|
Plagegeister aller Art und deren Bekämpfung: Fake Flash-Player Update gedownloadet :((Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
05.07.2014, 18:34 | #1 |
| Fake Flash-Player Update gedownloadet :(( Moin Moin, Eine Freundinn von mir hat auf einer Streaming Seite ein Fake Flash-Player Update gedownloadet. Da sie dachte das dieses Update wichtig wäre. Da hat sie mich um rat gebeten und da ich selbst ein Laie bin, bitte ich um Hilfe bei diesem Problem. Ich habe auf ihrem PC schon AdwCleaner und Anti Malwarebytes. Beide haben was gefunden. Auch vieles schon unter quarantäne gestellt. Doch ich glaube das da noch etwas ist. Da sie in gewissen abständen in Google Chrome eine Genesis-Offers seite öffnet ? Vielen dank schon im Vorauf für eure hilfe Hier die Logs AdwCleaner: Code:
ATTFilter # AdwCleaner v3.214 - Bericht erstellt am 05/07/2014 um 13:56:00 # Aktualisiert 29/06/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Yasmin - YASMIN-TOSH # Gestartet von : C:\Users\Yasmin\Downloads\adwcleaner_3.214.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : BackupStack Dienst Gelöscht : CltMngSvc [#] Dienst Gelöscht : globalUpdate [#] Dienst Gelöscht : globalUpdatem Dienst Gelöscht : IePluginServices Dienst Gelöscht : NewPlayerUpdaterService Dienst Gelöscht : pcsuservice ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\IePluginServices Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewPlayer Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Elite Max Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pc speed up Ordner Gelöscht : C:\Program Files (x86)\globalUpdate Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup Ordner Gelöscht : C:\Program Files (x86)\NewPlayer Ordner Gelöscht : C:\Program Files (x86)\Optimizer Elite Max Ordner Gelöscht : C:\Program Files (x86)\pc speed up Ordner Gelöscht : C:\Program Files (x86)\Plus-HD-9.1 Ordner Gelöscht : C:\Program Files (x86)\SearchProtect Ordner Gelöscht : C:\Program Files (x86)\SupTab Ordner Gelöscht : C:\Program Files (x86)\fst_de_88 Ordner Gelöscht : C:\Users\Yasmin\AppData\Local\globalUpdate Ordner Gelöscht : C:\Users\Yasmin\AppData\Local\NewPlayer Ordner Gelöscht : C:\Users\Yasmin\AppData\Local\SearchProtect Ordner Gelöscht : C:\Users\Yasmin\AppData\Local\fst_de_88 Ordner Gelöscht : C:\Users\Yasmin\AppData\Local\Temp\OCS Ordner Gelöscht : C:\Users\Yasmin\AppData\Roaming\InetStat Ordner Gelöscht : C:\Users\Yasmin\AppData\Roaming\Optimizer Elite Max Ordner Gelöscht : C:\Users\Yasmin\AppData\Roaming\VOPackage Ordner Gelöscht : C:\Users\Yasmin\AppData\Roaming\webssearches Ordner Gelöscht : C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup Ordner Gelöscht : C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage Datei Gelöscht : C:\END Datei Gelöscht : C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk Datei Gelöscht : C:\Users\Yasmin\Desktop\PC Speed Up.lnk Datei Gelöscht : C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx Datei Gelöscht : C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage Datei Gelöscht : C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal Datei Gelöscht : C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job Datei Gelöscht : C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore Datei Gelöscht : C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job Datei Gelöscht : C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA Datei Gelöscht : C:\Windows\Tasks\PC SpeedUp Service Deactivator.job Datei Gelöscht : C:\Windows\System32\Tasks\PC SpeedUp Service Deactivator Datei Gelöscht : C:\Windows\Tasks\PCHelpers_period.job Datei Gelöscht : C:\Windows\System32\Tasks\PCHelpers_period Datei Gelöscht : C:\Windows\Tasks\PCHelpers1st.job Datei Gelöscht : C:\Windows\System32\Tasks\PCHelpers1st Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-1.job Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-1 Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-11.job Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-11 Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-2.job Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-2 Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-3.job Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-3 Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-4.job Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-4 Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-5.job Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-5 Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-5_user.job Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-5_user Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-6.job Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-6 Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-7.job Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-7 ***** [ Verknüpfungen ] ***** Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Google Chrome.lnk Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk Verknüpfung Desinfiziert : C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk Verknüpfung Desinfiziert : C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Verknüpfung Desinfiziert : C:\Users\Yasmin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk Verknüpfung Desinfiziert : C:\Users\Yasmin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Verknüpfung Desinfiziert : C:\Users\Yasmin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk Verknüpfung Desinfiziert : C:\Users\Yasmin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ainbkicbloikcngphmjfpjdemblcojdd Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [InetStat] Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [pcspeedup] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10 Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4 Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [fst_de_88] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0060346.BHO Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0060346.BHO.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0060346.Sandbox Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0060346.Sandbox.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B89F5C49-51DB-4974-AB5A-E25901AA339C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E9B5B0D2-D08A-49FC-8B5C-159B60BAA268} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{09B73D47-DE1A-89C6-EE3B-3DEC891DE5E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611031146} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622032246} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655035546} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666036646} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644034446} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{09B73D47-DE1A-89C6-EE3B-3DEC891DE5E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611031146} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{09B73D47-DE1A-89C6-EE3B-3DEC891DE5E4} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611031146} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{09B73D47-DE1A-89C6-EE3B-3DEC891DE5E4} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611031146} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2318C2B1-4965-11D4-9B18-009027A5CD4F}] Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{2318C2B1-4965-11D4-9B18-009027A5CD4F}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611031146} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622032246} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655035546} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666036646} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611031146} Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2318C2B1-4965-11D4-9B18-009027A5CD4F}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command Schlüssel Gelöscht : HKCU\Software\genesis Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\Optimizer Elite Max Schlüssel Gelöscht : HKCU\Software\Speedchecker Limited Schlüssel Gelöscht : HKCU\Software\Tutorials Schlüssel Gelöscht : HKCU\Software\TutoTag Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider Schlüssel Gelöscht : HKLM\Software\installedbrowserextensions Schlüssel Gelöscht : HKLM\Software\NewPlayer Schlüssel Gelöscht : HKLM\Software\Plus-HD-9.1 Schlüssel Gelöscht : HKLM\Software\PriceMeterLiveUpdate Schlüssel Gelöscht : HKLM\Software\SearchProtect Schlüssel Gelöscht : HKLM\Software\Speedchecker Limited Schlüssel Gelöscht : HKLM\Software\SupDp Schlüssel Gelöscht : HKLM\Software\SupTab Schlüssel Gelöscht : HKLM\Software\supWPM Schlüssel Gelöscht : HKLM\Software\Tutorials Schlüssel Gelöscht : HKLM\Software\webssearchesSoftware Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeSoftToday_is1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NewPlayer Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Elite Max_is1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Plus-HD-9.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\installedbrowserextensions Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Speedchecker Limited Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCSU-SL_is1 Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~1.DLL Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~2.DLL ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17126 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] -\\ Google Chrome v35.0.1916.114 [ Datei : C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=ds&ts=1404551260&from=tugs&uid=TOSHIBAXMK3275GSX_22LPCSXUTXX22LPCSXUT&q={searchTerms} Gelöscht [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325376&octid=EB_ORIGINAL_CTID&ISID=M2F425585-7467-4F98-9BF6-3BF4B16B7094&SearchSource=58&CUI=&UM=6&UP=SP298F7D06-A19A-4299-99BB-6902736674E4&q={searchTerms}&SSPV= Gelöscht [Startup_urls] : hxxp://istart.webssearches.com/?type=hp&ts=1404551260&from=tugs&uid=TOSHIBAXMK3275GSX_22LPCSXUTXX22LPCSXUT Gelöscht [Homepage] : hxxp://www.trovi.com/?gd=&ctid=CT3325376&octid=EB_ORIGINAL_CTID&ISID=M2F425585-7467-4F98-9BF6-3BF4B16B7094&SearchSource=55&CUI=&UM=6&UP=SP298F7D06-A19A-4299-99BB-6902736674E4&SSPV= Gelöscht [Extension] : ainbkicbloikcngphmjfpjdemblcojdd Gelöscht [Extension] : booedmolknjekdopkepjjeckmjkdpfgl Gelöscht [Extension] : flpcjncodpafbgdpnkljologafpionhb Gelöscht [Extension] : pelmeidfhdlhlbjimpabfcbnnojbboma ************************* AdwCleaner[R0].txt - [24473 octets] - [15/06/2014 14:19:01] AdwCleaner[R1].txt - [21733 octets] - [05/07/2014 13:51:01] AdwCleaner[S0].txt - [20206 octets] - [15/06/2014 14:21:27] AdwCleaner[S1].txt - [16933 octets] - [05/07/2014 13:56:00] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [16994 octets] ########## Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 05.07.2014 Suchlauf-Zeit: 14:16:21 Logdatei: Ergebnisse.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.07.05.04 Rootkit Datenbank: v2014.07.03.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Yasmin Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 275750 Verstrichene Zeit: 48 Min, 32 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 3 PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1288, Löschen bei Neustart, [b4342c6fa9d261d5b7bd26695da4ce32] PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerBz174.exe, 4320, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34] PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\wdNewPlayerE.exe, 3652, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34] Module: 2 PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerBz174.dll, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34], PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerBz174.dll, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34], Registrierungsschlüssel: 10 PUP.Optional.WPM.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, Keine Aktion durch Benutzer, [b4342c6fa9d261d5b7bd26695da4ce32], PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WindowsMangerProtect, In Quarantäne, [b4342c6fa9d261d5b7bd26695da4ce32], PUP.Optional.BrowserApp.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Browser App, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [67816a3188f3c96d399efa144db79070], PUP.Optional.FreeSoftToday.A, HKLM\SOFTWARE\WOW6432NODE\FST\fst_de_37, In Quarantäne, [ae3aebb0136838fe2fbee6d5b84aa957], PUP.Optional.PriceMeter.A, HKU\S-1-5-21-2410883006-3698484201-3815030499-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\PriceMeter, In Quarantäne, [9157cfcc1665f442b0c2646717ebfe02], PUP.Optional.Ciuvo.A, HKU\S-1-5-21-2410883006-3698484201-3815030499-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\ciuvo.com, In Quarantäne, [618793088cef999d4ffd4c683fc3bf41], PUP.Optional.SuperFish.A, HKU\S-1-5-21-2410883006-3698484201-3815030499-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com, In Quarantäne, [ba2e6f2c26550a2c0744aa0a9d6515eb], PUP.Optional.NewPlayer.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\A6163528-B826-5EA9-5BC2-B379600F4AB8, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], PUP.Optional.NewPlayer.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NewPlayer, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], Registrierungswerte: 1 PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2410883006-3698484201-3815030499-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|BlockAndSurf, C:\Program Files (x86)\BlockAndSurf-soft\BlockAndSurf.exe, In Quarantäne, [539578239dde44f2d426dbde36cc2fd1] Registrierungsdaten: 0 (No malicious items detected) Ordner: 8 PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.Extutil.A, C:\Users\Yasmin\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B, In Quarantäne, [64845447d6a54ee8dd4011a02cd6fa06], PUP.Optional.Managera.A, C:\Users\Yasmin\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42, In Quarantäne, [7b6d6c2fff7c42f4ad71664bf11154ac], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Löschen bei Neustart, [16d2fba0a6d54de92706e0d1dd25d828], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, In Quarantäne, [16d2fba0a6d54de92706e0d1dd25d828], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [16d2fba0a6d54de92706e0d1dd25d828], PUP.Optional.FreeSoftwareToday.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FrEeSoFtOdAy, In Quarantäne, [5a8eb4e78deea78ffc5c961b32d0bc44], PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34], Dateien: 90 PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Löschen bei Neustart, [b4342c6fa9d261d5b7bd26695da4ce32], PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsa4B4D.exe, In Quarantäne, [58909cff532890a6b0a855331ee36b95], PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nseCD65.exe, In Quarantäne, [9d4b85161566b383abad40481ce539c7], PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nseF7AD.exe, In Quarantäne, [f9efc4d787f49c9a48103850976aa060], PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsj5CC4.exe, In Quarantäne, [95536734fa814fe74414691f2ad702fe], PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsjEF43.exe, In Quarantäne, [82666b30433854e24f091f694bb6e020], PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nskA2F9.exe, In Quarantäne, [09df9b00d9a2b77fc395a8e0c33ebe42], PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsp964B.exe, In Quarantäne, [f8f0504b0378f244bc9c9eea31d06799], PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nspBBA9.exe, In Quarantäne, [0ddbc9d2bebd88aeb4a40286cc3529d7], PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsu4968.exe, In Quarantäne, [1bcde4b78eede05641171672a8594bb5], PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsu4E14.exe, In Quarantäne, [8d5b83186813fa3ce2766721fa0706fa], PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsu5413.exe, In Quarantäne, [14d49209a6d5033376e267216e93b749], PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsv2F15.exe, In Quarantäne, [86627a21fb80c670c692becacc35c63a], PUP.Optional.SearchProtect.A, C:\Users\Yasmin\AppData\Local\Temp\nszF0C8.tmp, In Quarantäne, [3eaa6239a9d2ba7c3745c5cdf80917e9], PUP.Optional.SearchProtect.A, C:\Users\Yasmin\AppData\Local\Temp\nsjACD6\SpSetup.exe, In Quarantäne, [7d6b504bb5c689ad8bf12a6853ae08f8], PUP.Optional.SearchProtect.A, C:\Users\Yasmin\AppData\Local\Temp\nsjB68\SpSetup.exe, In Quarantäne, [f6f24853d4a783b31b619ef49d64936d], PUP.Optional.SkyTech.A, C:\Users\Yasmin\AppData\Local\Temp\7473461\7473461.zipDir\alilog.dll, In Quarantäne, [bd2b1a81582346f00f1e2909fd03eb15], PUP.Optional.V9.A, C:\Users\Yasmin\AppData\Local\Temp\7473461\7473461.zipDir\qSE.exe, In Quarantäne, [bb2df6a5e596c76f2ca03e0af20eac54], PUP.Optional.Skytech.A, C:\Users\Yasmin\AppData\Local\Temp\7473461\7473461.zipDir\UninstallManager.exe, In Quarantäne, [09df475484f761d5606597f49071b54b], PUP.Optional.IePluginService.A, C:\Users\Yasmin\AppData\Local\Temp\7473461\7473461.zipDir\tmp\SupTab_Setup302.exe, In Quarantäne, [ac3cf3a8f78460d67b1f64f816ebcb35], PUP.Optional.WpManager, C:\Users\Yasmin\AppData\Local\Temp\7473461\7473461.zipDir\tmp\wpm_v18.8.0.304.exe, In Quarantäne, [05e3d6c5b0cb2b0bab6a5314aa57dc24], PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\7Dtmp\spidentifierimpl.exe, In Quarantäne, [29bfcbd083f8f442427f66236899c838], PUP.Optional.NewPlayer.A, C:\Users\Yasmin\AppData\Local\Temp\8965tmp\newvideoplayersetup.exe, In Quarantäne, [d216e6b5e29942f4d5fbceb62cd507f9], PUP.Optional.FreeSoft, C:\Users\Yasmin\AppData\Local\Temp\8A61tmp\freesofttoday.exe, In Quarantäne, [24c48b107cffc86e63522956dc25926e], PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\DLG\exe\conduit-ltd-ultra-search-protect-1.0-de-de\sp-downloader.exe, In Quarantäne, [5098f2a93942b3830cc5fd25bd44669a], PUP.Optional.Wajam.A, C:\Users\Yasmin\AppData\Local\Temp\is45637729\7414018_stp\wajam_download.exe, In Quarantäne, [3eaad5c62952221410ef73d3fe02649c], PUP.Optional.PriceMeter.A, C:\Users\Yasmin\AppData\Local\Temp\is45637729\9922322_stp\pm.exe, In Quarantäne, [2abed0cbb6c5f73fb54a691e2fd2758b], PUP.Optional.SearchHijacker.A, C:\Users\Yasmin\AppData\Local\Temp\8BF9tmp\lly_webssearches.exe, In Quarantäne, [f4f43764374479bdabf1c4d09e6326da], PUP.Optional.OutBrowse, C:\Users\Yasmin\Downloads\setup.exe, In Quarantäne, [f0f83f5c7803d95dc0c8c9b45aa78977], PUP.Optional.DomaIQ, C:\Users\Yasmin\Downloads\Java (1).exe, In Quarantäne, [1eca603bcbb0c3735331182a5ca4e917], PUP.Optional.DomaIQ, C:\Users\Yasmin\Downloads\Java (2).exe, In Quarantäne, [eafe9506f883d85e8afa6ad8ef11827e], PUP.Optional.BundleInstaller.A, C:\Users\Yasmin\Downloads\Java.exe, In Quarantäne, [cb1dd4c7b8c36ec85f6372d9f9080bf5], PUP.Optional.Downloader, C:\Users\Yasmin\Downloads\Player (1).exe, In Quarantäne, [4b9dddbe512aa492a032820642c28d73], PUP.Optional.OptimumInstaller.A, C:\Users\Yasmin\Downloads\Player-Chrome.exe, In Quarantäne, [5593afecdaa10333cd28c48f4fb2c23e], PUP.Optional.Downloader, C:\Users\Yasmin\Downloads\Player.exe, In Quarantäne, [43a5eead4635bb7b19b9662293710ef2], PUP.Optional.RegCleanPro, C:\Users\Yasmin\Downloads\regclean_my582531.exe, In Quarantäne, [d51362393546c076e5bdee46fb059b65], PUP.Optional.DomaIQ, C:\Users\Yasmin\Downloads\Setup (1).exe, In Quarantäne, [fcec5942ec8faa8c23ae6eda42be659b], PUP.Optional.DomaIQ, C:\Users\Yasmin\Downloads\Setup (5).exe, In Quarantäne, [70781f7c4f2c6cca6e632b1db050827e], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\background.html, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\1293297481.mxaddon, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\360-60346.crx, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\60346.crx, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\60346.xpi, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\bgNova.html, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App-bg.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App-bho.dll, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App-bho64.dll, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App-codedownloader.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App-nova.dll, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App-nova.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App-novainstaller.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App.ico, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-11.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-2.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-3.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-4.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-5.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9.crx, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Uninstall.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\utils.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], PUP.Optional.NewPlayer.A, C:\Windows\System32\Tasks\NewPlayer Update, In Quarantäne, [b4340e8d6e0dde587f85a51009f9956b], PUP.Optional.NewPlayer.A, C:\Windows\System32\Tasks\NewPlayer_wd, In Quarantäne, [17d15249166562d453b23e777c861ce4], PUP.Optional.Ciuvo.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage, In Quarantäne, [31b7abf01d5ee74fdd3b15a4649e17e9], PUP.Optional.Ciuvo.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage-journal, In Quarantäne, [796f9506740750e6dc3cb306cd359868], PUP.Optional.BetterDeals.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage, In Quarantäne, [8c5c42592a51dd591cbf1e9c1ee4ae52], PUP.Optional.BetterDeals.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage-journal, In Quarantäne, [a7418b1088f38da9538802b88c76a759], PUP.Optional.SelectNGo.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage, In Quarantäne, [ac3c3b6082f9ba7c2f951e9e06fc8878], PUP.Optional.SelectNGo.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage-journal, In Quarantäne, [c820445738438da9428207b509f9bc44], PUP.Optional.NewPlayer.A, C:\Windows\Tasks\NewPlayer Update.job, In Quarantäne, [816714871c5fef471da807b61ae859a7], PUP.Optional.NewPlayer.A, C:\Windows\Tasks\NewPlayer_wd.job, In Quarantäne, [feeaa3f8dc9f9d9916b0c1fc5ba78779], PUP.Optional.Superfish.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, In Quarantäne, [b8308615f18a56e09782457bbe44c63a], PUP.Optional.Superfish.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, In Quarantäne, [a7415a411764b87ec2579e22e022a15f], PUP.Optional.Extutil.A, C:\Users\Yasmin\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\bk.js, In Quarantäne, [64845447d6a54ee8dd4011a02cd6fa06], PUP.Optional.Extutil.A, C:\Users\Yasmin\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\cs.js, In Quarantäne, [64845447d6a54ee8dd4011a02cd6fa06], PUP.Optional.Extutil.A, C:\Users\Yasmin\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\manifest.json, In Quarantäne, [64845447d6a54ee8dd4011a02cd6fa06], PUP.Optional.Managera.A, C:\Users\Yasmin\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\cs.js, In Quarantäne, [7b6d6c2fff7c42f4ad71664bf11154ac], PUP.Optional.Managera.A, C:\Users\Yasmin\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\manifest.json, In Quarantäne, [7b6d6c2fff7c42f4ad71664bf11154ac], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-07-05[11-09-17-175].log, In Quarantäne, [16d2fba0a6d54de92706e0d1dd25d828], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [16d2fba0a6d54de92706e0d1dd25d828], PUP.Optional.FreeSoftwareToday.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FrEeSoFtOdAy\Freesofttoday.lnk, In Quarantäne, [5a8eb4e78deea78ffc5c961b32d0bc44], PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\174.dat, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\a.db, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\b.db, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\Uninstall.exe, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerBz174.bin, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerBz174.dll, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34], PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerBz174.exe, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34], PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerBz174.ini, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerR06.exe, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\wdNewPlayerE.exe, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34], Physische Sektoren: 0 (No malicious items detected) (end) |
05.07.2014, 18:40 | #2 |
/// the machine /// TB-Ausbilder | Fake Flash-Player Update gedownloadet :(( hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
05.07.2014, 18:57 | #3 |
| Fake Flash-Player Update gedownloadet :(( Moin,
__________________Alles klar hier die Posts Addition .txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-07-2014 01 Ran by Yasmin at 2014-07-05 19:50:40 Running from C:\Users\Yasmin\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {86355677-4064-3EA7-ABB3-1B136EB04637} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {3D54B793-665E-3129-9103-206115370C8A} FW: McAfee Firewall (Enabled) {BE0ED752-0A0B-3FFF-80EC-B2269063014C} ==================== Installed Programs ====================== Adobe Flash Player 11 ActiveX (HKLM-x32\...\{41042E28-CCA1-4147-869F-9E928B38F04C}) (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader 9.4.0 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.0 - Adobe Systems Incorporated) AMD Media Foundation Decoders (Version: 1.0.60628.2255 - ATI Technologies Inc.) Hidden AMD VISION Engine Control Center (x32 Version: 2011.0628.2340.40663 - Ihr Firmenname) Hidden ATI Catalyst Install Manager (HKLM\...\{6167672A-758D-9960-C32C-47A15E180A70}) (Version: 3.0.829.0 - ATI Technologies, Inc.) Audials (HKLM-x32\...\{DA6EBFC9-8869-4B61-8D38-2668A395C5B0}) (Version: 11.0.54400.0 - Audials AG) Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Bejeweled 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2011.0628.2340.40663 - ATI) Hidden Catalyst Control Center InstallProxy (x32 Version: 2011.0628.2340.40663 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2011.0628.2340.40663 - ATI) Hidden CCC Help Chinese Standard (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Chinese Traditional (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Czech (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Danish (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Dutch (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help English (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Finnish (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help French (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help German (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Greek (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Hungarian (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Italian (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Japanese (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Korean (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Norwegian (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Polish (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Portuguese (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Russian (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Spanish (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Swedish (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Thai (x32 Version: 2011.0628.2339.40663 - ATI) Hidden CCC Help Turkish (x32 Version: 2011.0628.2339.40663 - ATI) Hidden ccc-utility64 (Version: 2011.0628.2340.40663 - ATI) Hidden Chicken Invaders 3 - Revenge of the Yolk (x32 Version: 2.2.0.95 - WildTangent) Hidden Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.25.0 - Google Inc.) Hidden High-Definition Video Playback (x32 Version: 7.3.10900.8.0 - Nero AG) Hidden InetStat (HKCU\...\InetStat) (Version: 0.4 - InetStat) Insaniquarium Deluxe (x32 Version: 2.2.0.97 - WildTangent) Hidden Java Auto Updater (x32 Version: 2.0.2.1 - Sun Microsystems, Inc.) Hidden Java(TM) 6 Update 20 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216020FF}) (Version: 6.0.200 - Sun Microsystems, Inc.) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) McAfee Internet Security (HKLM-x32\...\MSC) (Version: 11.0.678 - McAfee, Inc.) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.5128.5002 - Microsoft Corporation) Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Primary Interoperability Assemblies 2005 (HKLM-x32\...\{2C303EE0-A595-3543-A71A-931C7AC40EDE}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Name (HKCU\...\name_07050906) (Version: - ) Nero 10 Movie ThemePack Basic (x32 Version: 10.6.10000.1.0 - Nero AG) Hidden Nero BackItUp 10 (HKLM-x32\...\{68AB6930-5BFF-4FF6-923B-516A91984FE6}) (Version: 5.8.10900.8.100 - Nero AG) Nero BackItUp 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden Nero BurnRights 10 (HKLM-x32\...\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.4.10400.2.100 - Nero AG) Nero BurnRights 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden Nero Control Center 10 (x32 Version: 10.6.12700.0.7 - Nero AG) Hidden Nero ControlCenter 10 Help (CHM) (x32 Version: 10.6.10800 - Nero AG) Hidden Nero Core Components 10 (x32 Version: 2.0.20000.9.12 - Nero AG) Hidden Nero Express 10 (HKLM-x32\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.6.10700.5.100 - Nero AG) Nero Express 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden Nero InfoTool 10 (HKLM-x32\...\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.4.10300.1.100 - Nero AG) Nero InfoTool 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden Nero Kwik Media (HKLM-x32\...\{1F7D9F37-C39C-486C-BDF8-8F440FFB3352}) (Version: 1.6.15100.59.100 - Nero AG) Nero Multimedia Suite 10 Essentials (HKLM-x32\...\{2063D199-D79F-471A-9019-9E647296394D}) (Version: 10.6.10300 - Nero AG) Nero RescueAgent 10 (HKLM-x32\...\{E337E787-CF61-4B7B-B84F-509202A54023}) (Version: 3.6.10500.3.100 - Nero AG) Nero RescueAgent 10 Help (CHM) (x32 Version: 10.6.10800 - Nero AG) Hidden Nero StartSmart 10 (HKLM-x32\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.6.10500.3.100 - Nero AG) Nero StartSmart 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden Nero Update (HKLM-x32\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.10900.31.0 - Nero AG) NeroKwikMedia Help (CHM) (x32 Version: 10.6.10900 - Nero AG) Hidden OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation) Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation) Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden PriceMeter Express (remove only) (HKCU\...\PriceMeter Express) (Version: 7.7.0.0 - PriceMeter Express) <==== ATTENTION Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.30.1019.2010 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6241 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30123 - Realtek Semiconductor Corp.) Realtek WLAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4fed-B2B9-173001290E16}) (Version: 2.00.0016 - REALTEK Semiconductor Corp.) Skype Click to Call (HKLM-x32\...\{BB285C9F-C821-4770-8970-56C4AB52C87E}) (Version: 7.2.15747.10003 - Microsoft Corporation) Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.) Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.1.16.0 - Synaptics Incorporated) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.29947 - TeamViewer) TOSHIBA Assist (HKLM-x32\...\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}) (Version: 4.01.00 - TOSHIBA CORPORATION) TOSHIBA Bulletin Board (HKLM-x32\...\InstallShield_{43DBC64B-3DD1-47E2-8788-D3C3B110C574}) (Version: 2.1.10.64 - TOSHIBA Corporation) TOSHIBA Bulletin Board (Version: 2.1.10.64 - TOSHIBA Corporation) Hidden TOSHIBA ConfigFree (HKLM-x32\...\{F52618B2-A995-4F8D-A6C8-9E235A470C68}) (Version: 8.0.36 - TOSHIBA CORPORATION) TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.4 for x64 - TOSHIBA Corporation) TOSHIBA Face Recognition (HKLM-x32\...\InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}) (Version: 3.1.3.64 - TOSHIBA Corporation) TOSHIBA Face Recognition (Version: 3.1.3.64 - TOSHIBA Corporation) Hidden TOSHIBA Flash Cards Support Utility (HKLM-x32\...\InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}) (Version: 1.63.0.11C - TOSHIBA CORPORATION) TOSHIBA Flash Cards Support Utility (x32 Version: 1.63.0.11C - TOSHIBA CORPORATION) Hidden TOSHIBA Hardware Setup (HKLM-x32\...\InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}) (Version: 1.63.0.34C - TOSHIBA CORPORATION) TOSHIBA Hardware Setup (x32 Version: 1.63.0.34C - TOSHIBA CORPORATION) Hidden TOSHIBA HDD/SSD Alert (HKLM-x32\...\InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: 3.1.64.6 - TOSHIBA Corporation) TOSHIBA HDD/SSD Alert (Version: 3.1.64.6 - TOSHIBA Corporation) Hidden TOSHIBA HDD/SSD Alert (x32 Version: 3.1.64.6 - TOSHIBA Corporation) Hidden Toshiba Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.02 - TOSHIBA) TOSHIBA Media Controller (HKLM-x32\...\{983CD6FE-8320-4B80-A8F6-0D0366E0AA22}) (Version: 1.0.80.8.64 - TOSHIBA CORPORATION) TOSHIBA Online Product Information (HKLM-x32\...\{2290A680-4083-410A-ADCC-7092C67FC052}) (Version: 4.01.0000 - TOSHIBA) TOSHIBA Places Icon Utility (HKLM-x32\...\{461F6F0D-7173-4902-9604-AB1A29108AF2}) (Version: 1.1.0.12 - TOSHIBA Corporation) TOSHIBA Recovery Media Creator (HKLM\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.0.5 x64 - TOSHIBA Corporation) TOSHIBA Recovery Media Creator Reminder (HKLM-x32\...\InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}) (Version: 1.00.0019 - TOSHIBA) TOSHIBA Recovery Media Creator Reminder (x32 Version: 1.00.0019 - TOSHIBA) Hidden TOSHIBA ReelTime (HKLM-x32\...\InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C}) (Version: 1.7.17.64 - TOSHIBA Corporation) TOSHIBA ReelTime (Version: 1.7.17.64 - TOSHIBA Corporation) Hidden TOSHIBA Service Station (HKLM-x32\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.1.45 - TOSHIBA) TOSHIBA Supervisor Password (x32 Version: 1.63.51.2C - TOSHIBA CORPORATION) Hidden TOSHIBA Supervisorkennwort (HKLM-x32\...\InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}) (Version: 1.63.51.2C - TOSHIBA CORPORATION) TOSHIBA TEMPRO (HKLM-x32\...\{F082CB11-4794-4259-99A1-D91BA762AD15}) (Version: 3.35 - Toshiba Europe GmbH) TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.3.22.64 - TOSHIBA Corporation) TOSHIBA Value Added Package (Version: 1.3.22.64 - TOSHIBA Corporation) Hidden TOSHIBA Value Added Package (x32 Version: 1.3.22.64 - TOSHIBA Corporation) Hidden TOSHIBA Web Camera Application (HKLM-x32\...\InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}) (Version: 1.1.5.7 - TOSHIBA Corporation) TOSHIBA Web Camera Application (x32 Version: 1.1.5.7 - TOSHIBA Corporation) Hidden TOSHIBA Wireless LAN Indicator (HKLM-x32\...\{5BA99779-6E12-49EF-BE49-F35B1EDB4DF9}) (Version: 1.0.4 - TOSHIBA CORPORATION) TRORMCLauncher (HKLM-x32\...\InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}) (Version: - ) TRORMCLauncher (Version: 1.0.0.10 - TOSHIBA) Hidden Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Utility Common Driver (x32 Version: 1.0.52.2C - TOSHIBA) Hidden webssearches uninstall (HKLM-x32\...\webssearches uninstall) (Version: - webssearches) <==== ATTENTION Wedding Dash 2 - Rings Around the World (x32 Version: 2.2.0.95 - WildTangent) Hidden WildTangent Games App (Toshiba Games) (x32 Version: 4.0.5.5 - WildTangent) Hidden WildTangent-Spiele (HKLM-x32\...\WildTangent toshiba Master Uninstall) (Version: 1.0.2.5 - WildTangent) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden ==================== Restore Points ========================= 15-05-2014 11:37:51 Windows Update 11-06-2014 20:15:51 OpenOffice 4.1.0 wird installiert 11-06-2014 21:53:04 RegClean Pro Mi, Jun 11, 14 23:52 12-06-2014 10:41:51 Windows Update 14-06-2014 12:44:17 Windows Update 14-06-2014 14:58:42 Wiederherstellungsvorgang 15-06-2014 12:37:01 OpenOffice 4.1.0 wird entfernt 15-06-2014 13:40:14 OpenOffice 4.1.0 wird installiert 05-07-2014 11:20:25 Gerätetreiber-Paketinstallation: RapidSolution Software Audio-, Video- und Gamecontroller 05-07-2014 11:24:55 Gerätetreiber-Paketinstallation: Audials AG Netzwerkdienst ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {06E604A3-0060-42D7-98AF-F503FE6AC481} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-4 No Task File <==== ATTENTION Task: {136333E3-4E4F-4FC9-A20C-DAC370FF8645} - System32\Tasks\ehhiar => C:\Users\Yasmin\AppData\Local\ehhiar.bat [2014-07-05] () Task: {1916F79D-C406-4C2A-87BE-9BEA0F85C8A1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {23919E98-98B7-4612-A70D-2781033B29D3} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-5_user No Task File <==== ATTENTION Task: {2443E6AC-280A-4521-8BA9-FE27A197B1FE} - \pricemeterdownloader No Task File <==== ATTENTION Task: {2D20B108-4C81-49DC-A067-DD69D760024D} - \APSnotifierPP1 No Task File <==== ATTENTION Task: {2F6FC6E0-BDA4-4786-B431-6B73835BF5EA} - \APSnotifierPP2 No Task File <==== ATTENTION Task: {2FA34A0E-950A-4570-ABFA-B293D4CBC08A} - \pricemetertask No Task File <==== ATTENTION Task: {35AFF216-5C1D-4DD8-AF79-7CEEBDEC3000} - \pricemeterwatcher No Task File <==== ATTENTION Task: {4182C2DA-65CC-4C7E-AA9A-D812EAD426B0} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-2 No Task File <==== ATTENTION Task: {420E0743-FC1C-4E5C-B566-57317858FFD7} - \BlockAndSurf_wd No Task File <==== ATTENTION Task: {481D3BE3-B678-4DF8-9FD3-6A0E61A72164} - \RegClean Pro_UPDATES No Task File <==== ATTENTION Task: {4AF40711-0CE9-4F32-8C04-3BBC8D805ADF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: {527586D9-6647-490C-BB46-B133425C3ACD} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-11 No Task File <==== ATTENTION Task: {58F88E88-2174-4827-B296-1294F654FC43} - System32\Tasks\mrxota => C:\Users\Yasmin\AppData\Local\mrxota.bat [2014-07-05] () Task: {60053A6E-1599-4F39-8B18-E564FBAEE7F4} - \c0dea5a2-14ac-4e72-9483-1db7a1278170-5 No Task File <==== ATTENTION Task: {62B5BFE8-2F70-4EF0-A5E0-2DE2EF6A24F7} - \PC SpeedUp Service Deactivator No Task File <==== ATTENTION Task: {6E2F1320-239B-41DD-BF1A-2803A16C23C5} - \RegClean Pro_DEFAULT No Task File <==== ATTENTION Task: {7F94A7B6-A38B-4525-8CC9-D733F281FA19} - \PCHelpers_period No Task File <==== ATTENTION Task: {81AE58A0-2399-405B-A53F-25D4BBAA97C1} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-7 No Task File <==== ATTENTION Task: {820C3ADA-160F-4285-AA42-14841F0E5317} - \2754ae73-35dd-4fab-a5ea-1ed8f35dbfa2-5 No Task File <==== ATTENTION Task: {872FDB1D-7F86-493D-AA0D-C55D648E2BC3} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-6 No Task File <==== ATTENTION Task: {924CF1A4-4437-44BB-8DF6-C31004F8EE7D} - \RegClean Pro No Task File <==== ATTENTION Task: {A008EB6B-7033-480E-85F8-5ED34D7F8D30} - \2754ae73-35dd-4fab-a5ea-1ed8f35dbfa2-7 No Task File <==== ATTENTION Task: {A2EE9636-E20A-44C3-8229-34B65AC0A9FA} - \2754ae73-35dd-4fab-a5ea-1ed8f35dbfa2-11 No Task File <==== ATTENTION Task: {AEF506D8-63E9-4D64-8C1E-168E8A735889} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION Task: {B2CC710F-DE94-4F17-8F20-10EFDCD2EF20} - \2754ae73-35dd-4fab-a5ea-1ed8f35dbfa2-3 No Task File <==== ATTENTION Task: {B6FDB691-13F1-4767-8B4B-DFE48575496B} - System32\Tasks\ConfigFree Startup Programs => C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe [2010-12-03] (TOSHIBA CORPORATION) Task: {B8A9FA13-C00E-411D-9CFC-5A67DCE25F43} - System32\Tasks\cfkxbi => C:\Users\Yasmin\AppData\Local\cfkxbi.bat Task: {C348F5EE-A56D-4FDC-BBED-6932E8F64515} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-1 No Task File <==== ATTENTION Task: {C3F48DA6-7138-4F60-ADAB-EF932888B004} - \APSnotifierPP3 No Task File <==== ATTENTION Task: {CBE11B04-EA35-4FB0-8819-9C0B168EBF64} - \PC Speed Maximizer Schedule No Task File <==== ATTENTION Task: {CEF5DE98-827C-4379-8AB5-533B9A49E361} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-5 No Task File <==== ATTENTION Task: {D1674CDA-B710-4E1C-8D72-3ABBACDECF6D} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-3 No Task File <==== ATTENTION Task: {D5C0943F-768E-443B-86D2-5BDBBD8F3FB6} - \PCHelpers1st No Task File <==== ATTENTION Task: {D9289FDC-4274-4E77-BC6F-912CFB899264} - \2754ae73-35dd-4fab-a5ea-1ed8f35dbfa2-4 No Task File <==== ATTENTION Task: {DB9D1B70-CE94-4A7F-BAAA-8833D13DC225} - \Advanced System Protector_startup No Task File <==== ATTENTION Task: {E15AE0B3-953E-4E0C-8AF0-7932194AFF0D} - System32\Tasks\qscfhzbe => C:\Users\Yasmin\AppData\Local\qscfhzbe.bat [2014-07-05] () Task: {E360B299-6C01-49ED-ADDD-D67C24EA7E2C} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION Task: {EB449933-DD80-494E-A2CD-067D7CD195CE} - System32\Tasks\PerfMonitor_strtp => C:\Program Files (x86)\Optimizer Elite Max\PerformanceMonitor.exe <==== ATTENTION Task: {F21A0ABE-F58A-4E44-8B68-9A69399385B8} - \BlockAndSurf Update No Task File <==== ATTENTION Task: {F532E7DC-EF91-4B0A-A8A3-6670BC98A06B} - System32\Tasks\elsbix => C:\Users\Yasmin\AppData\Local\elsbix.bat [2014-07-05] () Task: {F5F105CF-F79C-4AD5-AC66-A5B23088C06C} - System32\Tasks\cmelajsb => C:\Users\Yasmin\AppData\Local\cmelajsb.bat [2014-07-05] () Task: {F936F827-7CB5-4007-9ACA-5C6E41F99714} - \2754ae73-35dd-4fab-a5ea-1ed8f35dbfa2-2 No Task File <==== ATTENTION Task: {FD4DE7E6-85D5-4B87-81DD-2D2CF744030F} - System32\Tasks\difkadc => C:\Users\Yasmin\AppData\Local\difkadc.bat [2014-07-05] () Task: {FD825BD4-8052-4198-9B4C-500A76D2A480} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-11] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\PerfMonitor_strtp.job => C:\Program Files (x86)\Optimizer Elite Max\PerformanceMonitor.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2011-03-03 23:21 - 2011-03-03 23:21 - 03420584 _____ () C:\Program Files\TOSHIBA\BulletinBoard\TosNcUi.dll 2010-10-28 15:27 - 2010-10-28 15:27 - 09468728 _____ () C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll 2010-10-28 15:27 - 2010-10-28 15:27 - 00053560 _____ () C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnZ.dll 2010-10-28 15:27 - 2010-10-28 15:27 - 00019256 _____ () C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnF10.dll 2010-10-28 15:27 - 2010-10-28 15:27 - 00019256 _____ () C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnF11.dll 2011-08-22 11:10 - 2010-08-31 15:21 - 00017272 _____ () C:\Program Files\TOSHIBA\TOSHIBA Assist\NotifyX.dll 2009-03-12 20:08 - 2009-03-12 20:08 - 00048640 _____ () C:\Program Files (x86)\Toshiba\PCDiag\NotifyPCD.dll 2009-07-25 17:38 - 2009-07-25 17:38 - 00017800 _____ () C:\Program Files\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll 2011-08-22 11:27 - 2011-02-22 11:16 - 00559104 _____ () C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\de\Humphrey.resources.dll 2014-06-11 17:31 - 2014-06-11 17:31 - 02208520 _____ () C:\Program Files (x86)\Audials\Audials 11\AudialsNotifier.exe 2011-08-22 11:51 - 2011-08-02 15:56 - 00022400 _____ () C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\de\TosDILangPack.resources.dll 2011-08-22 11:51 - 2011-08-02 15:56 - 00063360 _____ () C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIInternal.XmlSerializers.dll 2014-07-05 11:06 - 2014-07-05 11:07 - 02990080 _____ () C:\Users\Yasmin\AppData\Local\name_07050906\name_07050906.exe 2011-06-29 00:38 - 2011-06-29 00:38 - 00243712 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2011-03-22 11:17 - 2011-03-22 11:17 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2010-02-05 18:44 - 2010-02-05 18:44 - 00079192 _____ () C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll 2014-06-11 17:31 - 2014-06-11 17:31 - 00046080 _____ () C:\Program Files (x86)\Audials\Audials 11\boost_thread-vc90-mt-1_39.dll 2014-06-11 17:31 - 2014-06-11 17:31 - 00045056 _____ () C:\Program Files (x86)\Audials\Audials 11\boost_date_time-vc90-mt-1_39.dll 2014-06-11 17:31 - 2014-06-11 17:31 - 00545032 _____ () C:\Program Files (x86)\Audials\Audials 11\StreamingClient.dll 2014-06-11 17:31 - 2014-06-11 17:31 - 00012800 _____ () C:\Program Files (x86)\Audials\Audials 11\boost_system-vc90-mt-1_39.dll 2014-06-11 17:31 - 2014-06-11 17:31 - 00068360 _____ () C:\Program Files (x86)\Audials\Audials 11\CrashRpt.dll 2014-06-11 17:31 - 2014-06-11 17:31 - 00409352 _____ () C:\Program Files (x86)\Audials\Audials 11\SQLite3.dll 2014-06-11 17:31 - 2014-06-11 17:31 - 00614912 _____ () C:\Program Files (x86)\Audials\Audials 11\boost_regex-vc90-mt-1_39.dll 2014-07-05 13:17 - 2014-07-05 13:17 - 00290816 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Utils\475aaa01867f0f91e9bb3b3945a7e75e\Utils.ni.dll 2014-07-05 13:17 - 2014-07-05 13:17 - 00590336 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ManagedInterfaces\2c469d1b5dd6af3398ba8536e042da21\ManagedInterfaces.ni.dll 2014-07-05 13:17 - 2014-07-05 13:17 - 02977280 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\AudialsComponents\061edcd67606321f9b82b085808114ca\AudialsComponents.ni.dll 2014-07-05 13:17 - 2014-07-05 13:17 - 00178688 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\fastJSON\d280aed23ee738bcb288ac17febd0772\fastJSON.ni.dll 2014-05-24 00:08 - 2014-05-14 01:40 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libglesv2.dll 2014-05-24 00:08 - 2014-05-14 01:40 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libegl.dll 2014-05-24 00:08 - 2014-05-14 01:40 - 04217672 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll 2014-05-24 00:08 - 2014-05-14 01:40 - 00414536 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll 2014-05-24 00:08 - 2014-05-14 01:40 - 01732424 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver" ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/05/2014 04:28:20 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/05/2014 02:00:21 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/05/2014 11:23:26 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/05/2014 11:10:00 AM) (Source: MsiInstaller) (EventID: 11309) (User: Yasmin-TOSH) Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt. System error 3. Verify that the file exists and that you can access it. Error: (07/05/2014 10:25:33 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/04/2014 03:19:15 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/03/2014 09:25:07 PM) (Source: TOSHIBA Service Station) (EventID: 0) (User: ) Description: TSS Load: could not communicate with TMachInfo service Error: (07/03/2014 09:22:17 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/02/2014 06:16:09 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/01/2014 09:08:26 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (07/05/2014 04:27:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "WindowsMangerProtect Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/05/2014 04:25:35 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (07/05/2014 01:57:16 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {3EB3C877-1F16-487C-9050-104DBCD66683} Error: (07/05/2014 01:57:14 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (07/05/2014 01:19:01 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (07/05/2014 01:17:48 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {ABC01078-F197-4B0B-ADBC-CFE684B39C82} Error: (07/05/2014 11:22:32 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Computer Backup (MyPC Backup)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (07/05/2014 11:22:32 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Computer Backup (MyPC Backup) erreicht. Error: (07/05/2014 11:20:41 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (07/05/2014 01:09:11 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Microsoft Office Sessions: ========================= Error: (07/05/2014 04:28:20 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/05/2014 02:00:21 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/05/2014 11:23:26 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/05/2014 11:10:00 AM) (Source: MsiInstaller) (EventID: 11309) (User: Yasmin-TOSH) Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt. System error 3. Verify that the file exists and that you can access it.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (07/05/2014 10:25:33 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/04/2014 03:19:15 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/03/2014 09:25:07 PM) (Source: TOSHIBA Service Station) (EventID: 0) (User: ) Description: TSS Load: could not communicate with TMachInfo service Error: (07/03/2014 09:22:17 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/02/2014 06:16:09 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/01/2014 09:08:26 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 44% Total physical RAM: 3691.64 MB Available physical RAM: 2055.92 MB Total Pagefile: 7681.45 MB Available Pagefile: 4891.95 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: (WINDOWS) (Fixed) (Total:149.04 GB) (Free:101.82 GB) NTFS Drive d: (Data) (Fixed) (Total:148.65 GB) (Free:85.05 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 41D68339) Partition 1: (Active) - (Size=400 MB) - (Type=27) Partition 2: (Not Active) - (Size=149 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=149 GB) - (Type=07 NTFS) ==================== End Of Log ============================ FRST .txt FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-07-2014 01 Ran by Yasmin (administrator) on YASMIN-TOSH on 05-07-2014 19:48:41 Running from C:\Users\Yasmin\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe () C:\Program Files (x86)\Audials\Audials 11\AudialsNotifier.exe (Toshiba) C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe () C:\Users\Yasmin\AppData\Local\name_07050906\name_07050906.exe (McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcagent.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Desktop.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [TosNC] => C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [597928 2011-03-03] (TOSHIBA Corporation) HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38304 2010-12-14] (TOSHIBA Corporation) HKLM\...\Run: [Toshiba TEMPRO] => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1546720 2011-02-10] (Toshiba Europe GmbH) HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [566184 2010-09-28] (TOSHIBA Corporation) HKLM\...\Run: [SmoothView] => C:\Program Files\Toshiba\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation) HKLM\...\Run: [00TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [915320 2010-10-28] (TOSHIBA Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11580520 2010-11-10] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2181224 2010-11-03] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2387752 2010-09-30] (Synaptics Incorporated) HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2010-02-05] (TOSHIBA Corporation) HKLM\...\Run: [SmartFaceVWatcher] => C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-10-19] (TOSHIBA Corporation) HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation) HKLM\...\Run: [Toshiba Registration] => C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe [150992 2011-08-22] (Toshiba Europe GmbH) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [NBAgent] => c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1409424 2011-06-29] (Nero AG) HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [1675160 2012-03-21] (McAfee, Inc.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-06-29] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SVPWUTIL] => C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe [532480 2010-11-09] (TOSHIBA) HKLM-x32\...\Run: [HWSetup] => C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [423936 2010-03-04] (TOSHIBA Electronics, Inc.) HKLM-x32\...\Run: [KeNotify] => C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [34160 2010-08-15] (TOSHIBA CORPORATION) HKLM-x32\...\Run: [TWebCamera] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2475384 2010-11-02] (TOSHIBA CORPORATION.) HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1295224 2010-07-01] (TOSHIBA Corporation) HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\.DEFAULT\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA) HKU\S-1-5-19\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA) HKU\S-1-5-20\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA) HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [846936 2011-05-16] (TOSHIBA) HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21444224 2014-05-08] (Skype Technologies S.A.) HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [name_07050906] => c:\users\yasmin\appdata\local\name_07050906\name_07050906.exe [2990080 2014-07-05] () HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-08-22] (Google Inc.) HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [AudialsNotifier] => C:\Program Files (x86)\Audials\Audials 11\AudialsNotifier.exe [2208520 2014-06-11] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Toshiba Places Icon Utility.lnk ShortcutTarget: Toshiba Places Icon Utility.lnk -> C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe (Toshiba) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\name_07050906.lnk ShortcutTarget: name_07050906.lnk -> C:\Users\Yasmin\AppData\Local\name_07050906\name_07050906.exe () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== ProxyServer: http=127.0.0.1:13957;https=127.0.0.1:13957 StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {15D1CCBD-7C64-49C2-B1D3-65DD51820FDA} URL = hxxp://url24.info/?id=2111s9412a6224&q={searchTerms} SearchScopes: HKLM - {15D1CCBD-7C64-49C2-B1D3-65DD51820FDA} URL = hxxp://url24.info/?id=2111s9412a6224&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {15D1CCBD-7C64-49C2-B1D3-65DD51820FDA} URL = hxxp://url24.info/?id=2111s9412a6224&q={searchTerms} BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20140112153556.dll (McAfee, Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20140112153556.dll (McAfee, Inc.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore FF Extension: McAfee ScriptScan for Firefox - C:\Program Files (x86)\Common Files\McAfee\SystemCore [2011-08-22] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2011-08-22] FF HKCU\...\Firefox\Extensions: [{C498947A-67CC-C868-A155-E77523522BAE}] - C:\Program Files (x86)\BlockAndSurf-soft\172.xpi Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR StartupUrls: "hxxp://www.google.de/" CHR Extension: (Google Docs) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-14] CHR Extension: (Google Drive) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-14] CHR Extension: (WOT) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-07-05] CHR Extension: (YouTube) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-14] CHR Extension: (Adblock Plus) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-05] CHR Extension: (Google-Suche) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-14] CHR Extension: (Google Wallet) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-12] CHR Extension: (Google Mail) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-14] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11] ==================== Services (Whitelisted) ================= R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation) R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [1809920 2010-08-04] (Realsil Microelectronics Inc.) [File not signed] R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) S3 McAWFwk; c:\Program Files\mcafee\msc\McAWFwk.exe [225216 2011-01-28] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) R2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [501768 2011-03-17] (McAfee, Inc.) R2 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [199304 2012-05-25] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [210616 2012-05-25] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [162224 2012-05-25] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.) S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH) S2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service [X] ==================== Drivers (Whitelisted) ==================== R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [65264 2012-02-22] (McAfee, Inc.) R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [160792 2012-02-22] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [229528 2012-02-22] (McAfee, Inc.) U3 mfeavfk01; No ImagePath R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [487296 2012-02-22] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [647208 2012-02-22] (McAfee, Inc.) R1 mfenlfk; C:\Windows\System32\DRIVERS\mfenlfk.sys [75936 2012-02-22] (McAfee, Inc.) S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [100912 2012-02-22] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [289664 2012-02-22] (McAfee, Inc.) R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-06-11] (Audials AG) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-05 19:48 - 2014-07-05 19:49 - 00021023 _____ () C:\Users\Yasmin\Downloads\FRST.txt 2014-07-05 19:48 - 2014-07-05 19:48 - 00000000 ____D () C:\FRST 2014-07-05 19:47 - 2014-07-05 19:48 - 02084352 _____ (Farbar) C:\Users\Yasmin\Downloads\FRST64.exe 2014-07-05 16:32 - 2014-07-05 16:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-07-05 15:20 - 2014-07-05 15:20 - 00017609 _____ () C:\Ergebnisse.txt 2014-07-05 14:14 - 2014-07-05 15:18 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-05 14:14 - 2014-07-05 14:14 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-05 14:14 - 2014-07-05 14:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-05 14:13 - 2014-07-05 14:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-05 14:13 - 2014-07-05 14:13 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-05 14:13 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-05 14:13 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-07-05 14:13 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-07-05 14:09 - 2014-07-05 14:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Yasmin\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-05 13:49 - 2014-07-05 13:50 - 01346519 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.214.exe 2014-07-05 13:35 - 2014-07-05 13:35 - 00001185 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk 2014-07-05 13:35 - 2014-07-05 13:35 - 00001173 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-07-05 13:35 - 2014-07-05 13:35 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-07-05 13:19 - 2014-07-05 13:19 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\CrashRpt 2014-07-05 13:15 - 2014-07-05 13:15 - 00000954 _____ () C:\Users\Public\Desktop\Audials 11.lnk 2014-07-05 13:14 - 2014-07-05 13:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audials 11 2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\ProgramData\RapidSolution 2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\Program Files (x86)\Audials 2014-07-05 13:11 - 2014-07-05 13:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\RapidSolution 2014-07-05 13:07 - 2014-07-05 13:07 - 00470552 _____ () C:\Users\Yasmin\Downloads\soft32_TeamViewer_1.0.exe 2014-07-05 11:20 - 2014-07-05 11:20 - 00003224 _____ () C:\Windows\System32\Tasks\cmelajsb 2014-07-05 11:20 - 2014-07-05 11:20 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\cmelajsb.bat 2014-07-05 11:18 - 2014-07-05 11:18 - 00003220 _____ () C:\Windows\System32\Tasks\elsbix 2014-07-05 11:18 - 2014-07-05 11:18 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\elsbix.bat 2014-07-05 11:16 - 2014-07-05 11:16 - 00003222 _____ () C:\Windows\System32\Tasks\difkadc 2014-07-05 11:16 - 2014-07-05 11:16 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\difkadc.bat 2014-07-05 11:14 - 2014-07-05 11:14 - 00003220 _____ () C:\Windows\System32\Tasks\ehhiar 2014-07-05 11:14 - 2014-07-05 11:14 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\ehhiar.bat 2014-07-05 11:12 - 2014-07-05 11:12 - 00003220 _____ () C:\Windows\System32\Tasks\mrxota 2014-07-05 11:12 - 2014-07-05 11:12 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\mrxota.bat 2014-07-05 11:11 - 2014-07-05 11:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\com 2014-07-05 11:10 - 2014-07-05 11:10 - 00003224 _____ () C:\Windows\System32\Tasks\qscfhzbe 2014-07-05 11:10 - 2014-07-05 11:10 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\qscfhzbe.bat 2014-07-05 11:09 - 2014-07-05 16:27 - 00000288 _____ () C:\Windows\Tasks\PerfMonitor_strtp.job 2014-07-05 11:09 - 2014-07-05 11:14 - 00002504 _____ () C:\Windows\System32\Tasks\PerfMonitor_strtp 2014-07-05 11:07 - 2014-07-05 11:07 - 00003220 _____ () C:\Windows\System32\Tasks\cfkxbi 2014-07-05 11:06 - 2014-07-05 19:47 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\name_07050906 2014-07-04 23:44 - 2014-07-04 23:44 - 00000030 _____ () C:\Users\Yasmin\Downloads\streamurl.ram 2014-07-04 22:09 - 2014-07-04 22:09 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{37404FF7-030E-48E2-A558-14DFA93EEE9E} 2014-07-03 21:58 - 2014-07-03 21:59 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E9BB536-0BF2-446D-8D48-DC87C01C2FC3} 2014-06-29 12:28 - 2014-06-29 12:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E1CAE782-0FD8-41B0-9FD8-7E33BBD98301} 2014-06-28 23:52 - 2014-06-28 23:52 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{810DEC4A-80C1-4FD5-B28B-5BFC530AE508} 2014-06-27 21:32 - 2014-06-27 21:32 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{24E647D5-B426-4A01-AF7E-14A6AE314912} 2014-06-26 20:30 - 2014-06-26 20:30 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{D8B715AD-B34D-4D33-A09C-C33244F9D5C0} 2014-06-25 19:28 - 2014-06-25 19:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E893FD49-F480-401D-914A-5942727764A4} 2014-06-24 21:22 - 2014-06-24 21:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{41D84405-36F0-449C-9EFA-213D56C3AA10} 2014-06-23 22:00 - 2014-06-23 22:00 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F110FA2D-C85B-4F52-B108-8E9ED1857A01} 2014-06-22 15:23 - 2014-06-22 15:23 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{75B97884-1D8B-4CCB-83FC-048BB61EB30E} 2014-06-21 20:24 - 2014-06-21 20:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{9C7EDFC2-FB6C-49EB-9193-23E5598340C5} 2014-06-20 23:26 - 2014-06-20 23:27 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B713B85D-3B2D-4962-8CA2-F1C383D94808} 2014-06-19 14:24 - 2014-06-19 14:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{FC9ED3F9-DD7E-411E-9269-3766501127B5} 2014-06-18 21:20 - 2014-06-18 21:20 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{EB3FAF98-E5F5-4F1E-8E10-ABA85A38A761} 2014-06-16 20:22 - 2014-06-16 20:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{3BF0F0AD-2D46-4BED-A50C-18E664F4F590} 2014-06-15 21:57 - 2014-06-15 21:57 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{19CDCCD7-B9FD-4316-A1B1-2D06A27CF368} 2014-06-15 20:58 - 2014-06-15 20:58 - 04631095 _____ () C:\Users\Yasmin\Documents\Unbenannt 1.odp 2014-06-15 15:41 - 2014-06-15 15:42 - 00000000 ___SD () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0 2014-06-15 15:41 - 2014-06-15 15:41 - 00001192 _____ () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0.lnk 2014-06-15 15:40 - 2014-06-15 15:41 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-06-15 15:38 - 2014-06-15 15:38 - 00000000 ____D () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0 (de) Installation Files 2014-06-15 15:21 - 2014-06-15 15:21 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer (1).exe 2014-06-15 15:01 - 2014-06-15 15:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero_AG 2014-06-15 15:00 - 2014-06-15 15:26 - 164962843 _____ () C:\Users\Yasmin\Downloads\Apache_OpenOffice_4.1.0_Win_x86_install_de.exe 2014-06-15 15:00 - 2014-06-15 15:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero 2014-06-15 14:59 - 2014-06-15 14:59 - 00003106 _____ () C:\Windows\System32\Tasks\{DCDD5B02-D205-4113-8043-ABDAB776D6F9} 2014-06-15 14:57 - 2014-06-15 14:59 - 106801603 _____ () C:\Users\Yasmin\Downloads\Nicht bestätigt 864307.crdownload 2014-06-15 14:51 - 2014-06-15 14:51 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer.exe 2014-06-15 14:20 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-06-15 14:17 - 2014-07-05 13:56 - 00000000 ____D () C:\AdwCleaner 2014-06-15 14:15 - 2014-06-15 14:16 - 01333465 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.212.exe 2014-06-14 17:48 - 2014-06-14 17:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-14 17:12 - 2014-06-14 17:13 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Adobe 2014-06-14 15:53 - 2014-06-14 15:53 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E519259-ADFA-4445-9FF2-A60967D85830} 2014-06-14 14:41 - 2014-06-14 14:41 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{51B5E13B-B124-4678-B7E1-59E1D21E084E} 2014-06-12 13:43 - 2014-06-12 13:43 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6D0186BE-0396-43A5-8D71-4D0C5779FE26} 2014-06-12 12:58 - 2014-06-12 12:58 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0 (1).exe 2014-06-11 22:38 - 2014-06-11 22:38 - 00830792 _____ (Click Me In Limited) C:\Users\Yasmin\AppData\Local\nstE584.tmp 2014-06-11 22:31 - 2014-06-14 17:54 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\OpenOffice 2014-06-11 22:31 - 2014-06-11 22:31 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-06-11 22:24 - 2014-06-14 17:54 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Opera Software 2014-06-11 22:24 - 2014-06-11 22:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Opera Software 2014-06-11 22:23 - 2014-06-14 17:56 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMeterExpress 2014-06-11 22:22 - 2014-06-14 17:56 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\PriceMeter Express 2014-06-11 22:20 - 2014-06-15 14:29 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-06-11 22:19 - 2014-06-14 17:56 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér 2014-06-11 21:38 - 2014-07-05 19:37 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-11 21:38 - 2014-06-11 21:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-11 21:38 - 2014-06-11 21:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-11 21:38 - 2014-06-11 21:38 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-11 21:38 - 2014-06-11 21:38 - 00000000 ____D () C:\Windows\system32\Macromed 2014-06-11 21:16 - 2014-06-11 21:16 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0.exe 2014-06-11 20:07 - 2014-06-11 20:08 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F63CE874-95F4-4014-9FFA-E120BA697A33} 2014-06-11 19:44 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-11 19:44 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-11 19:44 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-06-11 19:44 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-11 19:44 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-11 19:44 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-11 19:44 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-06-11 19:44 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-11 19:44 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-11 19:44 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-11 19:44 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-11 19:44 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-06-11 19:44 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-06-11 19:44 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-11 19:44 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-06-11 19:44 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-11 19:44 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-11 19:44 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-11 19:44 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-06-11 19:44 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-11 19:44 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-11 19:44 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-06-11 19:44 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-11 19:44 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-11 19:44 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-06-11 19:44 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-11 19:44 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-11 19:44 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-11 19:44 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-11 19:44 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-06-11 19:44 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-11 19:44 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-06-11 19:44 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-06-11 19:44 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-06-11 19:44 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-11 19:44 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-11 19:44 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-06-11 19:44 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-11 19:44 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-11 19:44 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-11 19:44 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-11 19:44 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-11 19:44 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-11 19:44 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-06-11 19:44 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-11 19:44 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-11 19:44 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-11 19:44 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-11 19:44 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-11 19:44 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-11 19:44 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-06-11 19:44 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-06-11 19:44 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-11 19:44 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-06-11 19:44 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-11 19:44 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2014-06-11 19:44 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-11 19:44 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-11 19:44 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2014-06-11 19:44 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-06-11 19:44 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2014-06-11 19:44 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-06-11 19:44 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll 2014-06-11 19:44 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-06-11 19:43 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-11 19:43 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-11 17:31 - 2014-06-11 17:31 - 00047240 _____ (RapidSolution Software AG) C:\Windows\system32\Drivers\tbhsd.sys 2014-06-11 17:31 - 2014-06-11 17:31 - 00024744 _____ (Audials AG) C:\Windows\system32\Drivers\RrNetCapFilterDriver.sys 2014-06-10 20:28 - 2014-06-10 20:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{8DDAE57A-5162-4B54-83CA-34A6D1AD5A76} 2014-06-09 19:29 - 2014-06-09 19:29 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B679CC51-C608-4AE5-8429-423D93E97BB1} 2014-06-08 15:04 - 2014-06-08 15:04 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{BE799AB3-FEC9-439F-9EE9-50C2DEB968DE} ==================== One Month Modified Files and Folders ======= 2014-07-05 19:49 - 2014-07-05 19:48 - 00021023 _____ () C:\Users\Yasmin\Downloads\FRST.txt 2014-07-05 19:48 - 2014-07-05 19:48 - 00000000 ____D () C:\FRST 2014-07-05 19:48 - 2014-07-05 19:47 - 02084352 _____ (Farbar) C:\Users\Yasmin\Downloads\FRST64.exe 2014-07-05 19:47 - 2014-07-05 11:06 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\name_07050906 2014-07-05 19:39 - 2010-11-21 08:50 - 00699370 _____ () C:\Windows\system32\perfh007.dat 2014-07-05 19:39 - 2010-11-21 08:50 - 00149220 _____ () C:\Windows\system32\perfc007.dat 2014-07-05 19:39 - 2009-07-14 07:13 - 01619896 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-05 19:38 - 2014-01-12 03:20 - 02000693 _____ () C:\Windows\WindowsUpdate.log 2014-07-05 19:37 - 2014-06-11 21:38 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-05 19:37 - 2014-01-13 20:52 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Skype 2014-07-05 19:37 - 2011-08-22 11:52 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-05 16:35 - 2009-07-14 06:45 - 00024912 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-05 16:35 - 2009-07-14 06:45 - 00024912 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-05 16:32 - 2014-07-05 16:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2014-07-05 16:32 - 2011-08-22 11:41 - 00001835 _____ () C:\Users\Public\Desktop\McAfee Internet Security.lnk 2014-07-05 16:27 - 2014-07-05 11:09 - 00000288 _____ () C:\Windows\Tasks\PerfMonitor_strtp.job 2014-07-05 16:27 - 2011-08-22 11:52 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-05 16:27 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-05 16:27 - 2009-07-14 06:51 - 00062190 _____ () C:\Windows\setupact.log 2014-07-05 16:26 - 2010-11-21 05:47 - 00149776 _____ () C:\Windows\PFRO.log 2014-07-05 15:20 - 2014-07-05 15:20 - 00017609 _____ () C:\Ergebnisse.txt 2014-07-05 15:18 - 2014-07-05 14:14 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-05 14:14 - 2014-07-05 14:14 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-05 14:14 - 2014-07-05 14:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-05 14:14 - 2014-07-05 14:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-05 14:13 - 2014-07-05 14:13 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-05 14:10 - 2014-07-05 14:09 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Yasmin\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-05 14:04 - 2014-01-12 04:01 - 00064024 _____ () C:\Users\Yasmin\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-05 13:58 - 2009-07-14 06:45 - 00294736 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-05 13:56 - 2014-06-15 14:17 - 00000000 ____D () C:\AdwCleaner 2014-07-05 13:56 - 2014-01-12 03:59 - 00000998 _____ () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-07-05 13:56 - 2011-08-22 11:52 - 00001289 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-07-05 13:56 - 2011-08-22 11:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-07-05 13:50 - 2014-07-05 13:49 - 01346519 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.214.exe 2014-07-05 13:35 - 2014-07-05 13:35 - 00001185 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk 2014-07-05 13:35 - 2014-07-05 13:35 - 00001173 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-07-05 13:35 - 2014-07-05 13:35 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-07-05 13:19 - 2014-07-05 13:19 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\CrashRpt 2014-07-05 13:15 - 2014-07-05 13:15 - 00000954 _____ () C:\Users\Public\Desktop\Audials 11.lnk 2014-07-05 13:15 - 2014-07-05 13:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audials 11 2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\ProgramData\RapidSolution 2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\Program Files (x86)\Audials 2014-07-05 13:11 - 2014-07-05 13:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\RapidSolution 2014-07-05 13:07 - 2014-07-05 13:07 - 00470552 _____ () C:\Users\Yasmin\Downloads\soft32_TeamViewer_1.0.exe 2014-07-05 11:20 - 2014-07-05 11:20 - 00003224 _____ () C:\Windows\System32\Tasks\cmelajsb 2014-07-05 11:20 - 2014-07-05 11:20 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\cmelajsb.bat 2014-07-05 11:18 - 2014-07-05 11:18 - 00003220 _____ () C:\Windows\System32\Tasks\elsbix 2014-07-05 11:18 - 2014-07-05 11:18 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\elsbix.bat 2014-07-05 11:16 - 2014-07-05 11:16 - 00003222 _____ () C:\Windows\System32\Tasks\difkadc 2014-07-05 11:16 - 2014-07-05 11:16 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\difkadc.bat 2014-07-05 11:14 - 2014-07-05 11:14 - 00003220 _____ () C:\Windows\System32\Tasks\ehhiar 2014-07-05 11:14 - 2014-07-05 11:14 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\ehhiar.bat 2014-07-05 11:14 - 2014-07-05 11:09 - 00002504 _____ () C:\Windows\System32\Tasks\PerfMonitor_strtp 2014-07-05 11:12 - 2014-07-05 11:12 - 00003220 _____ () C:\Windows\System32\Tasks\mrxota 2014-07-05 11:12 - 2014-07-05 11:12 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\mrxota.bat 2014-07-05 11:11 - 2014-07-05 11:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\com 2014-07-05 11:10 - 2014-07-05 11:10 - 00003224 _____ () C:\Windows\System32\Tasks\qscfhzbe 2014-07-05 11:10 - 2014-07-05 11:10 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\qscfhzbe.bat 2014-07-05 11:07 - 2014-07-05 11:07 - 00003220 _____ () C:\Windows\System32\Tasks\cfkxbi 2014-07-05 10:24 - 2011-08-22 11:38 - 00000000 ____D () C:\Program Files (x86)\McAfee 2014-07-04 23:44 - 2014-07-04 23:44 - 00000030 _____ () C:\Users\Yasmin\Downloads\streamurl.ram 2014-07-04 22:09 - 2014-07-04 22:09 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{37404FF7-030E-48E2-A558-14DFA93EEE9E} 2014-07-03 21:59 - 2014-07-03 21:58 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E9BB536-0BF2-446D-8D48-DC87C01C2FC3} 2014-06-29 12:28 - 2014-06-29 12:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E1CAE782-0FD8-41B0-9FD8-7E33BBD98301} 2014-06-28 23:52 - 2014-06-28 23:52 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{810DEC4A-80C1-4FD5-B28B-5BFC530AE508} 2014-06-27 21:32 - 2014-06-27 21:32 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{24E647D5-B426-4A01-AF7E-14A6AE314912} 2014-06-26 20:30 - 2014-06-26 20:30 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{D8B715AD-B34D-4D33-A09C-C33244F9D5C0} 2014-06-25 19:28 - 2014-06-25 19:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E893FD49-F480-401D-914A-5942727764A4} 2014-06-24 21:22 - 2014-06-24 21:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{41D84405-36F0-449C-9EFA-213D56C3AA10} 2014-06-23 22:00 - 2014-06-23 22:00 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F110FA2D-C85B-4F52-B108-8E9ED1857A01} 2014-06-22 15:23 - 2014-06-22 15:23 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{75B97884-1D8B-4CCB-83FC-048BB61EB30E} 2014-06-21 20:24 - 2014-06-21 20:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{9C7EDFC2-FB6C-49EB-9193-23E5598340C5} 2014-06-20 23:27 - 2014-06-20 23:26 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B713B85D-3B2D-4962-8CA2-F1C383D94808} 2014-06-19 14:24 - 2014-06-19 14:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{FC9ED3F9-DD7E-411E-9269-3766501127B5} 2014-06-18 21:20 - 2014-06-18 21:20 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{EB3FAF98-E5F5-4F1E-8E10-ABA85A38A761} 2014-06-16 20:22 - 2014-06-16 20:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{3BF0F0AD-2D46-4BED-A50C-18E664F4F590} 2014-06-15 21:57 - 2014-06-15 21:57 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{19CDCCD7-B9FD-4316-A1B1-2D06A27CF368} 2014-06-15 20:58 - 2014-06-15 20:58 - 04631095 _____ () C:\Users\Yasmin\Documents\Unbenannt 1.odp 2014-06-15 15:42 - 2014-06-15 15:41 - 00000000 ___SD () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0 2014-06-15 15:41 - 2014-06-15 15:41 - 00001192 _____ () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0.lnk 2014-06-15 15:41 - 2014-06-15 15:40 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-06-15 15:38 - 2014-06-15 15:38 - 00000000 ____D () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0 (de) Installation Files 2014-06-15 15:26 - 2014-06-15 15:00 - 164962843 _____ () C:\Users\Yasmin\Downloads\Apache_OpenOffice_4.1.0_Win_x86_install_de.exe 2014-06-15 15:21 - 2014-06-15 15:21 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer (1).exe 2014-06-15 15:01 - 2014-06-15 15:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero_AG 2014-06-15 15:01 - 2014-06-15 15:00 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero 2014-06-15 14:59 - 2014-06-15 14:59 - 00003106 _____ () C:\Windows\System32\Tasks\{DCDD5B02-D205-4113-8043-ABDAB776D6F9} 2014-06-15 14:59 - 2014-06-15 14:57 - 106801603 _____ () C:\Users\Yasmin\Downloads\Nicht bestätigt 864307.crdownload 2014-06-15 14:51 - 2014-06-15 14:51 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer.exe 2014-06-15 14:29 - 2014-06-11 22:20 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-06-15 14:16 - 2014-06-15 14:15 - 01333465 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.212.exe 2014-06-15 14:02 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-06-14 18:11 - 2009-07-14 04:34 - 00000537 _____ () C:\Windows\win.ini 2014-06-14 17:59 - 2014-01-12 03:57 - 00000000 ____D () C:\Users\Yasmin 2014-06-14 17:56 - 2014-06-11 22:23 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMeterExpress 2014-06-14 17:56 - 2014-06-11 22:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\PriceMeter Express 2014-06-14 17:56 - 2014-06-11 22:19 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér 2014-06-14 17:56 - 2014-05-07 19:09 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-14 17:56 - 2014-01-12 04:45 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\TOSHIBA_Corporation 2014-06-14 17:56 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-06-14 17:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-06-14 17:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-06-14 17:55 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-06-14 17:54 - 2014-06-11 22:31 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\OpenOffice 2014-06-14 17:54 - 2014-06-11 22:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Opera Software 2014-06-14 17:54 - 2014-02-21 01:06 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\SoftGrid Client 2014-06-14 17:54 - 2011-08-22 11:38 - 00000000 ____D () C:\ProgramData\McAfee 2014-06-14 17:48 - 2014-06-14 17:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-14 17:13 - 2014-06-14 17:12 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Adobe 2014-06-14 17:12 - 2014-01-12 16:08 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Adobe 2014-06-14 16:51 - 2014-01-12 04:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Toshiba 2014-06-14 15:53 - 2014-06-14 15:53 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E519259-ADFA-4445-9FF2-A60967D85830} 2014-06-14 14:41 - 2014-06-14 14:41 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{51B5E13B-B124-4678-B7E1-59E1D21E084E} 2014-06-12 13:43 - 2014-06-12 13:43 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6D0186BE-0396-43A5-8D71-4D0C5779FE26} 2014-06-12 12:58 - 2014-06-12 12:58 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0 (1).exe 2014-06-11 22:38 - 2014-06-11 22:38 - 00830792 _____ (Click Me In Limited) C:\Users\Yasmin\AppData\Local\nstE584.tmp 2014-06-11 22:31 - 2014-06-11 22:31 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-06-11 22:24 - 2014-06-11 22:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Opera Software 2014-06-11 21:38 - 2014-06-11 21:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-11 21:38 - 2014-06-11 21:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-11 21:38 - 2014-06-11 21:38 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-11 21:38 - 2014-06-11 21:38 - 00000000 ____D () C:\Windows\system32\Macromed 2014-06-11 21:16 - 2014-06-11 21:16 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0.exe 2014-06-11 20:08 - 2014-06-11 20:07 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F63CE874-95F4-4014-9FFA-E120BA697A33} 2014-06-11 17:31 - 2014-06-11 17:31 - 00047240 _____ (RapidSolution Software AG) C:\Windows\system32\Drivers\tbhsd.sys 2014-06-11 17:31 - 2014-06-11 17:31 - 00024744 _____ (Audials AG) C:\Windows\system32\Drivers\RrNetCapFilterDriver.sys 2014-06-10 20:28 - 2014-06-10 20:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{8DDAE57A-5162-4B54-83CA-34A6D1AD5A76} 2014-06-09 19:29 - 2014-06-09 19:29 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B679CC51-C608-4AE5-8429-423D93E97BB1} 2014-06-08 15:04 - 2014-06-08 15:04 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{BE799AB3-FEC9-439F-9EE9-50C2DEB968DE} 2014-06-08 11:13 - 2014-06-11 19:43 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-08 11:08 - 2014-06-11 19:43 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll Some content of TEMP: ==================== C:\Users\Yasmin\AppData\Local\Temp\-23pzvcf.dll C:\Users\Yasmin\AppData\Local\Temp\-zw7ebio.dll C:\Users\Yasmin\AppData\Local\Temp\04czr0ef.dll C:\Users\Yasmin\AppData\Local\Temp\0y4qs-v8.dll C:\Users\Yasmin\AppData\Local\Temp\3j3exo3z.dll C:\Users\Yasmin\AppData\Local\Temp\4nyosznz.dll C:\Users\Yasmin\AppData\Local\Temp\59bg2dsi.dll C:\Users\Yasmin\AppData\Local\Temp\73-oiasl.dll C:\Users\Yasmin\AppData\Local\Temp\8hwvac6t.dll C:\Users\Yasmin\AppData\Local\Temp\BackupSetup.exe C:\Users\Yasmin\AppData\Local\Temp\bfk954rp.dll C:\Users\Yasmin\AppData\Local\Temp\bjsyqg_c.dll C:\Users\Yasmin\AppData\Local\Temp\dw_kcoie.dll C:\Users\Yasmin\AppData\Local\Temp\eqebiofn.dll C:\Users\Yasmin\AppData\Local\Temp\fenrybn2.dll C:\Users\Yasmin\AppData\Local\Temp\h3tcdzan.dll C:\Users\Yasmin\AppData\Local\Temp\i8syhl6v.dll C:\Users\Yasmin\AppData\Local\Temp\itavi2y-.dll C:\Users\Yasmin\AppData\Local\Temp\jn5lqovs.dll C:\Users\Yasmin\AppData\Local\Temp\k_312ihf.dll C:\Users\Yasmin\AppData\Local\Temp\lagmpmi6.dll C:\Users\Yasmin\AppData\Local\Temp\lgb3nyio.dll C:\Users\Yasmin\AppData\Local\Temp\melbg6oc.dll C:\Users\Yasmin\AppData\Local\Temp\oemsetup.exe C:\Users\Yasmin\AppData\Local\Temp\ognwvd9v.dll C:\Users\Yasmin\AppData\Local\Temp\om_ohj5c.dll C:\Users\Yasmin\AppData\Local\Temp\OpenOffice_4.1.0_Win_x86_install_de.exe C:\Users\Yasmin\AppData\Local\Temp\optprosetup.exe C:\Users\Yasmin\AppData\Local\Temp\p6ijzaea.dll C:\Users\Yasmin\AppData\Local\Temp\pirm6xjt.dll C:\Users\Yasmin\AppData\Local\Temp\PrefJsonCpp.exe C:\Users\Yasmin\AppData\Local\Temp\pxhrabew.dll C:\Users\Yasmin\AppData\Local\Temp\qces_gra.dll C:\Users\Yasmin\AppData\Local\Temp\qu7inx1k.dll C:\Users\Yasmin\AppData\Local\Temp\Quarantine.exe C:\Users\Yasmin\AppData\Local\Temp\sizrcajk.dll C:\Users\Yasmin\AppData\Local\Temp\spta3k3e.dll C:\Users\Yasmin\AppData\Local\Temp\sptgfvme.dll C:\Users\Yasmin\AppData\Local\Temp\sqlite3.exe C:\Users\Yasmin\AppData\Local\Temp\vkk8qkt0.dll C:\Users\Yasmin\AppData\Local\Temp\vsskyyrf.dll C:\Users\Yasmin\AppData\Local\Temp\vyahhbh2.dll C:\Users\Yasmin\AppData\Local\Temp\xsglum2y.dll C:\Users\Yasmin\AppData\Local\Temp\yf7lvekt.dll C:\Users\Yasmin\AppData\Local\Temp\zer9fyk5.dll C:\Users\Yasmin\AppData\Local\Temp\_yualj7d.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-11 20:02 ==================== End Of Log ============================ Danke schon mal für die Hilfe |
06.07.2014, 11:14 | #4 |
/// the machine /// TB-Ausbilder | Fake Flash-Player Update gedownloadet :(( Adware & Co. deinstallieren
Solltest Du ein Programm nicht finden oder nicht deinstallieren können, mache bitte mit dem nächsten Schritt weiter: Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
06.07.2014, 14:01 | #5 |
| Fake Flash-Player Update gedownloadet :(( Hallo, Ich habe ein Problem. beim Klicken des Links zum downladen von Combofix. Läd er das zwar herunter aber dann steht plötzlich "Fehler-Fehler beim Herunterladen" Gruß |
06.07.2014, 17:52 | #6 |
/// the machine /// TB-Ausbilder | Fake Flash-Player Update gedownloadet :(( Andere Browser getestet? AV Programm abgeschaltet?
__________________ --> Fake Flash-Player Update gedownloadet :(( |
07.07.2014, 17:53 | #7 |
| Fake Flash-Player Update gedownloadet :(( Moin, hier ist der cobofix log Code:
ATTFilter ComboFix 14-07-03.01 - Yasmin 06.07.2014 21:30:05.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3692.2383 [GMT 2:00] ausgeführt von:: c:\users\Yasmin\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Yasmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\SpadeCast_iels c:\users\Yasmin\AppData\Local\nstE584.tmp . . ((((((((((((((((((((((( Dateien erstellt von 2014-06-06 bis 2014-07-06 )))))))))))))))))))))))))))))) . . 2014-07-06 21:16 . 2014-07-06 21:16 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-07-05 17:48 . 2014-07-05 17:53 -------- d-----w- C:\FRST 2014-07-05 12:14 . 2014-07-05 13:18 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2014-07-05 12:13 . 2014-05-12 05:26 63704 ----a-w- c:\windows\system32\drivers\mwac.sys 2014-07-05 12:13 . 2014-05-12 05:26 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2014-07-05 12:13 . 2014-07-05 12:14 -------- d-----w- c:\program files (x86)\ Malwarebytes Anti-Malware 2014-07-05 12:13 . 2014-07-05 12:13 -------- d-----w- c:\programdata\Malwarebytes 2014-07-05 12:13 . 2014-05-12 05:25 25816 ----a-w- c:\windows\system32\drivers\mbam.sys 2014-07-05 11:35 . 2014-07-05 11:35 -------- d-----w- c:\program files (x86)\TeamViewer 2014-07-05 11:19 . 2014-07-05 11:19 -------- d-----w- c:\users\Yasmin\AppData\Local\CrashRpt 2014-07-05 11:14 . 2014-07-05 11:14 -------- d-----w- c:\programdata\RapidSolution 2014-07-05 11:14 . 2014-07-05 11:14 -------- d-----w- c:\program files (x86)\Audials 2014-07-05 11:11 . 2014-07-05 11:11 -------- d-----w- c:\users\Yasmin\AppData\Local\RapidSolution 2014-07-05 09:20 . 2014-07-05 09:20 266 ----a-w- c:\users\Yasmin\AppData\Local\cmelajsb.bat 2014-07-05 09:18 . 2014-07-05 09:18 266 ----a-w- c:\users\Yasmin\AppData\Local\elsbix.bat 2014-07-05 09:16 . 2014-07-05 09:16 266 ----a-w- c:\users\Yasmin\AppData\Local\difkadc.bat 2014-07-05 09:14 . 2014-07-05 09:14 266 ----a-w- c:\users\Yasmin\AppData\Local\ehhiar.bat 2014-07-05 09:12 . 2014-07-05 09:12 266 ----a-w- c:\users\Yasmin\AppData\Local\mrxota.bat 2014-07-05 09:11 . 2014-07-05 09:11 -------- d-----w- c:\users\Yasmin\AppData\Local\com 2014-07-05 09:10 . 2014-07-05 09:10 266 ----a-w- c:\users\Yasmin\AppData\Local\qscfhzbe.bat 2014-07-05 09:06 . 2014-07-05 18:03 -------- d-----w- c:\users\Yasmin\AppData\Local\name_07050906 2014-06-15 13:40 . 2014-06-15 13:41 -------- d-----w- c:\program files (x86)\OpenOffice 4 2014-06-15 13:00 . 2014-06-15 13:01 -------- d-----w- c:\users\Yasmin\AppData\Local\Nero 2014-06-15 12:20 . 2010-08-30 06:34 536576 ----a-w- c:\windows\SysWow64\sqlite3.dll 2014-06-15 12:17 . 2014-07-05 11:56 -------- d-----w- C:\AdwCleaner 2014-06-14 15:12 . 2014-06-14 15:13 -------- d-----w- c:\users\Yasmin\AppData\Local\Adobe 2014-06-11 20:31 . 2014-06-14 15:54 -------- d-----w- c:\users\Yasmin\AppData\Roaming\OpenOffice 2014-06-11 20:24 . 2014-06-11 20:24 -------- d-----w- c:\users\Yasmin\AppData\Local\Opera Software 2014-06-11 20:24 . 2014-06-14 15:54 -------- d-----w- c:\users\Yasmin\AppData\Roaming\Opera Software 2014-06-11 20:22 . 2014-06-14 15:56 -------- d-----w- c:\users\Yasmin\AppData\Local\PriceMeter Express 2014-06-11 20:20 . 2014-06-15 12:29 -------- d-----w- c:\program files (x86)\Opera 2014-06-11 20:19 . 2014-06-11 20:19 -------- d-----w- c:\users\Yasmin\AppData\Local\Programs 2014-06-11 19:38 . 2014-06-11 19:38 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-06-11 19:38 . 2014-06-11 19:38 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-06-11 19:38 . 2014-06-11 19:38 -------- d-----w- c:\windows\system32\Macromed 2014-06-11 17:43 . 2014-06-08 09:13 506368 ----a-w- c:\windows\system32\aepdu.dll 2014-06-11 17:43 . 2014-06-08 09:08 424448 ----a-w- c:\windows\system32\aeinv.dll 2014-06-11 15:31 . 2014-06-11 15:31 47240 ----a-w- c:\windows\system32\drivers\tbhsd.sys 2014-06-11 15:31 . 2014-06-11 15:31 24744 ----a-w- c:\windows\system32\drivers\RrNetCapFilterDriver.sys . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-04-12 02:22 . 2014-05-14 16:12 155072 ----a-w- c:\windows\system32\drivers\ksecpkg.sys 2014-04-12 02:22 . 2014-05-14 16:12 95680 ----a-w- c:\windows\system32\drivers\ksecdd.sys 2014-04-12 02:19 . 2014-05-14 16:12 136192 ----a-w- c:\windows\system32\sspicli.dll 2014-04-12 02:19 . 2014-05-14 16:12 29184 ----a-w- c:\windows\system32\sspisrv.dll 2014-04-12 02:19 . 2014-05-14 16:12 28160 ----a-w- c:\windows\system32\secur32.dll 2014-04-12 02:19 . 2014-05-14 16:12 1460736 ----a-w- c:\windows\system32\lsasrv.dll 2014-04-12 02:19 . 2014-05-14 16:12 31232 ----a-w- c:\windows\system32\lsass.exe 2014-04-12 02:12 . 2014-05-14 16:12 22016 ----a-w- c:\windows\SysWow64\secur32.dll 2014-04-12 02:10 . 2014-05-14 16:12 96768 ----a-w- c:\windows\SysWow64\sspicli.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TOPI.EXE"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe" [2011-05-16 846936] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-05-08 21444224] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-22 39408] "AudialsNotifier"="c:\program files (x86)\Audials\Audials 11\AudialsNotifier.exe" [2014-06-11 2208520] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288] "NBAgent"="c:\program files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2011-06-29 1409424] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-06-28 336384] "SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-11-09 532480] "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-04 423936] "KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2010-08-15 34160] "TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-11-02 2475384] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2010-07-01 1295224] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "TOPI.EXE"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2011-05-16 846936] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Toshiba Places Icon Utility.lnk - c:\program files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe [2011-8-22 1493888] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 0140851404674326mcinstcleanup;McAfee Application Installer Cleanup (0140851404674326);c:\users\Yasmin\AppData\Local\Temp\014085~1.EXE;c:\users\Yasmin\AppData\Local\Temp\014085~1.EXE [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [x] R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe;c:\windows\SYSNATIVE\mfevtps.exe [x] R2 WindowsMangerProtect;WindowsMangerProtect Service;c:\programdata\WindowsMangerProtect\ProtectWindowsManager.exe;c:\programdata\WindowsMangerProtect\ProtectWindowsManager.exe [x] R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys;c:\windows\SYSNATIVE\drivers\cfwids.sys [x] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys;c:\windows\SYSNATIVE\drivers\mfefirek.sys [x] R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys;c:\windows\SYSNATIVE\drivers\mferkdet.sys [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe;c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x] S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x] S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys;c:\windows\SYSNATIVE\drivers\mfewfpk.sys [x] S1 RrNetCapFilterDriver;RadioRip Filter Driver;c:\windows\system32\DRIVERS\RrNetCapFilterDriver.sys;c:\windows\SYSNATIVE\DRIVERS\RrNetCapFilterDriver.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x] S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x] S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [x] S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [x] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [x] S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x] S3 CeKbFilter;CeKbFilter;c:\windows\system32\DRIVERS\CeKbFilter.sys;c:\windows\SYSNATIVE\DRIVERS\CeKbFilter.sys [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys;c:\windows\SYSNATIVE\DRIVERS\pgeffect.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys;c:\windows\SYSNATIVE\DRIVERS\rtl8192Ce.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x] S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x] . . --- Andere Dienste/Treiber im Speicher --- . *Deregistered* - mfeavfk01 *Deregistered* - mfenlfk . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-05-23 22:08 1091912 ----a-w- c:\program files (x86)\Google\Chrome\Application\35.0.1916.114\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-07-06 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-11 19:38] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2011-02-10 1546720] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-10 11580520] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-11-03 2181224] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 709976] "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376] "Toshiba Registration"="c:\program files\TOSHIBA\Registration\ToshibaReminder.exe" [2011-08-22 150992] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com uDefault_Search_URL = hxxp://www.google.com mDefault_Search_URL = hxxp://www.google.com mDefault_Page_URL = hxxp://www.google.com mStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://www.google.com uInternet Settings,ProxyServer = http=127.0.0.1:13957;https=127.0.0.1:13957 IE: Zu TOSHIBA Bulletin Board hinzufügen - c:\program files\TOSHIBA\BulletinBoard\TosBBCom.dll/1000 TCP: DhcpNameServer = 192.168.0.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe AddRemove-webssearches uninstall - c:\users\Yasmin\AppData\Roaming\webssearches\UninstallManager.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-07-06 23:20:13 ComboFix-quarantined-files.txt 2014-07-06 21:20 . Vor Suchlauf: 9 Verzeichnis(se), 109.639.327.744 Bytes frei Nach Suchlauf: 11 Verzeichnis(se), 109.745.770.496 Bytes frei . - - End Of File - - 7B7060BB101885427B6AA96380368764 A36C5E4F47E84449FF07ED3517B43A31 |
08.07.2014, 09:36 | #8 |
/// the machine /// TB-Ausbilder | Fake Flash-Player Update gedownloadet :(( Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.07.2014, 20:50 | #9 |
| Fake Flash-Player Update gedownloadet :(( Moin hier die verschiedene Logs FRST FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-07-2014 01 Ran by Yasmin (administrator) on YASMIN-TOSH on 08-07-2014 16:26:46 Running from C:\Users\Yasmin\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (TOSHIBA Corporation) C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe () C:\Program Files (x86)\Audials\Audials 11\AudialsNotifier.exe (Toshiba) C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe (TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Desktop.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [TosNC] => C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [597928 2011-03-03] (TOSHIBA Corporation) HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38304 2010-12-14] (TOSHIBA Corporation) HKLM\...\Run: [Toshiba TEMPRO] => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1546720 2011-02-10] (Toshiba Europe GmbH) HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [566184 2010-09-28] (TOSHIBA Corporation) HKLM\...\Run: [SmoothView] => C:\Program Files\Toshiba\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation) HKLM\...\Run: [00TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [915320 2010-10-28] (TOSHIBA Corporation) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11580520 2010-11-10] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2181224 2010-11-03] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2387752 2010-09-30] (Synaptics Incorporated) HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2010-02-05] (TOSHIBA Corporation) HKLM\...\Run: [SmartFaceVWatcher] => C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-10-19] (TOSHIBA Corporation) HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation) HKLM\...\Run: [Toshiba Registration] => C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe [150992 2011-08-22] (Toshiba Europe GmbH) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [NBAgent] => c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1409424 2011-06-29] (Nero AG) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-06-29] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SVPWUTIL] => C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe [532480 2010-11-09] (TOSHIBA) HKLM-x32\...\Run: [HWSetup] => C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [423936 2010-03-04] (TOSHIBA Electronics, Inc.) HKLM-x32\...\Run: [KeNotify] => C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [34160 2010-08-15] (TOSHIBA CORPORATION) HKLM-x32\...\Run: [TWebCamera] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2475384 2010-11-02] (TOSHIBA CORPORATION.) HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1295224 2010-07-01] (TOSHIBA Corporation) HKU\.DEFAULT\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA) HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [846936 2011-05-16] (TOSHIBA) HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21444224 2014-05-08] (Skype Technologies S.A.) HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-08-22] (Google Inc.) HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [AudialsNotifier] => C:\Program Files (x86)\Audials\Audials 11\AudialsNotifier.exe [2208520 2014-06-11] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Toshiba Places Icon Utility.lnk ShortcutTarget: Toshiba Places Icon Utility.lnk -> C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe (Toshiba) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== ProxyServer: http=127.0.0.1:13957;https=127.0.0.1:13957 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {15D1CCBD-7C64-49C2-B1D3-65DD51820FDA} URL = hxxp://url24.info/?id=2111s9412a6224&q={searchTerms} SearchScopes: HKLM - {15D1CCBD-7C64-49C2-B1D3-65DD51820FDA} URL = hxxp://url24.info/?id=2111s9412a6224&q={searchTerms} SearchScopes: HKLM-x32 - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {15D1CCBD-7C64-49C2-B1D3-65DD51820FDA} URL = hxxp://url24.info/?id=2111s9412a6224&q={searchTerms} BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2011-08-22] FF HKCU\...\Firefox\Extensions: [{C498947A-67CC-C868-A155-E77523522BAE}] - C:\Program Files (x86)\BlockAndSurf-soft\172.xpi Chrome: ======= CHR HomePage: hxxp://www.google.com/ CHR StartupUrls: "hxxp://www.google.de/" CHR Extension: (Google Docs) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-14] CHR Extension: (Google Drive) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-14] CHR Extension: (WOT) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-07-05] CHR Extension: (YouTube) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-14] CHR Extension: (Adblock Plus) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-05] CHR Extension: (Google-Suche) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-14] CHR Extension: (Google Wallet) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-12] CHR Extension: (Google Mail) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-14] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11] ==================== Services (Whitelisted) ================= R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation) R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [1809920 2010-08-04] (Realsil Microelectronics Inc.) [File not signed] S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH) S2 0140851404674326mcinstcleanup; C:\Users\Yasmin\AppData\Local\Temp\014085~1.EXE -cleanup -nolog [X] S2 McAfee SiteAdvisor Service; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [X] S2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service [X] ==================== Drivers (Whitelisted) ==================== U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-06-11] (Audials AG) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-08 16:25 - 2014-07-08 16:25 - 00001160 _____ () C:\Users\Yasmin\Desktop\mbam.txt 2014-07-08 15:55 - 2014-07-08 15:55 - 00001059 _____ () C:\Users\Yasmin\Desktop\AdwCleaner[R2].txt 2014-07-07 18:55 - 2014-07-07 19:02 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-07-07 18:54 - 2014-07-07 18:55 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Yasmin\Downloads\revosetup95.exe 2014-07-06 21:27 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-07-06 21:27 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-07-06 21:27 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-07-06 21:27 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-07-06 21:27 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-07-06 21:27 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-07-06 21:27 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-07-06 21:27 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-07-06 21:25 - 2014-07-06 23:20 - 00000000 ____D () C:\Qoobox 2014-07-06 21:25 - 2014-07-06 23:17 - 00000000 ____D () C:\Windows\erdnt 2014-07-06 18:36 - 2014-07-06 21:22 - 05213907 ____R (Swearware) C:\Users\Yasmin\Desktop\ComboFix.exe 2014-07-05 19:50 - 2014-07-05 19:53 - 00037880 _____ () C:\Users\Yasmin\Downloads\Addition.txt 2014-07-05 19:48 - 2014-07-08 16:26 - 00016714 _____ () C:\Users\Yasmin\Downloads\FRST.txt 2014-07-05 19:48 - 2014-07-08 16:26 - 00000000 ____D () C:\FRST 2014-07-05 19:47 - 2014-07-05 19:48 - 02084352 _____ (Farbar) C:\Users\Yasmin\Downloads\FRST64.exe 2014-07-05 15:20 - 2014-07-05 15:20 - 00017609 _____ () C:\Ergebnisse.txt 2014-07-05 14:14 - 2014-07-08 15:57 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-05 14:14 - 2014-07-05 14:14 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-05 14:14 - 2014-07-05 14:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-05 14:13 - 2014-07-05 14:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-05 14:13 - 2014-07-05 14:13 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-05 14:13 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-05 14:13 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-07-05 14:13 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-07-05 14:09 - 2014-07-05 14:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Yasmin\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-05 13:49 - 2014-07-05 13:50 - 01346519 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.214.exe 2014-07-05 13:35 - 2014-07-05 13:35 - 00001185 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk 2014-07-05 13:35 - 2014-07-05 13:35 - 00001173 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-07-05 13:35 - 2014-07-05 13:35 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-07-05 13:19 - 2014-07-05 13:19 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\CrashRpt 2014-07-05 13:15 - 2014-07-05 13:15 - 00000954 _____ () C:\Users\Public\Desktop\Audials 11.lnk 2014-07-05 13:14 - 2014-07-05 13:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audials 11 2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\ProgramData\RapidSolution 2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\Program Files (x86)\Audials 2014-07-05 13:11 - 2014-07-05 13:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\RapidSolution 2014-07-05 13:07 - 2014-07-05 13:07 - 00470552 _____ () C:\Users\Yasmin\Downloads\soft32_TeamViewer_1.0.exe 2014-07-05 11:20 - 2014-07-05 11:20 - 00003224 _____ () C:\Windows\System32\Tasks\cmelajsb 2014-07-05 11:20 - 2014-07-05 11:20 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\cmelajsb.bat 2014-07-05 11:18 - 2014-07-05 11:18 - 00003220 _____ () C:\Windows\System32\Tasks\elsbix 2014-07-05 11:18 - 2014-07-05 11:18 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\elsbix.bat 2014-07-05 11:16 - 2014-07-05 11:16 - 00003222 _____ () C:\Windows\System32\Tasks\difkadc 2014-07-05 11:16 - 2014-07-05 11:16 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\difkadc.bat 2014-07-05 11:14 - 2014-07-05 11:14 - 00003220 _____ () C:\Windows\System32\Tasks\ehhiar 2014-07-05 11:14 - 2014-07-05 11:14 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\ehhiar.bat 2014-07-05 11:12 - 2014-07-05 11:12 - 00003220 _____ () C:\Windows\System32\Tasks\mrxota 2014-07-05 11:12 - 2014-07-05 11:12 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\mrxota.bat 2014-07-05 11:11 - 2014-07-05 11:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\com 2014-07-05 11:10 - 2014-07-05 11:10 - 00003224 _____ () C:\Windows\System32\Tasks\qscfhzbe 2014-07-05 11:10 - 2014-07-05 11:10 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\qscfhzbe.bat 2014-07-05 11:07 - 2014-07-05 11:07 - 00003220 _____ () C:\Windows\System32\Tasks\cfkxbi 2014-07-05 11:06 - 2014-07-05 20:03 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\name_07050906 2014-07-04 23:44 - 2014-07-04 23:44 - 00000030 _____ () C:\Users\Yasmin\Downloads\streamurl.ram 2014-07-04 22:09 - 2014-07-04 22:09 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{37404FF7-030E-48E2-A558-14DFA93EEE9E} 2014-07-03 21:58 - 2014-07-03 21:59 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E9BB536-0BF2-446D-8D48-DC87C01C2FC3} 2014-06-29 12:28 - 2014-06-29 12:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E1CAE782-0FD8-41B0-9FD8-7E33BBD98301} 2014-06-28 23:52 - 2014-06-28 23:52 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{810DEC4A-80C1-4FD5-B28B-5BFC530AE508} 2014-06-27 21:32 - 2014-06-27 21:32 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{24E647D5-B426-4A01-AF7E-14A6AE314912} 2014-06-26 20:30 - 2014-06-26 20:30 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{D8B715AD-B34D-4D33-A09C-C33244F9D5C0} 2014-06-25 19:28 - 2014-06-25 19:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E893FD49-F480-401D-914A-5942727764A4} 2014-06-24 21:22 - 2014-06-24 21:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{41D84405-36F0-449C-9EFA-213D56C3AA10} 2014-06-23 22:00 - 2014-06-23 22:00 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F110FA2D-C85B-4F52-B108-8E9ED1857A01} 2014-06-22 15:23 - 2014-06-22 15:23 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{75B97884-1D8B-4CCB-83FC-048BB61EB30E} 2014-06-21 20:24 - 2014-06-21 20:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{9C7EDFC2-FB6C-49EB-9193-23E5598340C5} 2014-06-20 23:26 - 2014-06-20 23:27 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B713B85D-3B2D-4962-8CA2-F1C383D94808} 2014-06-19 14:24 - 2014-06-19 14:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{FC9ED3F9-DD7E-411E-9269-3766501127B5} 2014-06-18 21:20 - 2014-06-18 21:20 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{EB3FAF98-E5F5-4F1E-8E10-ABA85A38A761} 2014-06-16 20:22 - 2014-06-16 20:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{3BF0F0AD-2D46-4BED-A50C-18E664F4F590} 2014-06-15 21:57 - 2014-06-15 21:57 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{19CDCCD7-B9FD-4316-A1B1-2D06A27CF368} 2014-06-15 20:58 - 2014-06-15 20:58 - 04631095 _____ () C:\Users\Yasmin\Documents\Unbenannt 1.odp 2014-06-15 15:41 - 2014-06-15 15:42 - 00000000 ___SD () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0 2014-06-15 15:41 - 2014-06-15 15:41 - 00001192 _____ () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0.lnk 2014-06-15 15:40 - 2014-06-15 15:41 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-06-15 15:38 - 2014-06-15 15:38 - 00000000 ____D () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0 (de) Installation Files 2014-06-15 15:21 - 2014-06-15 15:21 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer (1).exe 2014-06-15 15:01 - 2014-06-15 15:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero_AG 2014-06-15 15:00 - 2014-06-15 15:26 - 164962843 _____ () C:\Users\Yasmin\Downloads\Apache_OpenOffice_4.1.0_Win_x86_install_de.exe 2014-06-15 15:00 - 2014-06-15 15:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero 2014-06-15 14:59 - 2014-06-15 14:59 - 00003106 _____ () C:\Windows\System32\Tasks\{DCDD5B02-D205-4113-8043-ABDAB776D6F9} 2014-06-15 14:57 - 2014-06-15 14:59 - 106801603 _____ () C:\Users\Yasmin\Downloads\Nicht bestätigt 864307.crdownload 2014-06-15 14:51 - 2014-06-15 14:51 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer.exe 2014-06-15 14:20 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-06-15 14:17 - 2014-07-08 15:54 - 00000000 ____D () C:\AdwCleaner 2014-06-15 14:15 - 2014-06-15 14:16 - 01333465 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.212.exe 2014-06-14 17:48 - 2014-06-14 17:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-14 17:12 - 2014-06-14 17:13 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Adobe 2014-06-14 15:53 - 2014-06-14 15:53 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E519259-ADFA-4445-9FF2-A60967D85830} 2014-06-14 14:41 - 2014-06-14 14:41 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{51B5E13B-B124-4678-B7E1-59E1D21E084E} 2014-06-12 13:43 - 2014-06-12 13:43 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6D0186BE-0396-43A5-8D71-4D0C5779FE26} 2014-06-12 12:58 - 2014-06-12 12:58 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0 (1).exe 2014-06-11 22:31 - 2014-06-14 17:54 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\OpenOffice 2014-06-11 22:31 - 2014-06-11 22:31 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-06-11 22:24 - 2014-06-14 17:54 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Opera Software 2014-06-11 22:24 - 2014-06-11 22:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Opera Software 2014-06-11 22:23 - 2014-06-14 17:56 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMeterExpress 2014-06-11 22:22 - 2014-06-14 17:56 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\PriceMeter Express 2014-06-11 22:20 - 2014-06-15 14:29 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-06-11 22:19 - 2014-06-14 17:56 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér 2014-06-11 21:38 - 2014-07-08 16:17 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-11 21:38 - 2014-06-11 21:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-11 21:38 - 2014-06-11 21:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-11 21:38 - 2014-06-11 21:38 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-11 21:38 - 2014-06-11 21:38 - 00000000 ____D () C:\Windows\system32\Macromed 2014-06-11 21:16 - 2014-06-11 21:16 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0.exe 2014-06-11 20:07 - 2014-06-11 20:08 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F63CE874-95F4-4014-9FFA-E120BA697A33} 2014-06-11 19:44 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-06-11 19:44 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-06-11 19:44 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-06-11 19:44 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-06-11 19:44 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-06-11 19:44 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-06-11 19:44 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-06-11 19:44 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-06-11 19:44 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-06-11 19:44 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-06-11 19:44 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-06-11 19:44 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-06-11 19:44 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-06-11 19:44 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-06-11 19:44 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-06-11 19:44 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-06-11 19:44 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-06-11 19:44 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-06-11 19:44 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-06-11 19:44 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-06-11 19:44 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-06-11 19:44 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-06-11 19:44 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-06-11 19:44 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-06-11 19:44 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-06-11 19:44 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-06-11 19:44 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-06-11 19:44 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-06-11 19:44 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-06-11 19:44 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-06-11 19:44 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-06-11 19:44 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-06-11 19:44 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-06-11 19:44 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-06-11 19:44 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-06-11 19:44 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-06-11 19:44 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-06-11 19:44 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-06-11 19:44 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-06-11 19:44 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-06-11 19:44 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-06-11 19:44 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-06-11 19:44 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-06-11 19:44 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-06-11 19:44 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-06-11 19:44 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-06-11 19:44 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-06-11 19:44 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-06-11 19:44 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-06-11 19:44 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-06-11 19:44 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-06-11 19:44 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-06-11 19:44 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-11 19:44 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-06-11 19:44 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-11 19:44 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2014-06-11 19:44 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-11 19:44 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-11 19:44 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll 2014-06-11 19:44 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2014-06-11 19:44 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2014-06-11 19:44 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2014-06-11 19:44 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll 2014-06-11 19:44 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2014-06-11 19:43 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-11 19:43 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-06-11 17:31 - 2014-06-11 17:31 - 00047240 _____ (RapidSolution Software AG) C:\Windows\system32\Drivers\tbhsd.sys 2014-06-11 17:31 - 2014-06-11 17:31 - 00024744 _____ (Audials AG) C:\Windows\system32\Drivers\RrNetCapFilterDriver.sys 2014-06-10 20:28 - 2014-06-10 20:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{8DDAE57A-5162-4B54-83CA-34A6D1AD5A76} 2014-06-09 19:29 - 2014-06-09 19:29 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B679CC51-C608-4AE5-8429-423D93E97BB1} 2014-06-08 15:04 - 2014-06-08 15:04 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{BE799AB3-FEC9-439F-9EE9-50C2DEB968DE} ==================== One Month Modified Files and Folders ======= 2014-07-08 16:27 - 2014-07-05 19:48 - 00016714 _____ () C:\Users\Yasmin\Downloads\FRST.txt 2014-07-08 16:26 - 2014-07-05 19:48 - 00000000 ____D () C:\FRST 2014-07-08 16:25 - 2014-07-08 16:25 - 00001160 _____ () C:\Users\Yasmin\Desktop\mbam.txt 2014-07-08 16:17 - 2014-06-11 21:38 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-08 15:57 - 2014-07-05 14:14 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-08 15:56 - 2009-07-14 06:45 - 00024912 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-08 15:56 - 2009-07-14 06:45 - 00024912 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-08 15:55 - 2014-07-08 15:55 - 00001059 _____ () C:\Users\Yasmin\Desktop\AdwCleaner[R2].txt 2014-07-08 15:54 - 2014-06-15 14:17 - 00000000 ____D () C:\AdwCleaner 2014-07-08 15:52 - 2014-01-12 03:20 - 02087468 _____ () C:\Windows\WindowsUpdate.log 2014-07-08 15:48 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-08 15:48 - 2009-07-14 06:51 - 00062638 _____ () C:\Windows\setupact.log 2014-07-07 21:58 - 2010-11-21 08:50 - 00699370 _____ () C:\Windows\system32\perfh007.dat 2014-07-07 21:58 - 2010-11-21 08:50 - 00149220 _____ () C:\Windows\system32\perfc007.dat 2014-07-07 21:58 - 2009-07-14 07:13 - 01619896 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-07 20:14 - 2014-01-13 20:52 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Skype 2014-07-07 19:07 - 2010-11-21 05:47 - 00155356 _____ () C:\Windows\PFRO.log 2014-07-07 19:02 - 2014-07-07 18:55 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-07-07 18:55 - 2014-07-07 18:54 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Yasmin\Downloads\revosetup95.exe 2014-07-07 18:46 - 2011-08-22 11:38 - 00000000 ____D () C:\Program Files\Common Files\mcafee 2014-07-06 23:20 - 2014-07-06 21:25 - 00000000 ____D () C:\Qoobox 2014-07-06 23:17 - 2014-07-06 21:25 - 00000000 ____D () C:\Windows\erdnt 2014-07-06 23:16 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-07-06 21:22 - 2014-07-06 18:36 - 05213907 ____R (Swearware) C:\Users\Yasmin\Desktop\ComboFix.exe 2014-07-05 20:03 - 2014-07-05 11:06 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\name_07050906 2014-07-05 19:53 - 2014-07-05 19:50 - 00037880 _____ () C:\Users\Yasmin\Downloads\Addition.txt 2014-07-05 19:48 - 2014-07-05 19:47 - 02084352 _____ (Farbar) C:\Users\Yasmin\Downloads\FRST64.exe 2014-07-05 15:20 - 2014-07-05 15:20 - 00017609 _____ () C:\Ergebnisse.txt 2014-07-05 14:14 - 2014-07-05 14:14 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-05 14:14 - 2014-07-05 14:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-05 14:14 - 2014-07-05 14:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-05 14:13 - 2014-07-05 14:13 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-05 14:10 - 2014-07-05 14:09 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Yasmin\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-05 14:04 - 2014-01-12 04:01 - 00064024 _____ () C:\Users\Yasmin\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-05 13:58 - 2009-07-14 06:45 - 00294736 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-05 13:56 - 2014-01-12 03:59 - 00000998 _____ () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-07-05 13:56 - 2011-08-22 11:52 - 00001289 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-07-05 13:56 - 2011-08-22 11:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-07-05 13:50 - 2014-07-05 13:49 - 01346519 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.214.exe 2014-07-05 13:35 - 2014-07-05 13:35 - 00001185 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk 2014-07-05 13:35 - 2014-07-05 13:35 - 00001173 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2014-07-05 13:35 - 2014-07-05 13:35 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2014-07-05 13:19 - 2014-07-05 13:19 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\CrashRpt 2014-07-05 13:15 - 2014-07-05 13:15 - 00000954 _____ () C:\Users\Public\Desktop\Audials 11.lnk 2014-07-05 13:15 - 2014-07-05 13:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audials 11 2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\ProgramData\RapidSolution 2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\Program Files (x86)\Audials 2014-07-05 13:11 - 2014-07-05 13:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\RapidSolution 2014-07-05 13:07 - 2014-07-05 13:07 - 00470552 _____ () C:\Users\Yasmin\Downloads\soft32_TeamViewer_1.0.exe 2014-07-05 11:20 - 2014-07-05 11:20 - 00003224 _____ () C:\Windows\System32\Tasks\cmelajsb 2014-07-05 11:20 - 2014-07-05 11:20 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\cmelajsb.bat 2014-07-05 11:18 - 2014-07-05 11:18 - 00003220 _____ () C:\Windows\System32\Tasks\elsbix 2014-07-05 11:18 - 2014-07-05 11:18 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\elsbix.bat 2014-07-05 11:16 - 2014-07-05 11:16 - 00003222 _____ () C:\Windows\System32\Tasks\difkadc 2014-07-05 11:16 - 2014-07-05 11:16 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\difkadc.bat 2014-07-05 11:14 - 2014-07-05 11:14 - 00003220 _____ () C:\Windows\System32\Tasks\ehhiar 2014-07-05 11:14 - 2014-07-05 11:14 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\ehhiar.bat 2014-07-05 11:12 - 2014-07-05 11:12 - 00003220 _____ () C:\Windows\System32\Tasks\mrxota 2014-07-05 11:12 - 2014-07-05 11:12 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\mrxota.bat 2014-07-05 11:11 - 2014-07-05 11:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\com 2014-07-05 11:10 - 2014-07-05 11:10 - 00003224 _____ () C:\Windows\System32\Tasks\qscfhzbe 2014-07-05 11:10 - 2014-07-05 11:10 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\qscfhzbe.bat 2014-07-05 11:07 - 2014-07-05 11:07 - 00003220 _____ () C:\Windows\System32\Tasks\cfkxbi 2014-07-05 10:24 - 2011-08-22 11:38 - 00000000 ____D () C:\Program Files (x86)\McAfee 2014-07-04 23:44 - 2014-07-04 23:44 - 00000030 _____ () C:\Users\Yasmin\Downloads\streamurl.ram 2014-07-04 22:09 - 2014-07-04 22:09 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{37404FF7-030E-48E2-A558-14DFA93EEE9E} 2014-07-03 21:59 - 2014-07-03 21:58 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E9BB536-0BF2-446D-8D48-DC87C01C2FC3} 2014-06-29 12:28 - 2014-06-29 12:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E1CAE782-0FD8-41B0-9FD8-7E33BBD98301} 2014-06-28 23:52 - 2014-06-28 23:52 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{810DEC4A-80C1-4FD5-B28B-5BFC530AE508} 2014-06-27 21:32 - 2014-06-27 21:32 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{24E647D5-B426-4A01-AF7E-14A6AE314912} 2014-06-26 20:30 - 2014-06-26 20:30 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{D8B715AD-B34D-4D33-A09C-C33244F9D5C0} 2014-06-25 19:28 - 2014-06-25 19:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E893FD49-F480-401D-914A-5942727764A4} 2014-06-24 21:22 - 2014-06-24 21:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{41D84405-36F0-449C-9EFA-213D56C3AA10} 2014-06-23 22:00 - 2014-06-23 22:00 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F110FA2D-C85B-4F52-B108-8E9ED1857A01} 2014-06-22 15:23 - 2014-06-22 15:23 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{75B97884-1D8B-4CCB-83FC-048BB61EB30E} 2014-06-21 20:24 - 2014-06-21 20:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{9C7EDFC2-FB6C-49EB-9193-23E5598340C5} 2014-06-20 23:27 - 2014-06-20 23:26 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B713B85D-3B2D-4962-8CA2-F1C383D94808} 2014-06-19 14:24 - 2014-06-19 14:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{FC9ED3F9-DD7E-411E-9269-3766501127B5} 2014-06-18 21:20 - 2014-06-18 21:20 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{EB3FAF98-E5F5-4F1E-8E10-ABA85A38A761} 2014-06-16 20:22 - 2014-06-16 20:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{3BF0F0AD-2D46-4BED-A50C-18E664F4F590} 2014-06-15 21:57 - 2014-06-15 21:57 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{19CDCCD7-B9FD-4316-A1B1-2D06A27CF368} 2014-06-15 20:58 - 2014-06-15 20:58 - 04631095 _____ () C:\Users\Yasmin\Documents\Unbenannt 1.odp 2014-06-15 15:42 - 2014-06-15 15:41 - 00000000 ___SD () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0 2014-06-15 15:41 - 2014-06-15 15:41 - 00001192 _____ () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0.lnk 2014-06-15 15:41 - 2014-06-15 15:40 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4 2014-06-15 15:38 - 2014-06-15 15:38 - 00000000 ____D () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0 (de) Installation Files 2014-06-15 15:26 - 2014-06-15 15:00 - 164962843 _____ () C:\Users\Yasmin\Downloads\Apache_OpenOffice_4.1.0_Win_x86_install_de.exe 2014-06-15 15:21 - 2014-06-15 15:21 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer (1).exe 2014-06-15 15:01 - 2014-06-15 15:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero_AG 2014-06-15 15:01 - 2014-06-15 15:00 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero 2014-06-15 14:59 - 2014-06-15 14:59 - 00003106 _____ () C:\Windows\System32\Tasks\{DCDD5B02-D205-4113-8043-ABDAB776D6F9} 2014-06-15 14:59 - 2014-06-15 14:57 - 106801603 _____ () C:\Users\Yasmin\Downloads\Nicht bestätigt 864307.crdownload 2014-06-15 14:51 - 2014-06-15 14:51 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer.exe 2014-06-15 14:29 - 2014-06-11 22:20 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-06-15 14:16 - 2014-06-15 14:15 - 01333465 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.212.exe 2014-06-15 14:02 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-06-14 18:11 - 2009-07-14 04:34 - 00000537 _____ () C:\Windows\win.ini 2014-06-14 17:59 - 2014-01-12 03:57 - 00000000 ____D () C:\Users\Yasmin 2014-06-14 17:56 - 2014-06-11 22:23 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMeterExpress 2014-06-14 17:56 - 2014-06-11 22:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\PriceMeter Express 2014-06-14 17:56 - 2014-06-11 22:19 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér 2014-06-14 17:56 - 2014-05-07 19:09 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-06-14 17:56 - 2014-01-12 04:45 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\TOSHIBA_Corporation 2014-06-14 17:56 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-06-14 17:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-06-14 17:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-06-14 17:55 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-06-14 17:54 - 2014-06-11 22:31 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\OpenOffice 2014-06-14 17:54 - 2014-06-11 22:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Opera Software 2014-06-14 17:54 - 2014-02-21 01:06 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\SoftGrid Client 2014-06-14 17:54 - 2011-08-22 11:38 - 00000000 ____D () C:\ProgramData\McAfee 2014-06-14 17:48 - 2014-06-14 17:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-14 17:13 - 2014-06-14 17:12 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Adobe 2014-06-14 17:12 - 2014-01-12 16:08 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Adobe 2014-06-14 16:51 - 2014-01-12 04:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Toshiba 2014-06-14 15:53 - 2014-06-14 15:53 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E519259-ADFA-4445-9FF2-A60967D85830} 2014-06-14 14:41 - 2014-06-14 14:41 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{51B5E13B-B124-4678-B7E1-59E1D21E084E} 2014-06-12 13:43 - 2014-06-12 13:43 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6D0186BE-0396-43A5-8D71-4D0C5779FE26} 2014-06-12 12:58 - 2014-06-12 12:58 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0 (1).exe 2014-06-11 22:31 - 2014-06-11 22:31 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-06-11 22:24 - 2014-06-11 22:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Opera Software 2014-06-11 21:38 - 2014-06-11 21:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-06-11 21:38 - 2014-06-11 21:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-11 21:38 - 2014-06-11 21:38 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-06-11 21:38 - 2014-06-11 21:38 - 00000000 ____D () C:\Windows\system32\Macromed 2014-06-11 21:16 - 2014-06-11 21:16 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0.exe 2014-06-11 20:08 - 2014-06-11 20:07 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F63CE874-95F4-4014-9FFA-E120BA697A33} 2014-06-11 17:31 - 2014-06-11 17:31 - 00047240 _____ (RapidSolution Software AG) C:\Windows\system32\Drivers\tbhsd.sys 2014-06-11 17:31 - 2014-06-11 17:31 - 00024744 _____ (Audials AG) C:\Windows\system32\Drivers\RrNetCapFilterDriver.sys 2014-06-10 20:28 - 2014-06-10 20:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{8DDAE57A-5162-4B54-83CA-34A6D1AD5A76} 2014-06-09 19:29 - 2014-06-09 19:29 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B679CC51-C608-4AE5-8429-423D93E97BB1} 2014-06-08 15:04 - 2014-06-08 15:04 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{BE799AB3-FEC9-439F-9EE9-50C2DEB968DE} 2014-06-08 11:13 - 2014-06-11 19:43 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-06-08 11:08 - 2014-06-11 19:43 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-06-11 20:02 ==================== End Of Log ============================ --- --- --- --- --- --- Mbam Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 08.07.2014 Suchlauf-Zeit: 15:57:35 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.07.08.04 Rootkit Datenbank: v2014.07.07.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Yasmin Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 282563 Verstrichene Zeit: 20 Min, 54 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Yasmin on 08.07.2014 at 16:30:38,83 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{01F4689D-9EE5-45AC-92FB-22E936DE66B3} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{031FC851-4222-455C-AA4B-5EB5F5802E51} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{03912807-3A22-4FE2-8AFB-DBA93B1A52F6} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{05173330-94B6-42C4-96B4-3A7E7CFFB171} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{05915E00-ED26-4EFC-A667-69B687AB5B26} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{0C95668D-8E69-48D2-9804-95A0D51A76A5} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{0CBB26E7-1F9A-4F8E-8F7D-1A36EC950C05} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{0F2CD22F-46E5-4C0C-B075-0ED0C6D5CC66} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{11982317-4633-4194-9703-E5687E66E3C0} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{12AAC561-AFD9-4D4B-88DF-BC03D29D2DE7} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{13E179CA-D52D-4112-83CE-A2AD81DA5E75} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{14FBE841-44F8-4951-BF36-3329D8B0F89E} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{15B2E47D-8BBE-4292-9571-24F98E61B26A} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{15DEA250-6770-43C9-BBE7-A15631DD7A4F} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{1605570E-F265-4537-892C-BAF4A8959A1E} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{169018E4-E26B-4C7D-991D-748B64476810} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{16ED9A79-DEAD-4491-B11E-AE364FF9F754} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{18703BF3-925A-4048-8361-E321ED086303} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{18E5E849-801A-493A-A89D-70BE6406FF21} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{19CDCCD7-B9FD-4316-A1B1-2D06A27CF368} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{1A253856-F1E8-4568-BE2A-3C0EEB131058} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{1BFA21EA-0844-446E-BB8B-19DA9CDE9235} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{1C7794F2-5188-49CD-9D2E-3D124A66DE62} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{1DD6FC03-7FAF-4745-B087-88EEE0C3F35B} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{1E61FA61-83EC-4DF7-BD9F-456212236A7E} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{1EDB406F-B080-48F8-A7A4-669336E5C569} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{24E647D5-B426-4A01-AF7E-14A6AE314912} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{26D9C731-BE2A-4B37-853C-F18843B2D57F} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{26DACA7F-27DD-4B77-8422-8DD9B5D501AD} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{278E812D-78D1-40BC-A98C-FC7CB7DBB4D3} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{27E91624-A7A4-4A3B-8871-B90D79FB170A} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{2AA6BC0F-ECFE-479B-A838-56C342F235B6} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{2B2ACCC2-03C0-4FAD-9A67-72C3F3DD94C0} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{2B660AE8-3132-40CF-ADAD-D318E78C6135} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{2C26D848-0726-432B-9FF3-6973981872F1} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{2C2FFC3A-C97E-4326-81AB-73324EABC03D} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{2CA78C6D-4141-4B03-A24D-CDB6719DF53B} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{2DAEDF11-64A0-4A67-AB2F-3A9F0131EF75} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{3155A73D-E444-40EF-A2A8-6419CD2F9BBA} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{3248DC51-7280-4AE4-A67A-93DD8FEA2C6C} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{32F687CD-5AB3-4A7B-AC8C-AEB2AF12E4C7} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{37404FF7-030E-48E2-A558-14DFA93EEE9E} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{3A18D717-C485-4E3D-AB26-4572FDF4BCA5} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{3BF0F0AD-2D46-4BED-A50C-18E664F4F590} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{3E281AC7-30F7-4947-B991-CFDB1488ACAE} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{3F99EFB0-CFED-4D59-8255-F8C88D281A57} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{40317B7B-FF60-46CE-AFD0-F4FFEB439349} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{41D84405-36F0-449C-9EFA-213D56C3AA10} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{43EE14BC-6FBB-47D3-B0CD-85F55261DD4B} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{447C0671-870B-407C-8211-D06EB3E5FF28} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{45ACBBBC-0084-4079-8EAD-3240934481CA} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{4893FD4F-4D83-4A9C-90AA-834524E2A015} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{4B0C0035-442B-4D73-94DD-DE82FD32BBA4} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{4EFE1F6E-5772-40FA-A019-BC10317B1EA7} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{4F549286-2B1C-4FCC-95EF-B83528E22E8C} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{4FE1B648-AFFA-4589-B6F4-5EBCD1E32683} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{512DEA13-1FF2-4093-93FB-7621DBA3BCEB} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{51B5E13B-B124-4678-B7E1-59E1D21E084E} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{53971B5C-315D-44AD-B220-8807EAECA8D1} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{55C77714-63B1-44D0-8D43-FA859A3449D7} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{587872EA-2FA1-4AE9-899A-793487F6B9BE} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{5A614D0A-FF5B-45D8-B16D-EA754F8BBFDB} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{5AF9BD9D-C4D3-444C-8F21-1038A663509B} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{5D525624-F674-4CD4-9E66-19FE3DDB5F6E} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{5E263336-D1BA-44D7-B972-03A586700573} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{5F1050B8-1B3E-4291-B4DF-0255EB98CE0E} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{60DE3B45-7F02-40B6-839F-35325623B38D} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{62078431-3057-4D2F-A334-6BC214375EEC} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{62355EC8-25AA-41A8-8BBC-965872683B82} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{6409B39B-D4BE-4F07-B32F-AD0D9CF9C06D} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{64F0B40A-D957-468E-996C-22793CDEC6BB} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{6572E510-4C71-420D-A5A5-01DB32E2D582} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{65BB912D-11CD-41B6-8036-C084E78433CA} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{66B4BC5F-6919-4F52-AFB4-AF71BE240072} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{66F8F341-8208-4D00-9C17-3A61C4F88050} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{684E5F6C-69EA-4C09-9586-7C230EF42927} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{6D0186BE-0396-43A5-8D71-4D0C5779FE26} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{6E423027-85EF-4888-A2A7-4AEBF02F8A4B} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{6E519259-ADFA-4445-9FF2-A60967D85830} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{6E9BB536-0BF2-446D-8D48-DC87C01C2FC3} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{6EADF889-FA24-4D91-8396-2302A6F120B0} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{740E42C5-358A-41E9-A3A3-9182DB2E8505} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{74B17D7A-AFC1-4C50-9420-4DE5E99F6212} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{75B97884-1D8B-4CCB-83FC-048BB61EB30E} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{785E0FB4-7124-4612-BB59-C64AFE6EC45C} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{7AB836B5-DD7E-448A-B1EE-661C762A4812} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{7EE1AE3B-9FD1-4070-BCC2-20C3961C9D5C} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{7EEFA3BA-CDD7-4360-A6EF-B6FCD31BF5C5} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{810DEC4A-80C1-4FD5-B28B-5BFC530AE508} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{819795A9-6AFC-40A1-980A-1400BBB4B6FE} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{82EBA0EC-78CA-41EE-ADD9-A2396790867F} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{846697EB-B095-4034-93DD-D37F0109B617} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{852923AF-22C1-434C-92E5-03A3A024A487} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{86FF3BB0-CB57-4089-A96B-9FCAEA3E23B0} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{8A4131DB-79C2-43C4-8568-5EE7B940C019} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{8AE171D8-550A-4B55-B11E-75021755EE89} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{8B84EE17-2AF6-4CAD-9505-416F4486B04F} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{8C1AFCAC-F04E-43B1-ACE2-1576C8418C4F} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{8DDAE57A-5162-4B54-83CA-34A6D1AD5A76} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{8ECD87F2-83D9-46E3-BFB7-CBE98BC0C011} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{90A247D1-26EC-401E-988A-055662644AF8} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{9128FA43-3376-44AA-87C9-C1EF3604E985} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{9240A1A9-96FD-4D64-BBCC-EADD53C5FDCA} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{9280501E-1491-4CCC-8464-52D71275BE27} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{92909D5E-3F0C-4E5A-8532-3C848539E325} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{9416814D-8F05-441E-B7A2-DC4FCE6CFB7E} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{955697FB-5D54-4184-AE6A-C4D5C3C26F25} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{970A9DA1-29EA-48A7-A9DB-0F2A7F8C42D9} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{97E0DA87-8219-4B35-9207-659E3635874D} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{9940A864-C3CB-4123-A1FF-A38FC0CE834F} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{9C7EDFC2-FB6C-49EB-9193-23E5598340C5} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{9F7C0FBC-5BD0-499B-8484-74F69C8EC082} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{A0450E66-AB9C-44CB-A4E1-EA71F1F8D488} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{A09B5534-6543-4790-A9BD-D51EE5CEAABD} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{A25277D1-6374-468B-9781-5FFD9F47162A} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{A7478FA8-D20E-46F9-9282-6311A2588BDA} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{AB30E1EF-508A-4871-90A1-B6B5AF692241} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{ABD08CA5-4542-422D-BEB7-C8964A2D551A} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{AC89166E-757C-4DBC-B077-8BF37955B78B} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{ACEB128E-0725-4ECD-84A0-6AF3171270CB} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{ADB471F7-B107-4EF5-A735-B29678018445} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B03A38F6-50B2-4C13-A62A-AD4B3D50B9EE} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B13447A6-0C00-4CD7-8189-41AFE8B13C81} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B17628B5-4CEA-4821-8D31-78E702B2E077} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B2B9C21A-B008-4318-B2B3-9646A13004C5} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B5B73135-5D7D-4111-A776-47F505FEE543} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B65A5B5F-BB14-4816-A823-643B9563F2F1} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B679CC51-C608-4AE5-8429-423D93E97BB1} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B713B85D-3B2D-4962-8CA2-F1C383D94808} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B7A93844-0195-49B1-9BCF-90FB6A301A4A} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B905A3B3-D69D-4B11-AF37-E645E6B75A6C} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B90D8EBF-88BA-4898-8AF4-0F6F8AF9F88C} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B980266A-CA3D-49CC-BE41-CD4940A6DA0D} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BB27BF72-F050-4847-B983-4274D3A75F43} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BB2CC748-4A6A-4D87-9CCC-E8B7D086D7CD} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BB6131C2-4EE9-4EE2-8CC6-B36895BA1CD9} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BBAB4503-8557-4966-BDDD-1A327C67F6EA} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BBAF2E4A-35B1-4B4B-9686-01E4124FC4AA} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BE036108-2517-48A6-9D52-716E67A6A211} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BE799AB3-FEC9-439F-9EE9-50C2DEB968DE} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BEC65C83-DD24-4B35-A16F-5BFE1CD90CBA} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C022D95B-DB6F-436B-98A1-CDA88BFA5ED2} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C0F5E6BF-5EAC-4934-89C0-E99C782137B7} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C2019A68-C60F-43EA-9DE3-EDF97102D6CA} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C3659E30-5164-4C91-96A4-0541D5BEFFD2} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C37E7644-0272-4386-92C2-3C2874E2B867} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C3FE30AF-7F36-401B-8C2F-627441B90DCF} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C7A8E5F4-DBFF-44A9-A894-0D5661458100} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C956742E-5EFA-4823-8AFA-EC8F20A640C5} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{CC29C4DB-F754-4569-B5F6-729DB8813CC9} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{CE854635-C891-4EDE-9861-AE0265325A83} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{CF34905A-5028-4671-8A5A-447B39459489} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{CF7D2ACF-448A-41B5-BF84-5362A8BE401C} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{D2DAB0AA-2A64-476B-BB7F-6860A45CB69E} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{D590CA53-B760-490D-AA85-D199A4A1F4EB} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{D5A893D9-C11E-4F46-B767-DCEBBA06356D} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{D7A13B7E-9439-403E-9047-DD065963BBFF} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{D80CFB59-0698-41C9-A943-BAE9171047BB} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{D8B715AD-B34D-4D33-A09C-C33244F9D5C0} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{D9CCFAAF-D7E4-4231-9C35-46E4AD5B00E5} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{DA52E3C0-4E3C-4F08-B048-2C475527C18F} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{DB85AE62-FB4D-4CD3-8D92-70708AACA449} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{DBA115D0-199D-4800-8192-1308AE3CAB39} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{DEF94305-E288-443B-8872-09C76CFAC60B} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{E1BFA2C5-0673-41DD-9C20-0B144E57FA19} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{E1CAE782-0FD8-41B0-9FD8-7E33BBD98301} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{E23FCE17-E953-4878-92E5-F00E65207F0A} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{E261E901-66DF-4EAC-8CC3-CCAFAEAF94E1} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{E3B5554C-F6DE-4C7C-AA68-76751477E5A8} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{E467674C-1BB9-479C-93E4-6CCA9D4BB5EC} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{E893FD49-F480-401D-914A-5942727764A4} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{EA6A6897-A949-49D1-8964-E7771C0D3A95} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{EB3FAF98-E5F5-4F1E-8E10-ABA85A38A761} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{EC2C2940-E6D2-41B9-9605-F2F43AEEE17D} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{EE03B039-8AD8-4950-8E41-F6EA1AEA5055} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{EEF60F01-9196-4953-8297-8EEA670583E3} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{EFB4FA9E-07B9-4960-BFEA-0DB82A358DC1} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{F09AC637-2DA5-429F-BE2D-5866D0FF0E0B} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{F110FA2D-C85B-4F52-B108-8E9ED1857A01} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{F63CE874-95F4-4014-9FFA-E120BA697A33} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{F6904E27-E387-4039-B0D5-F9686A790E2B} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{F6C1450B-9F15-4A6B-A2F5-E71C34FF35B1} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{F8680A6B-6E04-497A-A454-9D66301A9450} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FA6390DD-A1DC-4214-9147-49C9FBDF57A5} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FAC697A4-A264-409D-BF5E-E6AE2B2FC704} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FB267BA4-675D-4A67-A907-12DA5B82BA3D} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FC347101-2A51-4941-BD0E-8EAE6734E388} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FC9ED3F9-DD7E-411E-9269-3766501127B5} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FD19C800-2036-476F-8086-B858AFF47320} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FE2A955F-CE00-4345-82FB-830125192873} Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FFF8FA18-4B12-4922-8FF6-AB7047DF3B8E} ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 08.07.2014 at 16:47:11,77 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter # AdwCleaner v3.214 - Bericht erstellt am 08/07/2014 um 15:53:27 # Aktualisiert 29/06/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Yasmin - YASMIN-TOSH # Gestartet von : C:\Users\Yasmin\Downloads\adwcleaner_3.214.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17126 -\\ Google Chrome v35.0.1916.114 [ Datei : C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [24473 octets] - [15/06/2014 14:19:01] AdwCleaner[R1].txt - [21733 octets] - [05/07/2014 13:51:01] AdwCleaner[R2].txt - [854 octets] - [08/07/2014 15:53:27] AdwCleaner[S0].txt - [20206 octets] - [15/06/2014 14:21:27] AdwCleaner[S1].txt - [17163 octets] - [05/07/2014 13:56:00] ########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [1095 octets] ########## Moin ich melde mich kurz wieder Wir haben Avira einmal durchlaufen lassen und es hat paar funde gefunden. hier der Log Code:
ATTFilter Avira Free Antivirus Erstellungsdatum der Reportdatei: Dienstag, 8. Juli 2014 19:32 Das Programm läuft als uneingeschränkte Vollversion. Online-Dienste stehen zur Verfügung. Lizenznehmer : Avira Antivirus Free Seriennummer : 0000149996-AVHOE-0000001 Plattform : Windows 7 Home Premium Windowsversion : (Service Pack 1) [6.1.7601] Boot Modus : Normal gebootet Benutzername : SYSTEM Computername : YASMIN-TOSH Versionsinformationen: BUILD.DAT : 14.0.5.464 91868 Bytes 02.07.2014 13:06:00 AVSCAN.EXE : 14.0.5.396 1042512 Bytes 02.07.2014 11:06:43 AVSCANRC.DLL : 14.0.5.364 62544 Bytes 02.07.2014 11:06:43 LUKE.DLL : 14.0.5.336 57936 Bytes 02.07.2014 11:06:46 AVSCPLR.DLL : 14.0.5.376 89680 Bytes 02.07.2014 11:06:43 AVREG.DLL : 14.0.5.356 261200 Bytes 02.07.2014 11:06:43 avlode.dll : 14.0.5.396 588368 Bytes 02.07.2014 11:06:42 avlode.rdf : 14.0.4.36 65096 Bytes 08.07.2014 17:27:44 XBV00008.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00009.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00010.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00011.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00012.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00013.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00014.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00015.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00016.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00017.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00018.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00019.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00020.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00021.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00022.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00023.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00024.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00025.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00026.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00027.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00028.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00029.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00030.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00031.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00032.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00033.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00034.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00035.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00036.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00037.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00038.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00039.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00040.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00041.VDF : 8.11.153.142 2048 Bytes 06.06.2014 11:06:47 XBV00252.VDF : 8.11.155.44 2048 Bytes 16.06.2014 11:06:47 XBV00253.VDF : 8.11.155.44 2048 Bytes 16.06.2014 11:06:47 XBV00254.VDF : 8.11.155.44 2048 Bytes 16.06.2014 11:06:47 XBV00255.VDF : 8.11.155.44 2048 Bytes 16.06.2014 11:06:47 XBV00000.VDF : 7.11.70.0 66736640 Bytes 04.04.2013 11:06:47 XBV00001.VDF : 7.11.74.226 2201600 Bytes 30.04.2013 11:06:47 XBV00002.VDF : 7.11.80.60 2751488 Bytes 28.05.2013 11:06:47 XBV00003.VDF : 7.11.85.214 2162688 Bytes 21.06.2013 11:06:47 XBV00004.VDF : 7.11.91.176 3903488 Bytes 23.07.2013 11:06:47 XBV00005.VDF : 7.11.98.186 6822912 Bytes 29.08.2013 11:06:47 XBV00006.VDF : 7.11.139.38 15708672 Bytes 27.03.2014 11:06:47 XBV00007.VDF : 7.11.152.100 4193792 Bytes 02.06.2014 11:06:47 XBV00042.VDF : 8.11.153.142 710656 Bytes 06.06.2014 11:06:47 XBV00043.VDF : 8.11.155.44 1013760 Bytes 16.06.2014 11:06:47 XBV00044.VDF : 8.11.155.46 3072 Bytes 16.06.2014 11:06:47 XBV00045.VDF : 8.11.155.52 38912 Bytes 16.06.2014 11:06:47 XBV00046.VDF : 8.11.155.54 29696 Bytes 16.06.2014 11:06:47 XBV00047.VDF : 8.11.155.58 13824 Bytes 16.06.2014 11:06:47 XBV00048.VDF : 8.11.155.62 20480 Bytes 17.06.2014 11:06:47 XBV00049.VDF : 8.11.155.64 5632 Bytes 17.06.2014 11:06:47 XBV00050.VDF : 8.11.155.66 139264 Bytes 17.06.2014 11:06:47 XBV00051.VDF : 8.11.155.68 2048 Bytes 17.06.2014 11:06:47 XBV00052.VDF : 8.11.155.70 6144 Bytes 17.06.2014 11:06:47 XBV00053.VDF : 8.11.155.74 180224 Bytes 17.06.2014 11:06:47 XBV00054.VDF : 8.11.155.78 18432 Bytes 17.06.2014 11:06:47 XBV00055.VDF : 8.11.155.80 6144 Bytes 17.06.2014 11:06:47 XBV00056.VDF : 8.11.155.82 4608 Bytes 18.06.2014 11:06:47 XBV00057.VDF : 8.11.155.86 17408 Bytes 18.06.2014 11:06:47 XBV00058.VDF : 8.11.155.100 144896 Bytes 18.06.2014 11:06:47 XBV00059.VDF : 8.11.155.114 25088 Bytes 18.06.2014 11:06:47 XBV00060.VDF : 8.11.155.128 2048 Bytes 18.06.2014 11:06:47 XBV00061.VDF : 8.11.155.146 27648 Bytes 18.06.2014 11:06:47 XBV00062.VDF : 8.11.155.148 2048 Bytes 18.06.2014 11:06:47 XBV00063.VDF : 8.11.155.150 148992 Bytes 18.06.2014 11:06:47 XBV00064.VDF : 8.11.155.152 5120 Bytes 18.06.2014 11:06:47 XBV00065.VDF : 8.11.155.156 12800 Bytes 18.06.2014 11:06:47 XBV00066.VDF : 8.11.155.158 2048 Bytes 18.06.2014 11:06:47 XBV00067.VDF : 8.11.155.160 2048 Bytes 18.06.2014 11:06:47 XBV00068.VDF : 8.11.155.164 7680 Bytes 18.06.2014 11:06:47 XBV00069.VDF : 8.11.155.168 18432 Bytes 19.06.2014 11:06:47 XBV00070.VDF : 8.11.155.172 2048 Bytes 19.06.2014 11:06:47 XBV00071.VDF : 8.11.155.174 7680 Bytes 19.06.2014 11:06:47 XBV00072.VDF : 8.11.155.176 2048 Bytes 19.06.2014 11:06:47 XBV00073.VDF : 8.11.155.178 7680 Bytes 19.06.2014 11:06:47 XBV00074.VDF : 8.11.155.180 5120 Bytes 19.06.2014 11:06:47 XBV00075.VDF : 8.11.155.182 4608 Bytes 19.06.2014 11:06:47 XBV00076.VDF : 8.11.155.184 6144 Bytes 19.06.2014 11:06:47 XBV00077.VDF : 8.11.155.186 4608 Bytes 19.06.2014 11:06:47 XBV00078.VDF : 8.11.155.188 5632 Bytes 19.06.2014 11:06:47 XBV00079.VDF : 8.11.155.190 5120 Bytes 19.06.2014 11:06:47 XBV00080.VDF : 8.11.155.192 2048 Bytes 19.06.2014 11:06:47 XBV00081.VDF : 8.11.155.196 17408 Bytes 19.06.2014 11:06:47 XBV00082.VDF : 8.11.155.200 2048 Bytes 19.06.2014 11:06:47 XBV00083.VDF : 8.11.155.202 5632 Bytes 20.06.2014 11:06:47 XBV00084.VDF : 8.11.155.204 14848 Bytes 20.06.2014 11:06:47 XBV00085.VDF : 8.11.155.206 3072 Bytes 20.06.2014 11:06:47 XBV00086.VDF : 8.11.155.208 2048 Bytes 20.06.2014 11:06:47 XBV00087.VDF : 8.11.155.210 11264 Bytes 20.06.2014 11:06:47 XBV00088.VDF : 8.11.155.214 4608 Bytes 20.06.2014 11:06:47 XBV00089.VDF : 8.11.155.218 8704 Bytes 20.06.2014 11:06:47 XBV00090.VDF : 8.11.155.222 2048 Bytes 20.06.2014 11:06:47 XBV00091.VDF : 8.11.155.224 2048 Bytes 20.06.2014 11:06:47 XBV00092.VDF : 8.11.155.228 151552 Bytes 20.06.2014 11:06:47 XBV00093.VDF : 8.11.155.242 13312 Bytes 21.06.2014 11:06:47 XBV00094.VDF : 8.11.156.2 12800 Bytes 21.06.2014 11:06:47 XBV00095.VDF : 8.11.156.4 58368 Bytes 21.06.2014 11:06:47 XBV00096.VDF : 8.11.156.18 146944 Bytes 21.06.2014 11:06:47 XBV00097.VDF : 8.11.156.20 2048 Bytes 21.06.2014 11:06:47 XBV00098.VDF : 8.11.156.22 49152 Bytes 22.06.2014 11:06:47 XBV00099.VDF : 8.11.156.24 2048 Bytes 22.06.2014 11:06:47 XBV00100.VDF : 8.11.156.26 9216 Bytes 22.06.2014 11:06:47 XBV00101.VDF : 8.11.156.30 2048 Bytes 22.06.2014 11:06:47 XBV00102.VDF : 8.11.156.32 12800 Bytes 22.06.2014 11:06:47 XBV00103.VDF : 8.11.156.34 36352 Bytes 23.06.2014 11:06:47 XBV00104.VDF : 8.11.156.36 2560 Bytes 23.06.2014 11:06:47 XBV00105.VDF : 8.11.156.38 2048 Bytes 23.06.2014 11:06:47 XBV00106.VDF : 8.11.156.40 7168 Bytes 23.06.2014 11:06:47 XBV00107.VDF : 8.11.156.52 8704 Bytes 23.06.2014 11:06:47 XBV00108.VDF : 8.11.156.72 204288 Bytes 23.06.2014 11:06:47 XBV00109.VDF : 8.11.156.76 2048 Bytes 23.06.2014 11:06:47 XBV00110.VDF : 8.11.156.88 2048 Bytes 23.06.2014 11:06:47 XBV00111.VDF : 8.11.156.100 2048 Bytes 23.06.2014 11:06:47 XBV00112.VDF : 8.11.156.114 37376 Bytes 24.06.2014 11:06:47 XBV00113.VDF : 8.11.156.126 2048 Bytes 24.06.2014 11:06:47 XBV00114.VDF : 8.11.156.144 28160 Bytes 24.06.2014 11:06:47 XBV00115.VDF : 8.11.156.146 2048 Bytes 24.06.2014 11:06:47 XBV00116.VDF : 8.11.156.150 145408 Bytes 24.06.2014 11:06:47 XBV00117.VDF : 8.11.156.152 13824 Bytes 24.06.2014 11:06:47 XBV00118.VDF : 8.11.156.154 2048 Bytes 24.06.2014 11:06:47 XBV00119.VDF : 8.11.156.158 35328 Bytes 24.06.2014 11:06:47 XBV00120.VDF : 8.11.156.160 18432 Bytes 24.06.2014 11:06:47 XBV00121.VDF : 8.11.156.162 5632 Bytes 24.06.2014 11:06:47 XBV00122.VDF : 8.11.156.166 10240 Bytes 24.06.2014 11:06:47 XBV00123.VDF : 8.11.156.180 21504 Bytes 25.06.2014 11:06:47 XBV00124.VDF : 8.11.156.190 3072 Bytes 25.06.2014 11:06:47 XBV00125.VDF : 8.11.156.206 147968 Bytes 25.06.2014 11:06:47 XBV00126.VDF : 8.11.156.208 2048 Bytes 25.06.2014 11:06:47 XBV00127.VDF : 8.11.156.220 2048 Bytes 25.06.2014 11:06:47 XBV00128.VDF : 8.11.156.232 29696 Bytes 25.06.2014 11:06:47 XBV00129.VDF : 8.11.156.242 2048 Bytes 25.06.2014 11:06:47 XBV00130.VDF : 8.11.157.0 181248 Bytes 26.06.2014 11:06:47 XBV00131.VDF : 8.11.157.4 15872 Bytes 26.06.2014 11:06:47 XBV00132.VDF : 8.11.157.6 2560 Bytes 26.06.2014 11:06:47 XBV00133.VDF : 8.11.157.24 151552 Bytes 26.06.2014 11:06:47 XBV00134.VDF : 8.11.157.26 9728 Bytes 26.06.2014 11:06:47 XBV00135.VDF : 8.11.157.28 5632 Bytes 26.06.2014 11:06:47 XBV00136.VDF : 8.11.157.30 2048 Bytes 26.06.2014 11:06:47 XBV00137.VDF : 8.11.157.32 25600 Bytes 26.06.2014 11:06:47 XBV00138.VDF : 8.11.157.38 42496 Bytes 26.06.2014 11:06:47 XBV00139.VDF : 8.11.157.46 2048 Bytes 27.06.2014 11:06:47 XBV00140.VDF : 8.11.157.50 15360 Bytes 27.06.2014 11:06:47 XBV00141.VDF : 8.11.157.76 2048 Bytes 27.06.2014 11:06:47 XBV00142.VDF : 8.11.157.78 166400 Bytes 27.06.2014 11:06:47 XBV00143.VDF : 8.11.157.88 2048 Bytes 27.06.2014 11:06:47 XBV00144.VDF : 8.11.157.98 17408 Bytes 27.06.2014 11:06:47 XBV00145.VDF : 8.11.157.100 2048 Bytes 27.06.2014 11:06:47 XBV00146.VDF : 8.11.157.110 158208 Bytes 27.06.2014 11:06:47 XBV00147.VDF : 8.11.157.112 166912 Bytes 27.06.2014 11:06:47 XBV00148.VDF : 8.11.157.114 2048 Bytes 27.06.2014 11:06:47 XBV00149.VDF : 8.11.157.118 11264 Bytes 27.06.2014 11:06:47 XBV00150.VDF : 8.11.157.120 2048 Bytes 27.06.2014 11:06:47 XBV00151.VDF : 8.11.157.126 156160 Bytes 28.06.2014 11:06:47 XBV00152.VDF : 8.11.157.128 2048 Bytes 28.06.2014 11:06:47 XBV00153.VDF : 8.11.157.130 6144 Bytes 28.06.2014 11:06:47 XBV00154.VDF : 8.11.157.132 14336 Bytes 28.06.2014 11:06:47 XBV00155.VDF : 8.11.157.134 2048 Bytes 28.06.2014 11:06:47 XBV00156.VDF : 8.11.157.138 3584 Bytes 29.06.2014 11:06:47 XBV00157.VDF : 8.11.157.140 2048 Bytes 29.06.2014 11:06:47 XBV00158.VDF : 8.11.157.142 26624 Bytes 29.06.2014 11:06:47 XBV00159.VDF : 8.11.157.144 2048 Bytes 29.06.2014 11:06:47 XBV00160.VDF : 8.11.157.146 2048 Bytes 29.06.2014 11:06:47 XBV00161.VDF : 8.11.157.148 12800 Bytes 29.06.2014 11:06:47 XBV00162.VDF : 8.11.157.150 55808 Bytes 30.06.2014 11:06:47 XBV00163.VDF : 8.11.157.152 2048 Bytes 30.06.2014 11:06:47 XBV00164.VDF : 8.11.157.162 10240 Bytes 30.06.2014 11:06:47 XBV00165.VDF : 8.11.157.170 2048 Bytes 30.06.2014 11:06:47 XBV00166.VDF : 8.11.157.178 5632 Bytes 30.06.2014 11:06:47 XBV00167.VDF : 8.11.157.186 2048 Bytes 30.06.2014 11:06:47 XBV00168.VDF : 8.11.157.196 37888 Bytes 30.06.2014 11:06:47 XBV00169.VDF : 8.11.157.202 8192 Bytes 30.06.2014 11:06:47 XBV00170.VDF : 8.11.157.204 2048 Bytes 30.06.2014 11:06:47 XBV00171.VDF : 8.11.157.208 7168 Bytes 30.06.2014 11:06:47 XBV00172.VDF : 8.11.157.210 16384 Bytes 30.06.2014 11:06:47 XBV00173.VDF : 8.11.157.214 2048 Bytes 30.06.2014 11:06:47 XBV00174.VDF : 8.11.157.218 162304 Bytes 01.07.2014 11:06:47 XBV00175.VDF : 8.11.157.220 2048 Bytes 01.07.2014 11:06:47 XBV00176.VDF : 8.11.157.222 18432 Bytes 01.07.2014 11:06:47 XBV00177.VDF : 8.11.157.224 2048 Bytes 01.07.2014 11:06:47 XBV00178.VDF : 8.11.157.226 2048 Bytes 01.07.2014 11:06:47 XBV00179.VDF : 8.11.157.228 23040 Bytes 01.07.2014 11:06:47 XBV00180.VDF : 8.11.157.234 152064 Bytes 01.07.2014 11:06:47 XBV00181.VDF : 8.11.157.236 6656 Bytes 01.07.2014 11:06:47 XBV00182.VDF : 8.11.157.238 2048 Bytes 01.07.2014 11:06:47 XBV00183.VDF : 8.11.157.240 6144 Bytes 01.07.2014 11:06:47 XBV00184.VDF : 8.11.157.242 2048 Bytes 01.07.2014 11:06:47 XBV00185.VDF : 8.11.157.246 5632 Bytes 01.07.2014 11:06:47 XBV00186.VDF : 8.11.157.248 2048 Bytes 01.07.2014 11:06:47 XBV00187.VDF : 8.11.157.250 2560 Bytes 02.07.2014 11:06:47 XBV00188.VDF : 8.11.157.254 3072 Bytes 02.07.2014 17:27:44 XBV00189.VDF : 8.11.158.2 153600 Bytes 02.07.2014 17:27:44 XBV00190.VDF : 8.11.158.4 178176 Bytes 02.07.2014 17:27:44 XBV00191.VDF : 8.11.158.6 17920 Bytes 02.07.2014 17:27:44 XBV00192.VDF : 8.11.158.14 2048 Bytes 02.07.2014 17:27:44 XBV00193.VDF : 8.11.158.22 7680 Bytes 02.07.2014 17:27:44 XBV00194.VDF : 8.11.158.30 2048 Bytes 02.07.2014 17:27:44 XBV00195.VDF : 8.11.158.38 2560 Bytes 02.07.2014 17:27:44 XBV00196.VDF : 8.11.158.50 166912 Bytes 02.07.2014 17:27:44 XBV00197.VDF : 8.11.158.56 2560 Bytes 02.07.2014 17:27:44 XBV00198.VDF : 8.11.158.62 38912 Bytes 03.07.2014 17:27:44 XBV00199.VDF : 8.11.158.64 2048 Bytes 03.07.2014 17:27:44 XBV00200.VDF : 8.11.158.68 174592 Bytes 03.07.2014 17:27:45 XBV00201.VDF : 8.11.158.72 2048 Bytes 03.07.2014 17:27:45 XBV00202.VDF : 8.11.158.74 12288 Bytes 03.07.2014 17:27:45 XBV00203.VDF : 8.11.158.76 2048 Bytes 03.07.2014 17:27:45 XBV00204.VDF : 8.11.158.78 14848 Bytes 03.07.2014 17:27:45 XBV00205.VDF : 8.11.158.80 11264 Bytes 03.07.2014 17:27:45 XBV00206.VDF : 8.11.158.84 185856 Bytes 03.07.2014 17:27:45 XBV00207.VDF : 8.11.158.86 2048 Bytes 03.07.2014 17:27:45 XBV00208.VDF : 8.11.158.88 3584 Bytes 03.07.2014 17:27:45 XBV00209.VDF : 8.11.158.90 2048 Bytes 03.07.2014 17:27:45 XBV00210.VDF : 8.11.158.92 9216 Bytes 03.07.2014 17:27:45 XBV00211.VDF : 8.11.158.96 12800 Bytes 03.07.2014 17:27:45 XBV00212.VDF : 8.11.158.98 6656 Bytes 03.07.2014 17:27:45 XBV00213.VDF : 8.11.158.102 20992 Bytes 04.07.2014 17:27:45 XBV00214.VDF : 8.11.158.108 161280 Bytes 04.07.2014 17:27:45 XBV00215.VDF : 8.11.158.114 13312 Bytes 04.07.2014 17:27:45 XBV00216.VDF : 8.11.158.116 2048 Bytes 04.07.2014 17:27:45 XBV00217.VDF : 8.11.158.124 2048 Bytes 04.07.2014 17:27:45 XBV00218.VDF : 8.11.158.134 42496 Bytes 04.07.2014 17:27:46 XBV00219.VDF : 8.11.158.136 163328 Bytes 04.07.2014 17:27:46 XBV00220.VDF : 8.11.158.138 2048 Bytes 04.07.2014 17:27:46 XBV00221.VDF : 8.11.158.144 12288 Bytes 04.07.2014 17:27:46 XBV00222.VDF : 8.11.158.146 2048 Bytes 04.07.2014 17:27:46 XBV00223.VDF : 8.11.158.148 7680 Bytes 04.07.2014 17:27:46 XBV00224.VDF : 8.11.158.154 22016 Bytes 05.07.2014 17:27:46 XBV00225.VDF : 8.11.158.156 6656 Bytes 05.07.2014 17:27:46 XBV00226.VDF : 8.11.158.158 10240 Bytes 05.07.2014 17:27:46 XBV00227.VDF : 8.11.158.160 2048 Bytes 05.07.2014 17:27:46 XBV00228.VDF : 8.11.158.162 9216 Bytes 05.07.2014 17:27:46 XBV00229.VDF : 8.11.158.164 2048 Bytes 05.07.2014 17:27:47 XBV00230.VDF : 8.11.158.166 36864 Bytes 06.07.2014 17:27:47 XBV00231.VDF : 8.11.158.168 12288 Bytes 06.07.2014 17:27:47 XBV00232.VDF : 8.11.158.174 8704 Bytes 06.07.2014 17:27:47 XBV00233.VDF : 8.11.158.178 9216 Bytes 06.07.2014 17:27:47 XBV00234.VDF : 8.11.158.182 36352 Bytes 07.07.2014 17:27:47 XBV00235.VDF : 8.11.158.184 5632 Bytes 07.07.2014 17:27:47 XBV00236.VDF : 8.11.158.186 4096 Bytes 07.07.2014 17:27:47 XBV00237.VDF : 8.11.158.188 173056 Bytes 07.07.2014 17:27:47 XBV00238.VDF : 8.11.158.190 2048 Bytes 07.07.2014 17:27:47 XBV00239.VDF : 8.11.158.192 8704 Bytes 07.07.2014 17:27:47 XBV00240.VDF : 8.11.158.194 29184 Bytes 07.07.2014 17:27:47 XBV00241.VDF : 8.11.158.196 2048 Bytes 07.07.2014 17:27:47 XBV00242.VDF : 8.11.158.198 7168 Bytes 07.07.2014 17:27:47 XBV00243.VDF : 8.11.158.200 8704 Bytes 07.07.2014 17:27:47 XBV00244.VDF : 8.11.158.204 33792 Bytes 07.07.2014 17:27:47 XBV00245.VDF : 8.11.158.206 2048 Bytes 07.07.2014 17:27:47 XBV00246.VDF : 8.11.158.208 2048 Bytes 07.07.2014 17:27:47 XBV00247.VDF : 8.11.158.210 17408 Bytes 07.07.2014 17:27:47 XBV00248.VDF : 8.11.158.214 18432 Bytes 08.07.2014 17:27:47 XBV00249.VDF : 8.11.159.14 191488 Bytes 08.07.2014 17:27:48 XBV00250.VDF : 8.11.159.40 35328 Bytes 08.07.2014 17:27:48 XBV00251.VDF : 8.11.159.66 6144 Bytes 08.07.2014 17:27:48 LOCAL001.VDF : 8.11.159.66 107874816 Bytes 08.07.2014 17:29:04 Engineversion : 8.3.20.30 AEVDF.DLL : 8.3.0.4 118976 Bytes 02.07.2014 11:06:41 AESCRIPT.DLL : 8.1.4.218 532680 Bytes 08.07.2014 17:27:43 AESCN.DLL : 8.3.1.2 135360 Bytes 02.07.2014 11:06:41 AESBX.DLL : 8.2.20.24 1409224 Bytes 02.07.2014 11:06:41 AERDL.DLL : 8.2.0.138 704888 Bytes 02.07.2014 11:06:41 AEPACK.DLL : 8.4.0.42 786632 Bytes 08.07.2014 17:27:43 AEOFFICE.DLL : 8.3.0.8 205000 Bytes 08.07.2014 17:27:43 AEHEUR.DLL : 8.1.4.1132 6820040 Bytes 02.07.2014 11:06:41 AEHELP.DLL : 8.3.1.0 278728 Bytes 02.07.2014 11:06:41 AEGEN.DLL : 8.1.7.28 450752 Bytes 02.07.2014 11:06:41 AEEXP.DLL : 8.4.2.6 237760 Bytes 02.07.2014 11:06:41 AEEMU.DLL : 8.1.3.2 393587 Bytes 02.07.2014 11:06:41 AEDROID.DLL : 8.4.2.24 442568 Bytes 02.07.2014 11:06:41 AECORE.DLL : 8.3.1.4 241864 Bytes 02.07.2014 11:06:41 AEBB.DLL : 8.1.1.4 53619 Bytes 02.07.2014 11:06:41 AVWINLL.DLL : 14.0.5.320 24144 Bytes 02.07.2014 11:06:44 AVPREF.DLL : 14.0.5.320 50256 Bytes 02.07.2014 11:06:43 AVREP.DLL : 14.0.5.320 219216 Bytes 02.07.2014 11:06:43 AVARKT.DLL : 14.0.5.368 226384 Bytes 02.07.2014 11:06:42 AVEVTLOG.DLL : 14.0.5.320 182352 Bytes 02.07.2014 11:06:42 SQLITE3.DLL : 14.0.5.320 452176 Bytes 02.07.2014 11:06:47 AVSMTP.DLL : 14.0.5.320 76368 Bytes 02.07.2014 11:06:44 NETNT.DLL : 14.0.5.320 13392 Bytes 02.07.2014 11:06:46 RCIMAGE.DLL : 14.0.5.320 4998224 Bytes 02.07.2014 11:06:46 RCTEXT.DLL : 14.0.5.322 73808 Bytes 02.07.2014 11:06:46 Konfiguration für den aktuellen Suchlauf: Job Name..............................: Vollständige Systemprüfung Konfigurationsdatei...................: C:\Program Files (x86)\Avira\AntiVir Desktop\sysscan.avp Protokollierung.......................: standard Primäre Aktion........................: Interaktiv Sekundäre Aktion......................: Ignorieren Durchsuche Masterbootsektoren.........: ein Durchsuche Bootsektoren...............: ein Bootsektoren..........................: C:, D:, Q:, Durchsuche aktive Programme...........: ein Laufende Programme erweitert..........: ein Durchsuche Registrierung..............: ein Suche nach Rootkits...................: ein Integritätsprüfung von Systemdateien..: aus Prüfe alle Dateien....................: Alle Dateien Durchsuche Archive....................: ein Rekursionstiefe einschränken..........: 20 Archiv Smart Extensions...............: ein Makrovirenheuristik...................: ein Dateiheuristik........................: erweitert Beginn des Suchlaufs: Dienstag, 8. Juli 2014 19:32 Der Suchlauf über die Bootsektoren wird begonnen: Bootsektor 'HDD0(C:, D:, Q:)' [INFO] Es wurde kein Virus gefunden! Der Suchlauf nach versteckten Objekten wird begonnen. Der Suchlauf über gestartete Prozesse wird begonnen: Durchsuche Prozess 'svchost.exe' - '52' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '36' Modul(e) wurden durchsucht Durchsuche Prozess 'atiesrxx.exe' - '26' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '96' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '119' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '85' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '170' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '88' Modul(e) wurden durchsucht Durchsuche Prozess 'atieclxx.exe' - '34' Modul(e) wurden durchsucht Durchsuche Prozess 'spoolsv.exe' - '79' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '61' Modul(e) wurden durchsucht Durchsuche Prozess 'SkypeC2CAutoUpdateSvc.exe' - '30' Modul(e) wurden durchsucht Durchsuche Prozess 'SkypeC2CPNRSvc.exe' - '25' Modul(e) wurden durchsucht Durchsuche Prozess 'RIconMan.exe' - '42' Modul(e) wurden durchsucht Durchsuche Prozess 'sftvsa.exe' - '32' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '35' Modul(e) wurden durchsucht Durchsuche Prozess 'TeamViewer_Service.exe' - '98' Modul(e) wurden durchsucht Durchsuche Prozess 'TODDSrv.exe' - '23' Modul(e) wurden durchsucht Durchsuche Prozess 'TosCoSrv.exe' - '26' Modul(e) wurden durchsucht Durchsuche Prozess 'WLIDSVC.EXE' - '74' Modul(e) wurden durchsucht Durchsuche Prozess 'sftlist.exe' - '77' Modul(e) wurden durchsucht Durchsuche Prozess 'WLIDSvcM.exe' - '17' Modul(e) wurden durchsucht Durchsuche Prozess 'wmiprvse.exe' - '49' Modul(e) wurden durchsucht Durchsuche Prozess 'CVHSVC.EXE' - '83' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '37' Modul(e) wurden durchsucht Durchsuche Prozess 'taskhost.exe' - '69' Modul(e) wurden durchsucht Durchsuche Prozess 'Dwm.exe' - '33' Modul(e) wurden durchsucht Durchsuche Prozess 'TosNcCore.exe' - '34' Modul(e) wurden durchsucht Durchsuche Prozess 'TosReelTimeMonitor.exe' - '63' Modul(e) wurden durchsucht Durchsuche Prozess 'TemproTray.exe' - '70' Modul(e) wurden durchsucht Durchsuche Prozess 'TPwrMain.exe' - '38' Modul(e) wurden durchsucht Durchsuche Prozess 'SmoothView.exe' - '15' Modul(e) wurden durchsucht Durchsuche Prozess 'TCrdMain.exe' - '87' Modul(e) wurden durchsucht Durchsuche Prozess 'RAVCpl64.exe' - '46' Modul(e) wurden durchsucht Durchsuche Prozess 'RAVBg64.exe' - '45' Modul(e) wurden durchsucht Durchsuche Prozess 'SynTPEnh.exe' - '61' Modul(e) wurden durchsucht Durchsuche Prozess 'Skype.exe' - '135' Modul(e) wurden durchsucht Durchsuche Prozess 'AudialsNotifier.exe' - '145' Modul(e) wurden durchsucht Durchsuche Prozess 'TosDIMonitor.exe' - '93' Modul(e) wurden durchsucht Durchsuche Prozess 'SynTPHelper.exe' - '17' Modul(e) wurden durchsucht Durchsuche Prozess 'SearchIndexer.exe' - '57' Modul(e) wurden durchsucht Durchsuche Prozess 'KeNotify.exe' - '28' Modul(e) wurden durchsucht Durchsuche Prozess 'ToshibaServiceStation.exe' - '97' Modul(e) wurden durchsucht Durchsuche Prozess 'MOM.exe' - '72' Modul(e) wurden durchsucht Durchsuche Prozess 'wmpnetwk.exe' - '121' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '72' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '59' Modul(e) wurden durchsucht Durchsuche Prozess 'CCC.exe' - '195' Modul(e) wurden durchsucht Durchsuche Prozess 'DllHost.exe' - '45' Modul(e) wurden durchsucht Durchsuche Prozess 'TMachInfo.exe' - '51' Modul(e) wurden durchsucht Durchsuche Prozess 'PresentationFontCache.exe' - '35' Modul(e) wurden durchsucht Durchsuche Prozess 'CFIWmxSvcs64.exe' - '17' Modul(e) wurden durchsucht Durchsuche Prozess 'CFSvcs.exe' - '59' Modul(e) wurden durchsucht Durchsuche Prozess 'NASvc.exe' - '46' Modul(e) wurden durchsucht Durchsuche Prozess 'TosSmartSrv.exe' - '40' Modul(e) wurden durchsucht Durchsuche Prozess 'TosSENotify.exe' - '42' Modul(e) wurden durchsucht Durchsuche Prozess 'wuauclt.exe' - '39' Modul(e) wurden durchsucht Durchsuche Prozess 'explorer.exe' - '167' Modul(e) wurden durchsucht Durchsuche Prozess 'TeamViewer.exe' - '120' Modul(e) wurden durchsucht Durchsuche Prozess 'tv_w32.exe' - '37' Modul(e) wurden durchsucht Durchsuche Prozess 'tv_x64.exe' - '31' Modul(e) wurden durchsucht Durchsuche Prozess 'avgnt.exe' - '98' Modul(e) wurden durchsucht Durchsuche Prozess 'avguard.exe' - '107' Modul(e) wurden durchsucht Durchsuche Prozess 'avshadow.exe' - '29' Modul(e) wurden durchsucht Durchsuche Prozess 'sched.exe' - '60' Modul(e) wurden durchsucht Durchsuche Prozess 'avscan.exe' - '119' Modul(e) wurden durchsucht Durchsuche Prozess 'vssvc.exe' - '47' Modul(e) wurden durchsucht Durchsuche Prozess 'svchost.exe' - '28' Modul(e) wurden durchsucht Durchsuche Prozess 'smss.exe' - '2' Modul(e) wurden durchsucht Durchsuche Prozess 'csrss.exe' - '18' Modul(e) wurden durchsucht Durchsuche Prozess 'wininit.exe' - '26' Modul(e) wurden durchsucht Durchsuche Prozess 'csrss.exe' - '18' Modul(e) wurden durchsucht Durchsuche Prozess 'winlogon.exe' - '32' Modul(e) wurden durchsucht Durchsuche Prozess 'services.exe' - '33' Modul(e) wurden durchsucht Durchsuche Prozess 'lsass.exe' - '69' Modul(e) wurden durchsucht Durchsuche Prozess 'lsm.exe' - '16' Modul(e) wurden durchsucht Der Suchlauf auf Verweise zu ausführbaren Dateien (Registry) wird begonnen: Die Registry wurde durchsucht ( '11115' Dateien ). Der Suchlauf über die ausgewählten Dateien wird begonnen: Beginne mit der Suche in 'C:\' <WINDOWS> C:\AdwCleaner\Quarantine\C\Program Files (x86)\fst_de_37\freeSoftToday_widget.exe.vir [FUND] Enthält Erkennungsmuster der Adware ADWARE/EoRezo.A.514 C:\AdwCleaner\Quarantine\C\Program Files (x86)\fst_de_37\fst_de_37.exe.vir [FUND] Enthält Erkennungsmuster der Adware ADWARE/EoRezo.A.445 C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\RSHP.exe.vir [FUND] Enthält Erkennungsmuster der Adware ADWARE/Agent.oez.1 C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir [FUND] Enthält Erkennungsmuster der Adware ADWARE/Agent.ALJT.1 C:\AdwCleaner\Quarantine\C\ProgramData\WPM\wprotectmanager.exe.vir [FUND] Enthält Erkennungsmuster der Adware ADWARE/WProtManager.E C:\Users\Yasmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9YP48W4V\5555-1001_NewPlayer[1].exe [0] Archivtyp: NSIS --> ProgramFilesDir/[PluginsDir]/e.dll [FUND] Enthält Erkennungsmuster der Adware ADWARE/AgentCV.A.6945 [WARNUNG] Infizierte Dateien in Archiven können nicht repariert werden C:\Users\Yasmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EDVMW6BW\setup_fst_de[1].exe [0] Archivtyp: Inno Setup --> {pf}\fst_de_37\fst_de_37.exe [FUND] Enthält Erkennungsmuster der Adware ADWARE/EoRezo.A.445 [WARNUNG] Infizierte Dateien in Archiven können nicht repariert werden --> {pf}\fst_de_37\freeSoftToday_widget.exe [FUND] Enthält Erkennungsmuster der Adware ADWARE/EoRezo.A.514 [WARNUNG] Infizierte Dateien in Archiven können nicht repariert werden C:\Users\Yasmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VZEQBGKD\Setup[1].exe [FUND] Enthält Erkennungsmuster der Adware ADWARE/InstallCore.Gen9 Beginne mit der Suche in 'D:\' <Data> Beginne mit der Suche in 'Q:\' Der zu durchsuchende Pfad Q:\ konnte nicht geöffnet werden! Systemfehler [5]: Zugriff verweigert Beginne mit der Desinfektion: C:\Users\Yasmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VZEQBGKD\Setup[1].exe [FUND] Enthält Erkennungsmuster der Adware ADWARE/InstallCore.Gen9 [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '50f0e7e9.qua' verschoben! C:\Users\Yasmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EDVMW6BW\setup_fst_de[1].exe [FUND] Enthält Erkennungsmuster der Adware ADWARE/EoRezo.A.514 [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4867c84e.qua' verschoben! C:\Users\Yasmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9YP48W4V\5555-1001_NewPlayer[1].exe [FUND] Enthält Erkennungsmuster der Adware ADWARE/AgentCV.A.6945 [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '1df99356.qua' verschoben! C:\AdwCleaner\Quarantine\C\ProgramData\WPM\wprotectmanager.exe.vir [FUND] Enthält Erkennungsmuster der Adware ADWARE/WProtManager.E [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '7c11dd53.qua' verschoben! C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir [FUND] Enthält Erkennungsmuster der Adware ADWARE/Agent.ALJT.1 [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '398af052.qua' verschoben! C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\RSHP.exe.vir [FUND] Enthält Erkennungsmuster der Adware ADWARE/Agent.oez.1 [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '46a4c228.qua' verschoben! C:\AdwCleaner\Quarantine\C\Program Files (x86)\fst_de_37\fst_de_37.exe.vir [FUND] Enthält Erkennungsmuster der Adware ADWARE/EoRezo.A.445 [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '0a28ee42.qua' verschoben! C:\AdwCleaner\Quarantine\C\Program Files (x86)\fst_de_37\freeSoftToday_widget.exe.vir [FUND] Enthält Erkennungsmuster der Adware ADWARE/EoRezo.A.514 [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '7621ae12.qua' verschoben! Ende des Suchlaufs: Dienstag, 8. Juli 2014 21:46 Benötigte Zeit: 1:53:05 Stunde(n) Der Suchlauf wurde vollständig durchgeführt. 26434 Verzeichnisse wurden überprüft 534526 Dateien wurden geprüft 9 Viren bzw. unerwünschte Programme wurden gefunden 0 Dateien wurden als verdächtig eingestuft 0 Dateien wurden gelöscht 0 Viren bzw. unerwünschte Programme wurden repariert 8 Dateien wurden in die Quarantäne verschoben 0 Dateien wurden umbenannt 0 Dateien konnten nicht durchsucht werden 534517 Dateien ohne Befall 9600 Archive wurden durchsucht 3 Warnungen 8 Hinweise 672780 Objekte wurden beim Rootkitscan durchsucht 0 Versteckte Objekte wurden gefunden Geändert von JJ11 (08.07.2014 um 18:38 Uhr) |
09.07.2014, 16:29 | #10 |
/// the machine /// TB-Ausbilder | Fake Flash-Player Update gedownloadet :(( sind schon in Quarantäne oder in den temps Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |