - 2014-05-22 07:06 - 00000000 ____D () C:\Program Files (x86)\MAGIX 2014-05-22 07:05 - 2011-12-29 22:25 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0 2014-05-22 05:55 - 2013-09-05 05:41 - 00000000 ____D () C:\Users\Sven\Downloads\4ZuDer9 2014-05-22 03:21 - 2014-05-22 03:02 - 00000738 _____ () C:\Users\Public\Desktop\Fraps.lnk 2014-05-22 03:21 - 2012-05-07 06:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastChaosGER 2014-05-22 03:19 - 2014-05-22 03:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps 2014-05-22 03:13 - 2014-05-22 03:10 - 00004535 _____ () C:\Users\Sven\AppData\Roaming\CamStudio.cfg 2014-05-22 03:13 - 2014-05-22 03:10 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamShapes.ini 2014-05-22 03:13 - 2014-05-22 03:10 - 00000408 _____ () C:\Users\Sven\AppData\Roaming\CamLayout.ini 2014-05-22 03:13 - 2014-05-22 03:10 - 00000124 _____ () C:\Users\Sven\AppData\Roaming\Camdata.ini 2014-05-22 03:12 - 2014-05-22 03:11 - 00000000 ____D () C:\Users\Sven\Documents\My CamStudio Temp Files 2014-05-22 03:10 - 2014-05-22 03:09 - 00000096 _____ () C:\Users\Sven\AppData\Roaming\version2.xml 2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7 2014-05-22 03:09 - 2014-05-22 03:09 - 00000000 ____D () C:\Program Files\CamStudio 2.7 2014-05-21 08:31 - 2014-06-10 12:03 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.scr 2014-05-21 08:31 - 2014-06-10 12:03 - 01414867 _____ () C:\Users\Sven\Downloads\zoek.com 2014-05-20 02:05 - 2014-03-09 11:51 - 00000000 ____D () C:\ProgramData\Oracle 2014-05-20 02:04 - 2014-05-20 02:04 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log 2014-05-20 02:04 - 2010-05-02 14:59 - 00000000 ____D () C:\Program Files (x86)\Java 2014-05-20 01:49 - 2012-08-19 02:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony 2014-05-20 01:49 - 2012-08-19 02:55 - 00000000 ____D () C:\Program Files (x86)\Sony 2014-05-20 01:47 - 2014-05-20 01:47 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\InstallShield 2014-05-20 01:47 - 2012-08-21 02:26 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\Wippien 2014-05-20 01:47 - 2012-08-21 02:26 - 00000000 ____D () C:\Program Files\Wippien 2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\FreeHideIP 2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Hide IP 2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\ProgramData\FreeHideIP 2014-05-20 01:33 - 2014-05-20 01:33 - 00000000 ____D () C:\Program Files (x86)\FreeHideIP 2014-05-18 11:29 - 2013-06-07 06:32 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2014-05-18 11:29 - 2011-07-16 21:42 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\DVDVideoSoft 2014-05-18 11:29 - 2010-05-02 01:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2014-05-17 03:21 - 2012-07-12 11:08 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-17 03:21 - 2012-07-12 11:08 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-05-17 03:21 - 2011-10-10 11:10 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-17 03:20 - 2010-05-02 01:24 - 00000000 ____D () C:\Users\Sven\AppData\Local\Adobe 2014-05-15 14:14 - 2010-05-02 00:42 - 00000000 ___RD () C:\Users\Sven\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-15 14:10 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-05-15 13:31 - 2014-05-07 03:01 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-15 12:48 - 2013-08-14 04:10 - 00000000 ____D () C:\Windows\system32\MRT 2014-05-15 12:37 - 2010-05-02 11:19 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-13 21:12 - 2014-05-13 21:12 - 17938608 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2014-05-13 20:30 - 2014-05-08 18:29 - 00000000 ____D () C:\Users\Sven\Downloads\RapidLC 2014-05-12 20:46 - 2010-11-07 21:40 - 00000000 ____D () C:\Windows\System32\Tasks\Games 2014-05-12 10:29 - 2013-09-30 15:57 - 00000000 ____D () C:\Program Files (x86)\Steam 2014-05-12 10:29 - 2010-10-03 14:41 - 00000000 ____D () C:\Users\Sven\AppData\Roaming\TS3Client 2014-05-12 10:29 - 2010-05-02 01:37 - 00000000 ____D () C:\Users\Sven\Tracing 2014-05-12 10:29 - 2010-05-02 01:34 - 00000000 ____D () C:\Windows\Panther 2014-05-12 07:26 - 2014-06-10 11:28 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:26 - 2014-06-10 11:28 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2012-03-08 00:36 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys Files to move or delete: ==================== C:\Users\Sven\AppData\Roaming\CamLayout.ini C:\Users\Sven\AppData\Roaming\CamShapes.ini Some content of TEMP: ==================== C:\Users\Sven\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp4f7lre.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-08 00:01 ==================== End Of Log ============================ --- --- --- |
10.06.2014, 12:01 | #21 |
/// TB-Ausbilder | Sicheres Löschen von "PSHD-9.9" Vergiss meinen letzten Beitrag.... |
10.06.2014, 12:02 | #22 |
| Sicheres Löschen von "PSHD-9.9"Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-06-2014 01 Ran by Sven at 2014-06-10 12:58:38 Running from C:\Users\Sven\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== 7-Zip 4.65 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0465-000001000000}) (Version: 4.65.00.0 - Igor Pavlov) Adobe Acrobat 4.0 (HKLM-x32\...\Adobe Acrobat 4.0) (Version: - ) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.7.0.19530 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 2.7.0.19530 - Adobe Systems Incorporated) Hidden Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Reader 9.4.1 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.1 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.0.112 - Adobe Systems, Inc.) Alarm für Cobra 11 - Das Syndikat - DEMO (HKLM-x32\...\Alarm für Cobra 11 - Das Syndikat - DEMO_is1) (Version: - dtp) Angry Birds (HKLM-x32\...\{61637194-D4E8-45CB-8619-23CE7B637FCF}) (Version: 2.0.2 - Rovio) Angry Birds Space (HKLM-x32\...\{40044440-4ED4-4792-8417-5EE6374F001C}) (Version: 1.1.0 - Rovio) Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ArmA 2 Free Uninstall (HKLM-x32\...\ArmA 2) (Version: - ) ARMA 2 Operation Arrowhead Uninstall (HKLM-x32\...\ARMA 2 Operation Arrowhead) (Version: - ) ARMA 3 (HKLM-x32\...\QVJNQTM=_is1) (Version: 1 - ) Assassin's Creed Brotherhood (HKLM-x32\...\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}) (Version: 1.01 - Ubisoft) Audacity 2.0.3 (HKLM-x32\...\Audacity_is1) (Version: 2.0.3 - Audacity Team) AutoHotkey 1.0.48.05 (HKLM-x32\...\AutoHotkey) (Version: 1.0.48.05 - Chris Mallett) AutoIt v3.3.8.0 (HKLM-x32\...\AutoItv3) (Version: - AutoIt Team) Avast License by ZeNiX [2014-03-14] (HKLM-x32\...\Avast_2050_ZeNiX [2014-03-14]_is1) (Version: - ) avast! Pro Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2017 - Avast Software) Avidemux 2.5 (32-bit) (HKLM-x32\...\Avidemux 2.5) (Version: 2.5.4.7200 - ) AwesomiumSetup (HKLM-x32\...\{19EF99D1-7EE6-4B5E-ABEE-0B3825F703B0}) (Version: 1.00.0000 - SIX Networks GmbH) Axife Mouse Recorder DEMO 5.01 (HKLM-x32\...\Axife Mouse Recorder DEMO_is1) (Version: - Axife Software) Batman Arkham City version 1.0 (HKLM-x32\...\{B531E735-8ED5-4270-ACCE-3809086FBD02}_is1) (Version: 1.0 - WB Games) Battlefield 3™ (HKLM-x32\...\{76285C16-411A-488A-BCE3-C83CB933D8CF}) (Version: 1.0.0.0 - Electronic Arts) Battlefield 4™ Beta (HKLM-x32\...\{CFAB3721-549D-4827-A4E8-7F90192114AB}) (Version: 1.0.0.0 - Electronic Arts) Battlelog Web Plugins (HKLM-x32\...\Battlelog Web Plugins) (Version: 2.3.0 - EA Digital Illusions CE AB) BattlEye (A2Free) Uninstall (HKLM-x32\...\BattlEye A2 Free) (Version: - ) BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version: - ) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) CamStudio 2.7.2 (HKLM\...\{04B83666-3A62-452B-85D3-70F8117F2329}_is1) (Version: 2.7.2 - CamStudio Open Source) CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform) CPUID HWMonitor 1.21 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) Crysis® 2 (HKLM-x32\...\{6033673D-2530-4587-8AD0-EB059FC263F9}) (Version: 1.0.0.0 - Electronic Arts) Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.1.0.0 - Electronic Arts) Cuttermaran 1.70 (HKLM-x32\...\{5F499D33-546A-442B-B0F9-4C58F3B5B6E3}) (Version: 1.7.0 - toarnold) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.47.1.0337 - Disc Soft Ltd) Dark Souls Prepare to Die Edition (HKLM-x32\...\GFWL_{4E4D0FA1-F880-4CCB-999A-501000008200}) (Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.) Dark Souls Prepare to Die Edition (x32 Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.) Hidden DayZ Commander (HKLM-x32\...\{99C28455-E285-4639-B4C6-9F747C0C3D4C}) (Version: 0.92.90 - Dotjosh Studios) DayZero Launcher (HKLM-x32\...\{121CAAD8-0CD7-48CC-A3E1-A1AB8C0B1086}) (Version: 01.00.004 - ZOMBIES.NU) Der Herr der Ringe Der Krieg im Norden Version v1.0 (HKLM-x32\...\{4F7F52F2-DFD5-4FE3-8D24-2B7CEB9980C8}_is1) (Version: v1.0 - ) DiRT 3 (HKLM-x32\...\GFWL_{434D0FA0-1558-4D8E-AC3D-BD1000008200}) (Version: 1.0.0000.130 - Codemasters) DiRT 3 (x32 Version: 1.0.0000.130 - Codemasters) Hidden DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.100 - DivX, LLC) Download Protect (HKCU\...\{132401a7-2006-4342-b43c-ccf5f02c2b01}) (Version: - Download Protect) Dr. Hardware 2013 13.0d (HKLM-x32\...\Dr. Hardware 2013_is1) (Version: - Peter A. Gebhard) Dropbox (HKCU\...\Dropbox) (Version: 2.8.2 - Dropbox, Inc.) DVD Architect Studio 5.0 (HKLM-x32\...\{04DF4A51-DE2A-11E0-9AB5-F04DA23A5C58}) (Version: 5.0.156 - Sony) ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB) EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc) F1 2010 (x32 Version: 1.0.0001.132 - Codemasters) Hidden F1 2010 AI Settings (HKLM-x32\...\{C0EBA426-3C37-4DFC-B96C-1AE9263E720D}_is1) (Version: 1.0 - ) F1 2011 (HKLM-x32\...\GFWL_{434D0FA1-3E0C-4D03-A5D4-5E1000008100}) (Version: 1.0.0000.129 - Codemasters) F1 2011 (x32 Version: 1.0.0000.129 - Codemasters) Hidden F1 2013 German (HKLM-x32\...\RjEyMDEz_is1) (Version: 1 - ) Facebook Messenger 2.1.4814.0 (HKLM-x32\...\{7204BDEE-1A48-4D95-A964-44A9250B439E}) (Version: 2.1.4814.0 - Facebook) Facebook Video Calling 2.0.0.447 (HKLM-x32\...\{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}) (Version: 2.0.447 - Skype Limited) FIFA 13 (HKLM-x32\...\{A29E18C2-7AB1-4b6b-848C-5D5E2C85F0C0}) (Version: 1.5.0.0 - Electronic Arts) Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - ) Free Hide IP (HKLM-x32\...\FreeHideIP) (Version: 3.9.6.6 - ) Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com) Free YouTube Download version 3.2.2.430 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.2.430 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.35.514 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.35.514 - DVDVideoSoft Ltd.) Freemake Audio Converter Version 1.1.0 (HKLM-x32\...\Freemake Audio Converter_is1) (Version: 1.1.0 - Ellora Assets Corporation) Freemake Video Converter Version 3.0.1 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 3.0.1 - Ellora Assets Corporation) German Truck Simulator 1.00 (HKLM-x32\...\German Truck Simulator) (Version: 1.00 - ) GhostMouse (HKLM-x32\...\GhostMouse_is1) (Version: Free V3.2 - ghost-mouse.com) GIMP 2.6.8 (HKLM\...\WinGimp-2.0_is1) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.0 - Google Inc.) Hidden Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google) Google+ RegHelper (HKLM-x32\...\de.txptr.googleplus) (Version: 1.4.0 - UNKNOWN) Google+ RegHelper (x32 Version: 1.4.0 - UNKNOWN) Hidden Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games) Grand Theft Auto IV (x32 Version: 1.0.0011.131 - Rockstar Games Inc.) Hidden Grand Theft Auto IV (x32 Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden Grand Theft Auto IV v1.0 Eng (HKLM-x32\...\Grand Theft Auto IV_is1) (Version: - ) GSview 4.9 (HKLM-x32\...\GSview 4.9) (Version: - ) Gunblade Saga (HKLM-x32\...\{0AC07A77-0511-4904-9FA1-616DC9BEF50D}) (Version: 11.09.30 - Mail.Ru Games GmbH) HyperCam 3 (HKLM-x32\...\HyperCam 3) (Version: 3.4.1205.14 - Solveig Multimedia) IL-2 Sturmovik 1946 (HKLM-x32\...\InstallShield_{79438F1E-DEC3-443D-9DCD-FECE2D68C605}) (Version: 1.00.0000 - Ihr Firmenname) IL-2 Sturmovik 1946 (x32 Version: 1.00.0000 - Ihr Firmenname) Hidden IL-2 Sturmovik Cliffs of Dover (HKLM-x32\...\IL-2 Sturmovik Cliffs of Dover_is1) (Version: - ) Java 7 Update 21 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417021FF}) (Version: 7.0.210 - Oracle) Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.550 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 27 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216020FF}) (Version: 6.0.270 - Sun Microsystems, Inc.) JDownloader (HKLM-x32\...\JDownloader) (Version: 0.89 - AppWork UG (haftungsbeschränkt)) JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH) JDownloader 2 (HKLM-x32\...\0630-0716-3135-7887) (Version: 2 - AppWork GmbH) KaloMa 4.76 (HKLM-x32\...\KaloMa_is1) (Version: - Frank Böpple) LastChaosGER (HKLM-x32\...\{A86A50FC-7C22-478B-BAEF-82393328825F}) (Version: 1.00.000 - Barunsongames CO., LTD.) LCGenericName02 Version 1 (HKLM-x32\...\{4AA19E32-8010-477A-8FC3-B6C1691174AD}_is1) (Version: 1 - LCGenericName02) Macro Recorder (HKCU\...\2a7a433177cfa3a6) (Version: 5.0.0.156 - Jitbit Macro Recorder) MAGIX Speed burnR (MSI) (HKLM-x32\...\MX.{368FDD4C-1D79-44B6-9E86-6A1FF6D1496E}) (Version: 7.0.2.6 - MAGIX AG) MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden MAGIX Video Pro X6 (HKLM\...\MX.{CBC84EDA-E830-4240-9392-325C3E6D5DCA}) (Version: 13.0.3.24 - MAGIX AG) MAGIX Video Pro X6 (Version: 13.0.3.24 - MAGIX AG) Hidden MAGIX Video Pro X6 64 bit Update (Version: 13.0.4.2 - MAGIX AG) Hidden Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Hidden Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{F2508213-9989-4E85-A078-72BE483917EF}) (Version: 3.5.88.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Train Simulator (HKLM-x32\...\Train Simulator 1.0) (Version: - ) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (HKLM\...\{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}) (Version: 8.0.51011 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (HKLM\...\{8338783A-0968-3B85-AFC7-BAAE0A63DC50}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{09298F26-A95C-31E2-9D95-2C60F586F075}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation) Minecraft Beta 1.8.1 Version v1.0 (HKLM-x32\...\{1753427B-E948-4E5B-B4A1-1E7959AD9BDA}_is1) (Version: v1.0 - Godslayers) Minecraft Cracked (HKLM-x32\...\Minecraft Cracked) (Version: - ) MotioninJoy Gamepad tool 0.7.1001 (HKLM\...\{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1) (Version: 0.7.1001 - www.motioninjoy.com) Mount&Blade With Fire and Sword (HKLM-x32\...\Mount&Blade With Fire and Sword) (Version: - ) Mouse Recorder Pro 2.0.7.4 (HKLM-x32\...\{889E44CE-435C-4D37-B302-A7E43339E5FA}_is1) (Version: - Nemex Studios) Move Media Player (HKCU\...\Move Media Player) (Version: - Move Networks) Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 13.0.1 - Mozilla) MSI Afterburner 2.3.1 (HKLM-x32\...\Afterburner) (Version: 2.3.1 - MSI Co., LTD) MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden MSVCRT Redists (x32 Version: 1.0 - Sony Creative Software Inc.) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Need for Speed(TM) Hot Pursuit (HKLM-x32\...\{83A606F5-BF6F-42ED-9F33-B9F74297CDED}) (Version: 1.0.0.0 - Electronic Arts) Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.43.2 - Black Tree Gaming) NVIDIA 3D Vision Controller Driver (x32 Version: 275.33 - NVIDIA Corporation) Hidden NVIDIA 3D Vision Controller-Treiber 326.80 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 326.80 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 326.80 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 326.80 - NVIDIA Corporation) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - ) NVIDIA Grafiktreiber 326.80 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 326.80 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden NVIDIA nTune (HKLM-x32\...\InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}) (Version: 1.00.0000 - NVIDIA Corporation) NVIDIA nTune (x32 Version: 1.00.0000 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.0725 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0725 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2680 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 326.80 (Version: 326.80 - NVIDIA Corporation) Hidden OpenAL (HKLM-x32\...\OpenAL) (Version: - ) Opera Next 12.01 internal build 1491 (HKLM\...\Opera 12.01.1491) (Version: 12.01.1491 - Opera Software ASA) Opera Stable 22.0.1471.50 (HKLM-x32\...\Opera 22.0.1471.50) (Version: 22.0.1471.50 - Opera Software ASA) Origin (HKLM-x32\...\Origin) (Version: 9.3.7.2735 - Electronic Arts, Inc.) Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.3.3.6 - Pando Networks Inc.) PC Connectivity Solution (HKLM-x32\...\{AC599724-5755-48C1-ABE7-ABB857652930}) (Version: 8.15.0.0 - Nokia) PC Inspector File Recovery (HKLM-x32\...\{0DD140D3-9563-481E-AA75-BA457CBDAEF2}) (Version: 4.0 - ) Perfect Effects 3 Free (HKLM-x32\...\{B8D92680-34AC-4B76-8D95-7E95B11B5121}) (Version: 3.0.2 - onOne Software) PhotoScape (HKLM-x32\...\PhotoScape) (Version: - ) Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.) Pinnacle VideoSpin (HKLM-x32\...\{FEB15887-0932-4D2D-BB85-6AC03FBF1AA8}) (Version: 2.0.0.669 - Pinnacle Systems) Platform (x32 Version: 1.34 - VIA Technologies, Inc.) Hidden Pro Evolution Soccer 2010 (HKLM-x32\...\{283FFB23-8751-4B08-ACB8-5E0F8BCF7727}) (Version: 1.03.0000 - KONAMI) Pro Evolution Soccer 2011 (HKLM-x32\...\{1148E85C-E1AF-48E0-A29C-68DACE07E054}) (Version: 1.00.0000 - KONAMI) Pro Evolution Soccer 2014 (HKLM-x32\...\{5EFD3544-2371-4900-8ACA-F157BA80FB0C}) (Version: 1.01.0000 - KONAMI) Process Hacker 2.30 (r5267) (HKLM\...\Process_Hacker2_is1) (Version: 2.30.0.5267 - wj32) Project64 1.6 (HKLM-x32\...\{9559F7CA-5E34-4237-A2D9-D856464AD727}) (Version: 1.6 - Project64) Protegere (HKLM-x32\...\Protegere) (Version: - ) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.) PVSonyDll (Version: 1.00.0001 - NVIDIA Corporation) Hidden QuickTime (HKLM-x32\...\{7BE15435-2D3E-4B58-867F-9C75BED0208C}) (Version: 7.71.80.42 - Apple Inc.) Rainmeter (HKLM-x32\...\Rainmeter) (Version: - ) Rapture3D 2.4.9 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version: - Blue Ripple Sound) raving reyven (HKLM\...\raving reyven) (Version: 2014.03.27.174842 - raving reyven) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6029 - Realtek Semiconductor Corp.) Samsung Mobile phone USB driver Drive Software (HKLM\...\Samsung Mobile phone USB driver Drive) (Version: - ) Samsung New PC Studio (HKLM-x32\...\InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Samsung New PC Studio (x32 Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.650.0 - SAMSUNG Electronics Co., Ltd.) SamsungConnectivityCableDriver (HKLM-x32\...\{7E84FAC8-C518-40F9-9807-7455301D6D25}) (Version: 6.83.6.2.1 - Samsung) Sandboxie 3.66 (64-bit) (HKLM\...\Sandboxie) (Version: 3.66 - SANDBOXIE L.T.D) Ship Simulator Extremes (HKLM-x32\...\Ship Simulator Extremes_is1) (Version: - ) shopping-preise.de - AddOn für Firefox (HKLM-x32\...\{2B11BA9C-7F97-4C16-970F-1491FD77969B}_is1) (Version: 2.81 - shopping-preise.de) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Sound Forge Audio Studio 10.0 (HKLM-x32\...\{0AA0DA00-A1D3-11E0-B9A9-005056C00008}) (Version: 10.0.176 - Sony) StarCraft II (HKLM-x32\...\StarCraft II) (Version: 1.0.0.16117 - Blizzard Entertainment) Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation) Strike Suit Zero (HKLM-x32\...\Strike Suit Zero) (Version: - ) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden System Explorer 3.9.8 (HKLM-x32\...\{40F485F7-6478-4896-B0D5-F94BE677EB78}_is1) (Version: - Mister Group) System Requirements Lab (HKLM-x32\...\{9E1BAB75-EB78-440D-94C0-A3857BE2E733}) (Version: 4.1.71.0 - Husdawg, LLC) System Requirements Lab (HKLM-x32\...\SystemRequirementsLab) (Version: - ) System Requirements Lab CYRI (HKLM-x32\...\{E362724E-9320-4946-AF34-874E7B6B2927}) (Version: 6.0.7.0 - Husdawg, LLC) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.13 - TeamSpeak Systems GmbH) The Elder Scrolls V Skyrim Update 11 (1.8.151.0.7) Deutsche Version 1.00 (HKLM-x32\...\The Elder Scrolls V Skyrim Update 11 (1.8.151.0.7) Deutsche Version 1.00) (Version: - ) The Elder Scrolls V: Skyrim (HKLM-x32\...\{3844035A-9429-4E54-86B0-6EE3778BA3FB}_is1) (Version: 1.1.21.0 - RAF) The Last Remnant (HKLM-x32\...\The Last Remnant_is1) (Version: - ) The Walking Dead: Episode 1 and 2 (HKLM-x32\...\{26B906EC-2979-4936-AED1-30CB96927F64}_is1) (Version: 1.0 - RAF) TopSecret Biometrics Components (HKLM-x32\...\{C8BCC14C-2807-4C2D-A659-843427BF82E2}) (Version: 1.00.0000 - G DATA Software) Tropico 4 Collectors Bundle (HKLM-x32\...\Tropico 4 Collectors Bundle_is1) (Version: 1.0 - ADDONiA) Tunngle beta (HKLM-x32\...\Tunngle beta_is1) (Version: - Tunngle.net GmbH) Uninstall 1.0.0.1 (HKLM-x32\...\Uninstall_is1) (Version: - ) Uplay (HKLM-x32\...\Uplay) (Version: 4.3 - Ubisoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.) War Thunder Launcher 1.0.1.199 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version: - 2012 Gaijin Entertainment Corporation) WATCH_DOGS (HKLM-x32\...\Uplay Install 274) (Version: - Ubisoft) Watson (HKLM-x32\...\{9B88DD94-1AAE-41C4-BD95-2D8737D5E9E2}) (Version: 1.0.0 - Windows Live Safety Center) Windows Live Call (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8117.0416 - Microsoft Corporation) Windows Live Essentials (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 14.0.8117.416 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation) Windows Live Messenger (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 14.0.8117.0416 - Microsoft Corporation) Hidden Windows Live OneCare safety scanner (HKLM-x32\...\Windows Live OneCare safety scanner) (Version: - Microsoft Corporation) Windows Live OneCare safety scanner (x32 Version: 1.0.0.0 - Microsoft Corporation) Hidden Windows Live Sync (HKLM-x32\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation) Windows Live-Uploadtool (HKLM-x32\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) Windows-Treiberpaket - Nokia pccsmcfd (10/12/2007 6.85.4.0) (HKLM\...\BC15EA930074932BB2C4B4493C9FD4EA95087D1A) (Version: 10/12/2007 6.85.4.0 - Nokia) WinRAR (HKLM\...\WinRAR archiver) (Version: - ) ==================== Restore Points ========================= 09-06-2014 13:45:59 Removed Microsoft Office Professional Plus 2010 10-06-2014 10:04:54 zoek.exe restore point ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {00206791-3604-49AF-A7B6-6F9F96435F75} - System32\Tasks\{48D33453-E9D9-469F-849D-160A78897C05} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {0060DF2D-C334-4E56-AC85-3BA0B4BB8C19} - System32\Tasks\{0482E8F0-DC94-4116-82C3-A524AA6EDD56} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {00DE4891-4768-4781-B8F9-D3BACDC71C60} - System32\Tasks\{5FC532AA-6E13-40F5-B394-1335CB2802E7} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe Task: {01543BE2-B3C2-432D-8625-B3E687D20ECC} - System32\Tasks\{6EA1C590-18CC-4242-A3EE-D4D863F62C44} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {028BF155-0170-4774-A4CC-20D842C89A45} - System32\Tasks\{42382861-E829-44D8-82CA-CAEE691391DD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {047FB690-D3B8-4407-BC58-CF1BEAAA9109} - System32\Tasks\{5DB0F65E-BA72-42BD-9F77-902282F494D5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {04CDF2BE-9C9E-496F-B957-1C56120C5971} - System32\Tasks\{FB0C5B4B-828E-4A3A-8E3E-5CF0415AC411} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {05290312-83EB-408E-B517-6FACAF272D54} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001UA => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.) Task: {05768801-9C10-4797-BA90-B0C2AFE28B74} - System32\Tasks\{3B811B6B-73E2-4C71-900E-DDFD4DF79ACD} => E:\AutoRun.exe Task: {059CDD4F-B16C-43B6-B938-D9B530A62A51} - System32\Tasks\{9AC660E1-E379-48DA-A67E-E8AAD6BFC56E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {07DCA1A2-0AD2-4B86-B2FD-715C05CCA7AB} - System32\Tasks\{0BDE8801-35E5-4CD1-B357-8B6E6DF01DCC} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe Task: {09240454-01FE-4102-9921-BBDA41827BDE} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001Core => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-07-12] (Facebook Inc.) Task: {0A4CE36B-9B12-4B1E-B540-CA6072A90AEE} - System32\Tasks\{46F5B8DA-D479-487D-A2CB-ED1923FB1373} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {0A6C2D4D-1161-4D27-B474-59BAAE8F27FB} - System32\Tasks\{531E50E7-B9D2-4660-95F5-9641C3586AAC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {0A6C8C93-F7AB-43F6-A0CC-281D24D3CF72} - System32\Tasks\{E47A74B7-37CB-40DE-8AF4-D63E9E1F8C1A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {0BD63AAF-49E0-4A9A-BDEF-BD66D87211E1} - System32\Tasks\{EBFB120D-5756-4184-8E28-539FF3975ED0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {0C06DDDD-3F65-4B71-B0F6-EAB79FA8F6E0} - System32\Tasks\{16D23950-57D0-4260-A83C-7A9EF3BA8B10} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {0D011E81-3D76-44F3-8626-D2750C23ED12} - System32\Tasks\{56327058-6A18-428D-8411-A8D80E3FD0DC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {0DADA3D1-96FD-46DA-A2EE-5F7F740710A8} - System32\Tasks\{C10B0F16-9D9E-44BE-B53F-2A79DD22417C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {0DC20443-9129-4C90-9D0B-469A0FE8065F} - System32\Tasks\{1AD275C9-3DEC-44AE-9C34-FF6453D7FDCB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {0EC1E659-64D9-4CC9-813C-2B19E5FECBF7} - System32\Tasks\{1808866F-9A73-4701-B5B8-92DDDCA1A936} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {0EF04926-207E-445D-96F6-71F7BFB973C7} - System32\Tasks\{9FFEA193-9C5E-42FB-A13A-3C45B191659E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {0F8CC94F-048A-4366-8240-9F01292E5C25} - System32\Tasks\{BC26F19E-C830-4EA2-85AE-3D5AA929C880} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {108C58DC-9854-44E7-A15A-E8D4A2CC38BD} - System32\Tasks\{716EAD2A-A1E3-4E82-9C02-36776753AE4D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {1313A74E-8497-4CCC-B653-3430D26F947D} - System32\Tasks\{6136571D-6365-4A71-800A-9C16B89DC946} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe Task: {14CCF703-5440-4955-AE87-C0BEC0BCDF82} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-06-05] (AVAST Software) Task: {151F64D7-9CE9-4B1E-B0B6-12A82939FAF7} - System32\Tasks\{8ECB201E-0FC2-497B-8C23-F10C1A93DA27} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {15666D0F-7586-4000-9932-149CDA127E6F} - System32\Tasks\{C43090F5-62C8-42D4-BADF-150BBF0A3F2B} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.114/de/go/help.faq.installer?LastError=1603 Task: {1591003B-2F48-465D-981B-7B8A41007100} - System32\Tasks\{3113EAE0-844D-46F8-A4E2-97BCA735D923} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {15CC64F6-C57C-4E1B-B266-D0FAEB366850} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION Task: {1646E41A-0620-458D-9842-6A07C0AA33EE} - System32\Tasks\{F92CFB9A-E557-47B1-A8A8-D48BF88C12E5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {1670DFB5-521E-472F-84EF-3AE74946A37A} - System32\Tasks\{CE9CC2D0-7509-4B2D-A43D-5BB9A1710D03} => C:\Program Files (x86)\Team17\Worms Reloaded\WormsReloaded.exe Task: {17BB7FAD-D2FC-49F3-AE14-A4225B06B8E3} - System32\Tasks\{28AB3BCF-EE50-484F-BE21-F66EF3461957} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {18A75256-BA65-4CDA-AB02-9A1FBCA6AC0E} - System32\Tasks\{FE6DADBB-DE8F-4BDC-87FD-D36DB2CEEAA9} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {18FD2294-3EDF-4904-AA67-94057FBF0BA2} - System32\Tasks\{A7523CFB-164F-4EAB-B8CC-4CADB4D534DC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {1B2FEB5E-2676-43C1-908A-4B640D75A679} - System32\Tasks\{86A0D00A-38FF-4988-B2A3-31B1F266576E} => C:\Program Files (x86)\Railworks 2010\RailWorks.exe Task: {1D1F8052-52AC-44ED-B134-C4C689E7AB48} - System32\Tasks\{81E83BD6-E3AC-4909-9EAF-74158FB16614} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {1D782067-0E4C-41F2-91EC-51C1CBA0F339} - System32\Tasks\{9F2389C9-E0A7-477B-9909-F031582AD6F5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {1DD72608-CFA6-4AD2-B913-E3B6831F2464} - System32\Tasks\{72826905-205B-4821-8621-1D8C8E08F2BC} => C:\Users\Sven\Downloads\PortableZombie Driver1.0.4\Zombie Driver.exe Task: {1DF7B898-5E91-4ED8-90F1-B725BE742DCA} - System32\Tasks\{6F286A32-34B2-4E27-AF82-2D838BCB3012} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {1E503B2C-0E1A-4C72-965A-09996706192C} - System32\Tasks\{4DBAEF55-EF8E-4852-B9F5-AFB4ED2630A1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {2199FF4C-C031-4D14-BF52-F596A11DCA8B} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2014\OneClick.exe Task: {23941C5E-F5AF-4F47-ADF6-E326297ADA8A} - System32\Tasks\{F3092C73-8B09-4013-ADED-52F3D3F4B852} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {248467D6-6AE9-474E-B9D8-C2B325203880} - System32\Tasks\{C5CC5AE2-842A-40F2-BED4-FDD2C8FBED5A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {258C4939-0DEC-4711-8B26-F2DAFEE63003} - System32\Tasks\{3DFE2278-9A94-4095-A89F-8E4DB9B77C0C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {25FCB770-2B27-43F5-82C6-9A99F7CF951C} - System32\Tasks\{33702D64-5E9F-4E66-B15D-57A6C7753CF1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {264FE3BF-A728-4ED0-8784-485E95EB9332} - System32\Tasks\{4DF0AC0C-7E9F-476A-812D-66F469EB75C5} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] () Task: {26AFDCE2-62B0-4A72-9BF5-46014D9C84FE} - System32\Tasks\{C14816C9-AC1D-44B3-A1B4-2D930E834141} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {26F96DDC-18B4-4D1E-AD74-F4D4F74ABE9F} - System32\Tasks\{10C1E1CD-1BAF-4D59-A603-08BFCA24646D} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe Task: {2A71016B-03C8-4233-B859-2F22E75C79F5} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1098949856-1301053314-1890294551-1001 Task: {2C83876C-E904-40A0-BC07-504872AE2B1D} - System32\Tasks\{61B863D1-021C-4E73-897A-46FF41577FBD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {2CA817F9-FBB1-494E-B5BA-1A78D6C7033D} - System32\Tasks\{EF0E0319-3DD7-45C8-86EB-15DFE8C8BCDC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {2D6CAF9A-1CD9-4364-988E-B477F7EF5522} - System32\Tasks\{734FA937-B120-4B5C-A837-2088381DA3D1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {2D991809-8C7D-40DD-BDC7-D5C5636BB74C} - System32\Tasks\{48E2514F-1BB2-4C45-A316-4FBC8FD30901} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {2EEFA68F-9662-4975-B6F9-786821AA4B7D} - System32\Tasks\{CBA16325-3343-4E45-8DB1-EA6FD9411E8E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {2F1602D8-2D54-4CE8-AA5A-5EEF7E2A858E} - System32\Tasks\{D21EA65A-44EB-464A-9DE2-146F048CA557} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {2F94047F-3A85-4824-B184-84E692DD8FDC} - System32\Tasks\{8AAC4425-84C7-473A-9176-7CDC1B945E17} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {3024CA3C-1A96-4627-9537-ED118A186E67} - System32\Tasks\{E2F5210F-2631-4D91-846F-19297E04B896} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {3032538E-C43C-4D03-9188-6A4F0549E71B} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation) Task: {30568D3D-7971-4F36-81FD-E61631C4BB57} - System32\Tasks\{7A87D65E-FDC1-4CB9-90D4-D12D3FA46EBD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {327DE954-86CA-4727-BEDB-3D552CE75DC2} - System32\Tasks\{B2F079F0-A5EA-4E87-8D44-B8520B2B3744} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe Task: {34B0DB67-D565-4912-B698-F6A3820BB42E} - System32\Tasks\{326BB3CB-2AA7-409F-8145-AE956B1109A2} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe Task: {34DC50F6-70ED-48F6-9E59-E47E80C5F6C5} - System32\Tasks\{81F3A03F-A984-4D44-8C6E-481C91E702C2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {38033478-0F98-4B7F-9FE4-F40D65526668} - System32\Tasks\{A285C147-7F6E-460C-8794-6453B4B02DDE} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe Task: {38596C41-5023-4B7B-A97A-FFCFB4638D5B} - System32\Tasks\{56D14608-B485-45C4-AFA3-D4697153A8EB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {3896DA66-668F-4E13-8D8B-14701CA38B7A} - System32\Tasks\{02976DCA-3D64-4818-8AB2-D452E2EDBD39} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe Task: {3AAFDACA-05D8-49D7-A834-1DBEB4447E00} - \41220790-4b35-4753-91f3-94289344bd48-3 No Task File <==== ATTENTION Task: {3BA6A538-EDC3-42E7-B0DC-94555326A0E0} - System32\Tasks\{F599B4D3-A939-427B-BFAD-41215FFA4B06} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {3BB70042-89B5-4A30-AC51-AB0D69BB4B48} - System32\Tasks\{3A87CEDE-5E99-4260-A802-4AA83B8A0AD3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {3BC27ED0-6484-4FF7-A68A-D54328294275} - System32\Tasks\{0FEA611C-B1BF-4668-9918-41A30DF48CC3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {3D42ADE7-E1E6-4302-8844-122441F4B904} - System32\Tasks\{76D5F951-BF21-4A9D-8603-7AE010F98315} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.) Task: {3F5B5D63-9908-4BA1-8C99-A3C1718E5EE9} - System32\Tasks\{DBC5E996-473B-425F-9DB0-97B88D1C9349} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {3FDBAE0C-A108-4561-BFDD-89C3C2F3D570} - System32\Tasks\{0BD20564-C544-4345-A074-D421C4CC49E0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {415EAC50-7423-4ECB-B27D-1D20376B9A4F} - System32\Tasks\{362EC899-4A81-4D93-96BA-13249EE94512} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {41F754B4-BA61-4685-AE07-6402385F6933} - System32\Tasks\{8AEB40A7-FA35-48F5-82EB-EA0819FB326B} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] () Task: {422EB8B1-2BD7-4FF0-A55D-6A3F7EBE8EDF} - System32\Tasks\{4A347536-E75E-4196-AB34-F33A32433986} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {4350EF98-4350-4E0F-98FD-C4EB6ED33391} - System32\Tasks\{11911F7C-AFE3-47ED-9FF5-A0B6F51AB520} => Chrome.exe hxxp://ui.skype.com/ui/0/6.16.0.105/de/go/help.faq.installer?LastError=1618 Task: {45DC1622-0863-4EC2-8060-B48745AA713B} - System32\Tasks\{EAC80C87-0609-4B31-966F-868E17803A7B} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] () Task: {4737680D-7D41-4EDD-89C7-3608C0004939} - System32\Tasks\{C8071675-FABC-45F3-BF98-E3D37474BB4E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {475F81D7-458B-41BC-8A3D-9C3162F60648} - System32\Tasks\{D7CDC2B5-4F80-47C5-B6DD-1D8018821633} => C:\Program Files (x86)\Team17\Worms Reloaded\WormsReloaded.exe Task: {4770E7B8-7CFF-493C-9976-C434C787CD0B} - System32\Tasks\{8F1ECE0A-1A81-48B5-85BC-2B7D41547151} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] () Task: {47D83C6B-CF1E-4562-96CA-C7D25840572B} - System32\Tasks\{0AA5EC75-C091-44FA-82A9-44BC0DDA59E3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {4A9A003A-7665-4B9E-B336-A56DE8E8789B} - System32\Tasks\{BE4896D2-6869-4B2B-8F8D-BCA1F61A2487} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {4B2BDB10-32EF-4B37-9AA1-B15CAD2A48F6} - System32\Tasks\{887B7566-0AAF-435D-B5EB-86E215D22677} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {4B437054-DE44-423D-8381-6D09430DFFA9} - System32\Tasks\{CD46C27E-3FC1-4211-920C-E8A7F411CF5A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {4B64318D-5F94-4677-BDEF-13D5B6FDFB73} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-03] (Google Inc.) Task: {4C482DEE-9E14-4738-A2C6-84243B47285E} - System32\Tasks\{65FE692F-FAE1-4833-A4E3-5B91189BDA71} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {4CE83691-0839-4DF7-BB2D-16C096CA1DD9} - System32\Tasks\{DCB5B081-0D7D-4A9D-BFB6-F75BA6B4FFE4} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] () Task: {4D272B4D-0F7B-4149-96B7-E92D0CE78840} - System32\Tasks\{179B45CD-DEC5-4ED2-A215-93FE8E3A3B52} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {4E55A326-7F9C-456A-B061-F773C26BB4B9} - System32\Tasks\{C287E2B1-6EFF-4D09-9101-EAD7B150CB7B} => Chrome.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/abandoninstall?page=tsProgressBar Task: {4F9E67CB-A23E-4973-85EA-DC854F0C5049} - System32\Tasks\{115DA74C-5B2D-40DA-947B-BAEDFEA6A8E2} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe Task: {521EC980-CAC6-4F1D-B6FA-C7BC3A98441F} - System32\Tasks\{81DCE1C0-894D-4779-A1BB-70EE95F4E4B2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {55FEEF07-8E10-45F7-85F6-11C4D8959BF6} - System32\Tasks\{B37F681A-EF3E-45CC-9F17-864119A91E65} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {56C4AFB3-803E-46C9-8C94-ACC9588F0452} - System32\Tasks\{C694B19B-E147-4FDB-9837-2D8A57B43CD8} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {57D5AA40-981A-438F-B928-D3733FD29B8D} - System32\Tasks\{0D35558A-B8E3-478D-92C2-CB6CAF71D82C} => C:\Program Files (x86)\Team17\Worms Reloaded\WormsReloaded.exe Task: {585C0F3C-AD7C-494C-95AB-929FC93FD477} - System32\Tasks\{7D4A2968-2466-423B-8693-D892F5770BC2} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe Task: {59201B3B-2CF8-44D3-BA51-AA71F9BD925B} - System32\Tasks\{2A7E476D-1AB7-4688-A479-ED4CB5FE309C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {5A19A249-F795-411F-B1A5-22070127E4D8} - System32\Tasks\{3D7F2444-BC97-4FC1-A3AD-2050924AB4E4} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {5A75A413-5A4D-47D6-B08F-3A09AF467BA6} - System32\Tasks\{126D53C6-D39A-48FE-87A3-BE39FECA82A3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {5B55648B-938F-4098-AA57-C551B3F04294} - System32\Tasks\{BA7A9134-7D67-401C-8D4C-39B014EC993C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {5BC20421-CD55-437D-B993-7ED3F777584D} - System32\Tasks\{92825E9C-7F09-4EF5-A901-8D20AB4C1CED} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {5BF5E050-9C81-448E-B218-B99FBEE1D85B} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION Task: {5D2C9C91-EBBD-4630-BE2B-DDB3E6EB314E} - System32\Tasks\{5CE6AC57-2F71-4A9C-B339-34847941A456} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {5F627168-4146-41EC-A6E7-4139910834F3} - System32\Tasks\{0498C35C-C89F-4EDA-BA65-F25B08667C06} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {63385CAB-C77F-4D19-8E64-56010138AA02} - System32\Tasks\{F9D4650D-451C-4CF7-AF96-55C9D5512DF6} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe Task: {6508B54E-7342-451D-B651-920729BB2E43} - System32\Tasks\{E2A806C7-3C0D-402F-ACE6-28E8CB964BE2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {65DDD6CA-9B68-44C9-B4BC-B2360B7CB949} - System32\Tasks\{C8F7C6D2-FC04-41A4-AB21-AF4830FD735C} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe Task: {685EC281-E83D-41DF-A5CC-91A8925976AC} - System32\Tasks\{F4948F46-A30B-4C1A-B276-7F5EC91174F1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {687804B6-E9CD-4E37-9D92-D197693B397E} - System32\Tasks\{0EECE376-7CDE-44E3-84E0-72D5A5ED585D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {6A8E2C17-BAEB-4DC8-A342-84DF6286A844} - System32\Tasks\{6EFAE2C9-AE73-4A53-B318-92B8924F73F6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {6B8374AE-0ECA-4D2D-BB9A-45344C01B9C5} - System32\Tasks\{9325521E-959B-40C0-AE8A-DE5FABB2B06F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {6BA32B1F-4293-4074-BD78-CE1A5F17ED99} - System32\Tasks\{8E72C766-9BB4-4166-9866-76139173268C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {6C1979F1-AB41-4EC0-944E-0D16797FF4FD} - System32\Tasks\{454F111B-9668-405C-9D32-5B05FDF5731F} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe Task: {7250271B-F6A2-470A-85A2-0168259D90A8} - System32\Tasks\{E4F229CC-7F16-4DC9-A408-AAB6CAC3F797} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {73D95EE9-648D-4C8F-8911-6B63E0A22F04} - System32\Tasks\{3E98FF82-D955-45DF-983A-3EFBA31786F9} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe Task: {757946F4-35A8-4AEC-B087-00F90BFC2B01} - System32\Tasks\{7B88D895-FA14-4844-A488-041B3EAA833E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {76212287-AAC0-4420-A612-24FD8A9DA5F9} - System32\Tasks\{A2D10B81-B079-4BC6-987C-A19BF3AF4496} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {7916DCDF-AC27-4A62-892F-9DE2BAADE7BB} - System32\Tasks\{0DBAD5B0-D837-4E82-8270-D732E84B8997} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe Task: {79F6D2E3-BB87-4B16-A090-9A6AA4E273DA} - System32\Tasks\{0C33B5D8-227A-489D-9DC7-201BDC56A2CB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {7A79C6A3-E123-4706-990B-7FA2A25E8334} - System32\Tasks\{C77745DF-3ABE-49EA-84BB-ACDF2CB0C172} => C:\Users\Sven\Desktop\GBA\Gamboy Advance\VisualBoyAdvance.exe Task: {7EDE632F-8D75-4EDA-8D30-5F6D6E0DE3F0} - System32\Tasks\{0F216DE1-10A4-4121-9354-94F1FCAE0BA7} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {7FA4FAB4-B29B-46CB-A242-E31BD6102BC8} - System32\Tasks\{6F643769-F667-45A7-89A3-EFB78BAD30D2} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {805A90DD-4661-4FA4-ACC5-9746B1FD37E9} - System32\Tasks\{899D1CD0-E191-4706-820D-6FCC78860A5D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {812EA991-4051-4066-8F6D-7657E59F6F13} - System32\Tasks\{13CC1F28-B809-4E6A-92F6-050867303E38} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe Task: {8432A04B-4B1C-4DF7-88E8-D224B18E0864} - System32\Tasks\{7D8FC48F-F5D5-41C9-A0C7-46FFDB261DF9} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {843DBDDA-40BA-402E-BA69-2271D24F05F8} - System32\Tasks\{C6726A3E-D031-4D25-A625-2FB541085294} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {846792F6-E344-4F5C-8269-35876689B894} - System32\Tasks\{722EE7AC-CBDE-41B1-A4FB-3996382D0916} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {85198C15-CF04-4EB5-8361-B1B6A57279E2} - System32\Tasks\{C6F24B23-E357-414F-8A77-F68FAC2F537E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {85B0D0F1-A5E5-4225-91A2-6AE76820489D} - System32\Tasks\{B1D3638D-7AC5-4FDE-B0B3-8646717611E3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {85B242CA-8635-4CE5-8A89-BC0B930AFB26} - System32\Tasks\{3438563C-BDA2-4240-86FE-C250087D876B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {860D5616-C807-42E4-9471-34492936869C} - System32\Tasks\{0C52ACFB-76D7-4572-AC1F-5C817BC6F9B7} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {89C98CDB-86B4-4B1E-83FE-3BFDA3BBA61B} - System32\Tasks\{85CA7BEC-BAC3-4039-951D-6DD6897DA82A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {8BDBE9D0-F1E1-4282-8D2C-595C2EB28B92} - System32\Tasks\{82A89D01-11E0-4CC3-80AE-23A6B6E0FC61} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {8CB35F7E-5585-4B14-8711-11D6FAC29378} - System32\Tasks\{D2A2BD67-9A7E-4D6F-BE2C-6A8B2D0F1BA1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {8D8F82B8-57B8-4BFE-A952-D123EFC13ECC} - System32\Tasks\{203C25BA-F232-4421-B3DA-A376B3774516} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {8D97D69A-AD7F-493C-8DCC-7CB007C6A8F2} - System32\Tasks\{9C7168A6-031A-469A-AA01-62138FAD5C64} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {8DF97B81-3559-47F4-9420-360B447E1FD0} - System32\Tasks\{FECF6647-C213-4C31-93D8-DA36CEF2D2E5} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {8E04509E-7AFC-454D-841A-708BB706F7DC} - System32\Tasks\{3E9663A7-8201-4FF2-B1EB-833DE8AD30E6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {8FA91399-CE12-4FBD-A967-DFD7D9109D84} - System32\Tasks\{9D64689E-0BD4-4A36-BD88-4A0E50CDC83F} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe Task: {903E2695-1203-484C-B1FB-D551272A2574} - System32\Tasks\{8DB1831F-D69A-4DDE-831A-FAA560851E70} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {904FCA34-E617-4024-8059-1269ADC0C47F} - System32\Tasks\{4C21C9AE-2772-474A-A218-F693E2CF602B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {931B5588-6B96-408B-B873-41412BFE2B8E} - System32\Tasks\{C7652E09-4AA0-4B7F-94CB-751180B2AC84} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe Task: {9879350E-87CA-40F0-964A-DFC97AB3BC30} - System32\Tasks\{41A7B7D7-A9E8-4FDD-AB09-12810CB9DE9C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {98AF9170-2913-4F80-95D2-95B7477DE797} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-17] (Adobe Systems Incorporated) Task: {9974FA93-556E-4FDD-ABA7-D41F1D4176D6} - System32\Tasks\{0BE877C9-7403-4859-BB65-3F99D03088A8} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {9ADA0808-016F-4483-B32E-F4712A3C1511} - System32\Tasks\{31210AE0-BEE0-48B0-AD32-F3DFF7AF8585} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] () Task: {9B469F57-8F99-42A1-8801-E8E97EC4CDD1} - System32\Tasks\{F66DE0CE-872C-44E9-AD32-7E45842B895C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {9BA28B79-CD14-416E-9A76-1B33558AAB10} - System32\Tasks\{AB2ECB65-FA3E-40E1-A023-0E8D5E03A224} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {9DBF7F80-5E83-4F91-91D2-32FA850EF84F} - System32\Tasks\{3CCABE20-2386-4504-81C4-4235BAAC31B7} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {9DFAF053-ECF1-4951-B8B9-D566381CF17E} - System32\Tasks\{12CBB338-12C1-4249-84A2-07241A16A2D6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {9E7E9471-FE25-4DB0-99FC-8E598F78A02E} - System32\Tasks\{DE3AD989-7BFD-4AD9-8EDC-6F505EB64364} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {A1B61844-B80C-4D9A-94F1-4645C98FC2B8} - System32\Tasks\{75FCFCA1-F6E7-4195-8FDB-205A363174BD} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {A212F777-60F2-4D21-AE31-7D8EDE725661} - System32\Tasks\{107A92FE-4711-4473-8E02-B7C9963E7371} => Chrome.exe hxxp://ui.skype.com/ui/0/6.16.0.105/de/abandoninstall?page=tsMain Task: {A2ED97D9-08BE-45A0-8F5E-DF79EE68E5EA} - System32\Tasks\{E792460F-EDFC-488E-8731-0BBFB1110EB6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {A6B88D73-C7CC-4AC8-9868-003E3D1A6117} - System32\Tasks\{123ECB18-D866-4EAF-A87C-2B532824BBFF} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {A88B4C8C-9BCA-4F56-B093-7BB101C93929} - System32\Tasks\{88F50087-6CF7-4A6A-B06F-AD288A88A6DA} => E:\AutoRun.exe Task: {A97D22B7-423F-439C-9A10-3C6091CA5D1A} - System32\Tasks\{1BFCBFF7-66FB-4E87-81A8-FB7CF75207DE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {AA445193-1181-4478-AEF2-B0ED5C6C2E97} - System32\Tasks\{2FFB54D9-0F45-4439-A0AB-B2246A92D499} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {ACFC14E5-8848-4358-90F5-8817059D3A5E} - System32\Tasks\{537B3161-6C44-4CA2-94A2-5BDB3B8C8D3E} => C:\Users\Sven\Downloads\PortableZombie Driver1.0.4\Zombie Driver.exe Task: {ADC16C61-80CB-4175-BEB7-3723F4552311} - System32\Tasks\{65BF13AD-A284-4838-9987-577314060DB0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {ADCB1719-67BA-4895-9D04-8A1A0C26DEB7} - System32\Tasks\{697D2AB0-4D70-40B2-BA95-E58EF151514D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {AE410752-87F2-492D-9D1A-6D81D53BAF55} - System32\Tasks\{20EE37CD-2303-4DD3-97A5-61226D364CF1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {B01A395C-1E4E-4257-A8F2-51DC50233552} - System32\Tasks\{A772563F-BDDC-463B-99F1-C77841420332} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {B1CD2103-56BA-4745-9177-223FFDD53ADC} - System32\Tasks\{470BF604-D7FC-467D-A26E-CF0F03148BEC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {B26A8951-5FE0-4FB7-873E-A0D132A2025F} - System32\Tasks\{98160B25-2EF3-494D-855C-85407974E878} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe Task: {B39BD072-35FE-4CC5-A530-A8909B6872D3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-04-03] (Google Inc.) Task: {B408996C-AB90-4D16-848B-E5C3A70821D8} - System32\Tasks\{667B8D52-5E64-4C4A-9884-01C81DCCA5A8} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] () Task: {B40A4AAC-C52E-47C0-8860-D0D8CFBF36B3} - System32\Tasks\{8528129B-330F-4FB9-BD05-0B63A185738C} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {B46D754A-55E2-4756-BC53-3885E70D6472} - System32\Tasks\{A379F55A-1CF2-4571-AACC-0F2431A98E00} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {B5F85DB4-3143-4086-91FA-2D4D1E3681FC} - System32\Tasks\{73E77971-0011-4D43-AD03-9117C0D1EFDC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {B6A0B547-231E-4DD7-90D8-4EED1969E049} - System32\Tasks\{51ABC066-D83B-4170-8165-07805CC167F0} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {B6BFFAAD-9659-42EF-AA02-57D301DBA5A3} - System32\Tasks\{6C2FFB99-7192-428B-B38C-1D8F0B6F7FC6} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\gameunp.exe Task: {BA9030C6-4777-4D8C-AB61-76025BFA120F} - System32\Tasks\{313997D6-C748-4720-826F-E7E9A6BC21CC} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe Task: {BCFF6A0A-67BC-421B-A03C-20012560E161} - System32\Tasks\{7AB46240-BDE2-4A4F-919C-21CFD95DEB91} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {BD78545A-B9EB-4AF6-AE31-BDA236D2BAE8} - System32\Tasks\{B315BDCA-1064-453A-A6CC-C79F19F7D016} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {C0FF2097-FA54-4970-ABCC-D3C6970BDB8F} - System32\Tasks\{909D4AED-895C-4B2A-96DD-6CA6D80B3960} => C:\Program Files (x86)\Ubisoft\IL-2 Sturmovik 1946\il2fb.exe [2006-09-05] () Task: {C1130E74-46A9-4A07-855A-CDF608DEBBF8} - System32\Tasks\{83AAA377-4550-4890-81AB-EABAA6D54F2F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {C1992231-5AD6-4DEB-9429-A822E9B6459F} - System32\Tasks\{73E2DA90-10C9-4FEB-8303-D06CFBA64319} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {C2180CA4-8AED-48C7-A2E9-F6AE7C2EA254} - System32\Tasks\{68575AA0-FDE2-4EFD-9481-ECADE3C34DA9} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {C4CD2A1C-B81A-4DF8-A06D-66F8EE0C9E08} - System32\Tasks\{4954985C-7557-42F2-9DA3-44DAB4B574EA} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {C6B28C1E-EB4C-49E1-9C0B-AB8E2704CBA2} - System32\Tasks\{F92A9599-40B3-4A4D-AC6B-DB14C925E677} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {C70B179E-12FD-4FA2-9ADF-F9B845F76EBE} - System32\Tasks\{7B61AC9C-9B02-4800-95D6-DC4C2193ECA4} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {C956224D-737E-44AC-A135-B8A291573F99} - System32\Tasks\{C5CECD65-EFFE-4679-8ED8-9083413AF641} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {C9C1E1CF-9F4F-4893-8DF5-FFD570756159} - System32\Tasks\{1F69CD65-61D9-472C-95EE-8793CAB2098E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {CD835294-0684-4E85-93D7-57FA3413500A} - System32\Tasks\{7AD6CBE5-95F9-4616-B6CE-1FBF3ACBB0D1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {CD878935-40AC-4D8D-8C98-045CA41BB390} - System32\Tasks\{F83E546C-96CD-4EB6-8305-C82BC2EE455A} => Chrome.exe hxxp://ui.skype.com/ui/0/6.16.0.105/de/go/help.faq.installer?LastError=1618 Task: {CDAC83D4-811F-4165-8722-856EAE3449B3} - System32\Tasks\{E0B10180-47E9-4AB1-9FE0-6C44B2EF97A1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {CE724C0F-EA35-4437-9D30-1113211B6A09} - System32\Tasks\{4C940F41-C0B3-4969-884C-E442672E162D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {CF2606A0-ACA7-45F9-AD40-268630067DC0} - System32\Tasks\{96124692-6A3C-4996-8C1C-D5A23375B7EE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {D21F7BE1-05EB-44B3-BAA5-9BCD4AE31875} - System32\Tasks\{901FF9AA-59B7-48DE-82FE-581B7F599280} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {D264BCEC-BABB-4C67-AB5E-F518C830438A} - System32\Tasks\{F600C80E-888F-4E6B-9B51-FEB3021CC358} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {D360F099-830B-49E3-8626-6FA307F5DDE8} - System32\Tasks\{BC56BB0E-CC7A-4E3C-BAA7-76686DE08AC6} => C:\Program Files (x86)\il-2 sturmovik cliffs of dover\Launcher.exe [2011-04-03] (1C:SoftClub) Task: {D4A58010-4058-414F-B75C-F534647CCADE} - System32\Tasks\{60083AE6-8669-4F76-A8C9-EC5394929A9B} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe Task: {D652DAE9-1CF0-45B1-BB5B-73CBD75E3D7A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files (x86)\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd) Task: {D71B37E9-5FF9-4CDC-8C10-90DBE9D9D2C7} - System32\Tasks\{A08D600B-BB0B-4BB7-B7E5-EFA9DBA72624} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {D84CF91D-4A8A-4C38-8808-78F24EEA7D00} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {D92C729A-F461-430D-9536-06B0A6EEF5D5} - System32\Tasks\Opera scheduled Autoupdate 1401931354 => C:\Program Files (x86)\Opera\launcher.exe [2014-05-27] (Opera Software) Task: {D934BBFE-2B1B-462F-B25C-A7FC1696106C} - System32\Tasks\{B83314D1-CE37-47EB-93D3-5F69CE06C9BE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {DA5E0905-D48D-4F65-A292-DCE54E3DF4DE} - System32\Tasks\{48B23608-CF81-40DF-866F-E9149F931791} => C:\Program Files (x86)\English Bid for Power Final 4.0\EBFPF 4.0.exe Task: {DCB6E2F6-56D1-4247-8394-3366B53DBE91} - System32\Tasks\{D0C97849-AFD1-450D-A83D-E2ABAF26C11D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {DD54C13C-6AA2-45C9-98FB-4F3C4F706776} - System32\Tasks\{D636E579-ECC1-48E6-8D34-0898C8B8AB88} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {DF3520E2-5C0C-45C7-9E29-C0A3CF6624CD} - System32\Tasks\{F9064DAF-E8C8-42B4-872B-CF84AEB8A5A1} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {DFDC1780-CB4B-49C6-9D0C-6A307018E041} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: {E06029EB-0DB6-46F4-8D96-010660E515F6} - System32\Tasks\{6D9D7339-3B94-4B93-A4D6-B3152EBECD01} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {E069F814-CBF7-4E4F-9793-7A842132DBBA} - System32\Tasks\{373EABBD-53C5-4E40-898F-4C5069D8A499} => C:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe [2009-06-28] (Sony DADC Austria AG) Task: {E13EACA4-DC9F-4ADC-9A68-67B64DFE23B6} - System32\Tasks\{DEF987AD-81AC-42EB-B412-5A8403716DDA} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {E1C1E3A3-A460-421D-A2A3-CD52241FD7D5} - System32\Tasks\{C0F296D8-C7D3-40E7-BE16-E643CDDEC0BC} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {E2191329-4BE6-4CFE-A6D1-734AF9A17EFA} - System32\Tasks\{3BA18019-EAF4-452D-A4A2-3E20F326FC0D} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {E3C57322-4D59-48CE-9D42-CC0D884733F7} - System32\Tasks\{BA768B60-C681-4E86-B54D-B818BB13C841} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {E44DAC2B-B71A-4537-A501-996802E1A023} - System32\Tasks\{03B26415-BC1D-4284-9D4A-A178EB9B3EB6} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {E4508BB6-1429-49BD-BCBA-083AAA7E5AA8} - System32\Tasks\{BC238E47-DE85-42C8-A42A-5CAEAE4649FB} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe Task: {E4FA1C11-710B-467C-8C5B-869390DF8A61} - System32\Tasks\{699BB15C-2884-457A-BA98-A4B8698C652A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {E6A13448-9338-473B-BAA0-23B9F616B6D0} - System32\Tasks\{775735C3-BC90-4F41-82D2-6C5EE14FD15A} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {E712900C-C47E-492D-BF1A-DE095C31D309} - System32\Tasks\{3A9C2093-CDC6-4117-A344-E59636C8D654} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {E92D78D6-0882-4D25-8296-F91672232EC3} - System32\Tasks\{0B804F92-4E06-4F0B-8398-FBFF1770A638} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {EAD179B7-8EFB-4C37-A13B-DAA71D740E0D} - System32\Tasks\{CEDABE9A-9564-465A-B4B1-1257AC1B2C43} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {EB6B115F-67DB-4599-B4F8-8766B8ED346F} - \41220790-4b35-4753-91f3-94289344bd48-5 No Task File <==== ATTENTION Task: {ED37749E-137A-4F1C-9FD0-3DCF709567E5} - System32\Tasks\{A4B072C7-A2B2-4870-8C3F-6B6324B02FBB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {EF1BD8C8-A15F-4BC6-AD60-672E42A93C49} - System32\Tasks\{A6450515-09C9-444A-B374-6304A0A11E67} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {EFC87779-05F4-4C10-8880-71EAEBE1391F} - System32\Tasks\{8A126FB2-9DF1-40B6-BF29-94BC77C74FAB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {F0108CE8-B277-4C4D-BEB9-83F45F46F170} - System32\Tasks\{6E35942B-EC74-4C6C-8ECD-5787FEE77389} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe Task: {F11AE687-5F0D-4509-9E7D-904D61C5BA98} - System32\Tasks\{177FAF9C-8814-4261-A21C-CA7506F2B82F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {F28B5784-80AB-4325-8C31-358E7215BB3C} - System32\Tasks\{6F04151D-6AB6-4AD1-AD9E-5AE5BB416094} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {F62B21A2-FAEC-44BA-93B9-C1AE49234444} - System32\Tasks\{11514906-B372-4DBD-B566-488DF1E6F029} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe Task: {F800F910-22FD-49C7-938B-A6C0AD765100} - System32\Tasks\{88CE8631-1046-44CF-88EE-4849D81EE9E3} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {F875476F-7142-4F9D-812C-13343492E7A1} - System32\Tasks\{D9DFF9E6-6D3B-4AE0-9D39-D0AC25C7B9BE} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {F89D7FAD-847B-495E-B7A9-1102853A0B96} - System32\Tasks\{B518FFEB-D63F-452B-82E4-F45EF890BC97} => C:\Users\Sven\Desktop\RAF 3.0 - RAF 3.0 (Premium Edition) (2012)\gamin16\game.exe Task: {F8E344A2-D4C9-4CE7-98BB-521D2CA6A434} - System32\Tasks\{D691C721-D450-4C82-B4C4-495A1B64DBD3} => C:\Users\Sven\Desktop\GBA\18\VisualBoyAdvance.exe Task: {F91D746E-4CF8-41DE-83CB-31432B4543D9} - System32\Tasks\{DCEAF480-641F-4ACD-A325-BDBA0CCC540B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {FA2B38D9-60DC-455F-BB4A-D4810EB33769} - System32\Tasks\{0A9C2DB2-D33D-4DE9-A45C-528B8C1AEE1B} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {FA31A522-796E-426B-848D-E9077313AD8A} - System32\Tasks\{A0DA316A-D472-444F-A426-D6D46912C19F} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {FBFCFB6D-C9AD-4075-A58D-ADD617EF8D2B} - System32\Tasks\{45962B83-FB74-456E-BE05-674FB7E57069} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: {FCE91E30-A0CA-4991-A909-F7CF995FB676} - System32\Tasks\{B8DE84ED-80C7-4218-A29E-5B4B9E36DDAA} => C:\Users\Sven\Desktop\GBA\Gamboy Advance\VisualBoyAdvance.exe Task: {FE3ECFB4-5ADB-4B7C-92C9-E7F27D53C159} - System32\Tasks\{08AF28EA-188F-4A3C-AA80-C8A5DC185025} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/de/go/help.faq.installer?LastError=1603 Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001Core.job => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1098949856-1301053314-1890294551-1001UA.job => C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-10-26 03:31 - 2013-08-18 21:34 - 00097568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2013-10-12 04:11 - 2013-10-12 04:11 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe 2010-05-02 11:53 - 2010-05-02 11:53 - 02937528 _____ () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe 2010-05-02 01:13 - 2009-05-07 16:51 - 00071680 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll 2010-05-02 01:13 - 2009-05-07 16:53 - 00379392 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll 2010-05-02 01:13 - 2008-01-18 14:50 - 00098816 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\VMicApi.dll 2010-05-02 01:13 - 2009-07-10 10:48 - 47601664 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Skin.dll 2014-06-05 03:22 - 2014-05-27 12:00 - 01396344 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\opera_crashreporter.exe 2014-06-05 06:20 - 2014-03-14 08:00 - 00695808 _____ () C:\Program Files\AVAST Software\Avast\VERSION.dll 2014-06-10 11:51 - 2014-06-10 11:51 - 02775040 _____ () C:\Program Files\AVAST Software\Avast\defs\14061001\algo.dll 2011-09-27 08:23 - 2011-09-27 08:23 - 00087912 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2011-09-27 08:22 - 2011-09-27 08:22 - 01242472 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-06-05 06:14 - 2014-06-05 06:14 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2014-06-05 06:20 - 2014-03-14 08:00 - 00695808 _____ () C:\Program Files\AVAST Software\Avast\version.DLL 2014-06-10 12:53 - 2014-06-10 12:53 - 00043008 _____ () c:\users\sven\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp4f7lre.dll 2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Sven\AppData\Roaming\Dropbox\bin\libcef.dll 2014-06-05 03:22 - 2014-05-27 12:00 - 00877176 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\libglesv2.dll 2014-06-05 03:22 - 2014-05-27 12:00 - 00135800 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\libegl.dll 2014-06-05 03:22 - 2014-05-27 12:00 - 00957048 _____ () C:\Program Files (x86)\Opera\22.0.1471.50\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GamersFirst LIVE!.lnk => C:\Windows\pss\GamersFirst LIVE!.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Rainmeter.lnk => C:\Windows\pss\Rainmeter.lnk.CommonStartup MSCONFIG\startupfolder: C:^Users^Sven^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupfolder: C:^Users^Sven^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Facebook Messenger.lnk => C:\Windows\pss\Facebook Messenger.lnk.Startup MSCONFIG\startupfolder: C:^Users^Sven^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^regsvr43.lnk => C:\Windows\pss\regsvr43.lnk.Startup MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: AutoStartNPSAgent => C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun MSCONFIG\startupreg: DivXMediaServer => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW MSCONFIG\startupreg: Facebook Update => "C:\Users\Sven\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver MSCONFIG\startupreg: msnmsgr => "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: SandboxieControl => "C:\Program Files\Sandboxie\SbieCtrl.exe" MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent ==================== Faulty Device Manager Devices ============= Name: SbieDrv Description: SbieDrv Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: SbieDrv Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Event log errors: ========================= Application errors: ================== Error: (06/10/2014 11:08:28 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: adwcleaner_3.212.exe, Version: 3.2.1.2, Zeitstempel: 0x4f25baec Name des fehlerhaften Moduls: adwcleaner_3.212.exe, Version: 3.2.1.2, Zeitstempel: 0x4f25baec Ausnahmecode: 0xc0000005 Fehleroffset: 0x000111c9 ID des fehlerhaften Prozesses: 0x13c8 Startzeit der fehlerhaften Anwendung: 0xadwcleaner_3.212.exe0 Pfad der fehlerhaften Anwendung: adwcleaner_3.212.exe1 Pfad des fehlerhaften Moduls: adwcleaner_3.212.exe2 Berichtskennung: adwcleaner_3.212.exe3 Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9999 Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9999 Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9001 Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9001 Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 8003 Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 8003 Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second System errors: ============= Error: (06/10/2014 00:53:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "KMService" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (06/10/2014 00:53:30 PM) (Source: SbieSvc) (EventID: 9153) (User: ) Description: SBIE9153 Treiber kann nicht gestartet werden (SbieDrv) Error: (06/10/2014 00:31:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "KMService" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (06/10/2014 00:30:50 PM) (Source: SbieSvc) (EventID: 9153) (User: ) Description: SBIE9153 Treiber kann nicht gestartet werden (SbieDrv) Error: (06/10/2014 00:22:23 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (06/10/2014 00:22:22 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (06/10/2014 00:22:21 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (06/10/2014 00:22:21 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (06/10/2014 00:22:20 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (06/10/2014 11:50:57 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "KMService" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Microsoft Office Sessions: ========================= Error: (06/10/2014 11:08:28 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: adwcleaner_3.212.exe3.2.1.24f25baecadwcleaner_3.212.exe3.2.1.24f25baecc0000005000111c913c801cf848aa06ca209C:\Users\Sven\Downloads\adwcleaner_3.212.exeC:\Users\Sven\Downloads\adwcleaner_3.212.exec8693396-f07e-11e3-95c1-002618bca0f6 Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9999 Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9999 Error: (06/10/2014 10:39:33 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 9001 Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 9001 Error: (06/10/2014 10:39:32 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 8003 Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 8003 Error: (06/10/2014 10:39:31 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second CodeIntegrity Errors: =================================== Date: 2014-06-10 12:57:09.216 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 12:57:08.175 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 12:57:07.156 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 12:57:05.415 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 12:53:30.820 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-06-10 12:53:30.414 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-06-10 12:39:35.652 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 12:39:34.877 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-06-10 12:30:50.021 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-06-10 12:30:49.693 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Sandboxie\SbieDrv.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 56% Total physical RAM: 4095.18 MB Available physical RAM: 1766.4 MB Total Pagefile: 8188.54 MB Available Pagefile: 5871.79 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.41 GB) (Free:229.38 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 3AC77A71) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
10.06.2014, 12:05 | #23 | |
/// TB-Ausbilder | Sicheres Löschen von "PSHD-9.9" ok bevor es weitergeht, habe ich eine Frage: Zitat:
|
10.06.2014, 12:07 | #24 |
| Sicheres Löschen von "PSHD-9.9" Nein habe ich nicht.. benutze Firefox schon länger nicht mehr, weil sich mit ihm keine websiten mehr laden lassen. |
10.06.2014, 12:14 | #25 |
/// TB-Ausbilder | Sicheres Löschen von "PSHD-9.9" Dachte ich mir... dann geht es so weiter: Wir entfernen die letzten Reste und kontrollieren nochmal alles. ESET kann länger (> 3 h) dauern. Im Anschluss entfernen wir alle verwendeten Tools und ich gebe dir noch ein paar Tipps mit auf den Weg. Schritt 1 Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter start S4 DlProtectSvc; C:\Windows\System32\DlProtectSvc.exe [123392 2014-06-04] () [File not signed] C:\Windows\System32\DlProtectSvc.exe HKLM-x32\...\Run: [NextSTART] => [X] HKLM-x32\...\Run: [Workshelf] => [X] HKLM-x32\...\Run: [NPSStartup] => [X] HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Upgrade] => C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F}\Upgrade.exe C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F} URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP80B4BA23-BA51-47B6-A18B-B617C84C81FE&q={searchTerms}&SSPV= SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} FF NetworkProxy: "autoconfig_url", "64.85.181.46" FF NetworkProxy: "http", "64.85.181.46" FF NetworkProxy: "http_port", 8080 FF NetworkProxy: "type", 1 FF Extension: OutBrowse Toolbar - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc} [2013-04-17] S2 KMService; C:\Windows\system32\srvany.exe [X] R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X] S3 X6va003; \??\C:\Users\Sven\AppData\Local\Temp\0035BEA.tmp [X] S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X] S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [X] C:\Users\Sven\AppData\Roaming\CamLayout.ini C:\Users\Sven\AppData\Roaming\CamShapes.ini Task: {15CC64F6-C57C-4E1B-B266-D0FAEB366850} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION Task: {3AAFDACA-05D8-49D7-A834-1DBEB4447E00} - \41220790-4b35-4753-91f3-94289344bd48-3 No Task File <==== ATTENTION Task: {5BF5E050-9C81-448E-B218-B99FBEE1D85B} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION Task: {EB6B115F-67DB-4599-B4F8-8766B8ED346F} - \41220790-4b35-4753-91f3-94289344bd48-5 No Task File <==== ATTENTION Reboot: end Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Schritt 2 Lade dir die passende Version von SystemLook vom folgenden Spiegel herunter und speichere das Tool auf dem Desktop: SystemLook (32 bit) | SystemLook (64 bit)
Schritt 3 ESET Online Scanner
Schritt 4 Downloade Dir bitte SecurityCheck und:
Bitte poste mit deiner nächsten Antwort
|
10.06.2014, 12:25 | #26 |
| Sicheres Löschen von "PSHD-9.9"Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-06-2014 01 Ran by Sven at 2014-06-10 13:18:36 Run:1 Running from C:\Users\Sven\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** start S4 DlProtectSvc; C:\Windows\System32\DlProtectSvc.exe [123392 2014-06-04] () [File not signed] C:\Windows\System32\DlProtectSvc.exe HKLM-x32\...\Run: [NextSTART] => [X] HKLM-x32\...\Run: [Workshelf] => [X] HKLM-x32\...\Run: [NPSStartup] => [X] HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\...\Run: [Upgrade] => C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F}\Upgrade.exe C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F} URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage} SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx?ctid=CT3321902&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP80B4BA23-BA51-47B6-A18B-B617C84C81FE&q={searchTerms}&SSPV= SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} FF NetworkProxy: "autoconfig_url", "64.85.181.46" FF NetworkProxy: "http", "64.85.181.46" FF NetworkProxy: "http_port", 8080 FF NetworkProxy: "type", 1 FF Extension: OutBrowse Toolbar - C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc} [2013-04-17] S2 KMService; C:\Windows\system32\srvany.exe [X] R2 Winstep Xtreme Service; C:\Program Files (x86)\Winstep\WsxService [X] S3 X6va003; \??\C:\Users\Sven\AppData\Local\Temp\0035BEA.tmp [X] S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X] S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [X] C:\Users\Sven\AppData\Roaming\CamLayout.ini C:\Users\Sven\AppData\Roaming\CamShapes.ini Task: {15CC64F6-C57C-4E1B-B266-D0FAEB366850} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION Task: {3AAFDACA-05D8-49D7-A834-1DBEB4447E00} - \41220790-4b35-4753-91f3-94289344bd48-3 No Task File <==== ATTENTION Task: {5BF5E050-9C81-448E-B218-B99FBEE1D85B} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION Task: {EB6B115F-67DB-4599-B4F8-8766B8ED346F} - \41220790-4b35-4753-91f3-94289344bd48-5 No Task File <==== ATTENTION Reboot: end ***************** DlProtectSvc => Service deleted successfully. C:\Windows\System32\DlProtectSvc.exe => Moved successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NextSTART => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Workshelf => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NPSStartup => value deleted successfully. HKU\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Upgrade => value deleted successfully. C:\Users\Sven\AppData\Roaming\Sun\{777A3333-E81B-4249-8295-1F562DC51B1F} => Moved successfully. HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} => Value not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\URL => value deleted successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\SuggestionsURL_JSON => value deleted successfully. Firefox Proxy settings were reset. Firefox Proxy settings were reset. Firefox Proxy settings were reset. Firefox Proxy settings were reset. C:\Users\Sven\AppData\Roaming\Mozilla\Firefox\Profiles\p4ytj1qg.default\Extensions\{abba8887-5879-4072-969e-b2a6a2cca1bc} => Moved successfully. KMService => Service deleted successfully. Winstep Xtreme Service => Service stopped successfully. Winstep Xtreme Service => Service deleted successfully. X6va003 => Service deleted successfully. X6va011 => Service deleted successfully. X6va012 => Service deleted successfully. C:\Users\Sven\AppData\Roaming\CamLayout.ini => Moved successfully. C:\Users\Sven\AppData\Roaming\CamShapes.ini => Moved successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{15CC64F6-C57C-4E1B-B266-D0FAEB366850}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{15CC64F6-C57C-4E1B-B266-D0FAEB366850}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineUA' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3AAFDACA-05D8-49D7-A834-1DBEB4447E00}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3AAFDACA-05D8-49D7-A834-1DBEB4447E00}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\41220790-4b35-4753-91f3-94289344bd48-3' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5BF5E050-9C81-448E-B218-B99FBEE1D85B}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5BF5E050-9C81-448E-B218-B99FBEE1D85B}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\globalUpdateUpdateTaskMachineCore' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EB6B115F-67DB-4599-B4F8-8766B8ED346F}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB6B115F-67DB-4599-B4F8-8766B8ED346F}' => Key deleted successfully. 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\41220790-4b35-4753-91f3-94289344bd48-5' => Key deleted successfully. The system needed a reboot. ==== End of Fixlog ==== Also haben wir es bald ja geschafft, danke dir für deine Geduld und Hilfe nochmals |
10.06.2014, 12:26 | #27 |
/// TB-Ausbilder | Sicheres Löschen von "PSHD-9.9" Gut gemacht. Immer weiter, eins nach dem anderen. |
10.06.2014, 12:35 | #28 |
| Sicheres Löschen von "PSHD-9.9"Code:
ATTFilter SystemLook 30.07.11 by jpshortstuff Log created at 13:27 on 10/06/2014 by Sven Administrator - Elevation successful ========== folderfind ========== Searching for "*PSHD-9.9*" No folders found. ========== regfind ========== Searching for "PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}] "AppName"="PSHD-9.9-codedownloader.exe" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{19E6B430-8939-486D-A9B4-C81AB83A54B0}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{204114BF-9D1E-4F5C-95A2-5D7FC75C5553}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{225A1E1C-39C6-4FEA-807B-65C050E34218}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2522F635-E0DA-40E7-80E0-1957BDFF1224}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{28E606E4-13F1-45BF-80DA-AE5153B162AD}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2937F19F-FBEA-46E1-A843-3194414595}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{295B128F-80B8-4C89-A9E2-419A42803738}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2B5C22CF-8368-4D4F-8CA9-E17917EC9EF}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{34C62A0B-9CE6-4130-8361-AA4A7FE5F3}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{354CFB61-739B-4CCD-9D14-23224A32A4AE}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3AD62C28-6327-47C0-BB18-974F2A5BD248}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{41536BE9-239A-4B2D-A82C-88DB5AA6C192}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{43773D51-CA30-48E7-A36-4F322D8DBEA}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{460211B7-E7FA-430C-8C33-1698A338DF50}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56ABEB18-6BD3-496D-96E9-7938C3BB3D6B}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56CE1A96-624-42A0-9BEC-144E78DB565F}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{57D55C1E-BEDE-4058-992B-9B6543F1BE7}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E5132D9-76B3-4080-91A9-59D1AD1E7448}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61FD3EAB-F4A7-4B49-A44E-84CA4BC2DA8}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6278C536-F890-4B7E-A242-19F4CCA9D9C9}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{645607EE-466D-40C4-901A-B65848C4EFD5}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65D2E6F9-1396-4430-93EC-9BFF6107156}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6A200C98-6B0A-4715-ADDD-3E241B5E201D}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6BAAA66-D001-4031-8358-16BFBCDA154}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E4D2BE9-46C2-424E-B00-96E2CFB71D49}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6F3CBD17-1AD5-4CE7-B721-E2376EBCE732}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{718E603-1AAC-40E9-8915-24E69CC6778E}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{720A7F6C-4CB0-4225-AE1E-D4FC62BE3355}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{75AA3E2D-E831-4A39-8F68-33133DE982C}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78020622-6B73-4B60-816C-85CBDE4232A}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7840DA43-E56D-47D9-96D3-C37DB97F2E2B}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79C744DB-1C9B-4DBC-B3BD-E8A5A5C8BEE5}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F516459-6056-4106-A3E2-6715AE811D65}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{924E1C60-F131-4EED-8FD2-247BBC4568D8}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}] "AppName"="PSHD-9.9-bg.exe" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93500650-CFBE-4ECE-AC59-7138B4EC79E6}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{950588AC-4F98-4479-89A4-7813AF1D477D}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95CCA599-BDB3-4909-AAAD-372958F767A}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CBE1CD3-99B-4E61-BE25-A7111D511A6D}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9EB3D095-A184-44BE-8B28-47582431D2B}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9F8CE472-726E-4126-B3A7-8E1932E3183}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2BFADEF-2DD0-45B2-9C33-C5311158FF9}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4384461-4B10-4BD8-B6CC-CCE6DF618E6}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5039154-BAB-4409-9AA8-B45E6981EA11}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A88AC80E-1AD4-4C4E-90D9-2F76678F1DF}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A984BA40-EB90-455E-A61A-5C865AC25E7D}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC476297-55E3-43EF-8DE2-B3EB1E41D02}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF4CAA4C-4EE1-4C8C-A784-16CACE8494F6}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B3406F8A-99CD-48E9-B82A-A22B44565E0}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B787AF2A-EB75-402D-8E66-C0A33BABD89F}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BA89C16-B97D-4DD8-8B24-D47F167712B2}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C1609283-FD8A-4317-B9DE-4ECC199E24F}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C2ED9D17-6923-4087-99B3-C7D261D99E71}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3FC765B-13EE-4B5E-B540-E3A472461532}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C576D330-6FE0-4695-9778-D04A32E35C3D}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C80C0F4-D216-4B33-A058-604AD982A773}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D099CE66-920D-4D91-8BAB-ED3C3D3342E6}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D249689B-4959-496F-B97C-4E59F88688C}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6BAF6EC-C708-4C00-A9A4-90F23BAC8AFB}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB3DC33D-829D-404E-81F6-05C99BED2D2}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD22B052-D0F2-4C8F-87F4-3C1E52D82CB}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD282AA7-652B-41CB-91A1-57F0A1477865}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE94E69-980A-4CC4-B8A-F2738BA2AE4C}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E58E90C6-ED93-4E5E-95F-B82224899C}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7808D13-3A9D-4531-B3A4-C57D5C889773}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E84EB0FA-DDEF-47D3-8AB4-1EB8804ED159}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EA1E5BDE-F92B-46B7-8683-2E192D126CA}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC1B7EA3-73C0-4C83-A944-2BE27ADC0DB}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEFD29F8-7061-4EDC-A723-5D302AADFD4A}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EF4840EB-E2A7-4F36-B635-5361678D4A4}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFBF6720-F576-4C15-A829-83B9E4E66199}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA150BE7-B443-434A-9184-C8497414A257}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FB009888-631A-4BD0-BBBF-B73AA1E42C5D}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\PSHD-9.9] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}] "AppName"="PSHD-9.9-codedownloader.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}] "AppName"="PSHD-9.9-bg.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}] "AppName"="PSHD-9.9-codedownloader.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}] "AppName"="PSHD-9.9-bg.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\PSHD-9.9] [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}] "AppName"="PSHD-9.9-codedownloader.exe" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1091d5a4-0cf5-455e-bfb1-5e9dc2a880aa}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{19E6B430-8939-486D-A9B4-C81AB83A54B0}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{204114BF-9D1E-4F5C-95A2-5D7FC75C5553}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{225A1E1C-39C6-4FEA-807B-65C050E34218}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2522F635-E0DA-40E7-80E0-1957BDFF1224}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{28E606E4-13F1-45BF-80DA-AE5153B162AD}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2937F19F-FBEA-46E1-A843-3194414595}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{295B128F-80B8-4C89-A9E2-419A42803738}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2B5C22CF-8368-4D4F-8CA9-E17917EC9EF}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{34C62A0B-9CE6-4130-8361-AA4A7FE5F3}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{354CFB61-739B-4CCD-9D14-23224A32A4AE}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3AD62C28-6327-47C0-BB18-974F2A5BD248}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{41536BE9-239A-4B2D-A82C-88DB5AA6C192}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{43773D51-CA30-48E7-A36-4F322D8DBEA}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{460211B7-E7FA-430C-8C33-1698A338DF50}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56ABEB18-6BD3-496D-96E9-7938C3BB3D6B}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{56CE1A96-624-42A0-9BEC-144E78DB565F}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{57D55C1E-BEDE-4058-992B-9B6543F1BE7}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E5132D9-76B3-4080-91A9-59D1AD1E7448}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61FD3EAB-F4A7-4B49-A44E-84CA4BC2DA8}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6278C536-F890-4B7E-A242-19F4CCA9D9C9}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{645607EE-466D-40C4-901A-B65848C4EFD5}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65D2E6F9-1396-4430-93EC-9BFF6107156}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6A200C98-6B0A-4715-ADDD-3E241B5E201D}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6BAAA66-D001-4031-8358-16BFBCDA154}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6E4D2BE9-46C2-424E-B00-96E2CFB71D49}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6F3CBD17-1AD5-4CE7-B721-E2376EBCE732}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{718E603-1AAC-40E9-8915-24E69CC6778E}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{720A7F6C-4CB0-4225-AE1E-D4FC62BE3355}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{75AA3E2D-E831-4A39-8F68-33133DE982C}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{78020622-6B73-4B60-816C-85CBDE4232A}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7840DA43-E56D-47D9-96D3-C37DB97F2E2B}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{79C744DB-1C9B-4DBC-B3BD-E8A5A5C8BEE5}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F516459-6056-4106-A3E2-6715AE811D65}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{924E1C60-F131-4EED-8FD2-247BBC4568D8}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}] "AppName"="PSHD-9.9-bg.exe" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9254b178-6061-4881-9d63-b36eac09f818}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{93500650-CFBE-4ECE-AC59-7138B4EC79E6}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{950588AC-4F98-4479-89A4-7813AF1D477D}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{95CCA599-BDB3-4909-AAAD-372958F767A}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9CBE1CD3-99B-4E61-BE25-A7111D511A6D}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9EB3D095-A184-44BE-8B28-47582431D2B}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9F8CE472-726E-4126-B3A7-8E1932E3183}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2BFADEF-2DD0-45B2-9C33-C5311158FF9}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A4384461-4B10-4BD8-B6CC-CCE6DF618E6}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5039154-BAB-4409-9AA8-B45E6981EA11}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A88AC80E-1AD4-4C4E-90D9-2F76678F1DF}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A984BA40-EB90-455E-A61A-5C865AC25E7D}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC476297-55E3-43EF-8DE2-B3EB1E41D02}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AF4CAA4C-4EE1-4C8C-A784-16CACE8494F6}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B3406F8A-99CD-48E9-B82A-A22B44565E0}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B787AF2A-EB75-402D-8E66-C0A33BABD89F}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BA89C16-B97D-4DD8-8B24-D47F167712B2}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C1609283-FD8A-4317-B9DE-4ECC199E24F}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C2ED9D17-6923-4087-99B3-C7D261D99E71}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3FC765B-13EE-4B5E-B540-E3A472461532}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C576D330-6FE0-4695-9778-D04A32E35C3D}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C80C0F4-D216-4B33-A058-604AD982A773}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D099CE66-920D-4D91-8BAB-ED3C3D3342E6}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D249689B-4959-496F-B97C-4E59F88688C}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D6BAF6EC-C708-4C00-A9A4-90F23BAC8AFB}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DB3DC33D-829D-404E-81F6-05C99BED2D2}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD22B052-D0F2-4C8F-87F4-3C1E52D82CB}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD282AA7-652B-41CB-91A1-57F0A1477865}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DE94E69-980A-4CC4-B8A-F2738BA2AE4C}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E58E90C6-ED93-4E5E-95F-B82224899C}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7808D13-3A9D-4531-B3A4-C57D5C889773}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E84EB0FA-DDEF-47D3-8AB4-1EB8804ED159}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EA1E5BDE-F92B-46B7-8683-2E192D126CA}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC1B7EA3-73C0-4C83-A944-2BE27ADC0DB}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEFD29F8-7061-4EDC-A723-5D302AADFD4A}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EF4840EB-E2A7-4F36-B635-5361678D4A4}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFBF6720-F576-4C15-A829-83B9E4E66199}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FA150BE7-B443-434A-9184-C8497414A257}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FB009888-631A-4BD0-BBBF-B73AA1E42C5D}] "AppPath"="C:\Program Files (x86)\PSHD-9.9" [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\PSHD-9.9] [HKEY_USERS\S-1-5-21-1098949856-1301053314-1890294551-1001_Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\PSHD-9.9] [HKEY_USERS\S-1-5-18\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\PSHD-9.9] -= EOF =- |
10.06.2014, 13:37 | #29 |
/// TB-Ausbilder | Sicheres Löschen von "PSHD-9.9" Gut, fehlen nur noch 2 Schritte. |
10.06.2014, 13:57 | #30 |
| Sicheres Löschen von "PSHD-9.9" Ja bin gerade dabei, ESET läuft. |