|
Log-Analyse und Auswertung: Lässtige werbung trotz addblockWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
27.12.2014, 15:05 | #1 |
| Lässtige werbung trotz addblock Hi zusammen Seid Gestern habe ich in google chrome andauernd einblendende werbung die ich nicht weg bekomme die stört sowas von!!! benutze win 7 64 bit brauche Dringend Hilfe MFG Adrian FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-12-2014 Ran by Reisser (administrator) on REISSER-PC on 27-12-2014 15:01:45 Running from C:\Users\Reisser\Downloads Loaded Profile: Reisser (Available profiles: Reisser) Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Englisch (USA) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (CartCrunch Israel Ltd.) C:\ProgramData\SecurityUtility\ColorMedia.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\rcore.exe () C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Apple Inc.) C:\Program Files (x86)\QuickTime\qttask.exe () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Time Lapse Solutions) C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe (Abengine) C:\Program Files (x86)\Flwsrf\abengine.exe () C:\Program Files (x86)\Flwsrf\ijs.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Cinema HDV27.12) C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6.exe (globalUpdate) C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2463552 2014-10-04] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [282624 2007-04-27] (Apple Inc.) HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] () HKLM-x32\...\Run: [gmsd_de_44] => [X] HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Run: [LiveSupport] => "C:\Program Files (x86)\LiveSupport\LiveSupport.exe" /noshow /log HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Run: [SwvUpdtr] => C:\Users\Reisser\AppData\Local\24567\Updater.exe [773632 2014-12-27] () HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Run: [PCSpeedUp] => C:\Program Files (x86)\PC Speed Up\PCSUNotifier.exe [342472 2014-12-10] () HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: G - G:\StorioSetup.exe HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {2e971c8e-719e-11e4-b18f-bc5ff45b0bd1} - F:\SNC715MusicPlayer.exe HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {432e0770-7651-11e4-a244-806e6f6e6963} - F:\VTech_toy_Setup.exe HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {9dac61e2-89ed-11e4-b4c2-bc5ff45b0bd1} - G:\StorioSetup.exe CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:50863;https=127.0.0.1:50863 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = omiga-plus HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419615594&from=tugs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = omiga-plus HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419615594&from=tugs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Start Page = Tikotin HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Tikotin StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe omiga-plus SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419615594&from=tugs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419615594&from=tugs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope value is missing. SearchScopes: HKLM-x32 -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.searchoholic.info/?l=1&q={searchTerms}&pid=1091&r=2014/12/22&hid=8793653231034268742&lg=EN&cc=DE&unqvl=72 SearchScopes: HKU\S-1-5-21-1744345613-2801571155-2633355246-1000 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M967FE9C1-A9A5-43A2-8659-C914B636C4B4&SearchSource=58&CUI=&UM=8&UP=SP7CE64842-07CE-4A5F-8347-E1F6816C072C&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-1744345613-2801571155-2633355246-1000 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M967FE9C1-A9A5-43A2-8659-C914B636C4B4&SearchSource=58&CUI=&UM=8&UP=SP7CE64842-07CE-4A5F-8347-E1F6816C072C&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-1744345613-2801571155-2633355246-1000 -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.searchoholic.info/?l=1&q={searchTerms}&pid=1091&r=2014/12/22&hid=8793653231034268742&lg=EN&cc=DE&unqvl=72 BHO: CinemaHd For Pro 2.4cV27.12 -> {11111111-1111-1111-1111-110611571181} -> C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\CinemaHd For Pro 2.4cV27.12-bho64.dll (Cinema HDV27.12) BHO-x32: CinemaHd For Pro 2.4cV27.12 -> {11111111-1111-1111-1111-110611571181} -> C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\CinemaHd For Pro 2.4cV27.12-bho.dll (Cinema HDV27.12) BHO-x32: No Name -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> No File Winsock: Catalog9 01 C:\Windows\SysWOW64\abengine.dll [324592] (Abengine) Winsock: Catalog9 02 C:\Windows\SysWOW64\abengine.dll [324592] (Abengine) Winsock: Catalog9 03 C:\Windows\SysWOW64\abengine.dll [324592] (Abengine) Winsock: Catalog9 04 C:\Windows\SysWOW64\abengine.dll [324592] (Abengine) Winsock: Catalog9 16 C:\Windows\SysWOW64\abengine.dll [324592] (Abengine) Winsock: Catalog9-x64 01 C:\Windows\system32\abengine64.dll [370880] (Abengine) Winsock: Catalog9-x64 02 C:\Windows\system32\abengine64.dll [370880] (Abengine) Winsock: Catalog9-x64 03 C:\Windows\system32\abengine64.dll [370880] (Abengine) Winsock: Catalog9-x64 04 C:\Windows\system32\abengine64.dll [370880] (Abengine) Winsock: Catalog9-x64 05 C:\Windows\system32\ColorMedia64.dll [378640] (CartCrunch Israel Ltd.) Winsock: Catalog9-x64 06 C:\Windows\system32\ColorMedia64.dll [378640] (CartCrunch Israel Ltd.) Winsock: Catalog9-x64 07 C:\Windows\system32\ColorMedia64.dll [378640] (CartCrunch Israel Ltd.) Winsock: Catalog9-x64 08 C:\Windows\system32\ColorMedia64.dll [378640] (CartCrunch Israel Ltd.) Winsock: Catalog9-x64 20 C:\Windows\system32\ColorMedia64.dll [378640] (CartCrunch Israel Ltd.) Winsock: Catalog9-x64 21 C:\Windows\system32\abengine64.dll [370880] (Abengine) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate) FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome: ======= CHR HomePage: Default -> CHR StartupUrls: Default -> "" CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter} CHR Profile: C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-26] CHR Extension: (Google Docs) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-26] CHR Extension: (Google Drive) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-26] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-26] CHR Extension: (YouTube) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-26] CHR Extension: (Google Search) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-26] CHR Extension: (Google Sheets) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-26] CHR Extension: (Google Wallet) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-26] CHR Extension: (Gmail) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-26] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 abengine; C:\Program Files (x86)\Flwsrf\abengine.exe [1348168 2014-12-05] (Abengine) [File not signed] R2 ColorMedia; C:\ProgramData\SecurityUtility\ColorMedia.exe [1398576 2014-12-14] (CartCrunch Israel Ltd.) R2 dZPlDQFMAyN; C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe [2726776 2014-12-27] (Time Lapse Solutions) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-10-04] (NVIDIA Corporation) S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-12-27] (globalUpdate) [File not signed] S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-12-27] (globalUpdate) [File not signed] R2 InjectorService; C:\Program Files (x86)\Flwsrf\ijs.exe [164352 2014-11-29] () [File not signed] R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-10-04] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-10-04] (NVIDIA Corporation) R2 rcores; C:\Windows\rcore.exe [4963840 2014-12-25] () [File not signed] R2 SecurityUtility Service; C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe [537248 2014-12-25] () S2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe -service [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-10-04] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation) R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-27 15:01 - 2014-12-27 15:02 - 00016117 _____ () C:\Users\Reisser\Downloads\FRST.txt 2014-12-27 15:01 - 2014-12-27 15:01 - 02122752 _____ (Farbar) C:\Users\Reisser\Downloads\FRST64.exe 2014-12-27 15:01 - 2014-12-27 15:01 - 00000000 ____D () C:\FRST 2014-12-27 14:59 - 2014-12-27 14:59 - 00001137 _____ () C:\Users\Reisser\Desktop\Continue File Opener Installation.lnk 2014-12-27 14:48 - 2014-12-27 14:48 - 00797824 _____ ( ) C:\Users\Reisser\Downloads\FileOpenerSetup.exe 2014-12-27 14:29 - 2014-12-27 14:40 - 00000000 ____D () C:\Program Files (x86)\PC Speed Up 2014-12-27 14:29 - 2014-12-27 14:29 - 00003952 _____ () C:\Windows\System32\Tasks\amiupdaterExi 2014-12-27 14:29 - 2014-12-27 14:29 - 00003748 _____ () C:\Windows\System32\Tasks\amiupdaterExd 2014-12-27 14:29 - 2014-12-27 14:29 - 00002724 _____ () C:\Windows\System32\Tasks\PC SpeedUp Service Deactivator 2014-12-27 14:29 - 2014-12-27 14:29 - 00000344 _____ () C:\Windows\Tasks\PC SpeedUp Service Deactivator.job 2014-12-27 14:29 - 2014-12-27 14:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Up 2014-12-27 14:23 - 2014-12-27 14:23 - 00008564 _____ () C:\Windows\System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-7 2014-12-27 14:23 - 2014-12-27 14:23 - 00008562 _____ () C:\Windows\System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6 2014-12-27 14:23 - 2014-12-27 14:23 - 00006524 _____ () C:\Windows\System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-1 2014-12-27 14:23 - 2014-12-27 14:23 - 00005534 _____ () C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-7.job 2014-12-27 14:23 - 2014-12-27 14:23 - 00005534 _____ () C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6.job 2014-12-27 14:23 - 2014-12-27 14:23 - 00005492 _____ () C:\Windows\System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5 2014-12-27 14:23 - 2014-12-27 14:23 - 00005156 _____ () C:\Windows\System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-2 2014-12-27 14:23 - 2014-12-27 14:23 - 00003494 _____ () C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-1.job 2014-12-27 14:23 - 2014-12-27 14:23 - 00002462 _____ () C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5_user.job 2014-12-27 14:23 - 2014-12-27 14:23 - 00002462 _____ () C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5.job 2014-12-27 14:23 - 2014-12-27 14:23 - 00002126 _____ () C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-2.job 2014-12-27 14:23 - 2014-12-27 14:23 - 00000000 ____D () C:\Program Files (x86)\2f4249ae-2ea2-4d9e-8f18-8c64e6461106 2014-12-27 14:22 - 2014-12-27 14:23 - 00004376 _____ () C:\Windows\System32\Tasks\KWWB 2014-12-27 14:22 - 2014-12-27 14:23 - 00001342 _____ () C:\Windows\Tasks\KWWB.job 2014-12-27 14:22 - 2014-12-27 14:23 - 00000000 ____D () C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12 2014-12-27 14:22 - 2014-12-27 14:22 - 02055144 _____ (Cinema HDV27.12) C:\Users\Reisser\AppData\Roaming\KWWB.exe 2014-12-27 14:22 - 2014-12-27 14:22 - 00007540 _____ () C:\Windows\System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-3 2014-12-27 14:22 - 2014-12-27 14:22 - 00004510 _____ () C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-3.job 2014-12-27 14:22 - 2014-12-27 14:22 - 00000000 ____D () C:\Program Files (x86)\globalUpdate 2014-12-27 12:15 - 2014-12-27 12:15 - 00000000 ____D () C:\Users\Reisser\AppData\Local\24567 2014-12-27 11:53 - 2014-12-27 11:53 - 00004640 _____ () C:\Windows\SysWOW64\abengine.ini 2014-12-27 11:53 - 2014-12-27 11:53 - 00003090 _____ () C:\Windows\System32\Tasks\upfs7235 2014-12-27 11:53 - 2014-12-27 11:53 - 00002544 _____ () C:\Windows\SysWOW64\abengineOff.ini 2014-12-27 11:53 - 2014-12-27 11:53 - 00002544 _____ () C:\Windows\system32\abengineOff.ini 2014-12-27 11:53 - 2014-12-27 11:53 - 00000002 _____ () C:\END 2014-12-27 11:53 - 2014-12-27 11:53 - 00000000 ____D () C:\Program Files (x86)\Flwsrf 2014-12-27 11:53 - 2014-12-05 00:09 - 00370880 _____ (Abengine) C:\Windows\system32\abengine64.dll 2014-12-27 11:53 - 2014-12-05 00:09 - 00324592 _____ (Abengine) C:\Windows\SysWOW64\abengine.dll 2014-12-27 11:52 - 2014-12-27 14:51 - 00000000 ____D () C:\Users\Reisser\AppData\Local\ZombieInvasion 2014-12-27 11:52 - 2014-12-27 11:52 - 00000000 ____D () C:\ProgramData\ZombieInvasion 2014-12-27 11:52 - 2014-12-27 11:52 - 00000000 ____D () C:\ProgramData\qMuLXOMiMf 2014-12-26 20:54 - 2014-12-26 21:03 - 00000000 ____D () C:\Users\Reisser\Desktop\weihnachten 14 2014-12-26 20:45 - 2014-12-26 08:06 - 00008977 _____ () C:\Users\Reisser\Downloads\rla-dtvpmt1.ts.nfo 2014-12-26 20:45 - 2014-12-25 23:20 - 745466933 _____ () C:\Users\Reisser\Downloads\die tribute von Panem.mkv 2014-12-26 20:45 - 2014-12-23 12:02 - 00000220 _____ () C:\Users\Reisser\Downloads\Goldesel.to - Die Seite fuer Direkt-Downloads aller Art.url 2014-12-26 20:45 - 2014-12-23 12:02 - 00000116 _____ () C:\Users\Reisser\Downloads\goldesel.to - quality source for more than 15 years .txt 2014-12-26 20:35 - 2014-12-26 20:42 - 208666624 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part1.rar 2014-12-26 20:34 - 2014-12-26 20:42 - 208666624 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part3.rar 2014-12-26 20:34 - 2014-12-26 20:41 - 208666624 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part2.rar 2014-12-26 20:34 - 2014-12-26 20:38 - 126903232 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part4.rar 2014-12-26 19:28 - 2014-12-26 19:30 - 00002196 _____ () C:\Users\Reisser\Desktop\chrome.lnk 2014-12-26 19:18 - 2014-12-26 19:18 - 00003160 _____ () C:\Windows\System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B} 2014-12-26 19:12 - 2014-12-26 19:12 - 00003156 _____ () C:\Windows\System32\Tasks\Run_Bobby_Browser 2014-12-26 19:08 - 2014-12-26 19:08 - 00000000 ____D () C:\Program Files (x86)\predm 2014-12-26 19:06 - 2014-12-26 19:06 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\dlg 2014-12-26 19:05 - 2014-12-26 19:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-12-26 19:04 - 2014-12-27 11:44 - 00005240 _____ () C:\Windows\SysWOW64\ColorMedia.ini 2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\SysWOW64\ColorMediaOff.ini 2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\system32\ColorMediaOff.ini 2014-12-26 19:04 - 2014-12-26 19:04 - 00000000 ____D () C:\ProgramData\SecurityUtilityData 2014-12-26 19:04 - 2014-12-26 19:04 - 00000000 ____D () C:\ProgramData\SecurityUtility 2014-12-26 19:04 - 2014-12-26 19:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-12-26 19:04 - 2014-12-14 10:53 - 00378640 _____ (CartCrunch Israel Ltd.) C:\Windows\system32\ColorMedia64.dll 2014-12-26 19:04 - 2014-12-14 10:53 - 00332568 _____ (CartCrunch Israel Ltd.) C:\Windows\SysWOW64\ColorMedia.dll 2014-12-26 19:00 - 2014-12-26 19:00 - 00596368 _____ () C:\Users\Reisser\Downloads\download-adblock-chrome.exe 2014-12-26 18:53 - 2014-12-26 18:57 - 00019405 _____ () C:\Users\Reisser\Downloads\software_removal_tool.log 2014-12-26 18:42 - 2014-12-27 14:29 - 00000000 ___HD () C:\Users\Public\Temp 2014-12-26 18:41 - 2014-12-26 18:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-12-26 18:40 - 2014-12-27 14:45 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-12-26 18:40 - 2014-12-27 14:27 - 00000966 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job 2014-12-26 18:40 - 2014-12-27 14:27 - 00000962 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job 2014-12-26 18:40 - 2014-12-27 14:22 - 00003964 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA 2014-12-26 18:40 - 2014-12-27 14:22 - 00003710 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore 2014-12-26 18:40 - 2014-12-27 11:44 - 00001694 _____ () C:\Windows\Tasks\PTJGYIFC.job 2014-12-26 18:40 - 2014-12-27 11:44 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-12-26 18:40 - 2014-12-26 18:55 - 00001925 _____ () C:\Windows\patsearch.bin 2014-12-26 18:40 - 2014-12-26 18:55 - 00000000 ____D () C:\ProgramData\IePluginServices 2014-12-26 18:40 - 2014-12-26 18:40 - 01966056 _____ (HQ-VideoV26.12) C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe 2014-12-26 18:40 - 2014-12-26 18:40 - 00004728 _____ () C:\Windows\System32\Tasks\PTJGYIFC 2014-12-26 18:40 - 2014-12-26 18:40 - 00003896 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-12-26 18:40 - 2014-12-26 18:40 - 00003644 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-12-26 18:40 - 2014-12-26 18:40 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrNewH_01009.Wdf 2014-12-26 18:40 - 2014-12-26 18:40 - 00000000 ____D () C:\Users\Reisser\AppData\Local\globalUpdate 2014-12-26 18:40 - 2014-12-25 12:44 - 04963840 _____ () C:\Windows\rcore.exe 2014-12-26 18:39 - 2014-12-26 19:18 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\omiga-plus 2014-12-26 18:39 - 2014-12-26 18:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip 2014-12-26 18:35 - 2014-12-26 18:35 - 00000000 ___DC () C:\Users\Reisser\AppData\Local\MigWiz 2014-12-26 07:16 - 2014-12-26 07:16 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2014-12-25 18:43 - 2014-12-25 20:53 - 1995124610 _____ () C:\Users\Reisser\Downloads\Orphan.Das.Waisenkind.German.AC3.HDRip.XViD-FuN.avi 2014-12-25 16:59 - 2014-12-25 17:00 - 00000000 ____D () C:\Users\Reisser\Downloads\34020109 2014-12-25 14:19 - 2014-12-23 09:12 - 00000000 ____D () C:\Users\Reisser\Downloads\Ice_Age_Sid_Und_Seine_Freunde-Cool_Und_Locker-2014-NoGroup 2014-12-24 17:15 - 2014-12-24 17:15 - 00000000 ____D () C:\Program Files (x86)\Ripple Emulator 2014-12-24 17:14 - 2014-12-24 17:14 - 00000000 ____D () C:\ProgramData\3980744520298899654 2014-12-24 17:14 - 2014-12-24 17:14 - 00000000 ____D () C:\Program Files (x86)\BuyyNsaave 2014-12-24 17:13 - 2014-12-24 17:13 - 00000000 ____D () C:\ProgramData\migbhnamcclanachieldofcbpebkajke 2014-12-23 23:14 - 2014-11-04 16:50 - 878567444 _____ () C:\Users\Reisser\Downloads\The Purge 2.mkv 2014-12-22 21:43 - 2014-12-22 21:43 - 00000000 ____D () C:\Users\Reisser\Downloads\G0neGrl.ld.HD.de 2014-12-22 17:40 - 2014-12-22 17:40 - 00000000 ____D () C:\ProgramData\3872871776 2014-12-22 17:31 - 2014-12-22 17:31 - 00000000 ____D () C:\Users\Reisser\Documents\Optimizer Pro 2014-12-22 16:27 - 2014-12-22 16:28 - 00000000 ____D () C:\Users\Reisser\AppData\Local\DownloadManager 2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\VTech 2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTech 2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\Program Files (x86)\VTech 2014-12-19 17:14 - 2014-12-19 17:14 - 00000000 _____ () C:\Users\Reisser\AppData\Local\{E9C16533-9CB5-45BF-A1F9-47B28A73E05D} 2014-12-18 15:33 - 2014-12-18 17:29 - 00000000 ____D () C:\Users\Reisser\Downloads\Hörbücher 2014-12-18 13:21 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-12-18 13:21 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-12-17 17:42 - 2014-12-17 17:42 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\NVIDIA 2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Mindscape 2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mindscape 2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mindscape 2014-12-17 17:39 - 2014-12-17 17:39 - 00000000 ____D () C:\Program Files (x86)\Mindscape 2014-12-17 17:36 - 2014-12-17 17:36 - 00054156 ____H () C:\Windows\QTFont.qfn 2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-12-17 17:32 - 2014-12-17 17:35 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-12-12 23:05 - 2014-12-12 23:05 - 00159200 ____T () C:\Users\Reisser\AppData\Roaming\CrashRpt1402.dll 2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\Users\Reisser\AppData\Local\CrashRpt 2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIW Pro Trial 2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\Program Files (x86)\SIW Pro Trial 2014-12-12 03:19 - 2014-12-12 03:19 - 00000000 ____D () C:\Windows\system32\appraiser 2014-12-12 03:01 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2014-12-12 03:01 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2014-12-12 03:01 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2014-12-12 03:01 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2014-12-12 03:01 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2014-12-12 03:01 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2014-12-12 03:01 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2014-12-12 03:01 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2014-12-12 03:01 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2014-12-12 03:01 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2014-12-11 04:56 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-12-11 04:56 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2014-12-11 04:55 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-12-11 04:55 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-12-11 04:55 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-12-11 04:55 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-12-11 04:55 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-12-11 04:55 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-12-11 04:55 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-12-11 04:55 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-12-11 04:55 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-12-11 04:55 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-12-11 04:55 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-12-11 04:55 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-12-11 04:55 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-12-11 04:55 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-12-11 04:55 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-12-11 04:55 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-12-11 04:55 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-12-11 04:55 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-12-11 04:55 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-12-11 04:55 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-12-11 04:55 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-12-11 04:55 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-12-11 04:55 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-12-11 04:55 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-12-11 04:55 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-12-11 04:55 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-12-11 04:55 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-12-11 04:55 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-12-11 04:55 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-12-11 04:55 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-12-11 04:55 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-12-11 04:55 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-12-11 04:55 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-12-11 04:55 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-12-11 04:55 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-12-11 04:55 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-12-11 04:55 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-12-11 04:55 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-12-11 04:55 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-12-11 04:55 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-12-11 04:55 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-12-11 04:55 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-12-11 04:55 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-12-11 04:55 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-12-11 04:55 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-12-11 04:55 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-12-11 04:55 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-12-11 04:55 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-12-11 04:55 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-12-11 04:55 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-12-11 04:55 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-12-11 04:55 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-12-11 04:55 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-12-11 04:55 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-12-11 04:55 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-12-11 04:55 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-12-11 04:55 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2014-12-11 04:54 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-12-11 04:54 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-12-11 04:54 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe 2014-12-11 04:54 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe 2014-12-11 04:54 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2014-12-11 04:54 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2014-12-11 04:54 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2014-12-11 04:54 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2014-12-11 04:54 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2014-12-11 04:54 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2014-12-11 04:54 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll 2014-12-11 04:54 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2014-12-11 04:54 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll 2014-12-11 04:54 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe 2014-12-11 00:26 - 2014-12-11 00:26 - 01413208 _____ () C:\Windows\Minidump\121114-20248-01.dmp 2014-12-05 12:01 - 2014-12-27 11:40 - 00012288 _____ () C:\Users\Reisser\Desktop\Stundenzettelfür Feru - Dezember14 -.xls 2014-12-04 13:29 - 2014-12-13 15:32 - 00000062 _____ () C:\Users\Reisser\Desktop\Neues Textdokument.txt 2014-12-04 12:53 - 2014-12-25 14:20 - 00000000 ____D () C:\Users\Reisser\Downloads\Musik 2014-12-04 12:52 - 2014-12-09 19:08 - 00000000 ____D () C:\Users\Reisser\Downloads\Kinder Filme 2014-11-28 13:23 - 2014-12-11 00:26 - 564424988 _____ () C:\Windows\MEMORY.DMP 2014-11-28 13:23 - 2014-12-11 00:26 - 00000000 ____D () C:\Windows\Minidump 2014-11-27 19:28 - 2014-12-22 18:10 - 00000000 ____D () C:\Users\Reisser\Desktop\Wallpapers 2014-11-27 18:51 - 2014-11-27 18:51 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-11-27 18:20 - 2014-11-27 18:21 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Nero 2014-11-27 18:20 - 2014-11-27 18:20 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\OpenCandy 2014-11-27 18:15 - 2014-11-27 18:50 - 00000000 ____D () C:\ProgramData\Nero 2014-11-27 18:14 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2014-11-27 18:14 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2014-11-27 18:13 - 2014-11-27 18:13 - 00000000 ____D () C:\ProgramData\Package Cache 2014-11-27 17:58 - 2014-11-27 18:17 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\DeepBurner 2014-11-27 17:57 - 2014-11-27 17:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DeepBurner 2014-11-27 17:57 - 2014-11-27 17:57 - 00000000 ____D () C:\Program Files (x86)\Astonsoft 2014-11-27 17:21 - 2014-11-27 17:21 - 00000000 ____D () C:\Users\Reisser\Documents\Ashampoo Burning Studio FREE 2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Ashampoo 2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\Users\Reisser\AppData\Local\ashampoo 2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo 2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\ProgramData\Ashampoo 2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\Program Files (x86)\Ashampoo ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-27 14:23 - 2014-11-08 15:29 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-12-27 13:25 - 2014-11-08 14:39 - 01971342 _____ () C:\Windows\WindowsUpdate.log 2014-12-27 11:52 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-27 11:52 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-27 11:51 - 2014-11-08 16:15 - 00697256 _____ () C:\Windows\system32\perfh007.dat 2014-12-27 11:51 - 2014-11-08 16:15 - 00149224 _____ () C:\Windows\system32\perfc007.dat 2014-12-27 11:51 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-27 11:44 - 2014-11-08 14:52 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-12-27 11:44 - 2010-11-21 04:47 - 00037796 _____ () C:\Windows\PFRO.log 2014-12-27 11:44 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-27 11:44 - 2009-07-14 05:51 - 00041347 _____ () C:\Windows\setupact.log 2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Users\Reisser\AppData\Local\Google 2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Program Files (x86)\Google 2014-12-26 18:39 - 2014-11-08 14:42 - 00001649 _____ () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-12-25 12:22 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-12-22 18:10 - 2014-11-10 17:53 - 00000000 ____D () C:\Users\Reisser\Downloads\Filme 2014-12-17 17:42 - 2014-11-08 14:42 - 00000000 ____D () C:\Users\Reisser\AppData\Local\VirtualStore 2014-12-12 05:23 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-12-12 03:19 - 2014-11-08 19:04 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat 2014-12-12 03:04 - 2014-11-08 19:30 - 00000000 ____D () C:\Windows\system32\MRT 2014-12-12 03:02 - 2014-11-08 19:30 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-12-11 00:29 - 2014-11-16 15:02 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-12-05 11:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-12-01 06:58 - 2014-11-20 17:29 - 00012288 _____ () C:\Users\Reisser\Desktop\Stundenzettelfür Feru - November 14 - Kopie.xls 2014-11-27 18:20 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Cursors Some content of TEMP: ==================== C:\Users\Reisser\AppData\Local\Temp\089C73368233.exe C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.dll C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.exe C:\Users\Reisser\AppData\Local\Temp\EFDF6877-8E55-A3B8-0364-69652FE51F4F.exe C:\Users\Reisser\AppData\Local\Temp\ICReinstall_FileOpenerSetup.exe C:\Users\Reisser\AppData\Local\Temp\Launcher__10272.exe C:\Users\Reisser\AppData\Local\Temp\Launcher__9848.exe C:\Users\Reisser\AppData\Local\Temp\Launcher__9999.exe C:\Users\Reisser\AppData\Local\Temp\LiveSupport_setup.exe C:\Users\Reisser\AppData\Local\Temp\ms.exe C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Reisser\AppData\Local\Temp\nvStInst.exe C:\Users\Reisser\AppData\Local\Temp\optprosetup.exe C:\Users\Reisser\AppData\Local\Temp\setup_384.exe C:\Users\Reisser\AppData\Local\Temp\SpOrder.dll C:\Users\Reisser\AppData\Local\Temp\Storio2_DE_ger_Setup_pid_1588.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-15 17:20 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-12-2014 Ran by Reisser at 2014-12-27 15:02:47 Running from C:\Users\Reisser\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1} AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Abenteuer Pferderücken Demo (HKLM-x32\...\Abenteuer Pferderücken Demo) (Version: - ) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Ashampoo Burning Studio FREE v.1.14.5 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG) Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.12.0 - Asmedia Technology) CinemaHd For Pro 2.4cV27.12 (HKLM-x32\...\CinemaHd For Pro 2.4cV27.12) (Version: 1.35.12.18 - Cinema HDV27.12) Flwsrf (HKLM-x32\...\Flwsrf) (Version: 3.0.0.2 - Flwsrf) <==== ATTENTION! Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.65 - Google Inc.) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden K-Lite Codec Pack 10.8.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.8.0 - ) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation) Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) mkv2vob (HKLM-x32\...\{21AE04E8-EBF6-40DB-9AA9-B7A80C5D057D}) (Version: 2.4.9 - 3r1c) NVIDIA 3D Vision Controller Driver 344.46 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 344.46 - NVIDIA Corporation) NVIDIA 3D Vision Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 344.60 - NVIDIA Corporation) NVIDIA GeForce Experience 2.1.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.3 - NVIDIA Corporation) NVIDIA Graphics Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.60 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.32.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation) NVIDIA PhysX System Software 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation) omiga-plus uninstall (HKLM-x32\...\omiga-plus uninstall) (Version: - omiga-plus) <==== ATTENTION OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) PC Speed Up (HKLM\...\PCSU-SL_is1) (Version: 3.8.3.0 - Speedchecker Limited) <==== ATTENTION QuickTime (HKLM-x32\...\{08094E03-AFE4-4853-9D31-6D0743DF5328}) (Version: 7.1.6.200 - Apple Computer, Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.) SecurityUtility (HKLM-x32\...\SecurityUtility) (Version: 1.0.0.992 - ) SHIELD Streaming (Version: 3.1.1000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 16.13.56 - NVIDIA Corporation) Hidden SIW Pro Edition (Trial Version) (HKLM-x32\...\{3B9704C8-1286-4a17-9EA8-F63004FC74A1}_is1) (Version: 2014.10.16 - Topala Software Solutions) Software Version Updater (HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}) (Version: 1.1.4.2 - ) <==== ATTENTION VTech Download Agent Library (x32 Version: 1.00.0000 - VTech) Hidden VTech Download Manager (HKLM-x32\...\VTechDownloadManager) (Version: - VTech) WinRAR 5.10 Beta 4 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH) Zombie Invasion (HKLM-x32\...\ZombieInvasion) (Version: 2.7.50 - Time Lapse Solutions) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 22-12-2014 17:38:19 Removed Apple Software Update 25-12-2014 17:07:37 Windows Update 26-12-2014 18:53:33 Software Removal Tool ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {058D4BF1-586D-49C2-8015-438E97637BB8} - System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5 => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION Task: {07C4EDDE-20D1-4BFF-8659-B50E309D06FA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.) Task: {32E4AC8B-D955-4847-BF7D-215EA9001513} - System32\Tasks\PTJGYIFC => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe [2014-12-26] (HQ-VideoV26.12) <==== ATTENTION Task: {375D32C7-2DF3-4769-A2C8-2CC4A1A2038A} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-12-27] (globalUpdate) <==== ATTENTION Task: {4D0C693A-EBE8-4241-B781-4B9F04671106} - System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-3 => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-3.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION Task: {4DCB2EBB-48CF-46E4-B971-2C82DC29C90D} - System32\Tasks\PC SpeedUp Service Deactivator => C:\Program Files (x86)\PC Speed Up\PCSUSD.exe [2014-12-10] () <==== ATTENTION Task: {7C46BBB5-8422-47C1-A9C2-3BB2C3C41657} - System32\Tasks\upfs7235 => C:\Program Files (x86)\Flwsrf\upfs7235.exe [2014-12-05] () Task: {7D3768C6-C09E-49D4-BDF0-3A2B8040FDB0} - System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-7 => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-7.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION Task: {850FC5E5-AE51-4C51-95E1-FF3768705CCA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.) Task: {8B1C00F0-602F-40B2-9557-43584EC56145} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2014-10-06] () Task: {93F395D4-4E96-4489-8C49-75F00D051B22} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-12-27] (globalUpdate) <==== ATTENTION Task: {95357790-1215-4EC2-8985-08746970D29D} - System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-1 => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\CinemaHd For Pro 2.4cV27.12-codedownloader.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION Task: {D5ACE67C-2D56-4D85-AAEF-15701D01ECB4} - System32\Tasks\Run_Bobby_Browser => C:\Users\Reisser\AppData\Local\BoBrowser\Application\bobrowser.exe <==== ATTENTION Task: {DCFAB0D7-340E-42C6-A8C1-45EF755A38FD} - System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-2 => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-2.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION Task: {E1B12AA3-8587-49F7-8FD4-24A42FBB9ED3} - System32\Tasks\KWWB => C:\Users\Reisser\AppData\Roaming\KWWB.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION Task: {E4E2559A-16D1-4F31-B32E-7D55DC599C1A} - System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5_user => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION Task: {E7D7C2C6-68D3-4C46-9826-F912206163EA} - System32\Tasks\amiupdaterExd => cmd.exe /c start /min bitsadmin /transfer amijob /download /priority high hxxp://d17xr4aw9ok0me.cloudfront.net/Updater.exe "C:\Users\Reisser\AppData\Local\Temp\amiupdater1440.exe" Task: {F125BC51-2941-4F4A-B676-B6C8A5B0E166} - System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B} => pcalua.exe -a C:\Users\Reisser\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=tugs Task: {F1E05127-80E4-400F-8C60-436999246896} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {F7148153-DE7E-454F-9759-3E651C5CF7A7} - System32\Tasks\amiupdaterExi => C:\Users\Reisser\AppData\Local\Temp\amiupdater1440.exe <==== ATTENTION Task: {FC55D932-5FAC-4A5D-8814-F6F2264ED660} - System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6 => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION Task: C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-1.job => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\CinemaHd For Pro 2.4cV27.12-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-2.job => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-2.exe <==== ATTENTION Task: C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-3.job => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-3.exe <==== ATTENTION Task: C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5.job => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5.exe <==== ATTENTION Task: C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5_user.job => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5.exe <==== ATTENTION Task: C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6.job => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6.exe <==== ATTENTION Task: C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-7.job => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-7.exe <==== ATTENTION Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\KWWB.job => C:\Users\Reisser\AppData\Roaming\KWWB.exe <==== ATTENTION Task: C:\Windows\Tasks\PC SpeedUp Service Deactivator.job => C:\Program Files (x86)\PC Speed Up\PCSUSD.exe <==== ATTENTION Task: C:\Windows\Tasks\PTJGYIFC.job => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2014-11-08 14:51 - 2014-10-30 03:10 - 00117064 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-12-26 18:40 - 2014-12-25 12:44 - 04963840 _____ () C:\Windows\rcore.exe 2014-12-26 19:04 - 2014-12-25 19:14 - 00537248 _____ () C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe 2014-10-13 02:49 - 2014-06-20 07:42 - 00401280 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe 2014-11-29 13:26 - 2014-11-29 13:26 - 00164352 _____ () C:\Program Files (x86)\Flwsrf\ijs.exe 2014-10-13 02:49 - 2014-03-04 12:20 - 00117760 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QtSolutions_SOAP-2.7.dll 2014-10-13 02:49 - 2014-04-22 03:14 - 00065536 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QHttpServer.dll 2014-10-13 02:49 - 2014-05-06 06:39 - 00861184 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\platforms\qwindows.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00021504 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qgif.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00020992 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qico.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00204800 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qjpeg.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00218112 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qmng.dll 2014-10-13 02:49 - 2014-05-06 06:58 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qsvg.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00015360 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtga.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00307712 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtiff.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00014848 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qwbmp.dll 2014-10-13 02:49 - 2014-05-06 07:31 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\sensors\qtsensors_dummy.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00036352 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qgenericbearer.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00038912 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qnativewifibearer.dll 2014-12-27 14:23 - 2014-12-27 14:23 - 00182760 _____ () C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\eee4bccf-2d1a-41af-827c-69d1b17a9cc6.dll 2014-12-26 18:41 - 2014-11-14 22:15 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\libglesv2.dll 2014-12-26 18:41 - 2014-11-14 22:15 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\libegl.dll 2014-12-26 18:41 - 2014-11-14 22:15 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\ffmpegsumo.dll 2014-12-26 18:41 - 2014-11-14 22:15 - 14910280 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\PepperFlash\pepflashplayer.dll 2014-12-26 18:41 - 2014-11-14 22:15 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\pdf.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\abengine => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ColorMedia => ""="service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-1744345613-2801571155-2633355246-500 - Administrator - Disabled) Guest (S-1-5-21-1744345613-2801571155-2633355246-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1744345613-2801571155-2633355246-1002 - Limited - Enabled) Reisser (S-1-5-21-1744345613-2801571155-2633355246-1000 - Administrator - Enabled) => C:\Users\Reisser ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/27/2014 02:23:02 PM) (Source: MsiInstaller) (EventID: 11309) (User: Reisser-PC) Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt. System error 3. Verify that the file exists and that you can access it. Error: (12/27/2014 00:23:19 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm chrome.exe, Version 39.0.2171.65 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1fc0 Startzeit: 01d021c34c497746 Endzeit: 16 Anwendungspfad: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Berichts-ID: bc3b44d9-8dba-11e4-8bfc-bc5ff45b0bd1 Error: (12/27/2014 11:46:14 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/26/2014 08:45:52 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 5792. Message ID: [0x2509]. Error: (12/26/2014 07:27:09 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1". Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (12/26/2014 07:27:09 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1". Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (12/26/2014 07:27:06 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1". Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (12/26/2014 07:27:06 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1". Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (12/26/2014 07:27:04 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1". Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (12/26/2014 07:27:04 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1". Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". System errors: ============= Error: (12/27/2014 11:46:58 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "globalUpdate Update Service (globalUpdate)" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (12/27/2014 11:44:45 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "IePlugin Services" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (12/27/2014 11:44:26 AM) (Source: Ntfs) (EventID: 137) (User: ) Description: Auf dem Volume "\\?\Volume{2dd34089-674c-11e4-af0b-806e6f6e6963}" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (12/27/2014 11:44:26 AM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (12/26/2014 08:15:43 PM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (12/26/2014 08:15:41 PM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (12/26/2014 08:15:40 PM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (12/26/2014 08:15:39 PM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (12/26/2014 08:15:37 PM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (12/26/2014 08:15:36 PM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Microsoft Office Sessions: ========================= Error: (12/27/2014 02:23:02 PM) (Source: MsiInstaller) (EventID: 11309) (User: Reisser-PC) Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt. System error 3. Verify that the file exists and that you can access it.(NULL)(NULL)(NULL)(NULL)(NULL) Error: (12/27/2014 00:23:19 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: chrome.exe39.0.2171.651fc001d021c34c49774616C:\Program Files (x86)\Google\Chrome\Application\chrome.exebc3b44d9-8dba-11e4-8bfc-bc5ff45b0bd1 Error: (12/27/2014 11:46:14 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/26/2014 08:45:52 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 5792. Message ID: [0x2509]. Error: (12/26/2014 07:27:09 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl Error: (12/26/2014 07:27:09 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl Error: (12/26/2014 07:27:06 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl Error: (12/26/2014 07:27:06 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl Error: (12/26/2014 07:27:04 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl Error: (12/26/2014 07:27:04 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl ==================== Memory info =========================== Processor: AMD FX(tm)-6100 Six-Core Processor Percentage of memory in use: 31% Total physical RAM: 8171.53 MB Available physical RAM: 5558.59 MB Total Pagefile: 16341.24 MB Available Pagefile: 13317.54 MB Total Virtual: 8192 MB Available Virtual: 8191.77 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:172.79 GB) (Free:69.58 GB) NTFS Drive d: () (Fixed) (Total:292.97 GB) (Free:27.66 GB) NTFS Drive e: (Filme 2 St) (Fixed) (Total:465.61 GB) (Free:189.89 GB) NTFS Drive f: (GSP1RMCULXFRER_EN_DVD) (CDROM) (Total:3.09 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: FFB8F33B) Partition 1: (Not Active) - (Size=172.8 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=293 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 3280EB00) Partition 1: (Active) - (Size=126 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.6 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
27.12.2014, 15:34 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Lässtige werbung trotz addblock Hi und
__________________Adware/Junkware/Toolbars entfernen (alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!) 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
27.12.2014, 16:10 | #3 |
| adw cleaner AdwCleaner Logfile:
__________________Code:
ATTFilter # AdwCleaner v4.106 - Report created 27/12/2014 at 15:50:26 # Updated 21/12/2014 by Xplode # Database : 2014-12-21.4 [Live] # Operating System : Windows 7 Ultimate Service Pack 1 (64 bits) # Username : Reisser - REISSER-PC # Running from : C:\Users\Reisser\Downloads\AdwCleaner_4.106.exe # Option : Clean ***** [ Services ] ***** [#] Service Deleted : globalUpdate [#] Service Deleted : globalUpdatem [#] Service Deleted : IePluginServices Service Deleted : rcores Service Deleted : ColorMedia Service Deleted : InjectorService Service Deleted : abengine ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\IePluginServices Folder Deleted : C:\ProgramData\ZombieInvasion Folder Deleted : C:\ProgramData\3980744520298899654 Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pc speed up Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip [!] Folder Deleted : C:\Program Files (x86)\globalUpdate Folder Deleted : C:\Program Files (x86)\pc speed up Folder Deleted : C:\Program Files (x86)\predm Folder Deleted : C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12 Folder Deleted : C:\Users\Reisser\AppData\Local\globalUpdate Folder Deleted : C:\Users\Reisser\AppData\Local\Microsoft\Silverlight\OutOfBrowser\Speedchecker.PCSpeedUp Folder Deleted : C:\Users\Reisser\AppData\Local\CrashRpt Folder Deleted : C:\Users\Reisser\AppData\Local\DownloadManager Folder Deleted : C:\Users\Reisser\AppData\Local\ZombieInvasion Folder Deleted : C:\Users\Reisser\AppData\Roaming\omiga-plus Folder Deleted : C:\Users\Reisser\AppData\Roaming\OpenCandy Folder Deleted : C:\Users\Reisser\Documents\Optimizer Pro File Deleted : C:\END File Deleted : C:\Windows\rcore.exe File Deleted : C:\Users\Reisser\AppData\Roaming\LiveSupport.exe_log.txt File Deleted : C:\Users\Reisser\AppData\Roaming\regsvr32.exe_log.txt File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_inst.shoppingate.info_0.localstorage File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_inst.shoppingate.info_0.localstorage-journal File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage-journal File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal ***** [ Scheduled Tasks ] ***** Task Deleted : globalUpdateUpdateTaskMachineCore Task Deleted : globalUpdateUpdateTaskMachineUA Task Deleted : PC SpeedUp Service Deactivator Task Deleted : Run_Bobby_Browser Task Deleted : f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-1 Task Deleted : f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-2 Task Deleted : f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-3 Task Deleted : f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5 Task Deleted : f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5_user Task Deleted : f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6 Task Deleted : f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-7 ***** [ Shortcuts ] ***** Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk Shortcut Disinfected : C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk Shortcut Disinfected : C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Shortcut Disinfected : C:\Users\Reisser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Shortcut Disinfected : C:\Users\Reisser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk ***** [ Registry ] ***** Key Deleted : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [livesupport] Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [pcspeedup] Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10 Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0 Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4 Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0 Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1 Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1 Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0 Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0 Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0 Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0 Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0 Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0 Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0 Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0 Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0 Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10 Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4 Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect Key Deleted : HKLM\SOFTWARE\Classes\BuyNsave.BuyNsave Key Deleted : HKLM\SOFTWARE\Classes\BuyNsave.BuyNsave.9 Key Deleted : HKLM\SOFTWARE\Classes\. Key Deleted : HKLM\SOFTWARE\Classes\..9 Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1f80c42e-d3a4-491a-8c2c-1c587df69b2e} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9c183513-92d9-43dd-81e0-9f30a36ca67f} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611571181} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622572281} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655575581} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666576681} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644574481} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571181} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1f80c42e-d3a4-491a-8c2c-1c587df69b2e} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9c183513-92d9-43dd-81e0-9f30a36ca67f} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5e62c5b3-db2c-46c6-88ae-9b102ba6421e} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f434484f-cbc8-45f2-9444-0b82be85500f} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{1f80c42e-d3a4-491a-8c2c-1c587df69b2e} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{9c183513-92d9-43dd-81e0-9f30a36ca67f} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611571181} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622572281} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655575581} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666576681} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571181} Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5e62c5b3-db2c-46c6-88ae-9b102ba6421e} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f434484f-cbc8-45f2-9444-0b82be85500f} Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} Key Deleted : HKCU\Software\GlobalUpdate Key Deleted : HKCU\Software\InetStat Key Deleted : HKCU\Software\InstalledBrowserExtensions Key Deleted : HKCU\Software\OCS Key Deleted : HKCU\Software\Optimizer Pro Key Deleted : HKCU\Software\Speedchecker Limited Key Deleted : HKCU\Software\TutoTag Key Deleted : HKCU\Software\StormWatchApp Key Deleted : HKCU\Software\BoBrowser Key Deleted : HKCU\Software\Wnkey Key Deleted : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9} Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider Key Deleted : HKCU\Software\AppDataLow\Software\DynConIE Key Deleted : HKCU\Software\AppDataLow\Software\CinemaHd For Pro 2.4cV27.12 Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Key Deleted : HKLM\SOFTWARE\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9} Key Deleted : HKLM\SOFTWARE\FlowSurf Key Deleted : HKLM\SOFTWARE\GlobalUpdate Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions Key Deleted : HKLM\SOFTWARE\omiga-plusSoftware Key Deleted : HKLM\SOFTWARE\Speedchecker Limited Key Deleted : HKLM\SOFTWARE\Tutorials Key Deleted : HKLM\SOFTWARE\Clara Key Deleted : HKLM\SOFTWARE\GAMESDESKTOP Key Deleted : HKLM\SOFTWARE\CinemaHd For Pro 2.4cV27.12 Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\omiga-plus uninstall Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{842C4394-47F7-60DE-480B-C09116B63559} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaHd For Pro 2.4cV27.12 Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions Key Deleted : [x64] HKLM\SOFTWARE\Speedchecker Limited Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCSU-SL_is1 Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\websearch.searchoholic.info ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.17496 Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] -\\ Google Chrome v39.0.2171.65 [C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419615594&from=tugs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms} [C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419615594&from=tugs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms} [C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://websearch.searchoholic.info/?l=1&q={searchTerms}&pid=1091&r=2014/12/22&hid=8793653231034268742&lg=EN&cc=DE&unqvl=72 [C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3331398&octid=EB_ORIGINAL_CTID&ISID=M6911AFB1-B655-464C-8E34-5E1CC33D8BD5&SearchSource=58&CUI=&UM=6&UP=SPFCE036FE-6C01-4AD8-BCF5-2AF6403F7C7C&q={searchTerms}&SSPV= [C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3331398&octid=EB_ORIGINAL_CTID&ISID=M6911AFB1-B655-464C-8E34-5E1CC33D8BD5&SearchSource=58&CUI=&UM=6&UP=SPFCE036FE-6C01-4AD8-BCF5-2AF6403F7C7C&q={searchTerms}&SSPV= [C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M967FE9C1-A9A5-43A2-8659-C914B636C4B4&SearchSource=58&CUI=&UM=8&UP=SP7CE64842-07CE-4A5F-8347-E1F6816C072C&q={searchTerms}&SSPV= [C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M967FE9C1-A9A5-43A2-8659-C914B636C4B4&SearchSource=58&CUI=&UM=8&UP=SP7CE64842-07CE-4A5F-8347-E1F6816C072C&q={searchTerms}&SSPV= ************************* AdwCleaner[R0].txt - [20752 octets] - [27/12/2014 15:47:37] AdwCleaner[S0].txt - [19862 octets] - [27/12/2014 15:50:26] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [19923 octets] ########## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.0 (11.29.2014:1) OS: Windows 7 Ultimate x64 Ran by Reisser on 27.12.2014 at 15:56:14,99 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611171162} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611171162} ~~~ Files Successfully deleted: [File] "C:\Users\Reisser\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage" Successfully deleted: [File] "C:\Users\Reisser\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage-journal" ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 27.12.2014 at 15:58:41,48 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ # FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-12-2014 Ran by Reisser (administrator) on REISSER-PC on 27-12-2014 16:06:01 Running from C:\Users\Reisser\Downloads Loaded Profile: Reisser (Available profiles: Reisser) Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Englisch (USA) Internet Explorer Version 11 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe (Time Lapse Solutions) C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Apple Inc.) C:\Program Files (x86)\QuickTime\qttask.exe () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2463552 2014-10-04] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [282624 2007-04-27] (Apple Inc.) HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] () HKLM-x32\...\Run: [gmsd_de_44] => [X] HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Run: [SwvUpdtr] => C:\Users\Reisser\AppData\Local\24567\Updater.exe [773632 2014-12-27] () HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: G - G:\StorioSetup.exe HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {2e971c8e-719e-11e4-b18f-bc5ff45b0bd1} - F:\SNC715MusicPlayer.exe HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {432e0770-7651-11e4-a244-806e6f6e6963} - F:\VTech_toy_Setup.exe HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {9dac61e2-89ed-11e4-b4c2-bc5ff45b0bd1} - G:\StorioSetup.exe CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:50863;https=127.0.0.1:50863 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Google HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = Google HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = Google HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome: ======= CHR HomePage: Default -> CHR StartupUrls: Default -> "" CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter} CHR Profile: C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-26] CHR Extension: (Google Docs) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-26] CHR Extension: (Google Drive) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-26] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-26] CHR Extension: (YouTube) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-26] CHR Extension: (Google Search) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-26] CHR Extension: (Google Sheets) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-26] CHR Extension: (Google Wallet) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-26] CHR Extension: (Gmail) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-26] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 dZPlDQFMAyN; C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe [2726776 2014-12-27] (Time Lapse Solutions) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-10-04] (NVIDIA Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-10-04] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-10-04] (NVIDIA Corporation) R2 SecurityUtility Service; C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe [537248 2014-12-25] () ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-10-04] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation) R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-27 15:58 - 2014-12-27 15:58 - 00001474 _____ () C:\Users\Reisser\Desktop\JRT.txt 2014-12-27 15:56 - 2014-12-27 15:56 - 00000000 ____D () C:\Windows\ERUNT 2014-12-27 15:53 - 2014-12-27 15:53 - 00000000 ____D () C:\Users\Reisser\AppData\Local\ZombieInvasion 2014-12-27 15:46 - 2014-12-27 15:50 - 00000000 ____D () C:\AdwCleaner 2014-12-27 15:46 - 2014-12-27 15:46 - 02173952 _____ () C:\Users\Reisser\Downloads\AdwCleaner_4.106.exe 2014-12-27 15:46 - 2014-12-27 15:46 - 01707646 _____ (Thisisu) C:\Users\Reisser\Downloads\JRT.exe 2014-12-27 15:02 - 2014-12-27 15:03 - 00027876 _____ () C:\Users\Reisser\Downloads\Addition.txt 2014-12-27 15:01 - 2014-12-27 16:06 - 00010546 _____ () C:\Users\Reisser\Downloads\FRST.txt 2014-12-27 15:01 - 2014-12-27 16:06 - 00000000 ____D () C:\FRST 2014-12-27 15:01 - 2014-12-27 15:01 - 02122752 _____ (Farbar) C:\Users\Reisser\Downloads\FRST64.exe 2014-12-27 14:59 - 2014-12-27 14:59 - 00001137 _____ () C:\Users\Reisser\Desktop\Continue File Opener Installation.lnk 2014-12-27 14:48 - 2014-12-27 14:48 - 00797824 _____ ( ) C:\Users\Reisser\Downloads\FileOpenerSetup.exe 2014-12-27 14:23 - 2014-12-27 14:23 - 00000000 ____D () C:\Program Files (x86)\2f4249ae-2ea2-4d9e-8f18-8c64e6461106 2014-12-27 14:22 - 2014-12-27 15:52 - 00001342 _____ () C:\Windows\Tasks\KWWB.job 2014-12-27 14:22 - 2014-12-27 14:23 - 00004376 _____ () C:\Windows\System32\Tasks\KWWB 2014-12-27 14:22 - 2014-12-27 14:22 - 02055144 _____ (Cinema HDV27.12) C:\Users\Reisser\AppData\Roaming\KWWB.exe 2014-12-27 12:15 - 2014-12-27 12:15 - 00000000 ____D () C:\Users\Reisser\AppData\Local\24567 2014-12-27 11:53 - 2014-12-27 15:52 - 00000000 ____D () C:\Program Files (x86)\Flwsrf 2014-12-27 11:53 - 2014-12-27 11:53 - 00004640 _____ () C:\Windows\SysWOW64\abengine.ini 2014-12-27 11:53 - 2014-12-27 11:53 - 00003090 _____ () C:\Windows\System32\Tasks\upfs7235 2014-12-27 11:53 - 2014-12-27 11:53 - 00002544 _____ () C:\Windows\SysWOW64\abengineOff.ini 2014-12-27 11:53 - 2014-12-27 11:53 - 00002544 _____ () C:\Windows\system32\abengineOff.ini 2014-12-27 11:53 - 2014-12-05 00:09 - 00370880 _____ (Abengine) C:\Windows\system32\abengine64.dll 2014-12-27 11:53 - 2014-12-05 00:09 - 00324592 _____ (Abengine) C:\Windows\SysWOW64\abengine.dll 2014-12-27 11:52 - 2014-12-27 11:52 - 00000000 ____D () C:\ProgramData\qMuLXOMiMf 2014-12-26 20:54 - 2014-12-26 21:03 - 00000000 ____D () C:\Users\Reisser\Desktop\weihnachten 14 2014-12-26 20:45 - 2014-12-26 08:06 - 00008977 _____ () C:\Users\Reisser\Downloads\rla-dtvpmt1.ts.nfo 2014-12-26 20:45 - 2014-12-25 23:20 - 745466933 _____ () C:\Users\Reisser\Downloads\die tribute von Panem.mkv 2014-12-26 20:45 - 2014-12-23 12:02 - 00000220 _____ () C:\Users\Reisser\Downloads\Goldesel.to - Die Seite fuer Direkt-Downloads aller Art.url 2014-12-26 20:45 - 2014-12-23 12:02 - 00000116 _____ () C:\Users\Reisser\Downloads\goldesel.to - quality source for more than 15 years .txt 2014-12-26 20:35 - 2014-12-26 20:42 - 208666624 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part1.rar 2014-12-26 20:34 - 2014-12-26 20:42 - 208666624 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part3.rar 2014-12-26 20:34 - 2014-12-26 20:41 - 208666624 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part2.rar 2014-12-26 20:34 - 2014-12-26 20:38 - 126903232 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part4.rar 2014-12-26 19:28 - 2014-12-26 19:30 - 00002196 _____ () C:\Users\Reisser\Desktop\chrome.lnk 2014-12-26 19:18 - 2014-12-26 19:18 - 00003160 _____ () C:\Windows\System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B} 2014-12-26 19:06 - 2014-12-26 19:06 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\dlg 2014-12-26 19:05 - 2014-12-26 19:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-12-26 19:04 - 2014-12-27 11:44 - 00005240 _____ () C:\Windows\SysWOW64\ColorMedia.ini 2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\SysWOW64\ColorMediaOff.ini 2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\system32\ColorMediaOff.ini 2014-12-26 19:04 - 2014-12-26 19:04 - 00000000 ____D () C:\ProgramData\SecurityUtilityData 2014-12-26 19:04 - 2014-12-26 19:04 - 00000000 ____D () C:\ProgramData\SecurityUtility 2014-12-26 19:04 - 2014-12-26 19:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-12-26 19:04 - 2014-12-14 10:53 - 00378640 _____ (CartCrunch Israel Ltd.) C:\Windows\system32\ColorMedia64.dll 2014-12-26 19:04 - 2014-12-14 10:53 - 00332568 _____ (CartCrunch Israel Ltd.) C:\Windows\SysWOW64\ColorMedia.dll 2014-12-26 19:00 - 2014-12-26 19:00 - 00596368 _____ () C:\Users\Reisser\Downloads\download-adblock-chrome.exe 2014-12-26 18:53 - 2014-12-26 18:57 - 00019405 _____ () C:\Users\Reisser\Downloads\software_removal_tool.log 2014-12-26 18:42 - 2014-12-27 14:29 - 00000000 ___HD () C:\Users\Public\Temp 2014-12-26 18:41 - 2014-12-27 15:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-12-26 18:40 - 2014-12-27 15:52 - 00001694 _____ () C:\Windows\Tasks\PTJGYIFC.job 2014-12-26 18:40 - 2014-12-27 15:52 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-12-26 18:40 - 2014-12-27 15:45 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-12-26 18:40 - 2014-12-26 18:55 - 00001925 _____ () C:\Windows\patsearch.bin 2014-12-26 18:40 - 2014-12-26 18:40 - 01966056 _____ (HQ-VideoV26.12) C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe 2014-12-26 18:40 - 2014-12-26 18:40 - 00004728 _____ () C:\Windows\System32\Tasks\PTJGYIFC 2014-12-26 18:40 - 2014-12-26 18:40 - 00003896 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-12-26 18:40 - 2014-12-26 18:40 - 00003644 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-12-26 18:40 - 2014-12-26 18:40 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrNewH_01009.Wdf 2014-12-26 18:35 - 2014-12-26 18:35 - 00000000 ___DC () C:\Users\Reisser\AppData\Local\MigWiz 2014-12-26 07:16 - 2014-12-26 07:16 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2014-12-25 18:43 - 2014-12-25 20:53 - 1995124610 _____ () C:\Users\Reisser\Downloads\Orphan.Das.Waisenkind.German.AC3.HDRip.XViD-FuN.avi 2014-12-25 16:59 - 2014-12-25 17:00 - 00000000 ____D () C:\Users\Reisser\Downloads\34020109 2014-12-25 14:19 - 2014-12-23 09:12 - 00000000 ____D () C:\Users\Reisser\Downloads\Ice_Age_Sid_Und_Seine_Freunde-Cool_Und_Locker-2014-NoGroup 2014-12-24 17:15 - 2014-12-24 17:15 - 00000000 ____D () C:\Program Files (x86)\Ripple Emulator 2014-12-24 17:14 - 2014-12-24 17:14 - 00000000 ____D () C:\Program Files (x86)\BuyyNsaave 2014-12-24 17:13 - 2014-12-24 17:13 - 00000000 ____D () C:\ProgramData\migbhnamcclanachieldofcbpebkajke 2014-12-23 23:14 - 2014-11-04 16:50 - 878567444 _____ () C:\Users\Reisser\Downloads\The Purge 2.mkv 2014-12-22 21:43 - 2014-12-22 21:43 - 00000000 ____D () C:\Users\Reisser\Downloads\G0neGrl.ld.HD.de 2014-12-22 17:40 - 2014-12-22 17:40 - 00000000 ____D () C:\ProgramData\3872871776 2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\VTech 2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTech 2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\Program Files (x86)\VTech 2014-12-19 17:14 - 2014-12-19 17:14 - 00000000 _____ () C:\Users\Reisser\AppData\Local\{E9C16533-9CB5-45BF-A1F9-47B28A73E05D} 2014-12-18 15:33 - 2014-12-18 17:29 - 00000000 ____D () C:\Users\Reisser\Downloads\Hörbücher 2014-12-18 13:21 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-12-18 13:21 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-12-17 17:42 - 2014-12-17 17:42 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\NVIDIA 2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Mindscape 2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mindscape 2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mindscape 2014-12-17 17:39 - 2014-12-17 17:39 - 00000000 ____D () C:\Program Files (x86)\Mindscape 2014-12-17 17:36 - 2014-12-17 17:36 - 00054156 ____H () C:\Windows\QTFont.qfn 2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-12-17 17:32 - 2014-12-17 17:35 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-12-12 23:05 - 2014-12-12 23:05 - 00159200 ____T () C:\Users\Reisser\AppData\Roaming\CrashRpt1402.dll 2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIW Pro Trial 2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\Program Files (x86)\SIW Pro Trial 2014-12-12 03:19 - 2014-12-12 03:19 - 00000000 ____D () C:\Windows\system32\appraiser 2014-12-12 03:01 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2014-12-12 03:01 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2014-12-12 03:01 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2014-12-12 03:01 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2014-12-12 03:01 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2014-12-12 03:01 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2014-12-12 03:01 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2014-12-12 03:01 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2014-12-12 03:01 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2014-12-12 03:01 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2014-12-11 04:56 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-12-11 04:56 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2014-12-11 04:55 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-12-11 04:55 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-12-11 04:55 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-12-11 04:55 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-12-11 04:55 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-12-11 04:55 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-12-11 04:55 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-12-11 04:55 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-12-11 04:55 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-12-11 04:55 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-12-11 04:55 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-12-11 04:55 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-12-11 04:55 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-12-11 04:55 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-12-11 04:55 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-12-11 04:55 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-12-11 04:55 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-12-11 04:55 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-12-11 04:55 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-12-11 04:55 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-12-11 04:55 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-12-11 04:55 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-12-11 04:55 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-12-11 04:55 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-12-11 04:55 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-12-11 04:55 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-12-11 04:55 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-12-11 04:55 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-12-11 04:55 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-12-11 04:55 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-12-11 04:55 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-12-11 04:55 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-12-11 04:55 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-12-11 04:55 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-12-11 04:55 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-12-11 04:55 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-12-11 04:55 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-12-11 04:55 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-12-11 04:55 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-12-11 04:55 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-12-11 04:55 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-12-11 04:55 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-12-11 04:55 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-12-11 04:55 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-12-11 04:55 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-12-11 04:55 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-12-11 04:55 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-12-11 04:55 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-12-11 04:55 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-12-11 04:55 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-12-11 04:55 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-12-11 04:55 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-12-11 04:55 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-12-11 04:55 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-12-11 04:55 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-12-11 04:55 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-12-11 04:55 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2014-12-11 04:54 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-12-11 04:54 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-12-11 04:54 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe 2014-12-11 04:54 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe 2014-12-11 04:54 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2014-12-11 04:54 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2014-12-11 04:54 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2014-12-11 04:54 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2014-12-11 04:54 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2014-12-11 04:54 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2014-12-11 04:54 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll 2014-12-11 04:54 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2014-12-11 04:54 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll 2014-12-11 04:54 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe 2014-12-11 00:26 - 2014-12-11 00:26 - 01413208 _____ () C:\Windows\Minidump\121114-20248-01.dmp 2014-12-05 12:01 - 2014-12-27 11:40 - 00012288 _____ () C:\Users\Reisser\Desktop\Stundenzettelfür Feru - Dezember14 -.xls 2014-12-04 13:29 - 2014-12-13 15:32 - 00000062 _____ () C:\Users\Reisser\Desktop\Neues Textdokument.txt 2014-12-04 12:53 - 2014-12-25 14:20 - 00000000 ____D () C:\Users\Reisser\Downloads\Musik 2014-12-04 12:52 - 2014-12-09 19:08 - 00000000 ____D () C:\Users\Reisser\Downloads\Kinder Filme 2014-11-28 13:23 - 2014-12-11 00:26 - 564424988 _____ () C:\Windows\MEMORY.DMP 2014-11-28 13:23 - 2014-12-11 00:26 - 00000000 ____D () C:\Windows\Minidump 2014-11-27 19:28 - 2014-12-22 18:10 - 00000000 ____D () C:\Users\Reisser\Desktop\Wallpapers 2014-11-27 18:51 - 2014-11-27 18:51 - 00000000 ____D () C:\Windows\system32\appmgmt 2014-11-27 18:20 - 2014-11-27 18:21 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Nero 2014-11-27 18:15 - 2014-11-27 18:50 - 00000000 ____D () C:\ProgramData\Nero 2014-11-27 18:14 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll 2014-11-27 18:14 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll 2014-11-27 18:13 - 2014-11-27 18:13 - 00000000 ____D () C:\ProgramData\Package Cache 2014-11-27 17:58 - 2014-11-27 18:17 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\DeepBurner 2014-11-27 17:57 - 2014-11-27 17:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DeepBurner 2014-11-27 17:57 - 2014-11-27 17:57 - 00000000 ____D () C:\Program Files (x86)\Astonsoft 2014-11-27 17:21 - 2014-11-27 17:21 - 00000000 ____D () C:\Users\Reisser\Documents\Ashampoo Burning Studio FREE 2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Ashampoo 2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\Users\Reisser\AppData\Local\ashampoo 2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo 2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\ProgramData\Ashampoo 2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\Program Files (x86)\Ashampoo ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-27 15:59 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-27 15:59 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-27 15:58 - 2014-11-08 16:15 - 00697256 _____ () C:\Windows\system32\perfh007.dat 2014-12-27 15:58 - 2014-11-08 16:15 - 00149224 _____ () C:\Windows\system32\perfc007.dat 2014-12-27 15:58 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-27 15:55 - 2014-11-08 14:39 - 01982971 _____ () C:\Windows\WindowsUpdate.log 2014-12-27 15:51 - 2014-11-08 14:52 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-12-27 15:51 - 2010-11-21 04:47 - 00038116 _____ () C:\Windows\PFRO.log 2014-12-27 15:51 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-27 15:51 - 2009-07-14 05:51 - 00041515 _____ () C:\Windows\setupact.log 2014-12-27 15:50 - 2014-11-08 14:42 - 00000993 _____ () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-12-27 14:23 - 2014-11-08 15:29 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Users\Reisser\AppData\Local\Google 2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Program Files (x86)\Google 2014-12-25 12:22 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-12-22 18:10 - 2014-11-10 17:53 - 00000000 ____D () C:\Users\Reisser\Downloads\Filme 2014-12-17 17:42 - 2014-11-08 14:42 - 00000000 ____D () C:\Users\Reisser\AppData\Local\VirtualStore 2014-12-12 05:23 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-12-12 03:19 - 2014-11-08 19:04 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat 2014-12-12 03:04 - 2014-11-08 19:30 - 00000000 ____D () C:\Windows\system32\MRT 2014-12-12 03:02 - 2014-11-08 19:30 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-12-11 00:29 - 2014-11-16 15:02 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-12-05 11:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-12-01 06:58 - 2014-11-20 17:29 - 00012288 _____ () C:\Users\Reisser\Desktop\Stundenzettelfür Feru - November 14 - Kopie.xls 2014-11-27 18:20 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Cursors Some content of TEMP: ==================== C:\Users\Reisser\AppData\Local\Temp\089C73368233.exe C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.dll C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.exe C:\Users\Reisser\AppData\Local\Temp\EFDF6877-8E55-A3B8-0364-69652FE51F4F.exe C:\Users\Reisser\AppData\Local\Temp\ICReinstall_FileOpenerSetup.exe C:\Users\Reisser\AppData\Local\Temp\Launcher__10272.exe C:\Users\Reisser\AppData\Local\Temp\Launcher__9848.exe C:\Users\Reisser\AppData\Local\Temp\Launcher__9999.exe C:\Users\Reisser\AppData\Local\Temp\LiveSupport_setup.exe C:\Users\Reisser\AppData\Local\Temp\ms.exe C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Reisser\AppData\Local\Temp\nvStInst.exe C:\Users\Reisser\AppData\Local\Temp\optprosetup.exe C:\Users\Reisser\AppData\Local\Temp\Quarantine.exe C:\Users\Reisser\AppData\Local\Temp\setup_384.exe C:\Users\Reisser\AppData\Local\Temp\SpOrder.dll C:\Users\Reisser\AppData\Local\Temp\sqlite3.dll C:\Users\Reisser\AppData\Local\Temp\Storio2_DE_ger_Setup_pid_1588.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-15 17:20 ==================== End Of Log ============================ --- --- --- --- --- --- ist das alles so richtig? |
27.12.2014, 17:09 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Lässtige werbung trotz addblock Bitte auch ne neue Addition.txt erstellen, dazu FRST starten und einen Haken setzen bei Addition.txt, dann auf Scan klicken.
__________________ Logfiles bitte immer in CODE-Tags posten |
28.12.2014, 12:23 | #5 |
| Lässtige werbung trotz addblock FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-12-2014 Ran by Reisser at 2014-12-28 12:20:59 Running from C:\Users\Reisser\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1} AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Abenteuer Pferderücken Demo (HKLM-x32\...\Abenteuer Pferderücken Demo) (Version: - ) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Ashampoo Burning Studio FREE v.1.14.5 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG) Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.12.0 - Asmedia Technology) Flwsrf (HKLM-x32\...\Flwsrf) (Version: 3.0.0.2 - Flwsrf) <==== ATTENTION! Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.65 - Google Inc.) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden K-Lite Codec Pack 10.8.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.8.0 - ) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) mkv2vob (HKLM-x32\...\{21AE04E8-EBF6-40DB-9AA9-B7A80C5D057D}) (Version: 2.4.9 - 3r1c) NVIDIA 3D Vision Controller Driver 344.46 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 344.46 - NVIDIA Corporation) NVIDIA 3D Vision Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 344.60 - NVIDIA Corporation) NVIDIA GeForce Experience 2.1.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.3 - NVIDIA Corporation) NVIDIA Graphics Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.60 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.32.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation) NVIDIA PhysX System Software 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation) OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) QuickTime (HKLM-x32\...\{08094E03-AFE4-4853-9D31-6D0743DF5328}) (Version: 7.1.6.200 - Apple Computer, Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.) SecurityUtility (HKLM-x32\...\SecurityUtility) (Version: 1.0.0.992 - ) SHIELD Streaming (Version: 3.1.1000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 16.13.56 - NVIDIA Corporation) Hidden SIW Pro Edition (Trial Version) (HKLM-x32\...\{3B9704C8-1286-4a17-9EA8-F63004FC74A1}_is1) (Version: 2014.10.16 - Topala Software Solutions) VTech Download Agent Library (x32 Version: 1.00.0000 - VTech) Hidden VTech Download Manager (HKLM-x32\...\VTechDownloadManager) (Version: - VTech) WinRAR 5.10 Beta 4 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH) Zombie Invasion (HKLM-x32\...\ZombieInvasion) (Version: 2.7.50 - Time Lapse Solutions) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 22-12-2014 17:38:19 Removed Apple Software Update 25-12-2014 17:07:37 Windows Update 26-12-2014 18:53:33 Software Removal Tool 28-12-2014 03:00:23 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {07C4EDDE-20D1-4BFF-8659-B50E309D06FA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.) Task: {32E4AC8B-D955-4847-BF7D-215EA9001513} - System32\Tasks\PTJGYIFC => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe [2014-12-26] (HQ-VideoV26.12) <==== ATTENTION Task: {7C46BBB5-8422-47C1-A9C2-3BB2C3C41657} - System32\Tasks\upfs7235 => C:\Program Files (x86)\Flwsrf\upfs7235.exe [2014-12-05] () Task: {850FC5E5-AE51-4C51-95E1-FF3768705CCA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.) Task: {8B1C00F0-602F-40B2-9557-43584EC56145} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2014-10-06] () Task: {E1B12AA3-8587-49F7-8FD4-24A42FBB9ED3} - System32\Tasks\KWWB => C:\Users\Reisser\AppData\Roaming\KWWB.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION Task: {F125BC51-2941-4F4A-B676-B6C8A5B0E166} - System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B} => pcalua.exe -a C:\Users\Reisser\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=tugs Task: {F1E05127-80E4-400F-8C60-436999246896} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\KWWB.job => C:\Users\Reisser\AppData\Roaming\KWWB.exe <==== ATTENTION Task: C:\Windows\Tasks\PTJGYIFC.job => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2014-11-08 14:51 - 2014-10-30 03:10 - 00117064 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-12-26 19:04 - 2014-12-25 19:14 - 00537248 _____ () C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe 2014-10-13 02:49 - 2014-06-20 07:42 - 00401280 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe 2014-10-13 02:49 - 2014-03-04 12:20 - 00117760 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QtSolutions_SOAP-2.7.dll 2014-10-13 02:49 - 2014-04-22 03:14 - 00065536 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QHttpServer.dll 2014-10-13 02:49 - 2014-05-06 06:39 - 00861184 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\platforms\qwindows.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00021504 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qgif.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00020992 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qico.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00204800 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qjpeg.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00218112 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qmng.dll 2014-10-13 02:49 - 2014-05-06 06:58 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qsvg.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00015360 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtga.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00307712 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtiff.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00014848 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qwbmp.dll 2014-10-13 02:49 - 2014-05-06 07:31 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\sensors\qtsensors_dummy.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00036352 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qgenericbearer.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00038912 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qnativewifibearer.dll 2014-12-26 18:41 - 2014-11-14 22:15 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\libglesv2.dll 2014-12-26 18:41 - 2014-11-14 22:15 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\libegl.dll 2014-12-26 18:41 - 2014-11-14 22:15 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\pdf.dll 2014-12-26 18:41 - 2014-11-14 22:15 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\ffmpegsumo.dll 2014-12-26 18:41 - 2014-11-14 22:15 - 14910280 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\abengine => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ColorMedia => ""="service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-1744345613-2801571155-2633355246-500 - Administrator - Disabled) Guest (S-1-5-21-1744345613-2801571155-2633355246-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1744345613-2801571155-2633355246-1002 - Limited - Enabled) Reisser (S-1-5-21-1744345613-2801571155-2633355246-1000 - Administrator - Enabled) => C:\Users\Reisser ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Error: (12/28/2014 00:10:09 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT AUTHORITY60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.191.939.0 Aktualisierungsquelle: %NT AUTHORITY59 Aktualisierungsphase: 4.6.0305.00 Quellpfad: 4.6.0305.01 Signaturtyp: %NT AUTHORITY602 Aktualisierungstyp: %NT AUTHORITY604 Benutzer: NT AUTHORITY\SYSTEM Aktuelle Modulversion: %NT AUTHORITY605 Vorherige Modulversion: %NT AUTHORITY606 Fehlercode: %NT AUTHORITY607 Fehlerbeschreibung: %NT AUTHORITY608 Error: (12/28/2014 10:44:05 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT AUTHORITY60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.191.939.0 Aktualisierungsquelle: %NT AUTHORITY59 Aktualisierungsphase: 4.6.0305.00 Quellpfad: 4.6.0305.01 Signaturtyp: %NT AUTHORITY602 Aktualisierungstyp: %NT AUTHORITY604 Benutzer: NT AUTHORITY\SYSTEM Aktuelle Modulversion: %NT AUTHORITY605 Vorherige Modulversion: %NT AUTHORITY606 Fehlercode: %NT AUTHORITY607 Fehlerbeschreibung: %NT AUTHORITY608 Error: (12/28/2014 03:00:23 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT AUTHORITY60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.191.939.0 Aktualisierungsquelle: %NT AUTHORITY59 Aktualisierungsphase: 4.6.0305.00 Quellpfad: 4.6.0305.01 Signaturtyp: %NT AUTHORITY602 Aktualisierungstyp: %NT AUTHORITY604 Benutzer: NT AUTHORITY\SYSTEM Aktuelle Modulversion: %NT AUTHORITY605 Vorherige Modulversion: %NT AUTHORITY606 Fehlercode: %NT AUTHORITY607 Fehlerbeschreibung: %NT AUTHORITY608 Error: (12/28/2014 00:53:41 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT AUTHORITY60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.191.939.0 Aktualisierungsquelle: %NT AUTHORITY59 Aktualisierungsphase: 4.6.0305.00 Quellpfad: 4.6.0305.01 Signaturtyp: %NT AUTHORITY602 Aktualisierungstyp: %NT AUTHORITY604 Benutzer: NT AUTHORITY\SYSTEM Aktuelle Modulversion: %NT AUTHORITY605 Vorherige Modulversion: %NT AUTHORITY606 Fehlercode: %NT AUTHORITY607 Fehlerbeschreibung: %NT AUTHORITY608 Error: (12/27/2014 08:44:29 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT AUTHORITY60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.191.939.0 Aktualisierungsquelle: %NT AUTHORITY59 Aktualisierungsphase: 4.6.0305.00 Quellpfad: 4.6.0305.01 Signaturtyp: %NT AUTHORITY602 Aktualisierungstyp: %NT AUTHORITY604 Benutzer: NT AUTHORITY\SYSTEM Aktuelle Modulversion: %NT AUTHORITY605 Vorherige Modulversion: %NT AUTHORITY606 Fehlercode: %NT AUTHORITY607 Fehlerbeschreibung: %NT AUTHORITY608 Error: (12/27/2014 08:34:34 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: AMD FX(tm)-6100 Six-Core Processor Percentage of memory in use: 26% Total physical RAM: 8171.53 MB Available physical RAM: 5989.85 MB Total Pagefile: 16641.24 MB Available Pagefile: 13664.34 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:172.79 GB) (Free:68.8 GB) NTFS Drive d: () (Fixed) (Total:292.97 GB) (Free:27.66 GB) NTFS Drive e: (Filme 2 St) (Fixed) (Total:465.61 GB) (Free:189.89 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: FFB8F33B) Partition 1: (Not Active) - (Size=172.8 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=293 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 3280EB00) Partition 1: (Active) - (Size=126 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.6 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
28.12.2014, 23:44 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Lässtige werbung trotz addblock Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKLM-x32\...\Run: [gmsd_de_44] => [X] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:50863;https=127.0.0.1:50863 SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = R2 dZPlDQFMAyN; C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe [2726776 2014-12-27] (Time Lapse Solutions) Task: {32E4AC8B-D955-4847-BF7D-215EA9001513} - System32\Tasks\PTJGYIFC => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe [2014-12-26] (HQ-VideoV26.12) <==== ATTENTION Task: {7C46BBB5-8422-47C1-A9C2-3BB2C3C41657} - System32\Tasks\upfs7235 => C:\Program Files (x86)\Flwsrf\upfs7235.exe [2014-12-05] () Task: {E1B12AA3-8587-49F7-8FD4-24A42FBB9ED3} - System32\Tasks\KWWB => C:\Users\Reisser\AppData\Roaming\KWWB.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION Task: {F125BC51-2941-4F4A-B676-B6C8A5B0E166} - System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B} => pcalua.exe -a C:\Users\Reisser\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=tugs Task: C:\Windows\Tasks\KWWB.job => C:\Users\Reisser\AppData\Roaming\KWWB.exe <==== ATTENTION Task: C:\Windows\Tasks\PTJGYIFC.job => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe <==== ATTENTION C:\Users\Reisser\AppData\Roaming\omiga-plus C:\Users\Reisser\AppData\Local\Temp\089C73368233.exe C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.dll C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.exe C:\Users\Reisser\AppData\Local\Temp\EFDF6877-8E55-A3B8-0364-69652FE51F4F.exe C:\Users\Reisser\AppData\Local\Temp\ICReinstall_FileOpenerSetup.exe C:\Users\Reisser\AppData\Local\Temp\Launcher__10272.exe C:\Users\Reisser\AppData\Local\Temp\Launcher__9848.exe C:\Users\Reisser\AppData\Local\Temp\Launcher__9999.exe C:\Users\Reisser\AppData\Local\Temp\LiveSupport_setup.exe C:\Users\Reisser\AppData\Local\Temp\ms.exe C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Reisser\AppData\Local\Temp\nvStInst.exe C:\Users\Reisser\AppData\Local\Temp\optprosetup.exe C:\Users\Reisser\AppData\Local\Temp\Quarantine.exe C:\Users\Reisser\AppData\Local\Temp\setup_384.exe C:\Users\Reisser\AppData\Local\Temp\SpOrder.dll C:\Users\Reisser\AppData\Local\Temp\sqlite3.dll C:\Users\Reisser\AppData\Local\Temp\Storio2_DE_ger_Setup_pid_1588.exe C:\Users\Reisser\Desktop\Continue File Opener Installation.lnk C:\Users\Reisser\Downloads\FileOpenerSetup.exe C:\Program Files (x86)\2f4249ae-2ea2-4d9e-8f18-8c64e6461106 C:\Windows\Tasks\KWWB.job C:\Windows\System32\Tasks\KWWB C:\Users\Reisser\AppData\Roaming\KWWB.exe C:\Program Files (x86)\Flwsrf C:\Windows\SysWOW64\abengine.ini C:\Windows\System32\Tasks\upfs7235 C:\Windows\SysWOW64\abengineOff.ini C:\Windows\system32\abengineOff.ini C:\Windows\system32\abengine64.dll C:\Windows\SysWOW64\abengine.dll C:\ProgramData\qMuLXOMiMf C:\Users\Reisser\Downloads\rla-dtvpmt1.ts.nfo C:\Users\Reisser\Downloads\Goldesel.to - Die Seite fuer Direkt-Downloads aller Art.url C:\Users\Reisser\Downloads\goldesel.to - quality source for more than 15 years .txt C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part1.rar C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part3.rar C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part2.rar C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part4.rar C:\Windows\System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B} C:\Users\Reisser\Downloads\Orphan.Das.Waisenkind.German.AC3.HDRip.XViD-FuN.avi C:\Users\Reisser\AppData\Roaming\dlg C:\ProgramData\SecurityUtilityData C:\ProgramData\SecurityUtility C:\Windows\Tasks\PTJGYIFC.job C:\Windows\patsearch.bin C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe C:\Windows\System32\Tasks\PTJGYIFC C:\Users\Reisser\Downloads\34020109 C:\Program Files (x86)\BuyyNsaave C:\ProgramData\migbhnamcclanachieldofcbpebkajke C:\Users\Reisser\Downloads\The Purge 2.mkv C:\Users\Reisser\Downloads\G0neGrl.ld.HD.de C:\ProgramData\3872871776 C:\ProgramData\SecurityUtility C:\ProgramData\qMuLXOMiMf C:\Users\Reisser\AppData\Local\24567 EmptyTemp: Hosts: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ --> Lässtige werbung trotz addblock |
29.12.2014, 10:56 | #7 |
| Lässtige werbung trotz addblock Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-12-2014 Ran by Reisser at 2014-12-29 08:15:52 Run:1 Running from C:\Users\Reisser\Downloads\FRST-OlderVersion Loaded Profile: Reisser (Available profiles: Reisser) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM-x32\...\Run: [gmsd_de_44] => [X] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:50863;https=127.0.0.1:50863 SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = R2 dZPlDQFMAyN; C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe [2726776 2014-12-27] (Time Lapse Solutions) Task: {32E4AC8B-D955-4847-BF7D-215EA9001513} - System32\Tasks\PTJGYIFC => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe [2014-12-26] (HQ-VideoV26.12) <==== ATTENTION Task: {7C46BBB5-8422-47C1-A9C2-3BB2C3C41657} - System32\Tasks\upfs7235 => C:\Program Files (x86)\Flwsrf\upfs7235.exe [2014-12-05] () Task: {E1B12AA3-8587-49F7-8FD4-24A42FBB9ED3} - System32\Tasks\KWWB => C:\Users\Reisser\AppData\Roaming\KWWB.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION Task: {F125BC51-2941-4F4A-B676-B6C8A5B0E166} - System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B} => pcalua.exe -a C:\Users\Reisser\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=tugs Task: C:\Windows\Tasks\KWWB.job => C:\Users\Reisser\AppData\Roaming\KWWB.exe <==== ATTENTION Task: C:\Windows\Tasks\PTJGYIFC.job => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe <==== ATTENTION C:\Users\Reisser\AppData\Roaming\omiga-plus C:\Users\Reisser\AppData\Local\Temp\089C73368233.exe C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.dll C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.exe C:\Users\Reisser\AppData\Local\Temp\EFDF6877-8E55-A3B8-0364-69652FE51F4F.exe C:\Users\Reisser\AppData\Local\Temp\ICReinstall_FileOpenerSetup.exe C:\Users\Reisser\AppData\Local\Temp\Launcher__10272.exe C:\Users\Reisser\AppData\Local\Temp\Launcher__9848.exe C:\Users\Reisser\AppData\Local\Temp\Launcher__9999.exe C:\Users\Reisser\AppData\Local\Temp\LiveSupport_setup.exe C:\Users\Reisser\AppData\Local\Temp\ms.exe C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Reisser\AppData\Local\Temp\nvStInst.exe C:\Users\Reisser\AppData\Local\Temp\optprosetup.exe C:\Users\Reisser\AppData\Local\Temp\Quarantine.exe C:\Users\Reisser\AppData\Local\Temp\setup_384.exe C:\Users\Reisser\AppData\Local\Temp\SpOrder.dll C:\Users\Reisser\AppData\Local\Temp\sqlite3.dll C:\Users\Reisser\AppData\Local\Temp\Storio2_DE_ger_Setup_pid_1588.exe C:\Users\Reisser\Desktop\Continue File Opener Installation.lnk C:\Users\Reisser\Downloads\FileOpenerSetup.exe C:\Program Files (x86)\2f4249ae-2ea2-4d9e-8f18-8c64e6461106 C:\Windows\Tasks\KWWB.job C:\Windows\System32\Tasks\KWWB C:\Users\Reisser\AppData\Roaming\KWWB.exe C:\Program Files (x86)\Flwsrf C:\Windows\SysWOW64\abengine.ini C:\Windows\System32\Tasks\upfs7235 C:\Windows\SysWOW64\abengineOff.ini C:\Windows\system32\abengineOff.ini C:\Windows\system32\abengine64.dll C:\Windows\SysWOW64\abengine.dll C:\ProgramData\qMuLXOMiMf C:\Users\Reisser\Downloads\rla-dtvpmt1.ts.nfo C:\Users\Reisser\Downloads\Goldesel.to - Die Seite fuer Direkt-Downloads aller Art.url C:\Users\Reisser\Downloads\goldesel.to - quality source for more than 15 years .txt C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part1.rar C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part3.rar C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part2.rar C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part4.rar C:\Windows\System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B} C:\Users\Reisser\Downloads\Orphan.Das.Waisenkind.German.AC3.HDRip.XViD-FuN.avi C:\Users\Reisser\AppData\Roaming\dlg C:\ProgramData\SecurityUtilityData C:\ProgramData\SecurityUtility C:\Windows\Tasks\PTJGYIFC.job C:\Windows\patsearch.bin C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe C:\Windows\System32\Tasks\PTJGYIFC C:\Users\Reisser\Downloads\34020109 C:\Program Files (x86)\BuyyNsaave C:\ProgramData\migbhnamcclanachieldofcbpebkajke C:\Users\Reisser\Downloads\The Purge 2.mkv C:\Users\Reisser\Downloads\G0neGrl.ld.HD.de C:\ProgramData\3872871776 C:\ProgramData\SecurityUtility C:\ProgramData\qMuLXOMiMf C:\Users\Reisser\AppData\Local\24567 EmptyTemp: Hosts: ***************** HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_de_44 => value deleted successfully. "HKLM\SOFTWARE\Policies\Google" => Key deleted successfully. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. dZPlDQFMAyN => Unable to stop service dZPlDQFMAyN => Service deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{32E4AC8B-D955-4847-BF7D-215EA9001513}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{32E4AC8B-D955-4847-BF7D-215EA9001513}" => Key deleted successfully. C:\Windows\System32\Tasks\PTJGYIFC => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PTJGYIFC" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7C46BBB5-8422-47C1-A9C2-3BB2C3C41657}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7C46BBB5-8422-47C1-A9C2-3BB2C3C41657}" => Key deleted successfully. C:\Windows\System32\Tasks\upfs7235 => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\upfs7235" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E1B12AA3-8587-49F7-8FD4-24A42FBB9ED3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E1B12AA3-8587-49F7-8FD4-24A42FBB9ED3}" => Key deleted successfully. C:\Windows\System32\Tasks\KWWB => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\KWWB" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F125BC51-2941-4F4A-B676-B6C8A5B0E166}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F125BC51-2941-4F4A-B676-B6C8A5B0E166}" => Key deleted successfully. C:\Windows\System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B} => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FAE8AC9F-4635-4533-905E-1266F8CF043B}" => Key deleted successfully. C:\Windows\Tasks\KWWB.job => Moved successfully. C:\Windows\Tasks\PTJGYIFC.job => Moved successfully. "C:\Users\Reisser\AppData\Roaming\omiga-plus" => File/Directory not found. C:\Users\Reisser\AppData\Local\Temp\089C73368233.exe => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.dll => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.exe => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\EFDF6877-8E55-A3B8-0364-69652FE51F4F.exe => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\ICReinstall_FileOpenerSetup.exe => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\Launcher__10272.exe => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\Launcher__9848.exe => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\Launcher__9999.exe => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\LiveSupport_setup.exe => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\ms.exe => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI.dll => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI64.dll => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\nvStInst.exe => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\optprosetup.exe => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\Quarantine.exe => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\setup_384.exe => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\SpOrder.dll => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\sqlite3.dll => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\Storio2_DE_ger_Setup_pid_1588.exe => Moved successfully. C:\Users\Reisser\Desktop\Continue File Opener Installation.lnk => Moved successfully. C:\Users\Reisser\Downloads\FileOpenerSetup.exe => Moved successfully. C:\Program Files (x86)\2f4249ae-2ea2-4d9e-8f18-8c64e6461106 => Moved successfully. "C:\Windows\Tasks\KWWB.job" => File/Directory not found. "C:\Windows\System32\Tasks\KWWB" => File/Directory not found. C:\Users\Reisser\AppData\Roaming\KWWB.exe => Moved successfully. C:\Program Files (x86)\Flwsrf => Moved successfully. C:\Windows\SysWOW64\abengine.ini => Moved successfully. "C:\Windows\System32\Tasks\upfs7235" => File/Directory not found. C:\Windows\SysWOW64\abengineOff.ini => Moved successfully. C:\Windows\system32\abengineOff.ini => Moved successfully. C:\Windows\system32\abengine64.dll => Moved successfully. C:\Windows\SysWOW64\abengine.dll => Moved successfully. "C:\ProgramData\qMuLXOMiMf" directory move: Could not move "C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.dat" => Scheduled to move on reboot. C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe => Moved successfully. C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe.config => Moved successfully. Could not move "C:\ProgramData\qMuLXOMiMf\info.dat" => Scheduled to move on reboot. Could not move "C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe" => Scheduled to move on reboot. Could not move "C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe.config" => Scheduled to move on reboot. Could not move "C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe" => Scheduled to move on reboot. Could not move "C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe.config" => Scheduled to move on reboot. Could not move "C:\ProgramData\qMuLXOMiMf\dat\fvbqzObVHb.dll" => Scheduled to move on reboot. Could not move "C:\ProgramData\qMuLXOMiMf\dat\WQSxEJcIi.dll" => Scheduled to move on reboot. Could not move "C:\ProgramData\qMuLXOMiMf" directory. => Scheduled to move on reboot. C:\Users\Reisser\Downloads\rla-dtvpmt1.ts.nfo => Moved successfully. C:\Users\Reisser\Downloads\Goldesel.to - Die Seite fuer Direkt-Downloads aller Art.url => Moved successfully. "C:\Users\Reisser\Downloads\goldesel.to - quality source for more than 15 years .txt" => File/Directory not found. C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part1.rar => Moved successfully. C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part3.rar => Moved successfully. C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part2.rar => Moved successfully. C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part4.rar => Moved successfully. "C:\Windows\System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B}" => File/Directory not found. C:\Users\Reisser\Downloads\Orphan.Das.Waisenkind.German.AC3.HDRip.XViD-FuN.avi => Moved successfully. C:\Users\Reisser\AppData\Roaming\dlg => Moved successfully. C:\ProgramData\SecurityUtilityData => Moved successfully. C:\ProgramData\SecurityUtility => Moved successfully. "C:\Windows\Tasks\PTJGYIFC.job" => File/Directory not found. C:\Windows\patsearch.bin => Moved successfully. C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe => Moved successfully. "C:\Windows\System32\Tasks\PTJGYIFC" => File/Directory not found. C:\Users\Reisser\Downloads\34020109 => Moved successfully. C:\Program Files (x86)\BuyyNsaave => Moved successfully. C:\ProgramData\migbhnamcclanachieldofcbpebkajke => Moved successfully. C:\Users\Reisser\Downloads\The Purge 2.mkv => Moved successfully. C:\Users\Reisser\Downloads\G0neGrl.ld.HD.de => Moved successfully. C:\ProgramData\3872871776 => Moved successfully. "C:\ProgramData\SecurityUtility" => File/Directory not found. "C:\ProgramData\qMuLXOMiMf" directory move: Could not move "C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.dat" => Scheduled to move on reboot. Could not move "C:\ProgramData\qMuLXOMiMf\info.dat" => Scheduled to move on reboot. Could not move "C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe" => Scheduled to move on reboot. Could not move "C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe.config" => Scheduled to move on reboot. Could not move "C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe" => Scheduled to move on reboot. Could not move "C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe.config" => Scheduled to move on reboot. Could not move "C:\ProgramData\qMuLXOMiMf\dat\fvbqzObVHb.dll" => Scheduled to move on reboot. Could not move "C:\ProgramData\qMuLXOMiMf\dat\WQSxEJcIi.dll" => Scheduled to move on reboot. Could not move "C:\ProgramData\qMuLXOMiMf" directory. => Scheduled to move on reboot. C:\Users\Reisser\AppData\Local\24567 => Moved successfully. C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. EmptyTemp: => Removed 14.2 GB temporary data. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-12-29 08:17:48)<= C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.dat => Is moved successfully. C:\ProgramData\qMuLXOMiMf\info.dat => Is moved successfully. C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe => Is moved successfully. C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe.config => Is moved successfully. C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe => Is moved successfully. C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe.config => Is moved successfully. C:\ProgramData\qMuLXOMiMf\dat\fvbqzObVHb.dll => Is moved successfully. C:\ProgramData\qMuLXOMiMf\dat\WQSxEJcIi.dll => Is moved successfully. C:\ProgramData\qMuLXOMiMf => Is moved successfully. C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.dat => Is moved successfully. C:\ProgramData\qMuLXOMiMf\info.dat => Is moved successfully. C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe => Is moved successfully. C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe.config => Is moved successfully. C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe => Is moved successfully. C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe.config => Is moved successfully. C:\ProgramData\qMuLXOMiMf\dat\fvbqzObVHb.dll => Is moved successfully. C:\ProgramData\qMuLXOMiMf\dat\WQSxEJcIi.dll => Is moved successfully. C:\ProgramData\qMuLXOMiMf => Is moved successfully. ==== End of Fixlog 08:17:48 ==== scheint als wenn alles ok ist kommt bis jetzt nichtzs mehr nerviges!!! vielen dank für die Kompetente Hilfe schnell und echt super geholfen MFG Adrian !TOP! |
29.12.2014, 18:29 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Lässtige werbung trotz addblock Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Scan klicken
__________________ Logfiles bitte immer in CODE-Tags posten |
30.12.2014, 09:18 | #9 |
| Lässtige werbung trotz addblock FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-12-2014 Ran by Reisser (administrator) on REISSER-PC on 30-12-2014 09:15:19 Running from C:\Users\Reisser\Downloads Loaded Profile: Reisser (Available profiles: Reisser) Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Englisch (USA) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe (Fuyu LIMITED) C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files (x86)\SupTab\HpUI.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe () C:\Program Files (x86)\SupTab\Loader64.exe () C:\Program Files (x86)\SupTab\Loader32.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Apple Inc.) C:\Program Files (x86)\QuickTime\qttask.exe () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (VTech) C:\Program Files (x86)\VTech\DownloadManager\System\DownloadManager.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2463552 2014-10-04] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [282624 2007-04-27] (Apple Inc.) HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] () HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Run: [SwvUpdtr] => C:\Users\Reisser\AppData\Local\24567\Updater.exe /reg HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: G - G:\StorioSetup.exe HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {2e971c8e-719e-11e4-b18f-bc5ff45b0bd1} - F:\SNC715MusicPlayer.exe HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {9dac61e2-89ed-11e4-b4c2-bc5ff45b0bd1} - G:\StorioSetup.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:51111;https=127.0.0.1:51111 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = webssearches HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = webssearches HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1419800064&from=cvs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = webssearches HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = webssearches HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1419800064&from=cvs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Start Page = webssearches HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = webssearches StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe webssearches SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1419800064&from=cvs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms} SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1419800064&from=cvs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms} SearchScopes: HKU\S-1-5-21-1744345613-2801571155-2633355246-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1419800064&from=cvs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms} SearchScopes: HKU\S-1-5-21-1744345613-2801571155-2633355246-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1419800064&from=cvs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms} BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) Chrome: ======= CHR HomePage: Default -> https://www.google.de/?gws_rd=ssl CHR StartupUrls: Default -> "hxxp://istart.webssearches.com/?type=hp&ts=1419800064&from=cvs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975" CHR DefaultSearchKeyword: Default -> webssearches CHR DefaultSuggestURL: Default -> CHR Profile: C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-26] CHR Extension: (Google Docs) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-26] CHR Extension: (Google Drive) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-26] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-26] CHR Extension: (YouTube) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-26] CHR Extension: (Google Search) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-26] CHR Extension: (Google Sheets) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-26] CHR Extension: (Google Wallet) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-26] CHR Extension: (Gmail) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-26] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-10-04] (NVIDIA Corporation) R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [715656 2014-12-28] (Cherished Technololgy LIMITED) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-10-04] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-10-04] (NVIDIA Corporation) R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [485888 2014-12-28] (Fuyu LIMITED) [File not signed] S2 SecurityUtility Service; C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe -p "Covus" -c "Covus_Coupons" -s "CCC8" -i "851594" -g "" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-10-04] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation) S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-30 09:13 - 2014-12-30 09:13 - 00023089 _____ () C:\Users\Reisser\Downloads\Addition.txt 2014-12-30 09:12 - 2014-12-30 09:15 - 00012865 _____ () C:\Users\Reisser\Downloads\FRST.txt 2014-12-30 08:57 - 2014-12-30 08:57 - 00000000 ____D () C:\Users\Reisser\AppData\Local\DownloadManager 2014-12-29 16:01 - 2014-12-26 16:15 - 1030449942 _____ () C:\Users\Reisser\Downloads\pso-pinguine-webrip.mkv 2014-12-29 16:01 - 2014-12-26 16:15 - 01435648 _____ () C:\Users\Reisser\Downloads\remove_this 2014-12-29 16:01 - 2014-12-26 16:15 - 00022191 _____ () C:\Users\Reisser\Downloads\pso-pinguine-webrip.nfo 2014-12-29 16:01 - 2014-12-26 16:15 - 00000220 _____ () C:\Users\Reisser\Downloads\Goldesel.to - Die Seite fuer Direkt-Downloads aller Art.url 2014-12-29 16:01 - 2014-12-26 16:15 - 00000116 _____ () C:\Users\Reisser\Downloads\goldesel.to - quality source for more than 15 years .txt 2014-12-29 15:50 - 2014-12-29 16:00 - 199972800 _____ () C:\Users\Reisser\Downloads\Die.Pinguine.aus.Madagascar-PsO.part1.rar 2014-12-29 15:50 - 2014-12-29 15:59 - 199972800 _____ () C:\Users\Reisser\Downloads\Die.Pinguine.aus.Madagascar-PsO.part5.rar 2014-12-29 15:50 - 2014-12-29 15:59 - 199972800 _____ () C:\Users\Reisser\Downloads\Die.Pinguine.aus.Madagascar-PsO.part3.rar 2014-12-29 15:50 - 2014-12-29 15:59 - 199972800 _____ () C:\Users\Reisser\Downloads\Die.Pinguine.aus.Madagascar-PsO.part2.rar 2014-12-29 15:50 - 2014-12-29 15:58 - 199972800 _____ () C:\Users\Reisser\Downloads\Die.Pinguine.aus.Madagascar-PsO.part4.rar 2014-12-29 15:50 - 2014-12-29 15:52 - 42332050 _____ () C:\Users\Reisser\Downloads\Die.Pinguine.aus.Madagascar-PsO.part6.rar 2014-12-29 09:09 - 2014-12-29 09:09 - 00000000 ____D () C:\ProgramData\1078601655 2014-12-29 08:14 - 2014-12-29 08:16 - 00000000 ____D () C:\Users\Reisser\Downloads\FRST-OlderVersion 2014-12-29 08:11 - 2014-12-29 08:11 - 00000000 ____D () C:\ProgramData\Browser 2014-12-29 08:06 - 2014-12-29 08:07 - 00000002 _____ () C:\END 2014-12-28 22:00 - 2014-12-28 22:00 - 00000000 ____D () C:\Users\Reisser\Documents\Optimizer Pro 2014-12-28 21:57 - 2014-12-28 21:57 - 00001188 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk 2014-12-28 21:57 - 2014-12-28 21:57 - 00001176 _____ () C:\Users\Public\Desktop\paint.net.lnk 2014-12-28 21:57 - 2014-12-28 21:57 - 00000000 ____D () C:\Program Files\paint.net 2014-12-28 21:56 - 2014-12-28 21:59 - 00000000 ____D () C:\Users\Reisser\AppData\Local\paint.net 2014-12-28 21:54 - 2014-12-28 21:54 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect 2014-12-28 21:54 - 2014-12-28 21:54 - 00000000 ____D () C:\ProgramData\IePluginServices 2014-12-28 21:54 - 2014-12-28 21:54 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-12-28 21:45 - 2014-12-28 21:45 - 00000854 _____ () C:\Users\Reisser\AppData\Local\recently-used.xbel 2014-12-28 21:45 - 2014-12-28 21:45 - 00000000 ____D () C:\Users\Reisser\.thumbnails 2014-12-28 21:43 - 2014-12-28 21:49 - 00000000 ____D () C:\Users\Reisser\.gimp-2.8 2014-12-28 21:43 - 2014-12-28 21:43 - 00000000 ____D () C:\Users\Reisser\AppData\Local\gegl-0.2 2014-12-28 03:01 - 2014-12-28 03:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-12-28 03:01 - 2014-12-28 03:01 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-12-28 03:01 - 2014-12-28 03:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-12-27 15:58 - 2014-12-27 15:58 - 00001474 _____ () C:\Users\Reisser\Desktop\JRT.txt 2014-12-27 15:56 - 2014-12-27 15:56 - 00000000 ____D () C:\Windows\ERUNT 2014-12-27 15:53 - 2014-12-29 08:07 - 00000000 ____D () C:\Users\Reisser\AppData\Local\ZombieInvasion 2014-12-27 15:46 - 2014-12-27 15:50 - 00000000 ____D () C:\AdwCleaner 2014-12-27 15:46 - 2014-12-27 15:46 - 01707646 _____ (Thisisu) C:\Users\Reisser\Downloads\JRT.exe 2014-12-27 15:01 - 2014-12-30 09:15 - 00000000 ____D () C:\FRST 2014-12-27 15:01 - 2014-12-29 08:14 - 02123264 _____ (Farbar) C:\Users\Reisser\Downloads\FRST64.exe 2014-12-26 20:54 - 2014-12-26 21:03 - 00000000 ____D () C:\Users\Reisser\Desktop\weihnachten 14 2014-12-26 19:28 - 2014-12-28 21:54 - 00002416 _____ () C:\Users\Reisser\Desktop\chrome.lnk 2014-12-26 19:04 - 2014-12-27 11:44 - 00005240 _____ () C:\Windows\SysWOW64\ColorMedia.ini 2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\SysWOW64\ColorMediaOff.ini 2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\system32\ColorMediaOff.ini 2014-12-26 19:04 - 2014-12-14 10:53 - 00378640 _____ (CartCrunch Israel Ltd.) C:\Windows\system32\ColorMedia64.dll 2014-12-26 19:04 - 2014-12-14 10:53 - 00332568 _____ (CartCrunch Israel Ltd.) C:\Windows\SysWOW64\ColorMedia.dll 2014-12-26 18:42 - 2014-12-27 14:29 - 00000000 ___HD () C:\Users\Public\Temp 2014-12-26 18:41 - 2014-12-27 15:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-12-26 18:40 - 2014-12-30 08:30 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-12-26 18:40 - 2014-12-29 08:18 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-12-26 18:40 - 2014-12-29 08:18 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-12-26 18:40 - 2014-12-29 08:18 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-12-26 18:40 - 2014-12-26 18:40 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrNewH_01009.Wdf 2014-12-26 18:35 - 2014-12-26 18:35 - 00000000 ___DC () C:\Users\Reisser\AppData\Local\MigWiz 2014-12-26 07:16 - 2014-12-26 07:16 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2014-12-24 17:15 - 2014-12-24 17:15 - 00000000 ____D () C:\Program Files (x86)\Ripple Emulator 2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\VTech 2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTech 2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\Program Files (x86)\VTech 2014-12-19 17:14 - 2014-12-19 17:14 - 00000000 _____ () C:\Users\Reisser\AppData\Local\{E9C16533-9CB5-45BF-A1F9-47B28A73E05D} 2014-12-18 15:33 - 2014-12-18 17:29 - 00000000 ____D () C:\Users\Reisser\Downloads\Hörbücher 2014-12-18 13:21 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-12-18 13:21 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-12-17 17:42 - 2014-12-17 17:42 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\NVIDIA 2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Mindscape 2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mindscape 2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mindscape 2014-12-17 17:39 - 2014-12-17 17:39 - 00000000 ____D () C:\Program Files (x86)\Mindscape 2014-12-17 17:36 - 2014-12-17 17:36 - 00054156 ____H () C:\Windows\QTFont.qfn 2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-12-17 17:32 - 2014-12-17 17:35 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-12-12 23:05 - 2014-12-12 23:05 - 00159200 ____T () C:\Users\Reisser\AppData\Roaming\CrashRpt1402.dll 2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIW Pro Trial 2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\Program Files (x86)\SIW Pro Trial 2014-12-12 03:19 - 2014-12-12 03:19 - 00000000 ____D () C:\Windows\system32\appraiser 2014-12-12 03:01 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2014-12-12 03:01 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2014-12-12 03:01 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2014-12-12 03:01 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2014-12-12 03:01 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2014-12-12 03:01 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2014-12-12 03:01 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2014-12-12 03:01 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2014-12-12 03:01 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2014-12-12 03:01 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2014-12-11 04:56 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-12-11 04:56 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2014-12-11 04:55 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-12-11 04:55 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-12-11 04:55 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-12-11 04:55 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-12-11 04:55 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-12-11 04:55 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-12-11 04:55 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-12-11 04:55 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-12-11 04:55 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-12-11 04:55 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-12-11 04:55 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-12-11 04:55 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-12-11 04:55 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-12-11 04:55 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-12-11 04:55 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-12-11 04:55 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-12-11 04:55 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-12-11 04:55 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-12-11 04:55 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-12-11 04:55 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-12-11 04:55 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-12-11 04:55 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-12-11 04:55 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-12-11 04:55 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-12-11 04:55 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-12-11 04:55 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-12-11 04:55 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-12-11 04:55 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-12-11 04:55 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-12-11 04:55 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-12-11 04:55 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-12-11 04:55 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-12-11 04:55 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-12-11 04:55 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-12-11 04:55 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-12-11 04:55 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-12-11 04:55 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-12-11 04:55 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-12-11 04:55 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-12-11 04:55 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-12-11 04:55 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-12-11 04:55 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-12-11 04:55 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-12-11 04:55 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-12-11 04:55 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-12-11 04:55 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-12-11 04:55 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-12-11 04:55 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-12-11 04:55 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-12-11 04:55 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-12-11 04:55 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-12-11 04:55 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-12-11 04:55 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-12-11 04:55 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-12-11 04:55 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-12-11 04:55 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-12-11 04:55 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2014-12-11 04:54 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-12-11 04:54 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-12-11 04:54 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe 2014-12-11 04:54 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe 2014-12-11 04:54 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2014-12-11 04:54 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2014-12-11 04:54 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2014-12-11 04:54 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2014-12-11 04:54 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2014-12-11 04:54 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2014-12-11 04:54 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll 2014-12-11 04:54 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2014-12-11 04:54 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll 2014-12-11 04:54 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe 2014-12-11 00:26 - 2014-12-11 00:26 - 01413208 _____ () C:\Windows\Minidump\121114-20248-01.dmp 2014-12-05 12:01 - 2014-12-27 11:40 - 00012288 _____ () C:\Users\Reisser\Desktop\Stundenzettelfür Feru - Dezember14 -.xls 2014-12-04 13:29 - 2014-12-13 15:32 - 00000062 _____ () C:\Users\Reisser\Desktop\Neues Textdokument.txt 2014-12-04 12:53 - 2014-12-29 14:39 - 00000000 ____D () C:\Users\Reisser\Downloads\Musik 2014-12-04 12:52 - 2014-12-29 14:55 - 00000000 ____D () C:\Users\Reisser\Downloads\Kinder Filme ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-12-30 08:42 - 2014-11-08 14:39 - 01502338 _____ () C:\Windows\WindowsUpdate.log 2014-12-29 14:50 - 2014-11-10 17:53 - 00000000 ____D () C:\Users\Reisser\Downloads\Filme 2014-12-29 14:40 - 2014-11-27 19:28 - 00000000 ____D () C:\Users\Reisser\Desktop\Wallpapers 2014-12-29 09:48 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-12-29 09:48 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-12-29 08:24 - 2014-11-08 16:15 - 00697256 _____ () C:\Windows\system32\perfh007.dat 2014-12-29 08:24 - 2014-11-08 16:15 - 00149224 _____ () C:\Windows\system32\perfc007.dat 2014-12-29 08:24 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-29 08:17 - 2014-11-08 14:52 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-12-29 08:17 - 2010-11-21 04:47 - 00042446 _____ () C:\Windows\PFRO.log 2014-12-29 08:17 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-12-29 08:17 - 2009-07-14 05:51 - 00042019 _____ () C:\Windows\setupact.log 2014-12-28 21:54 - 2014-11-08 14:42 - 00001213 _____ () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-12-28 21:45 - 2014-11-08 14:42 - 00000000 ____D () C:\Users\Reisser 2014-12-27 14:23 - 2014-11-08 15:29 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Users\Reisser\AppData\Local\Google 2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Program Files (x86)\Google 2014-12-25 12:22 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-12-17 17:42 - 2014-11-08 14:42 - 00000000 ____D () C:\Users\Reisser\AppData\Local\VirtualStore 2014-12-12 05:23 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-12-12 03:19 - 2014-11-08 19:04 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat 2014-12-12 03:04 - 2014-11-08 19:30 - 00000000 ____D () C:\Windows\system32\MRT 2014-12-12 03:02 - 2014-11-08 19:30 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-12-11 00:29 - 2014-11-16 15:02 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-12-11 00:26 - 2014-11-28 13:23 - 564424988 _____ () C:\Windows\MEMORY.DMP 2014-12-11 00:26 - 2014-11-28 13:23 - 00000000 ____D () C:\Windows\Minidump 2014-12-05 11:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-12-01 06:58 - 2014-11-20 17:29 - 00012288 _____ () C:\Users\Reisser\Desktop\Stundenzettelfür Feru - November 14 - Kopie.xls ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-12-15 17:20 ==================== End Of Log ============================ --- --- --- FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-12-2014 Ran by Reisser at 2014-12-30 09:15:38 Running from C:\Users\Reisser\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1} AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Abenteuer Pferderücken Demo (HKLM-x32\...\Abenteuer Pferderücken Demo) (Version: - ) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Ashampoo Burning Studio FREE v.1.14.5 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG) Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.12.0 - Asmedia Technology) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden K-Lite Codec Pack 10.8.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.8.0 - ) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) mkv2vob (HKLM-x32\...\{21AE04E8-EBF6-40DB-9AA9-B7A80C5D057D}) (Version: 2.4.9 - 3r1c) NVIDIA 3D Vision Controller Driver 344.46 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 344.46 - NVIDIA Corporation) NVIDIA 3D Vision Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 344.60 - NVIDIA Corporation) NVIDIA GeForce Experience 2.1.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.3 - NVIDIA Corporation) NVIDIA Graphics Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.60 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.32.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation) NVIDIA PhysX System Software 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation) OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) paint.net (HKLM\...\{F509C1F4-0029-49F9-B145-A4C4E8DF481A}) (Version: 4.0.3 - dotPDN LLC) QuickTime (HKLM-x32\...\{08094E03-AFE4-4853-9D31-6D0743DF5328}) (Version: 7.1.6.200 - Apple Computer, Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.) SecurityUtility (HKLM-x32\...\SecurityUtility) (Version: 1.0.0.992 - ) SHIELD Streaming (Version: 3.1.1000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 16.13.56 - NVIDIA Corporation) Hidden SIW Pro Edition (Trial Version) (HKLM-x32\...\{3B9704C8-1286-4a17-9EA8-F63004FC74A1}_is1) (Version: 2014.10.16 - Topala Software Solutions) VTech Download Agent Library (x32 Version: 1.00.0000 - VTech) Hidden VTech Download Manager (HKLM-x32\...\VTechDownloadManager) (Version: - VTech) webssearches uninstall (HKLM-x32\...\webssearches uninstall) (Version: - webssearches) <==== ATTENTION WinRAR 5.10 Beta 4 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 22-12-2014 17:38:19 Removed Apple Software Update 25-12-2014 17:07:37 Windows Update 26-12-2014 18:53:33 Software Removal Tool 28-12-2014 03:00:23 Windows Update 28-12-2014 21:56:42 paint.net v4.0.3 ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2014-12-29 08:16 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {07C4EDDE-20D1-4BFF-8659-B50E309D06FA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.) Task: {850FC5E5-AE51-4C51-95E1-FF3768705CCA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.) Task: {8B1C00F0-602F-40B2-9557-43584EC56145} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2014-10-06] () Task: {F1E05127-80E4-400F-8C60-436999246896} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-11-08 14:51 - 2014-10-30 03:10 - 00117064 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-08-21 12:33 - 2014-12-28 21:54 - 00106376 _____ () C:\Program Files (x86)\SupTab\WindowsSupportDll64.dll 2014-08-21 12:32 - 2014-12-28 21:54 - 00733576 _____ () C:\Program Files (x86)\SupTab\HpUI.exe 2014-07-16 10:55 - 2014-07-16 10:55 - 00073216 _____ () C:\Program Files (x86)\SupTab\Loader64.exe 2014-07-16 11:16 - 2014-07-16 11:16 - 00064000 _____ () C:\Program Files (x86)\SupTab\Loader32.exe 2014-10-13 02:49 - 2014-06-20 07:42 - 00401280 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe 2014-08-21 12:33 - 2014-12-28 21:54 - 00023944 _____ () C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll 2014-10-13 02:49 - 2014-03-04 12:20 - 00117760 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QtSolutions_SOAP-2.7.dll 2014-10-13 02:49 - 2014-04-22 03:14 - 00065536 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QHttpServer.dll 2014-10-13 02:49 - 2014-05-06 06:39 - 00861184 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\platforms\qwindows.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00021504 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qgif.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00020992 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qico.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00204800 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qjpeg.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00218112 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qmng.dll 2014-10-13 02:49 - 2014-05-06 06:58 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qsvg.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00015360 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtga.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00307712 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtiff.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00014848 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qwbmp.dll 2014-10-13 02:49 - 2014-05-06 07:31 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\sensors\qtsensors_dummy.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00036352 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qgenericbearer.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00038912 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qnativewifibearer.dll 2014-12-29 08:25 - 2014-12-06 02:50 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libglesv2.dll 2014-12-29 08:25 - 2014-12-06 02:50 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libegl.dll 2014-12-29 08:25 - 2014-12-06 02:50 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dll 2014-12-29 08:25 - 2014-12-06 02:50 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ffmpegsumo.dll 2014-10-13 02:49 - 2014-05-02 09:44 - 00032256 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QHttpMessageClient.dll 2014-11-05 03:13 - 2014-07-03 04:18 - 00031616 _____ () C:\Program Files (x86)\VTech\DownloadManager\Applications\InnoTab_DE_ger\InnoTabFSLibrary.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\abengine => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ColorMedia => ""="service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-1744345613-2801571155-2633355246-500 - Administrator - Disabled) Guest (S-1-5-21-1744345613-2801571155-2633355246-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1744345613-2801571155-2633355246-1002 - Limited - Enabled) Reisser (S-1-5-21-1744345613-2801571155-2633355246-1000 - Administrator - Enabled) => C:\Users\Reisser ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (12/29/2014 04:03:10 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 5168. Message ID: [0x2509]. Error: (12/29/2014 04:01:52 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 5368. Message ID: [0x2509]. Error: (12/29/2014 02:55:40 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 2472. Message ID: [0x2509]. Error: (12/29/2014 02:52:42 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 4420. Message ID: [0x2509]. Error: (12/29/2014 02:49:46 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 3344. Message ID: [0x2509]. Error: (12/29/2014 02:47:17 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 3964. Message ID: [0x2509]. Error: (12/29/2014 02:44:55 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 4676. Message ID: [0x2509]. Error: (12/29/2014 02:39:09 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 4988. Message ID: [0x2509]. Error: (12/29/2014 09:08:40 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1". Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (12/29/2014 09:08:40 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1". Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". System errors: ============= Error: (12/29/2014 11:50:01 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT AUTHORITY60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.191.1047.0 Aktualisierungsquelle: %NT AUTHORITY59 Aktualisierungsphase: 4.6.0305.00 Quellpfad: 4.6.0305.01 Signaturtyp: %NT AUTHORITY602 Aktualisierungstyp: %NT AUTHORITY604 Benutzer: NT AUTHORITY\SYSTEM Aktuelle Modulversion: %NT AUTHORITY605 Vorherige Modulversion: %NT AUTHORITY606 Fehlercode: %NT AUTHORITY607 Fehlerbeschreibung: %NT AUTHORITY608 Error: (12/29/2014 10:29:13 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT AUTHORITY60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.191.1047.0 Aktualisierungsquelle: %NT AUTHORITY59 Aktualisierungsphase: 4.6.0305.00 Quellpfad: 4.6.0305.01 Signaturtyp: %NT AUTHORITY602 Aktualisierungstyp: %NT AUTHORITY604 Benutzer: NT AUTHORITY\SYSTEM Aktuelle Modulversion: %NT AUTHORITY605 Vorherige Modulversion: %NT AUTHORITY606 Fehlercode: %NT AUTHORITY607 Fehlerbeschreibung: %NT AUTHORITY608 Error: (12/29/2014 08:17:39 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SecurityUtility Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (12/29/2014 08:17:09 AM) (Source: Ntfs) (EventID: 137) (User: ) Description: Auf dem Volume "\\?\Volume{2dd34089-674c-11e4-af0b-806e6f6e6963}" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (12/29/2014 08:17:09 AM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (12/29/2014 08:15:52 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Optimizer Pro Crash Monitor" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (12/29/2014 08:05:08 AM) (Source: Ntfs) (EventID: 137) (User: ) Description: Auf dem Volume "\\?\Volume{2dd34089-674c-11e4-af0b-806e6f6e6963}" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (12/29/2014 08:05:07 AM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Error: (12/28/2014 09:34:13 PM) (Source: Ntfs) (EventID: 137) (User: ) Description: Auf dem Volume "\\?\Volume{2dd34089-674c-11e4-af0b-806e6f6e6963}" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (12/28/2014 09:34:13 PM) (Source: Disk) (EventID: 7) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1. Microsoft Office Sessions: ========================= Error: (12/29/2014 04:03:10 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 5168. Message ID: [0x2509]. Error: (12/29/2014 04:01:52 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 5368. Message ID: [0x2509]. Error: (12/29/2014 02:55:40 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 2472. Message ID: [0x2509]. Error: (12/29/2014 02:52:42 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 4420. Message ID: [0x2509]. Error: (12/29/2014 02:49:46 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 3344. Message ID: [0x2509]. Error: (12/29/2014 02:47:17 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 3964. Message ID: [0x2509]. Error: (12/29/2014 02:44:55 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 4676. Message ID: [0x2509]. Error: (12/29/2014 02:39:09 PM) (Source: .NET Runtime) (EventID: 1022) (User: ) Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure. This process will not allow a profiler to attach. HRESULT: 0x80004005. Process ID (decimal): 4988. Message ID: [0x2509]. Error: (12/29/2014 09:08:40 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl Error: (12/29/2014 09:08:40 AM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl ==================== Memory info =========================== Processor: AMD FX(tm)-6100 Six-Core Processor Percentage of memory in use: 21% Total physical RAM: 8171.53 MB Available physical RAM: 6376.85 MB Total Pagefile: 16641.24 MB Available Pagefile: 13706.23 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:172.79 GB) (Free:103.17 GB) NTFS Drive d: () (Fixed) (Total:292.97 GB) (Free:58.35 GB) NTFS Drive e: (Filme 2 St) (Fixed) (Total:465.61 GB) (Free:129.15 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: FFB8F33B) Partition 1: (Not Active) - (Size=172.8 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=293 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 3280EB00) Partition 1: (Active) - (Size=126 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.6 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
30.12.2014, 09:24 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Lässtige werbung trotz addblock Das ist ja immer noch Adware ........bitte nochmal das volle Programm!! Adware/Junkware/Toolbars entfernen (alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!) 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten |
05.01.2015, 09:54 | #11 |
| Lässtige werbung trotz addblock AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v4.106 - Report created 05/01/2015 at 09:33:08 # Updated 21/12/2014 by Xplode # Database : 2015-01-03.1 [Live] # Operating System : Windows 7 Ultimate Service Pack 1 (64 bits) # Username : Reisser - REISSER-PC # Running from : C:\Users\Reisser\Desktop\AdwCleaner_4.106 - Kopie.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.trovi.com_0.localstorage File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.trovi.com_0.localstorage-journal File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal ***** [ Scheduled Tasks ] ***** ***** [ Shortcuts ] ***** ***** [ Registry ] ***** ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.17496 -\\ Google Chrome v39.0.2171.95 ************************* AdwCleaner[R0].txt - [20752 octets] - [27/12/2014 15:47:37] AdwCleaner[R1].txt - [18811 octets] - [05/01/2015 09:22:06] AdwCleaner[R2].txt - [1568 octets] - [05/01/2015 09:31:43] AdwCleaner[S0].txt - [20132 octets] - [27/12/2014 15:50:26] AdwCleaner[S1].txt - [18194 octets] - [05/01/2015 09:23:21] AdwCleaner[S2].txt - [1497 octets] - [05/01/2015 09:33:08] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1557 octets] ########## mnhg~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.1 (12.28.2014:1) OS: Windows 7 Ultimate x64 Ran by Reisser on 05.01.2015 at 9:36:32,08 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files Successfully deleted: [File] "C:\Users\Reisser\appdata\local\google\chrome\user data\default\local storage\http_www.trovi.com_0.localstorage" Successfully deleted: [File] "C:\Users\Reisser\appdata\local\google\chrome\user data\default\local storage\http_www.trovi.com_0.localstorage-journal" ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 05.01.2015 at 9:38:49,77 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2015 Ran by Reisser (administrator) on REISSER-PC on 05-01-2015 09:45:09 Running from C:\Users\Reisser\Desktop Loaded Profile: Reisser (Available profiles: Reisser) Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Englisch (USA) Internet Explorer Version 11 (Default browser: Bobrowser) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Apple Inc.) C:\Program Files (x86)\QuickTime\qttask.exe () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2463552 2014-10-04] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [282624 2007-04-27] (Apple Inc.) HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] () HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Run: [SwvUpdtr] => C:\Users\Reisser\AppData\Local\24567\Updater.exe /reg HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: G - G:\StorioSetup.exe HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {2e971c8e-719e-11e4-b18f-bc5ff45b0bd1} - F:\SNC715MusicPlayer.exe HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {9dac61e2-89ed-11e4-b4c2-bc5ff45b0bd1} - G:\StorioSetup.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:51111;https=127.0.0.1:51111 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Google HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = Google HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = Google HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Firefox\Extensions: [{75229658-C485-8921-6792-5A8E5A8C26B4}] - C:\Program Files (x86)\ver3BetterMarkIt\185.xpi Chrome: ======= CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3331316&octid=EB_ORIGINAL_CTID&ISID=M1D1612CD-E697-484A-B9DE-850FA4C8F09D&SearchSource=55&CUI=&UM=8&UP=SP0225E5DB-2AB9-423E-9B34-14F8D9DC2719&SSPV= CHR StartupUrls: Default -> "hxxp://www.trovi.com/?gd=&ctid=CT3331316&octid=EB_ORIGINAL_CTID&ISID=M1D1612CD-E697-484A-B9DE-850FA4C8F09D&SearchSource=55&CUI=&UM=8&UP=SP0225E5DB-2AB9-423E-9B34-14F8D9DC2719&SSPV=" CHR DefaultSearchKeyword: Default -> trovi.search CHR DefaultNewTabURL: Default -> https://www.trovi.com/?gd=&ctid=CT3331316&octid=EB_ORIGINAL_CTID&ISID=M1D1612CD-E697-484A-B9DE-850FA4C8F09D&SearchSource=69&CUI=&SSPV=&lay=5&p=cnts&UM=8&UP=SP0225E5DB-2AB9-423E-9B34-14F8D9DC2719&SAT=CNTS CHR DefaultSuggestURL: Default -> hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms} CHR Profile: C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-26] CHR Extension: (Google Docs) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-26] CHR Extension: (Google Drive) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-26] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-26] CHR Extension: (YouTube) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-26] CHR Extension: (Google Search) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-26] CHR Extension: (Google Sheets) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-26] CHR Extension: (Google Wallet) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-26] CHR Extension: (Gmail) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-26] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-10-04] (NVIDIA Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation) S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-10-04] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-10-04] (NVIDIA Corporation) S2 SecurityUtility Service; C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe -p "Covus" -c "Covus_Coupons" -s "CCC8" -i "851594" -g "" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-10-04] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation) R2 webinstrNHK; C:\Windows\system32\Drivers\webinstrNHK.sys [56432 2015-01-04] (Corsica) S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-05 09:45 - 2015-01-05 09:45 - 00010775 _____ () C:\Users\Reisser\Desktop\FRST.txt 2015-01-05 09:44 - 2015-01-05 09:44 - 02123776 _____ (Farbar) C:\Users\Reisser\Desktop\FRST64.exe 2015-01-05 09:38 - 2015-01-05 09:38 - 00000919 _____ () C:\Users\Reisser\Desktop\JRT.txt 2015-01-05 09:35 - 2015-01-05 09:35 - 00001637 _____ () C:\Users\Reisser\Desktop\AdwCleaner[S2].txt 2015-01-05 09:28 - 2015-01-05 09:18 - 02173952 _____ () C:\Users\Reisser\Desktop\AdwCleaner_4.106 - Kopie.exe 2015-01-05 09:28 - 2015-01-05 09:17 - 01707939 _____ (Thisisu) C:\Users\Reisser\Desktop\JRT - Kopie.exe 2015-01-04 19:22 - 2015-01-04 19:22 - 00002351 _____ () C:\Windows\patsearch.bin 2015-01-04 19:22 - 2015-01-04 19:21 - 00056432 _____ (Corsica) C:\Windows\system32\Drivers\webinstrNHK.sys 2015-01-04 19:20 - 2015-01-05 09:35 - 00001342 _____ () C:\Windows\Tasks\PESM.job 2015-01-04 19:20 - 2015-01-04 19:21 - 00004376 _____ () C:\Windows\System32\Tasks\PESM 2015-01-04 19:20 - 2015-01-04 19:21 - 00000000 ____D () C:\Program Files (x86)\c37590b6-b104-45a2-80cb-69d810a404ed 2015-01-04 19:20 - 2015-01-04 19:20 - 01965032 _____ (home) C:\Users\Reisser\AppData\Roaming\PESM.exe 2015-01-03 13:00 - 2015-01-01 23:33 - 1068301169 _____ () C:\Users\Reisser\Downloads\Fury-Herz aus Stahl.mkv 2015-01-03 12:10 - 2015-01-02 01:12 - 844664404 _____ () C:\Users\Reisser\Downloads\Nachts im Museum 3.mkv 2014-12-31 18:09 - 2014-12-31 18:09 - 00000000 ____D () C:\Program Files (x86)\Belkin 2014-12-31 18:08 - 2014-12-31 18:08 - 00000000 ____D () C:\Windows\{4626E3EA-85B3-464E-B296-F3F5488D8B08} 2014-12-29 09:09 - 2014-12-29 09:09 - 00000000 ____D () C:\ProgramData\1078601655 2014-12-28 21:57 - 2014-12-28 21:57 - 00001188 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk 2014-12-28 21:57 - 2014-12-28 21:57 - 00000000 ____D () C:\Program Files\paint.net 2014-12-28 21:56 - 2014-12-28 21:59 - 00000000 ____D () C:\Users\Reisser\AppData\Local\paint.net 2014-12-28 21:45 - 2014-12-28 21:45 - 00000854 _____ () C:\Users\Reisser\AppData\Local\recently-used.xbel 2014-12-28 21:45 - 2014-12-28 21:45 - 00000000 ____D () C:\Users\Reisser\.thumbnails 2014-12-28 21:43 - 2014-12-28 21:49 - 00000000 ____D () C:\Users\Reisser\.gimp-2.8 2014-12-28 21:43 - 2014-12-28 21:43 - 00000000 ____D () C:\Users\Reisser\AppData\Local\gegl-0.2 2014-12-28 03:01 - 2014-12-28 03:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2014-12-28 03:01 - 2014-12-28 03:01 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-12-28 03:01 - 2014-12-28 03:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight 2014-12-27 15:56 - 2014-12-27 15:56 - 00000000 ____D () C:\Windows\ERUNT 2014-12-27 15:46 - 2015-01-05 09:33 - 00000000 ____D () C:\AdwCleaner 2014-12-27 15:01 - 2015-01-05 09:45 - 00000000 ____D () C:\FRST 2014-12-26 20:54 - 2014-12-26 21:03 - 00000000 ____D () C:\Users\Reisser\Desktop\weihnachten 14 2014-12-26 19:04 - 2014-12-27 11:44 - 00005240 _____ () C:\Windows\SysWOW64\ColorMedia.ini 2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\SysWOW64\ColorMediaOff.ini 2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\system32\ColorMediaOff.ini 2014-12-26 19:04 - 2014-12-14 10:53 - 00378640 _____ (CartCrunch Israel Ltd.) C:\Windows\system32\ColorMedia64.dll 2014-12-26 19:04 - 2014-12-14 10:53 - 00332568 _____ (CartCrunch Israel Ltd.) C:\Windows\SysWOW64\ColorMedia.dll 2014-12-26 18:42 - 2014-12-27 14:29 - 00000000 ___HD () C:\Users\Public\Temp 2014-12-26 18:41 - 2015-01-05 09:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-12-26 18:40 - 2015-01-05 09:35 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-12-26 18:40 - 2014-12-29 08:18 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-12-26 18:40 - 2014-12-29 08:18 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-12-26 18:40 - 2014-12-29 08:18 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-12-26 18:40 - 2014-12-26 18:40 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrNewH_01009.Wdf 2014-12-26 18:35 - 2014-12-26 18:35 - 00000000 ___DC () C:\Users\Reisser\AppData\Local\MigWiz 2014-12-26 07:16 - 2014-12-26 07:16 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2014-12-24 17:15 - 2014-12-24 17:15 - 00000000 ____D () C:\Program Files (x86)\Ripple Emulator 2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\VTech 2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTech 2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\Program Files (x86)\VTech 2014-12-19 17:14 - 2014-12-19 17:14 - 00000000 _____ () C:\Users\Reisser\AppData\Local\{E9C16533-9CB5-45BF-A1F9-47B28A73E05D} 2014-12-18 15:33 - 2014-12-18 17:29 - 00000000 ____D () C:\Users\Reisser\Downloads\Hörbücher 2014-12-18 13:21 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-12-18 13:21 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-12-17 17:42 - 2014-12-17 17:42 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\NVIDIA 2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Mindscape 2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mindscape 2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mindscape 2014-12-17 17:39 - 2014-12-17 17:39 - 00000000 ____D () C:\Program Files (x86)\Mindscape 2014-12-17 17:36 - 2014-12-17 17:36 - 00054156 ____H () C:\Windows\QTFont.qfn 2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2014-12-17 17:32 - 2014-12-17 17:35 - 00000000 ____D () C:\ProgramData\Apple Computer 2014-12-12 23:05 - 2014-12-12 23:05 - 00159200 ____T () C:\Users\Reisser\AppData\Roaming\CrashRpt1402.dll 2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIW Pro Trial 2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\Program Files (x86)\SIW Pro Trial 2014-12-12 03:19 - 2014-12-12 03:19 - 00000000 ____D () C:\Windows\system32\appraiser 2014-12-12 03:01 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2014-12-12 03:01 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2014-12-12 03:01 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2014-12-12 03:01 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2014-12-12 03:01 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2014-12-12 03:01 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2014-12-12 03:01 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2014-12-12 03:01 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2014-12-12 03:01 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2014-12-12 03:01 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-12-11 04:56 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2014-12-11 04:56 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-12-11 04:56 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2014-12-11 04:55 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-12-11 04:55 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-12-11 04:55 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-12-11 04:55 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-12-11 04:55 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-12-11 04:55 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-12-11 04:55 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-12-11 04:55 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-12-11 04:55 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-12-11 04:55 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2014-12-11 04:55 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-12-11 04:55 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-12-11 04:55 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-12-11 04:55 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-12-11 04:55 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-12-11 04:55 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-12-11 04:55 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-12-11 04:55 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-12-11 04:55 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-12-11 04:55 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-12-11 04:55 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-12-11 04:55 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-12-11 04:55 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-12-11 04:55 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-12-11 04:55 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-12-11 04:55 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-12-11 04:55 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-12-11 04:55 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2014-12-11 04:55 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-12-11 04:55 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-12-11 04:55 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-12-11 04:55 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-12-11 04:55 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-12-11 04:55 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-12-11 04:55 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-12-11 04:55 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2014-12-11 04:55 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-12-11 04:55 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-12-11 04:55 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-12-11 04:55 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-12-11 04:55 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-12-11 04:55 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-12-11 04:55 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-12-11 04:55 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-12-11 04:55 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-12-11 04:55 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-12-11 04:55 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-12-11 04:55 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2014-12-11 04:55 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-12-11 04:55 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-12-11 04:55 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-12-11 04:55 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-12-11 04:55 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-12-11 04:55 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-12-11 04:55 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-12-11 04:55 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-12-11 04:55 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2014-12-11 04:54 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-12-11 04:54 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-12-11 04:54 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe 2014-12-11 04:54 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe 2014-12-11 04:54 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2014-12-11 04:54 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2014-12-11 04:54 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2014-12-11 04:54 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2014-12-11 04:54 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2014-12-11 04:54 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2014-12-11 04:54 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll 2014-12-11 04:54 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2014-12-11 04:54 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll 2014-12-11 04:54 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe 2014-12-11 00:26 - 2014-12-11 00:26 - 01413208 _____ () C:\Windows\Minidump\121114-20248-01.dmp ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-05 09:42 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-05 09:42 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-05 09:40 - 2014-11-08 16:15 - 00697256 _____ () C:\Windows\system32\perfh007.dat 2015-01-05 09:40 - 2014-11-08 16:15 - 00149224 _____ () C:\Windows\system32\perfc007.dat 2015-01-05 09:40 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-05 09:38 - 2014-11-08 14:39 - 01842146 _____ () C:\Windows\WindowsUpdate.log 2015-01-05 09:34 - 2014-11-08 14:52 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-01-05 09:34 - 2010-11-21 04:47 - 00047230 _____ () C:\Windows\PFRO.log 2015-01-05 09:34 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-05 09:34 - 2009-07-14 05:51 - 00043525 _____ () C:\Windows\setupact.log 2015-01-05 09:23 - 2014-11-08 14:42 - 00000993 _____ () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-01-04 19:21 - 2014-11-08 15:29 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies 2015-01-03 12:13 - 2014-12-04 12:53 - 00000000 ____D () C:\Users\Reisser\Downloads\Musik 2015-01-03 12:10 - 2014-12-04 12:52 - 00000000 ____D () C:\Users\Reisser\Downloads\Kinder Filme 2014-12-31 18:29 - 2014-11-10 17:53 - 00000000 ____D () C:\Users\Reisser\Downloads\Filme 2014-12-31 18:14 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-12-31 18:09 - 2014-11-08 14:44 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-12-29 14:40 - 2014-11-27 19:28 - 00000000 ____D () C:\Users\Reisser\Desktop\Wallpapers 2014-12-28 21:45 - 2014-11-08 14:42 - 00000000 ____D () C:\Users\Reisser 2014-12-27 11:40 - 2014-12-05 12:01 - 00012288 _____ () C:\Users\Reisser\Desktop\Stundenzettelfür Feru - Dezember14 -.xls 2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Users\Reisser\AppData\Local\Google 2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Program Files (x86)\Google 2014-12-25 12:22 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-12-17 17:42 - 2014-11-08 14:42 - 00000000 ____D () C:\Users\Reisser\AppData\Local\VirtualStore 2014-12-13 15:32 - 2014-12-04 13:29 - 00000062 _____ () C:\Users\Reisser\Desktop\Neues Textdokument.txt 2014-12-12 05:23 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2014-12-12 03:19 - 2014-11-08 19:04 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat 2014-12-12 03:04 - 2014-11-08 19:30 - 00000000 ____D () C:\Windows\system32\MRT 2014-12-12 03:02 - 2014-11-08 19:30 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-12-11 00:29 - 2014-11-16 15:02 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2014-12-11 00:26 - 2014-11-28 13:23 - 564424988 _____ () C:\Windows\MEMORY.DMP 2014-12-11 00:26 - 2014-11-28 13:23 - 00000000 ____D () C:\Windows\Minidump Some content of TEMP: ==================== C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.dll C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.exe C:\Users\Reisser\AppData\Local\Temp\ED0B3C23-8BE8-3EB3-1490-A4C4FFFA8DA2.exe C:\Users\Reisser\AppData\Local\Temp\nse838F.exe C:\Users\Reisser\AppData\Local\Temp\Quarantine.exe C:\Users\Reisser\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-04 14:49 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- --- --- --- FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-01-2015 Ran by Reisser at 2015-01-05 09:46:06 Running from C:\Users\Reisser\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Disabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1} AS: Microsoft Security Essentials (Disabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Abenteuer Pferderücken Demo (HKLM-x32\...\Abenteuer Pferderücken Demo) (Version: - ) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Ashampoo Burning Studio FREE v.1.14.5 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG) Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.12.0 - Asmedia Technology) Belkin F7D1101 Basic Wireless USB Adapter (HKLM-x32\...\InstallShield_{AFD89880-C544-4777-B645-FBF6D3391B11}) (Version: 1.0.0.4 - Belkin) Belkin F7D1101 Basic Wireless USB Adapter (x32 Version: 1.0.0.4 - Belkin) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden K-Lite Codec Pack 10.8.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.8.0 - ) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) mkv2vob (HKLM-x32\...\{21AE04E8-EBF6-40DB-9AA9-B7A80C5D057D}) (Version: 2.4.9 - 3r1c) NVIDIA 3D Vision Controller Driver 344.46 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 344.46 - NVIDIA Corporation) NVIDIA 3D Vision Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 344.60 - NVIDIA Corporation) NVIDIA GeForce Experience 2.1.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.3 - NVIDIA Corporation) NVIDIA Graphics Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.60 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.32.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation) NVIDIA PhysX System Software 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation) OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) paint.net (HKLM\...\{F509C1F4-0029-49F9-B145-A4C4E8DF481A}) (Version: 4.0.3 - dotPDN LLC) QuickTime (HKLM-x32\...\{08094E03-AFE4-4853-9D31-6D0743DF5328}) (Version: 7.1.6.200 - Apple Computer, Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.) SecurityUtility (HKLM-x32\...\SecurityUtility) (Version: 1.0.0.992 - ) SHIELD Streaming (Version: 3.1.1000 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 16.13.56 - NVIDIA Corporation) Hidden SIW Pro Edition (Trial Version) (HKLM-x32\...\{3B9704C8-1286-4a17-9EA8-F63004FC74A1}_is1) (Version: 2014.10.16 - Topala Software Solutions) VTech Download Agent Library (x32 Version: 1.00.0000 - VTech) Hidden VTech Download Manager (HKLM-x32\...\VTechDownloadManager) (Version: - VTech) WinRAR 5.10 Beta 4 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 31-12-2014 18:09:18 Installiert Belkin F7D1101 Basic Wireless USB Adapter 31-12-2014 18:24:58 Windows Update 04-01-2015 15:00:32 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2014-12-29 08:16 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {07C4EDDE-20D1-4BFF-8659-B50E309D06FA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.) Task: {850FC5E5-AE51-4C51-95E1-FF3768705CCA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.) Task: {8B1C00F0-602F-40B2-9557-43584EC56145} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2014-10-06] () Task: {C2A4DBCF-85DB-4AF7-9667-235505B79D5D} - System32\Tasks\PESM => C:\Users\Reisser\AppData\Roaming\PESM.exe [2015-01-04] (home) <==== ATTENTION Task: {F1E05127-80E4-400F-8C60-436999246896} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\PESM.job => C:\Users\Reisser\AppData\Roaming\PESM.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2014-11-08 14:51 - 2014-10-30 03:10 - 00117064 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2014-10-13 02:49 - 2014-06-20 07:42 - 00401280 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe 2014-10-13 02:49 - 2014-03-04 12:20 - 00117760 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QtSolutions_SOAP-2.7.dll 2014-10-13 02:49 - 2014-04-22 03:14 - 00065536 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QHttpServer.dll 2014-10-13 02:49 - 2014-05-06 06:39 - 00861184 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\platforms\qwindows.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00021504 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qgif.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00020992 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qico.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00204800 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qjpeg.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00218112 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qmng.dll 2014-10-13 02:49 - 2014-05-06 06:58 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qsvg.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00015360 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtga.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00307712 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtiff.dll 2014-10-13 02:49 - 2014-05-06 11:44 - 00014848 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qwbmp.dll 2014-10-13 02:49 - 2014-05-06 07:31 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\sensors\qtsensors_dummy.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00036352 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qgenericbearer.dll 2014-10-13 02:49 - 2014-05-06 06:38 - 00038912 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qnativewifibearer.dll 2014-12-29 08:25 - 2014-12-06 02:50 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libglesv2.dll 2014-12-29 08:25 - 2014-12-06 02:50 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libegl.dll 2014-12-29 08:25 - 2014-12-06 02:50 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dll 2014-12-29 08:25 - 2014-12-06 02:50 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ffmpegsumo.dll 2014-12-29 08:25 - 2014-12-06 02:50 - 14913352 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\abengine => ""="service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ColorMedia => ""="service" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-1744345613-2801571155-2633355246-500 - Administrator - Disabled) Guest (S-1-5-21-1744345613-2801571155-2633355246-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1744345613-2801571155-2633355246-1002 - Limited - Enabled) Reisser (S-1-5-21-1744345613-2801571155-2633355246-1000 - Administrator - Enabled) => C:\Users\Reisser ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: AMD FX(tm)-6100 Six-Core Processor Percentage of memory in use: 35% Total physical RAM: 8171.53 MB Available physical RAM: 5273.06 MB Total Pagefile: 16641.24 MB Available Pagefile: 13501.4 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:172.79 GB) (Free:103.26 GB) NTFS Drive d: () (Fixed) (Total:292.97 GB) (Free:54.41 GB) NTFS Drive e: (Filme 2 St) (Fixed) (Total:465.61 GB) (Free:136.17 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: FFB8F33B) Partition 1: (Not Active) - (Size=172.8 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=293 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 3280EB00) Partition 1: (Active) - (Size=126 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.6 GB) - (Type=07 NTFS) ==================== End Of Log ============================ #~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.1 (12.28.2014:1) OS: Windows 7 Ultimate x64 Ran by Reisser on 05.01.2015 at 9:36:32,08 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files Successfully deleted: [File] "C:\Users\Reisser\appdata\local\google\chrome\user data\default\local storage\http_www.trovi.com_0.localstorage" Successfully deleted: [File] "C:\Users\Reisser\appdata\local\google\chrome\user data\default\local storage\http_www.trovi.com_0.localstorage-journal" ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 05.01.2015 at 9:38:49,77 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
05.01.2015, 10:09 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Lässtige werbung trotz addblock Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:51111;https=127.0.0.1:51111 SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = FF HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Firefox\Extensions: [{75229658-C485-8921-6792-5A8E5A8C26B4}] - C:\Program Files (x86)\ver3BetterMarkIt\185.xpi CHR DefaultSuggestURL: Default -> http://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms} Task: {C2A4DBCF-85DB-4AF7-9667-235505B79D5D} - System32\Tasks\PESM => C:\Users\Reisser\AppData\Roaming\PESM.exe [2015-01-04] (home) <==== ATTENTION Task: C:\Windows\Tasks\PESM.job => C:\Users\Reisser\AppData\Roaming\PESM.exe <==== ATTENTION C:\Windows\Tasks\PESM.job C:\Windows\System32\Tasks\PESM C:\Program Files (x86)\c37590b6-b104-45a2-80cb-69d810a404ed C:\Users\Reisser\AppData\Roaming\PESM.exe C:\Windows\{4626E3EA-85B3-464E-B296-F3F5488D8B08} C:\ProgramData\1078601655 C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.dll C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.exe C:\Users\Reisser\AppData\Local\Temp\ED0B3C23-8BE8-3EB3-1490-A4C4FFFA8DA2.exe C:\Users\Reisser\AppData\Local\Temp\nse838F.exe C:\Program Files (x86)\ver3BetterMarkIt EmptyTemp: Hosts: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ Logfiles bitte immer in CODE-Tags posten |
05.01.2015, 13:24 | #13 |
| Lässtige werbung trotz addblock Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-01-2015 Ran by Reisser at 2015-01-05 13:14:57 Run:2 Running from C:\Users\Reisser\Desktop Loaded Profile: Reisser (Available profiles: Reisser) Boot Mode: Normal ============================================== Content of fixlist: ***************** ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyServer: [.DEFAULT] => http=127.0.0.1:51111;https=127.0.0.1:51111 SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = FF HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Firefox\Extensions: [{75229658-C485-8921-6792-5A8E5A8C26B4}] - C:\Program Files (x86)\ver3BetterMarkIt\185.xpi CHR DefaultSuggestURL: Default -> hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms} Task: {C2A4DBCF-85DB-4AF7-9667-235505B79D5D} - System32\Tasks\PESM => C:\Users\Reisser\AppData\Roaming\PESM.exe [2015-01-04] (home) <==== ATTENTION Task: C:\Windows\Tasks\PESM.job => C:\Users\Reisser\AppData\Roaming\PESM.exe <==== ATTENTION C:\Windows\Tasks\PESM.job C:\Windows\System32\Tasks\PESM C:\Program Files (x86)\c37590b6-b104-45a2-80cb-69d810a404ed C:\Users\Reisser\AppData\Roaming\PESM.exe C:\Windows\{4626E3EA-85B3-464E-B296-F3F5488D8B08} C:\ProgramData\1078601655 C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.dll C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.exe C:\Users\Reisser\AppData\Local\Temp\ED0B3C23-8BE8-3EB3-1490-A4C4FFFA8DA2.exe C:\Users\Reisser\AppData\Local\Temp\nse838F.exe C:\Program Files (x86)\ver3BetterMarkIt EmptyTemp: Hosts: ***************** HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully. HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Mozilla\Firefox\Extensions\\{75229658-C485-8921-6792-5A8E5A8C26B4} => value deleted successfully. Chrome DefaultSuggestURL deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C2A4DBCF-85DB-4AF7-9667-235505B79D5D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2A4DBCF-85DB-4AF7-9667-235505B79D5D}" => Key deleted successfully. C:\Windows\System32\Tasks\PESM => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PESM" => Key deleted successfully. C:\Windows\Tasks\PESM.job => Moved successfully. "C:\Windows\Tasks\PESM.job" => File/Directory not found. "C:\Windows\System32\Tasks\PESM" => File/Directory not found. C:\Program Files (x86)\c37590b6-b104-45a2-80cb-69d810a404ed => Moved successfully. C:\Users\Reisser\AppData\Roaming\PESM.exe => Moved successfully. C:\Windows\{4626E3EA-85B3-464E-B296-F3F5488D8B08} => Moved successfully. C:\ProgramData\1078601655 => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.dll => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.exe => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\ED0B3C23-8BE8-3EB3-1490-A4C4FFFA8DA2.exe => Moved successfully. C:\Users\Reisser\AppData\Local\Temp\nse838F.exe => Moved successfully. "C:\Program Files (x86)\ver3BetterMarkIt" => File/Directory not found. C:\Windows\System32\Drivers\etc\hosts => Moved successfully. Hosts was reset successfully. EmptyTemp: => Removed 545.4 MB temporary data. The system needed a reboot. ==== End of Fixlog 13:15:06 ==== |
05.01.2015, 13:26 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Lässtige werbung trotz addblock Okay, dann Kontrollscans mit MBAM und ESET bitte: Downloade Dir bitte Malwarebytes Anti-Malware
ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
05.01.2015, 15:12 | #15 |
| Lässtige werbung trotz addblock Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 05.01.2015 Suchlauf-Zeit: 13:52:38 Logdatei: mbam.txt Administrator: Ja Version: 2.00.4.1028 Malware Datenbank: v2015.01.05.05 Rootkit Datenbank: v2014.12.30.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Reisser Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 315176 Verstrichene Zeit: 7 Min, 28 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente erkannt) Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 9 PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, In Quarantäne, [696014dfa4e559ddc860835f788c56aa], PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, In Quarantäne, [92374fa48ffa092d4ed9f0f22ed6f50b], PUP.Optional.CinemaHDPro.A, HKLM\SOFTWARE\WOW6432NODE\CinemaHd For Pro 2.4cV27.12-nv, In Quarantäne, [dfea777c92f73ef89a9467ff966d7e82], PUP.Optional.HDVid.A, HKLM\SOFTWARE\WOW6432NODE\TheHDvid-Codec V10-nv, In Quarantäne, [dbee747fdfaae5512be530500cf73ec2], PUP.Optional.HDVid.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\TheHDvid-Codec V10-nv, In Quarantäne, [efda91620d7c82b4f9181f61ed16f907], PUP.Optional.CrossRider.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQPro-Video 1.6V26.12, In Quarantäne, [ffca26cd395054e2c0eb87e517ec8878], PUP.Optional.HDVid.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\TheHDvid-Codec V10, In Quarantäne, [4980f7fc9bee8ea8070b1769f3107e82], PUP.Optional.CinemaHDPro.A, HKU\S-1-5-21-1744345613-2801571155-2633355246-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CinemaHd For Pro 2.4cV27.12-nv, In Quarantäne, [9d2c965d3752e15575baa1c520e3cf31], PUP.Optional.HDVid.A, HKU\S-1-5-21-1744345613-2801571155-2633355246-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\TheHDvid-Codec V10-nv, In Quarantäne, [785137bcd4b5b97d60b1453bde25827e], Registrierungswerte: 0 (Keine schädliche Elemente erkannt) Registrierungsdaten: 0 (Keine schädliche Elemente erkannt) Ordner: 0 (Keine schädliche Elemente erkannt) Dateien: 13 PUP.Optional.Nova.A, C:\Program Files (x86)\AGEIA Technologies\382b2585-51fa-44d5-80fa-5d6425b8899f.dll, In Quarantäne, [4782b0436722191d479638c8b34f6c94], PUP.Optional.Nova.A, C:\Program Files (x86)\AGEIA Technologies\9c1d7823-4df5-447b-9440-3f94dbcc7595.dll, In Quarantäne, [7b4e886b5633b77fc41920e01ce6ce32], PUP.Optional.SearchProtect.A, C:\Windows\AppPatch\AppPatch64\VCLdr64.dll, In Quarantäne, [80492ac9800979bd033fe5c852af827e], PUP.Optional.SearchProtect.A, C:\Windows\AppPatch\nbin\VC32Loader.dll, In Quarantäne, [2d9c6d86444588aee35f139a9a679868], PUP.Optional.WebInstrNew.A, C:\Windows\System32\drivers\Msft_Kernel_webinstrNewH_01009.Wdf, In Quarantäne, [3e8b995a7c0d6bcb45d65f05010201ff], PUP.Optional.Trovi.A, C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.trovi.com_0.localstorage, Löschen bei Neustart, [8f3aca29e5a463d348e4820d19ea6898], PUP.Optional.Trovi.A, C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.trovi.com_0.localstorage-journal, Löschen bei Neustart, [2b9e24cff198e45248e4830c06fd04fc], PUP.Optional.SearchProtect, C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, In Quarantäne, [19b0f2015c2dc37353d8538fc44023dd], PUP.Optional.ReMarkable.A, C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage, Löschen bei Neustart, [1faa23d02a5f2c0ad63bfae9e024ee12], PUP.Optional.ReMarkable.A, C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal, Löschen bei Neustart, [8643d122810880b6ba5712d158ac52ae], PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMedia.ini, In Quarantäne, [1dac9f54f792e0561568816218ec9d63], PUP.Optional.ColorMedia.A, C:\Windows\System32\ColorMediaOff.ini, In Quarantäne, [2a9f22d1addc3600d1ad25bed43037c9], PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMediaOff.ini, In Quarantäne, [a623f5fed6b30e28c6b85c87c0447f81], Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) Geändert von reisser (05.01.2015 um 15:19 Uhr) |
Themen zu Lässtige werbung trotz addblock |
64 bit, andauernd, bobrowser, chrome, dauernd, entfernen, gestern, google, google chrome, hilfe, installmanager.exe, lässtige, securityutility, stört, trotz, virus, werbung, win, win 7, win 7 64 bit, zusammen |