|
Plagegeister aller Art und deren Bekämpfung: Firefox kommt auf Yahoo 404 - "page not found"Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
14.08.2014, 13:10 | #16 |
/// the machine /// TB-Ausbilder | Firefox kommt auf Yahoo 404 - "page not found" Antivirenprogramme bis auf eines wurden auch deinstalliert? Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.08.2014, 20:45 | #17 |
| Firefox kommt auf Yahoo 404 - "page not found"Code:
ATTFilter ComboFix 14-08-14.02 - User 14.08.2014 15:25:40.2.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8131.6399 [GMT 2:00] ausgeführt von:: c:\users\User\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {4D041356-F94D-285F-8768-AAE50FA36859} SP: Avira Desktop *Disabled/Updated* {F665F2B2-DF77-27D1-BDD8-9197742422E4} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\User\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll . . ((((((((((((((((((((((( Dateien erstellt von 2014-07-14 bis 2014-08-14 )))))))))))))))))))))))))))))) . . 2014-08-14 13:30 . 2014-08-14 13:30 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2014-08-14 13:30 . 2014-08-14 13:30 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-08-14 13:29 . 2014-07-14 02:12 10924376 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{BD76D7C8-B792-4AEE-B6B3-AC73FA707558}\mpengine.dll 2014-08-14 13:20 . 2013-07-02 14:29 24824 ----a-w- c:\windows\system32\drivers\IOMap64.sys 2014-08-11 11:32 . 2014-08-11 11:32 -------- d-----w- c:\users\User\AppData\Roaming\PDAppFlex 2014-08-11 11:31 . 2014-08-11 11:00 -------- d-----w- c:\programdata\regid.1986-12.com.adobe 2014-08-11 11:25 . 2014-08-11 11:25 -------- d-----r- c:\users\User\Creative Cloud Files 2014-08-11 11:20 . 2014-08-11 11:31 -------- d-----w- c:\program files (x86)\Common Files\Adobe 2014-08-11 11:11 . 2004-08-03 21:54 1712128 ----a-w- c:\windows\SysWow64\GdiPlus.dll 2014-08-11 11:00 . 2014-08-11 11:00 56496 ----a-w- C:\kxldapob.sys 2014-08-10 20:44 . 2014-08-11 10:50 -------- d-----w- C:\FRST 2014-08-09 13:14 . 2014-08-09 13:14 -------- d-----w- c:\programdata\Emsisoft 2014-08-09 12:53 . 2014-08-09 12:53 -------- d-----w- c:\users\User\AppData\Roaming\TuneUp Software 2014-08-09 12:52 . 2014-08-09 12:52 -------- d-----w- c:\users\User\AppData\Local\gtk-2.0 2014-08-09 12:52 . 2014-08-09 12:52 -------- d-----w- c:\users\User\.thumbnails 2014-08-09 12:51 . 2014-08-11 11:20 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2014-08-09 12:51 . 2014-08-11 10:48 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2 2014-08-09 12:50 . 2014-08-11 10:51 -------- d-----w- C:\$AVG 2014-08-09 12:50 . 2014-08-11 10:47 -------- d-----w- c:\programdata\AVG2014 2014-08-09 12:50 . 2014-08-09 12:50 -------- d-----w- c:\users\User\AppData\Roaming\Abelssoft 2014-08-09 12:50 . 2014-08-09 12:50 -------- d-----w- c:\programdata\XDMessagingv4 2014-08-09 12:50 . 2014-08-09 12:50 -------- d-----w- c:\users\User\AppData\Local\Abelssoft 2014-08-09 12:49 . 2014-08-09 12:49 -------- d-----w- c:\users\User\AppData\Roaming\DesktopIconGoodgame 2014-08-09 12:49 . 2014-08-09 12:49 -------- d-----w- c:\program files (x86)\CHIP Updater 2014-08-09 12:46 . 2014-08-11 10:47 -------- d-----w- c:\programdata\MFAData 2014-08-09 12:46 . 2014-08-09 12:46 -------- d--h--w- c:\programdata\Common Files 2014-08-09 12:46 . 2014-08-09 12:46 -------- d-----w- c:\users\User\AppData\Local\MFAData 2014-08-09 12:46 . 2014-08-11 11:14 -------- d-----w- c:\users\User\.gimp-2.8 2014-08-09 12:46 . 2014-08-09 12:46 -------- d-----w- c:\users\User\AppData\Local\gegl-0.2 2014-08-09 12:46 . 2014-08-09 12:46 -------- d-----w- c:\users\User\AppData\Local\fontconfig 2014-08-09 12:43 . 2014-08-11 10:48 -------- d-----w- c:\program files (x86)\Emsisoft Anti-Malware 2014-08-09 12:43 . 2014-08-09 12:44 -------- d-----w- c:\program files\GIMP 2 2014-08-08 19:20 . 2014-08-08 18:39 -------- d-----w- c:\users\User\AppData\Roaming\Virtuali 2014-08-08 18:59 . 2014-08-08 18:59 -------- d-----w- c:\users\User\AppData\Local\World_of_AI 2014-08-08 18:41 . 2014-08-08 18:42 -------- d-----w- C:\Gramblr 2014-07-21 16:40 . 2014-01-08 10:59 159008 ----a-w- c:\program files (x86)\Microsoft Games\UIAutomationCore.dll 2014-07-21 16:40 . 2014-01-08 10:59 159008 ----a-w- c:\program files (x86)\Microsoft Games\Microsoft Flight Simulator X\UIAutomationCore.dll 2014-07-21 16:19 . 2014-07-21 16:19 -------- d-----w- c:\program files (x86)\PMDG Operations Center 2014-07-21 16:00 . 2014-07-21 16:00 -------- d-----w- c:\users\User\AppData\Local\DriverToolkit 2014-07-21 15:59 . 2014-07-21 16:05 -------- d-----w- c:\program files (x86)\DriverToolkit 2014-07-21 15:57 . 2014-07-21 15:57 -------- d-----w- c:\users\User\AppData\Local\Skype 2014-07-21 15:56 . 2014-08-09 12:32 -------- d-----w- c:\users\User\AppData\Roaming\Skype 2014-07-21 15:56 . 2014-08-09 13:15 -------- d-----w- c:\programdata\Skype 2014-07-17 09:49 . 2014-07-17 09:49 -------- d-----w- C:\found.000 2014-07-15 19:54 . 2014-07-15 19:54 -------- d-----w- c:\windows\uninstall . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-08-05 07:20 . 2010-11-21 03:27 270496 ------w- c:\windows\system32\MpSigStub.exe 2014-07-17 09:50 . 2014-05-03 07:14 42040 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2014-07-09 20:55 . 2014-05-02 15:58 130584 ----a-w- c:\windows\system32\drivers\avipbb.sys 2014-07-09 20:55 . 2014-05-02 15:58 117712 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2014-06-30 02:09 . 2014-07-09 21:07 519168 ----a-w- c:\windows\system32\aepdu.dll 2014-06-30 02:04 . 2014-07-09 21:07 424448 ----a-w- c:\windows\system32\aeinv.dll 2014-06-26 15:40 . 2014-03-13 11:01 96441528 ----a-w- c:\windows\system32\MRT.exe 2014-06-20 20:14 . 2014-07-09 21:07 266424 ----a-w- c:\windows\system32\iedkcs32.dll 2014-06-19 01:39 . 2014-07-09 21:07 23464448 ----a-w- c:\windows\system32\mshtml.dll 2014-06-19 01:06 . 2014-07-09 21:07 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2014-06-19 01:06 . 2014-07-09 21:07 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2014-06-19 00:48 . 2014-07-09 21:07 2768384 ----a-w- c:\windows\system32\iertutil.dll 2014-06-19 00:42 . 2014-07-09 21:07 548352 ----a-w- c:\windows\system32\vbscript.dll 2014-06-19 00:42 . 2014-07-09 21:07 66048 ----a-w- c:\windows\system32\iesetup.dll 2014-06-19 00:41 . 2014-07-09 21:07 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2014-06-19 00:41 . 2014-07-09 21:07 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2014-06-19 00:32 . 2014-07-09 21:07 51200 ----a-w- c:\windows\system32\jsproxy.dll 2014-06-19 00:31 . 2014-07-09 21:07 33792 ----a-w- c:\windows\system32\iernonce.dll 2014-06-19 00:26 . 2014-07-09 21:07 598016 ----a-w- c:\windows\system32\ieui.dll 2014-06-19 00:24 . 2014-07-09 21:07 139264 ----a-w- c:\windows\system32\ieUnatt.exe 2014-06-19 00:24 . 2014-07-09 21:07 111616 ----a-w- c:\windows\system32\ieetwcollector.exe 2014-06-19 00:23 . 2014-07-09 21:07 752640 ----a-w- c:\windows\system32\jscript9diag.dll 2014-06-19 00:14 . 2014-07-09 21:07 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2014-06-19 00:09 . 2014-07-09 21:07 452608 ----a-w- c:\windows\system32\dxtmsft.dll 2014-06-18 23:59 . 2014-07-09 21:07 38400 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2014-06-18 23:56 . 2014-07-09 21:07 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2014-06-18 23:53 . 2014-07-09 21:07 195584 ----a-w- c:\windows\system32\msrating.dll 2014-06-18 23:51 . 2014-07-09 21:07 5721088 ----a-w- c:\windows\system32\jscript9.dll 2014-06-18 23:50 . 2014-07-09 21:07 85504 ----a-w- c:\windows\system32\mshtmled.dll 2014-06-18 23:48 . 2014-07-09 21:07 292864 ----a-w- c:\windows\system32\dxtrans.dll 2014-06-18 23:39 . 2014-07-09 21:07 608768 ----a-w- c:\windows\system32\ie4uinit.exe 2014-06-18 23:38 . 2014-07-09 21:07 455168 ----a-w- c:\windows\SysWow64\vbscript.dll 2014-06-18 23:37 . 2014-07-09 21:07 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2014-06-18 23:36 . 2014-07-09 21:07 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2014-06-18 23:35 . 2014-07-09 21:07 62464 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2014-06-18 23:33 . 2014-07-09 21:07 631808 ----a-w- c:\windows\system32\msfeeds.dll 2014-06-18 23:27 . 2014-07-09 21:07 1249280 ----a-w- c:\windows\system32\mshtmlmedia.dll 2014-06-18 23:27 . 2014-07-09 21:07 2040832 ----a-w- c:\windows\system32\inetcpl.cpl 2014-06-18 23:23 . 2014-07-09 21:07 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2014-06-18 23:22 . 2014-07-09 21:07 592896 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2014-06-18 23:06 . 2014-07-09 21:07 32256 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2014-06-18 22:58 . 2014-07-09 21:07 2266112 ----a-w- c:\windows\system32\wininet.dll 2014-06-18 22:52 . 2014-07-09 21:07 4254720 ----a-w- c:\windows\SysWow64\jscript9.dll 2014-06-18 22:51 . 2014-07-09 21:07 13527040 ----a-w- c:\windows\system32\ieframe.dll 2014-06-18 22:46 . 2014-07-09 21:07 1068032 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2014-06-18 22:45 . 2014-07-09 21:07 1964544 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2014-06-18 22:34 . 2014-07-09 21:07 1393664 ----a-w- c:\windows\system32\urlmon.dll 2014-06-18 22:15 . 2014-07-09 21:07 846336 ----a-w- c:\windows\system32\ieapfltr.dll 2014-06-18 22:13 . 2014-07-09 21:07 1791488 ----a-w- c:\windows\SysWow64\wininet.dll 2014-06-18 02:18 . 2014-07-09 21:07 692736 ----a-w- c:\windows\system32\osk.exe 2014-06-18 01:51 . 2014-07-09 21:07 646144 ----a-w- c:\windows\SysWow64\osk.exe 2014-06-18 01:10 . 2014-07-09 21:07 3157504 ----a-w- c:\windows\system32\win32k.sys 2014-06-06 10:10 . 2014-07-09 21:07 624128 ----a-w- c:\windows\system32\qedit.dll 2014-06-06 09:44 . 2014-07-09 21:07 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2014-06-05 14:45 . 2014-07-09 21:06 1460736 ----a-w- c:\windows\system32\lsasrv.dll 2014-06-05 14:26 . 2014-07-09 21:06 22016 ----a-w- c:\windows\SysWow64\secur32.dll 2014-06-05 14:25 . 2014-07-09 21:06 96768 ----a-w- c:\windows\SysWow64\sspicli.dll 2014-05-30 08:08 . 2014-07-09 21:07 210944 ----a-w- c:\windows\system32\wdigest.dll 2014-05-30 08:08 . 2014-07-09 21:07 86528 ----a-w- c:\windows\system32\TSpkg.dll 2014-05-30 08:08 . 2014-07-09 21:07 340992 ----a-w- c:\windows\system32\schannel.dll 2014-05-30 08:08 . 2014-07-09 21:07 314880 ----a-w- c:\windows\system32\msv1_0.dll 2014-05-30 08:08 . 2014-07-09 21:07 307200 ----a-w- c:\windows\system32\ncrypt.dll 2014-05-30 08:08 . 2014-07-09 21:07 728064 ----a-w- c:\windows\system32\kerberos.dll 2014-05-30 08:08 . 2014-07-09 21:07 22016 ----a-w- c:\windows\system32\credssp.dll 2014-05-30 07:52 . 2014-07-09 21:07 172032 ----a-w- c:\windows\SysWow64\wdigest.dll 2014-05-30 07:52 . 2014-07-09 21:07 65536 ----a-w- c:\windows\SysWow64\TSpkg.dll 2014-05-30 07:52 . 2014-07-09 21:07 247808 ----a-w- c:\windows\SysWow64\schannel.dll 2014-05-30 07:52 . 2014-07-09 21:07 220160 ----a-w- c:\windows\SysWow64\ncrypt.dll 2014-05-30 07:52 . 2014-07-09 21:07 259584 ----a-w- c:\windows\SysWow64\msv1_0.dll 2014-05-30 07:52 . 2014-07-09 21:07 550912 ----a-w- c:\windows\SysWow64\kerberos.dll 2014-05-30 07:52 . 2014-07-09 21:07 17408 ----a-w- c:\windows\SysWow64\credssp.dll 2014-05-30 06:45 . 2014-07-09 21:07 497152 ----a-w- c:\windows\system32\drivers\afd.sys 2014-05-29 23:07 . 2014-07-09 18:48 1291232 ----a-w- c:\windows\SysWow64\nvspbridge.dll 2014-05-29 23:07 . 2014-05-09 14:38 1122312 ----a-w- c:\windows\SysWow64\nvspcap.dll 2014-05-29 23:07 . 2014-07-09 18:48 1715176 ----a-w- c:\windows\system32\nvspbridge64.dll 2014-05-29 23:07 . 2014-05-09 14:38 1279480 ----a-w- c:\windows\system32\nvspcap64.dll 2014-05-20 02:44 . 2014-07-09 18:51 9697640 ----a-w- c:\windows\SysWow64\nvopencl.dll 2014-05-20 02:44 . 2014-07-09 18:51 837056 ----a-w- c:\windows\SysWow64\nvumdshim.dll 2014-05-20 02:44 . 2014-07-09 18:51 354016 ----a-w- c:\windows\system32\nvoglshim64.dll 2014-05-20 02:44 . 2014-07-09 18:51 31387936 ----a-w- c:\windows\system32\nvoglv64.dll 2014-05-20 02:44 . 2014-07-09 18:51 305600 ----a-w- c:\windows\SysWow64\nvoglshim32.dll 2014-05-20 02:44 . 2014-07-09 18:51 24025376 ----a-w- c:\windows\SysWow64\nvoglv32.dll 2014-05-20 02:44 . 2014-07-09 18:51 16003912 ----a-w- c:\windows\SysWow64\nvwgf2um.dll 2014-05-20 02:44 . 2014-07-09 18:51 11599072 ----a-w- c:\windows\system32\nvopencl.dll 2014-05-20 02:44 . 2014-07-09 18:51 9735256 ----a-w- c:\windows\SysWow64\nvcuda.dll 2014-05-20 02:44 . 2014-07-09 18:51 895776 ----a-w- c:\windows\system32\NvIFR64.dll 2014-05-20 02:44 . 2014-07-09 18:51 892704 ----a-w- c:\windows\system32\NvFBC64.dll 2014-05-20 02:44 . 2014-07-09 18:51 867784 ----a-w- c:\windows\SysWow64\NvIFR.dll 2014-05-20 02:44 . 2014-07-09 18:51 861128 ----a-w- c:\windows\SysWow64\NvFBC.dll 2014-05-20 02:44 . 2014-07-09 18:51 492376 ----a-w- c:\windows\system32\nvEncodeAPI64.dll 2014-05-20 02:44 . 2014-07-09 18:51 416712 ----a-w- c:\windows\SysWow64\nvEncodeAPI.dll 2014-05-20 02:44 . 2014-07-09 18:51 382240 ----a-w- c:\windows\system32\NvIFROpenGL.dll 2014-05-20 02:44 . 2014-07-09 18:51 335704 ----a-w- c:\windows\SysWow64\NvIFROpenGL.dll 2014-05-20 02:44 . 2014-07-09 18:51 3141976 ----a-w- c:\windows\system32\nvcuvid.dll 2014-05-20 02:44 . 2014-07-09 18:51 2953672 ----a-w- c:\windows\SysWow64\nvcuvid.dll 2014-05-20 02:44 . 2014-07-09 18:51 2785568 ----a-w- c:\windows\system32\nvcuvenc.dll 2014-05-20 02:44 . 2014-07-09 18:51 2412376 ----a-w- c:\windows\SysWow64\nvcuvenc.dll 2014-05-20 02:44 . 2014-07-09 18:51 1889112 ----a-w- c:\windows\system32\nvdispco6433788.dll 2014-05-20 02:44 . 2014-07-09 18:51 17480432 ----a-w- c:\windows\system32\nvd3dumx.dll 2014-05-20 02:44 . 2014-07-09 18:51 166568 ----a-w- c:\windows\system32\nvinitx.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2014-07-21 751184] "USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2013-12-21 292848] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720] "Avira Systray"="c:\program files (x86)\Avira\My Avira\Avira.OE.Systray.exe" [2014-07-24 190032] "Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2014-07-22 2694040] . c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-7-30 36414496] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . R0 PxHlpa64;PxHlpa64;c:\windows\System32\drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\drivers\PxHlpa64.sys [x] R2 Avira.OE.ServiceHost;Avira Service Host;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe;c:\program files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 Apowersoft_AudioDevice;Apowersoft_AudioDevice;c:\windows\system32\drivers\Apowersoft_AudioDevice.sys;c:\windows\SYSNATIVE\drivers\Apowersoft_AudioDevice.sys [x] R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x] R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x] R3 btath_avdt;Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x] R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x] R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x] R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x] R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x] R3 cleanhlp;cleanhlp;c:\program files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys;c:\program files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [x] R3 cpuz137;cpuz137;c:\windows\TEMP\cpuz137\cpuz137_x64.sys;c:\windows\TEMP\cpuz137\cpuz137_x64.sys [x] R3 GPUZ;GPUZ;c:\windows\TEMP\GPUZ.sys;c:\windows\TEMP\GPUZ.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S0 asahci64;asahci64;c:\windows\system32\DRIVERS\asahci64.sys;c:\windows\SYSNATIVE\DRIVERS\asahci64.sys [x] S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x] S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x] S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S2 AdobeActiveFileMonitor12.0;Adobe Active File Monitor V12;c:\program files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe;c:\program files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe;c:\program files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [x] S2 ASGT;ASGT;c:\windows\SysWOW64\ASGT.exe;c:\windows\SysWOW64\ASGT.exe [x] S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x] S2 DTSAudioSvc;DTSAudioSvc;c:\program files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe;c:\program files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe;c:\windows\SYSNATIVE\IProsetMonitor.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 ZAtheros Bt and Wlan Coex Agent;ZAtheros Bt and Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x] S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x] S3 e1dexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver D;c:\windows\system32\DRIVERS\e1d62x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1d62x64.sys [x] S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x] S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x] S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S4 IOMap;IOMap;c:\windows\system32\drivers\IOMap64.sys;c:\windows\SYSNATIVE\drivers\IOMap64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-08-14 14:04 1104200 ----a-w- c:\program files (x86)\Google\Chrome\Application\36.0.1985.143\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-05-09 16:32] . 2014-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-05-09 16:32] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1] @="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}" [HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}] 2014-07-16 09:06 672416 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2] @="{853B7E05-C47D-4985-909A-D0DC5C6D7303}" [HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}] 2014-07-16 09:06 672416 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3] @="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}" [HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}] 2014-07-16 09:06 672416 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 164760 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 164760 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"] @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 164760 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"] @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 164760 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 164760 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"] @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 164760 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 164760 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"] @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}] 2014-06-24 21:08 164760 ----a-w- c:\users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2013-08-19 7202520] "RtHDVBg_DTS"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2013-08-07 1321688] "IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2013-08-07 36352] "AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\btvstack.exe" [2012-11-29 1023104] "AthBtTray"="c:\program files (x86)\Bluetooth Suite\athbttray.exe" [2012-11-29 801920] "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-05-29 1279480] "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-05-29 2352072] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2014-02-27 558496] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyServer = localhost:8080 IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 62.2.17.60 62.2.24.162 62.2.17.61 62.2.24.158 FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\l2fwmsro.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - www.google.ch . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_206_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_206_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_206_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_206_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.13" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_206.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe c:\program files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe c:\program files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe c:\program files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe c:\users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-08-14 15:25:26 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-08-14 13:25 ComboFix2.txt 2014-08-14 13:29 . Vor Suchlauf: 23 Verzeichnis(se), 1.433.384.255.488 Bytes frei Nach Suchlauf: 24 Verzeichnis(se), 1.433.234.800.640 Bytes frei . - - End Of File - - 6B47EA65CCD8F48EF1DDA5B197D50A30 A36C5E4F47E84449FF07ED3517B43A31 |
15.08.2014, 18:51 | #18 |
/// the machine /// TB-Ausbilder | Firefox kommt auf Yahoo 404 - "page not found" Downloade Dir bitte Malwarebytes Anti-Malware
__________________
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
15.08.2014, 20:46 | #19 |
| Firefox kommt auf Yahoo 404 - "page not found"Code:
ATTFilter # AdwCleaner v3.305 - Bericht erstellt am 15/08/2014 um 11:33:41 # Aktualisiert 14/08/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : User - USER-PC # Gestartet von : C:\Users\User\Downloads\adwcleaner_3.305.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gelöscht : C:\Windows\System32\roboot64.exe ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600} Schlüssel Gelöscht : HKCU\Software\OCS ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17239 -\\ Mozilla Firefox v31.0 (x86 de) [ Datei : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\l2fwmsro.default\prefs.js ] -\\ Google Chrome v36.0.1985.143 [ Datei : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3314958&octid=EB_ORIGINAL_CTID&ISID=M08B9858D-D8A3-4271-B7F7-468961097011&SearchSource=58&CUI=&UM=6&UP=SP933714E8-184D-44EC-808D-571B33A3068E&q={searchTerms}&SSPV= ************************* AdwCleaner[R0].txt - [1468 octets] - [15/08/2014 11:33:22] AdwCleaner[S0].txt - [1343 octets] - [15/08/2014 11:33:41] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1403 octets] ########## Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 15.08.2014 Suchlauf-Zeit: 11:17:08 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.08.15.09 Rootkit Datenbank: v2014.08.04.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: User Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 359316 Verstrichene Zeit: 13 Min, 7 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 1 PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [3fa6a620f5867db96e7e12589c6625db], Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 2 PUP.Optional.Trovi.A, C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\l2fwmsro.default\searchplugins\trovi-search.xml, In Quarantäne, [4a9b477fafcc58dece820be94bb70af6], PUP.Optional.Trovi, C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ({"apps":{"shortcuts_have_been_created":true},"browser":{"check_default_browser":true,"clear_data":{"content_licenses":true,"form_data":true,"hosted_apps_data":true,"passwords":true,"time_period":4},"clear_lso_data_enabled":true,"last_clear_browsing_data_time":"13050064345582708","last_known_google_url":"https://www.google.ch/","last_prompted_google_url":"https://www.google.ch/","pepper_flash_settings_enabled":true,"show_home_button":true,"window_placement":{"bottom":1089,"left":330,"maximized":true,"right":1275,"top":69,"work_area_bottom":1040,"work_area_left":0,"work_area_right":1920,"work_area_top":0}},"countryid_at_install":17477,"default_apps_install_state":3,"default_search_provider":{"enabled":true,"id":"1","suggest_url":"hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms}","synced_guid":"D2B35E3E-83E2-4EF7-8FB0-3E2D596DD2C6"},"default_search_provider_data":{"template_url_data":{"alternate_urls":[],"created_by_policy":false,"date_created":"13051997891998208","favicon_url":"","id":"1","image_url":"","image_url_post_params":"","input_encodings":[],"instant_url":"","instant_url_post_params":"","keyword":"trovi.search","last_modified":"13051997891998208","new_tab_url":"","originating_url":"","prepopulate_id":0,"safe_for_autoreplace":false,"search_terms_replacement_key":"","search_url_post_params":"","short_name":"Trovi search","suggestions_url":"http:\/\/suggest.seccint.com\/CSuggestJson.ashx?prefix={searchTerms}","suggestions_url_post_params":"","synced_guid":"D2B35E3E-83E2-4EF7-8FB0-3E2D596DD2C6","url":"http:\/\/www.trovi.com\/Results.aspx?gd=&ctid=CT3314958&octid=EB_ORIGINAL_CTID&ISID=M08B9858D-D8A3-4271-B7F7-468961097011&SearchSource=58&CUI=&UM=6&UP=SP933714E8-184D-44EC-808D-571B33A3068E&q={searchTerms}&SSPV=","usage_count":0}},"distribution":{"create_all_shortcuts":true,"do_not_launch_chrome":true,"import_history":false,"import_search_engine":false,"make_chrome_default":true,"ping_delay":-60,"skip_first_run_ui":false,"verbose_logging":false},"dns_prefetching":{"host_referral_list":[2,["hxxp://admin.flightm.com/",["hxxp://www.flightm.com/",2.6037003999999997]],["hxxp://clkrev.com/",["hxxp://cdn1.clkrev.com/",3.1714050174239996,"hxxp://clkrev.com/",2.529573049612]],["hxxp://thepiratebay.ee/",["hxxp://clkrev.com/",3.4923210013299997,"hxxp://thepiratebay.ee/",4.775984936953999,"hxxp://www.google-analytics.com/",2.529573049612]],["hxxp://www.flightm.com/",["hxxp://ajax.googleapis.com/",1.2384095693862427,"hxxp://fonts.googleapis.com/",1.2384095693862427,"hxxp://themes.googleusercontent.com/",1.2384095693862427,"hxxp://www.flightm.com/",10.351761144700395,"https://www.flightm.com/",1.5687297693862425]],["hxxp://www.flightx.net/",["hxxp://flightx.net/",2.025335319191497]],["hxxp://www.trovi.com/",["hxxp://resources.trovi.com/",3.18201594682567,"hxxp://storage.stgbssint.com/",0.902812938141093]],["https://ch.search.yahoo.com/",["https://ad.yieldmanager.com/",2.084686339270529,"https://cdnk.interclick.com/",2.084686339270529,"https://csync.yahooapis.com/",2.084686339270529,"https://ec.yimg.com/",1.6396244539792004,"https://s.yimg.com/",5.507966632655697]]],"startup_list":[1,"hxxp://admin.flightm.com/","hxxp://resources.trovi.com/","hxxp://storage.stgbssint.com/","hxxp://suggest.seccint.com/","hxxp://www.flightm.com/","hxxp://www.trovi.com/","https://chrome.google.com/","https://clients2.google.com/","https://clients2.googleusercontent.com/","https://www.googleapis.com/"]},"download":{"directory_upgrade":true},"extensions":{"alerts":{"initialized":true},"autoupdate":{"last_check":"13049405996589757","next_check":"13051998936861208"},"blacklistupdate":{"lastpingday":"13044092393247248","version":"0.0.0.149"},"chrome_url_overrides":{"bookmarks":["chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html"]},"install_signature":{"expire_date":"2014-11-01","ids":["aohghmighlieiainnegkcijnfilokake","lifbcibllhkdhoafpjfnlhfpfgnpldfl","mkfokfffehpeedafpekjeddnmnjhmcmk"],"invalid_ids":[],"salt":"e3icY/bEPI4U0EgUwi9r3K7xJwq9LrJAWXhSqu6sB54=","signature":"BfGXw5jTjCR2aUKriYrgOBT+1mn9xq3kH7coTPXh/8D5UWpMtpVdBGr6R6ZvZQpBd8c0vaELDQT6niPyr7wQORjQJwtaye5P+IJHkA3tdjKgSE4/AicPAJJVl59rH7LydIG0RAjm3Tn6Sp2jyczhe9QC2ZcZAmYuhsA8C5ArXrN5V1yH/SsEu7ZYse+X49bfwGzZICBMi/P38w7c0stJhKf5t+K7iEhU3IvoY4vnaugUZBgDRGqQ90CsSbMYBJI5fW/e5v8bct15D4IqHOX2A4DAgkmYRc/eD5cSkv+ouMc/V1ddL0CZkd/U7YgJf72UJObBsN8lI724FOYwmYQBWg==","signature_format_version":2,"timestamp":"13051997901545329"},"known_disabled":["lifbcibllhkdhoafpjfnlhfpfgnpldfl","mkfokfffehpeedafpekjeddnmnjhmcmk"],"last_chrome_version":"36.0.1985.125","settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","webstorePrivate"],"manifest_permissions":[]},"app_launcher_ordinal":"n","creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"install_time":"13044126764569239","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Chrome Web Store","icons":{"128":"webstore_icon_128.png","16":"webstore_icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB","name":"Store","permissions":["webstorePrivate","management"],"version":"0.2"},"page_ordinal":"n","path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\29.0.1547.66\\resources\\web_store","was_installed_by_default":false},"aohghmighlieiainnegkcijnfilokake":{"ack_external":true,"active_permissions":{"api":[],"manifest_permissions":[]},"app_launcher_ordinal":"w","content_settings":[],"creation_flags":137,"events":[],"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":[],"manifest_permissions":[]},"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13049413825196199","lastpingday":"13051978741602329","location":1,"manifest":{"api_console_project_id":"619683526622","app":{"launch":{"local_path":"main.html"}},"container":"GOOGLE_DRIVE","current_locale":"de","default_locale":"en_US","description":"Dokumente erstellen und bearbeiten","icons":{"128":"icon_128.png","16":"icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDJhLK6fk/BWTEvJhywpk7jDe4A2r0bGXGOLZW4/AdBp3IiD9o9nx4YjLAtv0tIPxi7MvFd/GUUbQBwHT5wQWONJj1z/0Rc2qBkiJA0yqXh42p0snuA8dCfdlhOLsp7/XTMEwAVasjV5hC4awl78eKfJYlZ+8fM/UldLWJ/51iBQwIDAQAB","manifest_version":2,"name":"Google Docs","offline_enabled":true,"update_url":"https://clients2.google.com/service/update2/crx","version":"0.7"},"page_ordinal":"n","path":"aohghmighlieiainnegkcijnfilokake\\0.7_0","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":true,"was_installed_by_oem":false},"apdfllckaahabafndbhieahigkjlhalf":{"ack_external":true,"active_permissions":{"api":["background","clipboardRead","clipboardWrite","notifications","unlimitedStorage"],"manifest_permissions":[]},"app_launcher_ordinal":"y","content_settings":[],"creation_flags":137,"events":[],"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["background","clipboardRead","clipboardWrite","notifications","unlimitedStorage"],"manifest_permissions":[]},"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13049413824190199","lastpingday":"13051978741602329","location":1,"manifest":{"app":{"launch":{"web_url":"https://drive.google.com/?usp=chrome_app"},"urls":["hxxp://docs.google.com/","hxxp://drive.google.com/","https://docs.google.com/","https://drive.google.com/"]},"background":{"allow_js_access":false},"current_locale":"de","default_locale":"en_US","description":"Google Drive: Alle Inhalte an einem Ort erstellen, teilen und speichern.","icons":{"128":"128.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIl5KlKwL2TSkntkpY3naLLz5jsN0YwjhZyObcTOK6Nda4Ie21KRqZau9lx5SHcLh7pE2/S9OiArb+na2dn7YK5EvH+aRXS1ec3uxVlBhqLdnleVgwgwlg5fH95I52IeHcoeK6pR4hW/Nv39GNlI/Uqk6O6GBCCsAxYrdxww9BiQIDAQAB","manifest_version":2,"name":"Google Drive","offline_enabled":true,"options_page":"https://drive.google.com/settings","permissions":["background","clipboardRead","clipboardWrite","notifications","unlimitedStorage"],"update_url":"hxxp://clients2.google.com/service/update2/crx","version":"6.3"},"page_ordinal":"n","path":"apdfllckaahabafndbhieahigkjlhalf\\6.3_0","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":true,"was_installed_by_oem":false},"blpcfgokakmgnkcojhhkbfbldkacnbeo":{"ack_external":true,"active_permissions":{"api":[],"manifest_permissions":[]},"app_launcher_ordinal":"z","creation_flags":153,"events":[],"from_bookmark":true,"from_webstore":true,"granted_permissions":{"api":[],"manifest_permissions":[]},"install_time":"13044126767875248","lastpingday":"13051978741602329","location":1,"manifest":{"app":{"launch":{"container":"tab","web_url":"hxxp://www.youtube.com/?feature=ytca"},"web_content":{"enabled":true,"origin":"hxxp://www.youtube.com"}},"current_locale":"de","default_locale":"en","description":"Die beliebteste Online-Video-Community der Welt","icons":{"128":"128.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDC/HotmFlyuz5FaHaIbVBhhL4BwbcUtsfWwzgUMpZt5ZsLB2nW/Y5xwNkkPANYGdVsJkT2GPpRRIKBO5QiJ7jPMa3EZtcZHpkygBlQLSjMhdrAKevpKgIl6YTkwzNvExY6rzVDzeE9zqnIs33eppY4S5QcoALMxuSWlMKqgFQjHQIDAQAB","manifest_version":2,"name":"YouTube","permissions":["appNotifications"],"update_url":"hxxp://clients2.google.com/service/update2/crx","version":"4.2.6"},"page_ordinal":"n","path":"blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0","state":1,"was_installed_by_default":true},"booedmolknjekdopkepjjeckmjkdpfgl":{"active_permissions":{"api":["tabs","webNavigation","webRequest","webRequestBlocking"],"explicit_host":["chrome://newtab/*","chrome://settings-frame/*","hxxp://*/*","https://*/*"],"manifest_permissions":[],"scriptable_host":["chrome://settings-frame/*"]},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13049413811973196","location":5,"manifest":{"background":{"persistent":true,"scripts":["bk.js"]},"content_scripts":[{"js":["cs.js"],"matches":["chrome://settings-frame/*"]}],"content_security_policy":"default-src 'self'; script-src chrome://resources 'self' chrome://settings-frame 'unsafe-eval'; frame-src 'self' chrome://settings-frame; style-src 'self' 'unsafe-inline';object-src 'self';","description":"Extutil","incognito":"spanning","key":"MIAfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQcByy+ea9jzazWF/DPn7NW47sW7lgmpk6eKc0BQM18q8hvEM3zNm2n7HkJv/R6fU+X5mtqkDuKvq5skF6qqUF4oEyaleWDFhd1xFwV7JV+/DU7bZ00w2+6gzqsabkerFpoP33ZRIw7OviJenP0c0uWqDWF8EGSyMhB3txqhOtiQIDAQAB","manifest_version":2,"name":"Extutil","permissions":["chrome://newtab/","tabs","webNavigation","webRequest","webRequestBlocking","hxxp://*/*","https://*/*","chrome://settings-frame/"],"version":"0.1"},"path":"C:\\Users\\User\\AppData\\Local\\Temp\\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"coobgpohoikkiipiblmjeljniedjpjpf":{"ack_external":true,"active_permissions":{"api":[],"manifest_permissions":[]},"app_launcher_ordinal":"yn","content_settings":[],"creation_flags":153,"events":[],"from_bookmark":true,"from_webstore":true,"granted_permissions":{"api":[],"manifest_permissions":[]},"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13049413823380199","lastpingday":"13051978741602329","location":1,"manifest":{"app":{"launch":{"web_url":"hxxp://www.google.com/webhp?source=search_app"},"urls":["*://www.google.com/search","*://www.google.com/webhp","*://www.google.com/imgres"]},"current_locale":"de","default_locale":"en","description":"Die schnellste Suche im Web.","icons":{"128":"128.png","16":"16.png","32":"32.png","48":"48.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDIiso3Loy5VJHL40shGhUl6it5ZG55XB9q/2EX6aa88jAxwPutbCgy5d9bm1YmBzLfSgpX4xcpgTU08ydWbd7b50fbkLsqWl1mRhxoqnN01kuNfv9Hbz9dWWYd+O4ZfD3L2XZs0wQqo0y6k64n+qeLkUMd1MIhf6MR8Xz1SOA8pwIDAQAB","manifest_version":2,"name":"Google-Suche","permissions":[],"update_url":"hxxp://clients2.google.com/service/update2/crx","version":"0.0.0.20"},"page_ordinal":"n","path":"coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":true,"was_installed_by_oem":false},"eemcgdkfndhakfknompkggombfjjjeno":{"active_permissions":{"api":["bookmarks","bookmarkManagerPrivate","metricsPrivate","systemPrivate","tabs"],"explicit_host":["chrome://favicon/*","chrome://resources/*"],"manifest_permissions":[]},"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"initial_keybindings_set":true,"install_time":"13044126764568239","location":5,"manifest":{"chrome_url_overrides":{"bookmarks":"main.html"},"content_security_policy":"object-src 'none'; script-src chrome://resources 'self'","description":"Bookmark Manager","incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQcByy+eN9jzazWF/DPn7NW47sW7lgmpk6eKc0BQM18q8hvEM3zNm2n7HkJv/R6fU+X5mtqkDuKvq5skF6qqUF4oEyaleWDFhd1xFwV7JV+/DU7bZ00w2+6gzqsabkerFpoP33ZRIw7OviJenP0c0uWqDWF8EGSyMhB3txqhOtiQIDAQAB","manifest_version":2,"name":"Bookmark Manager","permissions":["bookmarks","bookmarkManagerPrivate","metricsPrivate","systemPrivate","tabs","chrome://favicon/","chrome://resources/"],"version":"0.1"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\29.0.1547.66\\resources\\bookmark_manager","was_installed_by_default":false},"ennkphjdgehloodpbhlhldgbnhmacadg":{"active_permissions":{"api":[],"explicit_host":["chrome://settings-frame/*"],"manifest_permissions":[]},"creation_flags":1,"events":["app.runtime.onLaunched"],"from_bookmark":false,"from_webstore":false,"initial_keybindings_set":true,"install_time":"13044126764569239","location":5,"manifest":{"app":{"background":{"scripts":["settings_app.js"]}},"description":"Settings","display_in_launcher":false,"icons":{"128":"settings_app_icon_128.png","16":"settings_app_icon_16.png","32":"settings_app_icon_32.png","48":"settings_app_icon_48.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDoVDPGX6fvKPVVgc+gnkYlGqHuuapgFDyKhsy4z7UzRLO/95zXPv8h8e5EacqbAQJLUbP6DERH5jowyNEYVxq9GJyntJMwP1ejvoz/52hnY3CCGGCmttmKzzpp5zwLuq3iZf8bslwywfflNUYtaCFSDa0TtrBZz0aOPrAAd/AhNwIDAQAB","manifest_version":2,"name":"Settings","permissions":["chrome://settings-frame/"],"version":"0.2"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\29.0.1547.66\\resources\\settings_app","running":false,"was_installed_by_default":false},"flpcjncodpafbgdpnkljologafpionhb":{"active_permissions":{"api":["tabs","webNavigation"],"explicit_host":["chrome://favicon/*","chrome://resources/*","chrome://settings-frame/*","hxxp://*.conduit.com/*","hxxp://*.devqaguard-search.com/*","hxxp://*.devtrovi.com/*","hxxp://*.devtrovigo.com/*","hxxp://*.guard-search.com/*","hxxp://*.qaautoguard-search.com/*","hxxp://*.qaautotrovi.com/*","hxxp://*.qaautotrovigo.com/*","hxxp://*.qaguard-search.com/*","hxxp://*.qasite-auto.com/*","hxxp://*.qasite.com/*","hxxp://*.qatrovi.com/*","hxxp://*.qatrovigo.com/*","hxxp://*.search.site.com/*","hxxp://*.trovi.com/*","hxxp://*.trovigo.com/*","hxxp://*/*","https://*/*"],"manifest_permissions":[],"scriptable_host":["chrome://settings-frame/*","hxxp://*.conduit.com/*","hxxp://*.devqaguard-search.com/*","hxxp://*.devtrovi.com/*","hxxp://*.devtrovigo.com/*","hxxp://*.guard-search.com/*","hxxp://*.qaautoguard-search.com/*","hxxp://*.qaautotrovi.com/*","hxxp://*.qaautotrovigo.com/*","hxxp://*.qaguard-search.com/*","hxxp://*.qasite-auto.com/*","hxxp://*.qasite.com/*","hxxp://*.qatrovi.com/*","hxxp://*.qatrovigo.com/*","hxxp://*.search.site.com/*","hxxp://*.trovi.com/*","hxxp://*.trovigo.com/*"]},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13049413811983196","location":5,"manifest":{"background":{"page":"background___background.html","persistent":true},"content_scripts":[{"js":["cs.js"],"matches":["hxxp://*.conduit.com/*","hxxp://*.qasite.com/*","hxxp://*.qasite-auto.com/*","hxxp://*.qatrovi.com/*","hxxp://*.trovi.com/*","hxxp://*.devtrovi.com/*","hxxp://*.devtrovigo.com/*","hxxp://*.qaautotrovi.com/*","hxxp://*.qaautotrovigo.com/*","hxxp://*.trovigo.com/*","hxxp://*.qatrovigo.com/*","hxxp://*.guard-search.com/*","hxxp://*.qaguard-search.com/*","hxxp://*.devqaguard-search.com/*","hxxp://*.qaautoguard-search.com/*","hxxp://*.search.site.com/*","chrome://settings-frame/*"]}],"content_security_policy":"default-src 'self'; script-src chrome://resources 'self' chrome://settings-frame 'unsafe-eval'; frame-src 'self' chrome://settings-frame; style-src 'self' 'unsafe-inline';object-src 'self';","description":"Managera","incognito":"spanning","key":"MIAfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQcByy+eN9jzazWF/DPn7NW47sW7lgmpk6eKc0BQM18q8hvEM3zNm2n7HkJv/R6fU+X5mtqkDuKvq5skF6qqUF4oEyaleWDFhd1xFwV7JV+/DU7bZ00w2+6gzqsabkerFpoP33ZRIw7OviJenP0c0uWqDWF8EGSyMhB3txqhOtiQIDAQAB","manifest_version":2,"name":"Managera","permissions":["tabs","webNavigation","hxxp://*.conduit.com/*","hxxp://*.qasite.com/*","hxxp://*.qasite-auto.com/*","hxxp://*.qatrovi.com/*","hxxp://*.trovi.com/*","hxxp://*.devtrovi.com/*","hxxp://*.devtrovigo.com/*","hxxp://*.qaautotrovi.com/*","hxxp://*.qaautotrovigo.com/*","hxxp://*.trovigo.com/*","hxxp://*.qatrovigo.com/*","hxxp://*.guard-search.com/*","hxxp://*.qaguard-search.com/*","hxxp://*.devqaguard-search.com/*","hxxp://*.qaautoguard-search.com/*","hxxp://*.search.site.com/*","chrome://favicon/","chrome://resources/","chrome://settings-frame/","chrome://resources/","hxxp://*/*","https://*/*"],"version":"0.1"},"path":"C:\\Users\\User\\AppData\\Local\\Temp\\38fdaae5-8e0e-493c-88ec-e05c3be06e42","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"gfdkimpbcpahaombhbimeihdjnejgicl":{"active_permissions":{"api":["feedbackPrivate"],"explicit_host":["chrome://resources/*"],"manifest_permissions":[]},"content_settings":[],"creation_flags":1,"events":["feedbackPrivate.onFeedbackRequested"],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13049413811063196","location":5,"manifest":{"app":{"background":{"scripts":["js/event_handler.js"]},"content_security_policy":"default-src 'none'; script-src 'self' chrome://resources; style-src 'unsafe-inline' *; img-src *; media-src 'self'"},"description":"User feedback extension","display_in_launcher":false,"display_in_new_tab_page":false,"icons":{"32":"http://www.trojaner-board.de/images/...":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\feedback","preferences":{},"regular_only_preferences":{},"running":false,"was_installed_by_default":false,"was_installed_by_oem":false},"kmendfapggjehodndflmmgagdbamhnfd":{"active_permissions":{"api":["hid","usb",{"usbDevices":[{"interfaceId":-1,"productId":512,"vendorId":4176},{"interfaceId":-1,"productId":529,"vendorId":4176}]},"webConnectable"],"explicit_host":["https://www.gstatic.com/*"],"manifest_permissions":[]},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13051997892617208","location":5,"manifest":{"background":{"persistent":false,"scripts":["util.js","b64.js","closeable.js","countdown.js","sha256.js","llgnubby.js","llhidgnubby.js","llusbgnubby.js","gnubbies.js","gnubby.js","gnubby-u2f.js","gnubbycodetypes.js","gnubbyfactory.js","gnubbymsgtypes.js","usbgnubbyfactory.js","devicestatuscodes.js","enroller.js","enrollhelper.js","usbenrollhelper.js","requestqueue.js","signer.js","signhelper.js","singlesigner.js","multiplesigner.js","usbsignhelper.js","webrequest.js","background.js"]},"description":"CryptoToken Component Extension","externally_connectable":{"accepts_tls_channel_id":true,"matches":["https://login.corp.google.com/*","https://accounts.google.com/*","https://security.google.com/*"]},"key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq7zRobvA+AVlvNqkHSSVhh1sEWsHSqz4oR/XptkDe/Cz3+gW9ZGumZ20NCHjaac8j1iiesdigp8B1LJsd/2WWv2Dbnto4f8GrQ5MVphKyQ9WJHwejEHN2K4vzrTcwaXqv5BSTXwxlxS/mXCmXskTfryKTLuYrcHEWK8fCHb+0gvr8b/kvsi75A1aMmb6nUnFJvETmCkOCPNX5CHTdy634Ts/x0fLhRuPlahk63rdf7agxQv5viVjQFk+tbgv6aa9kdSd11Js/RZ9yZjrFgHOBWgP4jTBqud4+HUglrzu8qynFipyNRLCZsaxhm+NItTyNgesxLdxZcwOz56KD1Q4IQIDAQAB","manifest_version":2,"name":"CryptoTokenExtension","permissions":["hid","usb",{"usbDevices":[{"productId":512,"vendorId":4176},{"productId":529,"vendorId":4176}]},"https://www.gstatic.com/"],"version":"0.0.1"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\36.0.1985.125\\resources\\cryptotoken","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"lifbcibllhkdhoafpjfnlhfpfgnpldfl":{"ack_prompt_count":1,"active_permissions":{"api":["tabs"],"explicit_host":["https://localhost:26143/*","https://pnrws.skype.com/*"],"manifest_permissions":[],"scriptable_host":["file:///*","hxxp://*/*","https://*/*"]},"content_settings":[],"creation_flags":9,"events":[],"from_bookmark":false,"from_webstore":true,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13051997901545329","lastpingday":"13051978741602329","location":6,"manifest":{"background":{"page":"background.html"},"browser_action":{"default_icon":{"19":"c2c_48x48.png"},"default_popup":"c2c_options_menu.html","default_title":"Skype Click to Call"},"content_scripts":[{"all_frames":true,"css":["number_highlighting.css","number_highlighting_ui1.css","number_highlighting_chrome.css","number_highlighting_chrome_ui1.css"],"js":["jquery-2.1.0.min.js","mutation-summary.js","localization.js","browserSpecificScript.js","number_highlighting_builder.js","pnr.js","fpnr.js","contentscript.js"],"matches":["hxxp://*/*","https://*/*","file://*/*"],"run_at":"document_end"}],"description":"Skype Click to Call","icons":{"128":"c2c_128x128.png","16":"c2c_16x16.png","48":"c2c_48x48.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMxFysW3wPKWRPPe3xuJQz3m1ZDLX1hN8EYdP37tRPf7lp8vIhG4xirlXHGK748qcLPc4Lm8WsHDhvS5okN54Kwcnw4T2tBXSCZJxMmlu14HZ5yc/t969QLTPLIbAsasq4NVo40YuP2B7umxV9BlcxZEB9TEKPEQq8DRoKhj9jBQIDAQAB","manifest_version":2,"name":"Skype Click to Call","permissions":["tabs","https://pnrws.skype.com/","https://localhost:26143/"],"update_url":"https://clients2.google.com/service/update2/crx","version":"7.3.16540.9015","web_accessible_resources":["call_skype_logo.png","call_skype_logo_ui1.png","call_icon.png","call_icon_ui1.png","plus_icon_ui1.png","gift_icon_ui1.png","skype_icon_ui1.png","skypecredit_icon_ui1.png","learnmore_icon_ui1.png","menu_handler.js","telemetry.js"]},"path":"lifbcibllhkdhoafpjfnlhfpfgnpldfl\\7.3.16540.9015_0","preferences":{},"regular_only_preferences":{},"state":0,"was_installed_by_default":false,"was_installed_by_oem":false},"mfehgcgbbipciphmccgaenjidiccnmng":{"active_permissions":{"api":["cloudPrintPrivate"],"manifest_permissions":[]},"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"install_time":"13044126764568239","location":5,"manifest":{"app":{"launch":{"web_url":"https://www.google.com/cloudprint"},"urls":["https://www.google.com/cloudprint/enable_chrome_connector"]},"description":"Cloud Print","display_in_launcher":false,"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqOhnwk4+HXVfGyaNsAQdU/js1Na56diW08oF1MhZiwzSnJsEaeuMN9od9q9N4ZdK3o1xXOSARrYdE+syV7Dl31nf6qz3A6K+D5NHe6sSB9yvYlIiN37jdWdrfxxE0pRYEVYZNTe3bzq3NkcYJlOdt1UPcpJB+isXpAGUKUvt7EQIDAQAB","name":"Cloud Print","permissions":["cloudPrintPrivate"],"version":"0.1"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\29.0.1547.66\\resources\\cloud_print","was_installed_by_default":false},"mgndgikekgjfcpckkfioiadnlibdjbkf":{"active_permissions":{"api":[],"manifest_permissions":[]},"app_launcher_ordinal":"t","creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"install_time":"13044126764569239","location":5,"manifest":{"app":{"launch":{"web_url":"hxxp://THIS-WILL-BE-REPLACED"}},"description":"Chrome as an app","display_in_launcher":true,"display_in_new_tab_page":false,"icons":{"128":"product_logo_128.png","16":"product_logo_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNuYLEQ1QPMcc5HfWI/9jiEf6FdJWqEtgRmIeI7qtjPLBM5oje+Ny2E2mTAhou5qdJiO2CHWdU1DQXY2F7Zu2gZaKZgHLfK4WimHxUT5Xd9/aro/R9PCzjguM1BLusiWYc9xlj1IsZpyiN1hcjU7SCnBhv1feQlv2WSB5KRiXwhQIDAQAB","name":"Chrome","version":"0.1"},"page_ordinal":"n","path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\29.0.1547.66\\resources\\chrome_app","was_installed_by_default":false},"mkfokfffehpeedafpekjeddnmnjhmcmk":{"ack_external":true,"active_permissions":{"api":["history","management","plugin","tabs","webNavigation"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[],"scriptable_host":["\u003Call_urls>"]},"content_settings":[],"creation_flags":9,"disable_reasons":1,"events":[],"from_bookmark":false,"from_webstore":true,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13051997903177329","lastpingday":"13051978741602329","location":3,"manifest":{"background":{"scripts":["background.js"]},"browser_action":{"default_icon":"http://www.trojaner-board.de/images/...title":"Norton Toolbar"},"content_scripts":[{"all_frames":true,"js":["docstart.js","wcid.js","wax.js"],"matches":["\u003Call_urls>"],"run_at":"document_start"}],"current_locale":"de","default_locale":"en","description":"Norton Safe Search and Safe Web warn you of dangerous sites when you search, shop or browse online.","icons":{"48":"http://www.trojaner-board.de/images/..."name":"Norton Security Toolbar","permissions":["tabs","history","webNavigation","management","\u003Call_urls>"],"plugins":[{"path":"npcoplgn.dll","public":true}],"requirements":{"plugins":{"npapi":false}},"update_url":"https://clients2.google.com/service/update2/crx","version":"2014.7.6.17","web_accessible_resources":["http://www.trojaner-board.de/images/...on":"Component extension providing speech via the Google network text-to-speech service.","key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8GSbNUMGygqQTNDMFGIjZNcwXsHLzkNkHjWbuY37PbNdSDZ4VqlVjzbWqODSe+MjELdv5Keb51IdytnoGYXBMyqKmWpUrg+RnKvQ5ibWr4MW9pyIceOIdp9GrzC1WZGgTmZismYR3AjaIpufZ7xDdQQv+XrghPWCkdVqLN+qZDA1HU+DURznkMICiDDSH2sU0egm9UbWfS218bZqzKeQDiC3OnTPlaxcbJtKUuupIm5knjze3Wo9Ae9poTDMzKgchg0VlFCv3uqox+wlD8sjXBoyBCCK9HpImdVAF1a7jpdgiUHpPeV/26oYzM9/grltwNR3bzECQgSpyXp0eyoegwIDAQAB","manifest_version":2,"name":"Google Network Speech","permissions":["systemPrivate","ttsEngine","https://www.google.com/"],"tts_engine":{"voices":[{"event_types":["start","end","error"],"gender":"female","lang":"en-US","remote":true,"voice_name":"Google US English"},{"event_types":["start","end","error"],"gender":"male","lang":"en-GB","remote":true,"voice_name":"Google UK English Male"},{"event_types":["start","end","error"],"gender":"female","lang":"en-GB","remote":true,"voice_name":"Google UK English Female"},{"event_types":["start","end","error"],"gender":"female","lang":"es-ES","remote":true,"voice_name":"Google Español"},{"event_types":["start","end","error"],"gender":"female","lang":"fr-FR","remote":true,"voice_name":"Google Français"},{"event_types":["start","end","error"],"gender":"female","lang":"it-IT","remote":true,"voice_name":"Google Italiano"},{"event_types":["start","end","error"],"gender":"female","lang":"de-DE","remote":true,"voice_name":"Google Deutsch"},{"event_types":["start","end","error"],"gender":"female","lang":"ja-JP","remote":true,"voice_name":"Google æ?¥æ?¬äºº"},{"event_types":["start","end","error"],"gender":"female","lang":"ko-KR","remote":true,"voice_name":"Google í??êµ*ì?"},{"event_types":["start","end","error"],"gender":"female","lang":"zh-CN","remote":true,"voice_name":"Google ä¸*å?½ç??"}]},"version":"1.0"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\network_speech_synthesis","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"nkeimhogjdpnpccoofpliimaahmaaome":{"active_permissions":{"api":["alarms","desktopCapture","processes","webConnectable","webrtcAudioPrivate","webrtcLoggingPrivate","system.cpu"],"manifest_permissions":[]},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13049413811063196","location":5,"manifest":{"background":{"page":"background.html","persistent":false},"externally_connectable":{"matches":["https://*.google.com/hangouts*","*://localhost/*"]},"incognito":"split","key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDAQt2ZDdPfoSe/JI6ID5bgLHRCnCu9T36aYczmhw/tnv6QZB2I6WnOCMZXJZlRdqWc7w9jo4BWhYS50Vb4weMfh/I0On7VcRwJUgfAxW2cHB+EkmtI1v4v/OU24OqIa1Nmv9uRVeX0GjhQukdLNhAE6ACWooaf5kqKlCeK+1GOkQIDAQAB","manifest_version":2,"name":"Google+ Hangouts","permissions":["alarms","desktopCapture","system.cpu","webrtcAudioPrivate","webrtcLoggingPrivate"],"version":"1.0"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\hangout_services","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"nmmhkkegccagdldgiimedpiccmgmieda":{"ack_external":true,"active_permissions":{"api":["identity","webview"],"explicit_host":["https://checkout.google.com/*","https://sandbox.google.com/*","https://www.google.com/*","https://www.googleapis.com/*"],"manifest_permissions":[]},"content_settings":[],"creation_flags":137,"events":["app.runtime.onLaunched"],"from_bookmark":false,"from_webstore":true,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13049413840238199","lastpingday":"13051978741602329","location":10,"manifest":{"app":{"background":{"scripts":["craw_background.js"]}},"current_locale":"de","default_locale":"en","description":"Google Wallet für digitale Produkte","display_in_launcher":false,"display_in_new_tab_page":false,"icons":{"128":"http://www.trojaner-board.de/images/..."name":"Google Wallet","oauth2":{"auto_approve":true,"client_id":"203784468217.apps.googleusercontent.com","scopes":["https://www.googleapis.com/auth/sierra","https://www.googleapis.com/auth/sierrasandbox","https://www.googleapis.com/auth/chromewebstore","https://www.googleapis.com/auth/chromewebstore.readonly"]},"permissions":["identity","webview","https://checkout.google.com/","https://sandbox.google.com/checkout/","https://www.google.com/","https://www.googleapis.com/*"],"update_url":"https://clients2.google.com/service/update2/crx","version":"0.0.6.1"},"path":"nmmhkkegccagdldgiimedpiccmgmieda\\0.0.6.1_1","preferences":{},"regular_only_preferences":{},"running":false,"state":1,"was_installed_by_default":true,"was_installed_by_oem":false},"pafkbggdmjlpgkdkcbjmhmfcdpncadgh":{"active_permissions":{"api":["alarms","identity","metricsPrivate","notifications","pushMessaging","storage","tabs","webstorePrivate"],"explicit_host":["\u003Call_urls>","chrome://favicon/*"],"manifest_permissions":[]},"content_settings":[],"creation_flags":1,"events":["alarms.onAlarm","identity.onSignInChanged","notifications.onButtonClicked","notifications.onClicked","notifications.onClosed","notifications.onPermissionLevelChanged","notifications.onShowSettings","pushMessaging.onMessage","runtime.onInstalled","runtime.onStartup","runtime.onSuspend","storage.onChanged"],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"initial_keybindings_set":true,"install_time":"13049405312691241","location":5,"manifest":{"background":{"persistent":false,"scripts":["utility.js","cards.js","background.js"]},"description":"Integrates Google Now into Chrome.","icons":{"128":"http://www.trojaner-board.de/images/..."name":"Google Now","oauth2":{"auto_approve":true,"scopes":["https://www.googleapis.com/auth/googlenow"]},"optional_permissions":["background"],"permissions":["alarms","identity","metricsPrivate","notifications","pushMessaging","storage","tabs","webstorePrivate","\u003Call_urls>"],"version":"1.2.0.1"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\35.0.1916.153\\resources\\google_now","preferences":{},"regular_only_preferences":{},"was_installed_by_default":false,"was_installed_by_oem":false},"pjkljhegncpnkpknbcohdijeoejaedia":{"ack_external":true,"active_permissions":{"api":["notifications"],"manifest_permissions":[]},"app_launcher_ordinal":"x","creation_flags":137,"events":[],"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["notifications"],"manifest_permissions":[]},"install_time":"13044126766255248","lastpingday":"13051978741602329","location":1,"manifest":{"app":{"launch":{"container":"tab","web_url":"https://mail.google.com/mail/ca"},"urls":["*://mail.google.com/mail/ca"]},"current_locale":"de","default_locale":"en","description":"Schneller E-Mail-Dienst mit Suchfunktion und wenig Spam.","icons":{"128":"128.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCuGglK43iAz3J9BEYK/Mz6ZhloIMMDqQSAaf3vJt4eHbTbSDsu4WdQ9dQDRcKlg8nwQdePBt0C3PSUBtiSNSS37Z3qEGfS7LCju3h6pI1Yr9MQtxw+jUa7kXXIS09VV73pEFUT/F7c6Qe8L5ZxgAcBvXBh1Fie63qb02I9XQ/CQIDAQAB","name":"Google Mail","options_page":"https://mail.google.com/mail/ca/#settings","permissions":["notifications"],"update_url":"hxxp://clients2.google.com/service/update2/crx","version":"7"},"page_ordinal":"n","path":"pjkljhegncpnkpknbcohdijeoejaedia\\7_0","state":1,"was_installed_by_default":true}}},"first_run_tabs":["hxxp://www.google.com/","hxxp://welcome_page"],"homepage":"http:\/\/www.google.com\/","homepage_is_newtabpage":false,"intl":{"accept_languages":"de-DE,de,en-US,en"},"invalidator":{"client_id":"xdVvvOQl5p3vhghiutFRVg=="},"media":{"device_id_salt":"NVqQsY+uH3966oeHliZMoA=="},"net":{"http_server_properties":{"servers":{"ajax.googleapis.com:80":{"alternate_protocol":{"port":80,"protocol_str":"quic"}},"chrome.google.com:443":{"alternate_protocol":{"port":443,"protocol_str":"quic"}},"clients2.google.com:443":{"alternate_protocol":{"port":443,"protocol_str":"quic"},"supports_spdy":true},"clients2.googleusercontent.com:443":{"alternate_protocol":{"port":443,"protocol_str":"quic"},"supports_spdy":true},"fonts.googleapis.com:80":{"alternate_protocol":{"port":80,"protocol_str":"quic"}},"themes.googleusercontent.com:80":{"alternate_protocol":{"port":80,"protocol_str":"quic"}},"www.google-analytics.com:80":{"alternate_protocol":{"port":80,"protocol_str":"quic"}},"www.googleapis.com:443":{"alternate_protocol":{"port":443,"protocol_str":"quic"},"supports_spdy":true}},"version":2}},"pinned_tabs":[],"plugins":{"enabled_internal_pdf3":true,"enabled_nacl":true,"migrated_to_pepper_flash":true,"plugins_list":[],"removed_old_component_pepper_flash_settings":true},"profile":{"avatar_index":0,"content_settings":{"clear_on_exit_migrated":true,"pattern_pairs":{},"pref_version":1},"exit_type":"Normal","exited_cleanly":true,"icon_version":2,"managed_user_id":"","name":"Erster Nutzer","per_host_zoom_levels":{"flightforum.ch":0.5227586988632231,"flightx.net":1.2239010857415449}},"savefile":{"default_directory":"C:\\Users\\User\\Downloads"},"session":{"restore_on_startup":4,"restore_on_startup_migrated":true,"startup_urls":[""],"startup_urls_migration_time":"13049413810623196"},"sync_promo":{"show_on_first_run_allowed":false},"translate_accepted_count":{"en":0},"translate_blocked_languages":["de"],"translate_denied_count":{"en":4},"translate_site_blacklist":["thepiratebay.ee"],"translate_whitelists":{}}), Ersetzt,[a3426a5c700bb58120ea0200e91cec14] Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by User on 15.08.2014 at 11:18:03,92 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin" ~~~ FireFox Emptied folder: C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\l2fwmsro.default\minidumps [9 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 15.08.2014 at 11:20:58,02 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-08-2014 Ran by User (administrator) on USER-PC on 15-08-2014 11:26:11 Running from C:\Users\User\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe () C:\Windows\SysWOW64\ASGT.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Dropbox, Inc.) C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Farbar) C:\Users\User\Downloads\FRST64(2).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\btvstack.exe [1023104 2012-11-29] (Atheros Communications) HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\athbttray.exe [801920 2012-11-29] (Atheros Commnucations) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-07-21] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-12-21] (Intel Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [190032 2014-07-24] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2694040 2014-07-22] (Adobe Systems Incorporated) HKU\S-1-5-21-3873043628-1780199607-4098311539-1000\...\Run: [CAHeadless] => C:\Program Files (x86)\Adobe\Elements 12 Organizer\CAHeadless\ElementsAutoAnalyzer.exe [1400224 2013-09-03] (Adobe Systems Incorporated) Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: AccExtIco1 -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll () ShellIconOverlayIdentifiers: AccExtIco2 -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll () ShellIconOverlayIdentifiers: AccExtIco3 -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll () ShellIconOverlayIdentifiers: "DropboxExt1" -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: "DropboxExt2" -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: "DropboxExt3" -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: "DropboxExt4" -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: "DropboxExt5" -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: "DropboxExt6" -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: "DropboxExt7" -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: "DropboxExt8" -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: localhost:8080 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6DE76A2ECC72CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) Tcpip\Parameters: [DhcpNameServer] 62.2.17.60 62.2.24.162 62.2.17.61 62.2.24.158 FireFox: ======== FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\l2fwmsro.default FF SelectedSearchEngine: Google FF Homepage: www.google.ch FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DownThemAll! - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\l2fwmsro.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2014-07-17] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-09] CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-09] CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-09] CHR Extension: (Google Search) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-09] CHR Extension: (Skype Click to Call) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-08-08] CHR Extension: (Norton Security Toolbar) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2014-07-09] CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-09] CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-09] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeActiveFileMonitor12.0; C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe [181152 2013-09-03] (Adobe Systems Incorporated) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-07-21] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-21] (Avira Operations GmbH & Co. KG) R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-05-17] () R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [File not signed] R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-24] (Avira Operations GmbH & Co. KG) R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [240584 2012-10-02] (DTS, Inc) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation) R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [327296 2012-11-29] (Atheros) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31920 2013-06-02] (Wondershare) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [47512 2013-01-10] (Asmedia Technology) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-05-17] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-07-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [495376 2013-05-30] (Intel Corporation) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-07] (Intel Corporation) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation) S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [8192 2005-03-29] () R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cleanhlp; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [X] S3 cpuz137; \??\C:\Windows\TEMP\cpuz137\cpuz137_x64.sys [X] S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X] R4 IOMap; \??\C:\Windows\system32\drivers\IOMap64.sys [X] S0 PxHlpa64; System32\drivers\PxHlpa64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-15 11:33 - 2014-08-15 11:33 - 00000000 ____D () C:\AdwCleaner 2014-08-15 11:32 - 2014-08-15 11:32 - 01356107 _____ () C:\Users\User\Downloads\adwcleaner_3.305.exe 2014-08-15 11:31 - 2014-08-15 11:31 - 00041069 _____ () C:\Users\User\Desktop\mbam.txt 2014-08-15 11:25 - 2014-08-15 11:25 - 02100224 _____ (Farbar) C:\Users\User\Downloads\FRST64(2).exe 2014-08-15 11:20 - 2014-08-15 11:21 - 00000824 _____ () C:\Users\User\Desktop\JRT.txt 2014-08-15 11:18 - 2014-08-15 11:18 - 00000000 ____D () C:\Windows\ERUNT 2014-08-15 11:16 - 2014-08-15 11:16 - 01016261 _____ (Thisisu) C:\Users\User\Desktop\JRT.exe 2014-08-15 11:16 - 2014-08-15 11:16 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-15 11:15 - 2014-08-15 11:15 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-15 11:15 - 2014-08-15 11:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-15 11:15 - 2014-08-15 11:15 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-15 11:15 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-08-15 11:15 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-08-15 11:15 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-08-15 11:04 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-15 11:04 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-08-15 11:04 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-15 11:04 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-15 11:04 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-15 11:04 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-15 11:04 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-08-15 11:04 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-08-14 15:30 - 2014-08-14 15:25 - 00000000 ____D () C:\Qoobox 2014-08-14 15:30 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-08-14 15:30 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-08-14 15:30 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-08-14 15:30 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-08-14 15:30 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-08-14 15:30 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-08-14 15:30 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-08-14 15:30 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-08-14 15:29 - 2014-08-14 15:28 - 00000000 ____D () C:\Windows\erdnt 2014-08-14 15:29 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-14 15:29 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-14 15:29 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-14 15:29 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-14 15:29 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-14 15:29 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-14 15:29 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-14 15:29 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-14 15:29 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-14 15:29 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-14 15:29 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-14 15:29 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-14 15:29 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-14 15:29 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-08-14 15:29 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-08-14 15:29 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-14 15:29 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-14 15:29 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-14 15:29 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-08-14 15:29 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-14 15:29 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-14 15:29 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-08-14 15:29 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-08-14 15:29 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-14 15:29 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-14 15:29 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-14 15:29 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-14 15:29 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-14 15:29 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-08-14 15:29 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-14 15:29 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-08-14 15:29 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-08-14 15:29 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-14 15:29 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-08-14 15:29 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-14 15:29 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-14 15:29 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-14 15:29 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-14 15:29 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-14 15:29 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-14 15:29 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-14 15:29 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-08-14 15:29 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-08-14 15:29 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-14 15:29 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-14 15:29 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-14 15:29 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-14 15:29 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-14 15:29 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-08-14 15:29 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-14 15:29 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-14 15:29 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-14 15:29 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-14 15:29 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-14 15:29 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-14 15:29 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-14 15:29 - 2014-07-16 05:25 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-14 15:29 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-08-14 15:29 - 2014-07-16 04:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-14 15:29 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-08-14 15:29 - 2014-07-16 04:12 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-14 15:29 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-08-14 15:29 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-08-14 15:29 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-08-14 15:29 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-08-14 15:29 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-08-14 15:29 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2014-08-14 15:29 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2014-08-14 15:29 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2014-08-14 15:29 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2014-08-14 15:29 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2014-08-14 15:29 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-08-14 15:29 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls 2014-08-14 15:29 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-08-14 15:29 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-08-14 15:29 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-14 15:29 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-14 15:29 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-14 15:29 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-14 15:29 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-14 15:29 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-14 15:29 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-08-14 15:29 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-14 15:28 - 2014-08-14 15:28 - 05571579 ____R (Swearware) C:\Users\User\Desktop\ComboFix.exe 2014-08-14 15:28 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-14 15:28 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2014-08-14 15:27 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-14 15:27 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-14 15:25 - 2014-08-14 15:34 - 00034163 _____ () C:\ComboFix.txt 2014-08-14 15:24 - 2014-08-14 15:25 - 00000000 ____D () C:\ComboFix 2014-08-11 13:41 - 2014-08-11 13:41 - 00000087 _____ () C:\Users\User\Desktop\Maxi N.txt 2014-08-11 13:37 - 2014-08-11 13:37 - 00000000 ____D () C:\Users\User\Desktop\Adobe 2014-08-11 13:35 - 2014-08-11 13:35 - 00125999 _____ () C:\Users\User\Desktop\GMER.log 2014-08-11 13:32 - 2014-08-11 13:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\PDAppFlex 2014-08-11 13:25 - 2014-08-11 13:25 - 00000000 ___RD () C:\Users\User\Creative Cloud Files 2014-08-11 13:24 - 2014-08-11 13:24 - 00002212 _____ () C:\Users\Public\Desktop\Google Earth.lnk 2014-08-11 13:24 - 2014-08-11 13:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2014-08-11 13:23 - 2014-08-11 13:23 - 00895120 _____ (Google Inc.) C:\Users\User\Downloads\GoogleEarthSetup.exe 2014-08-11 13:23 - 2014-08-11 13:23 - 00001313 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk 2014-08-11 13:23 - 2014-08-11 13:23 - 00001301 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2014-08-11 13:18 - 2014-08-11 13:18 - 00614792 _____ (Adobe Systems Incorporated) C:\Users\User\Downloads\CreativeCloudSet-Up.exe 2014-08-11 13:17 - 2014-08-11 13:17 - 00000265 _____ () C:\Users\User\Desktop\tesr.txt 2014-08-11 13:11 - 2014-08-11 13:11 - 00000533 _____ () C:\Users\Public\Desktop\Maps2Bgl_X.lnk 2014-08-11 13:11 - 2014-08-11 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maps2Bgl_X 2014-08-11 13:11 - 2004-08-03 23:54 - 01712128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll 2014-08-11 13:00 - 2014-08-11 13:00 - 00380416 _____ () C:\Users\User\Downloads\wwmvbxht.exe 2014-08-11 13:00 - 2014-08-11 13:00 - 00056496 _____ (GMER) C:\kxldapob.sys 2014-08-11 12:50 - 2014-08-11 12:57 - 00050783 _____ () C:\Users\User\Desktop\FRST.txt 2014-08-11 12:49 - 2014-08-11 12:49 - 02099712 _____ (Farbar) C:\Users\User\Downloads\FRST64(1).exe 2014-08-11 12:48 - 2014-08-11 12:48 - 00808704 _____ () C:\Windows\Minidump\081114-81214-01.dmp 2014-08-11 12:48 - 2014-08-11 12:48 - 00043878 _____ () C:\Users\User\Desktop\Addition.txt 2014-08-10 22:47 - 2014-08-10 22:48 - 00043878 _____ () C:\Users\User\Downloads\Addition.txt 2014-08-10 22:44 - 2014-08-15 11:26 - 00019111 _____ () C:\Users\User\Downloads\FRST.txt 2014-08-10 22:44 - 2014-08-15 11:26 - 00000000 ____D () C:\FRST 2014-08-10 22:44 - 2014-08-15 11:10 - 00449794 _____ () C:\Windows\PFRO.log 2014-08-10 22:43 - 2014-08-10 22:44 - 02099712 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe 2014-08-09 15:19 - 2014-08-09 15:19 - 00069340 _____ () C:\Users\User\Documents\OS 737 land loww 29.frc 2014-08-09 15:14 - 2014-08-09 15:14 - 00000000 ____D () C:\ProgramData\Emsisoft 2014-08-09 15:06 - 2014-08-14 16:08 - 00000000 ____D () C:\Users\User\Desktop\Unbenannter Export 2014-08-09 15:03 - 2014-08-09 15:03 - 00000000 ____D () C:\Users\User\Documents\ProcAlyzer Dumps 2014-08-09 14:59 - 2014-08-09 14:59 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\User\Downloads\tdsskiller.exe 2014-08-09 14:59 - 2014-08-09 14:59 - 00192698 _____ () C:\Users\User\Documents\LX563 climbing.frc 2014-08-09 14:54 - 2014-08-10 22:44 - 00000470 _____ () C:\Users\User\Desktop\defogger_disable.log 2014-08-09 14:53 - 2014-08-09 14:53 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-08-09 14:53 - 2014-08-09 14:53 - 00000000 ____D () C:\Users\User\AppData\Roaming\TuneUp Software 2014-08-09 14:52 - 2014-08-09 14:52 - 00050477 _____ () C:\Users\User\Downloads\Defogger.exe 2014-08-09 14:52 - 2014-08-09 14:52 - 00000470 _____ () C:\Users\User\Downloads\defogger_disable.log 2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\Users\User\AppData\Local\gtk-2.0 2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\Users\User\.thumbnails 2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Drzewiecki Design 2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 _____ () C:\Users\User\defogger_reenable 2014-08-09 14:51 - 2014-08-11 13:20 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-08-09 14:51 - 2014-08-11 12:48 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-08-09 14:50 - 2014-08-11 12:51 - 00000000 ____D () C:\$AVG 2014-08-09 14:50 - 2014-08-11 12:47 - 00000000 ____D () C:\ProgramData\AVG2014 2014-08-09 14:50 - 2014-08-09 14:50 - 00051469 _____ () C:\Users\User\Documents\LX563 taxi to rwy.frc 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Windows\System32\Tasks\Abelssoft 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Users\User\AppData\Roaming\Abelssoft 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Users\User\AppData\Local\Abelssoft 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\ProgramData\XDMessagingv4 2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\Users\User\AppData\Roaming\DesktopIconGoodgame 2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CHIP Updater 2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\Program Files (x86)\CHIP Updater 2014-08-09 14:48 - 2014-08-09 14:48 - 01101648 _____ () C:\Users\User\Downloads\SpyBot Search Destroy - CHIP-Installer.exe 2014-08-09 14:46 - 2014-08-11 13:14 - 00000000 ____D () C:\Users\User\.gimp-2.8 2014-08-09 14:46 - 2014-08-11 12:47 - 00000000 ____D () C:\ProgramData\MFAData 2014-08-09 14:46 - 2014-08-09 14:46 - 00000000 ____D () C:\Users\User\AppData\Local\MFAData 2014-08-09 14:46 - 2014-08-09 14:46 - 00000000 ____D () C:\Users\User\AppData\Local\gegl-0.2 2014-08-09 14:44 - 2014-08-09 14:45 - 168801544 _____ (AVG Technologies) C:\Users\User\Downloads\avg_avct_x64_all_2014_4744a7830.exe 2014-08-09 14:44 - 2014-08-09 14:44 - 00000894 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk 2014-08-09 14:43 - 2014-08-11 12:48 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware 2014-08-09 14:43 - 2014-08-09 14:44 - 00000000 ____D () C:\Program Files\GIMP 2 2014-08-09 14:41 - 2014-08-09 14:43 - 201035376 _____ (Emsisoft GmbH ) C:\Users\User\Downloads\EmsisoftAntiMalwareSetup.exe 2014-08-09 14:41 - 2014-08-09 14:41 - 90396104 _____ (The GIMP Team ) C:\Users\User\Downloads\gimp-2.8.10-setup.exe 2014-08-09 14:31 - 2014-08-09 14:31 - 00001490 _____ () C:\Users\User\AppData\Local\recently-used.xbel 2014-08-09 14:28 - 2014-08-09 14:47 - 00019279 _____ () C:\Users\User\Documents\LX563 pushback.frc 2014-08-08 21:20 - 2014-08-08 20:39 - 00000000 ____D () C:\Users\User\AppData\Roaming\Virtuali 2014-08-08 20:59 - 2014-08-08 20:59 - 00000000 ____D () C:\Users\User\AppData\Local\World_of_AI 2014-08-08 20:54 - 2014-08-09 14:57 - 00000000 ____D () C:\Users\User\Desktop\IG 2014-08-08 20:48 - 2014-08-09 14:52 - 00000000 ____D () C:\Users\User\Desktop\WoAI 2014-08-08 20:41 - 2014-08-08 20:42 - 00000000 ____D () C:\Gramblr 2014-08-08 20:41 - 2014-08-08 20:41 - 00000654 _____ () C:\Users\User\Desktop\Gramblr.lnk 2014-08-08 20:41 - 2014-08-08 20:41 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gramblr 2014-07-21 18:29 - 2014-07-21 18:29 - 00055761 _____ () C:\Users\User\Documents\ab 738 to 28.frc 2014-07-21 18:25 - 2014-07-21 18:25 - 00028159 _____ () C:\Users\User\Documents\ab 738.frc 2014-07-21 18:19 - 2014-07-21 18:19 - 00000000 ____D () C:\Program Files (x86)\PMDG Operations Center 2014-07-21 18:10 - 2014-07-21 18:10 - 00036780 _____ () C:\Users\User\Documents\AB 737 descent.frc 2014-07-21 18:00 - 2014-07-21 18:00 - 00000000 ____D () C:\Users\User\AppData\Local\DriverToolkit 2014-07-21 17:59 - 2014-07-21 18:05 - 00000000 ____D () C:\Program Files (x86)\DriverToolkit 2014-07-21 17:59 - 2014-07-21 17:59 - 02395840 _____ (Megaify Software ) C:\Users\User\Downloads\driver_setup.exe 2014-07-21 17:59 - 2014-07-21 17:59 - 00061940 _____ () C:\Users\User\Documents\Ab 737 takeoff 28 lszh.frc 2014-07-21 17:57 - 2014-07-21 17:57 - 00000000 ____D () C:\Users\User\AppData\Local\Skype 2014-07-21 17:56 - 2014-08-09 15:15 - 00000000 ____D () C:\ProgramData\Skype 2014-07-21 17:56 - 2014-08-09 14:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\Skype 2014-07-21 17:56 - 2014-07-21 17:56 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-07-21 17:55 - 2014-07-21 17:55 - 01677928 _____ (Skype Technologies S.A.) C:\Users\User\Downloads\SkypeSetup.exe 2014-07-21 17:52 - 2014-07-21 17:52 - 00022720 _____ () C:\Users\User\Documents\AB 737 pushback.frc 2014-07-17 12:33 - 2014-07-17 12:33 - 00112593 _____ () C:\Users\User\Documents\frfghjj.frc 2014-07-17 12:27 - 2014-07-17 12:27 - 00091207 _____ () C:\Users\User\Documents\AB2876 takeoff muc.frc 2014-07-17 12:26 - 2014-07-17 12:26 - 00098607 _____ () C:\Users\User\Documents\AB2876 landing ltaiä.frc 2014-07-17 12:13 - 2014-07-17 12:13 - 02050655 _____ (Anthony Ribeiro ) C:\Users\User\Downloads\Boeing 747-8i Lufthansa v1.00.exe 2014-07-17 12:12 - 2014-07-17 12:12 - 46507041 _____ (SkySpirit2012 ) C:\Users\User\Downloads\Boeing 747-8i Basepack v1.40.exe 2014-07-17 11:49 - 2014-07-17 11:49 - 00000000 ____D () C:\found.000 ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-15 11:33 - 2014-08-15 11:33 - 00000000 ____D () C:\AdwCleaner 2014-08-15 11:32 - 2014-08-15 11:32 - 01356107 _____ () C:\Users\User\Downloads\adwcleaner_3.305.exe 2014-08-15 11:31 - 2014-08-15 11:31 - 00041069 _____ () C:\Users\User\Desktop\mbam.txt 2014-08-15 11:26 - 2014-08-10 22:44 - 00019111 _____ () C:\Users\User\Downloads\FRST.txt 2014-08-15 11:26 - 2014-08-10 22:44 - 00000000 ____D () C:\FRST 2014-08-15 11:25 - 2014-08-15 11:25 - 02100224 _____ (Farbar) C:\Users\User\Downloads\FRST64(2).exe 2014-08-15 11:21 - 2014-08-15 11:20 - 00000824 _____ () C:\Users\User\Desktop\JRT.txt 2014-08-15 11:20 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-15 11:20 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-15 11:18 - 2014-08-15 11:18 - 00000000 ____D () C:\Windows\ERUNT 2014-08-15 11:16 - 2014-08-15 11:16 - 01016261 _____ (Thisisu) C:\Users\User\Desktop\JRT.exe 2014-08-15 11:16 - 2014-08-15 11:16 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-15 11:16 - 2014-05-19 20:36 - 01838166 _____ () C:\Windows\WindowsUpdate.log 2014-08-15 11:15 - 2014-08-15 11:15 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-15 11:15 - 2014-08-15 11:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-15 11:15 - 2014-08-15 11:15 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-15 11:14 - 2014-05-09 18:44 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-08-15 11:13 - 2014-05-01 21:00 - 00000000 ____D () C:\Users\User\AppData\Local\Adobe 2014-08-15 11:12 - 2014-07-09 20:59 - 00000000 ___RD () C:\Users\User\Dropbox 2014-08-15 11:12 - 2014-07-09 20:52 - 00000000 ____D () C:\Users\User\AppData\Roaming\Dropbox 2014-08-15 11:11 - 2014-05-19 20:33 - 00018268 _____ () C:\Windows\setupact.log 2014-08-15 11:11 - 2014-05-09 18:32 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-15 11:11 - 2014-04-25 12:56 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-08-15 11:11 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-15 11:11 - 2009-07-14 06:45 - 00628392 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-15 11:10 - 2014-08-10 22:44 - 00449794 _____ () C:\Windows\PFRO.log 2014-08-15 11:09 - 2014-03-13 13:01 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-15 11:09 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-15 11:08 - 2014-05-02 21:45 - 00000000 ____D () C:\Users\User\Documents\Flight Simulator X-Dateien 2014-08-15 11:08 - 2014-05-02 12:32 - 00000000 ____D () C:\Program Files (x86)\FS Recorder for FSX 2014-08-15 11:08 - 2014-03-13 13:01 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-08-15 11:04 - 2014-05-09 18:32 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-15 11:04 - 2014-04-25 14:20 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-14 16:23 - 2011-04-12 09:43 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer 2014-08-14 16:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI 2014-08-14 16:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\MUI 2014-08-14 16:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\servicing 2014-08-14 16:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-08-14 16:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-08-14 16:08 - 2014-08-09 15:06 - 00000000 ____D () C:\Users\User\Desktop\Unbenannter Export 2014-08-14 15:34 - 2014-08-14 15:25 - 00034163 _____ () C:\ComboFix.txt 2014-08-14 15:34 - 2014-05-01 10:01 - 00000000 ____D () C:\ProgramData\TEMP 2014-08-14 15:28 - 2014-08-14 15:29 - 00000000 ____D () C:\Windows\erdnt 2014-08-14 15:28 - 2014-08-14 15:28 - 05571579 ____R (Swearware) C:\Users\User\Desktop\ComboFix.exe 2014-08-14 15:25 - 2014-08-14 15:30 - 00000000 ____D () C:\Qoobox 2014-08-14 15:25 - 2014-08-14 15:24 - 00000000 ____D () C:\ComboFix 2014-08-14 15:23 - 2014-05-03 12:04 - 00000000 ____D () C:\Users\User\AppData\Local\CrashDumps 2014-08-14 15:22 - 2014-07-09 20:59 - 00000976 _____ () C:\Users\User\Desktop\Dropbox.lnk 2014-08-14 15:22 - 2014-07-09 20:53 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-08-14 15:21 - 2014-07-09 20:55 - 00000000 ____D () C:\Program Files\Adobe 2014-08-14 15:20 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-08-11 13:41 - 2014-08-11 13:41 - 00000087 _____ () C:\Users\User\Desktop\Maxi N.txt 2014-08-11 13:40 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-08-11 13:37 - 2014-08-11 13:37 - 00000000 ____D () C:\Users\User\Desktop\Adobe 2014-08-11 13:35 - 2014-08-11 13:35 - 00125999 _____ () C:\Users\User\Desktop\GMER.log 2014-08-11 13:32 - 2014-08-11 13:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\PDAppFlex 2014-08-11 13:31 - 2014-05-01 21:00 - 00000000 ____D () C:\ProgramData\Adobe 2014-08-11 13:25 - 2014-08-11 13:25 - 00000000 ___RD () C:\Users\User\Creative Cloud Files 2014-08-11 13:25 - 2014-04-25 11:05 - 00000000 ____D () C:\Users\User\AppData\Roaming\Adobe 2014-08-11 13:24 - 2014-08-11 13:24 - 00002212 _____ () C:\Users\Public\Desktop\Google Earth.lnk 2014-08-11 13:24 - 2014-08-11 13:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2014-08-11 13:24 - 2014-05-09 18:32 - 00000000 ____D () C:\Users\User\AppData\Local\Google 2014-08-11 13:24 - 2014-05-09 18:32 - 00000000 ____D () C:\Program Files (x86)\Google 2014-08-11 13:23 - 2014-08-11 13:23 - 00895120 _____ (Google Inc.) C:\Users\User\Downloads\GoogleEarthSetup.exe 2014-08-11 13:23 - 2014-08-11 13:23 - 00001313 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk 2014-08-11 13:23 - 2014-08-11 13:23 - 00001301 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2014-08-11 13:22 - 2014-05-02 17:56 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-11 13:20 - 2014-08-09 14:51 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-08-11 13:20 - 2014-05-01 21:00 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-08-11 13:18 - 2014-08-11 13:18 - 00614792 _____ (Adobe Systems Incorporated) C:\Users\User\Downloads\CreativeCloudSet-Up.exe 2014-08-11 13:17 - 2014-08-11 13:17 - 00000265 _____ () C:\Users\User\Desktop\tesr.txt 2014-08-11 13:14 - 2014-08-09 14:46 - 00000000 ____D () C:\Users\User\.gimp-2.8 2014-08-11 13:11 - 2014-08-11 13:11 - 00000533 _____ () C:\Users\Public\Desktop\Maps2Bgl_X.lnk 2014-08-11 13:11 - 2014-08-11 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maps2Bgl_X 2014-08-11 13:00 - 2014-08-11 13:31 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-08-11 13:00 - 2014-08-11 13:00 - 00380416 _____ () C:\Users\User\Downloads\wwmvbxht.exe 2014-08-11 13:00 - 2014-08-11 13:00 - 00056496 _____ (GMER) C:\kxldapob.sys 2014-08-11 12:57 - 2014-08-11 12:50 - 00050783 _____ () C:\Users\User\Desktop\FRST.txt 2014-08-11 12:51 - 2014-08-09 14:50 - 00000000 ____D () C:\$AVG 2014-08-11 12:49 - 2014-08-11 12:49 - 02099712 _____ (Farbar) C:\Users\User\Downloads\FRST64(1).exe 2014-08-11 12:48 - 2014-08-11 12:48 - 00808704 _____ () C:\Windows\Minidump\081114-81214-01.dmp 2014-08-11 12:48 - 2014-08-11 12:48 - 00043878 _____ () C:\Users\User\Desktop\Addition.txt 2014-08-11 12:48 - 2014-08-09 14:51 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-08-11 12:48 - 2014-08-09 14:43 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware 2014-08-11 12:48 - 2014-05-19 20:33 - 1290543419 _____ () C:\Windows\MEMORY.DMP 2014-08-11 12:48 - 2014-05-17 17:07 - 00000000 ____D () C:\Windows\Minidump 2014-08-11 12:47 - 2014-08-09 14:50 - 00000000 ____D () C:\ProgramData\AVG2014 2014-08-11 12:47 - 2014-08-09 14:46 - 00000000 ____D () C:\ProgramData\MFAData 2014-08-11 12:47 - 2014-05-18 10:47 - 00000000 ____D () C:\ProgramData\Norton 2014-08-10 22:48 - 2014-08-10 22:47 - 00043878 _____ () C:\Users\User\Downloads\Addition.txt 2014-08-10 22:44 - 2014-08-10 22:43 - 02099712 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe 2014-08-10 22:44 - 2014-08-09 14:54 - 00000470 _____ () C:\Users\User\Desktop\defogger_disable.log 2014-08-09 15:22 - 2014-07-09 23:51 - 00000472 _____ () C:\Windows\Pitch Target 2014-08-09 15:22 - 2014-07-09 23:51 - 00000466 _____ () C:\Windows\Roll Target 2014-08-09 15:22 - 2014-07-09 23:51 - 00000462 _____ () C:\Windows\Roll Error 2014-08-09 15:22 - 2014-07-09 23:51 - 00000462 _____ () C:\Windows\Pitch Error 2014-08-09 15:22 - 2014-07-09 23:51 - 00000462 _____ () C:\Windows\Gyro Speed 2014-08-09 15:22 - 2014-07-09 23:51 - 00000423 _____ () C:\Windows\Mode2BTimer 2014-08-09 15:22 - 2014-07-09 23:51 - 00000423 _____ () C:\Windows\Mode2_AltGain_timer 2014-08-09 15:22 - 2014-07-09 23:51 - 00000419 _____ () C:\Windows\Mode2ATimer 2014-08-09 15:22 - 2014-07-09 23:51 - 00000271 _____ () C:\Windows\CDU.1 2014-08-09 15:22 - 2014-07-09 23:51 - 00000271 _____ () C:\Windows\CDU.0 2014-08-09 15:20 - 2014-05-01 20:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aerosoft 2014-08-09 15:19 - 2014-08-09 15:19 - 00069340 _____ () C:\Users\User\Documents\OS 737 land loww 29.frc 2014-08-09 15:16 - 2014-05-03 12:33 - 00024400 _____ () C:\Users\User\AppData\Roaming\Notepad2.ini 2014-08-09 15:15 - 2014-07-21 17:56 - 00000000 ____D () C:\ProgramData\Skype 2014-08-09 15:15 - 2014-04-25 11:27 - 00167000 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT 2014-08-09 15:14 - 2014-08-09 15:14 - 00000000 ____D () C:\ProgramData\Emsisoft 2014-08-09 15:03 - 2014-08-09 15:03 - 00000000 ____D () C:\Users\User\Documents\ProcAlyzer Dumps 2014-08-09 14:59 - 2014-08-09 14:59 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\User\Downloads\tdsskiller.exe 2014-08-09 14:59 - 2014-08-09 14:59 - 00192698 _____ () C:\Users\User\Documents\LX563 climbing.frc 2014-08-09 14:57 - 2014-08-08 20:54 - 00000000 ____D () C:\Users\User\Desktop\IG 2014-08-09 14:53 - 2014-08-09 14:53 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-08-09 14:53 - 2014-08-09 14:53 - 00000000 ____D () C:\Users\User\AppData\Roaming\TuneUp Software 2014-08-09 14:52 - 2014-08-09 14:52 - 00050477 _____ () C:\Users\User\Downloads\Defogger.exe 2014-08-09 14:52 - 2014-08-09 14:52 - 00000470 _____ () C:\Users\User\Downloads\defogger_disable.log 2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\Users\User\AppData\Local\gtk-2.0 2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\Users\User\.thumbnails 2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Drzewiecki Design 2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 _____ () C:\Users\User\defogger_reenable 2014-08-09 14:52 - 2014-08-08 20:48 - 00000000 ____D () C:\Users\User\Desktop\WoAI 2014-08-09 14:50 - 2014-08-09 14:50 - 00051469 _____ () C:\Users\User\Documents\LX563 taxi to rwy.frc 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Windows\System32\Tasks\Abelssoft 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Users\User\AppData\Roaming\Abelssoft 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Users\User\AppData\Local\Abelssoft 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\ProgramData\XDMessagingv4 2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\Users\User\AppData\Roaming\DesktopIconGoodgame 2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CHIP Updater 2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\Program Files (x86)\CHIP Updater 2014-08-09 14:48 - 2014-08-09 14:48 - 01101648 _____ () C:\Users\User\Downloads\SpyBot Search Destroy - CHIP-Installer.exe 2014-08-09 14:47 - 2014-08-09 14:28 - 00019279 _____ () C:\Users\User\Documents\LX563 pushback.frc 2014-08-09 14:46 - 2014-08-09 14:46 - 00000000 ____D () C:\Users\User\AppData\Local\MFAData 2014-08-09 14:46 - 2014-08-09 14:46 - 00000000 ____D () C:\Users\User\AppData\Local\gegl-0.2 2014-08-09 14:45 - 2014-08-09 14:44 - 168801544 _____ (AVG Technologies) C:\Users\User\Downloads\avg_avct_x64_all_2014_4744a7830.exe 2014-08-09 14:45 - 2014-07-09 21:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PMDG Simulations 2014-08-09 14:45 - 2014-04-25 11:15 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-08-09 14:44 - 2014-08-09 14:44 - 00000894 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk 2014-08-09 14:44 - 2014-08-09 14:43 - 00000000 ____D () C:\Program Files\GIMP 2 2014-08-09 14:43 - 2014-08-09 14:41 - 201035376 _____ (Emsisoft GmbH ) C:\Users\User\Downloads\EmsisoftAntiMalwareSetup.exe 2014-08-09 14:41 - 2014-08-09 14:41 - 90396104 _____ (The GIMP Team ) C:\Users\User\Downloads\gimp-2.8.10-setup.exe 2014-08-09 14:39 - 2014-05-01 20:01 - 00000000 ____D () C:\Users\User\AppData\Roaming\uTorrent 2014-08-09 14:34 - 2014-07-09 16:47 - 00000000 ____D () C:\Users\User\AppData\Local\Sony 2014-08-09 14:34 - 2014-07-09 16:47 - 00000000 ____D () C:\Program Files\Sony 2014-08-09 14:34 - 2014-07-09 16:46 - 00000000 ____D () C:\ProgramData\Sony 2014-08-09 14:33 - 2014-05-18 19:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-08-09 14:32 - 2014-07-21 17:56 - 00000000 ____D () C:\Users\User\AppData\Roaming\Skype 2014-08-09 14:31 - 2014-08-09 14:31 - 00001490 _____ () C:\Users\User\AppData\Local\recently-used.xbel 2014-08-09 14:28 - 2014-05-18 19:41 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-09 14:28 - 2014-05-18 19:41 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-08-08 21:18 - 2014-08-08 21:17 - 18205840 _____ (VIRTUALI Sagl ) C:\Users\User\Downloads\setup_addonmanagerX.exe 2014-08-08 21:18 - 2014-08-08 21:15 - 247433295 ____R () C:\Users\User\Downloads\FSX - Aerosoft Nice-Cote d'Azur.zip 2014-08-08 21:18 - 2014-05-01 09:54 - 00000000 ____D () C:\ProgramData\Esellerate 2014-08-08 20:59 - 2014-08-08 20:59 - 00000000 ____D () C:\Users\User\AppData\Local\World_of_AI 2014-08-08 20:42 - 2014-08-08 20:41 - 00000000 ____D () C:\Gramblr 2014-08-08 20:41 - 2014-08-08 20:41 - 00000654 _____ () C:\Users\User\Desktop\Gramblr.lnk 2014-08-08 20:41 - 2014-08-08 20:41 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gramblr 2014-08-08 20:39 - 2014-08-08 21:20 - 00000000 ____D () C:\Users\User\AppData\Roaming\Virtuali 2014-08-08 20:32 - 2014-04-30 21:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-08-07 04:06 - 2014-08-14 15:27 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-07 04:01 - 2014-08-14 15:27 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-05 09:20 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-08-01 01:41 - 2014-08-14 15:29 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-01 01:16 - 2014-08-14 15:29 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-07-25 16:52 - 2014-08-14 15:29 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-25 16:02 - 2014-08-14 15:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-25 16:01 - 2014-08-14 15:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-07-25 15:51 - 2014-08-14 15:29 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-25 15:30 - 2014-08-14 15:29 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-25 15:28 - 2014-08-14 15:29 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-25 15:28 - 2014-08-14 15:29 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-07-25 15:25 - 2014-08-14 15:29 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-25 15:25 - 2014-08-14 15:29 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-07-25 15:11 - 2014-08-14 15:29 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-25 15:10 - 2014-08-14 15:29 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-25 15:04 - 2014-08-14 15:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-25 15:03 - 2014-08-14 15:29 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-25 15:00 - 2014-08-14 15:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-25 15:00 - 2014-08-14 15:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-07-25 14:59 - 2014-08-14 15:29 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-07-25 14:47 - 2014-08-14 15:29 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-07-25 14:40 - 2014-08-14 15:29 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-25 14:34 - 2014-08-14 15:29 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-07-25 14:34 - 2014-08-14 15:29 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-07-25 14:33 - 2014-08-14 15:29 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-07-25 14:30 - 2014-08-14 15:29 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-07-25 14:28 - 2014-08-14 15:29 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-25 14:28 - 2014-08-14 15:29 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-07-25 14:21 - 2014-08-14 15:29 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-25 14:19 - 2014-08-14 15:29 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-25 14:18 - 2014-08-14 15:29 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-25 14:17 - 2014-08-14 15:29 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-25 14:17 - 2014-08-14 15:29 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-07-25 14:12 - 2014-08-14 15:29 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-07-25 14:10 - 2014-08-14 15:29 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-25 14:10 - 2014-08-14 15:29 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-07-25 14:08 - 2014-08-14 15:29 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-07-25 14:06 - 2014-08-14 15:29 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-25 13:52 - 2014-08-14 15:29 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-25 13:47 - 2014-08-14 15:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-25 13:43 - 2014-08-14 15:29 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-07-25 13:42 - 2014-08-14 15:29 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-25 13:39 - 2014-08-14 15:29 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-25 13:39 - 2014-08-14 15:29 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-07-25 13:36 - 2014-08-14 15:29 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-07-25 13:34 - 2014-08-14 15:29 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-25 13:29 - 2014-08-14 15:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-25 13:23 - 2014-08-14 15:29 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-25 13:13 - 2014-08-14 15:29 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-25 13:07 - 2014-08-14 15:29 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-25 13:07 - 2014-08-14 15:29 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-07-25 13:03 - 2014-08-14 15:29 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-25 12:52 - 2014-08-14 15:29 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-25 12:26 - 2014-08-14 15:29 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-25 12:17 - 2014-08-14 15:29 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-07-25 12:09 - 2014-08-14 15:29 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-07-25 12:05 - 2014-08-14 15:29 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-25 12:00 - 2014-08-14 15:29 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-21 18:40 - 2014-05-02 13:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games 2014-07-21 18:39 - 2014-05-04 19:56 - 00000000 ____D () C:\Users\User\Desktop\Addons 2014-07-21 18:29 - 2014-07-21 18:29 - 00055761 _____ () C:\Users\User\Documents\ab 738 to 28.frc 2014-07-21 18:25 - 2014-07-21 18:25 - 00028159 _____ () C:\Users\User\Documents\ab 738.frc 2014-07-21 18:23 - 2014-07-09 22:00 - 00000000 ___HD () C:\Windows\msdownld.tmp 2014-07-21 18:23 - 2014-07-09 22:00 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-07-21 18:19 - 2014-07-21 18:19 - 00000000 ____D () C:\Program Files (x86)\PMDG Operations Center 2014-07-21 18:10 - 2014-07-21 18:10 - 00036780 _____ () C:\Users\User\Documents\AB 737 descent.frc 2014-07-21 18:05 - 2014-07-21 17:59 - 00000000 ____D () C:\Program Files (x86)\DriverToolkit 2014-07-21 18:00 - 2014-07-21 18:00 - 00000000 ____D () C:\Users\User\AppData\Local\DriverToolkit 2014-07-21 17:59 - 2014-07-21 17:59 - 02395840 _____ (Megaify Software ) C:\Users\User\Downloads\driver_setup.exe 2014-07-21 17:59 - 2014-07-21 17:59 - 00061940 _____ () C:\Users\User\Documents\Ab 737 takeoff 28 lszh.frc 2014-07-21 17:57 - 2014-07-21 17:57 - 00000000 ____D () C:\Users\User\AppData\Local\Skype 2014-07-21 17:56 - 2014-07-21 17:56 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-07-21 17:56 - 2014-05-02 17:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-07-21 17:56 - 2014-05-02 17:56 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-07-21 17:55 - 2014-07-21 17:55 - 01677928 _____ (Skype Technologies S.A.) C:\Users\User\Downloads\SkypeSetup.exe 2014-07-21 17:52 - 2014-07-21 17:52 - 00022720 _____ () C:\Users\User\Documents\AB 737 pushback.frc 2014-07-21 17:49 - 2014-07-09 21:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-07-17 12:33 - 2014-07-17 12:33 - 00112593 _____ () C:\Users\User\Documents\frfghjj.frc 2014-07-17 12:27 - 2014-07-17 12:27 - 00091207 _____ () C:\Users\User\Documents\AB2876 takeoff muc.frc 2014-07-17 12:26 - 2014-07-17 12:26 - 00098607 _____ () C:\Users\User\Documents\AB2876 landing ltaiä.frc 2014-07-17 12:16 - 2014-07-09 20:59 - 00000000 ____D () C:\Lightroom 5 2014-07-17 12:13 - 2014-07-17 12:13 - 02050655 _____ (Anthony Ribeiro ) C:\Users\User\Downloads\Boeing 747-8i Lufthansa v1.00.exe 2014-07-17 12:12 - 2014-07-17 12:12 - 46507041 _____ (SkySpirit2012 ) C:\Users\User\Downloads\Boeing 747-8i Basepack v1.40.exe 2014-07-17 12:03 - 2014-07-09 21:00 - 00000000 ____D () C:\Users\User\Documents\Adobe 2014-07-17 11:58 - 2014-07-09 20:56 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-07-17 11:50 - 2014-05-03 09:14 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-07-17 11:49 - 2014-07-17 11:49 - 00000000 ____D () C:\found.000 2014-07-16 05:25 - 2014-08-14 15:29 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-07-16 05:23 - 2014-08-14 15:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-07-16 04:46 - 2014-08-14 15:29 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-07-16 04:46 - 2014-08-14 15:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-07-16 04:12 - 2014-08-14 15:29 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys Some content of TEMP: ==================== C:\Users\User\AppData\Local\Temp\avgnt.exe C:\Users\User\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp31exai.dll C:\Users\User\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-09 15:26 ==================== End Of Log ============================ --- --- --- --- --- --- |
16.08.2014, 14:25 | #20 |
/// the machine /// TB-Ausbilder | Firefox kommt auf Yahoo 404 - "page not found"ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.08.2014, 10:38 | #21 |
| Firefox kommt auf Yahoo 404 - "page not found"Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=c59ad24c2741d249abacc82533ee862b # engine=19694 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-08-15 08:47:20 # local_time=2014-08-15 10:47:20 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Avira Desktop' # compatibility_mode=1810 16777213 100 100 0 14774776 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 0 159722290 0 0 # scanned=293987 # found=6 # cleaned=0 # scan_time=250 sh=CE2A40DE6641F64F8E4DB24E15BBADB1B62EB968 ft=1 fh=c894536f3c2e48aa vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CXOM8KFJ\SPSetup[1].exe" sh=C8ED85CBB679DFF0D72E7D8C79CE5E74B5EFADE0 ft=1 fh=37dd7ede875c1f3d vn="Variante von Win32/ClientConnect.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HO42K7IH\spstub[1].exe" sh=5CDDBE27743AE8142830767631CFD9132DA62F82 ft=1 fh=3649e97316c551eb vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\User\Downloads\avidemux.exe" sh=45B5D10291129AF1F3FB2023EE6CE4C42999575B ft=1 fh=26903b123e8979af vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\User\Downloads\Exif Viewer - CHIP-Installer.exe" sh=97C27C1503F07836179AEB977D40BCA8EC270AD0 ft=1 fh=988675573c107bc3 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\User\Downloads\FRAPS - CHIP-Downloader.exe" sh=7E00BBA4669D9953E46ABCC45E08F76E6CD5FA19 ft=1 fh=f125ae702b166bcd vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\User\Downloads\ViewNX 64 Bit - CHIP-Downloader.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.87 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 13.0.0.206 Flash Player out of Date! Mozilla Firefox (31.0) Google Chrome 36.0.1985.125 Google Chrome 36.0.1985.143 ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-08-2014 04 Ran by User (administrator) on USER-PC on 15-08-2014 10:48:24 Running from C:\Users\User\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe () C:\Windows\SysWOW64\ASGT.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Dropbox, Inc.) C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Farbar) C:\Users\User\Downloads\FRST64(3).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\btvstack.exe [1023104 2012-11-29] (Atheros Communications) HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\athbttray.exe [801920 2012-11-29] (Atheros Commnucations) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-07-21] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-12-21] (Intel Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [190032 2014-07-24] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2694040 2014-07-22] (Adobe Systems Incorporated) HKU\S-1-5-21-3873043628-1780199607-4098311539-1000\...\Run: [CAHeadless] => C:\Program Files (x86)\Adobe\Elements 12 Organizer\CAHeadless\ElementsAutoAnalyzer.exe [1400224 2013-09-03] (Adobe Systems Incorporated) Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: AccExtIco1 -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll () ShellIconOverlayIdentifiers: AccExtIco2 -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll () ShellIconOverlayIdentifiers: AccExtIco3 -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll () ShellIconOverlayIdentifiers: "DropboxExt1" -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: "DropboxExt2" -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: "DropboxExt3" -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: "DropboxExt4" -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: "DropboxExt5" -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: "DropboxExt6" -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: "DropboxExt7" -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers: "DropboxExt8" -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\User\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.) BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyServer: localhost:8080 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6DE76A2ECC72CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) Tcpip\Parameters: [DhcpNameServer] 62.2.17.60 62.2.24.162 62.2.17.61 62.2.24.158 FireFox: ======== FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\l2fwmsro.default FF SelectedSearchEngine: Google FF Homepage: www.google.ch FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DownThemAll! - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\l2fwmsro.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2014-07-17] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-09] CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-09] CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-09] CHR Extension: (Google Search) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-09] CHR Extension: (Skype Click to Call) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-08-08] CHR Extension: (Norton Security Toolbar) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2014-07-09] CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-09] CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-09] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-07-21] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-21] (Avira Operations GmbH & Co. KG) R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-05-17] () R2 ASGT; C:\Windows\SysWOW64\ASGT.exe [55296 2012-01-17] () [File not signed] R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-24] (Avira Operations GmbH & Co. KG) R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [240584 2012-10-02] (DTS, Inc) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation) R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [327296 2012-11-29] (Atheros) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31920 2013-06-02] (Wondershare) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [47512 2013-01-10] (Asmedia Technology) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-05-17] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-09] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-07-09] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG) R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [495376 2013-05-30] (Intel Corporation) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-07] (Intel Corporation) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation) S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [8192 2005-03-29] () R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 cleanhlp; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [X] S3 cpuz137; \??\C:\Windows\TEMP\cpuz137\cpuz137_x64.sys [X] S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X] R4 IOMap; \??\C:\Windows\system32\drivers\IOMap64.sys [X] S0 PxHlpa64; System32\drivers\PxHlpa64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-15 11:33 - 2014-08-15 11:33 - 00000000 ____D () C:\AdwCleaner 2014-08-15 11:32 - 2014-08-15 11:32 - 01356107 _____ () C:\Users\User\Downloads\adwcleaner_3.305.exe 2014-08-15 11:31 - 2014-08-15 11:31 - 00041069 _____ () C:\Users\User\Desktop\mbam.txt 2014-08-15 11:25 - 2014-08-15 11:25 - 02100224 _____ (Farbar) C:\Users\User\Downloads\FRST64(2).exe 2014-08-15 11:20 - 2014-08-15 11:21 - 00000824 _____ () C:\Users\User\Desktop\JRT.txt 2014-08-15 11:18 - 2014-08-15 11:18 - 00000000 ____D () C:\Windows\ERUNT 2014-08-15 11:16 - 2014-08-15 11:16 - 01016261 _____ (Thisisu) C:\Users\User\Desktop\JRT.exe 2014-08-15 11:16 - 2014-08-15 11:16 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-15 11:15 - 2014-08-15 11:15 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-15 11:15 - 2014-08-15 11:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-15 11:15 - 2014-08-15 11:15 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-15 11:15 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-08-15 11:15 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-08-15 11:15 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-08-15 11:04 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll 2014-08-15 11:04 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll 2014-08-15 11:04 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2014-08-15 11:04 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2014-08-15 11:04 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe 2014-08-15 11:04 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll 2014-08-15 11:04 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe 2014-08-15 11:04 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll 2014-08-15 10:48 - 2014-08-15 10:48 - 02101760 _____ (Farbar) C:\Users\User\Downloads\FRST64(3).exe 2014-08-15 10:47 - 2014-08-15 10:47 - 00000862 _____ () C:\Users\User\Desktop\securityheck.txt 2014-08-15 10:44 - 2014-08-15 10:44 - 00854417 _____ () C:\Users\User\Desktop\SecurityCheck.exe 2014-08-15 10:32 - 2014-08-15 10:33 - 02347384 _____ (ESET) C:\Users\User\Downloads\esetsmartinstaller_deu.exe 2014-08-14 15:30 - 2014-08-14 15:25 - 00000000 ____D () C:\Qoobox 2014-08-14 15:30 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-08-14 15:30 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-08-14 15:30 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-08-14 15:30 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-08-14 15:30 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-08-14 15:30 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-08-14 15:30 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-08-14 15:30 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-08-14 15:29 - 2014-08-14 15:28 - 00000000 ____D () C:\Windows\erdnt 2014-08-14 15:29 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-14 15:29 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-08-14 15:29 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-08-14 15:29 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-08-14 15:29 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-08-14 15:29 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-08-14 15:29 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-08-14 15:29 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-08-14 15:29 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-08-14 15:29 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-08-14 15:29 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-08-14 15:29 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-08-14 15:29 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-08-14 15:29 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-08-14 15:29 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-08-14 15:29 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-08-14 15:29 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-08-14 15:29 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-08-14 15:29 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-08-14 15:29 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-08-14 15:29 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-08-14 15:29 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-08-14 15:29 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-08-14 15:29 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-08-14 15:29 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-08-14 15:29 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-08-14 15:29 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-08-14 15:29 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-08-14 15:29 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-08-14 15:29 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-08-14 15:29 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-08-14 15:29 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-08-14 15:29 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-08-14 15:29 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-08-14 15:29 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-08-14 15:29 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-08-14 15:29 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-08-14 15:29 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-08-14 15:29 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-08-14 15:29 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-08-14 15:29 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-08-14 15:29 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-08-14 15:29 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-08-14 15:29 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-08-14 15:29 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-08-14 15:29 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-08-14 15:29 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-08-14 15:29 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-08-14 15:29 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-08-14 15:29 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-08-14 15:29 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-08-14 15:29 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-08-14 15:29 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-08-14 15:29 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-08-14 15:29 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-08-14 15:29 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-08-14 15:29 - 2014-07-16 05:25 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-08-14 15:29 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-08-14 15:29 - 2014-07-16 04:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-08-14 15:29 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-08-14 15:29 - 2014-07-16 04:12 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-08-14 15:29 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-08-14 15:29 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-08-14 15:29 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-08-14 15:29 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-08-14 15:29 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-08-14 15:29 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2014-08-14 15:29 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2014-08-14 15:29 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2014-08-14 15:29 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2014-08-14 15:29 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2014-08-14 15:29 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-08-14 15:29 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls 2014-08-14 15:29 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-08-14 15:29 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-08-14 15:29 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2014-08-14 15:29 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-08-14 15:29 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2014-08-14 15:29 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll 2014-08-14 15:29 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe 2014-08-14 15:29 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-08-14 15:29 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2014-08-14 15:29 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll 2014-08-14 15:28 - 2014-08-14 15:28 - 05571579 ____R (Swearware) C:\Users\User\Desktop\ComboFix.exe 2014-08-14 15:28 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2014-08-14 15:28 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2014-08-14 15:27 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-14 15:27 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-14 15:25 - 2014-08-14 15:34 - 00034163 _____ () C:\ComboFix.txt 2014-08-14 15:24 - 2014-08-14 15:25 - 00000000 ____D () C:\ComboFix 2014-08-11 13:41 - 2014-08-11 13:41 - 00000087 _____ () C:\Users\User\Desktop\Maxi N.txt 2014-08-11 13:37 - 2014-08-11 13:37 - 00000000 ____D () C:\Users\User\Desktop\Adobe 2014-08-11 13:35 - 2014-08-11 13:35 - 00125999 _____ () C:\Users\User\Desktop\GMER.log 2014-08-11 13:32 - 2014-08-11 13:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\PDAppFlex 2014-08-11 13:31 - 2014-08-11 13:00 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-08-11 13:25 - 2014-08-11 13:25 - 00000000 ___RD () C:\Users\User\Creative Cloud Files 2014-08-11 13:24 - 2014-08-11 13:24 - 00002212 _____ () C:\Users\Public\Desktop\Google Earth.lnk 2014-08-11 13:24 - 2014-08-11 13:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2014-08-11 13:23 - 2014-08-11 13:23 - 00895120 _____ (Google Inc.) C:\Users\User\Downloads\GoogleEarthSetup.exe 2014-08-11 13:23 - 2014-08-11 13:23 - 00001313 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk 2014-08-11 13:23 - 2014-08-11 13:23 - 00001301 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2014-08-11 13:18 - 2014-08-11 13:18 - 00614792 _____ (Adobe Systems Incorporated) C:\Users\User\Downloads\CreativeCloudSet-Up.exe 2014-08-11 13:17 - 2014-08-11 13:17 - 00000265 _____ () C:\Users\User\Desktop\tesr.txt 2014-08-11 13:11 - 2014-08-11 13:11 - 00000533 _____ () C:\Users\Public\Desktop\Maps2Bgl_X.lnk 2014-08-11 13:11 - 2014-08-11 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maps2Bgl_X 2014-08-11 13:11 - 2004-08-03 23:54 - 01712128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll 2014-08-11 13:00 - 2014-08-11 13:00 - 00380416 _____ () C:\Users\User\Downloads\wwmvbxht.exe 2014-08-11 13:00 - 2014-08-11 13:00 - 00056496 _____ (GMER) C:\kxldapob.sys 2014-08-11 12:50 - 2014-08-15 11:31 - 00067940 _____ () C:\Users\User\Desktop\FRST.txt 2014-08-11 12:49 - 2014-08-11 12:49 - 02099712 _____ (Farbar) C:\Users\User\Downloads\FRST64(1).exe 2014-08-11 12:48 - 2014-08-15 11:27 - 00036406 _____ () C:\Users\User\Desktop\Addition.txt 2014-08-11 12:48 - 2014-08-11 12:48 - 00808704 _____ () C:\Windows\Minidump\081114-81214-01.dmp 2014-08-10 22:47 - 2014-08-15 11:27 - 00036406 _____ () C:\Users\User\Downloads\Addition.txt 2014-08-10 22:44 - 2014-08-15 11:10 - 00449794 _____ () C:\Windows\PFRO.log 2014-08-10 22:44 - 2014-08-15 10:48 - 00019114 _____ () C:\Users\User\Downloads\FRST.txt 2014-08-10 22:44 - 2014-08-15 10:48 - 00000000 ____D () C:\FRST 2014-08-10 22:43 - 2014-08-10 22:44 - 02099712 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe 2014-08-09 15:19 - 2014-08-09 15:19 - 00069340 _____ () C:\Users\User\Documents\OS 737 land loww 29.frc 2014-08-09 15:14 - 2014-08-09 15:14 - 00000000 ____D () C:\ProgramData\Emsisoft 2014-08-09 15:06 - 2014-08-14 16:08 - 00000000 ____D () C:\Users\User\Desktop\Unbenannter Export 2014-08-09 15:03 - 2014-08-09 15:03 - 00000000 ____D () C:\Users\User\Documents\ProcAlyzer Dumps 2014-08-09 14:59 - 2014-08-09 14:59 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\User\Downloads\tdsskiller.exe 2014-08-09 14:59 - 2014-08-09 14:59 - 00192698 _____ () C:\Users\User\Documents\LX563 climbing.frc 2014-08-09 14:54 - 2014-08-10 22:44 - 00000470 _____ () C:\Users\User\Desktop\defogger_disable.log 2014-08-09 14:53 - 2014-08-09 14:53 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-08-09 14:53 - 2014-08-09 14:53 - 00000000 ____D () C:\Users\User\AppData\Roaming\TuneUp Software 2014-08-09 14:52 - 2014-08-09 14:52 - 00050477 _____ () C:\Users\User\Downloads\Defogger.exe 2014-08-09 14:52 - 2014-08-09 14:52 - 00000470 _____ () C:\Users\User\Downloads\defogger_disable.log 2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\Users\User\AppData\Local\gtk-2.0 2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\Users\User\.thumbnails 2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Drzewiecki Design 2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 _____ () C:\Users\User\defogger_reenable 2014-08-09 14:51 - 2014-08-11 13:20 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-08-09 14:51 - 2014-08-11 12:48 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-08-09 14:50 - 2014-08-11 12:51 - 00000000 ____D () C:\$AVG 2014-08-09 14:50 - 2014-08-11 12:47 - 00000000 ____D () C:\ProgramData\AVG2014 2014-08-09 14:50 - 2014-08-09 14:50 - 00051469 _____ () C:\Users\User\Documents\LX563 taxi to rwy.frc 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Windows\System32\Tasks\Abelssoft 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Users\User\AppData\Roaming\Abelssoft 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Users\User\AppData\Local\Abelssoft 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\ProgramData\XDMessagingv4 2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\Users\User\AppData\Roaming\DesktopIconGoodgame 2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CHIP Updater 2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\Program Files (x86)\CHIP Updater 2014-08-09 14:48 - 2014-08-09 14:48 - 01101648 _____ () C:\Users\User\Downloads\SpyBot Search Destroy - CHIP-Installer.exe 2014-08-09 14:46 - 2014-08-11 13:14 - 00000000 ____D () C:\Users\User\.gimp-2.8 2014-08-09 14:46 - 2014-08-11 12:47 - 00000000 ____D () C:\ProgramData\MFAData 2014-08-09 14:46 - 2014-08-09 14:46 - 00000000 ____D () C:\Users\User\AppData\Local\MFAData 2014-08-09 14:46 - 2014-08-09 14:46 - 00000000 ____D () C:\Users\User\AppData\Local\gegl-0.2 2014-08-09 14:44 - 2014-08-09 14:45 - 168801544 _____ (AVG Technologies) C:\Users\User\Downloads\avg_avct_x64_all_2014_4744a7830.exe 2014-08-09 14:44 - 2014-08-09 14:44 - 00000894 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk 2014-08-09 14:43 - 2014-08-11 12:48 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware 2014-08-09 14:43 - 2014-08-09 14:44 - 00000000 ____D () C:\Program Files\GIMP 2 2014-08-09 14:41 - 2014-08-09 14:43 - 201035376 _____ (Emsisoft GmbH ) C:\Users\User\Downloads\EmsisoftAntiMalwareSetup.exe 2014-08-09 14:41 - 2014-08-09 14:41 - 90396104 _____ (The GIMP Team ) C:\Users\User\Downloads\gimp-2.8.10-setup.exe 2014-08-09 14:31 - 2014-08-09 14:31 - 00001490 _____ () C:\Users\User\AppData\Local\recently-used.xbel 2014-08-09 14:28 - 2014-08-09 14:47 - 00019279 _____ () C:\Users\User\Documents\LX563 pushback.frc 2014-08-08 20:59 - 2014-08-08 20:59 - 00000000 ____D () C:\Users\User\AppData\Local\World_of_AI 2014-08-08 20:54 - 2014-08-09 14:57 - 00000000 ____D () C:\Users\User\Desktop\IG 2014-08-08 20:48 - 2014-08-09 14:52 - 00000000 ____D () C:\Users\User\Desktop\WoAI 2014-08-08 20:41 - 2014-08-08 20:42 - 00000000 ____D () C:\Gramblr 2014-08-08 20:41 - 2014-08-08 20:41 - 00000654 _____ () C:\Users\User\Desktop\Gramblr.lnk 2014-08-08 20:41 - 2014-08-08 20:41 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gramblr 2014-07-21 18:29 - 2014-07-21 18:29 - 00055761 _____ () C:\Users\User\Documents\ab 738 to 28.frc 2014-07-21 18:25 - 2014-07-21 18:25 - 00028159 _____ () C:\Users\User\Documents\ab 738.frc 2014-07-21 18:19 - 2014-07-21 18:19 - 00000000 ____D () C:\Program Files (x86)\PMDG Operations Center 2014-07-21 18:10 - 2014-07-21 18:10 - 00036780 _____ () C:\Users\User\Documents\AB 737 descent.frc 2014-07-21 18:00 - 2014-07-21 18:00 - 00000000 ____D () C:\Users\User\AppData\Local\DriverToolkit 2014-07-21 17:59 - 2014-07-21 18:05 - 00000000 ____D () C:\Program Files (x86)\DriverToolkit 2014-07-21 17:59 - 2014-07-21 17:59 - 02395840 _____ (Megaify Software ) C:\Users\User\Downloads\driver_setup.exe 2014-07-21 17:59 - 2014-07-21 17:59 - 00061940 _____ () C:\Users\User\Documents\Ab 737 takeoff 28 lszh.frc 2014-07-21 17:57 - 2014-07-21 17:57 - 00000000 ____D () C:\Users\User\AppData\Local\Skype 2014-07-21 17:56 - 2014-08-09 15:15 - 00000000 ____D () C:\ProgramData\Skype 2014-07-21 17:56 - 2014-08-09 14:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\Skype 2014-07-21 17:56 - 2014-07-21 17:56 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-07-21 17:55 - 2014-07-21 17:55 - 01677928 _____ (Skype Technologies S.A.) C:\Users\User\Downloads\SkypeSetup.exe 2014-07-21 17:52 - 2014-07-21 17:52 - 00022720 _____ () C:\Users\User\Documents\AB 737 pushback.frc 2014-07-17 12:33 - 2014-07-17 12:33 - 00112593 _____ () C:\Users\User\Documents\frfghjj.frc 2014-07-17 12:27 - 2014-07-17 12:27 - 00091207 _____ () C:\Users\User\Documents\AB2876 takeoff muc.frc 2014-07-17 12:26 - 2014-07-17 12:26 - 00098607 _____ () C:\Users\User\Documents\AB2876 landing ltaiä.frc 2014-07-17 12:13 - 2014-07-17 12:13 - 02050655 _____ (Anthony Ribeiro ) C:\Users\User\Downloads\Boeing 747-8i Lufthansa v1.00.exe 2014-07-17 12:12 - 2014-07-17 12:12 - 46507041 _____ (SkySpirit2012 ) C:\Users\User\Downloads\Boeing 747-8i Basepack v1.40.exe 2014-07-17 11:49 - 2014-07-17 11:49 - 00000000 ____D () C:\found.000 ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-08-15 11:33 - 2014-08-15 11:33 - 00000000 ____D () C:\AdwCleaner 2014-08-15 11:32 - 2014-08-15 11:32 - 01356107 _____ () C:\Users\User\Downloads\adwcleaner_3.305.exe 2014-08-15 11:31 - 2014-08-15 11:31 - 00041069 _____ () C:\Users\User\Desktop\mbam.txt 2014-08-15 11:31 - 2014-08-11 12:50 - 00067940 _____ () C:\Users\User\Desktop\FRST.txt 2014-08-15 11:27 - 2014-08-11 12:48 - 00036406 _____ () C:\Users\User\Desktop\Addition.txt 2014-08-15 11:27 - 2014-08-10 22:47 - 00036406 _____ () C:\Users\User\Downloads\Addition.txt 2014-08-15 11:25 - 2014-08-15 11:25 - 02100224 _____ (Farbar) C:\Users\User\Downloads\FRST64(2).exe 2014-08-15 11:21 - 2014-08-15 11:20 - 00000824 _____ () C:\Users\User\Desktop\JRT.txt 2014-08-15 11:18 - 2014-08-15 11:18 - 00000000 ____D () C:\Windows\ERUNT 2014-08-15 11:16 - 2014-08-15 11:16 - 01016261 _____ (Thisisu) C:\Users\User\Desktop\JRT.exe 2014-08-15 11:16 - 2014-08-15 11:16 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-08-15 11:15 - 2014-08-15 11:15 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.2.1012.exe 2014-08-15 11:15 - 2014-08-15 11:15 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-08-15 11:15 - 2014-08-15 11:15 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-08-15 11:14 - 2014-05-09 18:44 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-08-15 11:11 - 2009-07-14 06:45 - 00628392 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-08-15 11:10 - 2014-08-10 22:44 - 00449794 _____ () C:\Windows\PFRO.log 2014-08-15 11:09 - 2014-03-13 13:01 - 00000000 ____D () C:\Windows\system32\MRT 2014-08-15 11:09 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-08-15 11:08 - 2014-05-02 21:45 - 00000000 ____D () C:\Users\User\Documents\Flight Simulator X-Dateien 2014-08-15 11:08 - 2014-05-02 12:32 - 00000000 ____D () C:\Program Files (x86)\FS Recorder for FSX 2014-08-15 11:08 - 2014-03-13 13:01 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-08-15 11:04 - 2014-05-09 18:32 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-08-15 11:04 - 2014-04-25 14:20 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-08-15 10:48 - 2014-08-15 10:48 - 02101760 _____ (Farbar) C:\Users\User\Downloads\FRST64(3).exe 2014-08-15 10:48 - 2014-08-10 22:44 - 00019114 _____ () C:\Users\User\Downloads\FRST.txt 2014-08-15 10:48 - 2014-08-10 22:44 - 00000000 ____D () C:\FRST 2014-08-15 10:47 - 2014-08-15 10:47 - 00000862 _____ () C:\Users\User\Desktop\securityheck.txt 2014-08-15 10:44 - 2014-08-15 10:44 - 00854417 _____ () C:\Users\User\Desktop\SecurityCheck.exe 2014-08-15 10:36 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-08-15 10:36 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-08-15 10:33 - 2014-08-15 10:32 - 02347384 _____ (ESET) C:\Users\User\Downloads\esetsmartinstaller_deu.exe 2014-08-15 10:29 - 2014-05-19 20:33 - 00018772 _____ () C:\Windows\setupact.log 2014-08-15 10:29 - 2014-05-01 21:00 - 00000000 ____D () C:\Users\User\AppData\Local\Adobe 2014-08-15 10:28 - 2014-07-09 20:59 - 00000000 ___RD () C:\Users\User\Dropbox 2014-08-15 10:28 - 2014-07-09 20:52 - 00000000 ____D () C:\Users\User\AppData\Roaming\Dropbox 2014-08-15 10:27 - 2014-05-19 20:36 - 01846735 _____ () C:\Windows\WindowsUpdate.log 2014-08-15 10:27 - 2014-05-09 18:32 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-08-15 10:27 - 2014-04-25 12:56 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-08-15 10:27 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-08-14 16:23 - 2011-04-12 09:43 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer 2014-08-14 16:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\MUI 2014-08-14 16:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\MUI 2014-08-14 16:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\servicing 2014-08-14 16:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared 2014-08-14 16:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-08-14 16:08 - 2014-08-09 15:06 - 00000000 ____D () C:\Users\User\Desktop\Unbenannter Export 2014-08-14 15:34 - 2014-08-14 15:25 - 00034163 _____ () C:\ComboFix.txt 2014-08-14 15:34 - 2014-05-01 10:01 - 00000000 ____D () C:\ProgramData\TEMP 2014-08-14 15:28 - 2014-08-14 15:29 - 00000000 ____D () C:\Windows\erdnt 2014-08-14 15:28 - 2014-08-14 15:28 - 05571579 ____R (Swearware) C:\Users\User\Desktop\ComboFix.exe 2014-08-14 15:25 - 2014-08-14 15:30 - 00000000 ____D () C:\Qoobox 2014-08-14 15:25 - 2014-08-14 15:24 - 00000000 ____D () C:\ComboFix 2014-08-14 15:23 - 2014-05-03 12:04 - 00000000 ____D () C:\Users\User\AppData\Local\CrashDumps 2014-08-14 15:22 - 2014-07-09 20:59 - 00000976 _____ () C:\Users\User\Desktop\Dropbox.lnk 2014-08-14 15:22 - 2014-07-09 20:53 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-08-14 15:21 - 2014-07-09 20:55 - 00000000 ____D () C:\Program Files\Adobe 2014-08-14 15:20 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-08-11 13:41 - 2014-08-11 13:41 - 00000087 _____ () C:\Users\User\Desktop\Maxi N.txt 2014-08-11 13:40 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-08-11 13:37 - 2014-08-11 13:37 - 00000000 ____D () C:\Users\User\Desktop\Adobe 2014-08-11 13:35 - 2014-08-11 13:35 - 00125999 _____ () C:\Users\User\Desktop\GMER.log 2014-08-11 13:34 - 2014-08-11 13:28 - 976158128 _____ (Adobe Systems Incorporated) C:\Users\User\Downloads\Lightroom_5_LS11.exe 2014-08-11 13:32 - 2014-08-11 13:32 - 00000000 ____D () C:\Users\User\AppData\Roaming\PDAppFlex 2014-08-11 13:31 - 2014-05-01 21:00 - 00000000 ____D () C:\ProgramData\Adobe 2014-08-11 13:25 - 2014-08-11 13:25 - 00000000 ___RD () C:\Users\User\Creative Cloud Files 2014-08-11 13:25 - 2014-04-25 11:05 - 00000000 ____D () C:\Users\User\AppData\Roaming\Adobe 2014-08-11 13:24 - 2014-08-11 13:24 - 00002212 _____ () C:\Users\Public\Desktop\Google Earth.lnk 2014-08-11 13:24 - 2014-08-11 13:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2014-08-11 13:24 - 2014-05-09 18:32 - 00000000 ____D () C:\Users\User\AppData\Local\Google 2014-08-11 13:24 - 2014-05-09 18:32 - 00000000 ____D () C:\Program Files (x86)\Google 2014-08-11 13:23 - 2014-08-11 13:23 - 00895120 _____ (Google Inc.) C:\Users\User\Downloads\GoogleEarthSetup.exe 2014-08-11 13:23 - 2014-08-11 13:23 - 00001313 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk 2014-08-11 13:23 - 2014-08-11 13:23 - 00001301 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2014-08-11 13:22 - 2014-05-02 17:56 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-11 13:20 - 2014-08-09 14:51 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-08-11 13:20 - 2014-05-01 21:00 - 00000000 ____D () C:\Program Files (x86)\Adobe 2014-08-11 13:18 - 2014-08-11 13:18 - 00614792 _____ (Adobe Systems Incorporated) C:\Users\User\Downloads\CreativeCloudSet-Up.exe 2014-08-11 13:17 - 2014-08-11 13:17 - 00000265 _____ () C:\Users\User\Desktop\tesr.txt 2014-08-11 13:14 - 2014-08-09 14:46 - 00000000 ____D () C:\Users\User\.gimp-2.8 2014-08-11 13:11 - 2014-08-11 13:11 - 00000533 _____ () C:\Users\Public\Desktop\Maps2Bgl_X.lnk 2014-08-11 13:11 - 2014-08-11 13:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maps2Bgl_X 2014-08-11 13:00 - 2014-08-11 13:31 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe 2014-08-11 13:00 - 2014-08-11 13:00 - 00380416 _____ () C:\Users\User\Downloads\wwmvbxht.exe 2014-08-11 13:00 - 2014-08-11 13:00 - 00056496 _____ (GMER) C:\kxldapob.sys 2014-08-11 12:51 - 2014-08-09 14:50 - 00000000 ____D () C:\$AVG 2014-08-11 12:49 - 2014-08-11 12:49 - 02099712 _____ (Farbar) C:\Users\User\Downloads\FRST64(1).exe 2014-08-11 12:48 - 2014-08-11 12:48 - 00808704 _____ () C:\Windows\Minidump\081114-81214-01.dmp 2014-08-11 12:48 - 2014-08-09 14:51 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-08-11 12:48 - 2014-08-09 14:43 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware 2014-08-11 12:48 - 2014-05-19 20:33 - 1290543419 _____ () C:\Windows\MEMORY.DMP 2014-08-11 12:48 - 2014-05-17 17:07 - 00000000 ____D () C:\Windows\Minidump 2014-08-11 12:47 - 2014-08-09 14:50 - 00000000 ____D () C:\ProgramData\AVG2014 2014-08-11 12:47 - 2014-08-09 14:46 - 00000000 ____D () C:\ProgramData\MFAData 2014-08-11 12:47 - 2014-05-18 10:47 - 00000000 ____D () C:\ProgramData\Norton 2014-08-10 22:44 - 2014-08-10 22:43 - 02099712 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe 2014-08-10 22:44 - 2014-08-09 14:54 - 00000470 _____ () C:\Users\User\Desktop\defogger_disable.log 2014-08-09 15:22 - 2014-07-09 23:51 - 00000472 _____ () C:\Windows\Pitch Target 2014-08-09 15:22 - 2014-07-09 23:51 - 00000466 _____ () C:\Windows\Roll Target 2014-08-09 15:22 - 2014-07-09 23:51 - 00000462 _____ () C:\Windows\Roll Error 2014-08-09 15:22 - 2014-07-09 23:51 - 00000462 _____ () C:\Windows\Pitch Error 2014-08-09 15:22 - 2014-07-09 23:51 - 00000462 _____ () C:\Windows\Gyro Speed 2014-08-09 15:22 - 2014-07-09 23:51 - 00000423 _____ () C:\Windows\Mode2BTimer 2014-08-09 15:22 - 2014-07-09 23:51 - 00000423 _____ () C:\Windows\Mode2_AltGain_timer 2014-08-09 15:22 - 2014-07-09 23:51 - 00000419 _____ () C:\Windows\Mode2ATimer 2014-08-09 15:22 - 2014-07-09 23:51 - 00000271 _____ () C:\Windows\CDU.1 2014-08-09 15:22 - 2014-07-09 23:51 - 00000271 _____ () C:\Windows\CDU.0 2014-08-09 15:20 - 2014-05-01 20:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aerosoft 2014-08-09 15:19 - 2014-08-09 15:19 - 00069340 _____ () C:\Users\User\Documents\OS 737 land loww 29.frc 2014-08-09 15:16 - 2014-05-03 12:33 - 00024400 _____ () C:\Users\User\AppData\Roaming\Notepad2.ini 2014-08-09 15:15 - 2014-07-21 17:56 - 00000000 ____D () C:\ProgramData\Skype 2014-08-09 15:15 - 2014-04-25 11:27 - 00167000 _____ () C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT 2014-08-09 15:14 - 2014-08-09 15:14 - 00000000 ____D () C:\ProgramData\Emsisoft 2014-08-09 15:03 - 2014-08-09 15:03 - 00000000 ____D () C:\Users\User\Documents\ProcAlyzer Dumps 2014-08-09 14:59 - 2014-08-09 14:59 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\User\Downloads\tdsskiller.exe 2014-08-09 14:59 - 2014-08-09 14:59 - 00192698 _____ () C:\Users\User\Documents\LX563 climbing.frc 2014-08-09 14:57 - 2014-08-08 20:54 - 00000000 ____D () C:\Users\User\Desktop\IG 2014-08-09 14:53 - 2014-08-09 14:53 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-08-09 14:53 - 2014-08-09 14:53 - 00000000 ____D () C:\Users\User\AppData\Roaming\TuneUp Software 2014-08-09 14:52 - 2014-08-09 14:52 - 00050477 _____ () C:\Users\User\Downloads\Defogger.exe 2014-08-09 14:52 - 2014-08-09 14:52 - 00000470 _____ () C:\Users\User\Downloads\defogger_disable.log 2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\Users\User\AppData\Local\gtk-2.0 2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 ____D () C:\Users\User\.thumbnails 2014-08-09 14:52 - 2014-08-09 14:52 - 00000000 _____ () C:\Users\User\defogger_reenable 2014-08-09 14:52 - 2014-08-08 20:48 - 00000000 ____D () C:\Users\User\Desktop\WoAI 2014-08-09 14:50 - 2014-08-09 14:50 - 00051469 _____ () C:\Users\User\Documents\LX563 taxi to rwy.frc 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Windows\System32\Tasks\Abelssoft 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Users\User\AppData\Roaming\Abelssoft 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\Users\User\AppData\Local\Abelssoft 2014-08-09 14:50 - 2014-08-09 14:50 - 00000000 ____D () C:\ProgramData\XDMessagingv4 2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\Users\User\AppData\Roaming\DesktopIconGoodgame 2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CHIP Updater 2014-08-09 14:49 - 2014-08-09 14:49 - 00000000 ____D () C:\Program Files (x86)\CHIP Updater 2014-08-09 14:48 - 2014-08-09 14:48 - 01101648 _____ () C:\Users\User\Downloads\SpyBot Search Destroy - CHIP-Installer.exe 2014-08-09 14:47 - 2014-08-09 14:28 - 00019279 _____ () C:\Users\User\Documents\LX563 pushback.frc 2014-08-09 14:46 - 2014-08-09 14:46 - 00000000 ____D () C:\Users\User\AppData\Local\MFAData 2014-08-09 14:46 - 2014-08-09 14:46 - 00000000 ____D () C:\Users\User\AppData\Local\gegl-0.2 2014-08-09 14:45 - 2014-08-09 14:44 - 168801544 _____ (AVG Technologies) C:\Users\User\Downloads\avg_avct_x64_all_2014_4744a7830.exe 2014-08-09 14:45 - 2014-07-09 21:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PMDG Simulations 2014-08-09 14:45 - 2014-04-25 11:15 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-08-09 14:44 - 2014-08-09 14:44 - 00000894 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk 2014-08-09 14:44 - 2014-08-09 14:43 - 00000000 ____D () C:\Program Files\GIMP 2 2014-08-09 14:43 - 2014-08-09 14:41 - 201035376 _____ (Emsisoft GmbH ) C:\Users\User\Downloads\EmsisoftAntiMalwareSetup.exe 2014-08-09 14:41 - 2014-08-09 14:41 - 90396104 _____ (The GIMP Team ) C:\Users\User\Downloads\gimp-2.8.10-setup.exe 2014-08-09 14:39 - 2014-05-01 20:01 - 00000000 ____D () C:\Users\User\AppData\Roaming\uTorrent 2014-08-09 14:34 - 2014-07-09 16:47 - 00000000 ____D () C:\Users\User\AppData\Local\Sony 2014-08-09 14:34 - 2014-07-09 16:47 - 00000000 ____D () C:\Program Files\Sony 2014-08-09 14:34 - 2014-07-09 16:46 - 00000000 ____D () C:\ProgramData\Sony 2014-08-09 14:33 - 2014-05-18 19:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-08-09 14:32 - 2014-07-21 17:56 - 00000000 ____D () C:\Users\User\AppData\Roaming\Skype 2014-08-09 14:31 - 2014-08-09 14:31 - 00001490 _____ () C:\Users\User\AppData\Local\recently-used.xbel 2014-08-09 14:28 - 2014-05-18 19:41 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-08-09 14:28 - 2014-05-18 19:41 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-08-08 21:18 - 2014-05-01 09:54 - 00000000 ____D () C:\ProgramData\Esellerate 2014-08-08 20:59 - 2014-08-08 20:59 - 00000000 ____D () C:\Users\User\AppData\Local\World_of_AI 2014-08-08 20:42 - 2014-08-08 20:41 - 00000000 ____D () C:\Gramblr 2014-08-08 20:41 - 2014-08-08 20:41 - 00000654 _____ () C:\Users\User\Desktop\Gramblr.lnk 2014-08-08 20:41 - 2014-08-08 20:41 - 00000000 ____D () C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gramblr 2014-08-08 20:39 - 2014-08-08 21:20 - 00000000 ____D () C:\Users\User\AppData\Roaming\Virtuali 2014-08-08 20:32 - 2014-04-30 21:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-08-07 04:06 - 2014-08-14 15:27 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-08-07 04:01 - 2014-08-14 15:27 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-08-05 09:20 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-08-01 01:41 - 2014-08-14 15:29 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-08-01 01:16 - 2014-08-14 15:29 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-07-25 16:52 - 2014-08-14 15:29 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-07-25 16:02 - 2014-08-14 15:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-07-25 16:01 - 2014-08-14 15:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-07-25 15:51 - 2014-08-14 15:29 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-07-25 15:30 - 2014-08-14 15:29 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-07-25 15:28 - 2014-08-14 15:29 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-07-25 15:28 - 2014-08-14 15:29 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-07-25 15:25 - 2014-08-14 15:29 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-07-25 15:25 - 2014-08-14 15:29 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-07-25 15:11 - 2014-08-14 15:29 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-07-25 15:10 - 2014-08-14 15:29 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-07-25 15:04 - 2014-08-14 15:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-07-25 15:03 - 2014-08-14 15:29 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-07-25 15:00 - 2014-08-14 15:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-07-25 15:00 - 2014-08-14 15:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-07-25 14:59 - 2014-08-14 15:29 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-07-25 14:47 - 2014-08-14 15:29 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-07-25 14:40 - 2014-08-14 15:29 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-07-25 14:34 - 2014-08-14 15:29 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-07-25 14:34 - 2014-08-14 15:29 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-07-25 14:33 - 2014-08-14 15:29 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-07-25 14:30 - 2014-08-14 15:29 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-07-25 14:28 - 2014-08-14 15:29 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-07-25 14:28 - 2014-08-14 15:29 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-07-25 14:21 - 2014-08-14 15:29 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-07-25 14:19 - 2014-08-14 15:29 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-07-25 14:18 - 2014-08-14 15:29 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-07-25 14:17 - 2014-08-14 15:29 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-07-25 14:17 - 2014-08-14 15:29 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-07-25 14:12 - 2014-08-14 15:29 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-07-25 14:10 - 2014-08-14 15:29 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-07-25 14:10 - 2014-08-14 15:29 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-07-25 14:08 - 2014-08-14 15:29 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-07-25 14:06 - 2014-08-14 15:29 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-07-25 13:52 - 2014-08-14 15:29 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-07-25 13:47 - 2014-08-14 15:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-07-25 13:43 - 2014-08-14 15:29 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-07-25 13:42 - 2014-08-14 15:29 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-07-25 13:39 - 2014-08-14 15:29 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-07-25 13:39 - 2014-08-14 15:29 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-07-25 13:36 - 2014-08-14 15:29 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-07-25 13:34 - 2014-08-14 15:29 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-07-25 13:29 - 2014-08-14 15:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-07-25 13:23 - 2014-08-14 15:29 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-07-25 13:13 - 2014-08-14 15:29 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-07-25 13:07 - 2014-08-14 15:29 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-07-25 13:07 - 2014-08-14 15:29 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-07-25 13:03 - 2014-08-14 15:29 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-07-25 12:52 - 2014-08-14 15:29 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-07-25 12:26 - 2014-08-14 15:29 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-07-25 12:17 - 2014-08-14 15:29 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-07-25 12:09 - 2014-08-14 15:29 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-07-25 12:05 - 2014-08-14 15:29 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-07-25 12:00 - 2014-08-14 15:29 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-07-21 18:40 - 2014-05-02 13:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games 2014-07-21 18:39 - 2014-05-04 19:56 - 00000000 ____D () C:\Users\User\Desktop\Addons 2014-07-21 18:29 - 2014-07-21 18:29 - 00055761 _____ () C:\Users\User\Documents\ab 738 to 28.frc 2014-07-21 18:25 - 2014-07-21 18:25 - 00028159 _____ () C:\Users\User\Documents\ab 738.frc 2014-07-21 18:23 - 2014-07-09 22:00 - 00000000 ___HD () C:\Windows\msdownld.tmp 2014-07-21 18:23 - 2014-07-09 22:00 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-07-21 18:10 - 2014-07-21 18:10 - 00036780 _____ () C:\Users\User\Documents\AB 737 descent.frc 2014-07-21 18:05 - 2014-07-21 17:59 - 00000000 ____D () C:\Program Files (x86)\DriverToolkit 2014-07-21 18:00 - 2014-07-21 18:00 - 00000000 ____D () C:\Users\User\AppData\Local\DriverToolkit 2014-07-21 17:59 - 2014-07-21 17:59 - 02395840 _____ (Megaify Software ) C:\Users\User\Downloads\driver_setup.exe 2014-07-21 17:59 - 2014-07-21 17:59 - 00061940 _____ () C:\Users\User\Documents\Ab 737 takeoff 28 lszh.frc 2014-07-21 17:57 - 2014-07-21 17:57 - 00000000 ____D () C:\Users\User\AppData\Local\Skype 2014-07-21 17:56 - 2014-07-21 17:56 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk 2014-07-21 17:56 - 2014-05-02 17:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2014-07-21 17:56 - 2014-05-02 17:56 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-07-21 17:55 - 2014-07-21 17:55 - 01677928 _____ (Skype Technologies S.A.) C:\Users\User\Downloads\SkypeSetup.exe 2014-07-21 17:52 - 2014-07-21 17:52 - 00022720 _____ () C:\Users\User\Documents\AB 737 pushback.frc 2014-07-21 17:49 - 2014-07-09 21:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-07-17 12:33 - 2014-07-17 12:33 - 00112593 _____ () C:\Users\User\Documents\frfghjj.frc 2014-07-17 12:27 - 2014-07-17 12:27 - 00091207 _____ () C:\Users\User\Documents\AB2876 takeoff muc.frc 2014-07-17 12:26 - 2014-07-17 12:26 - 00098607 _____ () C:\Users\User\Documents\AB2876 landing ltaiä.frc 2014-07-17 12:13 - 2014-07-17 12:13 - 02050655 _____ (Anthony Ribeiro ) C:\Users\User\Downloads\Boeing 747-8i Lufthansa v1.00.exe 2014-07-17 12:12 - 2014-07-17 12:12 - 46507041 _____ (SkySpirit2012 ) C:\Users\User\Downloads\Boeing 747-8i Basepack v1.40.exe 2014-07-17 12:03 - 2014-07-09 21:00 - 00000000 ____D () C:\Users\User\Documents\Adobe 2014-07-17 11:58 - 2014-07-09 20:56 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-07-17 11:50 - 2014-05-03 09:14 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-07-17 11:49 - 2014-07-17 11:49 - 00000000 ____D () C:\found.000 2014-07-16 05:25 - 2014-08-14 15:29 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2014-07-16 05:23 - 2014-08-14 15:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-07-16 04:46 - 2014-08-14 15:29 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2014-07-16 04:46 - 2014-08-14 15:29 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-07-16 04:12 - 2014-08-14 15:29 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys Some content of TEMP: ==================== C:\Users\User\AppData\Local\Temp\avgnt.exe C:\Users\User\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp9zo3co.dll C:\Users\User\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-09 15:26 ==================== End Of Log ============================ --- --- --- |
17.08.2014, 14:57 | #22 |
/// the machine /// TB-Ausbilder | Firefox kommt auf Yahoo 404 - "page not found" Flash updaten. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter ProxyServer: localhost:8080 Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.08.2014, 12:34 | #23 |
| Firefox kommt auf Yahoo 404 - "page not found"Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-08-2014 01 Ran by User at 2014-08-18 11:19:50 Run:1 Running from C:\Users\User\Desktop Boot Mode: Normal ============================================== Content of fixlist: ***************** ProxyServer: localhost:8080 ***************** HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value not found. ==== End of Fixlog ==== Jetzt ist alles weg? Na dann,vielen Dank! |
19.08.2014, 04:37 | #24 |
/// the machine /// TB-Ausbilder | Firefox kommt auf Yahoo 404 - "page not found" Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Firefox kommt auf Yahoo 404 - "page not found" |
aufrufe, firefox, found, leitet, neue, neuen, not, pup.optional.searchprotect.a, pup.optional.trovi, pup.optional.trovi.a, tagen, win32/clientconnect.a, win32/downloadsponsor.a, yahoo, yahoo 404 |