Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Bekomme "search.gadgetbox" nicht weg

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 15.06.2014, 16:49   #1
Frontschwein
 
Bekomme "search.gadgetbox" nicht weg - Standard

Bekomme "search.gadgetbox" nicht weg



Habe mir den Schädling gadgetbox eingefangen. Internet sehr langsam.
Startseite nun nicht mehr google sondern gadgetbox.

Hatte erst Spybot laufen lassen, dann Malwarebytes. Zum Schluss nun FRST.

Hier die logs:

Frst:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-06-2014 02
Ran by wh (administrator) on WH-PC on 15-06-2014 17:27:28
Running from C:\Users\wh\Downloads
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0 apoEdition\ouservice\StarMoneyOnlineUpdate.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Play Touch\Touch Launcher\LauncherStarterCmd.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Touch Supporter\InputSupporterNLauncher.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Touch Supporter\InputSupporter.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Play Touch\Touch Launcher\LauncherStarter.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartRotation.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
(Samsung Electronics) C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Easy Support Center\SSCKbdHk.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12661352 2011-08-01] (Realtek Semiconductor)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101584 2014-04-25] (Safer-Networking Ltd.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-3424567567-1130603173-978095989-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566984 2014-04-25] (Safer-Networking Ltd.)
HKU\S-1-5-21-3424567567-1130603173-978095989-1000\...\MountPoints2: {5e394242-c7b7-11e3-af9f-24ec994b3939} - D:\LaunchU3.exe -a
AppInit_DLLs: C:\PROGRA~3\ASSIST~1\ASSIST~2.DLL => C:\PROGRA~3\ASSIST~1\ASSIST~2.DLL File Not Found
AppInit_DLLs-x32: c:\progra~3\assist~1\assist~1.dll => "c:\progra~3\assist~1\assist~1.dll" File Not Found
Lsa: [Notification Packages] scecli ConfigFilter
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.gboxapp.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.gboxapp.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.gboxapp.com/
BHO: NewiSSAVer - {8711D30F-7582-8372-36D2-F2B0BAC36D33} - C:\ProgramData\NewiSSAVer\RK9UOieO.x64.dll ()
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: NewiSSAVer - {8711D30F-7582-8372-36D2-F2B0BAC36D33} - C:\ProgramData\NewiSSAVer\RK9UOieO.dll ()
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2

FireFox:
========
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50917.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)

Chrome:
=======
CHR HomePage: hxxp://search.gboxapp.com/
CHR StartupUrls: "https://www.google.com/"
CHR Extension: (Google Docs) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-04]
CHR Extension: (Google Drive) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-04]
CHR Extension: (YouTube) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-04]
CHR Extension: (Google-Suche) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-04]
CHR Extension: (Google Wallet) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-04]
CHR Extension: (Google Mail) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-04]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738200 2014-04-25] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2081752 2014-04-25] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0 apoEdition\ouservice\StarMoneyOnlineUpdate.exe [663184 2014-01-27] (Star Finanz-Software Entwicklung und Vertriebs GmbH)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.)

==================== Drivers (Whitelisted) ====================

S3 AX88772; C:\Windows\System32\DRIVERS\ax88772.sys [77312 2010-05-31] (ASIX Electronics Corp.)
R3 GTNDIS62; C:\Windows\System32\DRIVERS\Gtuhs62.sys [208384 2011-10-03] (Option N.V.)
R3 GTUHSBUS; C:\Windows\System32\DRIVERS\gtuhsbus.sys [214528 2011-10-03] (Option N.V.)
R3 GTUHSSER; C:\Windows\System32\DRIVERS\gtuhsser.sys [12032 2011-10-03] (Option N.V.)
R3 LSM303DLH; C:\Windows\System32\DRIVERS\LSM303DLH.sys [61040 2011-08-19] (STMicroelectronics)
R2 SGDrv; C:\Windows\System32\DRIVERS\SGdrv64.sys [7680 2011-04-11] (Phoenix Technologies Ltd.)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-15 17:27 - 2014-06-15 17:27 - 00013039 _____ () C:\Users\wh\Downloads\FRST.txt
2014-06-15 17:27 - 2014-06-15 17:27 - 00000000 ____D () C:\FRST
2014-06-15 17:26 - 2014-06-15 17:26 - 02081792 _____ (Farbar) C:\Users\wh\Downloads\FRST64.exe
2014-06-15 16:44 - 2014-06-15 16:44 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-15 16:43 - 2014-06-15 16:43 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\wh\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-15 16:43 - 2014-06-15 16:43 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-06-15 16:43 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-06-15 16:43 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-06-15 16:43 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-06-15 14:22 - 2009-06-10 23:00 - 00000824 _____ () C:\windows\system32\Drivers\etc\hosts.20140615-142237.backup
2014-06-15 12:53 - 2014-06-15 12:53 - 00859992 _____ () C:\Users\wh\Downloads\snlTCNTplugins01.zip
2014-06-15 11:36 - 2009-06-10 23:00 - 00000824 _____ () C:\windows\system32\Drivers\etc\hosts.20140615-113648.backup
2014-06-15 00:50 - 2014-06-15 00:50 - 00000990 _____ () C:\windows\wininit.ini
2014-06-14 20:35 - 2014-06-15 11:34 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-06-14 20:35 - 2014-06-14 20:36 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-06-14 20:35 - 2014-06-14 20:35 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-06-14 20:35 - 2014-06-14 20:35 - 00001379 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-06-14 20:35 - 2014-06-14 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-06-14 20:35 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\windows\system32\sdnclean64.exe
2014-06-14 20:33 - 2014-06-14 20:33 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\wh\Downloads\spybot-2.3.exe
2014-06-12 20:31 - 2014-06-12 20:31 - 00000000 ____D () C:\ProgramData\NewiSSAVer
2014-06-10 20:09 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-10 20:09 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-10 20:09 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-06-10 20:09 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-06-10 20:09 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-06-10 20:09 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-06-10 20:09 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-06-10 20:09 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-06-10 20:09 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-06-10 20:09 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-06-10 20:09 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-06-10 20:09 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-06-10 20:09 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-06-10 20:09 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-06-10 20:09 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-06-10 20:09 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-06-10 20:09 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-06-10 20:09 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-06-10 20:09 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-06-10 20:09 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-06-10 20:09 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-06-10 20:09 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-06-10 20:09 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-06-10 20:09 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-06-10 20:09 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-06-10 20:09 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-06-10 20:09 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-06-10 20:09 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-06-10 20:09 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-06-10 20:09 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-06-10 20:09 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-06-10 20:09 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-06-10 20:09 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-06-10 20:09 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-06-10 20:09 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-06-10 20:09 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-06-10 20:09 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-06-10 20:09 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-06-10 20:09 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-10 20:09 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-06-10 20:09 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-06-10 20:09 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-06-10 20:09 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-06-10 20:09 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-06-10 20:09 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-06-10 20:09 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-06-10 20:09 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-06-10 20:09 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-06-10 20:09 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-06-10 20:09 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-06-10 20:09 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-06-10 20:09 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-06-10 20:09 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-06-10 20:09 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-06-10 20:09 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2014-06-10 20:09 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll
2014-06-10 20:09 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2014-06-10 20:09 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2014-06-10 20:09 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2014-06-10 20:09 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2014-06-10 20:09 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2014-06-10 20:09 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2014-06-10 20:09 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2014-06-10 20:09 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2014-06-10 20:09 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2014-06-10 20:09 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2014-06-09 11:09 - 2014-06-11 14:47 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-06-09 10:48 - 2014-06-09 10:48 - 00000056 _____ () C:\Users\wh\Downloads\heavy-metal.m3u
2014-06-03 21:33 - 2014-06-03 21:33 - 00003279 _____ () C:\Users\wh\Downloads\2-09399-g-06.AAM
2014-06-02 20:14 - 2014-06-02 20:14 - 00003303 _____ () C:\Users\wh\Downloads\2-09399-r-06.AAM
2014-06-01 18:15 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2014-06-01 18:15 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2014-06-01 18:15 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2014-06-01 18:15 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2014-06-01 18:15 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2014-06-01 18:15 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2014-06-01 18:15 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2014-06-01 18:15 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2014-06-01 18:15 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2014-06-01 18:15 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2014-06-01 18:15 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2014-06-01 18:15 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2014-06-01 18:15 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\windows\system32\objsel.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\wincredprovider.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2014-06-01 18:15 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\cngprovider.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\adprovider.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\capiprovider.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\dpapiprovider.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\dimsroam.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-06-01 18:15 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2014-06-01 18:15 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2014-06-01 18:15 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\windows\SysWOW64\objsel.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\cngprovider.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\windows\SysWOW64\adprovider.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\windows\SysWOW64\capiprovider.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dpapiprovider.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\dimsroam.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wincredprovider.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-06-01 18:15 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2014-06-01 18:11 - 2014-06-09 10:40 - 00000000 ____D () C:\ProgramData\VirtualizedApplications
2014-06-01 16:12 - 2014-06-01 16:12 - 00003303 _____ () C:\Users\wh\Downloads\2-09399-u-05.AAM
2014-05-31 17:37 - 2014-05-31 17:37 - 00003111 _____ () C:\Users\wh\Downloads\2-09384-r-06.AAM
2014-05-28 17:26 - 2014-05-28 17:26 - 00003279 _____ () C:\Users\wh\Downloads\2-09399-r-05.AAM
2014-05-25 12:23 - 2014-05-25 12:23 - 00003255 _____ () C:\Users\wh\Downloads\2-09399-u-04.AAM
2014-05-24 13:35 - 2014-06-15 16:53 - 00000000 ____D () C:\ProgramData\DigiSiAAVere
2014-05-23 20:33 - 2014-06-15 16:53 - 00000000 ____D () C:\ProgramData\ExxsTrauSavings
2014-05-22 20:02 - 2014-05-22 20:02 - 00000000 ____D () C:\ProgramData\Sun
2014-05-22 20:02 - 2014-05-22 20:02 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-22 20:01 - 2014-05-22 20:01 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-05-22 20:01 - 2014-05-22 20:01 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-05-22 20:01 - 2014-05-22 20:01 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-05-22 20:01 - 2014-05-22 20:01 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-22 20:01 - 2014-05-22 20:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-22 20:01 - 2014-05-22 20:01 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-22 20:00 - 2014-05-22 20:00 - 00921512 _____ (Oracle Corporation) C:\Users\wh\Downloads\chromeinstall-7u55.exe
2014-05-22 19:53 - 2014-05-22 19:53 - 00003471 _____ () C:\Users\wh\Downloads\2-09399-r-04.AAM
2014-05-21 08:59 - 2014-05-21 08:59 - 00005593 _____ () C:\Users\wh\Downloads\wpkey_v1.4.7d.zip
2014-05-21 07:45 - 2014-05-21 07:45 - 00003375 _____ () C:\Users\wh\Downloads\2-09399-j-03.AAM
2014-05-21 07:45 - 2014-05-21 07:45 - 00003135 _____ () C:\Users\wh\Downloads\2-09399-u-03.AAM
2014-05-19 20:29 - 2014-05-19 20:29 - 00000000 ____D () C:\Users\wh\AppData\Roaming\SoftGrid Client
2014-05-19 20:29 - 2014-05-19 20:29 - 00000000 ____D () C:\Users\wh\AppData\Local\SoftGrid Client
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (Deutsch)
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\Program Files (x86)\Microsoft Application Virtualization Client
2014-05-19 20:27 - 2014-05-19 20:30 - 00000000 ____D () C:\Users\wh\AppData\Roaming\TP
2014-05-16 23:30 - 2014-05-16 23:30 - 00003087 _____ () C:\Users\wh\Downloads\2-09399-j-36.AAM

==================== One Month Modified Files and Folders =======

2014-06-15 17:27 - 2014-06-15 17:27 - 00013039 _____ () C:\Users\wh\Downloads\FRST.txt
2014-06-15 17:27 - 2014-06-15 17:27 - 00000000 ____D () C:\FRST
2014-06-15 17:27 - 2013-08-28 23:14 - 00000000 ____D () C:\Users\wh\AppData\Local\Temp
2014-06-15 17:26 - 2014-06-15 17:26 - 02081792 _____ (Farbar) C:\Users\wh\Downloads\FRST64.exe
2014-06-15 17:12 - 2009-07-14 06:45 - 00021216 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-15 17:12 - 2009-07-14 06:45 - 00021216 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-15 17:11 - 2012-01-05 08:09 - 00700118 _____ () C:\windows\system32\perfh007.dat
2014-06-15 17:11 - 2012-01-05 08:09 - 00149968 _____ () C:\windows\system32\perfc007.dat
2014-06-15 17:11 - 2009-07-14 07:13 - 01622164 _____ () C:\windows\system32\PerfStringBackup.INI
2014-06-15 17:08 - 2012-01-04 09:25 - 01962745 _____ () C:\windows\WindowsUpdate.log
2014-06-15 17:05 - 2014-02-04 01:27 - 00001098 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-15 17:05 - 2012-01-04 09:30 - 00000000 ____D () C:\ProgramData\Samsung
2014-06-15 17:04 - 2014-04-06 00:05 - 00010987 _____ () C:\windows\setupact.log
2014-06-15 17:04 - 2014-04-06 00:05 - 00009142 _____ () C:\windows\PFRO.log
2014-06-15 17:04 - 2012-01-04 10:02 - 00000000 ____D () C:\windows\fi
2014-06-15 17:04 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-06-15 17:04 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\Registration
2014-06-15 16:53 - 2014-05-24 13:35 - 00000000 ____D () C:\ProgramData\DigiSiAAVere
2014-06-15 16:53 - 2014-05-23 20:33 - 00000000 ____D () C:\ProgramData\ExxsTrauSavings
2014-06-15 16:53 - 2014-03-23 19:42 - 00000000 ____D () C:\ProgramData\DealEEXpress
2014-06-15 16:53 - 2014-03-16 01:11 - 00000000 ____D () C:\ProgramData\safeweb
2014-06-15 16:53 - 2014-03-16 01:11 - 00000000 ____D () C:\Program Files (x86)\safeweb
2014-06-15 16:44 - 2014-06-15 16:44 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-15 16:43 - 2014-06-15 16:43 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\wh\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-15 16:43 - 2014-06-15 16:43 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware
2014-06-15 16:38 - 2014-02-04 01:27 - 00001102 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-15 13:34 - 2014-03-30 20:04 - 00000000 ____D () C:\ProgramData\Assistant
2014-06-15 12:53 - 2014-06-15 12:53 - 00859992 _____ () C:\Users\wh\Downloads\snlTCNTplugins01.zip
2014-06-15 12:46 - 2014-03-14 21:41 - 00000000 ____D () C:\Users\wh\AppData\Roaming\UseNeXT
2014-06-15 12:41 - 2014-03-14 21:41 - 00000000 ____D () C:\Users\wh\Documents\UseNeXT
2014-06-15 11:34 - 2014-06-14 20:35 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-06-15 00:50 - 2014-06-15 00:50 - 00000990 _____ () C:\windows\wininit.ini
2014-06-14 20:36 - 2014-06-14 20:35 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-06-14 20:35 - 2014-06-14 20:35 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-06-14 20:35 - 2014-06-14 20:35 - 00001379 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-06-14 20:35 - 2014-06-14 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-06-14 20:33 - 2014-06-14 20:33 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\wh\Downloads\spybot-2.3.exe
2014-06-12 20:31 - 2014-06-12 20:31 - 00000000 ____D () C:\ProgramData\NewiSSAVer
2014-06-12 20:31 - 2014-03-16 01:11 - 00000000 ____D () C:\ProgramData\8e2932845b0d7fdc
2014-06-11 15:02 - 2009-07-14 07:08 - 00011920 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-06-11 14:51 - 2014-03-05 15:54 - 00000000 ____D () C:\windows\system32\MRT
2014-06-11 14:49 - 2014-03-05 15:54 - 95414520 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-06-11 14:47 - 2014-06-09 11:09 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-06-10 20:03 - 2014-04-18 14:32 - 00000000 ____D () C:\Program Files (x86)\StarMoney 9.0 apoEdition
2014-06-10 19:56 - 2013-08-28 23:15 - 00000000 ___RD () C:\Users\wh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-06-10 19:56 - 2013-08-28 23:15 - 00000000 ___RD () C:\Users\wh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-06-09 11:09 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-06-09 10:48 - 2014-06-09 10:48 - 00000056 _____ () C:\Users\wh\Downloads\heavy-metal.m3u
2014-06-09 10:40 - 2014-06-01 18:11 - 00000000 ____D () C:\ProgramData\VirtualizedApplications
2014-06-08 11:13 - 2014-06-10 20:09 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-10 20:09 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-03 21:33 - 2014-06-03 21:33 - 00003279 _____ () C:\Users\wh\Downloads\2-09399-g-06.AAM
2014-06-02 20:14 - 2014-06-02 20:14 - 00003303 _____ () C:\Users\wh\Downloads\2-09399-r-06.AAM
2014-06-01 16:12 - 2014-06-01 16:12 - 00003303 _____ () C:\Users\wh\Downloads\2-09399-u-05.AAM
2014-06-01 16:08 - 2014-02-08 03:03 - 00000000 ____D () C:\Users\wh\AppData\Roaming\Skype
2014-06-01 11:51 - 2013-08-29 00:04 - 00000000 ____D () C:\Users\wh\AppData\Roaming\vlc
2014-05-31 17:37 - 2014-05-31 17:37 - 00003111 _____ () C:\Users\wh\Downloads\2-09384-r-06.AAM
2014-05-30 12:21 - 2014-06-10 20:09 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-05-30 12:02 - 2014-06-10 20:09 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-05-30 12:02 - 2014-06-10 20:09 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-05-30 11:45 - 2014-06-10 20:09 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-05-30 11:39 - 2014-06-10 20:09 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-05-30 11:39 - 2014-06-10 20:09 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-05-30 11:38 - 2014-06-10 20:09 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-05-30 11:28 - 2014-06-10 20:09 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-05-30 11:27 - 2014-06-10 20:09 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-05-30 11:24 - 2014-06-10 20:09 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-05-30 11:21 - 2014-06-10 20:09 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-05-30 11:21 - 2014-06-10 20:09 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-05-30 11:20 - 2014-06-10 20:09 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-05-30 11:18 - 2014-06-10 20:09 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-05-30 11:11 - 2014-06-10 20:09 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-05-30 11:08 - 2014-06-10 20:09 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-05-30 11:06 - 2014-06-10 20:09 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-05-30 11:02 - 2014-06-10 20:09 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-05-30 10:55 - 2014-06-10 20:09 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:49 - 2014-06-10 20:09 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-05-30 10:46 - 2014-06-10 20:09 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-05-30 10:44 - 2014-06-10 20:09 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-05-30 10:44 - 2014-06-10 20:09 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-05-30 10:43 - 2014-06-10 20:09 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-05-30 10:42 - 2014-06-10 20:09 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-10 20:09 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-05-30 10:35 - 2014-06-10 20:09 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-05-30 10:34 - 2014-06-10 20:09 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-05-30 10:33 - 2014-06-10 20:09 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-05-30 10:30 - 2014-06-10 20:09 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-05-30 10:29 - 2014-06-10 20:09 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-05-30 10:28 - 2014-06-10 20:09 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-05-30 10:27 - 2014-06-10 20:09 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-05-30 10:25 - 2014-03-16 11:45 - 00000000 ____D () C:\Users\wh\AppData\Local\CrashDumps
2014-05-30 10:24 - 2014-06-10 20:09 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-05-30 10:23 - 2014-06-10 20:09 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-05-30 10:16 - 2014-06-10 20:09 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-05-30 10:10 - 2014-06-10 20:09 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-10 20:09 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-05-30 10:04 - 2014-06-10 20:09 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-05-30 10:02 - 2014-06-10 20:09 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-05-30 09:56 - 2014-06-10 20:09 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-05-30 09:56 - 2014-06-10 20:09 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-05-30 09:54 - 2014-06-10 20:09 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-05-30 09:50 - 2014-06-10 20:09 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-10 20:09 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-05-30 09:43 - 2014-06-10 20:09 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-05-30 09:40 - 2014-06-10 20:09 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-05-30 09:30 - 2014-06-10 20:09 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-05-30 09:21 - 2014-06-10 20:09 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-05-30 09:15 - 2014-06-10 20:09 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-05-30 09:13 - 2014-06-10 20:09 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-05-30 09:13 - 2014-06-10 20:09 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-05-28 17:26 - 2014-05-28 17:26 - 00003279 _____ () C:\Users\wh\Downloads\2-09399-r-05.AAM
2014-05-25 12:23 - 2014-05-25 12:23 - 00003255 _____ () C:\Users\wh\Downloads\2-09399-u-04.AAM
2014-05-22 20:02 - 2014-05-22 20:02 - 00000000 ____D () C:\ProgramData\Sun
2014-05-22 20:02 - 2014-05-22 20:02 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-22 20:01 - 2014-05-22 20:01 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2014-05-22 20:01 - 2014-05-22 20:01 - 00175528 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2014-05-22 20:01 - 2014-05-22 20:01 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2014-05-22 20:01 - 2014-05-22 20:01 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2014-05-22 20:01 - 2014-05-22 20:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-22 20:01 - 2014-05-22 20:01 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-22 20:00 - 2014-05-22 20:00 - 00921512 _____ (Oracle Corporation) C:\Users\wh\Downloads\chromeinstall-7u55.exe
2014-05-22 19:53 - 2014-05-22 19:53 - 00003471 _____ () C:\Users\wh\Downloads\2-09399-r-04.AAM
2014-05-21 08:59 - 2014-05-21 08:59 - 00005593 _____ () C:\Users\wh\Downloads\wpkey_v1.4.7d.zip
2014-05-21 07:45 - 2014-05-21 07:45 - 00003375 _____ () C:\Users\wh\Downloads\2-09399-j-03.AAM
2014-05-21 07:45 - 2014-05-21 07:45 - 00003135 _____ () C:\Users\wh\Downloads\2-09399-u-03.AAM
2014-05-19 20:30 - 2014-05-19 20:27 - 00000000 ____D () C:\Users\wh\AppData\Roaming\TP
2014-05-19 20:29 - 2014-05-19 20:29 - 00000000 ____D () C:\Users\wh\AppData\Roaming\SoftGrid Client
2014-05-19 20:29 - 2014-05-19 20:29 - 00000000 ____D () C:\Users\wh\AppData\Local\SoftGrid Client
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (Deutsch)
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-05-19 20:28 - 2014-05-19 20:28 - 00000000 ____D () C:\Program Files (x86)\Microsoft Application Virtualization Client
2014-05-19 20:28 - 2012-01-04 09:54 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-05-19 20:28 - 2012-01-04 09:29 - 01649782 _____ () C:\windows\SysWOW64\PerfStringBackup.INI
2014-05-19 20:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-05-16 23:30 - 2014-05-16 23:30 - 00003087 _____ () C:\Users\wh\Downloads\2-09399-j-36.AAM

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-09 11:27

==================== End Of Log ============================





und Malwarebytes:


header>

<date>2014/06/15 16:45:10 +0200</date>

<logfile>mbam-log-2014-06-15 (16-44-52).xml</logfile>

<isadmin>yes</isadmin>

</header>


-<engine>

<version>2.00.2.1012</version>

<malware-database>v2014.06.15.03</malware-database>

<rootkit-database>v2014.06.02.01</rootkit-database>

<license>free</license>

<file-protection>disabled</file-protection>

<web-protection>disabled</web-protection>

<self-protection>disabled</self-protection>

</engine>


-<system>

<osversion>Windows 7 Service Pack 1</osversion>

<arch>x64</arch>

<username>wh</username>

<filesys>NTFS</filesys>

</system>


-<summary>

<type>threat</type>

<result>completed</result>

<objects>283570</objects>

<time>459</time>

<processes>1</processes>

<modules>0</modules>

<keys>58</keys>

<values>0</values>

<datas>0</datas>

<folders>1</folders>

<files>18</files>

<sectors>0</sectors>

</summary>


-<options>

<memory>enabled</memory>

<startup>enabled</startup>

<filesystem>enabled</filesystem>

<archives>enabled</archives>

<rootkits>disabled</rootkits>

<deeprootkit>disabled</deeprootkit>

<heuristics>enabled</heuristics>

<pup>enabled</pup>

<pum>enabled</pum>

</options>


-<items>


-<process>

<path>C:\ProgramData\SnowApp\SW-Booster\SW-Booster.exe</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>delete-on-reboot</action>

<pid>3020</pid>

<hash>b50ad6a26a1167cf3ae7e154dc255ca4</hash>

</process>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\S-5121721648</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>b50ad6a26a1167cf3ae7e154dc255ca4</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\safewebo.safewebo</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\safewebo.safewebo.1.1</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\safewebo.safewebo</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\safewebo.safewebo.1.1</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{34A9B414-3293-B5DA-1593-4E442618C1DA}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{34A9B414-3293-B5DA-1593-4E442618C1DA}\INPROCSERVER32</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\DigiSauvEr.DigiSauvEr</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\DigiSauvEr.DigiSauvEr.6.7</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\DigiSauvEr.DigiSauvEr</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\DigiSauvEr.DigiSauvEr.6.7</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{6F587A6B-2A4E-193F-7512-80432E6EAEAF}\INPROCSERVER32</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\DealExPress.DealExPress</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\DealExPress.DealExPress.2.1</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealExPress.DealExPress</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealExPress.DealExPress.2.1</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{7BA50BFC-37BC-4593-F140-A684FA5E16AD}\INPROCSERVER32</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\EExstRaaSaavingus.EExstRaaSaavingus</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\EExstRaaSaavingus.EExstRaaSaavingus.4.2</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\EExstRaaSaavingus.EExstRaaSaavingus</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\EExstRaaSaavingus.EExstRaaSaavingus.4.2</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{A2750502-DCC3-EA71-08C7-CBF4719CCC0F}\INPROCSERVER32</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{25F259ED-12F6-429F-5783-527C3E2F8586}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a31c5226e9920135c4ba3f0ec93819e7</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{7223EDAC-E091-B3C1-BD91-B66CE557800F}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>457a3b3d9dde1b1bd0aebb926899f010</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{C637A71C-A4B2-4B47-1B2A-1042A8D525A3}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>ead5a5d3b9c286b08fef2726639e966a</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{497C131E-2032-051B-B32A-C69A960FBB13}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>3b84770188f3dd596b1360ed37ca6799</hash>

</key>


-<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4820778D-AB0D-6D18-C316-52A6A0E1D507}</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cbf4a0d82b5048ee8cf2490434cd2ed2</hash>

</key>


-<folder>

<path>C:\ProgramData\YoutubeAdblocker</path>

<vendor>PUP.Optional.YoutubeAdblocker.A</vendor>

<action>success</action>

<hash>97280870a8d363d350e4662753afdb25</hash>

</folder>


-<file>

<path>C:\ProgramData\SnowApp\SW-Booster\SW-Booster.exe</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>delete-on-reboot</action>

<hash>b50ad6a26a1167cf3ae7e154dc255ca4</hash>

</file>


-<file>

<path>C:\Program Files (x86)\safeweb\r.x64.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</file>


-<file>

<path>C:\Program Files (x86)\safeweb\r.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a11ebeba96e54de9601e58f518e930d0</hash>

</file>


-<file>

<path>C:\ProgramData\DigiSiAAVere\k_9XP5.x64.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</file>


-<file>

<path>C:\ProgramData\DigiSiAAVere\k_9XP5.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>10af591fd0ab70c6b6c8d07dca37619f</hash>

</file>


-<file>

<path>C:\ProgramData\DealEEXpress\0l4ge5cbC.x64.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</file>


-<file>

<path>C:\ProgramData\DealEEXpress\0l4ge5cbC.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cef17ff93c3fb0860d7157f6af5228d8</hash>

</file>


-<file>

<path>C:\ProgramData\ExxsTrauSavings\0IX5N.x64.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</file>


-<file>

<path>C:\ProgramData\ExxsTrauSavings\0IX5N.dll</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>bb04f8807605f145e39b8dc0d52c3fc1</hash>

</file>


-<file>

<path>C:\ProgramData\DealEEXpress\0l4ge5cbC.exe</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>a31c5226e9920135c4ba3f0ec93819e7</hash>

</file>


-<file>

<path>C:\ProgramData\DigiSiAAVere\k_9XP5.exe</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>457a3b3d9dde1b1bd0aebb926899f010</hash>

</file>


-<file>

<path>C:\ProgramData\ExxsTrauSavings\0IX5N.exe</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>ead5a5d3b9c286b08fef2726639e966a</hash>

</file>


-<file>

<path>C:\ProgramData\safeweb\Fo.exe</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>3b84770188f3dd596b1360ed37ca6799</hash>

</file>


-<file>

<path>C:\ProgramData\YoutubeAdblocker\9misNOTlm.exe</path>

<vendor>PUP.Optional.MultiPlug.A</vendor>

<action>success</action>

<hash>cbf4a0d82b5048ee8cf2490434cd2ed2</hash>

</file>


-<file>

<path>C:\Users\wh\Downloads\UltimateCodec.exe</path>

<vendor>PUP.Optional.InstallCore</vendor>

<action>success</action>

<hash>b30c91e7d9a24fe7ba9aaf9e966e768a</hash>

</file>


-<file>

<path>C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage</path>

<vendor>PUP.Optional.Superfish.A</vendor>

<action>success</action>

<hash>e6d9a7d17b00053111843f695ba79070</hash>

</file>


-<file>

<path>C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal</path>

<vendor>PUP.Optional.Superfish.A</vendor>

<action>success</action>

<hash>f7c8a0d82853a294aee77236cd3516ea</hash>

</file>


-<file>

<path>C:\Windows\Tasks\SW-Booster-S-5121721648.job</path>

<vendor>PUP.Optional.SWBooster.A</vendor>

<action>success</action>

<hash>c4fbc5b3df9c9a9c39f78d269072867a</hash>

</file>

</items>

</mbam-log>


Kann mir jemand helfen?

Alt 15.06.2014, 19:05   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Bekomme "search.gadgetbox" nicht weg - Standard

Bekomme "search.gadgetbox" nicht weg



hi,

Addition.txt von FRST fehlt noch


So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________

__________________

Alt 25.06.2014, 20:13   #3
Frontschwein
 
Bekomme "search.gadgetbox" nicht weg - Standard

Bekomme "search.gadgetbox" nicht weg



So, jetzt endlich den fehlenden log.

Gruss, Wolfgang





Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-06-2014 02
Ran by wh at 2014-06-15 17:28:05
Running from C:\Users\wh\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

==================== Installed Programs ======================

„Windows Live Essentials“ (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
„Windows Live Mail“ (x32 Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden
„Windows Live Messenger“ (x32 Version: 15.4.3538.0513 - „Microsoft Corporation“) Hidden
„Windows Live“ fotogalerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version:  - )
ABattleMap (HKLM-x32\...\ABattleMap) (Version:  - )
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.5.1.17730 - Adobe Systems Inc.)
Adobe AIR (x32 Version: 2.5.1.17730 - Adobe Systems Inc.) Hidden
Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.44 - Adobe Systems Incorporated)
Assistant (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{699fd52f}) (Version:  - Verified Publisher) <==== ATTENTION
Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros)
Bing Bar (HKLM-x32\...\{3365E735-48A6-4194-9988-CE59AC5AE503}) (Version: 7.3.132.0 - Microsoft Corporation)
CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.4417 - CyberLink Corp.)
CyberLink YouCam (x32 Version: 3.1.4417 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Easy File Share (HKLM-x32\...\{12F81925-F3C1-40DB-91F7-777817974319}) (Version: 1.1.1705 - Samsung Electronics Co., Ltd.)
Easy Migration (HKLM-x32\...\{AD86049C-3D9C-43E1-BE73-643F57D83D50}) (Version: 1.0 - Samsung Electronics Co., Ltd.)
Easy Settings (HKLM-x32\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 1.2 - Samsung Electronics Co., Ltd.)
Easy Support Center 1.0 (HKLM-x32\...\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.44 - Samsung)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Foxit Reader (HKLM-x32\...\{27E3028E-06C8-4C09-8C3E-07F7F508304E}) (Version: 5.3.1.606 - Foxit Corporation)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2559 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.5.1001 - Intel Corporation)
Interactive Guide (HKLM-x32\...\{CB383BE9-7518-4ABD-826E-8FC4695F7D52}) (Version: 1.1 - )
Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217055FF}) (Version: 7.0.550 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50917.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
Multimedia POP (HKLM-x32\...\{331ECF61-69AF-4F57-AC35-AFED610231C3}) (Version: 1.1 - )
NewiSSAVer (HKLM-x32\...\{6A08B379-76FB-B4CF-0C70-CAFCD3635A77}) (Version:  - NewSaverr)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.214.0 - Tracker Software Products Ltd)
Play Touch AP News (HKLM-x32\...\{9A4E56F9-EABB-49C2-9787-4D3200773D48}) (Version: 1.0.0 - Samsung Electronics CO., LTD)
Play Touch Bing Map (HKLM-x32\...\{A36ED6C1-A332-49EC-9C59-F8B895AB68B7}) (Version: 1.0.0 - Samsung Electronics CO., LTD.)
Play Touch Calendar (HKLM-x32\...\{85F969B2-AA3B-4CED-A8E9-C48A7E5EB0D5}) (Version: 1.2.0 - Samsung Electronics CO., LTD.)
Play Touch Camera (HKLM-x32\...\{D2384412-4C54-4CA8-A401-3426647E4EED}) (Version: 1.0 - Samsung Electronics CO., LTD.)
Play Touch Clock (HKLM-x32\...\{59095C47-04DA-43C2-A9C6-4602A5698E62}) (Version: 1.0 - Samsung Electronics CO., LTD.)
Play Touch Launcher (HKLM-x32\...\{AE15515C-6A4E-4663-B0F0-6C61E802EBA6}) (Version: 1.2.0 - Samsung Electronics CO., LTD.)
Play Touch Music (HKLM-x32\...\{7C5AB932-40D7-405F-88ED-BD0939D665F3}) (Version: 1.2.0 - Samsung Electronics CO., LTD.)
Play Touch Notes (HKLM-x32\...\{E2B70FDD-1A57-4879-912F-0391D3F97158}) (Version: 1.2.0 - Samsung Electronics CO., LTD)
Play Touch Photos (HKLM-x32\...\{6ADF618A-62B9-454B-A806-A3DA2124B7C8}) (Version: 1.0.0 - Samsung Electronics CO., LTD.)
Play Touch Recipe (HKLM-x32\...\{DA13F475-9DB2-4CCA-A625-D99655CFEC1E}) (Version: 1.0 - Samsung Electronics CO., LTD.)
Play Touch RssReader (HKLM-x32\...\{4ADADD44-1B08-480A-BE9C-8E8E5B808EB4}) (Version: 1.0 - Samsung Electronics CO., LTD.)
Play Touch SocialDashboard (HKLM-x32\...\{A925AE13-A1FC-4D06-B93D-EA9041E22158}) (Version: 1.2.0 - Samsung Electronics CO., LTD)
Play Touch ToDo (HKLM-x32\...\{ACA0C8D8-5D60-4948-8447-23FCE6F89180}) (Version: 1.0 - Samsung Electronics CO., LTD.)
Play Touch Twitter (HKLM-x32\...\{E5679BCC-EA6F-42FD-88E7-431CDCC5A1C1}) (Version: 1.0.0 - Samsung Electronics CO., LTD.)
Play Touch Videos (HKLM-x32\...\{2BD864E7-3FAB-4BFF-9B85-0A11B64917AA}) (Version: 1.0.0 - Samsung Electronics CO., LTD.)
Play Touch Weather (HKLM-x32\...\{6274342F-1F2D-4823-857D-D98CCCFF81E3}) (Version: 1.0 - Samsung Electronics CO., LTD.)
Play Touch Yahoo! Finance (HKLM-x32\...\{2B1693AA-518D-48A5-B367-7B7DCA69FCFD}) (Version: 1.0.0 - Samsung Electronics CO., LTD)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.45.516.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6428 - Realtek Semiconductor Corp.)
S Agent (Version: 1.1.45 - Samsung Electronics CO., LTD.) Hidden
Sam and Max - Season One - Episode 104 - Abe Lincoln Must Die! (HKLM-x32\...\Episode 104 - Abe Lincoln Must Die!) (Version: 1.1.0.0-free - Telltale Games)
Samsung Recovery Solution 5 (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.1.8 - Samsung)
Skype™ 4.2 (HKLM-x32\...\{D103C4BA-F905-437A-8049-DB24763BBE36}) (Version: 4.2.169 - Skype Technologies S.A.)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.3.39 - Safer-Networking Ltd.)
StarMoney (x32 Version: 4.0.4.16 - StarFinanz) Hidden
StarMoney 9.0 apoEdition (HKLM-x32\...\{6E8F4B25-7917-468D-88C1-973289FAA3AD}) (Version: 9.0 - Star Finanz GmbH)
STMicroelectronics 6-Axis Accelerometer/Magnetometer (HKLM-x32\...\{149A7D75-8384-4FFD-8352-8D24B791C187}) (Version: 1.01.0015 - STMicroelectronics)
SW Update (HKLM-x32\...\{DA06101F-FD76-4BF0-88BD-B26A197005E3}) (Version: 2.1.21 - Samsung Electronics CO., LTD.)
Swype Windows 7 Keyboard (HKLM-x32\...\{E3ADF160-19FE-4E52-A7F4-B351A947541E}) (Version: 3.21.91 - Swype Inc)
Touch Logon (HKLM\...\{AFF0220E-1F50-4B46-91BF-7812F71275F0}) (Version: 2.0.0 - Samsung Electronics CO., LTD.)
Touch Supporter (HKLM-x32\...\{B6B5B296-3B3F-4905-BF7A-364D0E2A885B}) (Version: 1.2 - Samsung Electronics CO., LTD.)
UseNeXT by Tangysoft (HKLM-x32\...\UseNeXT by Tangysoft_is1) (Version:  - Tangysoft Ltd.)
User Guide (HKLM-x32\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.5 - )
VLC media player 2.0.7 (HKLM\...\VLC media player) (Version: 2.0.7 - VideoLAN)
WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.8800 - Broadcom Corporation)
Windows Driver Package - Option (GTNDIS62) Net  (10/03/2011 5.1.39.6) (HKLM\...\1D45F67745BD36EB031E60661F338D64730B4C50) (Version: 10/03/2011 5.1.39.6 - Option)
Windows Driver Package - Option (GTUHSBUS) USB  (10/03/2011 5.1.39.6) (HKLM\...\04F8F81D628953F8EEB6E10DB45E45A2C96088C5) (Version: 10/03/2011 5.1.39.6 - Option)
Windows Driver Package - Option (GTUHSSC) SmartCardReader  (10/03/2011 5.1.39.6) (HKLM\...\ACBB3C54E7B7E6A96DFB02557A4DE86854D9824C) (Version: 10/03/2011 5.1.39.6 - Option)
Windows Driver Package - Option (GTUHSSER) Modem  (10/03/2011 5.1.39.6) (HKLM\...\97EB06054E77831A22357013034C284FD8E49B06) (Version: 10/03/2011 5.1.39.6 - Option)
Windows Driver Package - Option (GTUHSSER) Ports  (10/03/2011 5.1.39.6) (HKLM\...\DC2D911B68FEB58407B70F6E7421E60315D42444) (Version: 10/03/2011 5.1.39.6 - Option)
Windows Driver Package - Option (WUDFRd) Sensor  (10/03/2011 5.1.39.6) (HKLM\...\E490E8223436D6501D9A825E87FEDB49E7403CA2) (Version: 10/03/2011 5.1.39.6 - Option)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live fotoattēlu galerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogaléria (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Foto-galerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Galeria de Fotos (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Galerija fotografija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Pošta (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 메일 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 사진 갤러리 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 필수 패키지 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 照片库 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 程式集 (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 软件包 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
YouTube (HKLM-x32\...\{AD2F3CEC-BB79-4CA0-9D94-212E5A8CE6E1}) (Version: 1.00.0005 - (c) YouTube, LLC)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

==================== Restore Points  =========================

15-06-2014 14:10:40 Geplanter Prüfpunkt

==================== Hosts content: ==========================

2009-07-14 04:34 - 2014-06-15 14:22 - 00450709 ____R C:\windows\system32\Drivers\etc\hosts
127.0.0.1	www.007guard.com
127.0.0.1	007guard.com
127.0.0.1	008i.com
127.0.0.1	www.008k.com
127.0.0.1	008k.com
127.0.0.1	www.00hq.com
127.0.0.1	00hq.com
127.0.0.1	010402.com
127.0.0.1	www.032439.com
127.0.0.1	032439.com
127.0.0.1	www.0scan.com
127.0.0.1	0scan.com
127.0.0.1	1000gratisproben.com
127.0.0.1	www.1000gratisproben.com
127.0.0.1	1001namen.com
127.0.0.1	www.1001namen.com
127.0.0.1	100888290cs.com
127.0.0.1	www.100888290cs.com
127.0.0.1	www.100sexlinks.com
127.0.0.1	100sexlinks.com
127.0.0.1	10sek.com
127.0.0.1	www.10sek.com
127.0.0.1	www.1-2005-search.com
127.0.0.1	1-2005-search.com
127.0.0.1	123fporn.info
127.0.0.1	www.123fporn.info
127.0.0.1	123haustiereundmehr.com
127.0.0.1	www.123haustiereundmehr.com
127.0.0.1	123moviedownload.com

There are 1000 more lines.


==================== Scheduled Tasks (whitelisted) =============

Task: {00E01973-7A7C-4B3E-957D-8161867E4856} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2013-10-16] (Samsung Electronics CO., LTD.)
Task: {17EC16F2-7ACD-4DD7-BA45-456C469795E8} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2011-09-08] (SEC)
Task: {18B859AF-F83C-42CB-889E-3167CA74917E} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Easy Support Center\SSCKbdHk.exe [2011-10-12] (SAMSUNG Electronics)
Task: {212E54F6-0C01-43B2-BE42-F31824FC1CD7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd)
Task: {27C9DF39-171A-477C-AF06-55C18F5349F5} - System32\Tasks\SCCSpeedBoot => C:\Program Files (x86)\Samsung\Easy Settings\SCCSpeedBoot.exe [2011-12-07] ()
Task: {27D47635-479F-46FA-AF59-32380913A32D} - System32\Tasks\SmartSetting => C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe [2011-12-07] (Samsung Electronics Co., Ltd.)
Task: {36298DDB-B22B-46F6-B5A3-4AC8D922F904} - System32\Tasks\InputSupporterNLauncher => C:\Program Files (x86)\Samsung\Touch Supporter\InputSupporterNLauncher.exe [2011-12-08] (Samsung Electronics CO., LTD.)
Task: {3D5F761C-D5DF-4C4D-A1B6-3BBEC9F3550A} - System32\Tasks\SmartRotation => C:\Program Files (x86)\Samsung\Easy Settings\SmartRotation.exe [2011-12-07] (Samsung Electronics Co., Ltd.)
Task: {4871C9F3-7E69-4FAF-B833-14CC14A950BB} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\Easy Settings\EBM\EasyBatteryMgr4.exe [2011-09-22] (SAMSUNG Electronics co., LTD.)
Task: {4C4917CB-716D-4DC8-8712-112CEF93883D} - System32\Tasks\SmartRotation_setting => C:\Program Files (x86)\Samsung\Easy Settings\SmartRotation.exe [2011-12-07] (Samsung Electronics Co., Ltd.)
Task: {616EF816-F113-4A4F-8666-09A69125921B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-02-04] (Google Inc.)
Task: {69C1C9A1-E181-4BE7-8294-CE40401448E9} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation)
Task: {7017F540-78A7-442D-8197-095763DEBF78} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe [2011-12-07] (Samsung Electronics Co., Ltd.)
Task: {7B1ACA10-9CAB-47A0-BA04-089AF5314902} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe [2011-12-07] (Samsung Electronics)
Task: {8ACAF756-FF9F-40D5-9E01-0397FC9912CE} - System32\Tasks\LauncherStarter2 => C:\Program Files (x86)\Samsung\Play Touch\Touch Launcher\LauncherStarterCmd.exe [2012-01-09] (Samsung Electronics CO., LTD.)
Task: {9513EFA1-8BFB-4E61-A8AD-BC3FC1107385} - System32\Tasks\InputSupporter => C:\Program Files (x86)\Samsung\Touch Supporter\InputSupporter.exe [2011-12-08] (Samsung Electronics CO., LTD.)
Task: {AA7F97A9-3AB7-4A69-A6E5-0A60FF0D987D} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-08-17] (CyberLink)
Task: {B25C6487-574B-48B9-BCD3-BE86153A3DAF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-02-04] (Google Inc.)
Task: {B9BAB5F1-C3EE-4DEA-A29C-114894E1A87F} - System32\Tasks\LauncherStarter => C:\Program Files (x86)\Samsung\Play Touch\Touch Launcher\LauncherStarter.exe [2012-01-09] (Samsung Electronics CO., LTD.)
Task: {DD28D5BA-7E9C-43BD-8E55-102FE76A5FC1} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe [2011-12-07] (Samsung Electronics Co., Ltd.)
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-10-31 07:00 - 2011-10-21 02:49 - 00094208 _____ () C:\windows\system32\IccLibDll_x64.dll
2014-06-14 20:35 - 2014-04-25 14:11 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2014-06-14 20:35 - 2014-04-25 14:11 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2014-06-14 20:35 - 2014-04-25 14:11 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2014-06-14 20:35 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2014-06-14 20:35 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2014-04-18 14:33 - 2011-01-13 10:44 - 00232800 _____ () C:\Program Files (x86)\StarMoney 9.0 apoEdition\ouservice\PATCHW32.dll
2012-01-04 09:33 - 2011-09-22 07:30 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Settings\HookDllPS2.dll
2012-01-04 09:33 - 2011-09-22 07:30 - 00203776 _____ () C:\Program Files (x86)\Samsung\Easy Settings\WinCRT.dll
2012-01-04 09:40 - 2011-09-08 12:40 - 01645056 _____ () C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\Temp:B606BA34

==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== MSCONFIG/TASK MANAGER disabled items =========


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/15/2014 05:04:55 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/15/2014 01:34:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/15/2014 00:50:38 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddWin32ServiceFiles: Unable to back up image of service Assistant since QueryServiceConfig API failed

System Error:
Das System kann die angegebene Datei nicht finden.
.

Error: (06/13/2014 05:43:16 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
(Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Zurzeit sind keine aktiven Netzwerkverbindungen verfügbar. Der Vorgang wird von BITS wiederholt, sobald der Adapter über eine Verbindung verfügt.

Error: (06/11/2014 03:04:33 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/11/2014 02:47:31 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
(Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Zurzeit sind keine aktiven Netzwerkverbindungen verfügbar. Der Vorgang wird von BITS wiederholt, sobald der Adapter über eine Verbindung verfügt.

Error: (06/09/2014 11:11:41 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/03/2014 09:11:06 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
(Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Zurzeit sind keine aktiven Netzwerkverbindungen verfügbar. Der Vorgang wird von BITS wiederholt, sobald der Adapter über eine Verbindung verfügt.

Error: (06/01/2014 06:11:41 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
(Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Zurzeit sind keine aktiven Netzwerkverbindungen verfügbar. Der Vorgang wird von BITS wiederholt, sobald der Adapter über eine Verbindung verfügt.

Error: (06/01/2014 04:11:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (06/15/2014 05:04:58 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: 
cdrom

Error: (06/15/2014 01:34:59 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: 
cdrom

Error: (06/15/2014 01:21:07 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (06/14/2014 08:36:56 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (06/13/2014 05:43:15 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {C332C124-340D-4430-AA0D-C75602876FCC}

Error: (06/12/2014 08:31:41 PM) (Source: NetBT) (EventID: 4321) (User: )
Description: Der Name "WH-PC          :0" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.13
registriert werden. Der Computer mit IP-Adresse 192.168.0.14 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.

Error: (06/12/2014 08:31:41 PM) (Source: NetBT) (EventID: 4321) (User: )
Description: Der Name "WH-PC          :20" konnte nicht auf der Schnittstelle mit IP-Adresse 192.168.0.13
registriert werden. Der Computer mit IP-Adresse 192.168.0.14 hat nicht
zugelassen, dass dieser Computer diesen Namen verwendet.

Error: (06/12/2014 08:31:41 PM) (Source: Server) (EventID: 2505) (User: )
Description: Aufgrund eines doppelten Netzwerknamens konnte zu der Transportschicht \Device\NetBT_Tcpip_{91D3AE9B-E5F5-4972-AF1F-49BCA572313F} vom Serverdienst nicht gebunden werden. Der Serverdienst konnte nicht gestartet werden.

Error: (06/11/2014 08:51:51 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (06/11/2014 03:04:33 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Benutzerprofildienst" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler: 
%%1056


Microsoft Office Sessions:
=========================
Error: (06/15/2014 05:04:55 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/15/2014 01:34:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/15/2014 00:50:38 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: 
Details:
AddWin32ServiceFiles: Unable to back up image of service Assistant since QueryServiceConfig API failed

System Error:
Das System kann die angegebene Datei nicht finden.

Error: (06/13/2014 05:43:16 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Zurzeit sind keine aktiven Netzwerkverbindungen verfügbar. Der Vorgang wird von BITS wiederholt, sobald der Adapter über eine Verbindung verfügt.

Error: (06/11/2014 03:04:33 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/11/2014 02:47:31 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Zurzeit sind keine aktiven Netzwerkverbindungen verfügbar. Der Vorgang wird von BITS wiederholt, sobald der Adapter über eine Verbindung verfügt.

Error: (06/09/2014 11:11:41 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/03/2014 09:11:06 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Zurzeit sind keine aktiven Netzwerkverbindungen verfügbar. Der Vorgang wird von BITS wiederholt, sobald der Adapter über eine Verbindung verfügt.

Error: (06/01/2014 06:11:41 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: (Patch task for {90140011-0066-0407-0000-0000000FF1CE}): DownloadLatest Failed: Zurzeit sind keine aktiven Netzwerkverbindungen verfügbar. Der Vorgang wird von BITS wiederholt, sobald der Adapter über eine Verbindung verfügt.

Error: (06/01/2014 04:11:57 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


==================== Memory info =========================== 

Percentage of memory in use: 32%
Total physical RAM: 4008.3 MB
Available physical RAM: 2721.64 MB
Total Pagefile: 7333.91 MB
Available Pagefile: 5897.25 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:59.03 GB) (Free:0.88 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 60 GB) (Disk ID: BA51655C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=59 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=512 MB) - (Type=27)

==================== End Of Log ============================
         
__________________

Alt 26.06.2014, 20:26   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Bekomme "search.gadgetbox" nicht weg - Standard

Bekomme "search.gadgetbox" nicht weg



Adware & Co. deinstallieren
  • Lade Dir bitte von hier Revo Uninstaller herunter.
  • Installiere und starte das Programm.
  • Suche im Uninstallerfeld nach den Programmen, die unter:

    diesen Zusatz haben:
  • Wähle die Programme nacheinander aus und klicke jedesmal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .

Solltest Du ein Programm nicht finden oder nicht deinstallieren können, mache bitte mit dem nächsten Schritt weiter:




Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 29.06.2014, 16:04   #5
Frontschwein
 
Bekomme "search.gadgetbox" nicht weg - Standard

Bekomme "search.gadgetbox" nicht weg



Hier die angeforderten logs, bin mal gespannt, wies jetzt aussieht



Code:
ATTFilter
<?xml version="1.0" encoding="UTF-16"?>
@namespace html url(hxxp://www.w3.org/1999/xhtml); :root {                       font:small Verdana;        font-weight: bold;         padding: 2em;              padding-left:4em;       }                          * {                           display: block;            padding-left: 2em;      }                          html|style {                  display: none;          }                          html|span, html|a {           display: inline;           padding: 0;                font-weight: normal;       text-decoration: none;  }                          html|span.block {             display: block;         }                          *[html|hidden],            span.block[html|hidden] {     display: none;          }                          .expand {                     display: block;         }                          .expand:before {              content: '+';              color: red;                position: absolute;        left: -1em;             }  .collapse {                   display: block;         }                          .collapse:before {            content: '-';              color: red;                position: absolute;        left:-1em;              }                         
<mbam-log>


<header>

<date>2014/06/29 16:07:59 +0200</date>

<logfile>mbam-log-2014-06-29 (16-07-49).xml</logfile>

<isadmin>yes</isadmin>

</header>


<engine>

<version>2.00.2.1012</version>

<malware-database>v2014.06.29.05</malware-database>

<rootkit-database>v2014.06.23.02</rootkit-database>

<license>free</license>

<file-protection>disabled</file-protection>

<web-protection>disabled</web-protection>

<self-protection>disabled</self-protection>

</engine>


<system>

<osversion>Windows 7 Service Pack 1</osversion>

<arch>x64</arch>

<username>wh</username>

<filesys>NTFS</filesys>

</system>


<summary>

<type>threat</type>

<result>completed</result>

<objects>288567</objects>

<time>467</time>

<processes>0</processes>

<modules>0</modules>

<keys>12</keys>

<values>0</values>

<datas>0</datas>

<folders>2</folders>

<files>4</files>

<sectors>0</sectors>

</summary>


<options>

<memory>enabled</memory>

<startup>enabled</startup>

<filesystem>enabled</filesystem>

<archives>enabled</archives>

<rootkits>disabled</rootkits>

<deeprootkit>disabled</deeprootkit>

<heuristics>enabled</heuristics>

<pup>enabled</pup>

<pum>enabled</pum>

</options>


<items>


<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{8711D30F-7582-8372-36D2-F2B0BAC36D33}</path>

<vendor>PUP.Optional.MultiPlug</vendor>

<action>success</action>

<hash>f742235b92e9cd698e4dccc6c63b24dc</hash>

</key>


<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER 
OBJECTS\{8711D30F-7582-8372-36D2-F2B0BAC36D33}</path>

<vendor>PUP.Optional.MultiPlug</vendor>

<action>success</action>

<hash>f742235b92e9cd698e4dccc6c63b24dc</hash>

</key>


<key>

<path>HKLM\SOFTWARE\CLASSES\NewSaverr.NewSaverr</path>

<vendor>PUP.Optional.MultiPlug</vendor>

<action>success</action>

<hash>f742235b92e9cd698e4dccc6c63b24dc</hash>

</key>


<key>

<path>HKLM\SOFTWARE\CLASSES\NewSaverr.NewSaverr.1.1</path>

<vendor>PUP.Optional.MultiPlug</vendor>

<action>success</action>

<hash>f742235b92e9cd698e4dccc6c63b24dc</hash>

</key>


<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\NewSaverr.NewSaverr</path>

<vendor>PUP.Optional.MultiPlug</vendor>

<action>success</action>

<hash>f742235b92e9cd698e4dccc6c63b24dc</hash>

</key>


<key>

<path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\NewSaverr.NewSaverr.1.1</path>

<vendor>PUP.Optional.MultiPlug</vendor>

<action>success</action>

<hash>f742235b92e9cd698e4dccc6c63b24dc</hash>

</key>


<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{8711D30F-7582-8372-36D2-F2B0BAC36D33}</path>

<vendor>PUP.Optional.MultiPlug</vendor>

<action>success</action>

<hash>f742235b92e9cd698e4dccc6c63b24dc</hash>

</key>


<key>

<path>HKU\S-1-5-21-3424567567-1130603173-978095989-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{8711D30F-7582-8372-36D2-F2B0BAC36D33}</path>

<vendor>PUP.Optional.MultiPlug</vendor>

<action>success</action>

<hash>f742235b92e9cd698e4dccc6c63b24dc</hash>

</key>


<key>

<path>HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{8711D30F-7582-8372-36D2-F2B0BAC36D33}</path>

<vendor>PUP.Optional.MultiPlug</vendor>

<action>success</action>

<hash>f742235b92e9cd698e4dccc6c63b24dc</hash>

</key>


<key>

<path>HKLM\SOFTWARE\CLASSES\CLSID\{8711D30F-7582-8372-36D2-F2B0BAC36D33}\INPROCSERVER32</path>

<vendor>PUP.Optional.MultiPlug</vendor>

<action>success</action>

<hash>f742235b92e9cd698e4dccc6c63b24dc</hash>

</key>


<key>

<path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{6A08B379-76FB-B4CF-0C70-CAFCD3635A77}</path>

<vendor>PUP.Optional.Multiplug</vendor>

<action>success</action>

<hash>ca6fbec091ea4cea7468bcd6936eb44c</hash>

</key>


<key>

<path>HKLM\SOFTWARE\WOW6432NODE\SW-Booster</path>

<vendor>PUP.Optional.SWBooster.A</vendor>

<action>success</action>

<hash>a396710d84f71d199770525e719113ed</hash>

</key>


<folder>

<path>C:\ProgramData\SnowApp\SW-Booster</path>

<vendor>PUP.Optional.WSBooster.A</vendor>

<action>success</action>

<hash>66d30777d8a3c96d44eac5e6837fa957</hash>

</folder>


<folder>

<path>C:\ProgramData\SnowApp\SW-Booster\5121721648</path>

<vendor>PUP.Optional.WSBooster.A</vendor>

<action>success</action>

<hash>66d30777d8a3c96d44eac5e6837fa957</hash>

</folder>


<file>

<path>C:\ProgramData\NewiSSAVer\RK9UOieO.x64.dll</path>

<vendor>PUP.Optional.MultiPlug</vendor>

<action>success</action>

<hash>f742235b92e9cd698e4dccc6c63b24dc</hash>

</file>


<file>

<path>C:\ProgramData\NewiSSAVer\RK9UOieO.dll</path>

<vendor>PUP.Optional.MultiPlug</vendor>

<action>success</action>

<hash>94a52f4f760590a65189642ee02114ec</hash>

</file>


<file>

<path>C:\ProgramData\NewiSSAVer\RK9UOieO.exe</path>

<vendor>PUP.Optional.Multiplug</vendor>

<action>success</action>

<hash>ca6fbec091ea4cea7468bcd6936eb44c</hash>

</file>


<file>

<path>C:\ProgramData\SnowApp\SW-Booster\5121721648.ini</path>

<vendor>PUP.Optional.WSBooster.A</vendor>

<action>success</action>

<hash>66d30777d8a3c96d44eac5e6837fa957</hash>

</file>

</items>

</mbam-log>
         


Code:
ATTFilter
# AdwCleaner v3.213 - Bericht erstellt am 29/06/2014 um 16:21:03
# Aktualisiert 23/06/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : wh - WH-PC
# Gestartet von : C:\Users\wh\Downloads\adwcleaner_3.213.exe
# Option : Suchen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gefunden : C:\Program Files (x86)\safeweb
Ordner Gefunden : C:\Program Files (x86)\SW-Booster
Ordner Gefunden : C:\ProgramData\Assistant
Ordner Gefunden : C:\ProgramData\DealEEXpress
Ordner Gefunden : C:\ProgramData\DigiSiAAVere
Ordner Gefunden : C:\ProgramData\ExxsTrauSavings
Ordner Gefunden : C:\ProgramData\NewiSSAVer
Ordner Gefunden : C:\ProgramData\safeweb
Ordner Gefunden : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fenibeobibfgjidgojgihemcpcigegmd
Ordner Gefunden : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmpodcogibpchhapceifdcbggbbdcemm
Ordner Gefunden : C:\Users\Administrator\AppData\Local\torch
Ordner Gefunden : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\fenibeobibfgjidgojgihemcpcigegmd
Ordner Gefunden : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmpodcogibpchhapceifdcbggbbdcemm
Ordner Gefunden : C:\Users\Gast\AppData\Local\torch
Ordner Gefunden : C:\Users\wh\AppData\Local\torch

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Daten Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\assist~1\assist~1.dll
Daten Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~3\ASSIST~1\ASSIST~2.DLL
Schlüssel Gefunden : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Schlüssel Gefunden : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Schlüssel Gefunden : HKCU\Software\RegisteredApplicationsEx
Schlüssel Gefunden : [x64] HKCU\Software\RegisteredApplicationsEx
Schlüssel Gefunden : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gefunden : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Schlüssel Gefunden : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17126

Einstellung Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://search.gboxapp.com/

-\\ Google Chrome v34.0.1847.116

[ Datei : C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Gefunden [Homepage] : hxxp://search.gboxapp.com/

*************************

AdwCleaner[R0].txt - [2721 octets] - [29/06/2014 16:21:03]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [2781 octets] ##########
         
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by wh on 29.06.2014 at 16:28:08,64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.06.2014 at 16:37:08,54
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-06-2014 02
Ran by wh (administrator) on WH-PC on 29-06-2014 16:54:06
Running from C:\Users\wh\Downloads
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Play Touch\Touch Launcher\LauncherStarterCmd.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Touch Supporter\InputSupporterNLauncher.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Touch Supporter\InputSupporter.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Play Touch\Touch Launcher\LauncherStarter.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0 apoEdition\ouservice\StarMoneyOnlineUpdate.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartRotation.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Easy Support Center\SSCKbdHk.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12661352 2011-08-01] (Realtek Semiconductor)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101584 2014-04-25] (Safer-Networking Ltd.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-3424567567-1130603173-978095989-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566984 2014-04-25] (Safer-Networking Ltd.)
HKU\S-1-5-21-3424567567-1130603173-978095989-1000\...\MountPoints2: {5e394242-c7b7-11e3-af9f-24ec994b3939} - D:\LaunchU3.exe -a
Lsa: [Notification Packages] scecli ConfigFilter
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2

FireFox:
========
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50917.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)

Chrome: 
=======
CHR HomePage: hxxp://search.gboxapp.com/
CHR StartupUrls: "https://www.google.com/"
CHR Extension: (Google Docs) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-04]
CHR Extension: (Google Drive) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-04]
CHR Extension: (YouTube) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-04]
CHR Extension: (Google-Suche) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-04]
CHR Extension: (Google Wallet) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-04]
CHR Extension: (Google Mail) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-04]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738200 2014-04-25] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2081752 2014-04-25] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0 apoEdition\ouservice\StarMoneyOnlineUpdate.exe [663184 2014-01-27] (Star Finanz-Software Entwicklung und Vertriebs GmbH)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.)

==================== Drivers (Whitelisted) ====================

S3 AX88772; C:\Windows\System32\DRIVERS\ax88772.sys [77312 2010-05-31] (ASIX Electronics Corp.)
R3 GTNDIS62; C:\Windows\System32\DRIVERS\Gtuhs62.sys [208384 2011-10-03] (Option N.V.)
R3 GTUHSBUS; C:\Windows\System32\DRIVERS\gtuhsbus.sys [214528 2011-10-03] (Option N.V.)
R3 GTUHSSER; C:\Windows\System32\DRIVERS\gtuhsser.sys [12032 2011-10-03] (Option N.V.)
R3 LSM303DLH; C:\Windows\System32\DRIVERS\LSM303DLH.sys [61040 2011-08-19] (STMicroelectronics)
R2 SGDrv; C:\Windows\System32\DRIVERS\SGdrv64.sys [7680 2011-04-11] (Phoenix Technologies Ltd.)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-29 16:53 - 2014-06-29 16:53 - 00000000 ____D () C:\Users\wh\Downloads\FRST-OlderVersion
2014-06-29 16:37 - 2014-06-29 16:37 - 00000622 _____ () C:\Users\wh\Desktop\JRT.txt
2014-06-29 16:21 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll
2014-06-29 16:17 - 2014-06-29 16:23 - 00002000 _____ () C:\windows\PFRO.log
2014-06-29 11:30 - 2014-06-29 11:30 - 01016261 _____ (Thisisu) C:\Users\wh\Downloads\JRT.exe
2014-06-29 11:30 - 2014-06-29 11:30 - 00000000 ____D () C:\windows\ERUNT
2014-06-29 11:29 - 2014-06-29 16:25 - 00000000 ____D () C:\AdwCleaner
2014-06-29 11:28 - 2014-06-29 11:28 - 01342659 _____ () C:\Users\wh\Downloads\adwcleaner_3.213.exe
2014-06-29 11:28 - 2014-06-29 11:28 - 00001264 _____ () C:\Users\wh\Desktop\Revo Uninstaller.lnk
2014-06-29 11:28 - 2014-06-29 11:28 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-29 11:27 - 2014-06-29 11:27 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\wh\Downloads\revosetup95.exe
2014-06-19 08:34 - 2014-06-29 16:23 - 00000896 _____ () C:\windows\setupact.log
2014-06-19 08:34 - 2014-06-19 08:34 - 00000000 _____ () C:\windows\setuperr.log
2014-06-19 08:24 - 2014-06-19 08:24 - 00146472 _____ () C:\Users\wh\Documents\cc_20140619_082420.reg
2014-06-15 17:31 - 2014-06-15 16:53 - 00037162 _____ () C:\Users\wh\Desktop\mbam-log-2014-06-15 (16-44-52).xml
2014-06-15 17:29 - 2014-06-15 17:29 - 00046683 _____ () C:\Users\wh\Desktop\FRST.txt
2014-06-15 17:28 - 2014-06-15 17:28 - 00032795 _____ () C:\Users\wh\Downloads\Addition.txt
2014-06-15 17:27 - 2014-06-29 16:54 - 00012520 _____ () C:\Users\wh\Downloads\FRST.txt
2014-06-15 17:27 - 2014-06-29 16:54 - 00000000 ____D () C:\FRST
2014-06-15 17:26 - 2014-06-29 16:53 - 02083328 _____ (Farbar) C:\Users\wh\Downloads\FRST64.exe
2014-06-15 16:44 - 2014-06-29 16:07 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-15 16:43 - 2014-06-15 16:43 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\wh\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-15 16:43 - 2014-06-15 16:43 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-15 16:43 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-06-15 16:43 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-06-15 16:43 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-06-15 14:22 - 2009-06-10 23:00 - 00000824 _____ () C:\windows\system32\Drivers\etc\hosts.20140615-142237.backup
2014-06-15 12:53 - 2014-06-15 12:53 - 00859992 _____ () C:\Users\wh\Downloads\snlTCNTplugins01.zip
2014-06-15 11:36 - 2009-06-10 23:00 - 00000824 _____ () C:\windows\system32\Drivers\etc\hosts.20140615-113648.backup
2014-06-15 00:50 - 2014-06-15 00:50 - 00000990 _____ () C:\windows\wininit.ini
2014-06-14 20:35 - 2014-06-15 11:34 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-06-14 20:35 - 2014-06-14 20:36 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-06-14 20:35 - 2014-06-14 20:35 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-06-14 20:35 - 2014-06-14 20:35 - 00001379 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-06-14 20:35 - 2014-06-14 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-06-14 20:35 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\windows\system32\sdnclean64.exe
2014-06-14 20:33 - 2014-06-14 20:33 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\wh\Downloads\spybot-2.3.exe
2014-06-10 20:09 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-10 20:09 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-10 20:09 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-06-10 20:09 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-06-10 20:09 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-06-10 20:09 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-06-10 20:09 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-06-10 20:09 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-06-10 20:09 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-06-10 20:09 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-06-10 20:09 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-06-10 20:09 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-06-10 20:09 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-06-10 20:09 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-06-10 20:09 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-06-10 20:09 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-06-10 20:09 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-06-10 20:09 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-06-10 20:09 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-06-10 20:09 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-06-10 20:09 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-06-10 20:09 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-06-10 20:09 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-06-10 20:09 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-06-10 20:09 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-06-10 20:09 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-06-10 20:09 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-06-10 20:09 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-06-10 20:09 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-06-10 20:09 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-06-10 20:09 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-06-10 20:09 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-06-10 20:09 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-06-10 20:09 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-06-10 20:09 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-06-10 20:09 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-06-10 20:09 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-06-10 20:09 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-06-10 20:09 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-10 20:09 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-06-10 20:09 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-06-10 20:09 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-06-10 20:09 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-06-10 20:09 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-06-10 20:09 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-06-10 20:09 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-06-10 20:09 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-06-10 20:09 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-06-10 20:09 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-06-10 20:09 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-06-10 20:09 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-06-10 20:09 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-06-10 20:09 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-06-10 20:09 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-06-10 20:09 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\usp10.dll
2014-06-10 20:09 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\windows\SysWOW64\usp10.dll
2014-06-10 20:09 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2014-06-10 20:09 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2014-06-10 20:09 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2014-06-10 20:09 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2014-06-10 20:09 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml6r.dll
2014-06-10 20:09 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\msxml3r.dll
2014-06-10 20:09 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2014-06-10 20:09 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2014-06-10 20:09 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6r.dll
2014-06-10 20:09 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3r.dll
2014-06-09 11:09 - 2014-06-11 14:47 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-06-09 10:48 - 2014-06-09 10:48 - 00000056 _____ () C:\Users\wh\Downloads\heavy-metal.m3u
2014-06-03 21:33 - 2014-06-03 21:33 - 00003279 _____ () C:\Users\wh\Downloads\2-09399-g-06.AAM
2014-06-02 20:14 - 2014-06-02 20:14 - 00003303 _____ () C:\Users\wh\Downloads\2-09399-r-06.AAM
2014-06-01 18:15 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2014-06-01 18:15 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2014-06-01 18:15 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2014-06-01 18:15 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2014-06-01 18:15 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2014-06-01 18:15 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2014-06-01 18:15 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2014-06-01 18:15 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2014-06-01 18:15 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2014-06-01 18:15 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2014-06-01 18:15 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2014-06-01 18:15 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2014-06-01 18:15 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\windows\system32\objsel.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-06-01 18:15 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\wincredprovider.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2014-06-01 18:15 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\cngprovider.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\adprovider.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\capiprovider.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\dpapiprovider.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\dimsroam.dll
2014-06-01 18:15 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-06-01 18:15 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2014-06-01 18:15 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2014-06-01 18:15 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\windows\SysWOW64\objsel.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\cngprovider.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\windows\SysWOW64\adprovider.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\windows\SysWOW64\capiprovider.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dpapiprovider.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\dimsroam.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wincredprovider.dll
2014-06-01 18:15 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-06-01 18:15 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2014-06-01 18:11 - 2014-06-09 10:40 - 00000000 ____D () C:\ProgramData\VirtualizedApplications
2014-06-01 16:12 - 2014-06-01 16:12 - 00003303 _____ () C:\Users\wh\Downloads\2-09399-u-05.AAM
2014-05-31 17:37 - 2014-05-31 17:37 - 00003111 _____ () C:\Users\wh\Downloads\2-09384-r-06.AAM

==================== One Month Modified Files and Folders =======

2014-06-29 16:54 - 2014-06-15 17:27 - 00012520 _____ () C:\Users\wh\Downloads\FRST.txt
2014-06-29 16:54 - 2014-06-15 17:27 - 00000000 ____D () C:\FRST
2014-06-29 16:53 - 2014-06-29 16:53 - 00000000 ____D () C:\Users\wh\Downloads\FRST-OlderVersion
2014-06-29 16:53 - 2014-06-15 17:26 - 02083328 _____ (Farbar) C:\Users\wh\Downloads\FRST64.exe
2014-06-29 16:41 - 2012-01-04 09:25 - 01146339 _____ () C:\windows\WindowsUpdate.log
2014-06-29 16:38 - 2014-02-04 01:27 - 00001102 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-29 16:37 - 2014-06-29 16:37 - 00000622 _____ () C:\Users\wh\Desktop\JRT.txt
2014-06-29 16:30 - 2009-07-14 06:45 - 00021216 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-29 16:30 - 2009-07-14 06:45 - 00021216 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-29 16:29 - 2012-01-05 08:09 - 00700118 _____ () C:\windows\system32\perfh007.dat
2014-06-29 16:29 - 2012-01-05 08:09 - 00149968 _____ () C:\windows\system32\perfc007.dat
2014-06-29 16:29 - 2009-07-14 07:13 - 01622164 _____ () C:\windows\system32\PerfStringBackup.INI
2014-06-29 16:25 - 2014-06-29 11:29 - 00000000 ____D () C:\AdwCleaner
2014-06-29 16:23 - 2014-06-29 16:17 - 00002000 _____ () C:\windows\PFRO.log
2014-06-29 16:23 - 2014-06-19 08:34 - 00000896 _____ () C:\windows\setupact.log
2014-06-29 16:23 - 2014-02-04 01:27 - 00001098 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-29 16:23 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-06-29 16:17 - 2012-01-04 09:30 - 00000000 ____D () C:\ProgramData\Samsung
2014-06-29 16:16 - 2014-03-16 01:11 - 00000000 ____D () C:\ProgramData\SnowApp
2014-06-29 16:16 - 2012-01-04 10:02 - 00000000 ____D () C:\windows\he
2014-06-29 16:07 - 2014-06-15 16:44 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-29 11:30 - 2014-06-29 11:30 - 01016261 _____ (Thisisu) C:\Users\wh\Downloads\JRT.exe
2014-06-29 11:30 - 2014-06-29 11:30 - 00000000 ____D () C:\windows\ERUNT
2014-06-29 11:28 - 2014-06-29 11:28 - 01342659 _____ () C:\Users\wh\Downloads\adwcleaner_3.213.exe
2014-06-29 11:28 - 2014-06-29 11:28 - 00001264 _____ () C:\Users\wh\Desktop\Revo Uninstaller.lnk
2014-06-29 11:28 - 2014-06-29 11:28 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-29 11:27 - 2014-06-29 11:27 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\wh\Downloads\revosetup95.exe
2014-06-27 23:09 - 2014-04-18 14:32 - 00000000 ____D () C:\Program Files (x86)\StarMoney 9.0 apoEdition
2014-06-27 22:07 - 2013-08-29 00:04 - 00000000 ____D () C:\Users\wh\AppData\Roaming\vlc
2014-06-19 08:34 - 2014-06-19 08:34 - 00000000 _____ () C:\windows\setuperr.log
2014-06-19 08:24 - 2014-06-19 08:24 - 00146472 _____ () C:\Users\wh\Documents\cc_20140619_082420.reg
2014-06-19 08:23 - 2014-03-16 11:45 - 00000000 ____D () C:\Users\wh\AppData\Local\CrashDumps
2014-06-15 17:29 - 2014-06-15 17:29 - 00046683 _____ () C:\Users\wh\Desktop\FRST.txt
2014-06-15 17:28 - 2014-06-15 17:28 - 00032795 _____ () C:\Users\wh\Downloads\Addition.txt
2014-06-15 17:04 - 2012-01-04 10:02 - 00000000 ____D () C:\windows\fi
2014-06-15 17:04 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\Registration
2014-06-15 16:53 - 2014-06-15 17:31 - 00037162 _____ () C:\Users\wh\Desktop\mbam-log-2014-06-15 (16-44-52).xml
2014-06-15 16:43 - 2014-06-15 16:43 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\wh\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-15 16:43 - 2014-06-15 16:43 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-15 16:43 - 2014-06-15 16:43 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-06-15 12:53 - 2014-06-15 12:53 - 00859992 _____ () C:\Users\wh\Downloads\snlTCNTplugins01.zip
2014-06-15 12:46 - 2014-03-14 21:41 - 00000000 ____D () C:\Users\wh\AppData\Roaming\UseNeXT
2014-06-15 12:41 - 2014-03-14 21:41 - 00000000 ____D () C:\Users\wh\Documents\UseNeXT
2014-06-15 11:34 - 2014-06-14 20:35 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-06-15 00:50 - 2014-06-15 00:50 - 00000990 _____ () C:\windows\wininit.ini
2014-06-14 20:36 - 2014-06-14 20:35 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-06-14 20:35 - 2014-06-14 20:35 - 00001391 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-06-14 20:35 - 2014-06-14 20:35 - 00001379 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-06-14 20:35 - 2014-06-14 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-06-14 20:33 - 2014-06-14 20:33 - 46392680 _____ (Safer-Networking Ltd. ) C:\Users\wh\Downloads\spybot-2.3.exe
2014-06-12 20:31 - 2014-03-16 01:11 - 00000000 ____D () C:\ProgramData\8e2932845b0d7fdc
2014-06-11 15:02 - 2009-07-14 07:08 - 00012928 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-06-11 14:51 - 2014-03-05 15:54 - 00000000 ____D () C:\windows\system32\MRT
2014-06-11 14:49 - 2014-03-05 15:54 - 95414520 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-06-11 14:47 - 2014-06-09 11:09 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-06-09 11:09 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-06-09 10:48 - 2014-06-09 10:48 - 00000056 _____ () C:\Users\wh\Downloads\heavy-metal.m3u
2014-06-09 10:40 - 2014-06-01 18:11 - 00000000 ____D () C:\ProgramData\VirtualizedApplications
2014-06-08 11:13 - 2014-06-10 20:09 - 00506368 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-10 20:09 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-03 21:33 - 2014-06-03 21:33 - 00003279 _____ () C:\Users\wh\Downloads\2-09399-g-06.AAM
2014-06-02 20:14 - 2014-06-02 20:14 - 00003303 _____ () C:\Users\wh\Downloads\2-09399-r-06.AAM
2014-06-01 16:12 - 2014-06-01 16:12 - 00003303 _____ () C:\Users\wh\Downloads\2-09399-u-05.AAM
2014-06-01 16:08 - 2014-02-08 03:03 - 00000000 ____D () C:\Users\wh\AppData\Roaming\Skype
2014-05-31 17:37 - 2014-05-31 17:37 - 00003111 _____ () C:\Users\wh\Downloads\2-09384-r-06.AAM
2014-05-30 12:21 - 2014-06-10 20:09 - 23414784 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-05-30 12:02 - 2014-06-10 20:09 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-05-30 12:02 - 2014-06-10 20:09 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-05-30 11:45 - 2014-06-10 20:09 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-05-30 11:39 - 2014-06-10 20:09 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-05-30 11:39 - 2014-06-10 20:09 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-05-30 11:38 - 2014-06-10 20:09 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-05-30 11:28 - 2014-06-10 20:09 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-05-30 11:27 - 2014-06-10 20:09 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-05-30 11:24 - 2014-06-10 20:09 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-05-30 11:21 - 2014-06-10 20:09 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-05-30 11:21 - 2014-06-10 20:09 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-05-30 11:20 - 2014-06-10 20:09 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-05-30 11:18 - 2014-06-10 20:09 - 17271296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-05-30 11:11 - 2014-06-10 20:09 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-05-30 11:08 - 2014-06-10 20:09 - 05782528 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-05-30 11:06 - 2014-06-10 20:09 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-05-30 11:02 - 2014-06-10 20:09 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-05-30 10:55 - 2014-06-10 20:09 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:49 - 2014-06-10 20:09 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-05-30 10:46 - 2014-06-10 20:09 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-05-30 10:44 - 2014-06-10 20:09 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-05-30 10:44 - 2014-06-10 20:09 - 00295424 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-05-30 10:43 - 2014-06-10 20:09 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-05-30 10:42 - 2014-06-10 20:09 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-10 20:09 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-05-30 10:35 - 2014-06-10 20:09 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-05-30 10:34 - 2014-06-10 20:09 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-05-30 10:33 - 2014-06-10 20:09 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-05-30 10:30 - 2014-06-10 20:09 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-05-30 10:29 - 2014-06-10 20:09 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-05-30 10:28 - 2014-06-10 20:09 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-05-30 10:27 - 2014-06-10 20:09 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-05-30 10:24 - 2014-06-10 20:09 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-05-30 10:23 - 2014-06-10 20:09 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-05-30 10:16 - 2014-06-10 20:09 - 00368128 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-05-30 10:10 - 2014-06-10 20:09 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-10 20:09 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-05-30 10:04 - 2014-06-10 20:09 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-05-30 10:02 - 2014-06-10 20:09 - 00242688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-05-30 09:56 - 2014-06-10 20:09 - 04244992 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-05-30 09:56 - 2014-06-10 20:09 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-05-30 09:54 - 2014-06-10 20:09 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-05-30 09:50 - 2014-06-10 20:09 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-10 20:09 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-05-30 09:43 - 2014-06-10 20:09 - 13522944 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-05-30 09:40 - 2014-06-10 20:09 - 11725312 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-05-30 09:30 - 2014-06-10 20:09 - 01398272 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-05-30 09:21 - 2014-06-10 20:09 - 01790976 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-05-30 09:15 - 2014-06-10 20:09 - 01143296 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-05-30 09:13 - 2014-06-10 20:09 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-05-30 09:13 - 2014-06-10 20:09 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-29 11:58

==================== End Of Log ============================
         
--- --- ---

--- --- ---

--- --- ---


Alt 30.06.2014, 11:34   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Bekomme "search.gadgetbox" nicht weg - Standard

Bekomme "search.gadgetbox" nicht weg



AdwCleaner auch Löschen lassen!!



ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
--> Bekomme "search.gadgetbox" nicht weg

Alt 20.07.2014, 16:25   #7
Frontschwein
 
Bekomme "search.gadgetbox" nicht weg - Standard

Bekomme "search.gadgetbox" nicht weg



Code:
ATTFilter
      ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=6fca8b6e3f6916438b240e3dc3a4addd
# engine=18986
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-07-02 01:44:24
# local_time=2014-07-02 03:44:24 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 2787 155938514 0 0
# scanned=134313
# found=4
# cleaned=0
# scan_time=2296
sh=22B079CBDF1296CA1BC94F01DDE55EA5564B1023 ft=1 fh=c71c001198f425ea vn="Win32/InstalleRex.M evtl. unerwünschte Anwendung" ac=I fn="C:\ProgramData\InstallMate\{2F5F78AA-E678-4A18-A8F3-AE5AF4BC5A5C}\Custom.dll"
sh=22B079CBDF1296CA1BC94F01DDE55EA5564B1023 ft=1 fh=c71c001198f425ea vn="Win32/InstalleRex.M evtl. unerwünschte Anwendung" ac=I fn="C:\Users\All Users\InstallMate\{2F5F78AA-E678-4A18-A8F3-AE5AF4BC5A5C}\Custom.dll"
sh=8E473F27D5346F74333852211AE2B975719E5C92 ft=1 fh=5a9b0dcadc624917 vn="Variante von Win32/DomaIQ.BG evtl. unerwünschte Anwendung" ac=I fn="C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\File System\002\t\00\00000000"
sh=82255DD089F9684B7B7F3B6C8FC74324EE9F8165 ft=1 fh=c71c0011b6bdcb6f vn="Variante von Win32/InstallCore.IK evtl. unerwünschte Anwendung" ac=I fn="C:\Users\wh\Downloads\ZipSetup.exe"
ESETSmartInstaller@High as downloader log:
all ok
         

Code:
ATTFilter
           Results of screen317's Security Check version 0.99.83  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 WMI entry may not exist for antivirus; attempting automatic update. 
`````````Anti-malware/Other Utilities Check:````````` 
 MVPS Hosts File  
 Spybot - Search & Destroy 
 Java 7 Update 55  
 Google Chrome 33.0.1750.154  
 Google Chrome 34.0.1847.116  
````````Process Check: objlist.exe by Laurent````````  
 Spybot Teatimer.exe is disabled! 
 StarMoney 9.0 apoEdition ouservice StarMoneyOnlineUpdate.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         



Code:
ATTFilter
        can result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-07-2014
Ran by wh (administrator) on WH-PC on 20-07-2014 17:08:02
Running from C:\Users\wh\Downloads
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ 
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ 
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.EXE
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0 apoEdition\ouservice\StarMoneyOnlineUpdate.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Touch Supporter\InputSupporterNLauncher.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Play Touch\Touch Launcher\LauncherStarterCmd.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Touch Supporter\InputSupporter.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Play Touch\Touch Launcher\LauncherStarter.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartRotation.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Samsung Electronics) C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_12_0_0_44_ActiveX.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Easy Support Center\SSCKbdHk.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12661352 2011-08-01] (Realtek Semiconductor)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101584 2014-04-25] (Safer-Networking Ltd.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-19\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3424567567-1130603173-978095989-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566984 2014-04-25] (Safer-Networking Ltd.)
HKU\S-1-5-21-3424567567-1130603173-978095989-1000\...\MountPoints2: {5e394242-c7b7-11e3-af9f-24ec994b3939} - D:\LaunchU3.exe -a
Lsa: [Notification Packages] scecli ConfigFilter
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung.msn.com
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2

FireFox:
========
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50917.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)

Chrome: 
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "https://www.google.com/"
CHR Extension: (Google Docs) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-04]
CHR Extension: (Google Drive) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-04]
CHR Extension: (YouTube) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-04]
CHR Extension: (Google-Suche) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-04]
CHR Extension: (Google Wallet) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-04]
CHR Extension: (Google Mail) - C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-04]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738200 2014-04-25] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2081752 2014-04-25] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0 apoEdition\ouservice\StarMoneyOnlineUpdate.exe [663184 2014-01-27] (Star Finanz-Software Entwicklung und Vertriebs GmbH)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.)

==================== Drivers (Whitelisted) ====================

S3 AX88772; C:\Windows\System32\DRIVERS\ax88772.sys [77312 2010-05-31] (ASIX Electronics Corp.)
R3 GTNDIS62; C:\Windows\System32\DRIVERS\Gtuhs62.sys [208384 2011-10-03] (Option N.V.)
R3 GTUHSBUS; C:\Windows\System32\DRIVERS\gtuhsbus.sys [214528 2011-10-03] (Option N.V.)
R3 GTUHSSER; C:\Windows\System32\DRIVERS\gtuhsser.sys [12032 2011-10-03] (Option N.V.)
R3 LSM303DLH; C:\Windows\System32\DRIVERS\LSM303DLH.sys [61040 2011-08-19] (STMicroelectronics)
R2 SGDrv; C:\Windows\System32\DRIVERS\SGdrv64.sys [7680 2011-04-11] (Phoenix Technologies Ltd.)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-20 16:55 - 2014-07-20 16:55 - 01354223 _____ () C:\Users\wh\Downloads\adwcleaner_3.216.exe
2014-07-20 15:43 - 2014-07-20 15:43 - 00003063 _____ () C:\Users\wh\Downloads\2-09422-g-11.AAM
2014-07-17 15:02 - 2014-07-17 15:02 - 00003351 _____ () C:\Users\wh\Downloads\2-09422-j-09.AAM
2014-07-10 15:33 - 2014-06-30 04:09 - 00519168 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-07-10 15:33 - 2014-06-30 04:04 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-07-10 15:33 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\windows\system32\osk.exe
2014-07-10 15:33 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe
2014-07-10 15:33 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-07-10 15:32 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2014-07-10 15:32 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
2014-07-10 15:32 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2014-07-10 15:32 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2014-07-10 15:32 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2014-07-10 15:32 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2014-07-10 15:32 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2014-07-10 15:32 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-07-10 15:32 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-07-10 15:32 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2014-07-10 15:32 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2014-07-10 15:32 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2014-07-10 15:32 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2014-07-10 15:32 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2014-07-10 15:32 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-07-10 15:32 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-07-10 15:32 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2014-07-10 15:31 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-07-10 15:31 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-07-10 15:31 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-07-10 15:31 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-07-10 15:31 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-07-10 15:31 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-07-10 15:31 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-07-10 15:31 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-07-10 15:31 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-07-10 15:31 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-07-10 15:31 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-07-10 15:31 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-07-10 15:31 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-07-10 15:31 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-07-10 15:31 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-07-10 15:31 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-07-10 15:31 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-07-10 15:31 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-07-10 15:31 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-07-10 15:31 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-07-10 15:31 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-07-10 15:31 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-07-10 15:31 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-07-10 15:31 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-07-10 15:31 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-07-10 15:31 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-07-10 15:31 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-07-10 15:31 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-07-10 15:31 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-07-10 15:31 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-07-10 15:31 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-07-10 15:31 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-07-10 15:31 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-07-10 15:31 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-07-10 15:31 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-07-10 15:31 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-07-10 15:31 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-07-10 15:31 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-07-10 15:31 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-07-10 15:31 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-07-10 15:31 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-10 15:31 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-07-10 15:31 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-07-10 15:31 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-07-10 15:31 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-07-10 15:31 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-07-10 15:31 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-07-10 15:31 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-07-10 15:31 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-07-10 15:31 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-07-10 15:31 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-07-10 15:31 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-07-10 15:31 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-07-10 15:31 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-07-10 15:31 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-07-10 15:31 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-07-10 15:31 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2014-07-10 15:31 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2014-07-10 15:31 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2014-07-05 18:40 - 2014-07-05 18:40 - 00002967 _____ () C:\Users\wh\Downloads\2-09422-j-03.AAM
2014-07-02 21:55 - 2014-07-02 21:55 - 00002775 _____ () C:\Users\wh\Downloads\2-09422-g-03.AAM
2014-07-02 19:33 - 2014-07-20 17:07 - 00000866 _____ () C:\Users\wh\Desktop\checkup.txt
2014-07-02 15:09 - 2014-07-02 15:09 - 00854367 _____ () C:\Users\wh\Downloads\SecurityCheck.exe
2014-07-02 15:00 - 2014-07-02 15:00 - 02347384 _____ (ESET) C:\Users\wh\Downloads\esetsmartinstaller_deu.exe
2014-07-02 15:00 - 2014-07-02 15:00 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-06-29 16:53 - 2014-07-20 17:07 - 00000000 ____D () C:\Users\wh\Downloads\FRST-OlderVersion
2014-06-29 16:37 - 2014-06-29 16:37 - 00000622 _____ () C:\Users\wh\Desktop\JRT.txt
2014-06-29 16:21 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll
2014-06-29 16:17 - 2014-07-20 16:58 - 00002314 _____ () C:\windows\PFRO.log
2014-06-29 11:30 - 2014-06-29 11:30 - 01016261 _____ (Thisisu) C:\Users\wh\Downloads\JRT.exe
2014-06-29 11:30 - 2014-06-29 11:30 - 00000000 ____D () C:\windows\ERUNT
2014-06-29 11:29 - 2014-07-20 16:59 - 00000000 ____D () C:\AdwCleaner
2014-06-29 11:28 - 2014-06-29 11:28 - 00001264 _____ () C:\Users\wh\Desktop\Revo Uninstaller.lnk
2014-06-29 11:28 - 2014-06-29 11:28 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-29 11:27 - 2014-06-29 11:27 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\wh\Downloads\revosetup95.exe

==================== One Month Modified Files and Folders =======

2014-07-20 17:08 - 2014-06-15 17:27 - 00012630 _____ () C:\Users\wh\Downloads\FRST.txt
2014-07-20 17:08 - 2014-06-15 17:27 - 00000000 ____D () C:\FRST
2014-07-20 17:07 - 2014-07-02 19:33 - 00000866 _____ () C:\Users\wh\Desktop\checkup.txt
2014-07-20 17:07 - 2014-06-29 16:53 - 00000000 ____D () C:\Users\wh\Downloads\FRST-OlderVersion
2014-07-20 17:07 - 2014-06-15 17:26 - 02089984 _____ (Farbar) C:\Users\wh\Downloads\FRST64.exe
2014-07-20 17:05 - 2012-01-05 08:09 - 00700118 _____ () C:\windows\system32\perfh007.dat
2014-07-20 17:05 - 2012-01-05 08:09 - 00149968 _____ () C:\windows\system32\perfc007.dat
2014-07-20 17:05 - 2009-07-14 07:13 - 01622164 _____ () C:\windows\system32\PerfStringBackup.INI
2014-07-20 17:05 - 2009-07-14 06:45 - 00021216 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-20 17:05 - 2009-07-14 06:45 - 00021216 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-20 17:01 - 2012-01-04 09:25 - 01693365 _____ () C:\windows\WindowsUpdate.log
2014-07-20 16:59 - 2014-06-29 11:29 - 00000000 ____D () C:\AdwCleaner
2014-07-20 16:58 - 2014-06-29 16:17 - 00002314 _____ () C:\windows\PFRO.log
2014-07-20 16:58 - 2014-06-19 08:34 - 00003808 _____ () C:\windows\setupact.log
2014-07-20 16:58 - 2014-02-04 01:27 - 00001098 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-20 16:58 - 2012-01-04 09:30 - 00000000 ____D () C:\ProgramData\Samsung
2014-07-20 16:58 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-07-20 16:55 - 2014-07-20 16:55 - 01354223 _____ () C:\Users\wh\Downloads\adwcleaner_3.216.exe
2014-07-20 16:44 - 2014-02-04 01:27 - 00001102 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-20 15:43 - 2014-07-20 15:43 - 00003063 _____ () C:\Users\wh\Downloads\2-09422-g-11.AAM
2014-07-19 09:11 - 2014-03-14 21:41 - 00000000 ____D () C:\Users\wh\Documents\UseNeXT
2014-07-19 09:11 - 2014-03-14 21:41 - 00000000 ____D () C:\Users\wh\AppData\Roaming\UseNeXT
2014-07-19 09:11 - 2013-08-29 00:04 - 00000000 ____D () C:\Users\wh\AppData\Roaming\vlc
2014-07-17 15:02 - 2014-07-17 15:02 - 00003351 _____ () C:\Users\wh\Downloads\2-09422-j-09.AAM
2014-07-15 20:30 - 2014-03-16 00:59 - 00000000 ____D () C:\Users\wh\Downloads\eMule 0.50a SBI Leecher v2.4
2014-07-13 12:14 - 2014-04-18 14:53 - 00000000 ____D () C:\Users\wh\AppData\Roaming\Foxit Software
2014-07-13 03:19 - 2009-07-14 06:45 - 00276584 _____ () C:\windows\system32\FNTCACHE.DAT
2014-07-13 03:18 - 2014-06-09 11:09 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-07-13 03:18 - 2012-01-05 08:02 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-13 03:18 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\SysWOW64\Dism
2014-07-13 03:18 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\system32\Dism
2014-07-13 03:02 - 2014-03-05 15:54 - 00000000 ____D () C:\windows\system32\MRT
2014-07-13 03:01 - 2014-03-05 15:54 - 96441528 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-07-12 22:22 - 2013-08-29 00:12 - 00000000 ____D () C:\Users\wh\AppData\Local\Samsung
2014-07-09 16:01 - 2014-04-18 14:32 - 00000000 ____D () C:\Program Files (x86)\StarMoney 9.0 apoEdition
2014-07-05 18:40 - 2014-07-05 18:40 - 00002967 _____ () C:\Users\wh\Downloads\2-09422-j-03.AAM
2014-07-02 21:55 - 2014-07-02 21:55 - 00002775 _____ () C:\Users\wh\Downloads\2-09422-g-03.AAM
2014-07-02 15:09 - 2014-07-02 15:09 - 00854367 _____ () C:\Users\wh\Downloads\SecurityCheck.exe
2014-07-02 15:00 - 2014-07-02 15:00 - 02347384 _____ (ESET) C:\Users\wh\Downloads\esetsmartinstaller_deu.exe
2014-07-02 15:00 - 2014-07-02 15:00 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-07-02 14:53 - 2009-07-14 07:08 - 00014440 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-06-30 04:09 - 2014-07-10 15:33 - 00519168 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-06-30 04:04 - 2014-07-10 15:33 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-29 16:37 - 2014-06-29 16:37 - 00000622 _____ () C:\Users\wh\Desktop\JRT.txt
2014-06-29 16:17 - 2012-01-04 10:02 - 00000000 ____D () C:\windows\he
2014-06-29 16:16 - 2014-03-16 01:11 - 00000000 ____D () C:\ProgramData\SnowApp
2014-06-29 16:07 - 2014-06-15 16:44 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-29 11:30 - 2014-06-29 11:30 - 01016261 _____ (Thisisu) C:\Users\wh\Downloads\JRT.exe
2014-06-29 11:30 - 2014-06-29 11:30 - 00000000 ____D () C:\windows\ERUNT
2014-06-29 11:28 - 2014-06-29 11:28 - 00001264 _____ () C:\Users\wh\Desktop\Revo Uninstaller.lnk
2014-06-29 11:28 - 2014-06-29 11:28 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-29 11:27 - 2014-06-29 11:27 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\wh\Downloads\revosetup95.exe
2014-06-20 22:14 - 2014-07-10 15:31 - 00266424 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-06-20 21:39 - 2014-07-10 15:31 - 00240824 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll

Some content of TEMP:
====================
C:\Users\wh\AppData\Local\Temp\Foxit Updater.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-18 18:55

==================== End Of Log ============================
         



mmmmmhhhh, gatgetbox erscheint immer noch als Startseite, und der Seitenaufbau dauert generell Ewigkeiten...noch eine Idee?

Alt 20.07.2014, 18:07   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Bekomme "search.gadgetbox" nicht weg - Standard

Bekomme "search.gadgetbox" nicht weg



In welchem Browser?

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
C:\ProgramData\InstallMate
C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\File System\002\t\00\00000000
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 11.09.2014, 18:37   #9
Frontschwein
 
Bekomme "search.gadgetbox" nicht weg - Standard

Bekomme "search.gadgetbox" nicht weg



Code:
ATTFilter
     Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-09-2014
Ran by wh at 2014-09-11 19:21:42 Run:1
Running from C:\Users\wh\Downloads
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\ProgramData\InstallMate 
C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\File System\002\t\00\00000000
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
*****************

C:\ProgramData\InstallMate => Moved successfully.
C:\Users\wh\AppData\Local\Google\Chrome\User Data\Default\File System\002\t\00\00000000 => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.

==== End of Fixlog ====
         

mmmhh, wenn ich chrome starte, kommt meine normale Startseite, wenn ich aber auf den "Startseitebutton" drücke kommt wieder: search.gboxapp.com

Auch kommt mir generell der Seitenaufbau unendlich langsam vor

Alt 12.09.2014, 19:52   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Bekomme "search.gadgetbox" nicht weg - Standard

Bekomme "search.gadgetbox" nicht weg



Revo Uninstaller - Download - Filepony
damit Chrome deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren.

Dann:
https://support.google.com/chrome/answer/3296214?hl=de


Frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Bekomme "search.gadgetbox" nicht weg
administrator, bingbar, browser, desktop, explorer, explorer.exe, free, google, helper, homepage, ics, internet, logfile, microsoft, realtek, registry, safer networking, schädling, secur, seite, services.exe, software, starmoney, svchost.exe, system, system32, tracker, win32, windows




Ähnliche Themen: Bekomme "search.gadgetbox" nicht weg


  1. Fehlerhinweis "Ungültiges Bild" unter WINDOWS 7: "C:\PROGRA~2\SEARCH~2\SEARCH~1\bin\VC32LO~1.DLL" +
    Log-Analyse und Auswertung - 19.04.2015 (9)
  2. Ich bekomme "positive finds ads" nicht von meinem Rechner
    Plagegeister aller Art und deren Bekämpfung - 03.03.2015 (7)
  3. es bleibt eine Maske " Driver restore " stehen, die bekomme ich nicht wieder weg.
    Log-Analyse und Auswertung - 13.02.2015 (1)
  4. Diverse Malware ("CoolSaleCoupon", "ddownlloaditkeep", "omiga-plus", "SaveSense", "SaleItCoupon"); lahmer PC & viel Werbung!
    Plagegeister aller Art und deren Bekämpfung - 11.01.2015 (16)
  5. Ich bekomme "Click to continue - smartshopping" nicht runter vom PC
    Log-Analyse und Auswertung - 06.11.2014 (1)
  6. Windows XP Nach Installation von HP Player immer zwei Startseiten beim Öffnen von Google chrome "start.iminent.com" und "Search gol"
    Log-Analyse und Auswertung - 08.10.2013 (5)
  7. "NAV-Links" und "Certified-Toolbar (Search)" rauben mir den letzten Nerv! Was tun?
    Log-Analyse und Auswertung - 23.08.2013 (8)
  8. Ich habe jetzt auch "Browse to Save" Werbebanner und bekomme diese nicht weg!
    Plagegeister aller Art und deren Bekämpfung - 04.02.2013 (20)
  9. Bekomme "Trojan-gameThief.win32.magania.bevf" nicht gebändigt
    Plagegeister aller Art und deren Bekämpfung - 21.10.2012 (1)
  10. Bekomme "Trojan-gameThief.win32.magania.bevf" nicht gebändigt
    Plagegeister aller Art und deren Bekämpfung - 16.10.2012 (29)
  11. Bekomme Meldung "Troj/JSRedir-HZ" und "MW:JS:JJ677"
    Plagegeister aller Art und deren Bekämpfung - 15.10.2012 (42)
  12. Bekomme "Trojan-gameThief.win32.magania.bevf" nicht gebändigt
    Alles rund um Windows - 19.08.2012 (2)
  13. bekomme Virus "TR/Crypt.ZPACK.Gen" nicht los
    Plagegeister aller Art und deren Bekämpfung - 04.05.2010 (10)
  14. Bekomme "Your Computer is infected" nicht weg!
    Plagegeister aller Art und deren Bekämpfung - 26.04.2009 (10)
  15. Bekomme "http://default.home/" und "ACCESS BLOCKED - VIRUS WARNING" nicht mehr los
    Log-Analyse und Auswertung - 16.01.2005 (5)
  16. Bekomme Hijack"Pleasure Zone" nicht weg! Hilfe!
    Log-Analyse und Auswertung - 20.07.2004 (1)
  17. Bekomme "Home Search" net weg!
    Plagegeister aller Art und deren Bekämpfung - 17.06.2004 (5)

Zum Thema Bekomme "search.gadgetbox" nicht weg - Habe mir den Schädling gadgetbox eingefangen. Internet sehr langsam. Startseite nun nicht mehr google sondern gadgetbox. Hatte erst Spybot laufen lassen, dann Malwarebytes. Zum Schluss nun FRST. Hier die logs: - Bekomme "search.gadgetbox" nicht weg...
Archiv
Du betrachtest: Bekomme "search.gadgetbox" nicht weg auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.