|
Plagegeister aller Art und deren Bekämpfung: Dauerhaftes Werbung öffnen macht Surfen fast unmöglichWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
09.07.2014, 15:01 | #1 |
| Dauerhaftes Werbung öffnen macht Surfen fast unmöglich Hi Trojaner-Board Team, mein PC wird seit längerem von Werbung auf Internetseiten zugemüllt, das das Surfen im Internet fast unmöglich macht. An dem PC wurde auch länger nichts gemacht, da er meist nur zum Spielen benutzt wurde nur langsam wird das unerträglich mit der Werbung. Auf sehr vielen Empfehlungen wurde ich auf diese Seite hier verwiesen, da man nur gutes von eurem Team hört. MfG Majin85 |
09.07.2014, 15:01 | #2 |
/// the machine /// TB-Ausbilder | Dauerhaftes Werbung öffnen macht Surfen fast unmöglich hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
09.07.2014, 15:13 | #3 |
| Dauerhaftes Werbung öffnen macht Surfen fast unmöglichFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-07-2014 Ran by Michi (administrator) on MICHI-PC on 09-07-2014 16:08:45 Running from C:\Users\Michi\Desktop Platform: Windows Vista (TM) Ultimate Service Pack 2 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe (Realtek) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe () C:\Program Files (x86)\Verbindungsassistent\WTGService.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe () C:\Program Files (x86)\AVG Secure Search\vprot.exe () C:\Program Files (x86)\Drakonia Configurator\hid.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Program Files (x86)\Drakonia Configurator\trayicon.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaUI.exe () C:\Program Files (x86)\MSI\DualCoreCenter\DualCoreCenter.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [WinSys2] => C:\Windows\system32\startup.exe [52072 2008-01-30] () HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation) HKLM-x32\...\Run: [WinampAgent] => C:\Program Files\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [DATAMNGR] => C:\PROGRA~2\WI371A~1\Datamngr\DATAMN~1.EXE HKLM-x32\...\Run: [DelReg] => C:\Program Files (x86)\MSI\DualCoreCenter\DelReg.exe [196608 2008-05-13] () HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Secure Search\vprot.exe [2571288 2014-06-22] () HKLM-x32\...\Run: [GamingMouse] => C:\Program Files (x86)\Drakonia Configurator\hid.exe [246784 2012-06-07] () HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-06-10] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [fst_de_16] => [X] HKLM-x32\...\Run: [t4pc_en_3] => [X] HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: F - F:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {0c06a6e8-491c-11e1-b54f-806e6f6e6963} - F:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {0c06a733-491c-11e1-b54f-00218508a415} - F:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {1fae0cfc-7b48-11e1-8f4f-00218508a415} - G:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {63a44bda-6498-11e1-9987-00218508a415} - F:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {63a44bdb-6498-11e1-9987-00218508a415} - F:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {6b7f28c9-6317-11e1-b602-00218508a415} - F:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {6b7f28ca-6317-11e1-b602-00218508a415} - H:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {740ac0ff-ba1b-11e2-8ff3-00218508a415} - G:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {bbd552c5-f997-11e0-9681-00218508a415} - F:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {bbd552de-f997-11e0-9681-00218508a415} - G:\AutoRun.exe AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found AppInit_DLLs: C:\PROGRA~3\PERFOR~1\PERFOR~2.DLL => C:\ProgramData\Performancer\Performancer_x64.dll [4302848 2014-06-06] () AppInit_DLLs-x32: c:\progra~2\suptab\search~1.dll => "c:\progra~2\suptab\search~1.dll" File Not Found AppInit_DLLs-x32: c:\progra~3\perfor~1\perfor~1.dll => c:\ProgramData\Performancer\Performancer.dll [4129280 2014-06-06] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\DualCoreCenter.lnk ShortcutTarget: DualCoreCenter.lnk -> C:\Program Files (x86)\MSI\DualCoreCenter\StartUpDualCoreCenter.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files (x86)\Ralink\Common\RaUI.exe (Ralink Technology, Corp.) ShellIconOverlayIdentifiers: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = Babylon Search HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms} URLSearchHook: HKCU - (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms} SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=MSD3_14_10_CH&cd=2XzuyEtN2Y1L1QzutDtDtBtCzzyDtDzz0AyEtCyDtAyC0A0FtN0D0Tzu0SyBzyyBtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyC0D0DtCyE0CyEtDtG0FyE0D0FtG0ByCtDyBtGtD0FtByDtGtBtBtC0FtByC0F0E0DyDyD0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyD0CtC0Ezz0EzytG0EtDyCtAtGzyzyyDyEtG0CtC0D0CtGyDtByB0F0E0FzyyB0AtCzytA2Q&cr=955174791&ir= SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ATU2&o=14670&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=T8&apn_dtid=YYYYYYYYDE&apn_uid=a7e0a2c2-b71e-4c4e-a9d7-675ba3e934eb&apn_sauid=512B1239-32D0-4290-B3A3-B971CE7EF391 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://search.babylon.com/?q={searchTerms}&AF=17350&babsrc=SP_ss&mntrId=547436af000000000000000000000000 SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms} BHO: ProShopperu - {03ADD959-BBFF-DB15-3889-E3B782F798B3} - C:\ProgramData\ProShopperu\vd.x64.dll () BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WI371A~1\Datamngr\x64\BROWSE~1.DLL No File BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: CoupScuanner - {EE8576D7-0A5F-FD10-841C-3FF359D97D4E} - C:\ProgramData\CoupScuanner\pUyJz3N_N.x64.dll () BHO: saavernett - {FB5E2C20-9D02-6288-3506-3C27D46DC1B2} - C:\ProgramData\saavernett\e.x64.dll () BHO-x32: ProShopperu - {03ADD959-BBFF-DB15-3889-E3B782F798B3} - C:\ProgramData\ProShopperu\vd.dll () BHO-x32: Plus-HD-2.2 - {11111111-1111-1111-1111-110311301136} - C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-bho.dll (Plus HD) BHO-x32: HDvid Codec V1 - {11111111-1111-1111-1111-110311431162} - C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-bho.dll (installdaddy) BHO-x32: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI371A~1\Datamngr\ToolBar\searchqudtx.dll No File BHO-x32: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WI371A~1\Datamngr\BROWSE~1.DLL No File BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: CoupScuanner - {EE8576D7-0A5F-FD10-841C-3FF359D97D4E} - C:\ProgramData\CoupScuanner\pUyJz3N_N.dll () BHO-x32: saavernett - {FB5E2C20-9D02-6288-3506-3C27D46DC1B2} - C:\ProgramData\saavernett\e.dll () Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI371A~1\Datamngr\ToolBar\searchqudtx.dll No File Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: HKLM-x32 {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll (AVG Secure Search) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default FF SearchEngineOrder.1: Ask.com FF DefaultSearchEngine: Ask.com FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.7\\npsitesafety.dll No File FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF user.js: detected! => C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\ask-search.xml FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\askcom.xml FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\delta.xml FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\Search_Results.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml FF Extension: Plus-HD-2.2 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com [2013-06-27] FF Extension: Babylon - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\ffxtlbr@babylon.com [2012-01-31] FF Extension: HDvid Codec 3 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc3@hdvidcodec.com [2013-08-09] FF Extension: No Name - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\staged [2014-06-08] FF Extension: Searchqu Toolbar - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} [2011-11-22] FF Extension: HDvid Codec 3 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc3@hdvidcodec.com.xpi [2013-06-30] FF Extension: HDvid Codec - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc@hdvc.com.xpi [2013-04-17] FF Extension: Yontoo - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\plugin@yontoo.com.xpi [2013-05-23] FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-11-02] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR StartupUrls: "hxxp://www.google.com/" CHR Plugin: (Shockwave Flash) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll (AVG Technologies) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Extension: (saavernett) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj [2014-06-08] CHR Extension: (Adblock for Youtube™) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2013-12-04] CHR Extension: (W3schools this!) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb [2014-05-18] CHR Extension: (HDvid Codec 3) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnllcmllkjofnojidnaknldfehfhehoo [2013-08-09] CHR Extension: (One Piece: Monkey D. Luffy (1366x768) Black) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebbcomiedmflgiplmdflpmkhkmkekcih [2013-07-20] CHR Extension: (AdBlock) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-12-04] CHR Extension: (Extensions new tab) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk [2014-06-20] CHR Extension: (Twitch Stream) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce [2014-07-06] CHR Extension: (Wikipedia search) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc [2014-06-08] CHR Extension: (Postcron) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed [2014-06-16] CHR Extension: (Plus-HD-2.2) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo [2013-07-20] CHR Extension: (HDvid Codec) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpkbnefaikfaeadgidhpoanckoiaheli [2013-07-20] CHR Extension: (Text Highlighter) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd [2014-05-18] CHR Extension: (AVG Security Toolbar) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2013-07-20] CHR Extension: (Google Wallet) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-18] CHR HKLM-x32\...\Chrome\Extension: [dnllcmllkjofnojidnaknldfehfhehoo] - C:\Program Files (x86)\HDvidCodec.com\HDvidCodec10.crx [2013-06-30] CHR HKLM-x32\...\Chrome\Extension: [kpkbnefaikfaeadgidhpoanckoiaheli] - C:\Program Files (x86)\HDvidCodec.com\HDvidCodec10.crx [2013-06-30] CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\18.1.0.443\avg.crx [2014-04-27] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-06-26] (BitRaider, LLC) R2 dfc86759; c:\ProgramData\Performancer\PerformancerSvc.dll [186192 2014-06-06] () [File not signed] R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [704112 2014-05-08] (Cherished Technololgy LIMITED) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) S3 OnlineStorageService; C:\Program Files\Trend Micro SafeSync\hrfscore.exe [7908664 2012-07-12] (Trend Micro Inc.) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-08-22] (Overwolf Ltd) S2 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [621632 2011-03-04] () R2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek) [File not signed] R2 vToolbarUpdater18.1.7; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe [1813528 2014-06-22] (AVG Secure Search) R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\wtgservice.exe [329168 2011-10-18] () S2 NewPlayer; C:\Program Files (x86)\NewPlayer\NewPlayerLwr161.exe [X] ==================== Drivers (Whitelisted) ==================== R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-06-22] (AVG Technologies) R3 DualCoreCenter; C:\Program Files (x86)\MSI\DualCoreCenter\NTGLM7X64.sys [44344 2010-02-08] (MICRO-STAR INT'L CO., LTD.) S3 GameKB; C:\Windows\System32\drivers\GameKB.sys [27648 2012-05-11] () [File not signed] S3 hwdatacard; C:\Windows\SysWOW64\DRIVERS\ewusbmdm.sys [115328 2008-07-24] (Huawei Technologies Co., Ltd.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) S3 MSIGreenPower; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\NTGLM7X64.sys [40248 2008-03-12] (MICRO-STAR INT'L CO., LTD.) [File not signed] S3 MSIGreenPowerRushTop; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushTop64.sys [74072 2008-04-23] (Your Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7369v290\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [File not signed] R3 NVR0Dev; C:\Windows\nvoclk64.sys [18216 2006-10-13] (NVidia Corp.) R3 RushTopDevice2; C:\Program Files (x86)\MSI\DualCoreCenter\RushTop64.sys [76088 2009-03-18] (Your Corporation) S3 RushTopDevice_J; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushJ64.sys [31544 2008-06-05] (Your Corporation) [File not signed] R1 {9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64; C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64.sys [60088 2014-05-16] (StdLib) S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S1 lhbjqqty; \??\C:\Windows\system32\drivers\lhbjqqty.sys [X] S3 MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [X] S1 neqnrghc; \??\C:\Windows\system32\drivers\neqnrghc.sys [X] S3 netr28ux; system32\DRIVERS\netr28ux.sys [X] S3 NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S1 rnigwgbp; \??\C:\Windows\system32\drivers\rnigwgbp.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-09 16:08 - 2014-07-09 16:09 - 00030116 _____ () C:\Users\Michi\Desktop\FRST.txt 2014-07-09 16:07 - 2014-07-09 16:08 - 00000000 ____D () C:\FRST 2014-07-09 16:05 - 2014-07-09 16:05 - 02084352 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe 2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip 2014-07-09 13:46 - 2014-06-07 06:02 - 17854464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-09 13:46 - 2014-06-07 04:59 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-09 13:46 - 2014-06-07 04:52 - 01348608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-09 13:46 - 2014-06-07 04:51 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-09 13:46 - 2014-06-07 04:51 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-09 13:46 - 2014-06-07 04:47 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-09 13:46 - 2014-06-07 04:45 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-07-09 13:46 - 2014-06-07 04:45 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-09 13:46 - 2014-06-07 04:45 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-09 13:46 - 2014-06-07 04:42 - 02148352 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-09 13:46 - 2014-06-07 04:42 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-09 13:46 - 2014-06-07 04:42 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-09 13:46 - 2014-06-07 04:42 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-09 13:46 - 2014-06-07 04:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-09 13:46 - 2014-06-07 04:41 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-07-09 13:46 - 2014-06-07 04:40 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-09 13:46 - 2014-06-07 04:39 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-07-09 13:46 - 2014-06-07 04:35 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-09 13:46 - 2014-06-07 02:05 - 12353024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-09 13:46 - 2014-06-07 01:12 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-09 13:46 - 2014-06-07 01:04 - 01106432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-09 13:46 - 2014-06-07 01:03 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-09 13:46 - 2014-06-07 01:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-09 13:46 - 2014-06-07 01:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-07-09 13:46 - 2014-06-07 00:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-07-09 13:46 - 2014-06-07 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-07-09 13:46 - 2014-06-07 00:54 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-09 13:46 - 2014-06-07 00:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-09 13:46 - 2014-06-07 00:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-07-09 13:46 - 2014-06-07 00:53 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-09 13:46 - 2014-06-07 00:52 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-09 13:46 - 2014-06-07 00:51 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-07-09 13:46 - 2014-06-07 00:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-07-09 13:45 - 2014-06-07 05:13 - 10890752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-09 13:45 - 2014-06-07 04:50 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-07-09 13:45 - 2014-06-07 04:41 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-07-09 13:45 - 2014-06-07 01:25 - 09711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-09 13:45 - 2014-06-07 00:58 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-09 13:45 - 2014-06-07 00:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-07-09 13:45 - 2014-06-07 00:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-09 13:45 - 2014-06-07 00:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-09 13:45 - 2014-06-07 00:53 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-07-09 13:44 - 2014-06-07 02:33 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-09 13:44 - 2014-06-06 10:59 - 00506880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-07-09 13:44 - 2014-06-06 09:13 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-09 13:44 - 2014-05-30 09:10 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-06 10:48 - 2014-07-06 10:48 - 00000000 ____D () C:\ProgramData\ProShopperu 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX 2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx 2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR 2014-06-26 15:21 - 2014-07-07 13:06 - 00000000 ____D () C:\ProgramData\BitRaider 2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider 2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk 2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA 2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk 2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment 2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk 2014-06-20 12:02 - 2014-06-20 12:03 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver 2014-06-20 10:16 - 2014-06-20 10:16 - 00000000 ____D () C:\ProgramData\CoupScuanner 2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk 2014-06-16 10:58 - 2014-06-16 10:57 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk 2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk 2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt 2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt 2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt 2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt 2014-06-15 11:44 - 2014-06-29 23:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks 2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe 2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe 2014-06-12 13:30 - 2014-04-26 20:21 - 00622592 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-12 13:30 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-06-12 13:30 - 2014-04-05 06:26 - 01417664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-12 13:30 - 2014-04-05 04:32 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2014-06-12 13:30 - 2014-03-10 08:26 - 01869824 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-12 13:30 - 2014-03-10 08:26 - 01794560 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-12 13:30 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2014-06-12 13:30 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll ==================== One Month Modified Files and Folders ======= 2014-07-09 16:09 - 2014-07-09 16:08 - 00030116 _____ () C:\Users\Michi\Desktop\FRST.txt 2014-07-09 16:08 - 2014-07-09 16:07 - 00000000 ____D () C:\FRST 2014-07-09 16:05 - 2014-07-09 16:05 - 02084352 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe 2014-07-09 16:03 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-09 16:03 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-09 15:57 - 2013-05-06 22:53 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-09 15:56 - 2013-08-09 21:56 - 00001212 _____ () C:\Windows\Tasks\HDvid Codec V1-updater.job 2014-07-09 15:56 - 2013-08-09 21:56 - 00001116 _____ () C:\Windows\Tasks\HDvid Codec V1-enabler.job 2014-07-09 15:55 - 2013-08-09 21:55 - 00001206 _____ () C:\Windows\Tasks\HDvid Codec V1-codedownloader.job 2014-07-09 14:17 - 2013-05-14 23:00 - 01578094 _____ () C:\Windows\WindowsUpdate.log 2014-07-09 14:06 - 2013-06-27 23:26 - 00001906 _____ () C:\Windows\Tasks\Plus-HD-2.2-chromeinstaller.job 2014-07-09 14:06 - 2013-06-27 23:26 - 00001830 _____ () C:\Windows\Tasks\Plus-HD-2.2-firefoxinstaller.job 2014-07-09 14:06 - 2013-06-27 23:26 - 00001194 _____ () C:\Windows\Tasks\Plus-HD-2.2-updater.job 2014-07-09 14:05 - 2013-06-27 23:26 - 00001198 _____ () C:\Windows\Tasks\Plus-HD-2.2-codedownloader.job 2014-07-09 14:05 - 2013-06-27 23:26 - 00001098 _____ () C:\Windows\Tasks\Plus-HD-2.2-enabler.job 2014-07-09 14:05 - 2013-05-06 22:53 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-09 14:03 - 2014-03-13 18:14 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-07-09 14:03 - 2006-11-02 17:40 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-09 14:03 - 2006-11-02 17:21 - 00255776 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-09 13:59 - 2006-11-02 17:40 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-09 13:59 - 2006-11-02 17:06 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-09 13:57 - 2013-07-22 05:26 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-09 13:54 - 2006-11-02 14:35 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip 2014-07-09 00:35 - 2012-08-16 08:22 - 00001692 _____ () C:\Users\Michi\Desktop\bla.txt 2014-07-07 13:06 - 2014-06-26 15:21 - 00000000 ____D () C:\ProgramData\BitRaider 2014-07-07 12:56 - 2011-10-18 16:41 - 00055560 _____ () C:\Users\Michi\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-07 12:54 - 2011-10-19 16:48 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-07-06 10:48 - 2014-07-06 10:48 - 00000000 ____D () C:\ProgramData\ProShopperu 2014-07-06 10:48 - 2014-06-08 19:55 - 00000000 ____D () C:\ProgramData\297d856b205d5963 2014-07-05 16:05 - 2011-11-22 11:56 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\vlc 2014-07-05 01:02 - 2012-02-02 03:37 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\TS3Client 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX 2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx 2014-07-04 17:09 - 2011-10-18 16:41 - 00000000 ____D () C:\Users\Michi 2014-07-03 14:42 - 2012-05-11 00:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Skype 2014-06-30 06:36 - 2011-10-20 02:44 - 00175616 _____ () C:\Users\Michi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-06-29 23:08 - 2014-06-15 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks 2014-06-27 11:36 - 2013-08-30 14:25 - 00000000 ____D () C:\Users\Michi\Desktop\TS Icons 2014-06-27 11:19 - 2012-02-02 03:35 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR 2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider 2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk 2014-06-26 14:06 - 2013-07-20 12:23 - 00014744 _____ () C:\Users\Michi\Documents\Install STAR WARS The Old Republic.log 2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-06-26 14:05 - 2014-05-18 13:49 - 00000000 _____ () C:\END 2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA 2014-06-23 08:33 - 2013-05-06 15:32 - 00001217 _____ () C:\Users\Michi\Desktop\WoW PWS.lnk 2014-06-22 19:39 - 2014-04-27 17:13 - 00000000 ____D () C:\ProgramData\AVG Secure Search 2014-06-22 19:39 - 2013-06-26 20:25 - 00050464 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2014-06-22 19:39 - 2013-06-26 20:25 - 00000000 ____D () C:\Program Files (x86)\AVG Secure Search 2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk 2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment 2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk 2014-06-20 12:03 - 2014-06-20 12:02 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver 2014-06-20 10:16 - 2014-06-20 10:16 - 00000000 ____D () C:\ProgramData\CoupScuanner 2014-06-17 17:56 - 2012-12-13 10:46 - 00000000 ____D () C:\Filme 2014-06-17 17:56 - 2012-08-25 14:45 - 00000000 ____D () C:\Users\Michi\Desktop\Wma 2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk 2014-06-16 11:00 - 2014-02-03 14:46 - 00155136 _____ () C:\Windows\SysWOW64\unrar.dll 2014-06-16 11:00 - 2014-02-03 14:46 - 00034308 _____ () C:\Windows\SysWOW64\bassmod.dll 2014-06-16 10:57 - 2014-06-16 10:58 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk 2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk 2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt 2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt 2014-06-16 07:18 - 2013-05-12 09:58 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-06-16 07:18 - 2012-01-27 19:49 - 00000000 ____D () C:\Games 2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt 2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt 2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe 2014-06-15 11:25 - 2013-05-12 18:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Wargaming.net 2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-09 14:08 ==================== End Of Log ============================ FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-07-2014 Ran by Michi at 2014-07-09 16:09:51 Running from C:\Users\Michi\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.8.800.175 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.7.700.224 - Adobe Systems Incorporated) Adobe Reader X (10.1.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated) aTube Catcher (HKLM-x32\...\aTube Catcher) (Version: 3.8.7955 - DsNET Corp) AVG Security Toolbar (HKLM-x32\...\AVG Secure Search) (Version: 18.1.7.644 - AVG Technologies) Bing Maps 3D (HKLM\...\{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}) (Version: 4.0.903.16005 - Microsoft Corporation) BitRaider Web Client (HKLM-x32\...\BitRaider Web Client) (Version: 1.1.9.9 - BitRaider, LLC) Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) CoupScuanner (HKLM-x32\...\{80E8B0A0-117D-1402-7CDE-688156237115}) (Version: - CCoupScAnneR) Drakonia Configurator (HKLM-x32\...\{A7B243AA-6D4C-4575-A873-6F01A1EFC5E2}}_is1) (Version: - ) DriverTuner 3.1.0.0 (HKLM-x32\...\{520C1D80-935C-42B9-9340-E883849D804F}_is1) (Version: 3.1.0.0 - LionSea SoftWare) DualCoreCenter (HKLM-x32\...\DualCoreCenter_is1) (Version: - MSI, Inc.) EasyViewer (HKLM-x32\...\InstallShield_{EECD7B96-1416-4D3A-B12D-0D2512120C36}) (Version: 1.3.0.9 - MSI) EasyViewer (x32 Version: 1.3.0.9 - MSI) Hidden ffdshow v1.2.4422 [2012-04-09] (HKLM-x32\...\ffdshow_is1) (Version: 1.2.4422.0 - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.137 - Google Inc.) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden HDvid Codec V1 (HKLM-x32\...\HDvid Codec V1) (Version: 1.27.153.8 - installdaddy) <==== ATTENTION HDVidCodec (HKLM-x32\...\1ClickDownload) (Version: 2.1 Build 26473 - hdvidcodec.com) <==== ATTENTION iLivid (HKLM-x32\...\iLivid) (Version: 1.92.0.117387 - Bandoo Media Inc.) <==== ATTENTION iLivid (x32 Version: 1.92.0.117387 - Bandoo Media Inc.) Hidden <==== ATTENTION Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.550 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Notepad++ (HKLM-x32\...\Notepad++) (Version: 5.9.6 - ) NVIDIA 3D Vision Controller Driver (x32 Version: 280.19 - NVIDIA Corporation) Hidden NVIDIA 3D Vision Treiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 311.06 - NVIDIA Corporation) NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.12.5896 - NVIDIA Corporation) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8.2.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.2.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.06 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 311.06 (Version: 311.06 - NVIDIA Corporation) Hidden NVIDIA Update 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 11.10.13 - NVIDIA Corporation) Hidden OpenOffice.org 3.4 (HKLM-x32\...\{4C552FD3-2CCD-4E00-AC64-0681DBB3F8B5}) (Version: 3.4.9590 - OpenOffice.org) Overwolf (HKLM-x32\...\{48615A7B-F026-4F62-A3F1-49001B8E21CB}) (Version: 0.44.256 - Overwolf) PDF24 Creator 5.6.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Performancer (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{dfc86759}) (Version: - 24soft) <==== ATTENTION Plus-HD-2.2 (HKLM-x32\...\Plus-HD-2.2) (Version: 1.27.153.6 - Plus HD) <==== ATTENTION ProShopperu (HKLM-x32\...\{8F213470-964F-4092-6B31-BC7570F31B5A}) (Version: - ProShopper) <==== ATTENTION Ralink RT2860 Wireless LAN Card (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.5.12.0 - Ralink) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 6.250.908.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6873 - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver and Utility (HKLM-x32\...\{9C049499-055C-4a0c-A916-1D8CA1FF45EB}) (Version: 1.00.0182 - REALTEK Semiconductor Corp.) saavernett (HKLM-x32\...\{614925F9-841A-53FE-A28F-DC30FA07239B}) (Version: - saveRnEt) Samsung_MonSetup (HKLM-x32\...\{8EA79DBF-D637-448A-89D6-410A087A4493}) (Version: 1.00.0000 - Samsung) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version: 7.0.0.45 - Bioware/EA) Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.) System Requirements Lab (HKLM-x32\...\SystemRequirementsLab) (Version: - ) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH) Trend Micro SafeSync (HKLM\...\HFRS_is1) (Version: 5.1.0.1173 - Trend Micro) Ultimate Extras sounds from Microsoft® Tinker™ (HKLM\...\UltSounds2) (Version: - Microsoft Corporation) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation) Verbindungsassistent (HKLM-x32\...\Verbindungsassistent) (Version: 2.1 - Verbindungsassistent) VideoGenie (HKLM-x32\...\{FC54FD8D-789C-406D-BB88-F7C4421B7E83}_is1) (Version: 1.0.0.12 - MSI) Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies) Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies) VLC classic (HKLM-x32\...\VLC classic) (Version: 1.14 - vlcplayerdownload.com) W322U (HKLM-x32\...\{B64CEFD3-B6AB-40CD-8333-EDDBDB951751}) (Version: 1.00.0000 - Tenda) Winamp (HKLM-x32\...\Winamp) (Version: 5.621 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKCU\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Windows iLivid Toolbar (HKLM-x32\...\Windows Searchqu Toolbar) (Version: 3.0.0.117530 - Bandoo Media, Inc) <==== ATTENTION Windows-Soundschemas (HKLM\...\UltSounds) (Version: - Microsoft Corporation) WinRAR 4.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH) ==================== Restore Points ========================= 30-06-2014 13:35:10 Geplanter Prüfpunkt 02-07-2014 17:26:26 Geplanter Prüfpunkt 03-07-2014 14:40:32 Geplanter Prüfpunkt 04-07-2014 09:27:42 Windows Update 04-07-2014 15:07:27 Installiert SHARKOON Skiller 04-07-2014 15:08:55 Gerätetreiber-Paketinstallation: Sharkoon Eingabegeräte (Human Interface Devices) 05-07-2014 16:59:42 Geplanter Prüfpunkt 06-07-2014 18:15:02 Entfernt SHARKOON Skiller 07-07-2014 11:06:44 Windows Update 08-07-2014 00:05:18 Geplanter Prüfpunkt 08-07-2014 13:17:40 Geplanter Prüfpunkt 09-07-2014 11:53:30 Windows Update ==================== Hosts content: ========================== 2006-11-02 14:34 - 2006-09-18 23:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {00C5BFF5-EEAF-4637-93EA-ADF6229D3234} - System32\Tasks\Plus-HD-2.2-firefoxinstaller => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-firefoxinstaller.exe [2013-06-27] (Plus HD) <==== ATTENTION Task: {07B42F71-7E37-4EC3-8E83-4BE1FFE5C03D} - System32\Tasks\eType Setup => C:\Users\Michi\AppData\Local\Temp\eType Setup403431.exe <==== ATTENTION Task: {0871AFF5-575C-40FC-A05F-24E29DC1452B} - System32\Tasks\HDvid Codec V1-codedownloader => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-codedownloader.exe [2013-08-09] (installdaddy) <==== ATTENTION Task: {09D6CD90-BE85-4FF1-9D62-B51B87202CCF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-06] (Google Inc.) Task: {09EAFC8C-A951-41B9-8D2B-A1F18FBB21EC} - System32\Tasks\Plus-HD-2.2-chromeinstaller => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-chromeinstaller.exe [2013-06-27] (Plus HD) <==== ATTENTION Task: {0D36FC03-8888-410A-9037-DF358381DDF0} - System32\Tasks\HDvid Codec V1-updater => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-updater.exe [2013-08-09] (installdaddy) <==== ATTENTION Task: {27664485-6DD3-4E67-A392-23E241238E1D} - System32\Tasks\Plus-HD-2.2-codedownloader => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-codedownloader.exe [2013-06-27] (Plus HD) <==== ATTENTION Task: {27DC0BEB-20BB-4BAF-A4D6-C38628372658} - System32\Tasks\Plus-HD-2.2-enabler => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-enabler.exe [2013-06-27] (Plus HD) <==== ATTENTION Task: {3027772B-B827-4998-B62C-4E4C617B5DFA} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation) Task: {34F4AFBD-4B27-4161-BB74-EC0D1F6139BC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-06] (Google Inc.) Task: {720B96CE-CD10-4370-A0B1-73D2741DFC9D} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files (x86)\TuneUp Utilities 2010\OneClick.exe Task: {8E146441-DDF2-4E33-AEA7-A1CECCAEBA5B} - System32\Tasks\HDvid Codec V1-enabler => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-enabler.exe [2013-08-09] (installdaddy) <==== ATTENTION Task: {9475DD97-BB54-4FD8-A31A-032B4833F6AA} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {996457A5-8249-47C5-B620-CA695B7E6DA1} - System32\Tasks\WOT WFRI1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {9A441CE9-6C4F-4991-954B-EDCB9256D04F} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => Rundll32.exe %windir%\system32\pla.dll,PlaConvertLogEntries Task: {AA105019-BFFB-4713-B627-81B47F4419F0} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {ADDB4957-FD21-4041-ADF2-C1DAF0991DA8} - System32\Tasks\Plus-HD-2.2-updater => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-updater.exe [2013-06-27] (Plus HD) <==== ATTENTION Task: {C0B38178-CA76-4475-90EB-B2F41221156B} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {C28278BF-1ABF-4595-BB2A-15201DDF25E3} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {C41E9FD5-A5DB-4DEF-9715-E4F7BAFEE730} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {E7D52131-C543-4A8D-8669-9FEC0C9AEE08} - System32\Tasks\{6E07F2B2-386B-4ABF-9A74-F6643ABA3D4E} => Chrome.exe Skype auf Ihren Computer herunterladen ? Mac, Windows, Linux*?*Skype Task: {F5B3AF16-E40C-4C45-B115-2698E999BB9F} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HDvid Codec V1-codedownloader.job => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\HDvid Codec V1-enabler.job => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-enabler.exe <==== ATTENTION Task: C:\Windows\Tasks\HDvid Codec V1-updater.job => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-updater.exe <==== ATTENTION Task: C:\Windows\Tasks\Plus-HD-2.2-chromeinstaller.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-chromeinstaller.exe <==== ATTENTION Task: C:\Windows\Tasks\Plus-HD-2.2-codedownloader.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\Plus-HD-2.2-enabler.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-enabler.exe <==== ATTENTION Task: C:\Windows\Tasks\Plus-HD-2.2-firefoxinstaller.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-firefoxinstaller.exe <==== ATTENTION Task: C:\Windows\Tasks\Plus-HD-2.2-updater.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-updater.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2014-06-06 09:51 - 2014-06-06 09:51 - 04302848 _____ () C:\ProgramData\Performancer\Performancer_x64.dll 2014-06-22 19:39 - 2014-06-22 19:39 - 00159768 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe 2011-10-18 16:53 - 2011-10-18 17:02 - 00329168 _____ () C:\Program Files (x86)\Verbindungsassistent\wtgservice.exe 2011-12-30 03:30 - 2011-05-28 23:05 - 00164864 _____ () C:\Program Files\WinRAR\rarext.dll 2011-07-18 23:04 - 2011-07-18 23:04 - 00301568 _____ () C:\Program Files (x86)\Notepad++\NppShell_04.dll 2013-06-26 20:25 - 2014-06-22 19:39 - 02571288 _____ () C:\Program Files (x86)\AVG Secure Search\vprot.exe 2013-06-29 11:36 - 2012-06-07 10:24 - 00246784 _____ () C:\Program Files (x86)\Drakonia Configurator\hid.exe 2013-06-29 11:36 - 2012-06-14 10:44 - 00240640 _____ () C:\Program Files (x86)\Drakonia Configurator\trayicon.exe 2013-05-08 09:35 - 2010-06-29 18:20 - 41382002 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\DualCoreCenter.exe 2014-06-06 09:51 - 2014-06-06 09:51 - 04129280 _____ () c:\ProgramData\Performancer\Performancer.dll 2014-06-06 09:51 - 2014-06-06 09:51 - 00186192 _____ () c:\ProgramData\Performancer\PerformancerSvc.dll 2014-06-22 19:39 - 2014-06-22 19:39 - 00519704 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\log4cplusU.dll 2013-06-29 11:36 - 2011-11-22 14:18 - 00061440 _____ () C:\Program Files (x86)\Drakonia Configurator\HidDevice.dll 2013-06-29 11:36 - 2011-11-22 14:18 - 00249856 _____ () C:\Program Files (x86)\Drakonia Configurator\language.dll 2013-10-08 02:19 - 2011-05-04 19:53 - 01058664 _____ () C:\Program Files (x86)\Ralink\Common\RaWLAPI.dll 2013-05-08 09:35 - 2009-03-17 16:36 - 00147456 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\RushTop.dll 2013-05-08 09:35 - 2007-01-05 11:59 - 00077824 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\CpuUsage.dll 2013-05-08 09:35 - 2008-09-08 15:02 - 00094208 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\VGADLL.dll 2014-05-18 12:42 - 2014-05-08 01:29 - 00065352 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\chrome_elf.dll 2014-05-18 12:42 - 2014-05-08 01:29 - 04081480 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\pdf.dll 2014-05-18 12:42 - 2014-05-08 01:29 - 00390472 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ppGoogleNaClPluginChrome.dll 2014-05-18 12:42 - 2014-05-08 01:29 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ffmpegsumo.dll 2014-05-18 12:42 - 2014-05-08 01:29 - 13695816 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:679ABA25 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service" ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= Name: Microsoft-ISATAP-Adapter #2 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-ISATAP-Adapter #3 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-ISATAP-Adapter #4 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-ISATAP-Adapter #5 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-ISATAP-Adapter #6 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: PolicyAgent4 Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4 Error: (07/09/2014 02:06:55 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: EmdCache4 Error: (07/09/2014 02:04:56 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: PolicyAgent4 Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: EmdCache4 Error: (07/09/2014 01:35:21 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: PolicyAgent4 Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4 Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: EmdCache4 System errors: ============= Error: (07/09/2014 02:05:53 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: 30000Realtek11nSU Error: (07/09/2014 02:04:57 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: 30000Ralink UPnP Media Server Error: (07/09/2014 02:02:23 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (07/09/2014 02:02:23 PM) (Source: Ntfs) (EventID: 137) (User: ) Description: Der Transaktionsressourcen-Manager auf Volume "F:" konnte aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (07/09/2014 02:02:19 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (07/09/2014 02:02:11 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (07/09/2014 02:02:07 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (07/09/2014 01:35:21 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: 30000Ralink UPnP Media Server Error: (07/09/2014 01:33:54 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (07/09/2014 01:33:54 PM) (Source: Ntfs) (EventID: 137) (User: ) Description: Der Transaktionsressourcen-Manager auf Volume "F:" konnte aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Microsoft Office Sessions: ========================= Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: PolicyAgent4 Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4 Error: (07/09/2014 02:06:55 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: EmdCache4 Error: (07/09/2014 02:04:56 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: PolicyAgent4 Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: EmdCache4 Error: (07/09/2014 01:35:21 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: PolicyAgent4 Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4 Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: EmdCache4 CodeIntegrity Errors: =================================== Date: 2014-07-08 13:48:59.581 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-08 13:48:59.269 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-08 13:48:58.941 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-08 13:48:58.613 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-08 13:48:57.988 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-08 13:48:57.675 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-07 03:40:54.653 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-07 03:40:54.325 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-07 03:40:53.995 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-07 03:40:53.661 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 53% Total physical RAM: 4094.46 MB Available physical RAM: 1923.58 MB Total Pagefile: 8425.43 MB Available Pagefile: 5869.19 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:232.88 GB) (Free:36.72 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive e: (F) (Fixed) (Total:149.05 GB) (Free:38.31 GB) NTFS Drive f: () (Fixed) (Total:298.09 GB) (Free:98.98 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: A2DEA2DE) Partition 1: (Active) - (Size=233 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 8136E346) Partition 1: (Active) - (Size=298 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 149 GB) (Disk ID: 3FC1A37E) Partition 1: (Not Active) - (Size=149 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Hi, super das ging ja schnell das du dich meiner annimmst eben noch andere Themen von dir gelesen |
09.07.2014, 15:14 | #4 |
| Dauerhaftes Werbung öffnen macht Surfen fast unmöglichFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-07-2014 Ran by Michi (administrator) on MICHI-PC on 09-07-2014 16:08:45 Running from C:\Users\Michi\Desktop Platform: Windows Vista (TM) Ultimate Service Pack 2 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe (Realtek) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe () C:\Program Files (x86)\Verbindungsassistent\WTGService.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe () C:\Program Files (x86)\AVG Secure Search\vprot.exe () C:\Program Files (x86)\Drakonia Configurator\hid.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe () C:\Program Files (x86)\Drakonia Configurator\trayicon.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaUI.exe () C:\Program Files (x86)\MSI\DualCoreCenter\DualCoreCenter.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\conime.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [WinSys2] => C:\Windows\system32\startup.exe [52072 2008-01-30] () HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation) HKLM-x32\...\Run: [WinampAgent] => C:\Program Files\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [DATAMNGR] => C:\PROGRA~2\WI371A~1\Datamngr\DATAMN~1.EXE HKLM-x32\...\Run: [DelReg] => C:\Program Files (x86)\MSI\DualCoreCenter\DelReg.exe [196608 2008-05-13] () HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Secure Search\vprot.exe [2571288 2014-06-22] () HKLM-x32\...\Run: [GamingMouse] => C:\Program Files (x86)\Drakonia Configurator\hid.exe [246784 2012-06-07] () HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-06-10] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [fst_de_16] => [X] HKLM-x32\...\Run: [t4pc_en_3] => [X] HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: F - F:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {0c06a6e8-491c-11e1-b54f-806e6f6e6963} - F:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {0c06a733-491c-11e1-b54f-00218508a415} - F:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {1fae0cfc-7b48-11e1-8f4f-00218508a415} - G:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {63a44bda-6498-11e1-9987-00218508a415} - F:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {63a44bdb-6498-11e1-9987-00218508a415} - F:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {6b7f28c9-6317-11e1-b602-00218508a415} - F:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {6b7f28ca-6317-11e1-b602-00218508a415} - H:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {740ac0ff-ba1b-11e2-8ff3-00218508a415} - G:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {bbd552c5-f997-11e0-9681-00218508a415} - F:\AutoRun.exe HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {bbd552de-f997-11e0-9681-00218508a415} - G:\AutoRun.exe AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found AppInit_DLLs: C:\PROGRA~3\PERFOR~1\PERFOR~2.DLL => C:\ProgramData\Performancer\Performancer_x64.dll [4302848 2014-06-06] () AppInit_DLLs-x32: c:\progra~2\suptab\search~1.dll => "c:\progra~2\suptab\search~1.dll" File Not Found AppInit_DLLs-x32: c:\progra~3\perfor~1\perfor~1.dll => c:\ProgramData\Performancer\Performancer.dll [4129280 2014-06-06] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\DualCoreCenter.lnk ShortcutTarget: DualCoreCenter.lnk -> C:\Program Files (x86)\MSI\DualCoreCenter\StartUpDualCoreCenter.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files (x86)\Ralink\Common\RaUI.exe (Ralink Technology, Corp.) ShellIconOverlayIdentifiers: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = Babylon Search HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms} URLSearchHook: HKCU - (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms} SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms} SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=MSD3_14_10_CH&cd=2XzuyEtN2Y1L1QzutDtDtBtCzzyDtDzz0AyEtCyDtAyC0A0FtN0D0Tzu0SyBzyyBtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyC0D0DtCyE0CyEtDtG0FyE0D0FtG0ByCtDyBtGtD0FtByDtGtBtBtC0FtByC0F0E0DyDyD0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyD0CtC0Ezz0EzytG0EtDyCtAtGzyzyyDyEtG0CtC0D0CtGyDtByB0F0E0FzyyB0AtCzytA2Q&cr=955174791&ir= SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ATU2&o=14670&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=T8&apn_dtid=YYYYYYYYDE&apn_uid=a7e0a2c2-b71e-4c4e-a9d7-675ba3e934eb&apn_sauid=512B1239-32D0-4290-B3A3-B971CE7EF391 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://search.babylon.com/?q={searchTerms}&AF=17350&babsrc=SP_ss&mntrId=547436af000000000000000000000000 SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms} BHO: ProShopperu - {03ADD959-BBFF-DB15-3889-E3B782F798B3} - C:\ProgramData\ProShopperu\vd.x64.dll () BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WI371A~1\Datamngr\x64\BROWSE~1.DLL No File BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: CoupScuanner - {EE8576D7-0A5F-FD10-841C-3FF359D97D4E} - C:\ProgramData\CoupScuanner\pUyJz3N_N.x64.dll () BHO: saavernett - {FB5E2C20-9D02-6288-3506-3C27D46DC1B2} - C:\ProgramData\saavernett\e.x64.dll () BHO-x32: ProShopperu - {03ADD959-BBFF-DB15-3889-E3B782F798B3} - C:\ProgramData\ProShopperu\vd.dll () BHO-x32: Plus-HD-2.2 - {11111111-1111-1111-1111-110311301136} - C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-bho.dll (Plus HD) BHO-x32: HDvid Codec V1 - {11111111-1111-1111-1111-110311431162} - C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-bho.dll (installdaddy) BHO-x32: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI371A~1\Datamngr\ToolBar\searchqudtx.dll No File BHO-x32: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WI371A~1\Datamngr\BROWSE~1.DLL No File BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: CoupScuanner - {EE8576D7-0A5F-FD10-841C-3FF359D97D4E} - C:\ProgramData\CoupScuanner\pUyJz3N_N.dll () BHO-x32: saavernett - {FB5E2C20-9D02-6288-3506-3C27D46DC1B2} - C:\ProgramData\saavernett\e.dll () Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI371A~1\Datamngr\ToolBar\searchqudtx.dll No File Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: HKLM-x32 {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll (AVG Secure Search) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default FF SearchEngineOrder.1: Ask.com FF DefaultSearchEngine: Ask.com FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.7\\npsitesafety.dll No File FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF user.js: detected! => C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\ask-search.xml FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\askcom.xml FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\delta.xml FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\Search_Results.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml FF Extension: Plus-HD-2.2 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com [2013-06-27] FF Extension: Babylon - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\ffxtlbr@babylon.com [2012-01-31] FF Extension: HDvid Codec 3 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc3@hdvidcodec.com [2013-08-09] FF Extension: No Name - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\staged [2014-06-08] FF Extension: Searchqu Toolbar - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} [2011-11-22] FF Extension: HDvid Codec 3 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc3@hdvidcodec.com.xpi [2013-06-30] FF Extension: HDvid Codec - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc@hdvc.com.xpi [2013-04-17] FF Extension: Yontoo - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\plugin@yontoo.com.xpi [2013-05-23] FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-11-02] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR StartupUrls: "hxxp://www.google.com/" CHR Plugin: (Shockwave Flash) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll (AVG Technologies) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Extension: (saavernett) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj [2014-06-08] CHR Extension: (Adblock for Youtube™) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2013-12-04] CHR Extension: (W3schools this!) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb [2014-05-18] CHR Extension: (HDvid Codec 3) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnllcmllkjofnojidnaknldfehfhehoo [2013-08-09] CHR Extension: (One Piece: Monkey D. Luffy (1366x768) Black) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebbcomiedmflgiplmdflpmkhkmkekcih [2013-07-20] CHR Extension: (AdBlock) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-12-04] CHR Extension: (Extensions new tab) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk [2014-06-20] CHR Extension: (Twitch Stream) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce [2014-07-06] CHR Extension: (Wikipedia search) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc [2014-06-08] CHR Extension: (Postcron) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed [2014-06-16] CHR Extension: (Plus-HD-2.2) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo [2013-07-20] CHR Extension: (HDvid Codec) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpkbnefaikfaeadgidhpoanckoiaheli [2013-07-20] CHR Extension: (Text Highlighter) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd [2014-05-18] CHR Extension: (AVG Security Toolbar) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2013-07-20] CHR Extension: (Google Wallet) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-18] CHR HKLM-x32\...\Chrome\Extension: [dnllcmllkjofnojidnaknldfehfhehoo] - C:\Program Files (x86)\HDvidCodec.com\HDvidCodec10.crx [2013-06-30] CHR HKLM-x32\...\Chrome\Extension: [kpkbnefaikfaeadgidhpoanckoiaheli] - C:\Program Files (x86)\HDvidCodec.com\HDvidCodec10.crx [2013-06-30] CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\18.1.0.443\avg.crx [2014-04-27] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-06-26] (BitRaider, LLC) R2 dfc86759; c:\ProgramData\Performancer\PerformancerSvc.dll [186192 2014-06-06] () [File not signed] R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [704112 2014-05-08] (Cherished Technololgy LIMITED) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) S3 OnlineStorageService; C:\Program Files\Trend Micro SafeSync\hrfscore.exe [7908664 2012-07-12] (Trend Micro Inc.) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-08-22] (Overwolf Ltd) S2 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [621632 2011-03-04] () R2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek) [File not signed] R2 vToolbarUpdater18.1.7; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe [1813528 2014-06-22] (AVG Secure Search) R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\wtgservice.exe [329168 2011-10-18] () S2 NewPlayer; C:\Program Files (x86)\NewPlayer\NewPlayerLwr161.exe [X] ==================== Drivers (Whitelisted) ==================== R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-06-22] (AVG Technologies) R3 DualCoreCenter; C:\Program Files (x86)\MSI\DualCoreCenter\NTGLM7X64.sys [44344 2010-02-08] (MICRO-STAR INT'L CO., LTD.) S3 GameKB; C:\Windows\System32\drivers\GameKB.sys [27648 2012-05-11] () [File not signed] S3 hwdatacard; C:\Windows\SysWOW64\DRIVERS\ewusbmdm.sys [115328 2008-07-24] (Huawei Technologies Co., Ltd.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) S3 MSIGreenPower; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\NTGLM7X64.sys [40248 2008-03-12] (MICRO-STAR INT'L CO., LTD.) [File not signed] S3 MSIGreenPowerRushTop; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushTop64.sys [74072 2008-04-23] (Your Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7369v290\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [File not signed] R3 NVR0Dev; C:\Windows\nvoclk64.sys [18216 2006-10-13] (NVidia Corp.) R3 RushTopDevice2; C:\Program Files (x86)\MSI\DualCoreCenter\RushTop64.sys [76088 2009-03-18] (Your Corporation) S3 RushTopDevice_J; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushJ64.sys [31544 2008-06-05] (Your Corporation) [File not signed] R1 {9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64; C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64.sys [60088 2014-05-16] (StdLib) S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S1 lhbjqqty; \??\C:\Windows\system32\drivers\lhbjqqty.sys [X] S3 MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [X] S1 neqnrghc; \??\C:\Windows\system32\drivers\neqnrghc.sys [X] S3 netr28ux; system32\DRIVERS\netr28ux.sys [X] S3 NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S1 rnigwgbp; \??\C:\Windows\system32\drivers\rnigwgbp.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-09 16:08 - 2014-07-09 16:09 - 00030116 _____ () C:\Users\Michi\Desktop\FRST.txt 2014-07-09 16:07 - 2014-07-09 16:08 - 00000000 ____D () C:\FRST 2014-07-09 16:05 - 2014-07-09 16:05 - 02084352 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe 2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip 2014-07-09 13:46 - 2014-06-07 06:02 - 17854464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-09 13:46 - 2014-06-07 04:59 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-09 13:46 - 2014-06-07 04:52 - 01348608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-09 13:46 - 2014-06-07 04:51 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-09 13:46 - 2014-06-07 04:51 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-09 13:46 - 2014-06-07 04:47 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-09 13:46 - 2014-06-07 04:45 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-07-09 13:46 - 2014-06-07 04:45 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-09 13:46 - 2014-06-07 04:45 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-09 13:46 - 2014-06-07 04:42 - 02148352 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-09 13:46 - 2014-06-07 04:42 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-09 13:46 - 2014-06-07 04:42 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-09 13:46 - 2014-06-07 04:42 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-09 13:46 - 2014-06-07 04:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-09 13:46 - 2014-06-07 04:41 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-07-09 13:46 - 2014-06-07 04:40 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-09 13:46 - 2014-06-07 04:39 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-07-09 13:46 - 2014-06-07 04:35 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-09 13:46 - 2014-06-07 02:05 - 12353024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-09 13:46 - 2014-06-07 01:12 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-09 13:46 - 2014-06-07 01:04 - 01106432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-09 13:46 - 2014-06-07 01:03 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-09 13:46 - 2014-06-07 01:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-09 13:46 - 2014-06-07 01:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-07-09 13:46 - 2014-06-07 00:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-07-09 13:46 - 2014-06-07 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-07-09 13:46 - 2014-06-07 00:54 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-09 13:46 - 2014-06-07 00:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-09 13:46 - 2014-06-07 00:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-07-09 13:46 - 2014-06-07 00:53 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-09 13:46 - 2014-06-07 00:52 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-09 13:46 - 2014-06-07 00:51 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-07-09 13:46 - 2014-06-07 00:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-07-09 13:45 - 2014-06-07 05:13 - 10890752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-09 13:45 - 2014-06-07 04:50 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-07-09 13:45 - 2014-06-07 04:41 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-07-09 13:45 - 2014-06-07 01:25 - 09711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-09 13:45 - 2014-06-07 00:58 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-09 13:45 - 2014-06-07 00:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-07-09 13:45 - 2014-06-07 00:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-09 13:45 - 2014-06-07 00:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-09 13:45 - 2014-06-07 00:53 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-07-09 13:44 - 2014-06-07 02:33 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-09 13:44 - 2014-06-06 10:59 - 00506880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-07-09 13:44 - 2014-06-06 09:13 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-09 13:44 - 2014-05-30 09:10 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-06 10:48 - 2014-07-06 10:48 - 00000000 ____D () C:\ProgramData\ProShopperu 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX 2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx 2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR 2014-06-26 15:21 - 2014-07-07 13:06 - 00000000 ____D () C:\ProgramData\BitRaider 2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider 2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk 2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA 2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk 2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment 2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk 2014-06-20 12:02 - 2014-06-20 12:03 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver 2014-06-20 10:16 - 2014-06-20 10:16 - 00000000 ____D () C:\ProgramData\CoupScuanner 2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk 2014-06-16 10:58 - 2014-06-16 10:57 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk 2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk 2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt 2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt 2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt 2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt 2014-06-15 11:44 - 2014-06-29 23:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks 2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe 2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe 2014-06-12 13:30 - 2014-04-26 20:21 - 00622592 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-12 13:30 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-06-12 13:30 - 2014-04-05 06:26 - 01417664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-12 13:30 - 2014-04-05 04:32 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2014-06-12 13:30 - 2014-03-10 08:26 - 01869824 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-12 13:30 - 2014-03-10 08:26 - 01794560 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-12 13:30 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2014-06-12 13:30 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll ==================== One Month Modified Files and Folders ======= 2014-07-09 16:09 - 2014-07-09 16:08 - 00030116 _____ () C:\Users\Michi\Desktop\FRST.txt 2014-07-09 16:08 - 2014-07-09 16:07 - 00000000 ____D () C:\FRST 2014-07-09 16:05 - 2014-07-09 16:05 - 02084352 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe 2014-07-09 16:03 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-09 16:03 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-09 15:57 - 2013-05-06 22:53 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-09 15:56 - 2013-08-09 21:56 - 00001212 _____ () C:\Windows\Tasks\HDvid Codec V1-updater.job 2014-07-09 15:56 - 2013-08-09 21:56 - 00001116 _____ () C:\Windows\Tasks\HDvid Codec V1-enabler.job 2014-07-09 15:55 - 2013-08-09 21:55 - 00001206 _____ () C:\Windows\Tasks\HDvid Codec V1-codedownloader.job 2014-07-09 14:17 - 2013-05-14 23:00 - 01578094 _____ () C:\Windows\WindowsUpdate.log 2014-07-09 14:06 - 2013-06-27 23:26 - 00001906 _____ () C:\Windows\Tasks\Plus-HD-2.2-chromeinstaller.job 2014-07-09 14:06 - 2013-06-27 23:26 - 00001830 _____ () C:\Windows\Tasks\Plus-HD-2.2-firefoxinstaller.job 2014-07-09 14:06 - 2013-06-27 23:26 - 00001194 _____ () C:\Windows\Tasks\Plus-HD-2.2-updater.job 2014-07-09 14:05 - 2013-06-27 23:26 - 00001198 _____ () C:\Windows\Tasks\Plus-HD-2.2-codedownloader.job 2014-07-09 14:05 - 2013-06-27 23:26 - 00001098 _____ () C:\Windows\Tasks\Plus-HD-2.2-enabler.job 2014-07-09 14:05 - 2013-05-06 22:53 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-09 14:03 - 2014-03-13 18:14 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-07-09 14:03 - 2006-11-02 17:40 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-09 14:03 - 2006-11-02 17:21 - 00255776 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-09 13:59 - 2006-11-02 17:40 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-09 13:59 - 2006-11-02 17:06 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-09 13:57 - 2013-07-22 05:26 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-09 13:54 - 2006-11-02 14:35 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip 2014-07-09 00:35 - 2012-08-16 08:22 - 00001692 _____ () C:\Users\Michi\Desktop\bla.txt 2014-07-07 13:06 - 2014-06-26 15:21 - 00000000 ____D () C:\ProgramData\BitRaider 2014-07-07 12:56 - 2011-10-18 16:41 - 00055560 _____ () C:\Users\Michi\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-07 12:54 - 2011-10-19 16:48 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-07-06 10:48 - 2014-07-06 10:48 - 00000000 ____D () C:\ProgramData\ProShopperu 2014-07-06 10:48 - 2014-06-08 19:55 - 00000000 ____D () C:\ProgramData\297d856b205d5963 2014-07-05 16:05 - 2011-11-22 11:56 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\vlc 2014-07-05 01:02 - 2012-02-02 03:37 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\TS3Client 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX 2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx 2014-07-04 17:09 - 2011-10-18 16:41 - 00000000 ____D () C:\Users\Michi 2014-07-03 14:42 - 2012-05-11 00:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Skype 2014-06-30 06:36 - 2011-10-20 02:44 - 00175616 _____ () C:\Users\Michi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-06-29 23:08 - 2014-06-15 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks 2014-06-27 11:36 - 2013-08-30 14:25 - 00000000 ____D () C:\Users\Michi\Desktop\TS Icons 2014-06-27 11:19 - 2012-02-02 03:35 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR 2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider 2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk 2014-06-26 14:06 - 2013-07-20 12:23 - 00014744 _____ () C:\Users\Michi\Documents\Install STAR WARS The Old Republic.log 2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-06-26 14:05 - 2014-05-18 13:49 - 00000000 _____ () C:\END 2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA 2014-06-23 08:33 - 2013-05-06 15:32 - 00001217 _____ () C:\Users\Michi\Desktop\WoW PWS.lnk 2014-06-22 19:39 - 2014-04-27 17:13 - 00000000 ____D () C:\ProgramData\AVG Secure Search 2014-06-22 19:39 - 2013-06-26 20:25 - 00050464 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2014-06-22 19:39 - 2013-06-26 20:25 - 00000000 ____D () C:\Program Files (x86)\AVG Secure Search 2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk 2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment 2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk 2014-06-20 12:03 - 2014-06-20 12:02 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver 2014-06-20 10:16 - 2014-06-20 10:16 - 00000000 ____D () C:\ProgramData\CoupScuanner 2014-06-17 17:56 - 2012-12-13 10:46 - 00000000 ____D () C:\Filme 2014-06-17 17:56 - 2012-08-25 14:45 - 00000000 ____D () C:\Users\Michi\Desktop\Wma 2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk 2014-06-16 11:00 - 2014-02-03 14:46 - 00155136 _____ () C:\Windows\SysWOW64\unrar.dll 2014-06-16 11:00 - 2014-02-03 14:46 - 00034308 _____ () C:\Windows\SysWOW64\bassmod.dll 2014-06-16 10:57 - 2014-06-16 10:58 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk 2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk 2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt 2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt 2014-06-16 07:18 - 2013-05-12 09:58 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-06-16 07:18 - 2012-01-27 19:49 - 00000000 ____D () C:\Games 2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt 2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt 2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe 2014-06-15 11:25 - 2013-05-12 18:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Wargaming.net 2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-09 14:08 ==================== End Of Log ============================ Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-07-2014 Ran by Michi at 2014-07-09 16:09:51 Running from C:\Users\Michi\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.8.800.175 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.7.700.224 - Adobe Systems Incorporated) Adobe Reader X (10.1.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated) aTube Catcher (HKLM-x32\...\aTube Catcher) (Version: 3.8.7955 - DsNET Corp) AVG Security Toolbar (HKLM-x32\...\AVG Secure Search) (Version: 18.1.7.644 - AVG Technologies) Bing Maps 3D (HKLM\...\{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}) (Version: 4.0.903.16005 - Microsoft Corporation) BitRaider Web Client (HKLM-x32\...\BitRaider Web Client) (Version: 1.1.9.9 - BitRaider, LLC) Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) CoupScuanner (HKLM-x32\...\{80E8B0A0-117D-1402-7CDE-688156237115}) (Version: - CCoupScAnneR) Drakonia Configurator (HKLM-x32\...\{A7B243AA-6D4C-4575-A873-6F01A1EFC5E2}}_is1) (Version: - ) DriverTuner 3.1.0.0 (HKLM-x32\...\{520C1D80-935C-42B9-9340-E883849D804F}_is1) (Version: 3.1.0.0 - LionSea SoftWare) DualCoreCenter (HKLM-x32\...\DualCoreCenter_is1) (Version: - MSI, Inc.) EasyViewer (HKLM-x32\...\InstallShield_{EECD7B96-1416-4D3A-B12D-0D2512120C36}) (Version: 1.3.0.9 - MSI) EasyViewer (x32 Version: 1.3.0.9 - MSI) Hidden ffdshow v1.2.4422 [2012-04-09] (HKLM-x32\...\ffdshow_is1) (Version: 1.2.4422.0 - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.137 - Google Inc.) Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.) Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden HDvid Codec V1 (HKLM-x32\...\HDvid Codec V1) (Version: 1.27.153.8 - installdaddy) <==== ATTENTION HDVidCodec (HKLM-x32\...\1ClickDownload) (Version: 2.1 Build 26473 - hdvidcodec.com) <==== ATTENTION iLivid (HKLM-x32\...\iLivid) (Version: 1.92.0.117387 - Bandoo Media Inc.) <==== ATTENTION iLivid (x32 Version: 1.92.0.117387 - Bandoo Media Inc.) Hidden <==== ATTENTION Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.550 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Notepad++ (HKLM-x32\...\Notepad++) (Version: 5.9.6 - ) NVIDIA 3D Vision Controller Driver (x32 Version: 280.19 - NVIDIA Corporation) Hidden NVIDIA 3D Vision Treiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 311.06 - NVIDIA Corporation) NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.12.5896 - NVIDIA Corporation) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation) NVIDIA GeForce Experience 1.8.2.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.2.1 - NVIDIA Corporation) NVIDIA Grafiktreiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.06 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) Hidden NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 311.06 (Version: 311.06 - NVIDIA Corporation) Hidden NVIDIA Update 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden NVIDIA Update Core (Version: 11.10.13 - NVIDIA Corporation) Hidden OpenOffice.org 3.4 (HKLM-x32\...\{4C552FD3-2CCD-4E00-AC64-0681DBB3F8B5}) (Version: 3.4.9590 - OpenOffice.org) Overwolf (HKLM-x32\...\{48615A7B-F026-4F62-A3F1-49001B8E21CB}) (Version: 0.44.256 - Overwolf) PDF24 Creator 5.6.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Performancer (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{dfc86759}) (Version: - 24soft) <==== ATTENTION Plus-HD-2.2 (HKLM-x32\...\Plus-HD-2.2) (Version: 1.27.153.6 - Plus HD) <==== ATTENTION ProShopperu (HKLM-x32\...\{8F213470-964F-4092-6B31-BC7570F31B5A}) (Version: - ProShopper) <==== ATTENTION Ralink RT2860 Wireless LAN Card (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.5.12.0 - Ralink) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 6.250.908.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6873 - Realtek Semiconductor Corp.) REALTEK Wireless LAN Driver and Utility (HKLM-x32\...\{9C049499-055C-4a0c-A916-1D8CA1FF45EB}) (Version: 1.00.0182 - REALTEK Semiconductor Corp.) saavernett (HKLM-x32\...\{614925F9-841A-53FE-A28F-DC30FA07239B}) (Version: - saveRnEt) Samsung_MonSetup (HKLM-x32\...\{8EA79DBF-D637-448A-89D6-410A087A4493}) (Version: 1.00.0000 - Samsung) Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.) Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version: 7.0.0.45 - Bioware/EA) Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.) System Requirements Lab (HKLM-x32\...\SystemRequirementsLab) (Version: - ) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH) Trend Micro SafeSync (HKLM\...\HFRS_is1) (Version: 5.1.0.1173 - Trend Micro) Ultimate Extras sounds from Microsoft® Tinker™ (HKLM\...\UltSounds2) (Version: - Microsoft Corporation) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation) Verbindungsassistent (HKLM-x32\...\Verbindungsassistent) (Version: 2.1 - Verbindungsassistent) VideoGenie (HKLM-x32\...\{FC54FD8D-789C-406D-BB88-F7C4421B7E83}_is1) (Version: 1.0.0.12 - MSI) Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies) Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies) VLC classic (HKLM-x32\...\VLC classic) (Version: 1.14 - vlcplayerdownload.com) W322U (HKLM-x32\...\{B64CEFD3-B6AB-40CD-8333-EDDBDB951751}) (Version: 1.00.0000 - Tenda) Winamp (HKLM-x32\...\Winamp) (Version: 5.621 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKCU\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Windows iLivid Toolbar (HKLM-x32\...\Windows Searchqu Toolbar) (Version: 3.0.0.117530 - Bandoo Media, Inc) <==== ATTENTION Windows-Soundschemas (HKLM\...\UltSounds) (Version: - Microsoft Corporation) WinRAR 4.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH) ==================== Restore Points ========================= 30-06-2014 13:35:10 Geplanter Prüfpunkt 02-07-2014 17:26:26 Geplanter Prüfpunkt 03-07-2014 14:40:32 Geplanter Prüfpunkt 04-07-2014 09:27:42 Windows Update 04-07-2014 15:07:27 Installiert SHARKOON Skiller 04-07-2014 15:08:55 Gerätetreiber-Paketinstallation: Sharkoon Eingabegeräte (Human Interface Devices) 05-07-2014 16:59:42 Geplanter Prüfpunkt 06-07-2014 18:15:02 Entfernt SHARKOON Skiller 07-07-2014 11:06:44 Windows Update 08-07-2014 00:05:18 Geplanter Prüfpunkt 08-07-2014 13:17:40 Geplanter Prüfpunkt 09-07-2014 11:53:30 Windows Update ==================== Hosts content: ========================== 2006-11-02 14:34 - 2006-09-18 23:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {00C5BFF5-EEAF-4637-93EA-ADF6229D3234} - System32\Tasks\Plus-HD-2.2-firefoxinstaller => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-firefoxinstaller.exe [2013-06-27] (Plus HD) <==== ATTENTION Task: {07B42F71-7E37-4EC3-8E83-4BE1FFE5C03D} - System32\Tasks\eType Setup => C:\Users\Michi\AppData\Local\Temp\eType Setup403431.exe <==== ATTENTION Task: {0871AFF5-575C-40FC-A05F-24E29DC1452B} - System32\Tasks\HDvid Codec V1-codedownloader => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-codedownloader.exe [2013-08-09] (installdaddy) <==== ATTENTION Task: {09D6CD90-BE85-4FF1-9D62-B51B87202CCF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-06] (Google Inc.) Task: {09EAFC8C-A951-41B9-8D2B-A1F18FBB21EC} - System32\Tasks\Plus-HD-2.2-chromeinstaller => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-chromeinstaller.exe [2013-06-27] (Plus HD) <==== ATTENTION Task: {0D36FC03-8888-410A-9037-DF358381DDF0} - System32\Tasks\HDvid Codec V1-updater => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-updater.exe [2013-08-09] (installdaddy) <==== ATTENTION Task: {27664485-6DD3-4E67-A392-23E241238E1D} - System32\Tasks\Plus-HD-2.2-codedownloader => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-codedownloader.exe [2013-06-27] (Plus HD) <==== ATTENTION Task: {27DC0BEB-20BB-4BAF-A4D6-C38628372658} - System32\Tasks\Plus-HD-2.2-enabler => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-enabler.exe [2013-06-27] (Plus HD) <==== ATTENTION Task: {3027772B-B827-4998-B62C-4E4C617B5DFA} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation) Task: {34F4AFBD-4B27-4161-BB74-EC0D1F6139BC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-06] (Google Inc.) Task: {720B96CE-CD10-4370-A0B1-73D2741DFC9D} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files (x86)\TuneUp Utilities 2010\OneClick.exe Task: {8E146441-DDF2-4E33-AEA7-A1CECCAEBA5B} - System32\Tasks\HDvid Codec V1-enabler => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-enabler.exe [2013-08-09] (installdaddy) <==== ATTENTION Task: {9475DD97-BB54-4FD8-A31A-032B4833F6AA} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {996457A5-8249-47C5-B620-CA695B7E6DA1} - System32\Tasks\WOT WFRI1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/ Task: {9A441CE9-6C4F-4991-954B-EDCB9256D04F} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => Rundll32.exe %windir%\system32\pla.dll,PlaConvertLogEntries Task: {AA105019-BFFB-4713-B627-81B47F4419F0} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages Task: {ADDB4957-FD21-4041-ADF2-C1DAF0991DA8} - System32\Tasks\Plus-HD-2.2-updater => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-updater.exe [2013-06-27] (Plus HD) <==== ATTENTION Task: {C0B38178-CA76-4475-90EB-B2F41221156B} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI Task: {C28278BF-1ABF-4595-BB2A-15201DDF25E3} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] () Task: {C41E9FD5-A5DB-4DEF-9715-E4F7BAFEE730} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation) Task: {E7D52131-C543-4A8D-8669-9FEC0C9AEE08} - System32\Tasks\{6E07F2B2-386B-4ABF-9A74-F6643ABA3D4E} => Chrome.exe Skype auf Ihren Computer herunterladen ? Mac, Windows, Linux*?*Skype Task: {F5B3AF16-E40C-4C45-B115-2698E999BB9F} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HDvid Codec V1-codedownloader.job => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\HDvid Codec V1-enabler.job => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-enabler.exe <==== ATTENTION Task: C:\Windows\Tasks\HDvid Codec V1-updater.job => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-updater.exe <==== ATTENTION Task: C:\Windows\Tasks\Plus-HD-2.2-chromeinstaller.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-chromeinstaller.exe <==== ATTENTION Task: C:\Windows\Tasks\Plus-HD-2.2-codedownloader.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\Plus-HD-2.2-enabler.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-enabler.exe <==== ATTENTION Task: C:\Windows\Tasks\Plus-HD-2.2-firefoxinstaller.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-firefoxinstaller.exe <==== ATTENTION Task: C:\Windows\Tasks\Plus-HD-2.2-updater.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-updater.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2014-06-06 09:51 - 2014-06-06 09:51 - 04302848 _____ () C:\ProgramData\Performancer\Performancer_x64.dll 2014-06-22 19:39 - 2014-06-22 19:39 - 00159768 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe 2011-10-18 16:53 - 2011-10-18 17:02 - 00329168 _____ () C:\Program Files (x86)\Verbindungsassistent\wtgservice.exe 2011-12-30 03:30 - 2011-05-28 23:05 - 00164864 _____ () C:\Program Files\WinRAR\rarext.dll 2011-07-18 23:04 - 2011-07-18 23:04 - 00301568 _____ () C:\Program Files (x86)\Notepad++\NppShell_04.dll 2013-06-26 20:25 - 2014-06-22 19:39 - 02571288 _____ () C:\Program Files (x86)\AVG Secure Search\vprot.exe 2013-06-29 11:36 - 2012-06-07 10:24 - 00246784 _____ () C:\Program Files (x86)\Drakonia Configurator\hid.exe 2013-06-29 11:36 - 2012-06-14 10:44 - 00240640 _____ () C:\Program Files (x86)\Drakonia Configurator\trayicon.exe 2013-05-08 09:35 - 2010-06-29 18:20 - 41382002 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\DualCoreCenter.exe 2014-06-06 09:51 - 2014-06-06 09:51 - 04129280 _____ () c:\ProgramData\Performancer\Performancer.dll 2014-06-06 09:51 - 2014-06-06 09:51 - 00186192 _____ () c:\ProgramData\Performancer\PerformancerSvc.dll 2014-06-22 19:39 - 2014-06-22 19:39 - 00519704 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\log4cplusU.dll 2013-06-29 11:36 - 2011-11-22 14:18 - 00061440 _____ () C:\Program Files (x86)\Drakonia Configurator\HidDevice.dll 2013-06-29 11:36 - 2011-11-22 14:18 - 00249856 _____ () C:\Program Files (x86)\Drakonia Configurator\language.dll 2013-10-08 02:19 - 2011-05-04 19:53 - 01058664 _____ () C:\Program Files (x86)\Ralink\Common\RaWLAPI.dll 2013-05-08 09:35 - 2009-03-17 16:36 - 00147456 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\RushTop.dll 2013-05-08 09:35 - 2007-01-05 11:59 - 00077824 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\CpuUsage.dll 2013-05-08 09:35 - 2008-09-08 15:02 - 00094208 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\VGADLL.dll 2014-05-18 12:42 - 2014-05-08 01:29 - 00065352 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\chrome_elf.dll 2014-05-18 12:42 - 2014-05-08 01:29 - 04081480 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\pdf.dll 2014-05-18 12:42 - 2014-05-08 01:29 - 00390472 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ppGoogleNaClPluginChrome.dll 2014-05-18 12:42 - 2014-05-08 01:29 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ffmpegsumo.dll 2014-05-18 12:42 - 2014-05-08 01:29 - 13695816 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:679ABA25 ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service" ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= ==================== Faulty Device Manager Devices ============= Name: Microsoft-ISATAP-Adapter #2 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-ISATAP-Adapter #3 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-ISATAP-Adapter #4 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-ISATAP-Adapter #5 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Microsoft-ISATAP-Adapter #6 Description: Microsoft-ISATAP-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: PolicyAgent4 Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4 Error: (07/09/2014 02:06:55 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: EmdCache4 Error: (07/09/2014 02:04:56 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: PolicyAgent4 Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: EmdCache4 Error: (07/09/2014 01:35:21 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: PolicyAgent4 Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4 Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: EmdCache4 System errors: ============= Error: (07/09/2014 02:05:53 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: 30000Realtek11nSU Error: (07/09/2014 02:04:57 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: 30000Ralink UPnP Media Server Error: (07/09/2014 02:02:23 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (07/09/2014 02:02:23 PM) (Source: Ntfs) (EventID: 137) (User: ) Description: Der Transaktionsressourcen-Manager auf Volume "F:" konnte aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (07/09/2014 02:02:19 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (07/09/2014 02:02:11 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (07/09/2014 02:02:07 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (07/09/2014 01:35:21 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: 30000Ralink UPnP Media Server Error: (07/09/2014 01:33:54 PM) (Source: disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (07/09/2014 01:33:54 PM) (Source: Ntfs) (EventID: 137) (User: ) Description: Der Transaktionsressourcen-Manager auf Volume "F:" konnte aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Microsoft Office Sessions: ========================= Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: PolicyAgent4 Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4 Error: (07/09/2014 02:06:55 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: EmdCache4 Error: (07/09/2014 02:04:56 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: PolicyAgent4 Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: EmdCache4 Error: (07/09/2014 01:35:21 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: PolicyAgent4 Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4 Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: ) Description: EmdCache4 CodeIntegrity Errors: =================================== Date: 2014-07-08 13:48:59.581 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-08 13:48:59.269 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-08 13:48:58.941 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-08 13:48:58.613 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-08 13:48:57.988 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-08 13:48:57.675 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-07 03:40:54.653 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-07 03:40:54.325 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-07 03:40:53.995 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-07-07 03:40:53.661 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 53% Total physical RAM: 4094.46 MB Available physical RAM: 1923.58 MB Total Pagefile: 8425.43 MB Available Pagefile: 5869.19 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:232.88 GB) (Free:36.72 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive e: (F) (Fixed) (Total:149.05 GB) (Free:38.31 GB) NTFS Drive f: () (Fixed) (Total:298.09 GB) (Free:98.98 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: A2DEA2DE) Partition 1: (Active) - (Size=233 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 8136E346) Partition 1: (Active) - (Size=298 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 149 GB) (Disk ID: 3FC1A37E) Partition 1: (Not Active) - (Size=149 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Hi, super das ging ja schnell das du dich meiner annimmst eben noch andere Themen von dir gelesen |
10.07.2014, 13:48 | #5 |
/// the machine /// TB-Ausbilder | Dauerhaftes Werbung öffnen macht Surfen fast unmöglich Adware & Co. deinstallieren
Solltest Du ein Programm nicht finden oder nicht deinstallieren können, mache bitte mit dem nächsten Schritt weiter: Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.07.2014, 17:02 | #6 |
| Dauerhaftes Werbung öffnen macht Surfen fast unmöglichCode:
ATTFilter ComboFix 14-07-08.04 - Michi 10.07.2014 17:45:19.1.2 - x64 Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.49.1031.18.4094.2263 [GMT 2:00] ausgeführt von:: c:\users\Michi\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F} SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\374311380 c:\programdata\CoupScuanner c:\programdata\CoupScuanner\pUyJz3N_N.dat c:\programdata\CoupScuanner\pUyJz3N_N.dll c:\programdata\CoupScuanner\pUyJz3N_N.exe c:\programdata\CoupScuanner\pUyJz3N_N.tlb c:\programdata\CoupScuanner\pUyJz3N_N.x64.dll c:\programdata\saavernett c:\programdata\saavernett\e.dat c:\programdata\saavernett\e.dll c:\programdata\saavernett\e.exe c:\programdata\saavernett\e.tlb c:\programdata\saavernett\e.x64.dll c:\users\Michi\4.0 c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_kfakeonomonapccoamcmdgpoaicnpnoo_0 c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_kfakeonomonapccoamcmdgpoaicnpnoo_0\27 c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_kfakeonomonapccoamcmdgpoaicnpnoo_0\28 c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj\1.3\background.html c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj\1.3\content.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj\1.3\lsdb.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj\1.3\manifest.json c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj\1.3\OCp.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk\221\background.html c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk\221\content.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk\221\lsdb.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk\221\manifest.json c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk\221\ubvQ4l5vHye.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce\154\background.html c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce\154\content.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce\154\idlITjgkPxk.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce\154\lsdb.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce\154\manifest.json c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc\135\background.html c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc\135\content.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc\135\DBgumc7XK.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc\135\lsdb.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc\135\manifest.json c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed\146\background.html c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed\146\content.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed\146\KTzl66zMp.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed\146\lsdb.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed\146\manifest.json c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\background.html c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\crossriderManifest.json c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\manifest.xml c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins.json c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\1_base.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\102_dealply_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\103_intext_5_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\104_jollywallet_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\105_corticas_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\119_similar_web_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\120_luck_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\123_intext_adv_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\13_CrossriderAppUtils.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\14_CrossriderUtils.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\155_ibario_pops_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\158_50onred_ads_only_no_fb_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\17_jQuery.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\177_crossriderDashboard.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\178_revizer_ws_dynamic_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\179_revizer_p_dynamic_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\180_bpo_serp_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\182_openUrl.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\183_tabsWrapper.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\184_noproblemppc_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\189_active_sanity.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\19_CHAppAPIWrapper.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\191_ciuvo_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\194_retargeting_bi_m.js.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\195_icm_convertmedia_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\21_debug.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\22_resources.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\28_initializer.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\4_jquery_1_7_1.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\47_resources_background.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\64_appApiMessage.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\7_hooks.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\72_appApiValidation.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\78_CrossriderInfo.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\80_CHPopupAppAPI.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\9_search_engine_hook.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\91_monetizationLoader.js.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\93_superfish_no_coupons_m.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\97_resourceApiWrapper.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\userCode\background.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\userCode\extension.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\icons\actions\1.png c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\icons\icon128.png c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\icons\icon16.png c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\icons\icon48.png c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\api\chrome.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\api\cookie.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\api\message.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\api\pageAction.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\api\pageActionBG.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\background.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\app_api.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\bg_app_api.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\consts.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\cookie_store.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\crossriderAPI.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\delegate.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\events.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\extensionDataStore.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\installer.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\logFile.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\logging.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\onBGDocumentLoad.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\popupResource\newPopup.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\popupResource\popup.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\reports.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\storageWrapper.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\updateManager.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\util.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\xhr.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\main.js c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\manifest.json c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\popup.html c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\version.json c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\000962.sst c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\000976.log c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\CURRENT c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\LOCK c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\LOG c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\LOG.old c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\MANIFEST-000974 c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bddaegpgigdnchenjnkebdfhiiiliggj_0.localstorage-journal c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bddaegpgigdnchenjnkebdfhiiiliggj_0.localstorage c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kfakeonomonapccoamcmdgpoaicnpnoo_0.localstorage-journal c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Preferences c:\users\Michi\AppData\Local\Temp\__tmp_2bbca911 c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome.manifest c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\asyncDB.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\background.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\browserAction.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\contextMenu.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\dbManager.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\dom_bg.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\fileManager.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\firefox.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\firefoxNotifications.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\firefoxOmnibox.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\message.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\request.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\tabs.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\webRequest.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\background.html c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\baseObject.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\browser.xul c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\console.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\consts.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\delegate.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\httpObserver.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\IDBWrapper.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\installer.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\pluginsManager.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\prefs.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\progressListenerObserver.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\registry.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\reloadObserver.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\reports.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\requestObject.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\searchSettings.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\uninstallObserver.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\updateManager.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\utils.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\xhr.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\dialog.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\extensionCode\backgroundCode.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\extensionCode\pageCode.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\main.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\options.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\options.xul c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\search_dialog.xul c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\defaults\preferences\prefs.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\install.rdf c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\locale\en-US\translations.dtd c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\button1.png c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\button2.png c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\button3.png c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\button4.png c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\button5.png c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\crossrider_statusbar.png c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\icon128.png c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\icon16.png c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\icon24.png c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\icon48.png c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\panelarrow-up.png c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\popup.html c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\skin.css c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\update.css c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\3u34e@hzpblpx.net\bootstrap.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\3u34e@hzpblpx.net\chrome.manifest c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\3u34e@hzpblpx.net\content\bg.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\3u34e@hzpblpx.net\install.rdf c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\hbbzzk@e-f.edu\bootstrap.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\hbbzzk@e-f.edu\chrome.manifest c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\hbbzzk@e-f.edu\content\bg.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\hbbzzk@e-f.edu\install.rdf c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\p26qgdb9@leftct.co.uk\bootstrap.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\p26qgdb9@leftct.co.uk\chrome.manifest c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\p26qgdb9@leftct.co.uk\content\bg.js c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\p26qgdb9@leftct.co.uk\install.rdf F:\install.exe . . ((((((((((((((((((((((( Dateien erstellt von 2014-06-10 bis 2014-07-10 )))))))))))))))))))))))))))))) . . 2014-07-10 15:53 . 2014-07-10 15:53 -------- d-----w- c:\users\hedev\AppData\Local\temp 2014-07-10 15:53 . 2014-07-10 15:53 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-07-10 15:25 . 2014-07-10 15:25 -------- d-----w- c:\program files (x86)\ProShopperu 2014-07-10 13:38 . 2014-07-10 13:38 -------- d-----w- c:\program files (x86)\VS Revo Group 2014-07-10 12:25 . 2014-07-10 12:25 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0440037D-239D-487B-8CB8-4B647E3AEC36}\offreg.dll 2014-07-10 12:15 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0440037D-239D-487B-8CB8-4B647E3AEC36}\mpengine.dll 2014-07-09 14:07 . 2014-07-09 14:10 -------- d-----w- C:\FRST 2014-07-09 12:15 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2014-07-09 11:45 . 2014-06-07 02:50 237056 ----a-w- c:\windows\system32\url.dll 2014-07-09 11:44 . 2014-06-07 01:41 1871872 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tipskins.dll 2014-07-09 11:44 . 2014-06-07 00:33 2777088 ----a-w- c:\windows\system32\win32k.sys 2014-07-09 11:44 . 2014-06-07 01:41 120832 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TipBand.dll 2014-07-09 11:44 . 2014-06-07 01:41 206336 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tabskb.dll 2014-07-09 11:44 . 2014-06-07 00:22 10240 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\TabTip32.exe 2014-07-09 11:44 . 2014-06-06 08:59 506880 ----a-w- c:\windows\SysWow64\qedit.dll 2014-07-09 11:44 . 2014-06-06 07:13 620032 ----a-w- c:\windows\system32\qedit.dll 2014-07-09 11:44 . 2014-05-30 07:10 404992 ----a-w- c:\windows\system32\drivers\afd.sys 2014-07-04 18:44 . 2014-07-04 18:44 1931296 ----a-w- c:\windows\CODEJO~2.OCX 2014-07-04 18:44 . 2014-07-04 18:44 1931296 ----a-w- c:\windows\Codejock.Controls.v15.3.1.ocx 2014-07-04 18:44 . 2014-07-04 18:44 136008 ----a-w- c:\windows\msinet.ocx 2014-07-04 09:33 . 2014-05-02 06:23 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{159D589E-ABD8-4EBC-A12A-A4C12597CC6D}\gapaengine.dll 2014-06-26 19:46 . 2014-06-26 19:46 -------- d-----w- c:\users\Michi\AppData\Local\SWTOR 2014-06-26 13:21 . 2014-07-07 11:06 -------- d-----w- c:\programdata\BitRaider 2014-06-26 12:05 . 2014-06-26 12:05 -------- d-----w- c:\program files (x86)\Electronic Arts 2014-06-20 10:02 . 2014-06-20 10:03 -------- d-----w- c:\program files (x86)\MonitorDriver 2014-06-12 11:30 . 2014-04-05 04:26 1417664 ----a-w- c:\windows\system32\drivers\tcpip.sys 2014-06-12 11:30 . 2014-04-05 02:32 40448 ----a-w- c:\windows\system32\drivers\tcpipreg.sys 2014-06-12 11:30 . 2014-04-26 18:21 622592 ----a-w- c:\windows\system32\usp10.dll 2014-06-12 11:30 . 2014-04-26 16:01 502784 ----a-w- c:\windows\SysWow64\usp10.dll 2014-06-12 11:30 . 2014-03-10 06:26 1794560 ----a-w- c:\windows\system32\msxml6.dll 2014-06-12 11:30 . 2014-03-10 06:26 1869824 ----a-w- c:\windows\system32\msxml3.dll 2014-06-12 11:30 . 2014-03-10 01:22 1401344 ----a-w- c:\windows\SysWow64\msxml6.dll 2014-06-12 11:30 . 2014-03-10 01:22 1248768 ----a-w- c:\windows\SysWow64\msxml3.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-07-09 11:54 . 2006-11-02 12:35 96441528 ----a-w- c:\windows\system32\mrt.exe 2014-06-22 17:39 . 2013-06-26 18:25 50464 ----a-w- c:\windows\system32\drivers\avgtpx64.sys 2014-06-16 09:00 . 2014-02-03 12:46 155136 ----a-w- c:\windows\SysWow64\unrar.dll 2014-05-16 16:34 . 2014-05-18 11:55 60088 ----a-w- c:\windows\system32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64.sys 2014-05-04 18:20 . 2014-05-04 18:20 1931296 ----a-w- c:\windows\SysWow64\Codejock.Controls.v15.3.1.ocx 2014-05-02 06:23 . 2013-07-18 07:39 1031560 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2014-04-25 12:49 . 2013-07-31 17:48 20312 ----a-w- c:\windows\system32\roboot64.exe 2014-04-14 18:13 . 2014-04-16 21:44 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoPaired] @="{A203F945-39E9-4286-AFA2-F3ADFCD5FAAA}" [HKEY_CLASSES_ROOT\CLSID\{A203F945-39E9-4286-AFA2-F3ADFCD5FAAA}] 2012-07-12 11:22 1186616 ----a-w- c:\program files\Trend Micro SafeSync\HrfsShellExtension32.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoPriority] @="{6F1BB626-1107-4b82-B322-54C5E64461B8}" [HKEY_CLASSES_ROOT\CLSID\{6F1BB626-1107-4b82-B322-54C5E64461B8}] 2012-07-12 11:22 1186616 ----a-w- c:\program files\Trend Micro SafeSync\HrfsShellExtension32.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoProblem] @="{7479C9AF-DA81-4944-92E5-23E49390BB2B}" [HKEY_CLASSES_ROOT\CLSID\{7479C9AF-DA81-4944-92E5-23E49390BB2B}] 2012-07-12 11:22 1186616 ----a-w- c:\program files\Trend Micro SafeSync\HrfsShellExtension32.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoSynced] @="{7479C9AF-DA81-4944-92E5-23E49390BB2A}" [HKEY_CLASSES_ROOT\CLSID\{7479C9AF-DA81-4944-92E5-23E49390BB2A}] 2012-07-12 11:22 1186616 ----a-w- c:\program files\Trend Micro SafeSync\HrfsShellExtension32.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoSyncing] @="{7479C9AF-DA81-4944-92E5-23E49390BB29}" [HKEY_CLASSES_ROOT\CLSID\{7479C9AF-DA81-4944-92E5-23E49390BB29}] 2012-07-12 11:22 1186616 ----a-w- c:\program files\Trend Micro SafeSync\HrfsShellExtension32.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoUnavailable] @="{66669544-5639-4922-99C8-CE7A86651364}" [HKEY_CLASSES_ROOT\CLSID\{66669544-5639-4922-99C8-CE7A86651364}] 2012-07-12 11:22 1186616 ----a-w- c:\program files\Trend Micro SafeSync\HrfsShellExtension32.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-07-11 74752] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] "DelReg"="c:\program files (x86)\MSI\DualCoreCenter\DelReg.exe" [2008-05-13 196608] "vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2014-06-22 2571288] "GamingMouse"="c:\program files (x86)\Drakonia Configurator\hid.exe" [2012-06-07 246784] "PDFPrint"="c:\program files (x86)\PDF24\pdf24.exe" [2013-06-10 162856] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "removeSearchqudatamngr"="RD" [X] "removeSearchqutoolbar"="RD" [X] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ DualCoreCenter.lnk - c:\program files (x86)\MSI\DualCoreCenter\StartUpDualCoreCenter.exe [2013-5-8 192512] Ralink Wireless Utility.lnk - c:\program files (x86)\Ralink\Common\RaUI.exe -s [2013-10-8 12909928] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" . --- Andere Dienste/Treiber im Speicher --- . *Deregistered* - NVR0Dev . HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs Themes . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-05-18 10:42 1077576 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.137\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-06 20:53] . 2014-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-06 20:53] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoPaired] @="{A203F945-39E9-4286-AFA2-F3ADFCD5FAAA}" [HKEY_CLASSES_ROOT\CLSID\{A203F945-39E9-4286-AFA2-F3ADFCD5FAAA}] 2012-07-12 11:23 1748280 ----a-w- c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoPriority] @="{6F1BB626-1107-4b82-B322-54C5E64461B8}" [HKEY_CLASSES_ROOT\CLSID\{6F1BB626-1107-4b82-B322-54C5E64461B8}] 2012-07-12 11:23 1748280 ----a-w- c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoProblem] @="{7479C9AF-DA81-4944-92E5-23E49390BB2B}" [HKEY_CLASSES_ROOT\CLSID\{7479C9AF-DA81-4944-92E5-23E49390BB2B}] 2012-07-12 11:23 1748280 ----a-w- c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoSynced] @="{7479C9AF-DA81-4944-92E5-23E49390BB2A}" [HKEY_CLASSES_ROOT\CLSID\{7479C9AF-DA81-4944-92E5-23E49390BB2A}] 2012-07-12 11:23 1748280 ----a-w- c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoSyncing] @="{7479C9AF-DA81-4944-92E5-23E49390BB29}" [HKEY_CLASSES_ROOT\CLSID\{7479C9AF-DA81-4944-92E5-23E49390BB29}] 2012-07-12 11:23 1748280 ----a-w- c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoUnavailable] @="{66669544-5639-4922-99C8-CE7A86651364}" [HKEY_CLASSES_ROOT\CLSID\{66669544-5639-4922-99C8-CE7A86651364}] 2012-07-12 11:23 1748280 ----a-w- c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WinSys2"="c:\windows\system32\startup.exe" [2008-01-30 52072] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-03-29 13513288] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072] "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-02-05 2234144] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mStart Page = about:blank mDefault_Page_URL = about:blank mDefault_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms} mSearch Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms} mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.2.1 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll . - - - - Entfernte verwaiste Registrierungseinträge - - - - . URLSearchHooks-{D8278076-BC68-4484-9233-6E7F1628B56C} - (no file) BHO-{99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~2\WI371A~1\Datamngr\ToolBar\searchqudtx.dll BHO-{9D717F81-9148-4f12-8568-69135F087DB0} - c:\progra~2\WI371A~1\Datamngr\BROWSE~1.DLL BHO-{EE8576D7-0A5F-FD10-841C-3FF359D97D4E} - c:\programdata\CoupScuanner\pUyJz3N_N.dll BHO-{FB5E2C20-9D02-6288-3506-3C27D46DC1B2} - c:\programdata\saavernett\e.dll Toolbar-{99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~2\WI371A~1\Datamngr\ToolBar\searchqudtx.dll Toolbar-10 - (no file) Toolbar-!{82E1477C-B154-48D3-9891-33D83C26BCD3} - (no file) Toolbar-!{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file) Wow6432Node-HKLM-Run-fst_de_16 - (no file) Wow6432Node-HKLM-Run-t4pc_en_3 - (no file) SafeBoot-WudfPf SafeBoot-WudfRd BHO-{9D717F81-9148-4f12-8568-69135F087DB0} - c:\progra~2\WI371A~1\Datamngr\x64\BROWSE~1.DLL BHO-{EE8576D7-0A5F-FD10-841C-3FF359D97D4E} - c:\programdata\CoupScuanner\pUyJz3N_N.x64.dll BHO-{FB5E2C20-9D02-6288-3506-3C27D46DC1B2} - c:\programdata\saavernett\e.x64.dll Toolbar-10 - (no file) Toolbar-!{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file) AddRemove-{614925F9-841A-53FE-A28F-DC30FA07239B} - c:\programdata\saavernett\e.exe AddRemove-{80E8B0A0-117D-1402-7CDE-688156237115} - c:\programdata\CoupScuanner\pUyJz3N_N.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes] "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Zeit der Fertigstellung: 2014-07-10 17:56:42 ComboFix-quarantined-files.txt 2014-07-10 15:56 . Vor Suchlauf: 16 Verzeichnis(se), 46.926.602.240 Bytes frei Nach Suchlauf: 20 Verzeichnis(se), 46.855.999.488 Bytes frei . - - End Of File - - 7D978701524027D4F03507464F71E6BE 5C616939100B85E558DA92B899A0FC36 |
11.07.2014, 11:14 | #7 |
/// the machine /// TB-Ausbilder | Dauerhaftes Werbung öffnen macht Surfen fast unmöglich Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.07.2014, 13:28 | #8 |
| Dauerhaftes Werbung öffnen macht Surfen fast unmöglichCode:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 11.07.2014 Suchlauf-Zeit: 13:20:40 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.07.11.04 Rootkit Datenbank: v2014.07.09.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Self-protection: Deaktiviert Betriebssystem: Windows Vista Service Pack 2 CPU: x64 Dateisystem: NTFS Benutzer: Michi Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 303003 Verstrichene Zeit: 11 Min, 29 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 1 PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 1832, Löschen bei Neustart, [f848b9e53942201664eadd809d64758b] Module: 0 (No malicious items detected) Registrierungsschlüssel: 47 PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, In Quarantäne, [f848b9e53942201664eadd809d64758b], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [29173d617dfe49ede4002069857d47b9], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [29173d617dfe49ede4002069857d47b9], PUP.Optional.WebCake.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{7169BBB3-3289-4696-B35D-4A88BCF6FB12}, In Quarantäne, [fc44efafaad189ade4028cfd17ebac54], PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}, In Quarantäne, [d16f3a64fb802a0cf8cd24668b77b14f], PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\SearchQUIEHelper.DNSGuard, In Quarantäne, [d16f3a64fb802a0cf8cd24668b77b14f], PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\SearchQUIEHelper.DNSGuard.1, In Quarantäne, [d16f3a64fb802a0cf8cd24668b77b14f], PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SearchQUIEHelper.DNSGuard, In Quarantäne, [d16f3a64fb802a0cf8cd24668b77b14f], PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SearchQUIEHelper.DNSGuard.1, In Quarantäne, [d16f3a64fb802a0cf8cd24668b77b14f], PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}, In Quarantäne, [d16f3a64fb802a0cf8cd24668b77b14f], PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}, In Quarantäne, [4ef2c0de9ae1a39390366d1d1ee48f71], PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}, In Quarantäne, [4ef2c0de9ae1a39390366d1d1ee48f71], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc.1, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.mysearchdialESrvc, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.mysearchdialESrvc.1, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}, In Quarantäne, [dd637a24f883979ffb4cc59246bca35d], PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{99079A25-328F-4BD4-BE04-00955ACAA0A7}, In Quarantäne, [dd637a24f883979ffb4cc59246bca35d], PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{99079A25-328F-4BD4-BE04-00955ACAA0A7}, In Quarantäne, [dd637a24f883979ffb4cc59246bca35d], PUP.Optional.Bandoo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9D717F81-9148-4f12-8568-69135F087DB0}, In Quarantäne, [f54b811d1b60a09669a0a1e94db5b14f], PUP.Optional.Bandoo.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{9D717F81-9148-4F12-8568-69135F087DB0}, In Quarantäne, [f54b811d1b60a09669a0a1e94db5b14f], PUP.Optional.Babylon.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, In Quarantäne, [56eaafefc1ba0c2aaec240108e742ad6], PUP.Optional.MySearchDial.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, In Quarantäne, [e55baef0e497ce68752be8685aa82dd3], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, In Quarantäne, [e55baef0e497ce68752be8685aa82dd3], PUP.Optional.Delta.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, In Quarantäne, [19277e208eed0c2a16cebcccb84a39c7], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [0c34fda14635b581b34581d3cf337c84], Adware.EoRezo, HKLM\SOFTWARE\WOW6432NODE\FreeSoftToday, In Quarantäne, [122e0797304bab8b54ef98637a89cf31], PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [3b057925394265d138ade920679d7d83], PUP.Optional.HDVidCodec.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\dnllcmllkjofnojidnaknldfehfhehoo, In Quarantäne, [bf81138b80fbcc6a41ebd62028db59a7], PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM, In Quarantäne, [0d33217dbac151e571c0f3039b6806fa], PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, In Quarantäne, [69d7d6c836452313a8eac7f2ba48eb15], PUP.Optional.NewPlayer.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NEWPLAYER, In Quarantäne, [81bf5c421863f6403d78487c1ae8df21], PUP.Optional.Feven.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Fpro_1.2, In Quarantäne, [ac94e5b90675fb3bd03612b339c9ac54], PUP.Optional.MPlayerplus.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\MPlayerplus_01, In Quarantäne, [d769e7b784f7fe384fc57b4a3ec4ee12], PUP.Optional.PlusHD.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-2.2, In Quarantäne, [1c242c721d5e5fd74b344c86986a8779], PUP.Optional.InstallCore.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [340c6e30a9d2a393211ccc139e64916f], PUP.Optional.InstallCore.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [45fbf5a999e2251147fe995c38cbe917], PUP.Optional.CrossRider.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\installdaddy, In Quarantäne, [3f01910df28949ed121c12e407fce11f], PUP.Optional.PlusHD.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Plus HD, In Quarantäne, [46fa0a946e0dc96d2d53834f52b05da3], PUP.Optional.BProtector.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, In Quarantäne, [49f747577cffce6842346395fb08f907], PUP.Optional.Softonic.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [310fd1cded8e6cca230e4b83e31fa65a], PUP.Optional.SweetIM.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, In Quarantäne, [f34d88165c1f75c11719ce282ad912ee], PUP.Optional.SystemSpeedup, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\ssd, In Quarantäne, [75cb3b639cdf73c34f42c6f3cc3603fd], Registrierungswerte: 7 PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{99079A25-328F-4BD4-BE04-00955ACAA0A7}, Searchqu Toolbar, In Quarantäne, [dd637a24f883979ffb4cc59246bca35d] PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{99079a25-328f-4bd4-be04-00955acaa0a7}, In Quarantäne, [023e8e10e7940531c87f7cdb5fa38c74], PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM|simapp_id, {8F553BE8-012D-11E3-BC1C-00218508A415}, In Quarantäne, [0d33217dbac151e571c0f3039b6806fa] PUP.Optional.NewPlayer.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NEWPLAYER|ImagePath, C:\Program Files (x86)\NewPlayer\NewPlayerLwr161.exe, In Quarantäne, [81bf5c421863f6403d78487c1ae8df21] PUP.Optional.InstallCore.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0V1D1S1R1D0V1O, In Quarantäne, [45fbf5a999e2251147fe995c38cbe917] PUP.BProtector, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, hxxp://search.babylon.com/?babsrc=HP_ss_gin2g&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926, In Quarantäne, [ad93b0eee09b2511ed36eb0a17ec3fc1] PUP.Optional.SweetIM.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, {8F553BE8-012D-11E3-BC1C-00218508A415}, In Quarantäne, [f34d88165c1f75c11719ce282ad912ee] Registrierungsdaten: 2 PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}),Ersetzt,[c27e6a34304b2c0ad36716862cd857a9] PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}),Ersetzt,[8ab6485697e467cfc850dbb617ed9e62] Ordner: 23 PUP.Optional.FileScout.A, C:\Users\Michi\AppData\Roaming\File Scout, In Quarantäne, [d0704757215a0135ce5ba1fc9270ae52], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com, Löschen bei Neustart, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\components, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content, Löschen bei Neustart, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs, Löschen bei Neustart, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\defaults, Löschen bei Neustart, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\defaults\preferences, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Datamngr.A, C:\Users\Michi\AppData\LocalLow\DataMngr, In Quarantäne, [37098b130d6e191d25650e95a26041bf], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb, Löschen bei Neustart, [fa46d9c5324937ffcf4e1e8616ec3fc1], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb\0.1_0, In Quarantäne, [fa46d9c5324937ffcf4e1e8616ec3fc1], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd, Löschen bei Neustart, [de6206987cfff244bf5fe0c455ad629e], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\0.1_0, In Quarantäne, [de6206987cfff244bf5fe0c455ad629e], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\LocalLow\BabylonToolbar, Löschen bei Neustart, [3907c3db8cef40f6e4168727ae5424dc], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\LocalLow\BabylonToolbar\BabylonToolbar, In Quarantäne, [3907c3db8cef40f6e4168727ae5424dc], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchquband, In Quarantäne, [b987504e7ffc2a0c60bc595655adc53b], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar, Löschen bei Neustart, [043c633b760542f4ec314d6206fce31d], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\weather, In Quarantäne, [043c633b760542f4ec314d6206fce31d], PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, Löschen bei Neustart, [75cb8d11ccaf4fe7b93c2989689a30d0], PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [75cb8d11ccaf4fe7b93c2989689a30d0], PUP.Optional.SearchProtect.A, C:\Users\Michi\AppData\Local\SearchProtect, Löschen bei Neustart, [162a6f2f6219d75fbf37625003ff7090], PUP.Optional.SearchProtect.A, C:\Users\Michi\AppData\Local\SearchProtect\Logs, In Quarantäne, [162a6f2f6219d75fbf37625003ff7090], PUP.Optional.SystemSpeedup, C:\Users\Michi\AppData\Roaming\Systweak\ssd, In Quarantäne, [5de38618a2d9ff3722eaeec822e06f91], Dateien: 159 PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, Löschen bei Neustart, [f848b9e53942201664eadd809d64758b], PUP.Optional.Skytech.A, C:\Users\Michi\AppData\Roaming\sweet-page\UninstallManager.exe, In Quarantäne, [fd43633b2655cf6754314745669bbd43], PUP.Optional.InstallCore, C:\Users\Michi\Downloads\google_chrome_de.exe, In Quarantäne, [1a262a745427a1953e7aa6e0c3413dc3], PUP.Optional.BrowserDefender.A, C:\Windows\System32\Tasks\BrowserDefendert, In Quarantäne, [e45c534b8cef0a2c7babdce0ff03847c], PUP.Optional.Yontoo.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\plugin@yontoo.com.xpi, In Quarantäne, [af918e10017a72c435208b322ad8cd33], PUP.Optional.Ciuvo.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage, In Quarantäne, [d16f2c726b10a294e425caf60ef42dd3], PUP.Optional.Ciuvo.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage-journal, In Quarantäne, [60e0207ee09b5cda59b0863afb07a35d], PUP.Optional.LiveLyrics.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.livelyrics00.live-lyrics.com_0.localstorage, In Quarantäne, [79c70e906f0c6acc8e77626521e13fc1], PUP.Optional.LiveLyrics.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.livelyrics00.live-lyrics.com_0.localstorage-journal, In Quarantäne, [ab95702e3e3da88e4db8dee9d72b40c0], PUP.Optional.Superfish.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, In Quarantäne, [8cb42a74681368ce689ee1e61ae84bb5], PUP.Optional.Superfish.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, In Quarantäne, [0739336b39421620e52153747989e020], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\babylon.xml, In Quarantäne, [b38dcfcf0279082edd745d77a161e61a], PUP.Optional.BProtector.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\bProtector_extensions.sqlite, In Quarantäne, [56ea742aa2d9082e510c488c8a78d62a], PUP.Optional.BProtector.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\bProtector_prefs.js, In Quarantäne, [a69a306ef5869f973628696b7092c838], PUP.Optional.Delta.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\delta.xml, In Quarantäne, [6dd3415d1c5f68ce4b39686c5aa88878], PUP.Optional.HDVidCodec.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\hdvc3@hdvidcodec.com.xpi, In Quarantäne, [0838247a215afe386e3fc014986aca36], PUP.Optional.Babylon.A, C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml, In Quarantäne, [2f1145595c1f65d12c4c2eabf80a32ce], PUP.Optional.Searchqu.A, C:\Users\Michi\AppData\Roaming\Mozilla\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}, In Quarantäne, [f54b2678d6a55bdb5f53896cc53ef40c], PUP.Optional.BProtector.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data, In Quarantäne, [d8688519205b8babcea9a45421e238c8], PUP.Optional.BProtector.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences, In Quarantäne, [87b9d5c9c7b42f070474e90f02011be5], PUP.Optional.MySpeedDial.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pflphaooapbgpeakohlggbpidpppgdff_0.localstorage, In Quarantäne, [dc64336b4a314fe7396043cecf3512ee], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\chrome.manifest, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\install.rdf, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\components\acplus-autocomplete.js, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\babylon.css, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\babylon.xul, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\mtstart.js, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\server.js, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\tmplt.js, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\arwDwn.gif, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\bbyln.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\help_16.gif, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\home.gif, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\logo.PNG, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\privecy_16_hot.gif, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\tellafriend.gif, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\vssver.scc, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ae.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\bg.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ch.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cn.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cz.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\de.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\eg.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\en.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\es.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\fr.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\gr.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\he.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\il.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\it.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ja.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\jp.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\nl.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\no.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pl.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pt.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ro.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ru.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sa.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\se.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sv.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\Thumbs.db, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\tr.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ua.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\us.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\defaults\preferences\babylon.js, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\defaults\preferences\dflt.js, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\defaults\preferences\instlPref.js, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], PUP.Optional.Datamngr.A, C:\Users\Michi\AppData\LocalLow\DataMngr\{7CA1F051-A4FB-4143-B263-02B41E571EED}, In Quarantäne, [37098b130d6e191d25650e95a26041bf], PUP.Optional.Datamngr.A, C:\Users\Michi\AppData\LocalLow\DataMngr\{7CA1F051-A4FB-4143-B263-02B41E571EED}64, In Quarantäne, [37098b130d6e191d25650e95a26041bf], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb\0.1_0\background.js, In Quarantäne, [fa46d9c5324937ffcf4e1e8616ec3fc1], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb\0.1_0\icon-128.png, In Quarantäne, [fa46d9c5324937ffcf4e1e8616ec3fc1], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb\0.1_0\icon-16.png, In Quarantäne, [fa46d9c5324937ffcf4e1e8616ec3fc1], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb\0.1_0\icon-48.png, In Quarantäne, [fa46d9c5324937ffcf4e1e8616ec3fc1], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb\0.1_0\manifest.json, In Quarantäne, [fa46d9c5324937ffcf4e1e8616ec3fc1], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb\0.1_0\script.js, In Quarantäne, [fa46d9c5324937ffcf4e1e8616ec3fc1], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\0.1_0\background.js, In Quarantäne, [de6206987cfff244bf5fe0c455ad629e], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\0.1_0\icon-128.png, In Quarantäne, [de6206987cfff244bf5fe0c455ad629e], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\0.1_0\icon-16.png, In Quarantäne, [de6206987cfff244bf5fe0c455ad629e], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\0.1_0\icon-48.png, In Quarantäne, [de6206987cfff244bf5fe0c455ad629e], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\0.1_0\manifest.json, In Quarantäne, [de6206987cfff244bf5fe0c455ad629e], PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\0.1_0\script.js, In Quarantäne, [de6206987cfff244bf5fe0c455ad629e], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\dtx.ini, In Quarantäne, [043c633b760542f4ec314d6206fce31d], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\geodata.xml, In Quarantäne, [043c633b760542f4ec314d6206fce31d], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\geoip.xml, In Quarantäne, [043c633b760542f4ec314d6206fce31d], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\guid.dat, In Quarantäne, [043c633b760542f4ec314d6206fce31d], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\log.txt, In Quarantäne, [043c633b760542f4ec314d6206fce31d], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\preferences.dat, In Quarantäne, [043c633b760542f4ec314d6206fce31d], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\stats.dat, In Quarantäne, [043c633b760542f4ec314d6206fce31d], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\uninstallIE.dat, In Quarantäne, [043c633b760542f4ec314d6206fce31d], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\version.xml, In Quarantäne, [043c633b760542f4ec314d6206fce31d], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\weatherbutton_prefs.xml, In Quarantäne, [043c633b760542f4ec314d6206fce31d], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\weather\7e66f0f9544a85ed2e152a7b26998de4, In Quarantäne, [043c633b760542f4ec314d6206fce31d], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\weather\c6249801542ff6b529bec9bbf3b3eda5, In Quarantäne, [043c633b760542f4ec314d6206fce31d], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\weather\forecasts_cache.xml, In Quarantäne, [043c633b760542f4ec314d6206fce31d], PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\weather\observations_cache.xml, In Quarantäne, [043c633b760542f4ec314d6206fce31d], PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, In Quarantäne, [75cb8d11ccaf4fe7b93c2989689a30d0], PUP.Optional.SystemSpeedup, C:\Users\Michi\AppData\Roaming\Systweak\ssd\SSDPTstub.exe, In Quarantäne, [5de38618a2d9ff3722eaeec822e06f91], PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.admin", false);), Ersetzt,[6dd38e10a0db3cfab80c7a50b054fb05] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.aflt", "babsst");), Ersetzt,[f34dfca2df9c2115fbc95971e0246f91] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.babExt", "");), Ersetzt,[ba86019d1467c076f9cbd0fa29db8080] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.babTrack", "affID=17350");), Ersetzt,[de6237679be0b284c9fb0dbd857ff60a] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.bbDpng", 29);), Ersetzt,[5de38f0f473478be725228a2669e56aa] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.dfltLng", "en");), Ersetzt,[55eb9b03f48744f21aaaf5d53acafb05] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.dfltSrch", true);), Ersetzt,[122ef7a7b0cb62d45f652c9e9b69bb45] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.hmpg", true);), Ersetzt,[2818c0de6d0e70c601c3e1e97a8ab848] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.id", "547436af000000000000000000000000");), Ersetzt,[2818910dcbb09c9a8044606a8084e11f] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.instlDay", "15370");), Ersetzt,[67d91a842d4e2016566e646607fd41bf] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.instlRef", "sst");), Ersetzt,[d36d425c582358decdf7dcee4cb832ce] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.keyWordUrl", "hxxp://search.babylon.com/?AF=17350&babsrc=adbartrp&mntrId=547436af000000000000000000000000&q=");), Ersetzt,[7bc5138b0774c076655f26a47f855ba5] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.lastDP", 29);), Ersetzt,[96aa36686a1141f5487c6c5eb64ec53b] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.171:40:12");), Ersetzt,[dc64227ca3d862d4774dd9f1b74d20e0] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "7.0");), Ersetzt,[7ec22876057653e3d4f0bd0de71d7f81] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.newTab", true);), Ersetzt,[231dc1ddbcbf2115daeac7034eb6fa06] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_bb");), Ersetzt,[00400a9481fa5ed818ac01c930d41be5] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.noFFXTlbr", false);), Ersetzt,[67d96935d2a93ff76d5741891de7be42] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");), Ersetzt,[99a7aef0e09b3204cbf908c2db29a060] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.propectorlck", 108390239);), Ersetzt,[310f148a87f45dd91ba9b515e81cbd43] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.prtnrId", "babylon");), Ersetzt,[350b3f5f4c2f39fd1aaaf9d1fb09b64a] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.ptch_0717", true);), Ersetzt,[8ab6415da1dabb7b665e06c4e61e49b7] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.smplGrp", "azb");), Ersetzt,[08383f5f4932ee48c2024b7f7c88d030] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.srcExt", "ss");), Ersetzt,[e55b5648b3c847ef368eb01ac1438f71] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.tlbrId", "base");), Ersetzt,[d46c504ed5a6f2448f35903a897b17e9] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.vrsn", "1.5.3.17");), Ersetzt,[9ba51a841c5f84b26460973302028080] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.vrsni", "1.5.3.17");), Ersetzt,[c779d8c6ef8cd1658341be0cd92b7090] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.171:40:12");), Ersetzt,[c779bde15f1c3afc9b293e8c46be3bc5] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.aflt", "babsst");), Ersetzt,[bb85a7f70c6f45f19e26cefc6c987c84] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babExt", "");), Ersetzt,[a89826785e1d47eff0d481498d77fd03] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babTrack", "affID=17350");), Ersetzt,[1c248d117902171ffcc87852ac58e020] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.hardId", "547436af000000000000000000000000");), Ersetzt,[86ba0599037883b30eb66f5bf80c2ed2] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.id", "547436af000000000000000000000000");), Ersetzt,[f0505c4298e3c274a4206b5fda2a4fb1] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.instlDay", "15370");), Ersetzt,[9ca4d5c990ebc472af157159966e4db3] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.instlRef", "sst");), Ersetzt,[9da3b6e88af1f83e11b37e4cba4a8d73] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.newTab", false);), Ersetzt,[7fc10995265572c44c78aa20a85c12ee] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");), Ersetzt,[2818a8f6304bac8a2a9ab317fe06ef11] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");), Ersetzt,[d36dacf2aad11521f6ce4486ed17a957] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.smplGrp", "none");), Ersetzt,[be82633b0378a29401c3be0c699b09f7] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.srcExt", "ss");), Ersetzt,[9ba55648a8d35cda4d77a723828247b9] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.tlbrId", "base");), Ersetzt,[8fb15747b6c5ea4ca3219733020216ea] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");), Ersetzt,[54ec5d414f2c77bf4c7835950004eb15] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");), Ersetzt,[f749afeff388d165992b7e4ce91b20e0] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.171:40:12");), Ersetzt,[eb556c3247349c9aaf15bc0e16ee5ca4] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.id", "547436af000000000000000000000000");), Ersetzt,[37092f6f1b6086b060e64684e81ca45c] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.hardId", "547436af000000000000000000000000");), Ersetzt,[1c244c5247348da98eb8fad0b252cd33] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.instlDay", "15370");), Ersetzt,[b48c2d7183f882b46bdbefdb6b99cd33] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");), Ersetzt,[1c24386624577abcc18538927d87a45c] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");), Ersetzt,[9fa19e00b2c9c0769da9af1bf3118e72] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.171:40:12");), Ersetzt,[df61d5c9bebdb680b096c6042adab44c] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");), Ersetzt,[82be3f5f92e995a1093d6763e51f53ad] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");), Ersetzt,[69d7722c205bec4acb7b6c5e61a3b44c] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.aflt", "babsst");), Ersetzt,[7ec2930b592269cd192d5a70e51f867a] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.smplGrp", "none");), Ersetzt,[231d5747592287af1c2a31998d776c94] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.tlbrId", "base");), Ersetzt,[350ba0fe86f543f3370fc109d430b848] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.newTab", false);), Ersetzt,[1729f5a9522995a196b05476956f36ca] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babTrack", "affID=17350");), Ersetzt,[2e129d0194e7de58b98d606aa75d629e] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babExt", "");), Ersetzt,[40001f7f7ffcd95d51f59f2b010351af] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.srcExt", "ss");), Ersetzt,[98a8227cf586eb4b7ec85b6f09fb53ad] PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.instlRef", "sst");), Ersetzt,[99a7abf3037804320442c3072cd808f8] Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.215 - Bericht erstellt am 11/07/2014 um 13:52:28 # Aktualisiert 09/07/2014 von Xplode # Betriebssystem : Windows (TM) Vista Ultimate Service Pack 2 (64 bits) # Benutzername : Michi - MICHI-PC # Gestartet von : C:\Users\Michi\Desktop\adwcleaner_3.215.exe # Option : Löschen ***** [ Dienste ] ***** Dienst Gelöscht : vToolbarUpdater18.1.7 ***** [ Dateien / Ordner ] ***** [!] Ordner Gelöscht : C:\ProgramData\apn [!] Ordner Gelöscht : C:\ProgramData\Ask [!] Ordner Gelöscht : C:\ProgramData\AVG Secure Search [!] Ordner Gelöscht : C:\ProgramData\Babylon [!] Ordner Gelöscht : C:\ProgramData\IBUpdaterService [!] Ordner Gelöscht : C:\ProgramData\Tarma Installer [!] Ordner Gelöscht : C:\ProgramData\WPM [!] Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue [!] Ordner Gelöscht : C:\Program Files (x86)\AVG Secure Search [!] Ordner Gelöscht : C:\Program Files (x86)\globalUpdate [!] Ordner Gelöscht : C:\Program Files (x86)\predm [!] Ordner Gelöscht : C:\Program Files (x86)\SupTab [!] Ordner Gelöscht : C:\Program Files (x86)\webget [!] Ordner Gelöscht : C:\Program Files (x86)\WinZip Registry Optimizer [!] Ordner Gelöscht : C:\Program Files (x86)\Common Files\AVG Secure Search [!] Ordner Gelöscht : C:\Users\Michi\AppData\Local\AVG Secure Search [!] Ordner Gelöscht : C:\Users\Michi\AppData\Local\globalUpdate [!] Ordner Gelöscht : C:\Users\Michi\AppData\Local\Ilivid Player [!] Ordner Gelöscht : C:\Users\Michi\AppData\Local\PackageAware [!] Ordner Gelöscht : C:\Users\Michi\AppData\LocalLow\AVG Secure Search [!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Activeris [!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Babylon [!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Nico Mak Computing [!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\sweet-page [!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Systweak [!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Uniblue [!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard [!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HDvidCodec.com [!] Ordner Gelöscht : C:\Users\Michi\Documents\Optimizer Pro [!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Searchqutoolbar [!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\{99079A25-328F-4BD4-BE04-00955ACAA0A7} [!] Ordner Gelöscht : C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433} Datei Gelöscht : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc@hdvc.com.xpi Datei Gelöscht : C:\END Datei Gelöscht : C:\Windows\System32\roboot64.exe Datei Gelöscht : C:\Users\Michi\AppData\Roaming\aps.uninstall.scan.results Datei Gelöscht : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\Askcom.xml Datei Gelöscht : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\ask-search.xml Datei Gelöscht : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\Search_Results.xml Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Search_Results.xml Datei Gelöscht : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js Datei Gelöscht : C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.softonic.de_0.localstorage Datei Gelöscht : C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.softonic.de_0.localstorage-journal ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\kpkbnefaikfaeadgidhpoanckoiaheli Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\babylon.com Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\*\shell\filescout Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\DNSBHO.dll Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DnsBHO.BHO Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DnsBHO.BHO.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt] Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CCoupScAnneR.CCoupScAnneR Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CCoupScAnneR.CCoupScAnneR.3.2 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\saveRnEt.saveRnEt Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\saveRnEt.saveRnEt.1.3 Schlüssel Gelöscht : HKCU\Software\5e2d9ddb73abd17 Schlüssel Gelöscht : HKLM\SOFTWARE\5e2d9ddb73abd17 Schlüssel Gelöscht : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE8576D7-0A5F-FD10-841C-3FF359D97D4E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FB5E2C20-9D02-6288-3506-3C27D46DC1B2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{841D5A49-E48D-413C-9C28-EB3D9081D705} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE8576D7-0A5F-FD10-841C-3FF359D97D4E} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB5E2C20-9D02-6288-3506-3C27D46DC1B2} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EE8576D7-0A5F-FD10-841C-3FF359D97D4E} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FB5E2C20-9D02-6288-3506-3C27D46DC1B2} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{2318C2B1-4965-11D4-9B18-009027A5CD4F}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Schlüssel Gelöscht : HKCU\Software\AnyProtect Schlüssel Gelöscht : HKCU\Software\APN PIP Schlüssel Gelöscht : HKCU\Software\AVG Secure Search Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\systweak Schlüssel Gelöscht : HKCU\Software\TutoTag Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\HDvid Codec V1 Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\searchqutoolbar Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Schlüssel Gelöscht : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B} Schlüssel Gelöscht : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C} Schlüssel Gelöscht : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252} Schlüssel Gelöscht : HKLM\Software\AVG Secure Search Schlüssel Gelöscht : HKLM\Software\AVG Security Toolbar Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\Software\PIP Schlüssel Gelöscht : HKLM\Software\SupDp Schlüssel Gelöscht : HKLM\Software\SupTab Schlüssel Gelöscht : HKLM\Software\supWPM Schlüssel Gelöscht : HKLM\Software\systweak Schlüssel Gelöscht : HKLM\Software\Tutorials Schlüssel Gelöscht : HKLM\Software\Uniblue Schlüssel Gelöscht : HKLM\Software\Wpm Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{614925F9-841A-53FE-A28F-DC30FA07239B} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{614925F9-841A-53FE-A28F-DC30FA07239B} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\1ClickDownload Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\HDvid Codec V1 Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ilivid Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Plus-HD-2.2 Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Windows Searchqu Toolbar Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF ***** [ Browser ] ***** -\\ Internet Explorer v9.0.8112.16561 -\\ Mozilla Firefox v [ Datei : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js ] Zeile gelöscht : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com"); Zeile gelöscht : user_pref("browser.search.defaultengine", "Ask.com"); Zeile gelöscht : user_pref("extensions.asktb.abar-war-timeout", "4000"); Zeile gelöscht : user_pref("extensions.asktb.apn_dbr", "ff_7.0.1"); Zeile gelöscht : user_pref("extensions.asktb.autofill-competitor-query-enabled", true); Zeile gelöscht : user_pref("extensions.asktb.autofill-text-highlight-enabled", true); Zeile gelöscht : user_pref("extensions.asktb.cbid", "T8"); Zeile gelöscht : user_pref("extensions.asktb.config-updated", true); Zeile gelöscht : user_pref("extensions.asktb.crumb", "2011.10.19+14.29.27-toolbar011iad-DE-RHVzc2VsZG9yZixHZXJtYW55"); Zeile gelöscht : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://de.ask.com/web?q={query}&qsrc={qsrc}&o={o}&l={l}"); Zeile gelöscht : user_pref("extensions.asktb.displaybehavior", ""); Zeile gelöscht : user_pref("extensions.asktb.displaytext", ""); Zeile gelöscht : user_pref("extensions.asktb.dtid", "YYYYYYYYDE"); Zeile gelöscht : user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false); Zeile gelöscht : user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "GMXX0028"); Zeile gelöscht : user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "C"); Zeile gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q="); Zeile gelöscht : user_pref("extensions.asktb.guid", "a7e0a2c2-b71e-4c4e-a9d7-675ba3e934eb"); Zeile gelöscht : user_pref("extensions.asktb.hpr", "YES"); Zeile gelöscht : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com\", \"www.facebook.com\", \"www.playsushi.com\", \"WWW.google.com\", \"hxxps://websearch.ask.com\", [...] Zeile gelöscht : user_pref("extensions.asktb.if", "first"); Zeile gelöscht : user_pref("extensions.asktb.InstallDir", "C:\\Program Files (x86)\\Ask.com\\"); Zeile gelöscht : user_pref("extensions.asktb.l", "dis"); Zeile gelöscht : user_pref("extensions.asktb.last-config-req", "1369332374986"); Zeile gelöscht : user_pref("extensions.asktb.last-v", "3.13.1.100007"); Zeile gelöscht : user_pref("extensions.asktb.locale", "de_DE"); Zeile gelöscht : user_pref("extensions.asktb.location", "Dusseldorf,Germany"); Zeile gelöscht : user_pref("extensions.asktb.lstation", ""); Zeile gelöscht : user_pref("extensions.asktb.new-tab-opt-out", true); Zeile gelöscht : user_pref("extensions.asktb.o", "14670"); Zeile gelöscht : user_pref("extensions.asktb.pstate", ""); Zeile gelöscht : user_pref("extensions.asktb.qsrc", "2871"); Zeile gelöscht : user_pref("extensions.asktb.sa", "YES"); Zeile gelöscht : user_pref("extensions.asktb.saguid", "512B1239-32D0-4290-B3A3-B971CE7EF391"); Zeile gelöscht : user_pref("extensions.asktb.search-suggestions-enabled", true); Zeile gelöscht : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false); Zeile gelöscht : user_pref("extensions.asktb.socialmini-first", true); Zeile gelöscht : user_pref("extensions.asktb.socialmini-interval", "1200000"); Zeile gelöscht : user_pref("extensions.asktb.socialmini-max-char-ticker", "33"); Zeile gelöscht : user_pref("extensions.asktb.socialmini-max-items", "30"); Zeile gelöscht : user_pref("extensions.asktb.socialmini-native-on", true); Zeile gelöscht : user_pref("extensions.asktb.socialmini-speed", "10000"); Zeile gelöscht : user_pref("extensions.asktb.socialmini-transition-first-open", false); Zeile gelöscht : user_pref("extensions.asktb.themeid", ""); Zeile gelöscht : user_pref("extensions.asktb.timeinstalled", "19.10.2011 23:31:29"); Zeile gelöscht : user_pref("extensions.asktb.to", ""); Zeile gelöscht : user_pref("extensions.enabledAddons", "ffxtlbr@babylon.com:1.2.0,{99079a25-328f-4bd4-be04-00955acaa0a7}:4.5.1.00,{20a82645-c095-46ed-80e3-08825760534b}:0.0.0,plugin@yontoo.com:1.20.02,toolbar@ask.com:[...] Zeile gelöscht : user_pref("browser.search.order.1", "Ask.com"); Zeile gelöscht : user_pref("browser.search.defaultenginename", "Ask.com"); -\\ Google Chrome v34.0.1847.137 [ Datei : C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Search Provider] : hxxp://websearch.ask.com/redirect?client=ff&src=crm&tb=ATU2&o=14670&locale=de_DE&apn_uid=a7e0a2c2-b71e-4c4e-a9d7-675ba3e934eb&apn_ptnrs=T8&apn_sauid=512B1239-32D0-4290-B3A3-B971CE7EF391&apn_dtid=YYYYYYYYDE&q={searchTerms}& Gelöscht [Search Provider] : hxxp://dts.search-results.com/sr?src=crb&appid=119&systemid=406&sr=0&q={searchTerms} Gelöscht [Search Provider] : hxxp://search.babylon.com/?q={searchTerms}&AF=17350&babsrc=SP_ss&mntrId=547436af000000000000000000000000 Gelöscht [Search Provider] : hxxp://isearch.avg.com/search?cid={2C3F8576-8701-4723-926B-6B262FF0542D}&mid=7b9e35bc36b947d19a48d168c3ec4de6-06ce4fc639803a2e3563922518183d8e94088cb9&lang=de&ds=AVG&pr=pr&d=2013-06-26 20:25:58&v=15.3.0.11&pid=avg&sg=0&sap=dsp&q={searchTerms} Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.search.ask.com/web?p2=%5EB7J%5EYYYYYY%5EYY%5EDE&gct=&o=APN11289&tpid=CME-V7&itbv=12.2.2.604&doi=2013-08-09&apn_uid=94769293-32CE-4BF7-A9CD-DE4FF8C9D886&apn_ptnrs=%5EB7J&apn_dtid=%5EYYYYYY%5EYY%5EDE&apn_dbr=cr_26.0.1410.64&psv=barid%253D%257B8F553BE8%252D012D%252D11E3%252DBC1C%252D00218508A415%257D%2526cargo%253DCME%252DV7%2526spr%253Da&trgb=CR&q={searchTerms} Gelöscht [Search Provider] : hxxp://www.softonic.de/s/{searchTerms} Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://eu.wowarmory.com/search.xml?searchQuery={searchTerms}&searchType=all Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.search.ask.com/web?p2=%5EB7J%5EYYYYYY%5EYY%5EDE&gct=&o=APN11289&tpid=CME-V7&itbv=12.2.2.604&doi=2013-08-09&apn_uid=94769293-32CE-4BF7-A9CD-DE4FF8C9D886&apn_ptnrs=%5EB7J&apn_dtid=%5EYYYYYY%5EYY%5EDE&apn_dbr=cr_26.0.1410.64&psv=barid%253D%257B8F553BE8%252D012D%252D11E3%252DBC1C%252D00218508A415%257D%2526cargo%253DCME%252DV7%2526spr%253Da&trgb=CR&q={searchTerms} Gelöscht [Search Provider] : hxxp://www.softonic.de/s/{searchTerms} Gelöscht [Search Provider] : hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=MSD3_14_10_CH&cd=2XzuyEtN2Y1L1QzutDtDtBtCzzyDtDzz0AyEtCyDtAyC0A0FtN0D0Tzu0SyBzyyBtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyC0D0DtCyE0CyEtDtG0FyE0D0FtG0ByCtDyBtGtD0FtByDtGtBtBtC0FtByC0F0E0DyDyD0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyD0CtC0Ezz0EzytG0EtDyCtAtGzyzyyDyEtG0CtC0D0CtGyDtByB0F0E0FzyyB0AtCzytA2Q&cr=955174791&ir= Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926 Gelöscht [Search Provider] : hxxp://www.sweet-page.com/web/?type=dspp&ts=1400416170&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms} Gelöscht [Extension] : dmgpbjjcdccinnndjdgmegndbmhbgglb Gelöscht [Extension] : kfakeonomonapccoamcmdgpoaicnpnoo Gelöscht [Extension] : majjphhgppkndjjkmhhnbgafooenebhd Gelöscht [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof ************************* AdwCleaner[R0].txt - [30501 octets] - [11/07/2014 13:50:31] AdwCleaner[S0].txt - [28095 octets] - [11/07/2014 13:52:28] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [28156 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows (TM) Vista Ultimate x64 Ran by Michi on 11.07.2014 at 14:05:07,84 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-503261611-1707939866-3478010161-1000\Software\sweetim Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21D59046-8568-4E51-BD32-79BD751DCCE6} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{499B15AC-881F-4224-9373-E2AF2D95108B} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5C2A9ED0-361D-4678-BBB6-FA668315952D} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{82FE22F6-6581-4ED3-B962-D0114CFC8F04} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A178FE10-2662-4286-93AB-0477A425A351} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess" Successfully deleted: [Empty Folder] C:\Users\Michi\appdata\local\{06D80EF3-6DA1-4A64-9A84-2F974DC1CB73} Successfully deleted: [Empty Folder] C:\Users\Michi\appdata\local\{46C35DA7-197F-4A20-9D60-1018CC587641} Successfully deleted: [Empty Folder] C:\Users\Michi\appdata\local\{955019F8-861E-4937-B119-2AE7C58D254D} ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 11.07.2014 at 14:15:05,92 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-07-2014 Ran by Michi (administrator) on MICHI-PC on 11-07-2014 14:22:08 Running from C:\Users\Michi\Desktop Platform: Windows Vista (TM) Ultimate Service Pack 2 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe () C:\Program Files (x86)\Drakonia Configurator\hid.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe () C:\Program Files (x86)\Drakonia Configurator\trayicon.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaUI.exe (Realtek) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe (Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWLan.exe () C:\Program Files (x86)\Verbindungsassistent\WTGService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe () C:\Program Files (x86)\MSI\DualCoreCenter\DualCoreCenter.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation) C:\Windows\SysWOW64\conime.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [WinSys2] => C:\Windows\system32\startup.exe [52072 2008-01-30] () HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation) HKLM-x32\...\Run: [WinampAgent] => C:\Program Files\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [DelReg] => C:\Program Files (x86)\MSI\DualCoreCenter\DelReg.exe [196608 2008-05-13] () HKLM-x32\...\Run: [GamingMouse] => C:\Program Files (x86)\Drakonia Configurator\hid.exe [246784 2012-06-07] () HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-06-10] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\DualCoreCenter.lnk ShortcutTarget: DualCoreCenter.lnk -> C:\Program Files (x86)\MSI\DualCoreCenter\StartUpDualCoreCenter.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files (x86)\Ralink\Common\RaUI.exe (Ralink Technology, Corp.) ShellIconOverlayIdentifiers: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 - DefaultScope value is missing. BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - No Name - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File Toolbar: HKLM - No Name - !{98889811-442D-49dd-99D7-DC866BE87DBC} - No File Toolbar: HKLM-x32 - No Name - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File Toolbar: HKLM-x32 - No Name - !{82E1477C-B154-48D3-9891-33D83C26BCD3} - No File Toolbar: HKLM-x32 - No Name - !{95B7759C-8C7F-4BF1-B163-73684A933233} - No File Toolbar: HKLM-x32 - No Name - !{98889811-442D-49dd-99D7-DC866BE87DBC} - No File DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: HKLM-x32 {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll () FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF Extension: HDvid Codec 3 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc3@hdvidcodec.com [2013-08-09] FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-11-02] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR StartupUrls: "hxxp://www.google.com/" CHR Plugin: (Shockwave Flash) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Extension: (Adblock for Youtube™) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2013-12-04] CHR Extension: (One Piece: Monkey D. Luffy (1366x768) Black) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebbcomiedmflgiplmdflpmkhkmkekcih [2013-07-20] CHR Extension: (AdBlock) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-12-04] CHR Extension: (Google Wallet) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-18] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-06-26] (BitRaider, LLC) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) S3 OnlineStorageService; C:\Program Files\Trend Micro SafeSync\hrfscore.exe [7908664 2012-07-12] (Trend Micro Inc.) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-08-22] (Overwolf Ltd) S2 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [621632 2011-03-04] () R2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek) [File not signed] R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\wtgservice.exe [329168 2011-10-18] () ==================== Drivers (Whitelisted) ==================== R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-06-22] (AVG Technologies) S1 Beep; No ImagePath R3 DualCoreCenter; C:\Program Files (x86)\MSI\DualCoreCenter\NTGLM7X64.sys [44344 2010-02-08] (MICRO-STAR INT'L CO., LTD.) S3 GameKB; C:\Windows\System32\drivers\GameKB.sys [27648 2012-05-11] () [File not signed] S3 hwdatacard; C:\Windows\SysWOW64\DRIVERS\ewusbmdm.sys [115328 2008-07-24] (Huawei Technologies Co., Ltd.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-11] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) S3 MSIGreenPower; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\NTGLM7X64.sys [40248 2008-03-12] (MICRO-STAR INT'L CO., LTD.) [File not signed] S3 MSIGreenPowerRushTop; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushTop64.sys [74072 2008-04-23] (Your Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7369v290\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [File not signed] R3 NVR0Dev; C:\Windows\nvoclk64.sys [18216 2006-10-13] (NVidia Corp.) R3 RushTopDevice2; C:\Program Files (x86)\MSI\DualCoreCenter\RushTop64.sys [76088 2009-03-18] (Your Corporation) S3 RushTopDevice_J; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushJ64.sys [31544 2008-06-05] (Your Corporation) [File not signed] R1 {9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64; C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64.sys [60088 2014-05-16] (StdLib) S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S1 lhbjqqty; \??\C:\Windows\system32\drivers\lhbjqqty.sys [X] S3 MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [X] S1 neqnrghc; \??\C:\Windows\system32\drivers\neqnrghc.sys [X] S3 netr28ux; system32\DRIVERS\netr28ux.sys [X] S3 NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S1 rnigwgbp; \??\C:\Windows\system32\drivers\rnigwgbp.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-11 14:22 - 2014-07-11 14:22 - 00018828 _____ () C:\Users\Michi\Desktop\FRST.txt 2014-07-11 14:17 - 2014-07-11 14:21 - 00000000 ____D () C:\Users\Michi\Desktop\FRST-OlderVersion 2014-07-11 14:15 - 2014-07-11 14:15 - 00002007 _____ () C:\Users\Michi\Desktop\JRT.txt 2014-07-11 14:05 - 2014-07-11 14:05 - 00000000 ____D () C:\Windows\ERUNT 2014-07-11 14:03 - 2014-07-11 14:03 - 01016261 _____ (Thisisu) C:\Users\Michi\Desktop\JRT.exe 2014-07-11 14:01 - 2014-07-11 14:01 - 00028265 _____ () C:\Users\Michi\Desktop\AdwCleaner[S0].txt 2014-07-11 13:51 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-07-11 13:50 - 2014-07-11 13:54 - 00000000 ____D () C:\AdwCleaner 2014-07-11 13:48 - 2014-07-11 13:48 - 00047922 _____ () C:\Users\Michi\Desktop\mbam.txt.txt 2014-07-11 13:42 - 2014-07-11 13:42 - 01348263 _____ () C:\Users\Michi\Desktop\adwcleaner_3.215.exe 2014-07-11 13:18 - 2014-07-11 13:58 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-11 13:15 - 2014-07-11 13:15 - 00000941 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-11 13:15 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-11 13:15 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-07-11 13:15 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-07-11 13:13 - 2014-07-11 13:13 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Michi\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-10 18:12 - 2014-07-11 13:55 - 00046394 _____ () C:\Windows\PFRO.log 2014-07-10 17:56 - 2014-07-10 17:56 - 00052795 _____ () C:\ComboFix.txt 2014-07-10 17:41 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-07-10 17:41 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-07-10 17:41 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-07-10 17:41 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-07-10 17:41 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-07-10 17:41 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-07-10 17:41 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-07-10 17:41 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-07-10 17:33 - 2014-07-10 17:56 - 00000000 ____D () C:\Qoobox 2014-07-10 17:32 - 2014-07-10 17:54 - 00000000 ____D () C:\Windows\erdnt 2014-07-10 17:30 - 2014-07-10 17:30 - 05217324 ____R (Swearware) C:\Users\Michi\Desktop\ComboFix.exe 2014-07-10 17:25 - 2014-07-10 17:25 - 00000000 ____D () C:\Program Files (x86)\ProShopperu 2014-07-10 15:38 - 2014-07-10 15:38 - 00001099 _____ () C:\Users\Michi\Desktop\Revo Uninstaller.lnk 2014-07-10 15:38 - 2014-07-10 15:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-07-10 15:37 - 2014-07-10 15:38 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Michi\Downloads\revosetup95.exe 2014-07-09 16:07 - 2014-07-11 14:22 - 00000000 ____D () C:\FRST 2014-07-09 16:05 - 2014-07-11 14:17 - 02084864 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe 2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip 2014-07-09 13:46 - 2014-06-07 06:02 - 17854464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-09 13:46 - 2014-06-07 04:59 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-09 13:46 - 2014-06-07 04:52 - 01348608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-09 13:46 - 2014-06-07 04:51 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-09 13:46 - 2014-06-07 04:51 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-09 13:46 - 2014-06-07 04:47 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-09 13:46 - 2014-06-07 04:45 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-07-09 13:46 - 2014-06-07 04:45 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-09 13:46 - 2014-06-07 04:45 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-09 13:46 - 2014-06-07 04:42 - 02148352 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-09 13:46 - 2014-06-07 04:42 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-09 13:46 - 2014-06-07 04:42 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-09 13:46 - 2014-06-07 04:42 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-09 13:46 - 2014-06-07 04:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-09 13:46 - 2014-06-07 04:41 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-07-09 13:46 - 2014-06-07 04:40 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-09 13:46 - 2014-06-07 04:39 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-07-09 13:46 - 2014-06-07 04:35 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-09 13:46 - 2014-06-07 02:05 - 12353024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-09 13:46 - 2014-06-07 01:12 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-09 13:46 - 2014-06-07 01:04 - 01106432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-09 13:46 - 2014-06-07 01:03 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-09 13:46 - 2014-06-07 01:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-09 13:46 - 2014-06-07 01:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-07-09 13:46 - 2014-06-07 00:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-07-09 13:46 - 2014-06-07 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-07-09 13:46 - 2014-06-07 00:54 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-09 13:46 - 2014-06-07 00:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-09 13:46 - 2014-06-07 00:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-07-09 13:46 - 2014-06-07 00:53 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-09 13:46 - 2014-06-07 00:52 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-09 13:46 - 2014-06-07 00:51 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-07-09 13:46 - 2014-06-07 00:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-07-09 13:45 - 2014-06-07 05:13 - 10890752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-09 13:45 - 2014-06-07 04:50 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-07-09 13:45 - 2014-06-07 04:41 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-07-09 13:45 - 2014-06-07 01:25 - 09711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-09 13:45 - 2014-06-07 00:58 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-09 13:45 - 2014-06-07 00:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-07-09 13:45 - 2014-06-07 00:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-09 13:45 - 2014-06-07 00:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-09 13:45 - 2014-06-07 00:53 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-07-09 13:44 - 2014-06-07 02:33 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-09 13:44 - 2014-06-06 10:59 - 00506880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-07-09 13:44 - 2014-06-06 09:13 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-09 13:44 - 2014-05-30 09:10 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX 2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx 2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR 2014-06-26 15:21 - 2014-07-07 13:06 - 00000000 ____D () C:\ProgramData\BitRaider 2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider 2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk 2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA 2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk 2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment 2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk 2014-06-20 12:02 - 2014-06-20 12:03 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver 2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk 2014-06-16 10:58 - 2014-06-16 10:57 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk 2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk 2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt 2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt 2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt 2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt 2014-06-15 11:44 - 2014-06-29 23:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks 2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe 2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe 2014-06-12 13:30 - 2014-04-26 20:21 - 00622592 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-12 13:30 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-06-12 13:30 - 2014-04-05 06:26 - 01417664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-12 13:30 - 2014-04-05 04:32 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2014-06-12 13:30 - 2014-03-10 08:26 - 01869824 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-12 13:30 - 2014-03-10 08:26 - 01794560 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-12 13:30 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2014-06-12 13:30 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll ==================== One Month Modified Files and Folders ======= 2014-07-11 14:22 - 2014-07-11 14:22 - 00018828 _____ () C:\Users\Michi\Desktop\FRST.txt 2014-07-11 14:22 - 2014-07-09 16:07 - 00000000 ____D () C:\FRST 2014-07-11 14:21 - 2014-07-11 14:17 - 00000000 ____D () C:\Users\Michi\Desktop\FRST-OlderVersion 2014-07-11 14:17 - 2014-07-09 16:05 - 02084864 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe 2014-07-11 14:15 - 2014-07-11 14:15 - 00002007 _____ () C:\Users\Michi\Desktop\JRT.txt 2014-07-11 14:05 - 2014-07-11 14:05 - 00000000 ____D () C:\Windows\ERUNT 2014-07-11 14:03 - 2014-07-11 14:03 - 01016261 _____ (Thisisu) C:\Users\Michi\Desktop\JRT.exe 2014-07-11 14:01 - 2014-07-11 14:01 - 00028265 _____ () C:\Users\Michi\Desktop\AdwCleaner[S0].txt 2014-07-11 14:01 - 2013-05-14 23:00 - 01702468 _____ () C:\Windows\WindowsUpdate.log 2014-07-11 13:58 - 2014-07-11 13:18 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-11 13:57 - 2013-05-06 22:53 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-11 13:57 - 2013-05-06 22:53 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-11 13:56 - 2014-03-13 18:14 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-07-11 13:56 - 2006-11-02 17:40 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-11 13:56 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-11 13:56 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-11 13:55 - 2014-07-10 18:12 - 00046394 _____ () C:\Windows\PFRO.log 2014-07-11 13:54 - 2014-07-11 13:50 - 00000000 ____D () C:\AdwCleaner 2014-07-11 13:54 - 2006-11-02 17:40 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-11 13:48 - 2014-07-11 13:48 - 00047922 _____ () C:\Users\Michi\Desktop\mbam.txt.txt 2014-07-11 13:42 - 2014-07-11 13:42 - 01348263 _____ () C:\Users\Michi\Desktop\adwcleaner_3.215.exe 2014-07-11 13:35 - 2006-11-02 15:33 - 00000000 ____D () C:\Windows\security 2014-07-11 13:15 - 2014-07-11 13:15 - 00000941 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-11 13:13 - 2014-07-11 13:13 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Michi\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-10 20:54 - 2012-02-02 03:37 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\TS3Client 2014-07-10 17:56 - 2014-07-10 17:56 - 00052795 _____ () C:\ComboFix.txt 2014-07-10 17:56 - 2014-07-10 17:33 - 00000000 ____D () C:\Qoobox 2014-07-10 17:56 - 2006-11-02 15:33 - 00000000 __RHD () C:\Users\Default 2014-07-10 17:54 - 2014-07-10 17:32 - 00000000 ____D () C:\Windows\erdnt 2014-07-10 17:53 - 2011-10-18 16:41 - 00000000 ____D () C:\Users\Michi 2014-07-10 17:53 - 2006-11-02 14:34 - 00000215 _____ () C:\Windows\system.ini 2014-07-10 17:31 - 2012-08-16 08:22 - 00001696 _____ () C:\Users\Michi\Desktop\bla.txt 2014-07-10 17:30 - 2014-07-10 17:30 - 05217324 ____R (Swearware) C:\Users\Michi\Desktop\ComboFix.exe 2014-07-10 17:25 - 2014-07-10 17:25 - 00000000 ____D () C:\Program Files (x86)\ProShopperu 2014-07-10 17:25 - 2014-06-08 19:55 - 00000000 ____D () C:\ProgramData\297d856b205d5963 2014-07-10 15:38 - 2014-07-10 15:38 - 00001099 _____ () C:\Users\Michi\Desktop\Revo Uninstaller.lnk 2014-07-10 15:38 - 2014-07-10 15:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-07-10 15:38 - 2014-07-10 15:37 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Michi\Downloads\revosetup95.exe 2014-07-09 14:03 - 2006-11-02 17:21 - 00255776 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-09 13:59 - 2006-11-02 17:06 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-09 13:57 - 2013-07-22 05:26 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-09 13:54 - 2006-11-02 14:35 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip 2014-07-07 13:06 - 2014-06-26 15:21 - 00000000 ____D () C:\ProgramData\BitRaider 2014-07-07 12:56 - 2011-10-18 16:41 - 00055560 _____ () C:\Users\Michi\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-07 12:54 - 2011-10-19 16:48 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-07-05 16:05 - 2011-11-22 11:56 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\vlc 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX 2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx 2014-07-03 14:42 - 2012-05-11 00:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Skype 2014-06-30 06:36 - 2011-10-20 02:44 - 00175616 _____ () C:\Users\Michi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-06-29 23:08 - 2014-06-15 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks 2014-06-27 11:36 - 2013-08-30 14:25 - 00000000 ____D () C:\Users\Michi\Desktop\TS Icons 2014-06-27 11:19 - 2012-02-02 03:35 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR 2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider 2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk 2014-06-26 14:06 - 2013-07-20 12:23 - 00014744 _____ () C:\Users\Michi\Documents\Install STAR WARS The Old Republic.log 2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA 2014-06-23 08:33 - 2013-05-06 15:32 - 00001217 _____ () C:\Users\Michi\Desktop\WoW PWS.lnk 2014-06-22 19:39 - 2013-06-26 20:25 - 00050464 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk 2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment 2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk 2014-06-20 12:03 - 2014-06-20 12:02 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver 2014-06-17 17:56 - 2012-12-13 10:46 - 00000000 ____D () C:\Filme 2014-06-17 17:56 - 2012-08-25 14:45 - 00000000 ____D () C:\Users\Michi\Desktop\Wma 2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk 2014-06-16 11:00 - 2014-02-03 14:46 - 00155136 _____ () C:\Windows\SysWOW64\unrar.dll 2014-06-16 11:00 - 2014-02-03 14:46 - 00034308 _____ () C:\Windows\SysWOW64\bassmod.dll 2014-06-16 10:57 - 2014-06-16 10:58 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk 2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk 2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt 2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt 2014-06-16 07:18 - 2013-05-12 09:58 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-06-16 07:18 - 2012-01-27 19:49 - 00000000 ____D () C:\Games 2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt 2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt 2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe 2014-06-15 11:25 - 2013-05-12 18:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Wargaming.net 2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe Some content of TEMP: ==================== C:\Users\Michi\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-11 14:03 ==================== End Of Log ============================ --- --- --- kleines Update : hat sich einiges getan zwar noch ungewohnt das die Seiten nicht mehr wie Flummis hin und herspringen wegen Werbung aber 100 mal besser |
12.07.2014, 07:42 | #9 |
/// the machine /// TB-Ausbilder | Dauerhaftes Werbung öffnen macht Surfen fast unmöglichESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.07.2014, 14:04 | #10 |
| Dauerhaftes Werbung öffnen macht Surfen fast unmöglichCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=6d9eb5f82028744ab91f518581738a66 # engine=19142 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-07-12 12:39:32 # local_time=2014-07-12 02:39:32 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode_1='Microsoft Security Essentials' # compatibility_mode=5895 16777213 100 100 8540205 46482088 0 0 # scanned=344891 # found=91 # cleaned=0 # scan_time=14135 sh=C7C0F42A23562AA6DCCD60326FD8CC2AA41B5448 ft=1 fh=c053642cee9f3def vn="Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface32.dll.vir" sh=9DC13DB9C123270C2356ED410128E11D5ADF7C6E ft=1 fh=023ab782f0a9b07d vn="Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupTab.dll.vir" sh=48EF8B4E06E0F1D3C06C4D6E1EA2B6CE48AA5231 ft=1 fh=ac26df35aa8ade69 vn="Variante von Win32/Adware.Yontoo.B Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll.vir" sh=8EB72E101395FEBB37131078A884E25D05BB51C9 ft=1 fh=c71c00113a7cc125 vn="Variante von Win32/AdWare.MultiPlug.T Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\CoupScuanner\pUyJz3N_N.dll.vir" sh=458A7DCB3C85CBE3C93EB7876FA0E6CD7E07F0F6 ft=1 fh=c71c0011129d357b vn="Variante von Win32/AdWare.MultiPlug.T Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\CoupScuanner\pUyJz3N_N.exe.vir" sh=21FA935C037CDD4DA753895AA750262A3056B871 ft=1 fh=c71c001127f5a6d6 vn="Variante von Win64/Adware.MultiPlug.C Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\CoupScuanner\pUyJz3N_N.x64.dll.vir" sh=8EB72E101395FEBB37131078A884E25D05BB51C9 ft=1 fh=c71c00113a7cc125 vn="Variante von Win32/AdWare.MultiPlug.T Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saavernett\e.dll.vir" sh=458A7DCB3C85CBE3C93EB7876FA0E6CD7E07F0F6 ft=1 fh=c71c0011129d357b vn="Variante von Win32/AdWare.MultiPlug.T Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saavernett\e.exe.vir" sh=21FA935C037CDD4DA753895AA750262A3056B871 ft=1 fh=c71c001127f5a6d6 vn="Variante von Win64/Adware.MultiPlug.C Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saavernett\e.x64.dll.vir" sh=4E63B8B2C46C7F59B8A1BF9D001290A2CC6C0B76 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.A evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_kfakeonomonapccoamcmdgpoaicnpnoo_0\28.vir" sh=B5ED1E639B7D9AD3C0F3C81E5AA2E9F88DDFEB65 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\102_dealply_m.js.vir" sh=464E61CE0A166C746C8BE32F8BD662B0EDF79938 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\103_intext_5_m.js.vir" sh=8BFBBD749FDAA46297DA7F28A30E29C55FD72880 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\104_jollywallet_m.js.vir" sh=0B21E41A47E579081215969619861996F43524B1 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\105_corticas_m.js.vir" sh=FE3704EEF2BFB9DCA552518E7AEC9D6AFC1ED15C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\119_similar_web_m.js.vir" sh=35CE3B76158991DDEA79CAF0C1F826A7EE18A820 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\120_luck_m.js.vir" sh=E106EF12FBA54AD37717391E3A2A8B7416B0A30E ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\123_intext_adv_m.js.vir" sh=AE2D5CE395EE9CD2595F77F616E574F4794B1152 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\155_ibario_pops_m.js.vir" sh=0CEB1A073B87956FD1F21F8425B8F76015B1BCD8 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\158_50onred_ads_only_no_fb_m.js.vir" sh=CFFCA6A4EE3A0DF2319440491BB297ADEC6EEF37 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\178_revizer_ws_dynamic_m.js.vir" sh=ADB54DE323736C99B4191A45B478B70DF1B7B945 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\179_revizer_p_dynamic_m.js.vir" sh=C9A8D5AE55FA65E00EE75767C5D2E9B56041858D ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\180_bpo_serp_m.js.vir" sh=24E6E5A06D24A5CC24C0B705FDB089FD4FEC70AC ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\184_noproblemppc_m.js.vir" sh=913EFB9D675CDABC6594788C8F6F1BA8FB057815 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\189_active_sanity.js.vir" sh=9F07ACC96BC246F25975479E9382CDF88E7D8711 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\191_ciuvo_m.js.vir" sh=CE36251B85631AF0D145BF086D14272593AB253A ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\194_retargeting_bi_m.js.js.vir" sh=28EF3B09E284C4A1F530AE035D9CF94E12BD2A97 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\195_icm_convertmedia_m.js.vir" sh=F545986C4CEA1996E51779B9B8DE73F3C8DF8834 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\91_monetizationLoader.js.js.vir" sh=0C5AC30A082628E85A9A8B68EF5E5EAFA46F0CC7 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\93_superfish_no_coupons_m.js.vir" sh=CC3F181DE2519244625F872A480F9F4C09B16161 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\000962.sst.vir" sh=D68C30132B7F1BB2FA423C602ADC4148C4E5FD46 ft=1 fh=c71c00112ae35862 vn="Variante von Win32/SProtector.D evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Temp\__tmp_2bbca911.vir" sh=E496D28CA82F39CF482A036A14A71B87FEFA0D8A ft=1 fh=032f2ea9d03063a8 vn="Variante von Win32/DomaIQ.AZ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\File System\000\t\00\00000000" sh=F99A0B474808C529DBAD311AFB32B17176239448 ft=1 fh=6874c078921d81a0 vn="Variante von Win32/DomaIQ.BF evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000000" sh=A1AF264931EC92BF3175733E0FFA32E38C7D48B2 ft=1 fh=782af8a2f4ac8179 vn="Win32/Toolbar.SearchSuite.H evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\BrowserConnection.dll" sh=140FD043B720BE515D9CB555505EBB10BD16025A ft=1 fh=42d2be50ff62fe5d vn="Variante von Win32/Toolbar.SearchSuite.C evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\datamngr.dll" sh=56AF5F152A3DA847A0E698CADE0A165165532F2E ft=1 fh=5c910fc021e270b2 vn="Variante von Win32/Toolbar.SearchSuite.A evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\datamngrUI.exe" sh=73558B9668C2DF9D35BD8F88A6B52A6E6BF7BF87 ft=1 fh=99fe90114de7e059 vn="Variante von Win32/Toolbar.SearchSuite.R evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\DnsBHO.dll" sh=FF958F72167B24E3A5CAB3B33B2144B60A692E89 ft=1 fh=a92b7986aaff0d8d vn="Variante von Win32/Toolbar.SearchSuite evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\IEBHO.dll" sh=BFDC3839ACE19D582651CBDBCA401D85ACB87CEE ft=1 fh=c71c0011ea55d4ef vn="Variante von Win32/Toolbar.Visicom.C evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe" sh=E02E52D8D6D4809A43A0747AD2D43EA571EFAF81 ft=1 fh=28dc55d634c41655 vn="Variante von Win32/Toolbar.Visicom.B evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\searchresultsDx.dll" sh=7223962B03D4EFEBB2183F1AD27EF47048F0B796 ft=1 fh=4e6c4908f37e801e vn="Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\searchresultstb.dll" sh=BBEADC524F11590D67F811E03A2713C5A3F4587C ft=1 fh=a93cd89afdab983e vn="Variante von Win64/Toolbar.SearchSuite.A evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\x64\datamngr.dll" sh=9743EF8EBC72394672B55A25BDC80BFACFCB30B8 ft=1 fh=b915534fd2914b03 vn="Variante von Win64/Toolbar.SearchSuite.A evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\x64\IEBHO.dll" sh=23B3E5F508EB6FC76D67A873A5AAC2D34C3CE5E1 ft=1 fh=b86fe1495473b541 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Communicator\mgcommon.dll" sh=7DB65607A18C67C0C8C0310E0FF23A202AB3F070 ft=1 fh=9f565fd3b0ad3b83 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Communicator\mgcommunication.dll" sh=3176C30E3A30990C42C968951B6BB2ADFD0B1C00 ft=1 fh=12a0591694d39321 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Communicator\mgsimcommon.dll" sh=08647AB20AED7B8385931FDF5B4A48165131A061 ft=1 fh=b4c21070436958b0 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Communicator\mgxml_wrapper.dll" sh=C6A9FB024D614702667E0768E0B673BA3A31F504 ft=1 fh=aa62bac49704426f vn="Variante von Win32/SweetIM.F evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe" sh=C8F1E3F28152C6C010B7AE8FA4D167E3C388FF0C ft=1 fh=84ff0b58ed098a1d vn="Win32/SweetIM.K evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Communicator\resources\sqlite\mgSqlite3.dll" sh=D09F832544B921CD7C61A7DB193F29EF6638AD88 ft=1 fh=58a116a27a6d5dbb vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\ContentPackagesActivationHandler.exe" sh=C6E3F8034D197C34D61701AC146694B6DBEC36CD ft=1 fh=7f9fa2fc68c7b7f4 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgAdaptersProxy.dll" sh=FC883B83DA2A9ED93AC2A4CEC9936268A6B264C2 ft=1 fh=80a06d85550fdea2 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgArchive.dll" sh=F3001B5F58A6C6AB8DD7E6E63CB89D20F74EF228 ft=1 fh=f50ea5fcbc656251 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgcommon.dll" sh=2CF3C9FBCBEBAA6D75DE43CCC487D62954538F81 ft=1 fh=446d6a4df1e456fa vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgcommunication.dll" sh=60FCD298549E0383DFACBE66420DC922D6BAAF84 ft=1 fh=73f28a50980afe65 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgconfig.dll" sh=531A5D492B39076AA7990DD76F41B762258B86A7 ft=1 fh=a45064434f491236 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgFlashPlayer.dll" sh=AE57E26160449200540B1FD8E839F1BD5A30327A ft=1 fh=c29c62a52f555ace vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mghooking.dll" sh=B6E78443D25AF8B978DC24D515DF7B2F673629CC ft=1 fh=ece232c764d65d89 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgICQAuto.dll" sh=42B14A7D72C6EDAF5140A2C7B95149B92473853C ft=1 fh=6f2c94e91302d1a2 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgICQMessengerAdapter.dll" sh=B28C9BCA89A124EBD2EAAF5073370E7E0E87DB4E ft=1 fh=c56c5ff3b0e7703d vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mglogger.dll" sh=87FF2D9A36B50B5A7DF4D08F87B92BEA86D7DAB7 ft=1 fh=71dc135578fffed6 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgMediaPlayer.dll" sh=C86CF9524D11A2392A491EA15ED12D2CA890F249 ft=1 fh=ae21d71fff630a17 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgMsnAuto.dll" sh=055E7A147AB9DCB141FDF58A0D3CCD825AE8B361 ft=1 fh=ac8cec2f7886b930 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgMsnMessengerAdapter.dll" sh=73987118D6F1799B0B29DB00BF7248B20347BB46 ft=1 fh=d25a2527398bc729 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgsimcommon.dll" sh=C786E62AB09C10B6277F3E9CFC34207FE56E1FFA ft=1 fh=6c27d70c5686a2b1 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgSweetIM.dll" sh=07695C8842935A01310F52C83BAB364950419841 ft=1 fh=e250219d9f9cd5af vn="Variante von Win32/SweetIM.F evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgUpdateSupport.dll" sh=093FB06E67DB8C5562A823E389853340405B8724 ft=1 fh=1b5e6676818f2ad9 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgxml_wrapper.dll" sh=A679EB39BB32DD88C09E150B0E5F7BAED12467A6 ft=1 fh=0ba701bbd4ac4b73 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgYahooAuto.dll" sh=9B45902B8B791A84EC6F7D1AD2E8099410D1A467 ft=1 fh=3191d44e293b78d5 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgYahooMessengerAdapter.dll" sh=AE3254BDF03A347110068EF29CB15C7B554491F0 ft=1 fh=30381f993c8268c2 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe" sh=C8F1E3F28152C6C010B7AE8FA4D167E3C388FF0C ft=1 fh=84ff0b58ed098a1d vn="Win32/SweetIM.K evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\resources\sqlite\mgSqlite3.dll" sh=106F591B2BD500597B72796DE6CF1882C4F19F0A ft=1 fh=4ffdf32f906db695 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\ClearHist.exe" sh=A50D4E8729EC3B275F6AFD9EE573E2A28546F01D ft=1 fh=b0987145db4c1583 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgcommon.dll" sh=851CA33721CF5E710133B4D36EAF921ACEB4CD50 ft=1 fh=15365fabb2edd5be vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgconfig.dll" sh=8B5C441500E865FC80A55583FC68036FAF7DAD06 ft=1 fh=c81a85374d8cfdb7 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" sh=95581618E0DAA5F92543B429C7EB383C6D63B3AE ft=1 fh=0132ebbe85145cfb vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe" sh=41C2EC5BB47E9A40E309ABAA048BA1F742E43574 ft=1 fh=f7ee8c0d578659e0 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mghooking.dll" sh=E32CD33BD92D0676F8F81103174AF5E4E9E3F38E ft=1 fh=0e4e3ab2b3f109e4 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mglogger.dll" sh=F5348CC7962B088ACCCD2F67138D43FB88DF67F2 ft=1 fh=5a321158315b5fe9 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll" sh=26B6B3788EF0A2A83A43DFE5E13F51B3E491A6F4 ft=1 fh=073310618d11024b vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" sh=10B68A9C897C5854EA80624B01EE8BECF7017F01 ft=1 fh=6858221c6d206eb6 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll" sh=B0C53EBE6A8C5B9B987F00F739D032767B291118 ft=1 fh=a07a814e5747bf62 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll" sh=B24958E90C37A562509F135AA942B997B52209B7 ft=1 fh=ecb2fb245305d5cc vn="Win32/Adware.1ClickDownload.K Anwendung" ac=I fn="F:\Program Files (x86)\TornTV.com\uninst.exe" sh=E1C99225C4C16710DE3AF3D52300E1E943F7C84F ft=1 fh=f891ef12b7700e02 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\ProgramData\SweetIM\Messenger\update\sweetimsetup.exe" sh=E15DF75E5B81A209E0E453092C9610C3F8DC7073 ft=1 fh=8918dac93ad3a346 vn="Win32/Toolbar.SearchSuite.M evtl. unerwünschte Anwendung" ac=I fn="F:\ProgramData\Wincert\win32cert.dll" sh=9B56D5787C88CF939DABA1E9273775A1D33EF25F ft=1 fh=8aacdf233e2d6e39 vn="Win32/Toolbar.SearchSuite.M evtl. unerwünschte Anwendung" ac=I fn="F:\ProgramData\Wincert\win32prop.dll" sh=2FA019C3D1CC2BC1905FBD6765DA3CFBE851DD64 ft=1 fh=f275e610e24fd946 vn="Win64/Toolbar.SearchSuite.B evtl. unerwünschte Anwendung" ac=I fn="F:\ProgramData\Wincert\win64cert.dll" sh=34ABB88310B01A075382292FDE9F2B6E727E5D66 ft=1 fh=1bef8d0f51d0bf3a vn="Win64/Toolbar.SearchSuite.B evtl. unerwünschte Anwendung" ac=I fn="F:\ProgramData\Wincert\win64prop.dll" sh=A4C87DB6A390CE18CAF367CC3C8AE182C34B6488 ft=0 fh=0000000000000000 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Windows\Installer\17fc195.msi" sh=F2CF5D55F2843F59864F93643E6931E32A54430F ft=0 fh=0000000000000000 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Windows\Installer\17fc19a.msi" sh=195E06474CD71867AEE3CC9C415F095328EA3935 ft=0 fh=0000000000000000 vn="Win32/SweetIM.K evtl. unerwünschte Anwendung" ac=I fn="F:\Windows\Installer\17fc19f.msi" Code:
ATTFilter Results of screen317's Security Check version 0.99.85 Windows Vista Service Pack 2 x64 (UAC is enabled) Internet Explorer 9 Internet Explorer 8 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials (On Access scanning disabled!) Error obtaining update status for antivirus! `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 55 Java version out of Date! Adobe Flash Player 14.0.0.145 Adobe Reader 10.1.10 Adobe Reader out of Date! Google Chrome 26.0.1410.64 Google Chrome 34.0.1847.137 ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Malwarebytes Anti-Malware mbamscheduler.exe system32 FirewallControlPanel.exe Trend Micro SafeSync hrfscore.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-07-2014 Ran by Michi (administrator) on MICHI-PC on 12-07-2014 14:56:12 Running from C:\Users\Michi\Desktop Platform: Windows Vista (TM) Ultimate Service Pack 2 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe () C:\Program Files (x86)\Drakonia Configurator\hid.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaUI.exe () C:\Program Files (x86)\Drakonia Configurator\trayicon.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe (Realtek) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe (Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWLan.exe () C:\Program Files (x86)\Verbindungsassistent\WTGService.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\conime.exe (Trend Micro Inc.) C:\Program Files\Trend Micro SafeSync\hrfscore.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [WinSys2] => C:\Windows\system32\startup.exe [52072 2008-01-30] () HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation) HKLM-x32\...\Run: [WinampAgent] => C:\Program Files\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [DelReg] => C:\Program Files (x86)\MSI\DualCoreCenter\DelReg.exe [196608 2008-05-13] () HKLM-x32\...\Run: [GamingMouse] => C:\Program Files (x86)\Drakonia Configurator\hid.exe [246784 2012-06-07] () HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-06-10] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\DualCoreCenter.lnk ShortcutTarget: DualCoreCenter.lnk -> C:\Program Files (x86)\MSI\DualCoreCenter\StartUpDualCoreCenter.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files (x86)\Ralink\Common\RaUI.exe (Ralink Technology, Corp.) ShellIconOverlayIdentifiers: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ShellIconOverlayIdentifiers-x32: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 - DefaultScope value is missing. BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - No Name - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File Toolbar: HKLM - No Name - !{98889811-442D-49dd-99D7-DC866BE87DBC} - No File Toolbar: HKLM-x32 - No Name - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File Toolbar: HKLM-x32 - No Name - !{82E1477C-B154-48D3-9891-33D83C26BCD3} - No File Toolbar: HKLM-x32 - No Name - !{95B7759C-8C7F-4BF1-B163-73684A933233} - No File Toolbar: HKLM-x32 - No Name - !{98889811-442D-49dd-99D7-DC866BE87DBC} - No File DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab DPF: HKLM-x32 {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ () FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF Extension: HDvid Codec 3 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc3@hdvidcodec.com [2013-08-09] FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-11-02] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR StartupUrls: "hxxp://www.google.com/" CHR Plugin: (Shockwave Flash) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.) CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Extension: (Adblock for Youtube™) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2013-12-04] CHR Extension: (One Piece: Monkey D. Luffy (1366x768) Black) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebbcomiedmflgiplmdflpmkhkmkekcih [2013-07-20] CHR Extension: (AdBlock) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-12-04] CHR Extension: (Google Wallet) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-18] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-06-26] (BitRaider, LLC) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation) R3 OnlineStorageService; C:\Program Files\Trend Micro SafeSync\hrfscore.exe [7908664 2012-07-12] (Trend Micro Inc.) S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-08-22] (Overwolf Ltd) S2 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [621632 2011-03-04] () R2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek) [File not signed] R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\wtgservice.exe [329168 2011-10-18] () ==================== Drivers (Whitelisted) ==================== R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-06-22] (AVG Technologies) S1 Beep; No ImagePath R3 DualCoreCenter; C:\Program Files (x86)\MSI\DualCoreCenter\NTGLM7X64.sys [44344 2010-02-08] (MICRO-STAR INT'L CO., LTD.) S3 GameKB; C:\Windows\System32\drivers\GameKB.sys [27648 2012-05-11] () [File not signed] S3 hwdatacard; C:\Windows\SysWOW64\DRIVERS\ewusbmdm.sys [115328 2008-07-24] (Huawei Technologies Co., Ltd.) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-12] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) S3 MSIGreenPower; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\NTGLM7X64.sys [40248 2008-03-12] (MICRO-STAR INT'L CO., LTD.) [File not signed] S3 MSIGreenPowerRushTop; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushTop64.sys [74072 2008-04-23] (Your Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7369v290\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [File not signed] R3 RushTopDevice2; C:\Program Files (x86)\MSI\DualCoreCenter\RushTop64.sys [76088 2009-03-18] (Your Corporation) S3 RushTopDevice_J; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushJ64.sys [31544 2008-06-05] (Your Corporation) [File not signed] R1 {9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64; C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64.sys [60088 2014-05-16] (StdLib) S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X] S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S1 lhbjqqty; \??\C:\Windows\system32\drivers\lhbjqqty.sys [X] S3 MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [X] S1 neqnrghc; \??\C:\Windows\system32\drivers\neqnrghc.sys [X] S3 netr28ux; system32\DRIVERS\netr28ux.sys [X] S3 NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] S1 rnigwgbp; \??\C:\Windows\system32\drivers\rnigwgbp.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-12 14:56 - 2014-07-12 14:56 - 00018863 _____ () C:\Users\Michi\Desktop\FRST.txt 2014-07-12 14:53 - 2014-07-12 14:54 - 00001245 _____ () C:\Users\Michi\Desktop\checkup.txt.txt 2014-07-12 14:47 - 2014-07-12 14:47 - 00854390 _____ () C:\Users\Michi\Desktop\SecurityCheck.exe 2014-07-12 10:34 - 2014-07-12 10:34 - 02347384 _____ (ESET) C:\Users\Michi\Downloads\esetsmartinstaller_deu.exe 2014-07-11 23:41 - 2014-07-12 14:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-11 23:41 - 2014-07-11 23:42 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-07-11 14:17 - 2014-07-12 10:35 - 00000000 ____D () C:\Users\Michi\Desktop\FRST-OlderVersion 2014-07-11 14:15 - 2014-07-11 14:15 - 00002007 _____ () C:\Users\Michi\Desktop\JRT.txt 2014-07-11 14:05 - 2014-07-11 14:05 - 00000000 ____D () C:\Windows\ERUNT 2014-07-11 14:03 - 2014-07-11 14:03 - 01016261 _____ (Thisisu) C:\Users\Michi\Desktop\JRT.exe 2014-07-11 14:01 - 2014-07-11 14:01 - 00028265 _____ () C:\Users\Michi\Desktop\AdwCleaner[S0].txt 2014-07-11 13:51 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll 2014-07-11 13:50 - 2014-07-11 13:54 - 00000000 ____D () C:\AdwCleaner 2014-07-11 13:48 - 2014-07-11 13:48 - 00047922 _____ () C:\Users\Michi\Desktop\mbam.txt.txt 2014-07-11 13:42 - 2014-07-11 13:42 - 01348263 _____ () C:\Users\Michi\Desktop\adwcleaner_3.215.exe 2014-07-11 13:18 - 2014-07-12 14:26 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-11 13:15 - 2014-07-11 13:15 - 00000941 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-11 13:15 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-11 13:15 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-07-11 13:15 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-07-11 13:13 - 2014-07-11 13:13 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Michi\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-10 18:12 - 2014-07-11 13:55 - 00046394 _____ () C:\Windows\PFRO.log 2014-07-10 17:56 - 2014-07-10 17:56 - 00052795 _____ () C:\ComboFix.txt 2014-07-10 17:41 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-07-10 17:41 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-07-10 17:41 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-07-10 17:41 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-07-10 17:41 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-07-10 17:41 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-07-10 17:41 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-07-10 17:41 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-07-10 17:33 - 2014-07-10 17:56 - 00000000 ____D () C:\Qoobox 2014-07-10 17:32 - 2014-07-10 17:54 - 00000000 ____D () C:\Windows\erdnt 2014-07-10 17:30 - 2014-07-10 17:30 - 05217324 ____R (Swearware) C:\Users\Michi\Desktop\ComboFix.exe 2014-07-10 17:25 - 2014-07-10 17:25 - 00000000 ____D () C:\Program Files (x86)\ProShopperu 2014-07-10 15:38 - 2014-07-10 15:38 - 00001099 _____ () C:\Users\Michi\Desktop\Revo Uninstaller.lnk 2014-07-10 15:38 - 2014-07-10 15:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-07-10 15:37 - 2014-07-10 15:38 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Michi\Downloads\revosetup95.exe 2014-07-09 16:07 - 2014-07-12 14:56 - 00000000 ____D () C:\FRST 2014-07-09 16:05 - 2014-07-11 14:17 - 02084864 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe 2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip 2014-07-09 13:46 - 2014-06-07 06:02 - 17854464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-09 13:46 - 2014-06-07 04:59 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-09 13:46 - 2014-06-07 04:52 - 01348608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-09 13:46 - 2014-06-07 04:51 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-09 13:46 - 2014-06-07 04:51 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-09 13:46 - 2014-06-07 04:47 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-09 13:46 - 2014-06-07 04:45 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-07-09 13:46 - 2014-06-07 04:45 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-09 13:46 - 2014-06-07 04:45 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-09 13:46 - 2014-06-07 04:42 - 02148352 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-09 13:46 - 2014-06-07 04:42 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-09 13:46 - 2014-06-07 04:42 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-09 13:46 - 2014-06-07 04:42 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-09 13:46 - 2014-06-07 04:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-09 13:46 - 2014-06-07 04:41 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2014-07-09 13:46 - 2014-06-07 04:40 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-09 13:46 - 2014-06-07 04:39 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2014-07-09 13:46 - 2014-06-07 04:35 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-09 13:46 - 2014-06-07 02:05 - 12353024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-09 13:46 - 2014-06-07 01:12 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-09 13:46 - 2014-06-07 01:04 - 01106432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-09 13:46 - 2014-06-07 01:03 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-09 13:46 - 2014-06-07 01:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-09 13:46 - 2014-06-07 01:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2014-07-09 13:46 - 2014-06-07 00:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-07-09 13:46 - 2014-06-07 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-07-09 13:46 - 2014-06-07 00:54 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-09 13:46 - 2014-06-07 00:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-09 13:46 - 2014-06-07 00:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2014-07-09 13:46 - 2014-06-07 00:53 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-09 13:46 - 2014-06-07 00:52 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-09 13:46 - 2014-06-07 00:51 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2014-07-09 13:46 - 2014-06-07 00:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-07-09 13:45 - 2014-06-07 05:13 - 10890752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-09 13:45 - 2014-06-07 04:50 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2014-07-09 13:45 - 2014-06-07 04:41 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2014-07-09 13:45 - 2014-06-07 01:25 - 09711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-09 13:45 - 2014-06-07 00:58 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-09 13:45 - 2014-06-07 00:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-07-09 13:45 - 2014-06-07 00:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-09 13:45 - 2014-06-07 00:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-09 13:45 - 2014-06-07 00:53 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2014-07-09 13:44 - 2014-06-07 02:33 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-07-09 13:44 - 2014-06-06 10:59 - 00506880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2014-07-09 13:44 - 2014-06-06 09:13 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-07-09 13:44 - 2014-05-30 09:10 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX 2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx 2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR 2014-06-26 15:21 - 2014-07-07 13:06 - 00000000 ____D () C:\ProgramData\BitRaider 2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider 2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk 2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA 2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk 2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment 2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk 2014-06-20 12:02 - 2014-06-20 12:03 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver 2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk 2014-06-16 10:58 - 2014-06-16 10:57 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk 2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk 2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt 2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt 2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt 2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt 2014-06-15 11:44 - 2014-06-29 23:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks 2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe 2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe 2014-06-12 13:30 - 2014-04-26 20:21 - 00622592 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll 2014-06-12 13:30 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll 2014-06-12 13:30 - 2014-04-05 06:26 - 01417664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2014-06-12 13:30 - 2014-04-05 04:32 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys 2014-06-12 13:30 - 2014-03-10 08:26 - 01869824 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2014-06-12 13:30 - 2014-03-10 08:26 - 01794560 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll 2014-06-12 13:30 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll 2014-06-12 13:30 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll ==================== One Month Modified Files and Folders ======= 2014-07-12 14:57 - 2013-05-06 22:53 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-12 14:56 - 2014-07-12 14:56 - 00018863 _____ () C:\Users\Michi\Desktop\FRST.txt 2014-07-12 14:56 - 2014-07-09 16:07 - 00000000 ____D () C:\FRST 2014-07-12 14:54 - 2014-07-12 14:53 - 00001245 _____ () C:\Users\Michi\Desktop\checkup.txt.txt 2014-07-12 14:47 - 2014-07-12 14:47 - 00854390 _____ () C:\Users\Michi\Desktop\SecurityCheck.exe 2014-07-12 14:42 - 2014-07-11 23:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-12 14:26 - 2014-07-11 13:18 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-12 13:56 - 2013-05-06 22:53 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-12 13:51 - 2013-05-14 23:00 - 01758503 _____ () C:\Windows\WindowsUpdate.log 2014-07-12 13:33 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-12 13:33 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-12 10:35 - 2014-07-11 14:17 - 00000000 ____D () C:\Users\Michi\Desktop\FRST-OlderVersion 2014-07-12 10:34 - 2014-07-12 10:34 - 02347384 _____ (ESET) C:\Users\Michi\Downloads\esetsmartinstaller_deu.exe 2014-07-12 07:33 - 2014-03-13 18:14 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-07-12 07:33 - 2006-11-02 17:40 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-12 02:48 - 2006-11-02 17:40 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-07-11 23:42 - 2014-07-11 23:41 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-07-11 23:42 - 2013-05-07 09:14 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-07-11 23:42 - 2011-10-19 14:08 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-07-11 22:39 - 2012-02-02 03:37 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\TS3Client 2014-07-11 15:20 - 2012-08-16 08:22 - 00001696 _____ () C:\Users\Michi\Desktop\bla.txt 2014-07-11 14:17 - 2014-07-09 16:05 - 02084864 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe 2014-07-11 14:15 - 2014-07-11 14:15 - 00002007 _____ () C:\Users\Michi\Desktop\JRT.txt 2014-07-11 14:05 - 2014-07-11 14:05 - 00000000 ____D () C:\Windows\ERUNT 2014-07-11 14:03 - 2014-07-11 14:03 - 01016261 _____ (Thisisu) C:\Users\Michi\Desktop\JRT.exe 2014-07-11 14:01 - 2014-07-11 14:01 - 00028265 _____ () C:\Users\Michi\Desktop\AdwCleaner[S0].txt 2014-07-11 13:55 - 2014-07-10 18:12 - 00046394 _____ () C:\Windows\PFRO.log 2014-07-11 13:54 - 2014-07-11 13:50 - 00000000 ____D () C:\AdwCleaner 2014-07-11 13:48 - 2014-07-11 13:48 - 00047922 _____ () C:\Users\Michi\Desktop\mbam.txt.txt 2014-07-11 13:42 - 2014-07-11 13:42 - 01348263 _____ () C:\Users\Michi\Desktop\adwcleaner_3.215.exe 2014-07-11 13:35 - 2006-11-02 15:33 - 00000000 ____D () C:\Windows\security 2014-07-11 13:15 - 2014-07-11 13:15 - 00000941 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-07-11 13:13 - 2014-07-11 13:13 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Michi\Downloads\mbam-setup-2.0.2.1012.exe 2014-07-10 17:56 - 2014-07-10 17:56 - 00052795 _____ () C:\ComboFix.txt 2014-07-10 17:56 - 2014-07-10 17:33 - 00000000 ____D () C:\Qoobox 2014-07-10 17:56 - 2006-11-02 15:33 - 00000000 __RHD () C:\Users\Default 2014-07-10 17:54 - 2014-07-10 17:32 - 00000000 ____D () C:\Windows\erdnt 2014-07-10 17:53 - 2011-10-18 16:41 - 00000000 ____D () C:\Users\Michi 2014-07-10 17:53 - 2006-11-02 14:34 - 00000215 _____ () C:\Windows\system.ini 2014-07-10 17:30 - 2014-07-10 17:30 - 05217324 ____R (Swearware) C:\Users\Michi\Desktop\ComboFix.exe 2014-07-10 17:25 - 2014-07-10 17:25 - 00000000 ____D () C:\Program Files (x86)\ProShopperu 2014-07-10 17:25 - 2014-06-08 19:55 - 00000000 ____D () C:\ProgramData\297d856b205d5963 2014-07-10 15:38 - 2014-07-10 15:38 - 00001099 _____ () C:\Users\Michi\Desktop\Revo Uninstaller.lnk 2014-07-10 15:38 - 2014-07-10 15:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-07-10 15:38 - 2014-07-10 15:37 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Michi\Downloads\revosetup95.exe 2014-07-09 14:03 - 2006-11-02 17:21 - 00255776 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-07-09 13:59 - 2006-11-02 17:06 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-09 13:57 - 2013-07-22 05:26 - 00000000 ____D () C:\Windows\system32\MRT 2014-07-09 13:54 - 2006-11-02 14:35 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip 2014-07-07 13:06 - 2014-06-26 15:21 - 00000000 ____D () C:\ProgramData\BitRaider 2014-07-07 12:56 - 2011-10-18 16:41 - 00055560 _____ () C:\Users\Michi\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-07 12:54 - 2011-10-19 16:48 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-07-05 16:05 - 2011-11-22 11:56 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\vlc 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx 2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX 2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx 2014-07-03 14:42 - 2012-05-11 00:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Skype 2014-06-30 06:36 - 2011-10-20 02:44 - 00175616 _____ () C:\Users\Michi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-06-29 23:08 - 2014-06-15 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks 2014-06-27 11:36 - 2013-08-30 14:25 - 00000000 ____D () C:\Users\Michi\Desktop\TS Icons 2014-06-27 11:19 - 2012-02-02 03:35 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client 2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR 2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider 2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk 2014-06-26 14:06 - 2013-07-20 12:23 - 00014744 _____ () C:\Users\Michi\Documents\Install STAR WARS The Old Republic.log 2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts 2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA 2014-06-23 08:33 - 2013-05-06 15:32 - 00001217 _____ () C:\Users\Michi\Desktop\WoW PWS.lnk 2014-06-22 19:39 - 2013-06-26 20:25 - 00050464 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys 2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk 2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment 2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt 2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk 2014-06-20 12:03 - 2014-06-20 12:02 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver 2014-06-17 17:56 - 2012-12-13 10:46 - 00000000 ____D () C:\Filme 2014-06-17 17:56 - 2012-08-25 14:45 - 00000000 ____D () C:\Users\Michi\Desktop\Wma 2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk 2014-06-16 11:00 - 2014-02-03 14:46 - 00155136 _____ () C:\Windows\SysWOW64\unrar.dll 2014-06-16 11:00 - 2014-02-03 14:46 - 00034308 _____ () C:\Windows\SysWOW64\bassmod.dll 2014-06-16 10:57 - 2014-06-16 10:58 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk 2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk 2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt 2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt 2014-06-16 07:18 - 2013-05-12 09:58 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-06-16 07:18 - 2012-01-27 19:49 - 00000000 ____D () C:\Games 2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt 2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt 2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt 2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe 2014-06-15 11:25 - 2013-05-12 18:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Wargaming.net 2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe Some content of TEMP: ==================== C:\Users\Michi\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-12 07:41 ==================== End Of Log ============================ --- --- --- Hi Schrauber nein, bis jetzt keine Probleme das läuft es alles wie geschmiert Hätte vielleicht im Anschluss wenn wir mit der Reise durch meinen verwurschteten PC fertig noch ein paar Fragen Ansonsten ist alles Top - keine Ping Pong Seiten mehr die springen - keine extrem lästige Werbung mehr die das Lesen unmöglich macht - und alles wird super schnell geladen Ihr macht eurem Ruf echt alle Ehre |
13.07.2014, 12:59 | #11 |
/// the machine /// TB-Ausbilder | Dauerhaftes Werbung öffnen macht Surfen fast unmöglich Java und Adobe updaten. Was ist Laufwerk F?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.07.2014, 18:05 | #12 |
| Dauerhaftes Werbung öffnen macht Surfen fast unmöglich Java-Version installiert (Version 7 Update 60) Adobe ist auf dem neusten stand jetzt auch ( wird mir zumindest gesagt ) Ehm Laufwerk F ist ne alte Festplatte aus meinem alten Laptop habe die einfach mit in PC geschoben gab bis jetzt keine Probleme |
14.07.2014, 14:52 | #13 |
/// the machine /// TB-Ausbilder | Dauerhaftes Werbung öffnen macht Surfen fast unmöglich Formatier F, die is voll mit Rotz Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.07.2014, 17:21 | #14 |
| Dauerhaftes Werbung öffnen macht Surfen fast unmöglich Hey Schrauber, also an sich alles Top rennt perfekt alles Gerade mal geschaut wegen solchen Registry Cleanern. Da habe ich eins gefunden. Auslogics heißt das, wollte ich Deinstallieren nur scheitert das irgendwie Ansonsten kann ich dir gar nicht genug Danken und danke für die Tipps im Anschluss werde ich Befolgen |
14.07.2014, 18:17 | #15 |
/// the machine /// TB-Ausbilder | Dauerhaftes Werbung öffnen macht Surfen fast unmöglich Deinstallier mal mit Revo Uninstaller
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |