Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Adware Roll around eingefangen

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 09.04.2015, 23:05   #76
Bayer76
 

Adware Roll around eingefangen - Standard

Adware Roll around eingefangen



Due meinst Die Google Chrome Secure Preferences? Ja wurden neu angelegt:
Code:
ATTFilter
{
   "browser": {
      "show_home_button": false
   },
   "extensions": {
      "settings": {
         "ahfgeienlihckogmohjhadlkjgocpleb": {
            "active_permissions": {
               "api": [ "management", "system.display", "system.storage", "webstorePrivate", "system.cpu", "system.memory", "system.network" ],
               "manifest_permissions": [  ]
            },
            "app_launcher_ordinal": "t",
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 1,
            "events": [  ],
            "from_bookmark": false,
            "from_webstore": false,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "install_time": "13072961118896037",
            "location": 5,
            "manifest": {
               "app": {
                  "launch": {
                     "web_url": "https://chrome.google.com/webstore"
                  },
                  "urls": [ "https://chrome.google.com/webstore" ]
               },
               "description": "Entdecken Sie tolle Apps, Spiele, Erweiterungen und Designs für Google Chrome.",
               "icons": {
                  "128": "webstore_icon_128.png",
                  "16": "webstore_icon_16.png"
               },
               "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB",
               "name": "Web Store",
               "permissions": [ "webstorePrivate", "management", "system.cpu", "system.display", "system.memory", "system.network", "system.storage" ],
               "version": "0.2"
            },
            "page_ordinal": "n",
            "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\web_store",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "bepbmhgboaologfdajaanbcjmnhjmhfn": {
            "disable_reasons": 1,
            "state": 0
         },
         "cfhdojbkjhnklbpkdaibdccddilifddb": {
            "active_permissions": {
               "api": [ "contextMenus", "notifications", "tabs", "unlimitedStorage", "webNavigation", "webRequest", "webRequestBlocking" ],
               "explicit_host": [ "hxxp://*/*", "https://*/*" ],
               "manifest_permissions": [  ],
               "scriptable_host": [ "hxxp://*/*", "https://*/*" ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 9,
            "events": [  ],
            "from_bookmark": false,
            "from_webstore": true,
            "granted_permissions": {
               "api": [ "contextMenus", "notifications", "tabs", "unlimitedStorage", "webNavigation", "webRequest", "webRequestBlocking" ],
               "explicit_host": [ "hxxp://*/*", "https://*/*" ],
               "manifest_permissions": [  ],
               "scriptable_host": [ "hxxp://*/*", "https://*/*" ]
            },
            "incognito": true,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "initial_keybindings_set": true,
            "install_time": "13072961236384365",
            "lastpingday": "13073036401510834",
            "location": 1,
            "manifest": {
               "background": {
                  "scripts": [ "ext/common.js", "ext/background.js", "lib/compat.js", "lib/info.js", "lib/io.js", "lib/adblockplus.js", "lib/punycode.js", "lib/publicSuffixList.js", "lib/sha1.js", "lib/jsbn.js", "lib/rsa.js", "webrequest.js", "messageResponder.js", "popupBlocker.js", "background.js" ]
               },
               "browser_action": {
                  "default_icon": {
                     "19": "icons/abp-19.png",
                     "38": "icons/abp-38.png"
                  },
                  "default_popup": "popup.html",
                  "default_title": "Adblock Plus"
               },
               "content_scripts": [ {
                  "all_frames": true,
                  "js": [ "ext/common.js", "ext/content.js", "include.preload.js" ],
                  "matches": [ "hxxp://*/*", "https://*/*" ],
                  "run_at": "document_start"
               }, {
                  "all_frames": true,
                  "js": [ "include.postload.js" ],
                  "matches": [ "hxxp://*/*", "https://*/*" ],
                  "run_at": "document_end"
               } ],
               "current_locale": "de",
               "default_locale": "en_US",
               "description": "Ein kostenloser Werbeblocker mit über 50 Mio Nutzern, der ALLE nervenden Werbeanzeigen, Malware- und Tracking-Angriffe blockiert.",
               "icons": {
                  "128": "icons/detailed/abp-128.png",
                  "16": "icons/abp-16.png",
                  "32": "icons/abp-32.png",
                  "48": "icons/detailed/abp-48.png",
                  "64": "icons/detailed/abp-64.png"
               },
               "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCxGWIIBRUVzQIXITqE6+js1FA24fsZC58G0fxcO1Duwfps+9gip5tedTziErKEpeAQVkgasdT4kk+b6Lw27yp3oysAj6zD9j+j4W+EMArTXqMIc6SMYD7Z8bPcwPb3tC1MUxMSpO6oOVpFE23UhKe91SYnrK92nHI2cmsor5elXQIDAQAB",
               "manifest_version": 2,
               "minimum_chrome_version": "28.0",
               "name": "Adblock Plus",
               "options_page": "options.html",
               "permissions": [ "tabs", "hxxp://*/*", "https://*/*", "contextMenus", "webRequest", "webRequestBlocking", "webNavigation", "unlimitedStorage", "notifications" ],
               "short_name": "Adblock Plus",
               "update_url": "https://clients2.google.com/service/update2/crx",
               "version": "1.8.12",
               "web_accessible_resources": [ "block.html" ]
            },
            "path": "cfhdojbkjhnklbpkdaibdccddilifddb\\1.8.12_0",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "eemcgdkfndhakfknompkggombfjjjeno": {
            "active_permissions": {
               "api": [ "bookmarks", "bookmarkManagerPrivate", "metricsPrivate", "systemPrivate", "tabs" ],
               "explicit_host": [ "chrome://favicon/*", "chrome://resources/*" ],
               "manifest_permissions": [  ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 1,
            "events": [  ],
            "from_bookmark": false,
            "from_webstore": false,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "initial_keybindings_set": true,
            "install_time": "13072961118894704",
            "location": 5,
            "manifest": {
               "chrome_url_overrides": {
                  "bookmarks": "main.html"
               },
               "content_security_policy": "object-src 'none'; script-src chrome://resources 'self'",
               "description": "Bookmark Manager",
               "icons": {

               },
               "incognito": "split",
               "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQcByy+eN9jzazWF/DPn7NW47sW7lgmpk6eKc0BQM18q8hvEM3zNm2n7HkJv/R6fU+X5mtqkDuKvq5skF6qqUF4oEyaleWDFhd1xFwV7JV+/DU7bZ00w2+6gzqsabkerFpoP33ZRIw7OviJenP0c0uWqDWF8EGSyMhB3txqhOtiQIDAQAB",
               "manifest_version": 2,
               "name": "Bookmark Manager",
               "permissions": [ "bookmarks", "bookmarkManagerPrivate", "metricsPrivate", "systemPrivate", "tabs", "chrome://favicon/", "chrome://resources/" ],
               "version": "0.1"
            },
            "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\bookmark_manager",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "ennkphjdgehloodpbhlhldgbnhmacadg": {
            "active_permissions": {
               "api": [  ],
               "explicit_host": [ "chrome://settings-frame/*" ],
               "manifest_permissions": [  ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 1,
            "events": [ "app.runtime.onLaunched" ],
            "from_bookmark": false,
            "from_webstore": false,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "initial_keybindings_set": true,
            "install_time": "13072961118900031",
            "location": 5,
            "manifest": {
               "app": {
                  "background": {
                     "scripts": [ "settings_app.js" ]
                  }
               },
               "description": "Settings",
               "display_in_launcher": false,
               "icons": {
                  "128": "settings_app_icon_128.png",
                  "16": "settings_app_icon_16.png",
                  "32": "settings_app_icon_32.png",
                  "48": "settings_app_icon_48.png"
               },
               "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDoVDPGX6fvKPVVgc+gnkYlGqHuuapgFDyKhsy4z7UzRLO/95zXPv8h8e5EacqbAQJLUbP6DERH5jowyNEYVxq9GJyntJMwP1ejvoz/52hnY3CCGGCmttmKzzpp5zwLuq3iZf8bslwywfflNUYtaCFSDa0TtrBZz0aOPrAAd/AhNwIDAQAB",
               "manifest_version": 2,
               "name": "Settings",
               "permissions": [ "chrome://settings-frame/" ],
               "version": "0.2"
            },
            "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\settings_app",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "running": false,
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "gfdkimpbcpahaombhbimeihdjnejgicl": {
            "active_permissions": {
               "api": [ "feedbackPrivate" ],
               "explicit_host": [ "chrome://resources/*" ],
               "manifest_permissions": [  ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 1,
            "events": [ "feedbackPrivate.onFeedbackRequested", "runtime.onMessageExternal" ],
            "from_bookmark": false,
            "from_webstore": false,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "initial_keybindings_set": true,
            "install_time": "13072961118899222",
            "location": 5,
            "manifest": {
               "app": {
                  "background": {
                     "scripts": [ "js/event_handler.js" ]
                  },
                  "content_security_policy": "default-src 'none'; script-src 'self' chrome://resources; style-src 'unsafe-inline' *; img-src *; media-src 'self'"
               },
               "description": "User feedback extension",
               "display_in_launcher": false,
               "display_in_new_tab_page": false,
               "icons": {
                  "32": "images/icon32.png",
                  "64": "images/icon64.png"
               },
               "incognito": "split",
               "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMZElzFX2J1g1nRQ/8S3rg/1CjFyDltWOxQg+9M8aVgNVxbutEWFQz+oQzIP9BB67mJifULgiv12ToFKsae4NpEUR8sPZjiKDIHumc6pUdixOm8SJ5Rs16SMR6+VYxFUjlVW+5CA3IILptmNBxgpfyqoK0qRpBDIhGk1KDEZ4zqQIDAQAB",
               "manifest_version": 2,
               "name": "Feedback",
               "permissions": [ "feedbackPrivate", "chrome://resources/" ],
               "version": "1.0"
            },
            "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\feedback",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "running": false,
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "gomekmidlodglbbmalcneegieacbdmki": {
            "ack_external": true,
            "active_permissions": {
               "api": [ "cookies", "tabs", "webNavigation", "webRequest", "webRequestBlocking" ],
               "explicit_host": [ "*://*.avast.com/*", "hxxp://*/*", "https://*/*" ],
               "manifest_permissions": [  ],
               "scriptable_host": [ "*://*.avast.com/*" ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 9,
            "events": [  ],
            "from_bookmark": false,
            "from_webstore": true,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "initial_keybindings_set": true,
            "install_time": "13072961128473041",
            "install_warning_on_enable": false,
            "lastpingday": "13073036401510834",
            "location": 6,
            "manifest": {
               "author": "Avast",
               "background": {
                  "scripts": [ "common/libs/q.js", "common/libs/eventemitter2.js", "common/libs/protobuf.js", "common/libs/lodash.js", "scripts/abek.bl.crx.js", "common/scripts/gpb.js", "common/scripts/query.js", "common/scripts/avastwrc.js", "common/scripts/bal.js", "scripts/aos.bl.js", "scripts/bs.crx.js", "scripts/bs.aos.crx.js" ]
               },
               "browser_action": {
                  "default_icon": "common/ui/icons/status-none.png",
                  "default_popup": "common/ui/aos.panel.html",
                  "default_title": "Avast Online Security"
               },
               "content_scripts": [ {
                  "js": [ "common/scripts/ava_connector.js" ],
                  "matches": [ "*://*.avast.com/*" ]
               } ],
               "content_security_policy": "script-src 'self' https://ssl.google-analytics.com; object-src 'self'",
               "current_locale": "de",
               "default_locale": "en",
               "description": "Avast Browser Security and Web Reputation Plugin.",
               "icons": {
                  "128": "common/skin/img/icon128.png",
                  "16": "common/skin/img/icon16.png",
                  "256": "common/skin/img/icon256.png",
                  "32": "common/skin/img/icon32.png",
                  "48": "common/skin/img/icon48.png",
                  "64": "common/skin/img/icon64.png"
               },
               "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDWStseB5KE8Vqukt6RkFc3NirSBRmBTKvNolNhsOo5Q/kUlJs1pajaMckUR5rJXlpzvxfvesfNlASR/QnHKdlGBxPlyi5dxN+nohCclJYf5dXVq2ndj2ykgd++rs1qD35tw3R2v5BaeTmLgP2G/Jd53BaJXDNTGIusbkGEhvZ2rQIDAQAB",
               "manifest_version": 2,
               "name": "Avast Online Security",
               "options_page": "options.html",
               "permissions": [ "cookies", "*://*.avast.com/*", "hxxp://*/*", "https://*/*", "tabs", "webNavigation", "webRequest", "webRequestBlocking" ],
               "update_url": "https://clients2.google.com/service/update2/crx",
               "version": "10.2.0.190",
               "web_accessible_resources": [ "common/skin/*", "common/skin/img/*", "common/skin/css/*", "common/mocks/*", "common/ui/icons/*", "common/ui/bgs/*" ]
            },
            "path": "gomekmidlodglbbmalcneegieacbdmki\\10.2.0.190_0",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "kmendfapggjehodndflmmgagdbamhnfd": {
            "active_permissions": {
               "api": [ "cryptotokenPrivate", "externally_connectable.all_urls", "hid", "tabs", "u2fDevices", "usb", {
                  "usbDevices": [ {
                     "interfaceId": -1,
                     "productId": 529,
                     "vendorId": 4176
                  } ]
               }, "webConnectable" ],
               "explicit_host": [ "hxxp://*/*", "https://*/*" ],
               "manifest_permissions": [  ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 1,
            "events": [ "runtime.onConnectExternal", "runtime.onMessageExternal" ],
            "from_bookmark": false,
            "from_webstore": false,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "initial_keybindings_set": true,
            "install_time": "13072961118902555",
            "location": 5,
            "manifest": {
               "background": {
                  "persistent": false,
                  "scripts": [ "util.js", "b64.js", "sha256.js", "countdown.js", "countdowntimer.js", "devicestatuscodes.js", "approvedorigins.js", "errorcodes.js", "gnubbycodetypes.js", "webrequest.js", "gnubbymsgtypes.js", "messagetypes.js", "factoryregistry.js", "closeable.js", "requesthelper.js", "webrequestsender.js", "enroller.js", "requestqueue.js", "signer.js", "origincheck.js", "textfetcher.js", "appid.js", "watchdog.js", "etld_names_list.js", "etld.js", "etldorigincheck.js", "cryptotokenapprovedorigins.js", "gnubbydevice.js", "hidgnubbydevice.js", "usbgnubbydevice.js", "gnubbies.js", "gnubby.js", "gnubby-u2f.js", "gnubbyfactory.js", "singlesigner.js", "multiplesigner.js", "generichelper.js", "inherits.js", "individualattest.js", "devicefactoryregistry.js", "usbhelper.js", "usbenrollhandler.js", "usbsignhandler.js", "usbgnubbyfactory.js", "googlecorpindividualattest.js", "cryptotokenbackground.js" ]
               },
               "description": "CryptoToken Component Extension",
               "externally_connectable": {
                  "accepts_tls_channel_id": true,
                  "ids": [ "fjajfjhkeibgmiggdfehjplbhmfkialk" ],
                  "matches": [ "\u003Call_urls>" ]
               },
               "incognito": "split",
               "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq7zRobvA+AVlvNqkHSSVhh1sEWsHSqz4oR/XptkDe/Cz3+gW9ZGumZ20NCHjaac8j1iiesdigp8B1LJsd/2WWv2Dbnto4f8GrQ5MVphKyQ9WJHwejEHN2K4vzrTcwaXqv5BSTXwxlxS/mXCmXskTfryKTLuYrcHEWK8fCHb+0gvr8b/kvsi75A1aMmb6nUnFJvETmCkOCPNX5CHTdy634Ts/x0fLhRuPlahk63rdf7agxQv5viVjQFk+tbgv6aa9kdSd11Js/RZ9yZjrFgHOBWgP4jTBqud4+HUglrzu8qynFipyNRLCZsaxhm+NItTyNgesxLdxZcwOz56KD1Q4IQIDAQAB",
               "manifest_version": 2,
               "name": "CryptoTokenExtension",
               "permissions": [ "hid", "usb", "cryptotokenPrivate", "externally_connectable.all_urls", "tabs", "u2fDevices", "https://*/*", "hxxp://*/*", {
                  "usbDevices": [ {
                     "productId": 529,
                     "vendorId": 4176
                  } ]
               } ],
               "version": "0.9.10"
            },
            "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\cryptotoken",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "lccekmodgklaepjeofjdjpbminllajkg": {
            "ack_external": true,
            "active_permissions": {
               "api": [  ],
               "manifest_permissions": [  ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 137,
            "events": [  ],
            "from_bookmark": false,
            "from_webstore": true,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "install_time": "13072961123767071",
            "lastpingday": "13073036401510834",
            "location": 10,
            "manifest": {
               "description": "Support files for Chrome Hotwording.",
               "export": {
                  "resources": [ "audio/*", "_platform_specific/*", "hotword_*.nmf" ],
                  "whitelist": [ "nbpagnldghgfoolbancepceaanlmhfmd" ]
               },
               "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAoxhwmnepSrtvEcatE9K4SxOUTy6U1LNpuaT3BNr12cuehQT5YAGeUcgeIMQmE0/h/EefU53TcjUEn9vgE8+aSZW0VirROE36hfcWpqyxf9jh0mPRluLIxCW+ObD/B5YoXj0kxTWIaDQqKYBJyo+QCRwef5hwfAoUoDggnYDRHHG4z3mfZJ4duY2H3ISEw4/tsvAm8SxCZm+W6laCV0AkJxO+s4bNNC0z0Y5+G3nw24uV8cdMnfQcFUWJncnwqDSTUp7vOZb570Wv02TD+qhpA2rlF0/ym6edXoKzapR4+SQQllDXZ0yLZ3GQ6uf7IsCufSoYPoIsmYExHrlZbgVkWwIDAQAB",
               "manifest_version": 2,
               "minimum_chrome_version": "39",
               "name": "Chrome Hotword Shared Module",
               "platforms": [ {
                  "lang": "de",
                  "nacl_arch": "arm",
                  "sub_package_path": "_platform_specific/arm_de/"
               }, {
                  "lang": "de",
                  "nacl_arch": "x86-32",
                  "sub_package_path": "_platform_specific/x86-32_de/"
               }, {
                  "lang": "de",
                  "nacl_arch": "x86-64",
                  "sub_package_path": "_platform_specific/x86-64_de/"
               }, {
                  "lang": "en-AU",
                  "nacl_arch": "arm",
                  "sub_package_path": "_platform_specific/arm_en-au/"
               }, {
                  "lang": "en-AU",
                  "nacl_arch": "x86-32",
                  "sub_package_path": "_platform_specific/x86-32_en-au/"
               }, {
                  "lang": "en-AU",
                  "nacl_arch": "x86-64",
                  "sub_package_path": "_platform_specific/x86-64_en-au/"
               }, {
                  "lang": "en-GB",
                  "nacl_arch": "arm",
                  "sub_package_path": "_platform_specific/arm_en-gb/"
               }, {
                  "lang": "en-GB",
                  "nacl_arch": "x86-32",
                  "sub_package_path": "_platform_specific/x86-32_en-gb/"
               }, {
                  "lang": "en-GB",
                  "nacl_arch": "x86-64",
                  "sub_package_path": "_platform_specific/x86-64_en-gb/"
               }, {
                  "lang": "es",
                  "nacl_arch": "arm",
                  "sub_package_path": "_platform_specific/arm_es/"
               }, {
                  "lang": "es",
                  "nacl_arch": "x86-32",
                  "sub_package_path": "_platform_specific/x86-32_es/"
               }, {
                  "lang": "es",
                  "nacl_arch": "x86-64",
                  "sub_package_path": "_platform_specific/x86-64_es/"
               }, {
                  "lang": "fr",
                  "nacl_arch": "arm",
                  "sub_package_path": "_platform_specific/arm_fr/"
               }, {
                  "lang": "fr",
                  "nacl_arch": "x86-32",
                  "sub_package_path": "_platform_specific/x86-32_fr/"
               }, {
                  "lang": "fr",
                  "nacl_arch": "x86-64",
                  "sub_package_path": "_platform_specific/x86-64_fr/"
               }, {
                  "lang": "it",
                  "nacl_arch": "arm",
                  "sub_package_path": "_platform_specific/arm_it/"
               }, {
                  "lang": "it",
                  "nacl_arch": "x86-32",
                  "sub_package_path": "_platform_specific/x86-32_it/"
               }, {
                  "lang": "it",
                  "nacl_arch": "x86-64",
                  "sub_package_path": "_platform_specific/x86-64_it/"
               }, {
                  "lang": "ja",
                  "nacl_arch": "arm",
                  "sub_package_path": "_platform_specific/arm_ja/"
               }, {
                  "lang": "ja",
                  "nacl_arch": "x86-32",
                  "sub_package_path": "_platform_specific/x86-32_ja/"
               }, {
                  "lang": "ja",
                  "nacl_arch": "x86-64",
                  "sub_package_path": "_platform_specific/x86-64_ja/"
               }, {
                  "lang": "ko",
                  "nacl_arch": "arm",
                  "sub_package_path": "_platform_specific/arm_ko/"
               }, {
                  "lang": "ko",
                  "nacl_arch": "x86-32",
                  "sub_package_path": "_platform_specific/x86-32_ko/"
               }, {
                  "lang": "ko",
                  "nacl_arch": "x86-64",
                  "sub_package_path": "_platform_specific/x86-64_ko/"
               }, {
                  "lang": "pt-BR",
                  "nacl_arch": "arm",
                  "sub_package_path": "_platform_specific/arm_pt-br/"
               }, {
                  "lang": "pt-BR",
                  "nacl_arch": "x86-32",
                  "sub_package_path": "_platform_specific/x86-32_pt-br/"
               }, {
                  "lang": "pt-BR",
                  "nacl_arch": "x86-64",
                  "sub_package_path": "_platform_specific/x86-64_pt-br/"
               }, {
                  "lang": "ru",
                  "nacl_arch": "arm",
                  "sub_package_path": "_platform_specific/arm_ru/"
               }, {
                  "lang": "ru",
                  "nacl_arch": "x86-32",
                  "sub_package_path": "_platform_specific/x86-32_ru/"
               }, {
                  "lang": "ru",
                  "nacl_arch": "x86-64",
                  "sub_package_path": "_platform_specific/x86-64_ru/"
               }, {
                  "nacl_arch": "arm",
                  "sub_package_path": "_platform_specific/arm_/"
               }, {
                  "nacl_arch": "x86-32",
                  "sub_package_path": "_platform_specific/x86-32_/"
               }, {
                  "nacl_arch": "x86-64",
                  "sub_package_path": "_platform_specific/x86-64_/"
               } ],
               "update_url": "https://clients2.google.com/service/update2/crx",
               "version": "0.3.0.2"
            },
            "path": "lccekmodgklaepjeofjdjpbminllajkg\\0.3.0.2_0",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 1,
            "was_installed_by_default": true,
            "was_installed_by_oem": false
         },
         "lifbcibllhkdhoafpjfnlhfpfgnpldfl": {
            "ack_prompt_count": 1,
            "active_permissions": {
               "api": [ "tabs" ],
               "explicit_host": [ "https://localhost:26143/*", "https://pnrws.skype.com/*" ],
               "manifest_permissions": [  ],
               "scriptable_host": [ "file:///*", "hxxp://*/*", "https://*/*" ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 9,
            "disable_reasons": 8192,
            "events": [  ],
            "from_bookmark": false,
            "from_webstore": true,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "initial_keybindings_set": true,
            "install_time": "13072961129771064",
            "lastpingday": "13072950002091880",
            "location": 6,
            "manifest": {
               "background": {
                  "page": "background.html"
               },
               "browser_action": {
                  "default_icon": {
                     "19": "c2c_48x48.png"
                  },
                  "default_popup": "c2c_options_menu.html",
                  "default_title": "Skype Click to Call"
               },
               "content_scripts": [ {
                  "all_frames": true,
                  "css": [ "number_highlighting.css", "number_highlighting_ui1.css", "number_highlighting_chrome.css", "number_highlighting_chrome_ui1.css" ],
                  "js": [ "jquery-2.1.0.min.js", "mutation-summary.js", "localization.js", "browserSpecificScript.js", "number_highlighting_builder.js", "pnr.js", "fpnr.js", "contentscript.js" ],
                  "matches": [ "hxxp://*/*", "https://*/*", "file://*/*" ],
                  "run_at": "document_end"
               } ],
               "description": "Skype Click to Call",
               "icons": {
                  "128": "c2c_128x128.png",
                  "16": "c2c_16x16.png",
                  "48": "c2c_48x48.png"
               },
               "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMxFysW3wPKWRPPe3xuJQz3m1ZDLX1hN8EYdP37tRPf7lp8vIhG4xirlXHGK748qcLPc4Lm8WsHDhvS5okN54Kwcnw4T2tBXSCZJxMmlu14HZ5yc/t969QLTPLIbAsasq4NVo40YuP2B7umxV9BlcxZEB9TEKPEQq8DRoKhj9jBQIDAQAB",
               "manifest_version": 2,
               "name": "Skype Click to Call",
               "permissions": [ "tabs", "https://pnrws.skype.com/", "https://localhost:26143/" ],
               "update_url": "https://clients2.google.com/service/update2/crx",
               "version": "7.3.16540.9015",
               "web_accessible_resources": [ "call_skype_logo.png", "call_skype_logo_ui1.png", "call_icon.png", "call_icon_ui1.png", "plus_icon_ui1.png", "gift_icon_ui1.png", "skype_icon_ui1.png", "skypecredit_icon_ui1.png", "learnmore_icon_ui1.png", "menu_handler.js", "telemetry.js" ]
            },
            "path": "lifbcibllhkdhoafpjfnlhfpfgnpldfl\\7.3.16540.9015_0",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 2,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "mbolhellljccdahaeelobbojpfdgjgco": {
            "active_permissions": {
               "api": [ "unlimitedStorage" ],
               "manifest_permissions": [  ]
            },
            "app_launcher_ordinal": "zp",
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 9,
            "disable_reasons": 32,
            "events": [  ],
            "from_bookmark": false,
            "from_webstore": true,
            "granted_permissions": {
               "api": [ "unlimitedStorage" ],
               "manifest_permissions": [  ]
            },
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "install_time": "13072961239827881",
            "lastpingday": "13073036401510834",
            "location": 1,
            "manifest": {
               "api_console_project_id": "72003345431",
               "app": {
                  "launch": {
                     "container": "tab",
                     "web_url": "hxxp://kmlviewer.nsspot.net/"
                  },
                  "urls": [ "hxxp://kmlviewer.nsspot.net/" ]
               },
               "container": "GOOGLE_DRIVE",
               "current_locale": "de",
               "default_locale": "en_US",
               "description": "A tool that views the KML, KMZ (Zipped KML format) file on a map. You can open KML, KMZ files from URL or from Google Drive.",
               "icons": {
                  "128": "icon128.png"
               },
               "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAz9ZalFOrFTuTkP03G7qa9dHbdvBDBse6GTdcOnuRumMZ1N080jSHKMqRQyz9lFLO6+urtmF010Y4oYAvK2IPbhv1T1/w9SpF7tOolWkIlteMnUDHRVhGMw08d7DBEmffqza7a/ivh4iTMzFSBfgHpUajibP+UbvYYXXLhRvFl2LQQnk+KPDai+bglbiI7HE3nk8Cr9/rEQnBWXr0xBIZ+KhmpRQn8PkUwgOP59awTHTfO5XTfzKPA7SDa4QIzDmuteZNYY2WaCs0G6S99qElRHIk8I7KpAGS3GqyDMPmCiBGIuaIfvWaU3iUcGvJPBdIdQcFYiHmMUQyTmS7IOimkQIDAQAB",
               "manifest_version": 2,
               "name": "KML, KMZ Viewer with Drive",
               "permissions": [ "unlimitedStorage" ],
               "update_url": "hxxp://clients2.google.com/service/update2/crx",
               "version": "1.0.1.7"
            },
            "page_ordinal": "n",
            "path": "mbolhellljccdahaeelobbojpfdgjgco\\1.0.1.7_0",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 0,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "mfehgcgbbipciphmccgaenjidiccnmng": {
            "active_permissions": {
               "api": [ "cloudPrintPrivate" ],
               "manifest_permissions": [  ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 1,
            "events": [  ],
            "from_bookmark": false,
            "from_webstore": false,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "install_time": "13072961118895442",
            "location": 5,
            "manifest": {
               "app": {
                  "launch": {
                     "web_url": "https://www.google.com/cloudprint"
                  },
                  "urls": [ "https://www.google.com/cloudprint/enable_chrome_connector" ]
               },
               "description": "Cloud Print",
               "display_in_launcher": false,
               "icons": {

               },
               "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqOhnwk4+HXVfGyaNsAQdU/js1Na56diW08oF1MhZiwzSnJsEaeuMN9od9q9N4ZdK3o1xXOSARrYdE+syV7Dl31nf6qz3A6K+D5NHe6sSB9yvYlIiN37jdWdrfxxE0pRYEVYZNTe3bzq3NkcYJlOdt1UPcpJB+isXpAGUKUvt7EQIDAQAB",
               "name": "Cloud Print",
               "permissions": [ "cloudPrintPrivate" ],
               "version": "0.1"
            },
            "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\cloud_print",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "mfffpogegjflfpflabcdkioaeobkgjik": {
            "active_permissions": {
               "api": [ "webRequest", "webRequestBlocking" ],
               "explicit_host": [ "\u003Call_urls>", "chrome://favicon/*" ],
               "manifest_permissions": [  ],
               "scriptable_host": [ "\u003Call_urls>" ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 1,
            "events": [  ],
            "from_bookmark": false,
            "from_webstore": false,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "initial_keybindings_set": true,
            "install_time": "13072961118948727",
            "location": 5,
            "manifest": {
               "background": {
                  "scripts": [ "channel.js", "background.js" ]
               },
               "content_scripts": [ {
                  "all_frames": true,
                  "js": [ "channel.js", "saml_injected.js" ],
                  "matches": [ "\u003Call_urls>" ],
                  "run_at": "document_start"
               } ],
               "content_security_policy": "default-src 'self'; script-src 'self'; frame-src *; style-src 'self' 'unsafe-inline'",
               "description": "GAIA Component Extension",
               "key": "MIGdMA0GCSqGSIb3DQEBAQUAA4GLADCBhwKBgQC4L17nAfeTd6Xhtx96WhQ6DSr8KdHeQmfzgCkieKLCgUkWdwB9G1DCuh0EPMDn1MdtSwUAT7xE36APEzi0X/UpKjOVyX8tCC3aQcLoRAE0aJAvCcGwK7qIaQaczHmHKvPC2lrRdzSoMMTC5esvHX+ZqIBMi123FOL0dGW6OPKzIwIBIw==",
               "manifest_version": 2,
               "name": "GaiaAuthExtension",
               "permissions": [ "\u003Call_urls>", "webRequest", "webRequestBlocking" ],
               "version": "0.0.1",
               "web_accessible_resources": [ "main.css", "main.html", "main.js", "offline.css", "offline.html", "offline.js", "success.html", "success.js", "util.js" ]
            },
            "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\gaia_auth",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "mgndgikekgjfcpckkfioiadnlibdjbkf": {
            "active_permissions": {
               "api": [  ],
               "manifest_permissions": [  ]
            },
            "app_launcher_ordinal": "n",
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 1,
            "events": [  ],
            "from_bookmark": false,
            "from_webstore": false,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "install_time": "13072961118896493",
            "location": 5,
            "manifest": {
               "app": {
                  "launch": {
                     "web_url": "hxxp://THIS-WILL-BE-REPLACED"
                  }
               },
               "description": "Der schnelle, einfache und sichere Browser, entwickelt für das moderne Web",
               "display_in_launcher": true,
               "display_in_new_tab_page": false,
               "icons": {
                  "128": "product_logo_128.png",
                  "16": "product_logo_16.png"
               },
               "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNuYLEQ1QPMcc5HfWI/9jiEf6FdJWqEtgRmIeI7qtjPLBM5oje+Ny2E2mTAhou5qdJiO2CHWdU1DQXY2F7Zu2gZaKZgHLfK4WimHxUT5Xd9/aro/R9PCzjguM1BLusiWYc9xlj1IsZpyiN1hcjU7SCnBhv1feQlv2WSB5KRiXwhQIDAQAB",
               "name": "Chrome",
               "version": "0.1"
            },
            "page_ordinal": "n",
            "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\chrome_app",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "nbpagnldghgfoolbancepceaanlmhfmd": {
            "active_permissions": {
               "api": [ "audioCapture", "hotwordPrivate", "idle", "management", "metricsPrivate", "tabs", "unlimitedStorage" ],
               "explicit_host": [ "*://*.google.co.uk/*", "*://*.google.com/*", "*://*.google.de/*", "*://*.google.fr/*", "*://*.google.ru/*", "chrome://newtab/*", "chrome://resources/*" ],
               "manifest_permissions": [  ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 1,
            "events": [ "hotwordPrivate.onEnabledChanged", "management.onInstalled", "runtime.onStartup" ],
            "from_bookmark": false,
            "from_webstore": false,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "initial_keybindings_set": true,
            "install_time": "13072961118898314",
            "location": 5,
            "manifest": {
               "background": {
                  "persistent": false,
                  "scripts": [ "chrome://resources/js/cr.js", "chrome://resources/js/util.js", "chrome://resources/js/cr/event_target.js", "constants.js", "keep_alive.js", "logging.js", "metrics.js", "nacl_manager.js", "state_manager.js", "base_session_manager.js", "always_on_manager.js", "launcher_manager.js", "page_audio_manager.js", "training_manager.js", "manager.js" ]
               },
               "content_security_policy": "object-src 'none'; script-src chrome://resources 'self'",
               "import": [ {
                  "id": "lccekmodgklaepjeofjdjpbminllajkg"
               } ],
               "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbHXRPiq2De9EJ+4pvNN6uE/D2avxrqyLSpA/Hq3II+btkPl1gboY3oUPTfevpVOFa90Y1c1b3/W682dXqybT0klIvFLKhdQx0LiVqSUQyIaDrwOCSo/ZcukbEwDRojegWymCjHvX6WZk4kKZzTJYzY1vrp0TWKLhttEMN9KFmowIDAQAB",
               "manifest_version": 2,
               "minimum_chrome_version": "38",
               "name": "Hotword triggering",
               "permissions": [ "*://*.google.com/*", "*://*.google.ru/*", "*://*.google.co.uk/*", "*://*.google.fr/*", "*://*.google.de/*", "chrome://newtab/", "chrome://resources/", "audioCapture", "hotwordPrivate", "idle", "management", "metricsPrivate", "tabs", "unlimitedStorage" ],
               "version": "0.0.1.3"
            },
            "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\hotword",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "nckgahadagoaajjgafhacjanaoiihapd": {
            "active_permissions": {
               "api": [ "background", "cookies", "idle", "notifications", "tabs", "webConnectable" ],
               "explicit_host": [ "*://*.google.com/*", "*://*.orkut.com/*" ],
               "manifest_permissions": [  ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 9,
            "events": [  ],
            "from_bookmark": false,
            "from_webstore": true,
            "granted_permissions": {
               "api": [ "background", "cookies", "idle", "notifications", "tabs", "webConnectable" ],
               "explicit_host": [ "*://*.google.com/*", "*://*.orkut.com/*" ],
               "manifest_permissions": [  ]
            },
            "incognito": true,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "initial_keybindings_set": true,
            "install_time": "13072961238765067",
            "lastpingday": "13073036401510834",
            "location": 1,
            "manifest": {
               "background": {
                  "scripts": [ "scripts/extension.js" ]
               },
               "browser_action": {
                  "default_icon": {
                     "19": "images_4/presence/offline_19.png",
                     "38": "images_4/presence/offline_38.png"
                  },
                  "default_title": "Hangouts"
               },
               "content_security_policy": "script-src 'self' https://*.google.com https://feedback.googleusercontent.com https://www.gstatic.com https://*.google.com:*/; img-src 'self' data: https://ssl.gstatic.com ; object-src 'self'",
               "current_locale": "de",
               "default_locale": "en",
               "description": "Hangouts macht Ihre Unterhaltungen noch lebendiger – mit Fotos, Emojis und kostenlosen Gruppen-Videoanrufen.",
               "externally_connectable": {
                  "matches": [ "https://*.google.com/*" ]
               },
               "icons": {
                  "128": "images_4/icon-128x128.png",
                  "48": "images_4/icon-48x48.png"
               },
               "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDsDApubb73tPfYlNIFxDu3K3/EHgV6/YOJXJkld1OZ20jW/cOht1j0NggnXhQYuu1mXFUufud4I2N7b5ydyg09gcM9Va3Zk17RhNV9smbPHOd4XlzJeXifX/9MgHPu4FzCen3CiSXsOeAELJIXEuT28xICriuUko/rNPwGeIB9VwIDAQAB",
               "manifest_version": 2,
               "minimum_chrome_version": "26.0.0.0",
               "name": "Hangouts",
               "options_page": "settingsdialog.html",
               "options_ui": {
                  "chrome_style": true,
                  "page": "settingsdialog.html"
               },
               "permissions": [ "cookies", "background", "idle", "notifications", "tabs", "*://*.google.com/*", "*://*.orkut.com/*" ],
               "system_indicator": {
                  "default_icon": {
                     "19": "images_4/presence/offline_19.png",
                     "38": "images_4/presence/offline_38.png"
                  }
               },
               "update_url": "https://clients2.google.com/service/update2/crx",
               "version": "2015.302.433.1",
               "web_accessible_resources": [ "*" ]
            },
            "path": "nckgahadagoaajjgafhacjanaoiihapd\\2015.302.433.1_0",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "neajdppkdcdipfabeoofebfddakdcjhd": {
            "active_permissions": {
               "api": [ "systemPrivate", "ttsEngine" ],
               "explicit_host": [ "https://www.google.com/*" ],
               "manifest_permissions": [  ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 1,
            "events": [ "ttsEngine.onPause", "ttsEngine.onResume", "ttsEngine.onSpeak", "ttsEngine.onStop" ],
            "from_bookmark": false,
            "from_webstore": false,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "initial_keybindings_set": true,
            "install_time": "13072961118901677",
            "location": 5,
            "manifest": {
               "background": {
                  "persistent": false,
                  "scripts": [ "tts_extension.js" ]
               },
               "description": "Component extension providing speech via the Google network text-to-speech service.",
               "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8GSbNUMGygqQTNDMFGIjZNcwXsHLzkNkHjWbuY37PbNdSDZ4VqlVjzbWqODSe+MjELdv5Keb51IdytnoGYXBMyqKmWpUrg+RnKvQ5ibWr4MW9pyIceOIdp9GrzC1WZGgTmZismYR3AjaIpufZ7xDdQQv+XrghPWCkdVqLN+qZDA1HU+DURznkMICiDDSH2sU0egm9UbWfS218bZqzKeQDiC3OnTPlaxcbJtKUuupIm5knjze3Wo9Ae9poTDMzKgchg0VlFCv3uqox+wlD8sjXBoyBCCK9HpImdVAF1a7jpdgiUHpPeV/26oYzM9/grltwNR3bzECQgSpyXp0eyoegwIDAQAB",
               "manifest_version": 2,
               "name": "Google Network Speech",
               "permissions": [ "systemPrivate", "ttsEngine", "https://www.google.com/" ],
               "tts_engine": {
                  "voices": [ {
                     "event_types": [ "start", "end", "error" ],
                     "gender": "female",
                     "lang": "en-US",
                     "remote": true,
                     "voice_name": "Google US English"
                  }, {
                     "event_types": [ "start", "end", "error" ],
                     "gender": "male",
                     "lang": "en-GB",
                     "remote": true,
                     "voice_name": "Google UK English Male"
                  }, {
                     "event_types": [ "start", "end", "error" ],
                     "gender": "female",
                     "lang": "en-GB",
                     "remote": true,
                     "voice_name": "Google UK English Female"
                  }, {
                     "event_types": [ "start", "end", "error" ],
                     "gender": "female",
                     "lang": "es-ES",
                     "remote": true,
                     "voice_name": "Google Español"
                  }, {
                     "event_types": [ "start", "end", "error" ],
                     "gender": "female",
                     "lang": "fr-FR",
                     "remote": true,
                     "voice_name": "Google Français"
                  }, {
                     "event_types": [ "start", "end", "error" ],
                     "gender": "female",
                     "lang": "it-IT",
                     "remote": true,
                     "voice_name": "Google Italiano"
                  }, {
                     "event_types": [ "start", "end", "error" ],
                     "gender": "female",
                     "lang": "de-DE",
                     "remote": true,
                     "voice_name": "Google Deutsch"
                  }, {
                     "event_types": [ "start", "end", "error" ],
                     "gender": "female",
                     "lang": "ja-JP",
                     "remote": true,
                     "voice_name": "Google 日本人"
                  }, {
                     "event_types": [ "start", "end", "error" ],
                     "gender": "female",
                     "lang": "ko-KR",
                     "remote": true,
                     "voice_name": "Google 한국의"
                  }, {
                     "event_types": [ "start", "end", "error" ],
                     "gender": "female",
                     "lang": "zh-CN",
                     "remote": true,
                     "voice_name": "Google 中国的"
                  } ]
               },
               "version": "1.0"
            },
            "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\network_speech_synthesis",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "nkeimhogjdpnpccoofpliimaahmaaome": {
            "active_permissions": {
               "api": [ "alarms", "desktopCapture", "processes", "webConnectable", "webrtcAudioPrivate", "webrtcLoggingPrivate", "system.cpu" ],
               "manifest_permissions": [  ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 1,
            "events": [ "runtime.onConnectExternal", "runtime.onMessageExternal" ],
            "from_bookmark": false,
            "from_webstore": false,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "initial_keybindings_set": true,
            "install_time": "13072961118897255",
            "location": 5,
            "manifest": {
               "background": {
                  "page": "background.html",
                  "persistent": false
               },
               "externally_connectable": {
                  "matches": [ "https://*.google.com/hangouts*", "*://localhost/*" ]
               },
               "incognito": "split",
               "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDAQt2ZDdPfoSe/JI6ID5bgLHRCnCu9T36aYczmhw/tnv6QZB2I6WnOCMZXJZlRdqWc7w9jo4BWhYS50Vb4weMfh/I0On7VcRwJUgfAxW2cHB+EkmtI1v4v/OU24OqIa1Nmv9uRVeX0GjhQukdLNhAE6ACWooaf5kqKlCeK+1GOkQIDAQAB",
               "manifest_version": 2,
               "name": "Google+ Hangouts",
               "permissions": [ "alarms", "desktopCapture", "processes", "system.cpu", "webrtcAudioPrivate", "webrtcLoggingPrivate" ],
               "version": "1.0"
            },
            "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\hangout_services",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "nmmhkkegccagdldgiimedpiccmgmieda": {
            "ack_external": true,
            "active_permissions": {
               "api": [ "identity", "webview" ],
               "explicit_host": [ "https://wallet-web.sandbox.google.com/*", "https://wallet.google.com/*", "https://www.google.com/*", "https://www.googleapis.com/*" ],
               "manifest_permissions": [  ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 137,
            "events": [ "app.runtime.onLaunched", "runtime.onConnectExternal" ],
            "from_bookmark": false,
            "from_webstore": true,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "initial_keybindings_set": true,
            "install_time": "13072961131802230",
            "lastpingday": "13073036401510834",
            "location": 10,
            "manifest": {
               "app": {
                  "background": {
                     "scripts": [ "craw_background.js" ]
                  }
               },
               "current_locale": "de",
               "default_locale": "en",
               "description": "Google Wallet für digitale Produkte",
               "display_in_launcher": false,
               "display_in_new_tab_page": false,
               "icons": {
                  "128": "images/icon_128.png",
                  "16": "images/icon_16.png"
               },
               "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCrKfMnLqViEyokd1wk57FxJtW2XXpGXzIHBzv9vQI/01UsuP0IV5/lj0wx7zJ/xcibUgDeIxobvv9XD+zO1MdjMWuqJFcKuSS4Suqkje6u+pMrTSGOSHq1bmBVh0kpToN8YoJs/P/yrRd7FEtAXTaFTGxQL4C385MeXSjaQfiRiQIDAQAB",
               "manifest_version": 2,
               "minimum_chrome_version": "29",
               "name": "Google Wallet",
               "oauth2": {
                  "auto_approve": true,
                  "client_id": "203784468217.apps.googleusercontent.com",
                  "scopes": [ "https://www.googleapis.com/auth/sierra", "https://www.googleapis.com/auth/sierrasandbox", "https://www.googleapis.com/auth/chromewebstore", "https://www.googleapis.com/auth/chromewebstore.readonly" ]
               },
               "permissions": [ "identity", "webview", "https://wallet.google.com/", "https://wallet-web.sandbox.google.com/", "https://www.google.com/", "https://www.googleapis.com/*" ],
               "update_url": "https://clients2.google.com/service/update2/crx",
               "version": "0.1.0.0"
            },
            "path": "nmmhkkegccagdldgiimedpiccmgmieda\\0.1.0.0_0",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "running": false,
            "state": 1,
            "was_installed_by_default": true,
            "was_installed_by_oem": false
         },
         "ohgndokldibnndfnjnagojmheejlengn": {
            "ack_external": true,
            "active_permissions": {
               "api": [ "contextMenus", "nativeMessaging", "tabs" ],
               "explicit_host": [ "hxxp://*.citavi.com/*", "hxxp://*/*", "https://*/*" ],
               "manifest_permissions": [  ],
               "scriptable_host": [ "hxxp://*/*", "https://*/*" ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 9,
            "events": [  ],
            "from_bookmark": false,
            "from_webstore": true,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "initial_keybindings_set": true,
            "install_time": "13072961125713361",
            "install_warning_on_enable": false,
            "lastpingday": "13073036401510834",
            "location": 6,
            "manifest": {
               "background": {
                  "page": "background.html"
               },
               "content_scripts": [ {
                  "all_frames": true,
                  "css": [ "libs/css/jquery.css", "libs/css/jsonSuggest.css" ],
                  "js": [ "libs/jquery/jquery.js", "libs/jquery/jquery-ui-1.8.23.custom.js", "libs/jquery/jquery.effects.bounce.js", "libs/jquery/jquery.effects.clip.js", "libs/jquery/jquery.effects.core.js", "libs/jquery/jquery.effects.drop.js", "libs/jquery/jquery.effects.explode.js", "libs/jquery/jquery.effects.fade.js", "libs/jquery/jquery.effects.fold.js", "libs/jquery/jquery.effects.highlight.js", "libs/jquery/jquery.effects.pulsate.js", "libs/jquery/jquery.effects.scale.js", "libs/jquery/jquery.effects.shake.js", "libs/jquery/jquery.effects.slide.js", "libs/jquery/jquery.effects.transfer.js", "libs/jquery/jquery.ui.accordion.js", "libs/jquery/jquery.ui.autocomplete.js", "libs/jquery/jquery.ui.button.js", "libs/jquery/jquery.ui.core.js", "libs/jquery/jquery.ui.dialog.js", "libs/jquery/jquery.ui.draggable.js", "libs/jquery/jquery.ui.droppable.js", "libs/jquery/jquery.ui.mouse.js", "libs/jquery/jquery.ui.position.js", "libs/jquery/jquery.ui.progressbar.js", "libs/jquery/jquery.ui.resizable.js", "libs/jquery/jquery.ui.selectable.js", "libs/jquery/jquery.ui.slider.js", "libs/jquery/jquery.ui.sortable.js", "libs/jquery/jquery.ui.tabs.js", "libs/jquery/jquery.ui.widget.js", "libs/jquery/jquery.effects.blind.js", "libs/jquery/jquery.jsonSuggest-dev.js", "libs/jquery/jquery.jsonSuggest.js", "libs/jquery/json2.js", "citaviPickerLogger.js", "jqueryHelper.js", "html/onlineSearchProgressDialog.js", "html/optionsDialog.js", "html/importDialog.js", "isbnValidator.js", "Hunter/kindleHunter.js", "pageModifier.js", "Base64.js", "Hunter/hunterManager.js", "citaviPicker.js", "Webservice/references.js", "Webservice/transformer.js", "Webservice/fetcher.js" ],
                  "matches": [ "hxxp://*/*", "https://*/*" ]
               } ],
               "current_locale": "de",
               "default_locale": "en",
               "description": "Citavi Picker für Google Chrome",
               "homepage_url": "hxxp://www.citavi.com",
               "icons": {
                  "128": "icon.ico",
                  "16": "icon.ico",
                  "48": "icon.ico"
               },
               "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6hZz7lcASmfJcGJQ3x/ZYvKCCKLpkBkx9IVqjsmTDvE+MjXh6Kp3+giPAIFZGfGycQ7DSD7x8PtecKDvsSB+xY7P6CdN3kEDernWIfuh8GEpPo0Q1CZ2Sj2mrb+ftvdIrhXygLU+PPCVimtDgBRNbKLzopARxKzqta1MtSEOYqn35kyWFFGN1FPRG26izgBlM9dO3ud39F5ZUcpOt6Wt6vosoiHGwefaHjWqI21b59MebjGE8vwKvWmHUSMoyFgYRB1o+iTZF9bbYM0X885QP7e5GZrbee5R+M6waQteDRSvSDyqegXye+wf3nUNo7rMArA6GY4sajUAHqeKD+2AHwIDAQAB",
               "manifest_version": 2,
               "name": "Citavi Picker",
               "permissions": [ "nativeMessaging", "hxxp://*/*", "https://*/*", "tabs", "contextMenus", "hxxp://*.citavi.com/" ],
               "update_url": "https://clients2.google.com/service/update2/crx",
               "version": "2015.1.27.2",
               "web_accessible_resources": [ "html/importDialog.html", "html/onlineSearchProgressDialog.html", "html/optionsDialog.html", "html/images/*.png" ]
            },
            "path": "ohgndokldibnndfnjnagojmheejlengn\\2015.1.27.2_1",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         },
         "pafkbggdmjlpgkdkcbjmhmfcdpncadgh": {
            "active_permissions": {
               "api": [ "alarms", "background", "identity", "metricsPrivate", "notifications", "pushMessaging", "storage", "tabs", "webstorePrivate" ],
               "explicit_host": [ "*://*.google.com/*", "*://*.gstatic.com/*", "https://*.googleapis.com/*", "https://*.googleusercontent.com/*" ],
               "manifest_permissions": [  ]
            },
            "commands": {

            },
            "content_settings": [  ],
            "creation_flags": 1,
            "events": [ "alarms.onAlarm", "identity.onSignInChanged", "notifications.onButtonClicked", "notifications.onClicked", "notifications.onClosed", "notifications.onPermissionLevelChanged", "notifications.onShowSettings", "pushMessaging.onMessage", "runtime.onInstalled", "runtime.onStartup", "runtime.onSuspend", "storage.onChanged" ],
            "from_bookmark": false,
            "from_webstore": false,
            "incognito_content_settings": [  ],
            "incognito_preferences": {

            },
            "initial_keybindings_set": true,
            "install_time": "13072961118900829",
            "location": 5,
            "manifest": {
               "background": {
                  "persistent": false,
                  "scripts": [ "utility.js", "cards.js", "background.js" ]
               },
               "description": "Integrates Google Now into Chrome.",
               "icons": {
                  "128": "images/icon128.png",
                  "16": "images/icon16.png",
                  "48": "images/icon48.png"
               },
               "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkhqJr32OFD/bMXW4Md7jMfd7LbwHXVc6x5bBQG5U+dloofoxrICDR20yur/40mQ8O//0sS1b8srvbab1CRlSrxoNCr9T80NAkfzx0gHyVS+p1Zow+1FzLMu9PiGwwFyN80HIB7GI/dIa0wC9K/2OrrzcHEhVH96DacTtWQqjfDVtZPjT7Xwv23dgoWcpbkRC86jMJot3dmX9xnn0KzoVc9gDOHSIkBLbkkr6Sp3LGXCCM4L0DJgxdFwaLr5WBzgC3y5x0/wwPIwN4PtIaK3BhH6njlksfnKwwIJ9iRT41V4BqbWu4mszO/7VJ3HJyw2DBpIc2grU9ZRRxrV3fRQG4wIDAQAB",
               "manifest_version": 2,
               "name": "Google Now",
               "oauth2": {
                  "auto_approve": true,
                  "scopes": [ "https://www.googleapis.com/auth/googlenow" ]
               },
               "optional_permissions": [ "background" ],
               "permissions": [ "alarms", "identity", "metricsPrivate", "notifications", "pushMessaging", "storage", "tabs", "webstorePrivate", "*://*.google.com/*", "*://*.gstatic.com/*", "https://*.googleapis.com/chromenow/v1/*", "https://*.googleusercontent.com/*" ],
               "version": "1.2.0.1"
            },
            "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\google_now",
            "preferences": {

            },
            "regular_only_preferences": {

            },
            "state": 1,
            "was_installed_by_default": false,
            "was_installed_by_oem": false
         }
      }
   },
   "google": {
      "services": {
         "last_username": "basil.eberle@googlemail.com",
         "username": "basil.eberle@googlemail.com"
      }
   },
   "homepage": "hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M5D03F840-0A34-4EF1-B1D2-7A24EF265FAD&SearchSource=55&CUI=&UM=5&UP=SPDD7AE828-8266-469E-A82F-77BE9505BDA3&SSPV=",
   "homepage_is_newtabpage": true,
   "pinned_tabs": [  ],
   "protection": {
      "macs": {
         "browser": {
            "show_home_button": "6AA2DA8BFDD25445ABB24BB8CDC07A4AFB70477DACA1A1985105F64B71056501"
         },
         "default_search_provider": {
            "keyword": "AA349BD6AE8FA3A0D6F3B9FEC6FDBF5D8175E8F5F2C1A684A2A0F3B4393D28EA",
            "name": "7B21C10AE38BE315ED7E49700B5346971B3C9850FEA5A186DA1D5B1F2963F28B",
            "search_url": "BD963AF047FA53A193678C8BA019FEB52ECECF9A842709675A9B7DC9D59A5CF1"
         },
         "default_search_provider_data": {
            "template_url_data": "B456F8E89A12855FE3C9926B8A6EDE2293293C8FE7794E759222B45A8C388DC8"
         },
         "extensions": {
            "settings": {
               "ahfgeienlihckogmohjhadlkjgocpleb": "774A225DEE5C9442CE48BAAE01FBCD92A6FBA8E0586D6395460D09506A0A1097",
               "bepbmhgboaologfdajaanbcjmnhjmhfn": "207BD5DFED379137BD933816AC834B774A41C133E0C7437CDD971465CF0D8C3D",
               "cfhdojbkjhnklbpkdaibdccddilifddb": "0F0DD27E03ED960A97CB61FCC90F098D771D577D2C3A999C249623D353311AD8",
               "eemcgdkfndhakfknompkggombfjjjeno": "52669445A6C9D00C4A47BA446F1244D1B313D8F12D765C4CE0089FEA9206906A",
               "ennkphjdgehloodpbhlhldgbnhmacadg": "044125F679AE5667E9CE7C3168E76DDFF24F50BD0801B5786E0142C39874DE61",
               "gfdkimpbcpahaombhbimeihdjnejgicl": "52C4DE3992DF5F8FD827E2A2ECF75821B8174B9BB6EBEB15B0321D2A8A346EFA",
               "gomekmidlodglbbmalcneegieacbdmki": "30C32E036F21684D6E0395391FC7DD824C63B2A1DFEF5511A4561E0CE7D257C8",
               "kmendfapggjehodndflmmgagdbamhnfd": "5C8B21D6DDD93B9C04BBFF2E1BE1BBB9ED4B483FB48BE03ACA302B4880BD6C67",
               "lccekmodgklaepjeofjdjpbminllajkg": "73A826F89E85DE6B4A2CF67E8EFA1E56206457DBBDB54BC7BEF68EEE7A4EFD83",
               "lifbcibllhkdhoafpjfnlhfpfgnpldfl": "984A1480435E8821FEAED5DABD21BBBCDED39F9340CEB2C36952A5E6F482F36B",
               "mbolhellljccdahaeelobbojpfdgjgco": "2E1E3BBC0D896905AA48D55174CCA3C15E96CA53FC585FF75334A120C345D33F",
               "mfehgcgbbipciphmccgaenjidiccnmng": "D956FDB3201D97A8B100DD285BC7C001D1A4A56A9DCEB7499DC766B42227AC26",
               "mfffpogegjflfpflabcdkioaeobkgjik": "CEB733D3DC6EB63BB1C4C6FC3AF48D228DC239496B6F8BEA841287B27FC912EA",
               "mgndgikekgjfcpckkfioiadnlibdjbkf": "FC28759E122AC25C1176ED21F17022AF5D7AC40CA6FC35FDCE198161DA2FF3D8",
               "nbpagnldghgfoolbancepceaanlmhfmd": "41C59F111B70B509F70C77637BD8A18D431382EFAD4334BA875A57EAE62FC122",
               "nckgahadagoaajjgafhacjanaoiihapd": "5210BF1C1FF1175E722818FB6621F35228C19A0B39C93404B3D4A37718F80582",
               "neajdppkdcdipfabeoofebfddakdcjhd": "D1B4FE342F47B8D3EBDA594FBDB61C9BA7F0534FF75DF2FD00A786A1CDCE401E",
               "nkeimhogjdpnpccoofpliimaahmaaome": "A94A9CE3823DB636F99B0FA893342F69070151CAC0D2137C42F2AF20FE5C5591",
               "nmmhkkegccagdldgiimedpiccmgmieda": "919E5AC76696856915CE7203E5DF3576745E002930E0689B16324686E90A9AF5",
               "ohgndokldibnndfnjnagojmheejlengn": "A8F9FAFF47DA042FC64DD7BCC9D5E74B3F0F81E6F537238C4C1E9D2203A788C5",
               "pafkbggdmjlpgkdkcbjmhmfcdpncadgh": "80CC01A8324B3F0BCFB62FF123A964638DB937EB44A3990274BB20D8BCC8F171"
            }
         },
         "google": {
            "services": {
               "last_username": "71F476FD6D124F81795640BE2483F35D5E108500FF5D5497081F4B2CC9B1BF5D",
               "username": "2899B25FC0807D8E3CF3FBFF0B07547E6B3DFCD5C9AF8C59BB288772C07E3CD1"
            }
         },
         "homepage": "6B79359431C3CB91DFFADD9D3EB7487E02D9A4D6B34F6F1C00B302EEDE106A2F",
         "homepage_is_newtabpage": "F09724F9195F838BD833309BE572472E658C5AF1503762BECF280C93D581C15F",
         "pinned_tabs": "A1A9C32317B879FE82B6ED6A6512D089789F05E30745B5CCCB76F1091DEE0717",
         "prefs": {
            "preference_reset_time": "0B408FF304A04908220B9ECD3E02F3577F681868FEF6230296D0AF605616FC4E"
         },
         "profile": {
            "reset_prompt_memento": "B04F84352991A271405CC3FAF236922D6A5E51181026CADBEBC245321582827F"
         },
         "safebrowsing": {
            "incidents_sent": "157A7080E8A63C89AC91EFBDCA9880B6B8C005C13D7AA68551AEC29EEA38B5CA"
         },
         "search_provider_overrides": "9D9C5947F6F4F9C0FF0DD7461D5359DD0A470290E107EBE0243F1AD973A52D5F",
         "session": {
            "restore_on_startup": "BF6C9B361E54C4393973A2B5968F75EE35C4C060E68D8B3C4FF99D553254C695",
            "startup_urls": "005FE60B4E4F327B992CC86B41DEB6041935CF94E69A83284FC77B687F683039"
         },
         "software_reporter": {
            "prompt_reason": "98F3E73884FBF4B6208ACDF770ADA749D9498FD0A06D7F039511C6225A985188",
            "prompt_version": "CA77F2CB73FF3ADEA6FABE97AB700FD33BF10D35F0AE1686B9B92B38E2CDB7F5"
         },
         "sync": {
            "remaining_rollback_tries": "23C1ECFD0AB13169B1679B3492AC4632C1377062BFB728BE088E087688C75320"
         }
      },
      "super_mac": "2B98B2019F8B235A8359AE2610A7F96A43DBF0394480F9F78FB8C26D6736E1E4"
   },
   "session": {
      "restore_on_startup": 5,
      "startup_urls": [ "hxxp://www.jura.uni-muenchen.de/index.html" ]
   },
   "sync": {
      "remaining_rollback_tries": 0
   }
}
         

Alt 10.04.2015, 15:30   #77
schrauber
/// the machine
/// TB-Ausbilder
 

Adware Roll around eingefangen - Standard

Adware Roll around eingefangen



Äusserst merkwürdig. Verbindest Du Chrome mit einem Google Konto?

Lade SystemLook von jpshortstuff von einem der folgenden Spiegel herunter und speichere das Tool auf dem Desktop.
SystemLook (64 bit)
  • Doppelklicke auf die SystemLook_x64.exe, um das Tool zu starten.
  • Kopiere den Inhalt der folgenden Codebox in das Textfeld des Tools:
    Code:
    ATTFilter
    :filefind
    *trovi*
    :regfind
    trovi
             
  • Klicke nun auf den Button Look, um den Scan zu starten.
  • Der Suchlauf kann einige Zeit dauern.
  • Wenn der Suchlauf beendet ist, wird sich Dein Editor mit den Ergebnissen öffnen, poste diese in deinen Thread.
  • Die Ergebnisse werden auf dem Desktop als SystemLook.txt gespeichert.
__________________

__________________

Alt 10.04.2015, 16:33   #78
Bayer76
 

Adware Roll around eingefangen - Standard

Adware Roll around eingefangen



Ja, ich verbinde Chrome mit einem Google Konto. Wird von dort aus der trovi "nachgeladen"??
Code:
ATTFilter
SystemLook 30.07.11 by jpshortstuff
Log created at 17:29 on 10/04/2015 by Basiliuws Eber
Administrator - Elevation successful

========== filefind ==========

Searching for "*trovi*"
C:\Games\World_of_Tanks\res\scripts\client\gui\scaleform\daapi\view\lobby\cybersport\cybersportintroview.pyc	--a---- 5508 bytes	[17:19 26/08/2014]	[14:49 05/02/2015] 592B7F2ED889887BE884400D10D40917
C:\Games\World_of_Tanks\res\scripts\client\gui\scaleform\daapi\view\lobby\fortifications\components\fortintroview.pyc	--a---- 5280 bytes	[17:19 26/08/2014]	[21:37 17/12/2014] E4733374A202919010675792E3328974
C:\Games\World_of_Tanks\res\scripts\client\gui\scaleform\daapi\view\lobby\rally\baserallyintroview.pyc	--a---- 760 bytes	[17:19 26/08/2014]	[17:59 22/07/2014] E93DBE44F43A17FBDE1CC62594374155
C:\Games\World_of_Tanks\res\scripts\client\gui\scaleform\daapi\view\meta\baserallyintroviewmeta.pyc	--a---- 491 bytes	[17:19 26/08/2014]	[17:59 22/07/2014] CA9FEFE565AA0A2BE00E9EA34B322108

========== regfind ==========

Searching for "trovi"
No data found.

-= EOF =-
         
Beim Suchlauf hat er nur Dateien mit in_trovi_ew gefunden, aber nichts relevantes. Habe aber vorher auch den MWB Scanner drüber laufen lassen, der den PUP.trovi jedes mal entfernt.
__________________

Alt 11.04.2015, 07:23   #79
schrauber
/// the machine
/// TB-Ausbilder
 

Adware Roll around eingefangen - Standard

Adware Roll around eingefangen



Dann verbinde Chrome mit dem Google Konto, dann den Browser komplett zurücksetzen und die EInstellungen und erweiterten Einstellungen von Hand durchgehen, ob noch irgendwo was ist.

Ebenso mal die Datei bei verbundenem Konto löschen.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 11.04.2015, 19:36   #80
Bayer76
 

Adware Roll around eingefangen - Standard

Adware Roll around eingefangen



Habe ich beides schon probiert, ohne Erfolg...


Alt 12.04.2015, 07:57   #81
schrauber
/// the machine
/// TB-Ausbilder
 

Adware Roll around eingefangen - Standard

Adware Roll around eingefangen



Chrome nochmal komplett mit Revo deinstallieren, NICHT neu installieren, dann ein frisches FRST log bitte.
__________________
--> Adware Roll around eingefangen

Alt 12.04.2015, 15:20   #82
Bayer76
 

Adware Roll around eingefangen - Standard

Adware Roll around eingefangen



Interessant: Habe Chrome mit dem Revon Uninstaller auf der sichersten Stufe komplett deinstalliert. Revo und CC Cleaner finden ihn jetzt nicht mehr. Das Icon auf dem Desktop ist aber immer noch da und er läßt sich immer nocht starten.
Im Chrome Ordner gibt es 2 Unterordner mit 2 Programmversionen??
Angehängte Grafiken
Dateityp: jpg Chrome.jpg (64,6 KB, 192x aufgerufen)

Alt 12.04.2015, 16:29   #83
Bayer76
 

Adware Roll around eingefangen - Standard

Adware Roll around eingefangen



Aktuelle FRST Log:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Basiliuws Eber (administrator) on BASILGAMING on 12-04-2015 16:35:52
Running from C:\Users\Basiliuws Eber\Downloads
Loaded Profiles: Basiliuws Eber & Basilius Eberle (Available profiles: Basiliuws Eber & Basilius Eberle)
Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\CtHdaSvc.exe
(devolo AG) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
() C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
() C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
(Dropbox, Inc.) C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\SBRcni.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\CTJckCfg.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart TimeLock\AlarmClock.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Microsoft Corporation) C:\Windows\System32\SnippingTool.exe
(Swiss Academic Software) C:\Program Files (x86)\Citavi 4\bin\Citavi.exe
(Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe
() C:\Program Files (x86)\Opera\28.0.1750.51\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2014-04-11] (Intel Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-02-13] (Apple Inc.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [590144 2015-03-12] (Razer Inc.)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [Sound Blaster Recon3Di SBX Control Panel] => C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\SBRcni.exe [976896 2012-11-28] (Creative Technology Ltd)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5511352 2015-03-22] (Avast Software s.r.o.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [335232 2015-03-07] (Oracle Corporation)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707984 2014-11-19] (Cisco Systems, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd)
HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [Google Update] => C:\Users\Basiliuws Eber\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-12-07] (Google Inc.)
HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [MusicManager] => C:\Users\Basiliuws Eber\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7475200 2015-04-01] (Google Inc.)
HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2015-01-28] (Garmin Ltd or its subsidiaries)
HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\MountPoints2: {39a7bf0b-76dd-11e4-8299-001109e5f38b} - "H:\HTC_Sync_Manager_PC.exe" 
HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\MountPoints2: {3aed501f-9b74-11e4-82a3-001109e5f38b} - "H:\HTC_Sync_Manager_PC.exe" 
HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\MountPoints2: {8cb957cc-cd4d-11e4-82b6-001109e5f38b} - "H:\HTC_Sync_Manager_PC.exe" 
HKU\S-1-5-21-2245731289-3221781707-2474736645-1004\...\Run: [GoogleChromeAutoLaunch_480223198B15635E392F8E5BDE9F021E] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
HKU\S-1-5-21-2245731289-3221781707-2474736645-1004\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11776 2014-10-29] (Microsoft Corporation)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [178512 2015-03-13] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [164568 2015-03-13] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE OC_GURU.lnk
ShortcutTarget: GIGABYTE OC_GURU.lnk -> C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe (GIGABYTE Technology Co.,Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk
ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{401FADAA-1C16-4721-9F02-19067E1A1CA8}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC)
Startup: C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (Avast Software s.r.o.)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BootExecute: autocheck autochk * bootdelete

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-2245731289-3221781707-2474736645-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\system32\mscoree.dll [2013-08-22] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-24] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-03-22] (Avast Software s.r.o.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-24] (Oracle Corporation)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2014-04-20] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)
BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\SysWOW64\mscoree.dll [2013-08-22] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-03-22] (Avast Software s.r.o.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2014-04-20] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft)
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-22] ()
FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-24] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-22] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2013-04-19] (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-03-13] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-03-13] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2245731289-3221781707-2474736645-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Basiliuws Eber\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin HKU\S-1-5-21-2245731289-3221781707-2474736645-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Basiliuws Eber\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin HKU\S-1-5-21-2245731289-3221781707-2474736645-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-04-04] ()
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-31]

Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://www.jura.uni-muenchen.de/index.html"
CHR Profile: C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Adblock Plus) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-04-08]
CHR Extension: (Avast Online Security) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-03-31]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-31]
CHR Extension: (KML, KMZ Viewer with Drive) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbolhellljccdahaeelobbojpfdgjgco [2015-04-08]
CHR Extension: (Hangouts) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2015-04-08]
CHR Extension: (Google Wallet) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-03-31]
CHR Extension: (Citavi Picker) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn [2015-04-04]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-22]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn] - https://clients2.google.com/service/update2/crx

Opera: 
=======
OPR Extension: (Adblock Plus) - C:\Users\Basiliuws Eber\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2015-03-20]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-03-22] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4030800 2015-03-22] (Avast Software)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2014-05-31] (Creative Labs) [File not signed]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2014-05-31] (Creative Labs) [File not signed]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [423424 2012-10-08] (Creative Technology Ltd) [File not signed]
R2 CtHdaSvc; C:\Windows\sysWow64\CtHdaSvc.exe [103936 2014-04-29] (Creative Technology Ltd)
R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3736520 2015-01-29] (devolo AG)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [528096 2014-06-08] (Futuremark)
R2 gadjservice; C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe [16384 2014-04-16] () [File not signed]
S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [517464 2015-01-28] (Garmin Ltd or its subsidiaries)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation)
R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2014-06-27] (Nero AG)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-04-11] (Intel Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-03-20] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-03-17] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-06-01] ()
R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [343040 2013-08-08] (Qualcomm Atheros) [File not signed]
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187072 2015-02-05] ()
R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe [102400 2013-02-22] (Gigabyte Technology CO., LTD.) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
         
Code:
ATTFilter
==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [150440 2014-12-23] (SlySoft, Inc.)
R3 AnyDVD; C:\Windows\SysWOW64\Drivers\AnyDVD.sys [150440 2014-12-23] (SlySoft, Inc.)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22240 2013-10-28] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-03-22] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [88408 2015-03-22] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-03-22] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-03-22] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-03-22] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [441728 2015-03-22] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [136752 2015-03-22] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [268640 2015-03-22] ()
S3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices)
R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [75056 2013-02-13] (Qualcomm Atheros, Inc.)
R3 cthda; C:\Windows\system32\drivers\cthda.sys [1050904 2014-04-29] (Creative Technology Ltd)
R2 DRHARD64; C:\Windows\system32\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software)
R2 DRHARD64; C:\Windows\SysWOW64\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software)
R2 DRHMSR64; C:\Windows\system32\drivers\DRHMSR64.sys [13760 2013-07-21] ()
R2 DRHMSR64; C:\Windows\SysWOW64\drivers\DRHMSR64.sys [13760 2013-07-21] ()
S3 etocdrv; C:\Windows\etocdrv.sys [15584 2013-10-30] (Giga-Byte Technology CO., LTD.)
S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] ()
S3 HtcVCom32; C:\Windows\system32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated)
R3 Ke2200; C:\Windows\system32\DRIVERS\e22w8x64.sys [163536 2013-03-20] (Qualcomm Atheros, Inc.)
R1 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [107736 2015-03-17] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-04-12] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-03-17] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [118272 2014-03-20] (Intel Corporation)
R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2015-01-29] (CACE Technologies)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
R3 rzdaendpt; C:\Windows\System32\drivers\rzdaendpt.sys [33448 2014-09-05] (Razer Inc)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2015-02-05] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129600 2014-10-23] (Razer, Inc.)
R3 rzvkeyboard; C:\Windows\System32\drivers\rzvkeyboard.sys [31912 2014-12-30] (Razer Inc)
S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2013-03-18] (Apple, Inc.) [File not signed]
S1 UsbCharger; C:\Windows\System32\DRIVERS\UsbCharger.sys [22240 2013-10-24] ()
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-03-22] (Avast Software)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52592 2014-11-19] (Cisco Systems, Inc.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 DRHARD; \??\C:\Windows\system32\DRIVERS\DRHARD.SYS [X]
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
         
Code:
ATTFilter
==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-12 16:30 - 2015-04-12 16:30 - 00053168 _____ () C:\Users\Basiliuws Eber\Desktop\HitmanPro_20150412_1630.log
2015-04-12 16:30 - 2015-04-12 16:30 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe
2015-04-12 16:30 - 2015-04-12 16:30 - 00000258 _____ () C:\Windows\system32\bootdelete.lst
2015-04-11 20:44 - 2015-04-11 20:44 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite
2015-04-11 16:51 - 2015-04-11 16:51 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Bewerbungen
2015-04-11 13:12 - 2015-04-12 16:23 - 00000000 ____D () C:\AdwCleaner
2015-04-11 13:12 - 2015-04-11 13:12 - 02217984 _____ () C:\Users\Basiliuws Eber\Downloads\AdwCleaner_4.201.exe
2015-04-10 19:20 - 2015-04-10 19:20 - 00000710 _____ () C:\Users\Basiliuws Eber\Desktop\World of Tanks.lnk
2015-04-10 19:20 - 2015-04-10 19:20 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\World of Tanks
2015-04-10 19:19 - 2015-04-10 19:19 - 05995160 _____ (Wargaming.net ) C:\Users\Basiliuws Eber\Downloads\WoT_internet_install_eu.exe
2015-04-10 17:29 - 2015-04-10 17:29 - 00165376 _____ () C:\Users\Basiliuws Eber\Desktop\SystemLook_x64.exe
2015-04-08 21:23 - 2015-04-08 21:23 - 00000000 ____D () C:\Users\Basiliuws Eber\.pdfsam
2015-04-08 21:18 - 2015-04-08 21:18 - 30843037 _____ () C:\Users\Basiliuws Eber\Downloads\PDFsam_224 (1).zip
2015-04-08 21:18 - 2015-04-08 21:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Split And Merge Basic
2015-04-08 21:18 - 2015-04-08 21:18 - 00000000 ____D () C:\Program Files\PDF Split And Merge Basic
2015-04-08 21:18 - 2014-06-26 09:23 - 16358440 _____ () C:\Users\Basiliuws Eber\Downloads\pdfsam-x64-v2_2_4.msi
2015-04-08 21:18 - 2014-06-26 09:22 - 16358452 _____ () C:\Users\Basiliuws Eber\Downloads\pdfsam-x86-v2_2_4.msi
2015-04-08 21:14 - 2015-04-08 21:14 - 30843037 _____ () C:\Users\Basiliuws Eber\Downloads\PDFsam_224.zip
2015-04-08 18:34 - 2015-04-08 18:34 - 02209056 _____ () C:\Users\Basiliuws Eber\Downloads\avira-eu-cleaner_de.exe
2015-04-06 18:05 - 2015-04-06 18:05 - 00000201 _____ () C:\Users\Basiliuws Eber\Downloads\fhsexport_endnote.enw
2015-04-06 17:02 - 2015-04-06 17:02 - 36450560 _____ (NVIDIA Corporation) C:\Users\Basiliuws Eber\Downloads\GeForce_Experience_v2.4.1.21 (1).exe
2015-04-06 17:02 - 2015-04-06 17:02 - 00002160 _____ () C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
2015-04-06 17:01 - 2015-04-12 16:08 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-06 17:01 - 2015-03-13 18:16 - 06861968 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-04-06 17:01 - 2015-03-13 18:16 - 03526856 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-04-06 17:01 - 2015-03-13 18:16 - 02559808 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-04-06 17:01 - 2015-03-13 18:16 - 00935056 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-04-06 17:01 - 2015-03-13 18:16 - 00386248 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-04-06 17:01 - 2015-03-13 18:16 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-04-06 17:01 - 2015-03-13 17:38 - 00622224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-04-06 17:01 - 2015-03-11 15:10 - 04246327 _____ () C:\Windows\system32\nvcoproc.bin
2015-04-06 17:00 - 2015-04-06 17:00 - 00000000 ____D () C:\NVIDIA
2015-04-06 17:00 - 2015-03-13 21:41 - 32114888 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 25460880 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 24775368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 20466376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 18580512 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 17258024 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 16022016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 14121624 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 13297144 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 13210080 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 10775080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 10715864 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 10262160 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-04-06 17:00 - 2015-03-13 21:41 - 03611792 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 03303448 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 03249352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 02906928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 01896136 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434788.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434788.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 01556624 _____ (NVIDIA Corporation) C:\Windows\system32\nvir3dgenco64.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 01540240 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00997856 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00970384 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00944784 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00930448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00909512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00878328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00833680 _____ () C:\Windows\system32\nvmcumd.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00496272 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00452424 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstusb.sys
2015-04-06 17:00 - 2015-03-13 21:41 - 00400584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00390288 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00354112 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00346824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00306208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00195728 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-04-06 17:00 - 2015-03-13 21:41 - 00178512 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00164568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00030536 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2015-04-06 17:00 - 2015-03-13 21:41 - 00027441 _____ () C:\Windows\system32\nvinfo.pb
2015-04-06 16:57 - 2015-04-06 16:59 - 309143408 _____ (NVIDIA Corporation) C:\Users\Basiliuws Eber\Downloads\347.88-desktop-win8-win7-winvista-64bit-international-whql.exe
2015-04-05 16:35 - 2015-04-05 16:35 - 00046575 _____ () C:\Users\Basiliuws Eber\Downloads\Addition.txt
2015-04-05 16:34 - 2015-04-12 16:35 - 00030706 _____ () C:\Users\Basiliuws Eber\Downloads\FRST.txt
2015-04-05 16:34 - 2015-04-12 16:35 - 00000000 ____D () C:\FRST
2015-04-05 16:34 - 2015-04-05 16:34 - 02095616 _____ (Farbar) C:\Users\Basiliuws Eber\Downloads\FRST64.exe
2015-04-04 20:59 - 2015-04-04 20:59 - 00003619 _____ () C:\Users\Basiliuws Eber\Downloads\download.ris
2015-04-04 17:35 - 2015-04-04 17:35 - 00166325 _____ () C:\Users\Basiliuws Eber\Downloads\sackpfeife_tief_c_ein_bordun_trichter.mp4
2015-04-04 17:34 - 2015-04-04 17:34 - 00194216 _____ () C:\Users\Basiliuws Eber\Downloads\sackpfeife_1_in_g_ein_bordun_trichter.mp4
2015-04-04 17:10 - 2015-04-06 22:13 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Mp3tag
2015-04-04 17:09 - 2015-04-04 17:09 - 00001002 _____ () C:\Users\Public\Desktop\Mp3tag.lnk
2015-04-04 17:09 - 2015-04-04 17:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2015-04-04 17:09 - 2015-04-04 17:09 - 00000000 ____D () C:\Program Files (x86)\Mp3tag
2015-04-04 17:08 - 2015-04-04 17:08 - 02802944 _____ () C:\Users\Basiliuws Eber\Downloads\mp3tagv269setup.exe
2015-04-04 16:53 - 2015-04-04 16:53 - 00000823 _____ () C:\Users\Basiliuws Eber\Desktop\Far Cry 4 Gold Edition.lnk
2015-04-04 12:37 - 2015-04-04 12:37 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-04-04 12:37 - 2015-04-04 12:37 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-04 11:06 - 2015-04-04 16:57 - 00037174 _____ () C:\Windows\DirectX.log
2015-04-04 11:01 - 2015-04-06 17:11 - 00001404 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk
2015-04-04 11:01 - 2015-04-04 11:01 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\NVIDIA
2015-04-04 11:01 - 2015-03-28 05:44 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2015-04-04 11:01 - 2015-03-28 05:44 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2015-04-04 11:01 - 2015-03-28 05:43 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2015-04-04 11:01 - 2015-03-28 05:43 - 01570672 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2015-04-04 11:01 - 2014-11-22 12:46 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2015-04-04 11:01 - 2014-11-22 12:46 - 00035472 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2015-04-04 11:01 - 2014-11-22 12:46 - 00032400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2015-04-04 11:00 - 2015-04-04 11:00 - 36450560 _____ (NVIDIA Corporation) C:\Users\Basiliuws Eber\Downloads\GeForce_Experience_v2.4.1.21.exe
2015-04-03 16:08 - 2015-04-03 16:08 - 00000222 _____ () C:\Users\Basiliuws Eber\Desktop\Far Cry 3 Blood Dragon.url
2015-04-02 14:57 - 2015-04-02 14:57 - 00000000 ____D () C:\ProgramData\Gibraltar
2015-04-02 13:48 - 2015-04-02 13:48 - 00002267 _____ () C:\Users\Basiliuws Eber\Downloads\Lesch2014deutsche.bib
2015-04-01 21:23 - 2015-04-01 21:23 - 00001846 _____ () C:\DelFix.txt
2015-04-01 21:23 - 2015-04-01 21:23 - 00000000 ____D () C:\Windows\ERUNT
2015-04-01 20:55 - 2015-04-01 20:55 - 00781312 _____ () C:\Users\Basiliuws Eber\Downloads\delfix_10.9.exe
2015-04-01 20:29 - 2015-04-01 20:29 - 00000000 ____D () C:\Users\Basiliuws Eber\Desktop\ProcessExplorer
2015-04-01 20:28 - 2015-04-01 20:29 - 01125626 _____ () C:\Users\Basiliuws Eber\Downloads\ProcessExplorer.zip
2015-04-01 18:30 - 2015-03-16 16:38 - 01713824 _____ (techPowerUp (www.techpowerup.com)) C:\Users\Basiliuws Eber\Downloads\GPU-Z.0.8.2.exe
2015-04-01 18:30 - 2007-02-18 04:34 - 00000140 _____ () C:\Users\Basiliuws Eber\Downloads\SysProfile.de--Dein_Systemprofil_online.url
2015-04-01 18:29 - 2015-04-01 18:29 - 00109549 _____ () C:\Users\Basiliuws Eber\Documents\BASILGAMING.txt
2015-04-01 18:25 - 2015-04-01 18:26 - 01582736 _____ ( ) C:\Users\Basiliuws Eber\Downloads\cpu-z_1.72-en.exe
2015-04-01 18:11 - 2015-04-01 18:11 - 08146560 _____ (TeamViewer GmbH) C:\Users\Basiliuws Eber\Downloads\TeamViewer_Setup.exe
2015-03-31 13:20 - 2015-03-31 13:22 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\2015-03-31
2015-03-31 11:17 - 2015-03-31 11:17 - 00000504 _____ () C:\Users\Basiliuws Eber\Downloads\Chip.txt
2015-03-31 10:51 - 2015-03-31 10:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-03-31 10:50 - 2015-03-31 10:50 - 00880208 _____ (Google Inc.) C:\Users\Basiliuws Eber\Downloads\ChromeSetup.exe
2015-03-31 10:45 - 2015-03-31 10:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Basiliuws Eber\Downloads\revosetup95.exe
2015-03-31 10:45 - 2015-03-31 10:45 - 00001291 _____ () C:\Users\Basiliuws Eber\Desktop\Revo Uninstaller.lnk
2015-03-31 10:45 - 2015-03-31 10:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-03-30 19:35 - 2015-03-30 19:35 - 00008793 _____ () C:\Users\Basiliuws Eber\Downloads\28.3.2015 10-07.kmz
2015-03-30 18:33 - 2015-03-30 18:35 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\2015-03-30
2015-03-30 16:24 - 2015-03-30 16:24 - 13087456 _____ (Microsoft Corporation) C:\Users\Basiliuws Eber\Downloads\Silverlight_x64.exe
2015-03-30 14:23 - 2015-03-30 14:23 - 00000165 _____ () C:\Users\Basiliuws Eber\Downloads\scholar.enw
2015-03-30 08:39 - 2015-04-01 20:49 - 00000000 ____D () C:\Program Files (x86)\Universal Media Server
2015-03-30 08:39 - 2015-04-01 18:09 - 00000000 ____D () C:\ProgramData\UMS
2015-03-30 08:39 - 2015-03-30 09:01 - 00001951 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Universal Media Server.lnk
2015-03-30 08:39 - 2015-03-30 09:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Universal Media Server
2015-03-30 08:39 - 2015-03-30 08:39 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth
2015-03-30 08:39 - 2015-03-30 08:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth
2015-03-30 08:38 - 2015-03-30 08:38 - 60871278 _____ () C:\Users\Basiliuws Eber\Downloads\UMS-5.1.0-Java7.exe
2015-03-29 22:09 - 2015-03-29 22:09 - 00000000 ____D () C:\ProgramData\Creative Labs
2015-03-29 22:02 - 2015-03-29 22:02 - 00000000 ____D () C:\Program Files (x86)\OpenAL
2015-03-28 19:41 - 2015-03-28 19:41 - 00000504 _____ () C:\Users\Basiliuws Eber\Downloads\regfix.reg
2015-03-27 01:46 - 2015-03-27 01:46 - 00001209 _____ () C:\Users\Basiliuws Eber\Downloads\HTC Support Chat.txt
2015-03-26 09:47 - 2015-03-26 09:52 - 00000000 ____D () C:\Users\Basiliuws Eber\Downloads\Garmin Blitzer
2015-03-26 09:31 - 2015-03-26 09:31 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Garmin
2015-03-26 09:23 - 2015-03-26 09:23 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Mein Garmin
2015-03-26 09:23 - 2015-03-26 09:23 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Garmin
2015-03-26 09:20 - 2015-03-26 09:20 - 00003556 _____ () C:\Windows\System32\Tasks\GarminUpdaterTask
2015-03-26 09:20 - 2015-03-26 09:20 - 00001911 _____ () C:\Users\Public\Desktop\Garmin Express.lnk
2015-03-26 09:19 - 2015-03-26 09:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2015-03-26 09:16 - 2015-03-26 09:16 - 00000319 _____ () C:\Users\Basiliuws Eber\Downloads\Garmin-InternetExplorer-Shortcut.vbs
2015-03-26 09:03 - 2015-04-12 16:08 - 00007356 _____ () C:\Windows\PFRO.log
2015-03-25 22:37 - 2015-03-26 00:45 - 00000000 ____D () C:\ProgramData\boost_interprocess
2015-03-25 22:33 - 2015-03-25 22:33 - 00001364 _____ () C:\Users\Public\Desktop\NAVIGON Fresh.lnk
2015-03-25 22:33 - 2015-03-25 22:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NAVIGON
2015-03-25 22:33 - 2015-03-25 22:33 - 00000000 ____D () C:\Program Files (x86)\NAVIGON
2015-03-25 22:30 - 2015-03-25 22:30 - 24192080 _____ (GARMIN Würzburg GmbH) C:\Users\Basiliuws Eber\Downloads\ud_setup_win_351.exe
2015-03-25 22:13 - 2015-03-25 22:13 - 01917440 _____ () C:\Users\Basiliuws Eber\Downloads\XmlNotepad25.msi
2015-03-25 22:13 - 2015-03-25 22:13 - 00001950 _____ () C:\Users\Basiliuws Eber\Desktop\XML Notepad 2007.lnk
2015-03-25 22:13 - 2015-03-25 22:13 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XML Notepad 2007
2015-03-25 22:13 - 2015-03-25 22:13 - 00000000 ____D () C:\Program Files (x86)\XML Notepad 2007
2015-03-25 15:15 - 2015-03-25 15:15 - 00030950 _____ () C:\Windows\DPINST.LOG
2015-03-25 15:04 - 2015-04-12 16:08 - 00009963 _____ () C:\Windows\setupact.log
2015-03-25 15:04 - 2015-03-25 15:04 - 03344552 _____ (Cisco Systems, Inc.) C:\Users\Basiliuws Eber\Downloads\anyconnect-win-3.1.06073-web-deploy-k9.exe
2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Cisco
2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco
2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\ProgramData\Cisco
2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\Program Files (x86)\Cisco
2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 _____ () C:\Windows\setuperr.log
2015-03-25 15:04 - 2014-11-19 17:09 - 00112496 ____R (Cisco Systems, Inc.) C:\Windows\system32\Drivers\acsock64.sys
2015-03-25 14:53 - 2015-04-12 16:30 - 01445431 _____ () C:\Windows\WindowsUpdate.log
2015-03-25 10:26 - 2015-03-11 04:38 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-03-25 10:26 - 2015-03-11 00:08 - 01107456 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-03-25 10:26 - 2015-03-11 00:08 - 00943104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-03-25 10:26 - 2015-03-11 00:08 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-03-25 10:26 - 2015-03-11 00:08 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-03-25 10:26 - 2015-03-11 00:08 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-03-25 10:26 - 2015-03-11 00:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-03-24 18:02 - 2015-03-24 18:02 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Swiss Academic Software
         
Code:
ATTFilter
2015-03-24 17:54 - 2015-04-12 16:23 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Citavi 4
2015-03-24 17:54 - 2015-04-10 01:21 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Swiss Academic Software
2015-03-24 17:54 - 2015-04-02 13:43 - 00000000 ____D () C:\ProgramData\Swiss Academic Software
2015-03-24 17:51 - 2015-03-24 17:51 - 00001972 _____ () C:\Users\Public\Desktop\Citavi 4.lnk
2015-03-24 17:51 - 2015-03-24 17:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citavi 4
2015-03-24 17:51 - 2015-03-24 17:51 - 00000000 ____D () C:\Program Files (x86)\Citavi 4
2015-03-24 17:40 - 2015-03-24 17:41 - 81307064 _____ (Swiss Academic Software) C:\Users\Basiliuws Eber\Downloads\Citavi4Setup.exe
2015-03-24 13:33 - 2007-08-11 15:38 - 00810952 _____ (Charles DeWeese) C:\Users\Basiliuws Eber\Downloads\FlashSfv.exe
2015-03-24 13:13 - 2015-03-24 13:13 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2015-03-24 13:13 - 2015-03-24 13:13 - 00000000 ____D () C:\Program Files\Java
2015-03-24 13:12 - 2015-03-24 13:12 - 42925480 _____ (Oracle Corporation) C:\Users\Basiliuws Eber\Downloads\jre-8u40-windows-x64.exe
2015-03-24 12:35 - 2015-03-24 15:26 - 00000000 ____D () C:\Program Files (x86)\Dr. Hardware 2015
2015-03-24 12:35 - 2015-03-24 12:35 - 00001003 _____ () C:\Users\Basiliuws Eber\Desktop\Dr. Hardware 2015.lnk
2015-03-24 12:35 - 2015-03-24 12:35 - 00001003 _____ () C:\Users\Basilius Eberle\Desktop\Dr. Hardware 2015.lnk
2015-03-24 12:35 - 2015-03-24 12:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dr. Hardware 2015
2015-03-24 12:35 - 2013-07-21 18:41 - 00013760 _____ () C:\Windows\SysWOW64\Drivers\DRHMSR64.sys
2015-03-24 12:35 - 2013-07-21 18:41 - 00013760 _____ () C:\Windows\system32\Drivers\DRHMSR64.sys
2015-03-24 12:35 - 2011-11-03 19:05 - 00021984 _____ (Licensed for Gebhard Software) C:\Windows\SysWOW64\Drivers\DRHARD64.sys
2015-03-24 12:35 - 2011-11-03 19:05 - 00021984 _____ (Licensed for Gebhard Software) C:\Windows\system32\Drivers\DRHARD64.sys
2015-03-24 11:37 - 2015-03-24 11:37 - 11800240 _____ () C:\Users\Basiliuws Eber\Downloads\SetupAnyDVD7590.exe
2015-03-23 09:48 - 2015-03-23 09:48 - 00001732 _____ () C:\Users\Public\Desktop\iTunes.lnk
2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\Program Files\iTunes
2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\Program Files\iPod
2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-03-22 23:27 - 2015-03-22 23:27 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-03-22 23:27 - 2015-03-22 23:27 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-03-20 09:53 - 2015-03-20 09:53 - 00000197 _____ () C:\Windows\system32\2015-03-20-07-53-19.037-AvastVBoxSVC.exe-3568.log
2015-03-20 09:09 - 2015-03-20 09:09 - 00000197 _____ () C:\Windows\system32\2015-03-20-07-09-20.093-AvastVBoxSVC.exe-3640.log
2015-03-20 00:56 - 2015-03-20 00:56 - 00000247 _____ () C:\Windows\system32\2015-03-19-22-56-47.018-aswFe.exe-5100.log
2015-03-20 00:55 - 2015-03-20 00:56 - 00000247 _____ () C:\Windows\system32\2015-03-19-22-55-00.053-aswFe.exe-892.log
2015-03-20 00:54 - 2015-03-20 00:54 - 00000197 _____ () C:\Windows\system32\2015-03-19-22-54-59.047-AvastVBoxSVC.exe-3240.log
2015-03-20 00:44 - 2015-03-20 00:44 - 00588816 _____ () C:\Users\Basiliuws Eber\Downloads\Autoruns.zip
2015-03-20 00:44 - 2015-03-20 00:44 - 00000000 ____D () C:\Users\Basiliuws Eber\Downloads\Autoruns
2015-03-20 00:27 - 2015-03-20 00:27 - 05325696 _____ (Piriform Ltd) C:\Users\Basiliuws Eber\Downloads\ccsetup503.exe
2015-03-18 15:06 - 2015-03-20 00:49 - 00001540 _____ () C:\Users\Basiliuws Eber\Downloads\malwarebytes.txt
2015-03-18 14:54 - 2015-03-18 14:54 - 00000197 _____ () C:\Windows\system32\2015-03-18-12-54-46.089-AvastVBoxSVC.exe-3700.log
2015-03-18 14:53 - 2015-03-18 14:53 - 00000358 _____ () C:\Windows\system32\.crusader
2015-03-18 14:23 - 2015-03-18 14:23 - 00000247 _____ () C:\Windows\system32\2015-03-18-12-23-15.080-aswFe.exe-7992.log
2015-03-18 14:21 - 2015-03-18 14:23 - 00000247 _____ () C:\Windows\system32\2015-03-18-12-21-12.001-aswFe.exe-3104.log
2015-03-18 14:21 - 2015-03-18 14:21 - 00000197 _____ () C:\Windows\system32\2015-03-18-12-21-10.073-AvastVBoxSVC.exe-956.log
2015-03-18 13:04 - 2015-03-18 13:04 - 02953520 _____ (AVAST Software) C:\Users\Basiliuws Eber\Downloads\avast-browser-cleanup.exe
2015-03-18 12:31 - 2015-01-29 15:24 - 00221184 _____ (CACE Technologies) C:\Windows\SysWOW64\devolopcap.dll
2015-03-18 12:31 - 2015-01-29 15:24 - 00081920 _____ (CACE Technologies) C:\Windows\SysWOW64\devolopacket.dll
2015-03-18 12:31 - 2015-01-29 15:24 - 00034048 _____ (CACE Technologies) C:\Windows\SysWOW64\Drivers\npf_devolo.sys
2015-03-18 11:04 - 2015-03-18 11:05 - 00000197 _____ () C:\Windows\system32\2015-03-18-09-04-59.098-AvastVBoxSVC.exe-3500.log
2015-03-18 10:50 - 2015-03-18 10:50 - 00000197 _____ () C:\Windows\system32\2015-03-18-08-50-08.045-AvastVBoxSVC.exe-3460.log
2015-03-18 10:46 - 2015-03-18 10:46 - 00001178 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk
2015-03-18 10:46 - 2015-03-18 10:46 - 00001128 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2015-03-18 10:46 - 2015-03-18 10:46 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Canneverbe Limited
2015-03-18 10:46 - 2015-03-18 10:46 - 00000000 ____D () C:\ProgramData\Canneverbe Limited
2015-03-18 10:46 - 2015-03-18 10:46 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP
2015-03-18 10:45 - 2015-03-18 10:45 - 05409016 _____ (Canneverbe Limited ) C:\Users\Basiliuws Eber\Downloads\cdbxp_setup_4.5.4.5306_minimal.exe
2015-03-17 23:37 - 2015-03-17 23:36 - 03312872 _____ (DVDVideoSoft Ltd. ) C:\Users\Basiliuws
2015-03-17 23:36 - 2015-03-18 09:55 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\DVDVideoSoft
2015-03-17 11:03 - 2015-03-17 11:03 - 00005364 _____ () C:\Users\Basiliuws Eber\Downloads\13.3.2015 19-50.kmz
2015-03-16 19:43 - 2015-03-16 19:43 - 00000197 _____ () C:\Windows\system32\2015-03-16-17-43-42.097-AvastVBoxSVC.exe-3712.log
2015-03-16 11:50 - 2015-03-16 11:50 - 19759661 _____ () C:\Users\Basiliuws Eber\Downloads\SpringBloomsRebeccaHeigel.themepack
2015-03-15 21:35 - 2015-03-15 21:35 - 00000197 _____ () C:\Windows\system32\2015-03-15-19-35-41.095-AvastVBoxSVC.exe-3548.log
2015-03-15 21:26 - 2015-03-15 21:26 - 00000000 ____D () C:\Users\Basiliuws Eber\Tracing
2015-03-15 21:24 - 2015-03-15 21:26 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-03-15 21:24 - 2015-03-15 21:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-03-15 21:06 - 2015-03-15 21:07 - 00000197 _____ () C:\Windows\system32\2015-03-15-19-06-30.070-AvastVBoxSVC.exe-3456.log
2015-03-15 20:57 - 2015-03-15 20:58 - 00000197 _____ () C:\Windows\system32\2015-03-15-18-57-47.015-AvastVBoxSVC.exe-3552.log
2015-03-14 19:09 - 2015-03-06 04:53 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-14 19:09 - 2015-03-06 04:33 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-03-14 19:09 - 2015-02-26 01:26 - 04178944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-14 19:09 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-14 19:09 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-03-14 19:09 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-03-14 19:09 - 2015-02-21 02:27 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-03-14 19:09 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-03-14 19:09 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-14 19:09 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-03-14 19:09 - 2015-02-20 05:03 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-14 19:09 - 2015-02-20 04:58 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-14 19:09 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-14 19:09 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-14 19:09 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-14 19:09 - 2015-02-20 04:35 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-03-14 19:09 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-14 19:09 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-14 19:09 - 2015-02-20 04:20 - 00301056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-03-14 19:09 - 2015-02-20 04:15 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-03-14 19:09 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-03-14 19:09 - 2015-02-20 04:07 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-03-14 19:09 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-03-14 19:09 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-14 19:09 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-03-14 19:09 - 2015-02-20 03:59 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-03-14 19:09 - 2015-02-20 03:56 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-03-14 19:09 - 2015-02-20 03:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-03-14 19:09 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-14 19:09 - 2015-02-20 03:49 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-14 19:09 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-14 19:09 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-14 19:09 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-03-14 19:09 - 2015-02-20 03:30 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-03-14 19:09 - 2015-02-20 03:29 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2015-03-14 19:09 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-14 19:09 - 2015-02-20 03:26 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-03-14 19:09 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-03-14 19:09 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-03-14 19:09 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-14 19:09 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-14 19:09 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-03-14 19:09 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-03-14 19:09 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-03-14 19:09 - 2015-02-07 01:09 - 00396419 _____ () C:\Windows\system32\ApnDatabase.xml
2015-03-14 19:09 - 2015-02-06 03:28 - 02257408 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-03-14 19:09 - 2015-02-06 03:08 - 01943040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-03-14 19:09 - 2015-02-05 22:24 - 01113920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-03-14 19:09 - 2015-02-04 01:58 - 00264000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2015-03-14 19:09 - 2015-02-04 01:58 - 00114496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdNisDrv.sys
2015-03-14 19:09 - 2015-02-04 01:58 - 00044024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2015-03-14 19:09 - 2015-02-03 02:03 - 03551744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2015-03-14 19:09 - 2015-02-03 02:02 - 04298240 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2015-03-14 19:09 - 2015-02-03 01:53 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\winshfhc.dll
2015-03-14 19:09 - 2015-02-03 01:53 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winshfhc.dll
2015-03-14 19:09 - 2015-01-31 01:42 - 03097600 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2015-03-14 19:09 - 2015-01-31 01:29 - 02484224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2015-03-14 19:09 - 2015-01-31 01:20 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-14 19:09 - 2015-01-30 05:01 - 00097792 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidbth.sys
2015-03-14 19:09 - 2015-01-30 05:00 - 00167424 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\rfcomm.sys
2015-03-14 19:09 - 2015-01-30 04:03 - 01488896 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2015-03-14 19:09 - 2015-01-30 04:03 - 01464832 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2015-03-14 19:09 - 2015-01-30 04:02 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll
2015-03-14 19:09 - 2015-01-30 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll
2015-03-14 19:09 - 2015-01-30 03:42 - 01204224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll
2015-03-14 19:09 - 2015-01-30 03:40 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappgnui.dll
2015-03-14 19:09 - 2015-01-30 03:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll
2015-03-14 19:09 - 2015-01-30 03:29 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atlthunk.dll
2015-03-14 19:09 - 2015-01-30 03:24 - 00339456 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll
2015-03-14 19:09 - 2015-01-30 03:24 - 00250880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapp3hst.dll
2015-03-14 19:09 - 2015-01-30 03:16 - 00266752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapphost.dll
2015-03-14 19:09 - 2015-01-30 03:08 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll
2015-03-14 19:09 - 2015-01-30 03:06 - 00278016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappcfg.dll
2015-03-14 19:09 - 2015-01-29 03:58 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll
2015-03-14 19:09 - 2015-01-29 03:29 - 00290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\photowiz.dll
2015-03-14 19:09 - 2015-01-29 03:11 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-14 19:09 - 2015-01-29 03:04 - 01091072 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2015-03-14 19:09 - 2015-01-29 03:04 - 00864256 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2015-03-14 19:09 - 2015-01-29 03:00 - 00210944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-14 19:09 - 2015-01-29 02:59 - 02773504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-03-14 19:09 - 2015-01-29 02:55 - 00971776 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2015-03-14 19:09 - 2015-01-29 02:50 - 00811008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2015-03-14 19:09 - 2015-01-29 02:49 - 02459136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-03-14 19:09 - 2015-01-28 17:41 - 07472960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-14 19:09 - 2015-01-28 17:41 - 01733440 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-03-14 19:09 - 2015-01-28 17:41 - 01498360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-03-14 19:09 - 2015-01-28 04:24 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\StorageContextHandler.dll
2015-03-14 19:09 - 2015-01-28 03:47 - 00060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StorageContextHandler.dll
2015-03-14 19:09 - 2015-01-27 06:22 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-03-14 19:09 - 2015-01-27 05:44 - 00933888 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe
2015-03-14 19:09 - 2015-01-27 04:11 - 03547648 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-03-14 19:09 - 2015-01-24 03:51 - 00816128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\calc.exe
2015-03-14 19:09 - 2015-01-23 09:17 - 00723072 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2015-03-14 19:09 - 2015-01-23 07:02 - 00560392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2015-03-14 19:08 - 2015-02-12 19:40 - 22291584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-14 19:08 - 2015-02-12 19:34 - 19731824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-03-14 19:08 - 2015-02-08 01:57 - 01090048 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2015-03-14 19:08 - 2015-02-08 01:49 - 00791040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
2015-03-14 19:08 - 2015-01-29 20:45 - 01763352 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-14 19:08 - 2015-01-29 20:34 - 01488040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-03-14 19:08 - 2015-01-28 03:31 - 00402432 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-14 19:08 - 2015-01-28 03:11 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2015-03-14 19:08 - 2015-01-28 01:47 - 02501368 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2015-03-14 19:08 - 2015-01-28 01:41 - 02207488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2015-03-14 19:08 - 2015-01-21 07:54 - 01384712 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-14 19:08 - 2015-01-21 07:15 - 01123848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2015-03-14 19:08 - 2014-12-11 07:36 - 00046456 _____ (Microsoft Corporation) C:\Windows\system32\LockScreenContentServer.exe
2015-03-14 19:06 - 2015-03-14 19:06 - 00000197 _____ () C:\Windows\system32\2015-03-14-17-06-15.019-AvastVBoxSVC.exe-3404.log
2015-03-14 07:49 - 2015-03-14 07:49 - 00009728 _____ (Razer Inc.) C:\Windows\SysWOW64\RzStats.IPC.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-12 16:34 - 2014-05-31 12:19 - 00000000 ____D () C:\Program Files (x86)\Google
2015-04-12 16:22 - 2014-09-15 21:39 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-12 16:19 - 2014-05-31 15:38 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\ClassicShell
2015-04-12 16:14 - 2014-05-31 17:26 - 01789004 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-12 16:14 - 2014-05-31 11:30 - 00003978 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{ADF8F266-BC9E-412C-B8EE-DDA5E6A3C8C5}
2015-04-12 16:14 - 2013-08-23 01:24 - 00768888 _____ () C:\Windows\system32\perfh007.dat
2015-04-12 16:14 - 2013-08-23 01:24 - 00160706 _____ () C:\Windows\system32\perfc007.dat
2015-04-12 16:10 - 2014-12-25 15:31 - 00006533 _____ () C:\Windows\SysWOW64\Gms.log
2015-04-12 16:09 - 2014-11-30 14:35 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\HTC MediaHub
2015-04-12 16:09 - 2014-05-31 17:23 - 00000000 ____D () C:\Users\Basiliuws Eber
2015-04-12 16:09 - 2014-05-31 13:33 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox
2015-04-12 16:09 - 2014-05-31 12:28 - 00000000 ___DO () C:\Users\Basiliuws Eber\SkyDrive
2015-04-12 16:09 - 2014-05-31 12:19 - 00001138 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-12 16:09 - 2014-05-31 11:33 - 00000000 ____D () C:\Users\Basilius Eberle
2015-04-12 16:08 - 2014-05-31 12:22 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2015-04-12 16:08 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-12 16:04 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2015-04-12 01:58 - 2014-12-07 16:02 - 00001180 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2245731289-3221781707-2474736645-1001UA.job
2015-04-12 01:44 - 2014-05-31 12:19 - 00001142 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-12 01:43 - 2014-08-03 20:04 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-11 22:58 - 2014-12-07 16:02 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2245731289-3221781707-2474736645-1001Core.job
2015-04-11 20:44 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-04-11 20:00 - 2015-03-03 11:18 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\JDownloader 2.0
2015-04-11 13:15 - 2014-06-03 16:35 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\vlc
2015-04-11 01:26 - 2014-05-31 16:21 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-04-11 01:24 - 2014-06-01 12:04 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2015-04-11 01:24 - 2014-06-01 12:00 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-04-11 00:34 - 2014-05-31 17:28 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2245731289-3221781707-2474736645-1001
2015-04-10 09:36 - 2014-05-31 13:37 - 00001105 _____ () C:\Users\Basiliuws Eber\Desktop\Dropbox.lnk
2015-04-10 09:36 - 2014-05-31 13:35 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-04-10 04:40 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\LiveKernelReports
2015-04-09 19:49 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF
2015-04-08 13:22 - 2015-01-11 20:23 - 00003858 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1421000576
2015-04-08 13:22 - 2015-01-11 20:22 - 00001070 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-04-08 13:22 - 2015-01-11 20:22 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-04-06 17:02 - 2014-08-23 19:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-04-06 17:01 - 2014-08-23 19:21 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2015-04-06 17:01 - 2014-08-23 19:20 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2015-04-06 17:01 - 2014-05-31 17:47 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2015-04-06 17:01 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\Help
2015-04-06 08:45 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-04-05 18:24 - 2014-06-01 10:42 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\my games
2015-04-04 12:37 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp
2015-04-04 11:37 - 2014-06-01 15:26 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\My Games
2015-04-04 11:01 - 2014-08-23 19:44 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\NVIDIA Corporation
2015-04-03 23:39 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\Vss
2015-04-03 16:08 - 2014-05-31 16:49 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-04-01 18:26 - 2014-06-01 16:00 - 00000852 _____ () C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2015-04-01 18:20 - 2014-06-01 10:50 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-04-01 18:20 - 2014-06-01 10:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-04-01 18:20 - 2014-06-01 10:50 - 00000000 ____D () C:\Program Files\WinRAR
2015-04-01 18:12 - 2014-10-20 21:45 - 00001201 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2015-04-01 18:12 - 2014-10-20 21:45 - 00001189 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2015-03-31 13:21 - 2014-07-08 21:58 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Canon
2015-03-31 11:04 - 2014-06-01 20:09 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Skype
2015-03-31 10:51 - 2014-05-31 12:19 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Google
2015-03-31 10:44 - 2014-08-04 09:41 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Adobe
2015-03-31 10:44 - 2014-08-03 20:04 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-03-30 22:51 - 2014-07-08 21:58 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\2014-07-08
2015-03-30 22:48 - 2015-01-25 13:42 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Congstar Rechnungen
2015-03-30 08:39 - 2014-06-03 13:58 - 00000000 ____D () C:\Program Files (x86)\AviSynth 2.5
2015-03-27 01:12 - 2014-09-15 21:39 - 00001125 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-03-27 01:12 - 2014-09-15 21:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-03-27 01:12 - 2014-09-15 21:39 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-03-26 23:49 - 2014-08-22 00:44 - 00005468 _____ () C:\Users\Basiliuws Eber\Documents\Database.kdb
2015-03-26 09:23 - 2014-06-09 10:10 - 00000000 ____D () C:\ProgramData\Garmin
2015-03-26 09:23 - 2014-06-09 09:58 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Garmin
2015-03-26 09:23 - 2014-06-09 09:58 - 00000000 ____D () C:\Program Files (x86)\Garmin
2015-03-26 09:20 - 2014-06-09 10:10 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Garmin
2015-03-26 09:20 - 2014-05-31 11:35 - 00000000 ____D () C:\ProgramData\Package Cache
2015-03-26 00:52 - 2014-12-10 00:39 - 00000000 ____D () C:\Windows\system32\appraiser
2015-03-26 00:52 - 2014-07-12 10:21 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-03-25 23:27 - 2014-05-31 17:23 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Adobe
2015-03-25 15:16 - 2014-11-30 14:34 - 00002054 _____ () C:\Users\Public\Desktop\HTC Sync Manager.lnk
2015-03-25 15:15 - 2014-05-31 11:59 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Downloaded Installations
2015-03-25 14:24 - 2014-11-24 15:43 - 00031232 ___SH () C:\Users\Basiliuws Eber\Desktop\Thumbs.db
2015-03-25 14:09 - 2014-06-16 17:11 - 00000000 ____D () C:\Windows\Minidump
2015-03-25 14:09 - 2014-06-01 20:03 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\TS3Client
2015-03-24 13:33 - 2014-06-16 12:00 - 00000000 ____D () C:\Users\Basiliuws Eber\Downloads\CyberLink PowerDVD Ultra 14.0.4028.58
2015-03-24 13:30 - 2014-06-09 11:37 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\OMC ModPack
2015-03-24 13:13 - 2014-10-26 21:18 - 00000000 ____D () C:\Program Files (x86)\Java
2015-03-24 12:44 - 2014-06-01 18:41 - 00000000 ____D () C:\Program Files (x86)\SpeedFan
2015-03-24 11:37 - 2014-06-03 13:50 - 00001128 _____ () C:\Users\Public\Desktop\AnyDVD.lnk
2015-03-24 11:33 - 2014-05-31 12:04 - 00000000 ____D () C:\ProgramData\CyberLink
2015-03-24 11:32 - 2014-06-16 12:23 - 00000000 ____D () C:\ProgramData\SUPPORTDIR
2015-03-23 09:48 - 2014-06-20 10:52 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2015-03-23 09:48 - 2014-06-20 10:51 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-03-22 23:27 - 2014-05-31 13:31 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-03-22 23:27 - 2014-05-31 13:31 - 00441728 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys
2015-03-22 23:27 - 2014-05-31 13:31 - 00268640 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-03-22 23:27 - 2014-05-31 13:31 - 00136752 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-03-22 23:27 - 2014-05-31 13:31 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-03-22 23:27 - 2014-05-31 13:31 - 00088408 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-03-22 23:27 - 2014-05-31 13:31 - 00065736 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-03-22 23:27 - 2014-05-31 13:31 - 00029168 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-03-22 23:27 - 2014-05-31 13:31 - 00003924 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-03-22 23:12 - 2014-06-01 15:26 - 00125664 _____ () C:\Users\Basiliuws Eber\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-20 11:16 - 2014-05-31 11:46 - 01807894 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-03-20 09:07 - 2013-08-22 16:44 - 00492672 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-20 01:08 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache
2015-03-20 00:27 - 2014-05-31 16:19 - 00000801 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-03-20 00:27 - 2014-05-31 16:19 - 00000000 ____D () C:\Program Files\CCleaner
2015-03-18 14:53 - 2014-09-15 21:53 - 00000000 ____D () C:\ProgramData\HitmanPro
2015-03-18 14:17 - 2014-08-24 18:44 - 00000000 ____D () C:\Temp
2015-03-18 12:32 - 2015-01-24 13:45 - 00000000 ____D () C:\Program Files (x86)\devolo
2015-03-18 10:47 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\Performance
2015-03-18 09:56 - 2014-05-31 11:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2015-03-17 11:17 - 2014-09-16 19:05 - 00019968 _____ () C:\Users\Basiliuws Eber\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-03-17 07:15 - 2014-09-15 21:39 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-03-17 07:15 - 2014-09-15 21:39 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-03-17 07:15 - 2014-09-15 21:39 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData
2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\WinStore
2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender
2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-03-15 21:26 - 2014-06-01 20:09 - 00000000 ____D () C:\ProgramData\Skype
2015-03-15 21:24 - 2014-06-01 20:09 - 00002715 _____ () C:\Users\Public\Desktop\Skype.lnk
2015-03-14 23:21 - 2014-05-31 18:34 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-14 23:21 - 2014-05-31 14:17 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-14 23:18 - 2014-05-31 14:17 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

==================== Files in the root of some directories =======

2014-09-16 19:05 - 2015-03-17 11:17 - 0019968 _____ () C:\Users\Basiliuws Eber\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-03 13:55 - 2014-06-16 14:35 - 0000040 ___SH () C:\ProgramData\.zreglib

Some content of TEMP:
====================
C:\Users\Basiliuws Eber\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp7zqszu.dll
C:\Users\Basiliuws Eber\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Basiliuws Eber\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Basiliuws Eber\AppData\Local\Temp\nvStInst.exe
C:\Users\Basiliuws Eber\AppData\Local\Temp\proxy_vole846848495695807889.dll
C:\Users\Basiliuws Eber\AppData\Local\Temp\Quarantine.exe
C:\Users\Basiliuws Eber\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-11 13:36

==================== End Of Log ============================
         
--- --- ---

Alt 13.04.2015, 08:27   #84
schrauber
/// the machine
/// TB-Ausbilder
 

Adware Roll around eingefangen - Standard

Adware Roll around eingefangen



Wenn Du Chrome nochmal neu installiert hast, nochmal deinstallieren mit Revo, dann die Ordner von Hand löschen. Alles von Chrome löschen was Du findest. Dann neu installierne und testen.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 13.04.2015, 15:27   #85
Bayer76
 

Adware Roll around eingefangen - Standard

Adware Roll around eingefangen



Habe ich soeben gemacht. Sabald ich Chroma aber neu installiere, findet er den Triovi wieder...
Nochmal zurück zu der Fehlermeldung ShellEecutEx fehlgeschlagen: Hatte heute wieder ca. 100 Pop Ups, besonders wenn der Geforce Treiber sich meldet.

Hier gibt es noch einen Thread dazu:

hxxp://www.modernboard.de/windows-7-probleme/117388-shellexecuteex-schlug-fehl-code-1155-a.html
und hier:
hxxp://www.gutefrage.net/frage/fehlermeldung-shellexecuteex-fehlgeschlagen-code-1155-hilfe#answers
Nur bringt mich das auch nicht weiter...

Alt 14.04.2015, 06:29   #86
schrauber
/// the machine
/// TB-Ausbilder
 

Adware Roll around eingefangen - Standard

Adware Roll around eingefangen



Mach bitte nochmal Systemlook:

:filefind
*Basiliuws Eber*
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 14.04.2015, 07:32   #87
Bayer76
 

Adware Roll around eingefangen - Standard

Adware Roll around eingefangen



Alles klar, hier die Ergebnisse...

Code:
ATTFilter
SystemLook 30.07.11 by jpshortstuff
Log created at 08:31 on 14/04/2015 by Basiliuws Eber
Administrator - Elevation successful

========== filefind ==========

Searching for "*Basiliuws Eber*"
C:\ProgramData\AVAST Software\Avast\RemoteCache\Basiliuws Eber.zip	--a---- 26624 bytes	[11:32 31/05/2014]	[16:36 19/08/2014] D456A3050CE1793C5F8A46A55759CE8B
C:\ProgramData\CanonBJ\IJPrinter\CNMWindows\Canon iP4800 series\Basiliuws Eber.pst	--a---- 3180 bytes	[10:00 08/07/2014]	[08:55 15/07/2014] AFB0B04272510F060BDA332FBCF06173
C:\ProgramData\CanonBJ\IJPrinter\CNMWindows\Canon iP4800 series\Canon iP4800 series\0002\cnmsm_Basiliuws Eber.dat	--a---- 364 bytes	[08:06 18/06/2014]	[16:21 31/07/2014] D8FDF9D9935913F5EB7D9A8000A752F0
C:\ProgramData\Microsoft\User Account Pictures\Basiliuws Eber.dat	--a---- 0 bytes	[15:23 31/05/2014]	[15:23 31/05/2014] D41D8CD98F00B204E9800998ECF8427E
C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log	--a---- 3751583 bytes	[08:56 14/11/2014]	[08:08 02/04/2015] 220CD66C8054081D75DC20B9725351F0
C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.01	--a---- 10000088 bytes	[08:56 14/11/2014]	[11:21 16/03/2015] BF9C976EF292AA9546AA213761872224
C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.02	--a---- 10000198 bytes	[08:56 14/11/2014]	[14:17 04/03/2015] 080780B938860EFDBCDC53AF84DF3C65
C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.03	--a---- 10000232 bytes	[08:56 14/11/2014]	[19:49 21/02/2015] C1982A85C27CC5E95FA6FC0E5BD7C766
C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.04	--a---- 10000220 bytes	[08:56 14/11/2014]	[20:07 07/02/2015] 4DE66B9401E90DE21F0438DF80B52B0B
C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.05	--a---- 10000106 bytes	[08:56 14/11/2014]	[15:03 23/01/2015] AD5FC300894A878CF7FA3A2D6F788846
C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.06	--a---- 10000016 bytes	[08:56 14/11/2014]	[22:37 16/01/2015] 6F670A19D062B03A4E14CF8C03315FC1
C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.07	--a---- 10000164 bytes	[08:56 14/11/2014]	[21:38 05/01/2015] 943BA12435A23713C903F297E5D9071F
C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.08	--a---- 10000116 bytes	[08:56 14/11/2014]	[14:07 30/12/2014] 5B32EC7F2D1B3EBD571533C50FACEB26
C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.09	--a---- 10000067 bytes	[08:56 14/11/2014]	[13:54 20/12/2014] B2EF72F7FE9537D91BCF610B88BAAB89
C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.10	--a---- 10000039 bytes	[08:56 14/11/2014]	[19:08 08/12/2014] A87863B94675B78685D38A414A4083B7
C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RzCefRenderProcess.log	--a---- 408719 bytes	[08:57 14/11/2014]	[07:54 18/03/2015] E55D7415DF87975F98569D8410580C42
C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RzStats.Manager.log	--a---- 5430049 bytes	[08:57 14/11/2014]	[07:55 18/03/2015] 9BD5520B456E058DD27D29FA469708E3
C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RzStats.Manager.log.01	--a---- 10000130 bytes	[08:57 14/11/2014]	[15:50 23/01/2015] 8E7E7C922AFBB68F8D9CB08410733A99
C:\ProgramData\Razer\Synapse\Logs\RzWizard_Basiliuws Eber.log	--a---- 1104 bytes	[09:32 31/05/2014]	[09:32 31/05/2014] 6AA1925076A785F440823EEC29598101
C:\ProgramData\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log	--a---- 3101866 bytes	[10:22 31/05/2014]	[06:15 14/04/2015] 84BBD5382961011C9EF67E6D48FE8C77
C:\ProgramData\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log.1	--a---- 5242895 bytes	[10:22 31/05/2014]	[21:02 23/03/2015] 2EE1C0FC802611909B3F4A94F3D64C5A
C:\ProgramData\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log.2	--a---- 5242939 bytes	[10:22 31/05/2014]	[21:53 06/02/2015] F37C36BCC94159082F1673DB0F30B7BE
C:\ProgramData\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log.3	--a---- 5242984 bytes	[10:22 31/05/2014]	[21:12 18/12/2014] 8EDDD4C9D827A8806D8D05CDAE78D8E4
C:\Users\All Users\AVAST Software\Avast\RemoteCache\Basiliuws Eber.zip	--a---- 26624 bytes	[11:32 31/05/2014]	[16:36 19/08/2014] D456A3050CE1793C5F8A46A55759CE8B
C:\Users\All Users\CanonBJ\IJPrinter\CNMWindows\Canon iP4800 series\Basiliuws Eber.pst	--a---- 3180 bytes	[10:00 08/07/2014]	[08:55 15/07/2014] AFB0B04272510F060BDA332FBCF06173
C:\Users\All Users\CanonBJ\IJPrinter\CNMWindows\Canon iP4800 series\Canon iP4800 series\0002\cnmsm_Basiliuws Eber.dat	--a---- 364 bytes	[08:06 18/06/2014]	[16:21 31/07/2014] D8FDF9D9935913F5EB7D9A8000A752F0
C:\Users\All Users\Microsoft\User Account Pictures\Basiliuws Eber.dat	--a---- 0 bytes	[15:23 31/05/2014]	[15:23 31/05/2014] D41D8CD98F00B204E9800998ECF8427E
C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log	--a---- 3751583 bytes	[08:56 14/11/2014]	[08:08 02/04/2015] 220CD66C8054081D75DC20B9725351F0
C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.01	--a---- 10000088 bytes	[08:56 14/11/2014]	[11:21 16/03/2015] BF9C976EF292AA9546AA213761872224
C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.02	--a---- 10000198 bytes	[08:56 14/11/2014]	[14:17 04/03/2015] 080780B938860EFDBCDC53AF84DF3C65
C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.03	--a---- 10000232 bytes	[08:56 14/11/2014]	[19:49 21/02/2015] C1982A85C27CC5E95FA6FC0E5BD7C766
C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.04	--a---- 10000220 bytes	[08:56 14/11/2014]	[20:07 07/02/2015] 4DE66B9401E90DE21F0438DF80B52B0B
C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.05	--a---- 10000106 bytes	[08:56 14/11/2014]	[15:03 23/01/2015] AD5FC300894A878CF7FA3A2D6F788846
C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.06	--a---- 10000016 bytes	[08:56 14/11/2014]	[22:37 16/01/2015] 6F670A19D062B03A4E14CF8C03315FC1
C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.07	--a---- 10000164 bytes	[08:56 14/11/2014]	[21:38 05/01/2015] 943BA12435A23713C903F297E5D9071F
C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.08	--a---- 10000116 bytes	[08:56 14/11/2014]	[14:07 30/12/2014] 5B32EC7F2D1B3EBD571533C50FACEB26
C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.09	--a---- 10000067 bytes	[08:56 14/11/2014]	[13:54 20/12/2014] B2EF72F7FE9537D91BCF610B88BAAB89
C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.10	--a---- 10000039 bytes	[08:56 14/11/2014]	[19:08 08/12/2014] A87863B94675B78685D38A414A4083B7
C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RzCefRenderProcess.log	--a---- 408719 bytes	[08:57 14/11/2014]	[07:54 18/03/2015] E55D7415DF87975F98569D8410580C42
C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RzStats.Manager.log	--a---- 5430049 bytes	[08:57 14/11/2014]	[07:55 18/03/2015] 9BD5520B456E058DD27D29FA469708E3
C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RzStats.Manager.log.01	--a---- 10000130 bytes	[08:57 14/11/2014]	[15:50 23/01/2015] 8E7E7C922AFBB68F8D9CB08410733A99
C:\Users\All Users\Razer\Synapse\Logs\RzWizard_Basiliuws Eber.log	--a---- 1104 bytes	[09:32 31/05/2014]	[09:32 31/05/2014] 6AA1925076A785F440823EEC29598101
C:\Users\All Users\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log	--a---- 3101866 bytes	[10:22 31/05/2014]	[06:15 14/04/2015] 84BBD5382961011C9EF67E6D48FE8C77
C:\Users\All Users\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log.1	--a---- 5242895 bytes	[10:22 31/05/2014]	[21:02 23/03/2015] 2EE1C0FC802611909B3F4A94F3D64C5A
C:\Users\All Users\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log.2	--a---- 5242939 bytes	[10:22 31/05/2014]	[21:53 06/02/2015] F37C36BCC94159082F1673DB0F30B7BE
C:\Users\All Users\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log.3	--a---- 5242984 bytes	[10:22 31/05/2014]	[21:12 18/12/2014] 8EDDD4C9D827A8806D8D05CDAE78D8E4
C:\Users\Basiliuws Eber\AppData\Local\Temp\Basiliuws Eber.bmp	--a---- 31832 bytes	[09:59 06/04/2015]	[22:42 13/04/2015] 8D6650CF35779429CC9D098BBED9133C

-= EOF =-
         

Alt 14.04.2015, 16:39   #88
schrauber
/// the machine
/// TB-Ausbilder
 

Adware Roll around eingefangen - Standard

Adware Roll around eingefangen



Komisch. Es muss in deinem Userordner ne Datei geben die einfach so heisst wie dein Benutzerkonto....
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 15.04.2015, 09:48   #89
Bayer76
 

Adware Roll around eingefangen - Standard

Adware Roll around eingefangen



Keine Ahnung. Jedenfalls öffnen Sich bei jedem Systemstart ca. 70-80 Prozesse: Setup/Uninstall. Alle verweisen auf .tmp Dateien in C:\Users\Basiliuws Eber\AppData\Local\Temp
Jeweils in Unterordnern wie is-0OGNV.tmp liegen dann immer Dateien, die gleich heißen:
Basiliuws.tmp
Es werden aber auch noch andere Prozesse gestartet:FreeYoutubeToMp3 Converter Setup.
Sie verweisen alle auf: C:\Users\basiliuws
Diese Datei hat keine Dateinamenerweiterung. Werde sie jetzt einmal löschen und schauen was passiert.


Bisher ist noch Ruhe mit den Pop Ups...

Alt 15.04.2015, 19:28   #90
schrauber
/// the machine
/// TB-Ausbilder
 

Adware Roll around eingefangen - Standard

Adware Roll around eingefangen



Die hatte keine Dateiendung?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Adware Roll around eingefangen
beseitigung, cc cleaner, dvdvideosoft ltd., fehlercode, fehlercode 0x80070057, fehlercode 0xc0000005, fehlercode 0xc0000142, fehlercode 0xc0000409, fehlercode windows, fehlermeldung, fehlermeldungen, pup.optional.trovi.a, roll around, shellexecuteex fehlgeschlagen, software, this device is disabled. (code 22), tracking, win32/browsefox.af, win32/downloadsponsor.c, win32/downware.l, win32/installmonetizer.aq, win32/packed.vmprotect.abd, win64/systweak.a




Ähnliche Themen: Adware Roll around eingefangen


  1. Adware eingefangen
    Log-Analyse und Auswertung - 10.06.2015 (7)
  2. Roll Around Virus eingefangen
    Plagegeister aller Art und deren Bekämpfung - 08.05.2015 (65)
  3. Windows 8.1: Adware eingefangen (Delta)?
    Log-Analyse und Auswertung - 01.04.2015 (7)
  4. Roll Around Ads/ Win 8 eingefangen
    Plagegeister aller Art und deren Bekämpfung - 24.03.2015 (13)
  5. Adware eingefangen! Sämtliche Viren/Adware-Scanner finden nichts.
    Log-Analyse und Auswertung - 23.03.2015 (18)
  6. Roll-Around Virus/Adware bei Win 8.1 eingefangen
    Plagegeister aller Art und deren Bekämpfung - 13.03.2015 (9)
  7. Windows 7, Adware eingefangen (Digisaver etc.)
    Log-Analyse und Auswertung - 13.03.2015 (21)
  8. Roll Around Virus eingefangen
    Plagegeister aller Art und deren Bekämpfung - 05.03.2015 (9)
  9. Windows 7: Adware eingefangen
    Log-Analyse und Auswertung - 22.10.2014 (19)
  10. Trojaner gefunden TR/Dldr.Agent.314440 und verschiedene Adwares ADWARE/EoRezo.AF, ADWARE/Adware.Gen7, ADWARE/AgentCV.A.2919
    Log-Analyse und Auswertung - 02.05.2014 (19)
  11. ADWARE.gen2 Malware eingefangen
    Plagegeister aller Art und deren Bekämpfung - 09.04.2014 (3)
  12. Hab mir Adware Bettersurf Win32 eingefangen, eine Adware die unerwünschte Werbungen im Browser aufzeigt, siehe Beschreibung
    Log-Analyse und Auswertung - 10.03.2014 (1)
  13. Adware eingefangen
    Plagegeister aller Art und deren Bekämpfung - 01.01.2014 (11)
  14. Pup.Optional Adware eingefangen
    Log-Analyse und Auswertung - 02.10.2013 (17)
  15. Adware und Malware eingefangen
    Log-Analyse und Auswertung - 19.04.2013 (15)
  16. pup.adware eingefangen und nun?
    Log-Analyse und Auswertung - 27.03.2013 (4)
  17. PC von Adware.Agent.ZGen, Adware.ClickPotato, Adware.ShopperReports, Adware.Hotbar, Adwa angegriffen
    Mülltonne - 30.06.2011 (0)

Zum Thema Adware Roll around eingefangen - Due meinst Die Google Chrome Secure Preferences? Ja wurden neu angelegt: Code: Alles auswählen Aufklappen ATTFilter { "browser": { "show_home_button": false }, "extensions": { "settings": { "ahfgeienlihckogmohjhadlkjgocpleb": { "active_permissions": { - Adware Roll around eingefangen...
Archiv
Du betrachtest: Adware Roll around eingefangen auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.