|
Plagegeister aller Art und deren Bekämpfung: Adware Roll around eingefangenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
09.04.2015, 23:05 | #76 |
Adware Roll around eingefangen Due meinst Die Google Chrome Secure Preferences? Ja wurden neu angelegt: Code:
ATTFilter { "browser": { "show_home_button": false }, "extensions": { "settings": { "ahfgeienlihckogmohjhadlkjgocpleb": { "active_permissions": { "api": [ "management", "system.display", "system.storage", "webstorePrivate", "system.cpu", "system.memory", "system.network" ], "manifest_permissions": [ ] }, "app_launcher_ordinal": "t", "commands": { }, "content_settings": [ ], "creation_flags": 1, "events": [ ], "from_bookmark": false, "from_webstore": false, "incognito_content_settings": [ ], "incognito_preferences": { }, "install_time": "13072961118896037", "location": 5, "manifest": { "app": { "launch": { "web_url": "https://chrome.google.com/webstore" }, "urls": [ "https://chrome.google.com/webstore" ] }, "description": "Entdecken Sie tolle Apps, Spiele, Erweiterungen und Designs für Google Chrome.", "icons": { "128": "webstore_icon_128.png", "16": "webstore_icon_16.png" }, "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB", "name": "Web Store", "permissions": [ "webstorePrivate", "management", "system.cpu", "system.display", "system.memory", "system.network", "system.storage" ], "version": "0.2" }, "page_ordinal": "n", "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\web_store", "preferences": { }, "regular_only_preferences": { }, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false }, "bepbmhgboaologfdajaanbcjmnhjmhfn": { "disable_reasons": 1, "state": 0 }, "cfhdojbkjhnklbpkdaibdccddilifddb": { "active_permissions": { "api": [ "contextMenus", "notifications", "tabs", "unlimitedStorage", "webNavigation", "webRequest", "webRequestBlocking" ], "explicit_host": [ "hxxp://*/*", "https://*/*" ], "manifest_permissions": [ ], "scriptable_host": [ "hxxp://*/*", "https://*/*" ] }, "commands": { }, "content_settings": [ ], "creation_flags": 9, "events": [ ], "from_bookmark": false, "from_webstore": true, "granted_permissions": { "api": [ "contextMenus", "notifications", "tabs", "unlimitedStorage", "webNavigation", "webRequest", "webRequestBlocking" ], "explicit_host": [ "hxxp://*/*", "https://*/*" ], "manifest_permissions": [ ], "scriptable_host": [ "hxxp://*/*", "https://*/*" ] }, "incognito": true, "incognito_content_settings": [ ], "incognito_preferences": { }, "initial_keybindings_set": true, "install_time": "13072961236384365", "lastpingday": "13073036401510834", "location": 1, "manifest": { "background": { "scripts": [ "ext/common.js", "ext/background.js", "lib/compat.js", "lib/info.js", "lib/io.js", "lib/adblockplus.js", "lib/punycode.js", "lib/publicSuffixList.js", "lib/sha1.js", "lib/jsbn.js", "lib/rsa.js", "webrequest.js", "messageResponder.js", "popupBlocker.js", "background.js" ] }, "browser_action": { "default_icon": { "19": "icons/abp-19.png", "38": "icons/abp-38.png" }, "default_popup": "popup.html", "default_title": "Adblock Plus" }, "content_scripts": [ { "all_frames": true, "js": [ "ext/common.js", "ext/content.js", "include.preload.js" ], "matches": [ "hxxp://*/*", "https://*/*" ], "run_at": "document_start" }, { "all_frames": true, "js": [ "include.postload.js" ], "matches": [ "hxxp://*/*", "https://*/*" ], "run_at": "document_end" } ], "current_locale": "de", "default_locale": "en_US", "description": "Ein kostenloser Werbeblocker mit über 50 Mio Nutzern, der ALLE nervenden Werbeanzeigen, Malware- und Tracking-Angriffe blockiert.", "icons": { "128": "icons/detailed/abp-128.png", "16": "icons/abp-16.png", "32": "icons/abp-32.png", "48": "icons/detailed/abp-48.png", "64": "icons/detailed/abp-64.png" }, "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCxGWIIBRUVzQIXITqE6+js1FA24fsZC58G0fxcO1Duwfps+9gip5tedTziErKEpeAQVkgasdT4kk+b6Lw27yp3oysAj6zD9j+j4W+EMArTXqMIc6SMYD7Z8bPcwPb3tC1MUxMSpO6oOVpFE23UhKe91SYnrK92nHI2cmsor5elXQIDAQAB", "manifest_version": 2, "minimum_chrome_version": "28.0", "name": "Adblock Plus", "options_page": "options.html", "permissions": [ "tabs", "hxxp://*/*", "https://*/*", "contextMenus", "webRequest", "webRequestBlocking", "webNavigation", "unlimitedStorage", "notifications" ], "short_name": "Adblock Plus", "update_url": "https://clients2.google.com/service/update2/crx", "version": "1.8.12", "web_accessible_resources": [ "block.html" ] }, "path": "cfhdojbkjhnklbpkdaibdccddilifddb\\1.8.12_0", "preferences": { }, "regular_only_preferences": { }, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false }, "eemcgdkfndhakfknompkggombfjjjeno": { "active_permissions": { "api": [ "bookmarks", "bookmarkManagerPrivate", "metricsPrivate", "systemPrivate", "tabs" ], "explicit_host": [ "chrome://favicon/*", "chrome://resources/*" ], "manifest_permissions": [ ] }, "commands": { }, "content_settings": [ ], "creation_flags": 1, "events": [ ], "from_bookmark": false, "from_webstore": false, "incognito_content_settings": [ ], "incognito_preferences": { }, "initial_keybindings_set": true, "install_time": "13072961118894704", "location": 5, "manifest": { "chrome_url_overrides": { "bookmarks": "main.html" }, "content_security_policy": "object-src 'none'; script-src chrome://resources 'self'", "description": "Bookmark Manager", "icons": { }, "incognito": "split", "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDQcByy+eN9jzazWF/DPn7NW47sW7lgmpk6eKc0BQM18q8hvEM3zNm2n7HkJv/R6fU+X5mtqkDuKvq5skF6qqUF4oEyaleWDFhd1xFwV7JV+/DU7bZ00w2+6gzqsabkerFpoP33ZRIw7OviJenP0c0uWqDWF8EGSyMhB3txqhOtiQIDAQAB", "manifest_version": 2, "name": "Bookmark Manager", "permissions": [ "bookmarks", "bookmarkManagerPrivate", "metricsPrivate", "systemPrivate", "tabs", "chrome://favicon/", "chrome://resources/" ], "version": "0.1" }, "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\bookmark_manager", "preferences": { }, "regular_only_preferences": { }, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false }, "ennkphjdgehloodpbhlhldgbnhmacadg": { "active_permissions": { "api": [ ], "explicit_host": [ "chrome://settings-frame/*" ], "manifest_permissions": [ ] }, "commands": { }, "content_settings": [ ], "creation_flags": 1, "events": [ "app.runtime.onLaunched" ], "from_bookmark": false, "from_webstore": false, "incognito_content_settings": [ ], "incognito_preferences": { }, "initial_keybindings_set": true, "install_time": "13072961118900031", "location": 5, "manifest": { "app": { "background": { "scripts": [ "settings_app.js" ] } }, "description": "Settings", "display_in_launcher": false, "icons": { "128": "settings_app_icon_128.png", "16": "settings_app_icon_16.png", "32": "settings_app_icon_32.png", "48": "settings_app_icon_48.png" }, "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDoVDPGX6fvKPVVgc+gnkYlGqHuuapgFDyKhsy4z7UzRLO/95zXPv8h8e5EacqbAQJLUbP6DERH5jowyNEYVxq9GJyntJMwP1ejvoz/52hnY3CCGGCmttmKzzpp5zwLuq3iZf8bslwywfflNUYtaCFSDa0TtrBZz0aOPrAAd/AhNwIDAQAB", "manifest_version": 2, "name": "Settings", "permissions": [ "chrome://settings-frame/" ], "version": "0.2" }, "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\settings_app", "preferences": { }, "regular_only_preferences": { }, "running": false, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false }, "gfdkimpbcpahaombhbimeihdjnejgicl": { "active_permissions": { "api": [ "feedbackPrivate" ], "explicit_host": [ "chrome://resources/*" ], "manifest_permissions": [ ] }, "commands": { }, "content_settings": [ ], "creation_flags": 1, "events": [ "feedbackPrivate.onFeedbackRequested", "runtime.onMessageExternal" ], "from_bookmark": false, "from_webstore": false, "incognito_content_settings": [ ], "incognito_preferences": { }, "initial_keybindings_set": true, "install_time": "13072961118899222", "location": 5, "manifest": { "app": { "background": { "scripts": [ "js/event_handler.js" ] }, "content_security_policy": "default-src 'none'; script-src 'self' chrome://resources; style-src 'unsafe-inline' *; img-src *; media-src 'self'" }, "description": "User feedback extension", "display_in_launcher": false, "display_in_new_tab_page": false, "icons": { "32": "images/icon32.png", "64": "images/icon64.png" }, "incognito": "split", "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMZElzFX2J1g1nRQ/8S3rg/1CjFyDltWOxQg+9M8aVgNVxbutEWFQz+oQzIP9BB67mJifULgiv12ToFKsae4NpEUR8sPZjiKDIHumc6pUdixOm8SJ5Rs16SMR6+VYxFUjlVW+5CA3IILptmNBxgpfyqoK0qRpBDIhGk1KDEZ4zqQIDAQAB", "manifest_version": 2, "name": "Feedback", "permissions": [ "feedbackPrivate", "chrome://resources/" ], "version": "1.0" }, "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\feedback", "preferences": { }, "regular_only_preferences": { }, "running": false, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false }, "gomekmidlodglbbmalcneegieacbdmki": { "ack_external": true, "active_permissions": { "api": [ "cookies", "tabs", "webNavigation", "webRequest", "webRequestBlocking" ], "explicit_host": [ "*://*.avast.com/*", "hxxp://*/*", "https://*/*" ], "manifest_permissions": [ ], "scriptable_host": [ "*://*.avast.com/*" ] }, "commands": { }, "content_settings": [ ], "creation_flags": 9, "events": [ ], "from_bookmark": false, "from_webstore": true, "incognito_content_settings": [ ], "incognito_preferences": { }, "initial_keybindings_set": true, "install_time": "13072961128473041", "install_warning_on_enable": false, "lastpingday": "13073036401510834", "location": 6, "manifest": { "author": "Avast", "background": { "scripts": [ "common/libs/q.js", "common/libs/eventemitter2.js", "common/libs/protobuf.js", "common/libs/lodash.js", "scripts/abek.bl.crx.js", "common/scripts/gpb.js", "common/scripts/query.js", "common/scripts/avastwrc.js", "common/scripts/bal.js", "scripts/aos.bl.js", "scripts/bs.crx.js", "scripts/bs.aos.crx.js" ] }, "browser_action": { "default_icon": "common/ui/icons/status-none.png", "default_popup": "common/ui/aos.panel.html", "default_title": "Avast Online Security" }, "content_scripts": [ { "js": [ "common/scripts/ava_connector.js" ], "matches": [ "*://*.avast.com/*" ] } ], "content_security_policy": "script-src 'self' https://ssl.google-analytics.com; object-src 'self'", "current_locale": "de", "default_locale": "en", "description": "Avast Browser Security and Web Reputation Plugin.", "icons": { "128": "common/skin/img/icon128.png", "16": "common/skin/img/icon16.png", "256": "common/skin/img/icon256.png", "32": "common/skin/img/icon32.png", "48": "common/skin/img/icon48.png", "64": "common/skin/img/icon64.png" }, "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDWStseB5KE8Vqukt6RkFc3NirSBRmBTKvNolNhsOo5Q/kUlJs1pajaMckUR5rJXlpzvxfvesfNlASR/QnHKdlGBxPlyi5dxN+nohCclJYf5dXVq2ndj2ykgd++rs1qD35tw3R2v5BaeTmLgP2G/Jd53BaJXDNTGIusbkGEhvZ2rQIDAQAB", "manifest_version": 2, "name": "Avast Online Security", "options_page": "options.html", "permissions": [ "cookies", "*://*.avast.com/*", "hxxp://*/*", "https://*/*", "tabs", "webNavigation", "webRequest", "webRequestBlocking" ], "update_url": "https://clients2.google.com/service/update2/crx", "version": "10.2.0.190", "web_accessible_resources": [ "common/skin/*", "common/skin/img/*", "common/skin/css/*", "common/mocks/*", "common/ui/icons/*", "common/ui/bgs/*" ] }, "path": "gomekmidlodglbbmalcneegieacbdmki\\10.2.0.190_0", "preferences": { }, "regular_only_preferences": { }, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false }, "kmendfapggjehodndflmmgagdbamhnfd": { "active_permissions": { "api": [ "cryptotokenPrivate", "externally_connectable.all_urls", "hid", "tabs", "u2fDevices", "usb", { "usbDevices": [ { "interfaceId": -1, "productId": 529, "vendorId": 4176 } ] }, "webConnectable" ], "explicit_host": [ "hxxp://*/*", "https://*/*" ], "manifest_permissions": [ ] }, "commands": { }, "content_settings": [ ], "creation_flags": 1, "events": [ "runtime.onConnectExternal", "runtime.onMessageExternal" ], "from_bookmark": false, "from_webstore": false, "incognito_content_settings": [ ], "incognito_preferences": { }, "initial_keybindings_set": true, "install_time": "13072961118902555", "location": 5, "manifest": { "background": { "persistent": false, "scripts": [ "util.js", "b64.js", "sha256.js", "countdown.js", "countdowntimer.js", "devicestatuscodes.js", "approvedorigins.js", "errorcodes.js", "gnubbycodetypes.js", "webrequest.js", "gnubbymsgtypes.js", "messagetypes.js", "factoryregistry.js", "closeable.js", "requesthelper.js", "webrequestsender.js", "enroller.js", "requestqueue.js", "signer.js", "origincheck.js", "textfetcher.js", "appid.js", "watchdog.js", "etld_names_list.js", "etld.js", "etldorigincheck.js", "cryptotokenapprovedorigins.js", "gnubbydevice.js", "hidgnubbydevice.js", "usbgnubbydevice.js", "gnubbies.js", "gnubby.js", "gnubby-u2f.js", "gnubbyfactory.js", "singlesigner.js", "multiplesigner.js", "generichelper.js", "inherits.js", "individualattest.js", "devicefactoryregistry.js", "usbhelper.js", "usbenrollhandler.js", "usbsignhandler.js", "usbgnubbyfactory.js", "googlecorpindividualattest.js", "cryptotokenbackground.js" ] }, "description": "CryptoToken Component Extension", "externally_connectable": { "accepts_tls_channel_id": true, "ids": [ "fjajfjhkeibgmiggdfehjplbhmfkialk" ], "matches": [ "\u003Call_urls>" ] }, "incognito": "split", "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq7zRobvA+AVlvNqkHSSVhh1sEWsHSqz4oR/XptkDe/Cz3+gW9ZGumZ20NCHjaac8j1iiesdigp8B1LJsd/2WWv2Dbnto4f8GrQ5MVphKyQ9WJHwejEHN2K4vzrTcwaXqv5BSTXwxlxS/mXCmXskTfryKTLuYrcHEWK8fCHb+0gvr8b/kvsi75A1aMmb6nUnFJvETmCkOCPNX5CHTdy634Ts/x0fLhRuPlahk63rdf7agxQv5viVjQFk+tbgv6aa9kdSd11Js/RZ9yZjrFgHOBWgP4jTBqud4+HUglrzu8qynFipyNRLCZsaxhm+NItTyNgesxLdxZcwOz56KD1Q4IQIDAQAB", "manifest_version": 2, "name": "CryptoTokenExtension", "permissions": [ "hid", "usb", "cryptotokenPrivate", "externally_connectable.all_urls", "tabs", "u2fDevices", "https://*/*", "hxxp://*/*", { "usbDevices": [ { "productId": 529, "vendorId": 4176 } ] } ], "version": "0.9.10" }, "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\cryptotoken", "preferences": { }, "regular_only_preferences": { }, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false }, "lccekmodgklaepjeofjdjpbminllajkg": { "ack_external": true, "active_permissions": { "api": [ ], "manifest_permissions": [ ] }, "commands": { }, "content_settings": [ ], "creation_flags": 137, "events": [ ], "from_bookmark": false, "from_webstore": true, "incognito_content_settings": [ ], "incognito_preferences": { }, "install_time": "13072961123767071", "lastpingday": "13073036401510834", "location": 10, "manifest": { "description": "Support files for Chrome Hotwording.", "export": { "resources": [ "audio/*", "_platform_specific/*", "hotword_*.nmf" ], "whitelist": [ "nbpagnldghgfoolbancepceaanlmhfmd" ] }, "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAoxhwmnepSrtvEcatE9K4SxOUTy6U1LNpuaT3BNr12cuehQT5YAGeUcgeIMQmE0/h/EefU53TcjUEn9vgE8+aSZW0VirROE36hfcWpqyxf9jh0mPRluLIxCW+ObD/B5YoXj0kxTWIaDQqKYBJyo+QCRwef5hwfAoUoDggnYDRHHG4z3mfZJ4duY2H3ISEw4/tsvAm8SxCZm+W6laCV0AkJxO+s4bNNC0z0Y5+G3nw24uV8cdMnfQcFUWJncnwqDSTUp7vOZb570Wv02TD+qhpA2rlF0/ym6edXoKzapR4+SQQllDXZ0yLZ3GQ6uf7IsCufSoYPoIsmYExHrlZbgVkWwIDAQAB", "manifest_version": 2, "minimum_chrome_version": "39", "name": "Chrome Hotword Shared Module", "platforms": [ { "lang": "de", "nacl_arch": "arm", "sub_package_path": "_platform_specific/arm_de/" }, { "lang": "de", "nacl_arch": "x86-32", "sub_package_path": "_platform_specific/x86-32_de/" }, { "lang": "de", "nacl_arch": "x86-64", "sub_package_path": "_platform_specific/x86-64_de/" }, { "lang": "en-AU", "nacl_arch": "arm", "sub_package_path": "_platform_specific/arm_en-au/" }, { "lang": "en-AU", "nacl_arch": "x86-32", "sub_package_path": "_platform_specific/x86-32_en-au/" }, { "lang": "en-AU", "nacl_arch": "x86-64", "sub_package_path": "_platform_specific/x86-64_en-au/" }, { "lang": "en-GB", "nacl_arch": "arm", "sub_package_path": "_platform_specific/arm_en-gb/" }, { "lang": "en-GB", "nacl_arch": "x86-32", "sub_package_path": "_platform_specific/x86-32_en-gb/" }, { "lang": "en-GB", "nacl_arch": "x86-64", "sub_package_path": "_platform_specific/x86-64_en-gb/" }, { "lang": "es", "nacl_arch": "arm", "sub_package_path": "_platform_specific/arm_es/" }, { "lang": "es", "nacl_arch": "x86-32", "sub_package_path": "_platform_specific/x86-32_es/" }, { "lang": "es", "nacl_arch": "x86-64", "sub_package_path": "_platform_specific/x86-64_es/" }, { "lang": "fr", "nacl_arch": "arm", "sub_package_path": "_platform_specific/arm_fr/" }, { "lang": "fr", "nacl_arch": "x86-32", "sub_package_path": "_platform_specific/x86-32_fr/" }, { "lang": "fr", "nacl_arch": "x86-64", "sub_package_path": "_platform_specific/x86-64_fr/" }, { "lang": "it", "nacl_arch": "arm", "sub_package_path": "_platform_specific/arm_it/" }, { "lang": "it", "nacl_arch": "x86-32", "sub_package_path": "_platform_specific/x86-32_it/" }, { "lang": "it", "nacl_arch": "x86-64", "sub_package_path": "_platform_specific/x86-64_it/" }, { "lang": "ja", "nacl_arch": "arm", "sub_package_path": "_platform_specific/arm_ja/" }, { "lang": "ja", "nacl_arch": "x86-32", "sub_package_path": "_platform_specific/x86-32_ja/" }, { "lang": "ja", "nacl_arch": "x86-64", "sub_package_path": "_platform_specific/x86-64_ja/" }, { "lang": "ko", "nacl_arch": "arm", "sub_package_path": "_platform_specific/arm_ko/" }, { "lang": "ko", "nacl_arch": "x86-32", "sub_package_path": "_platform_specific/x86-32_ko/" }, { "lang": "ko", "nacl_arch": "x86-64", "sub_package_path": "_platform_specific/x86-64_ko/" }, { "lang": "pt-BR", "nacl_arch": "arm", "sub_package_path": "_platform_specific/arm_pt-br/" }, { "lang": "pt-BR", "nacl_arch": "x86-32", "sub_package_path": "_platform_specific/x86-32_pt-br/" }, { "lang": "pt-BR", "nacl_arch": "x86-64", "sub_package_path": "_platform_specific/x86-64_pt-br/" }, { "lang": "ru", "nacl_arch": "arm", "sub_package_path": "_platform_specific/arm_ru/" }, { "lang": "ru", "nacl_arch": "x86-32", "sub_package_path": "_platform_specific/x86-32_ru/" }, { "lang": "ru", "nacl_arch": "x86-64", "sub_package_path": "_platform_specific/x86-64_ru/" }, { "nacl_arch": "arm", "sub_package_path": "_platform_specific/arm_/" }, { "nacl_arch": "x86-32", "sub_package_path": "_platform_specific/x86-32_/" }, { "nacl_arch": "x86-64", "sub_package_path": "_platform_specific/x86-64_/" } ], "update_url": "https://clients2.google.com/service/update2/crx", "version": "0.3.0.2" }, "path": "lccekmodgklaepjeofjdjpbminllajkg\\0.3.0.2_0", "preferences": { }, "regular_only_preferences": { }, "state": 1, "was_installed_by_default": true, "was_installed_by_oem": false }, "lifbcibllhkdhoafpjfnlhfpfgnpldfl": { "ack_prompt_count": 1, "active_permissions": { "api": [ "tabs" ], "explicit_host": [ "https://localhost:26143/*", "https://pnrws.skype.com/*" ], "manifest_permissions": [ ], "scriptable_host": [ "file:///*", "hxxp://*/*", "https://*/*" ] }, "commands": { }, "content_settings": [ ], "creation_flags": 9, "disable_reasons": 8192, "events": [ ], "from_bookmark": false, "from_webstore": true, "incognito_content_settings": [ ], "incognito_preferences": { }, "initial_keybindings_set": true, "install_time": "13072961129771064", "lastpingday": "13072950002091880", "location": 6, "manifest": { "background": { "page": "background.html" }, "browser_action": { "default_icon": { "19": "c2c_48x48.png" }, "default_popup": "c2c_options_menu.html", "default_title": "Skype Click to Call" }, "content_scripts": [ { "all_frames": true, "css": [ "number_highlighting.css", "number_highlighting_ui1.css", "number_highlighting_chrome.css", "number_highlighting_chrome_ui1.css" ], "js": [ "jquery-2.1.0.min.js", "mutation-summary.js", "localization.js", "browserSpecificScript.js", "number_highlighting_builder.js", "pnr.js", "fpnr.js", "contentscript.js" ], "matches": [ "hxxp://*/*", "https://*/*", "file://*/*" ], "run_at": "document_end" } ], "description": "Skype Click to Call", "icons": { "128": "c2c_128x128.png", "16": "c2c_16x16.png", "48": "c2c_48x48.png" }, "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMxFysW3wPKWRPPe3xuJQz3m1ZDLX1hN8EYdP37tRPf7lp8vIhG4xirlXHGK748qcLPc4Lm8WsHDhvS5okN54Kwcnw4T2tBXSCZJxMmlu14HZ5yc/t969QLTPLIbAsasq4NVo40YuP2B7umxV9BlcxZEB9TEKPEQq8DRoKhj9jBQIDAQAB", "manifest_version": 2, "name": "Skype Click to Call", "permissions": [ "tabs", "https://pnrws.skype.com/", "https://localhost:26143/" ], "update_url": "https://clients2.google.com/service/update2/crx", "version": "7.3.16540.9015", "web_accessible_resources": [ "call_skype_logo.png", "call_skype_logo_ui1.png", "call_icon.png", "call_icon_ui1.png", "plus_icon_ui1.png", "gift_icon_ui1.png", "skype_icon_ui1.png", "skypecredit_icon_ui1.png", "learnmore_icon_ui1.png", "menu_handler.js", "telemetry.js" ] }, "path": "lifbcibllhkdhoafpjfnlhfpfgnpldfl\\7.3.16540.9015_0", "preferences": { }, "regular_only_preferences": { }, "state": 2, "was_installed_by_default": false, "was_installed_by_oem": false }, "mbolhellljccdahaeelobbojpfdgjgco": { "active_permissions": { "api": [ "unlimitedStorage" ], "manifest_permissions": [ ] }, "app_launcher_ordinal": "zp", "commands": { }, "content_settings": [ ], "creation_flags": 9, "disable_reasons": 32, "events": [ ], "from_bookmark": false, "from_webstore": true, "granted_permissions": { "api": [ "unlimitedStorage" ], "manifest_permissions": [ ] }, "incognito_content_settings": [ ], "incognito_preferences": { }, "install_time": "13072961239827881", "lastpingday": "13073036401510834", "location": 1, "manifest": { "api_console_project_id": "72003345431", "app": { "launch": { "container": "tab", "web_url": "hxxp://kmlviewer.nsspot.net/" }, "urls": [ "hxxp://kmlviewer.nsspot.net/" ] }, "container": "GOOGLE_DRIVE", "current_locale": "de", "default_locale": "en_US", "description": "A tool that views the KML, KMZ (Zipped KML format) file on a map. You can open KML, KMZ files from URL or from Google Drive.", "icons": { "128": "icon128.png" }, "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAz9ZalFOrFTuTkP03G7qa9dHbdvBDBse6GTdcOnuRumMZ1N080jSHKMqRQyz9lFLO6+urtmF010Y4oYAvK2IPbhv1T1/w9SpF7tOolWkIlteMnUDHRVhGMw08d7DBEmffqza7a/ivh4iTMzFSBfgHpUajibP+UbvYYXXLhRvFl2LQQnk+KPDai+bglbiI7HE3nk8Cr9/rEQnBWXr0xBIZ+KhmpRQn8PkUwgOP59awTHTfO5XTfzKPA7SDa4QIzDmuteZNYY2WaCs0G6S99qElRHIk8I7KpAGS3GqyDMPmCiBGIuaIfvWaU3iUcGvJPBdIdQcFYiHmMUQyTmS7IOimkQIDAQAB", "manifest_version": 2, "name": "KML, KMZ Viewer with Drive", "permissions": [ "unlimitedStorage" ], "update_url": "hxxp://clients2.google.com/service/update2/crx", "version": "1.0.1.7" }, "page_ordinal": "n", "path": "mbolhellljccdahaeelobbojpfdgjgco\\1.0.1.7_0", "preferences": { }, "regular_only_preferences": { }, "state": 0, "was_installed_by_default": false, "was_installed_by_oem": false }, "mfehgcgbbipciphmccgaenjidiccnmng": { "active_permissions": { "api": [ "cloudPrintPrivate" ], "manifest_permissions": [ ] }, "commands": { }, "content_settings": [ ], "creation_flags": 1, "events": [ ], "from_bookmark": false, "from_webstore": false, "incognito_content_settings": [ ], "incognito_preferences": { }, "install_time": "13072961118895442", "location": 5, "manifest": { "app": { "launch": { "web_url": "https://www.google.com/cloudprint" }, "urls": [ "https://www.google.com/cloudprint/enable_chrome_connector" ] }, "description": "Cloud Print", "display_in_launcher": false, "icons": { }, "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDqOhnwk4+HXVfGyaNsAQdU/js1Na56diW08oF1MhZiwzSnJsEaeuMN9od9q9N4ZdK3o1xXOSARrYdE+syV7Dl31nf6qz3A6K+D5NHe6sSB9yvYlIiN37jdWdrfxxE0pRYEVYZNTe3bzq3NkcYJlOdt1UPcpJB+isXpAGUKUvt7EQIDAQAB", "name": "Cloud Print", "permissions": [ "cloudPrintPrivate" ], "version": "0.1" }, "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\cloud_print", "preferences": { }, "regular_only_preferences": { }, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false }, "mfffpogegjflfpflabcdkioaeobkgjik": { "active_permissions": { "api": [ "webRequest", "webRequestBlocking" ], "explicit_host": [ "\u003Call_urls>", "chrome://favicon/*" ], "manifest_permissions": [ ], "scriptable_host": [ "\u003Call_urls>" ] }, "commands": { }, "content_settings": [ ], "creation_flags": 1, "events": [ ], "from_bookmark": false, "from_webstore": false, "incognito_content_settings": [ ], "incognito_preferences": { }, "initial_keybindings_set": true, "install_time": "13072961118948727", "location": 5, "manifest": { "background": { "scripts": [ "channel.js", "background.js" ] }, "content_scripts": [ { "all_frames": true, "js": [ "channel.js", "saml_injected.js" ], "matches": [ "\u003Call_urls>" ], "run_at": "document_start" } ], "content_security_policy": "default-src 'self'; script-src 'self'; frame-src *; style-src 'self' 'unsafe-inline'", "description": "GAIA Component Extension", "key": "MIGdMA0GCSqGSIb3DQEBAQUAA4GLADCBhwKBgQC4L17nAfeTd6Xhtx96WhQ6DSr8KdHeQmfzgCkieKLCgUkWdwB9G1DCuh0EPMDn1MdtSwUAT7xE36APEzi0X/UpKjOVyX8tCC3aQcLoRAE0aJAvCcGwK7qIaQaczHmHKvPC2lrRdzSoMMTC5esvHX+ZqIBMi123FOL0dGW6OPKzIwIBIw==", "manifest_version": 2, "name": "GaiaAuthExtension", "permissions": [ "\u003Call_urls>", "webRequest", "webRequestBlocking" ], "version": "0.0.1", "web_accessible_resources": [ "main.css", "main.html", "main.js", "offline.css", "offline.html", "offline.js", "success.html", "success.js", "util.js" ] }, "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\gaia_auth", "preferences": { }, "regular_only_preferences": { }, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false }, "mgndgikekgjfcpckkfioiadnlibdjbkf": { "active_permissions": { "api": [ ], "manifest_permissions": [ ] }, "app_launcher_ordinal": "n", "commands": { }, "content_settings": [ ], "creation_flags": 1, "events": [ ], "from_bookmark": false, "from_webstore": false, "incognito_content_settings": [ ], "incognito_preferences": { }, "install_time": "13072961118896493", "location": 5, "manifest": { "app": { "launch": { "web_url": "hxxp://THIS-WILL-BE-REPLACED" } }, "description": "Der schnelle, einfache und sichere Browser, entwickelt für das moderne Web", "display_in_launcher": true, "display_in_new_tab_page": false, "icons": { "128": "product_logo_128.png", "16": "product_logo_16.png" }, "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDNuYLEQ1QPMcc5HfWI/9jiEf6FdJWqEtgRmIeI7qtjPLBM5oje+Ny2E2mTAhou5qdJiO2CHWdU1DQXY2F7Zu2gZaKZgHLfK4WimHxUT5Xd9/aro/R9PCzjguM1BLusiWYc9xlj1IsZpyiN1hcjU7SCnBhv1feQlv2WSB5KRiXwhQIDAQAB", "name": "Chrome", "version": "0.1" }, "page_ordinal": "n", "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\chrome_app", "preferences": { }, "regular_only_preferences": { }, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false }, "nbpagnldghgfoolbancepceaanlmhfmd": { "active_permissions": { "api": [ "audioCapture", "hotwordPrivate", "idle", "management", "metricsPrivate", "tabs", "unlimitedStorage" ], "explicit_host": [ "*://*.google.co.uk/*", "*://*.google.com/*", "*://*.google.de/*", "*://*.google.fr/*", "*://*.google.ru/*", "chrome://newtab/*", "chrome://resources/*" ], "manifest_permissions": [ ] }, "commands": { }, "content_settings": [ ], "creation_flags": 1, "events": [ "hotwordPrivate.onEnabledChanged", "management.onInstalled", "runtime.onStartup" ], "from_bookmark": false, "from_webstore": false, "incognito_content_settings": [ ], "incognito_preferences": { }, "initial_keybindings_set": true, "install_time": "13072961118898314", "location": 5, "manifest": { "background": { "persistent": false, "scripts": [ "chrome://resources/js/cr.js", "chrome://resources/js/util.js", "chrome://resources/js/cr/event_target.js", "constants.js", "keep_alive.js", "logging.js", "metrics.js", "nacl_manager.js", "state_manager.js", "base_session_manager.js", "always_on_manager.js", "launcher_manager.js", "page_audio_manager.js", "training_manager.js", "manager.js" ] }, "content_security_policy": "object-src 'none'; script-src chrome://resources 'self'", "import": [ { "id": "lccekmodgklaepjeofjdjpbminllajkg" } ], "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDbHXRPiq2De9EJ+4pvNN6uE/D2avxrqyLSpA/Hq3II+btkPl1gboY3oUPTfevpVOFa90Y1c1b3/W682dXqybT0klIvFLKhdQx0LiVqSUQyIaDrwOCSo/ZcukbEwDRojegWymCjHvX6WZk4kKZzTJYzY1vrp0TWKLhttEMN9KFmowIDAQAB", "manifest_version": 2, "minimum_chrome_version": "38", "name": "Hotword triggering", "permissions": [ "*://*.google.com/*", "*://*.google.ru/*", "*://*.google.co.uk/*", "*://*.google.fr/*", "*://*.google.de/*", "chrome://newtab/", "chrome://resources/", "audioCapture", "hotwordPrivate", "idle", "management", "metricsPrivate", "tabs", "unlimitedStorage" ], "version": "0.0.1.3" }, "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\hotword", "preferences": { }, "regular_only_preferences": { }, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false }, "nckgahadagoaajjgafhacjanaoiihapd": { "active_permissions": { "api": [ "background", "cookies", "idle", "notifications", "tabs", "webConnectable" ], "explicit_host": [ "*://*.google.com/*", "*://*.orkut.com/*" ], "manifest_permissions": [ ] }, "commands": { }, "content_settings": [ ], "creation_flags": 9, "events": [ ], "from_bookmark": false, "from_webstore": true, "granted_permissions": { "api": [ "background", "cookies", "idle", "notifications", "tabs", "webConnectable" ], "explicit_host": [ "*://*.google.com/*", "*://*.orkut.com/*" ], "manifest_permissions": [ ] }, "incognito": true, "incognito_content_settings": [ ], "incognito_preferences": { }, "initial_keybindings_set": true, "install_time": "13072961238765067", "lastpingday": "13073036401510834", "location": 1, "manifest": { "background": { "scripts": [ "scripts/extension.js" ] }, "browser_action": { "default_icon": { "19": "images_4/presence/offline_19.png", "38": "images_4/presence/offline_38.png" }, "default_title": "Hangouts" }, "content_security_policy": "script-src 'self' https://*.google.com https://feedback.googleusercontent.com https://www.gstatic.com https://*.google.com:*/; img-src 'self' data: https://ssl.gstatic.com ; object-src 'self'", "current_locale": "de", "default_locale": "en", "description": "Hangouts macht Ihre Unterhaltungen noch lebendiger – mit Fotos, Emojis und kostenlosen Gruppen-Videoanrufen.", "externally_connectable": { "matches": [ "https://*.google.com/*" ] }, "icons": { "128": "images_4/icon-128x128.png", "48": "images_4/icon-48x48.png" }, "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDsDApubb73tPfYlNIFxDu3K3/EHgV6/YOJXJkld1OZ20jW/cOht1j0NggnXhQYuu1mXFUufud4I2N7b5ydyg09gcM9Va3Zk17RhNV9smbPHOd4XlzJeXifX/9MgHPu4FzCen3CiSXsOeAELJIXEuT28xICriuUko/rNPwGeIB9VwIDAQAB", "manifest_version": 2, "minimum_chrome_version": "26.0.0.0", "name": "Hangouts", "options_page": "settingsdialog.html", "options_ui": { "chrome_style": true, "page": "settingsdialog.html" }, "permissions": [ "cookies", "background", "idle", "notifications", "tabs", "*://*.google.com/*", "*://*.orkut.com/*" ], "system_indicator": { "default_icon": { "19": "images_4/presence/offline_19.png", "38": "images_4/presence/offline_38.png" } }, "update_url": "https://clients2.google.com/service/update2/crx", "version": "2015.302.433.1", "web_accessible_resources": [ "*" ] }, "path": "nckgahadagoaajjgafhacjanaoiihapd\\2015.302.433.1_0", "preferences": { }, "regular_only_preferences": { }, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false }, "neajdppkdcdipfabeoofebfddakdcjhd": { "active_permissions": { "api": [ "systemPrivate", "ttsEngine" ], "explicit_host": [ "https://www.google.com/*" ], "manifest_permissions": [ ] }, "commands": { }, "content_settings": [ ], "creation_flags": 1, "events": [ "ttsEngine.onPause", "ttsEngine.onResume", "ttsEngine.onSpeak", "ttsEngine.onStop" ], "from_bookmark": false, "from_webstore": false, "incognito_content_settings": [ ], "incognito_preferences": { }, "initial_keybindings_set": true, "install_time": "13072961118901677", "location": 5, "manifest": { "background": { "persistent": false, "scripts": [ "tts_extension.js" ] }, "description": "Component extension providing speech via the Google network text-to-speech service.", "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8GSbNUMGygqQTNDMFGIjZNcwXsHLzkNkHjWbuY37PbNdSDZ4VqlVjzbWqODSe+MjELdv5Keb51IdytnoGYXBMyqKmWpUrg+RnKvQ5ibWr4MW9pyIceOIdp9GrzC1WZGgTmZismYR3AjaIpufZ7xDdQQv+XrghPWCkdVqLN+qZDA1HU+DURznkMICiDDSH2sU0egm9UbWfS218bZqzKeQDiC3OnTPlaxcbJtKUuupIm5knjze3Wo9Ae9poTDMzKgchg0VlFCv3uqox+wlD8sjXBoyBCCK9HpImdVAF1a7jpdgiUHpPeV/26oYzM9/grltwNR3bzECQgSpyXp0eyoegwIDAQAB", "manifest_version": 2, "name": "Google Network Speech", "permissions": [ "systemPrivate", "ttsEngine", "https://www.google.com/" ], "tts_engine": { "voices": [ { "event_types": [ "start", "end", "error" ], "gender": "female", "lang": "en-US", "remote": true, "voice_name": "Google US English" }, { "event_types": [ "start", "end", "error" ], "gender": "male", "lang": "en-GB", "remote": true, "voice_name": "Google UK English Male" }, { "event_types": [ "start", "end", "error" ], "gender": "female", "lang": "en-GB", "remote": true, "voice_name": "Google UK English Female" }, { "event_types": [ "start", "end", "error" ], "gender": "female", "lang": "es-ES", "remote": true, "voice_name": "Google Español" }, { "event_types": [ "start", "end", "error" ], "gender": "female", "lang": "fr-FR", "remote": true, "voice_name": "Google Français" }, { "event_types": [ "start", "end", "error" ], "gender": "female", "lang": "it-IT", "remote": true, "voice_name": "Google Italiano" }, { "event_types": [ "start", "end", "error" ], "gender": "female", "lang": "de-DE", "remote": true, "voice_name": "Google Deutsch" }, { "event_types": [ "start", "end", "error" ], "gender": "female", "lang": "ja-JP", "remote": true, "voice_name": "Google 日本人" }, { "event_types": [ "start", "end", "error" ], "gender": "female", "lang": "ko-KR", "remote": true, "voice_name": "Google 한국의" }, { "event_types": [ "start", "end", "error" ], "gender": "female", "lang": "zh-CN", "remote": true, "voice_name": "Google 中国的" } ] }, "version": "1.0" }, "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\network_speech_synthesis", "preferences": { }, "regular_only_preferences": { }, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false }, "nkeimhogjdpnpccoofpliimaahmaaome": { "active_permissions": { "api": [ "alarms", "desktopCapture", "processes", "webConnectable", "webrtcAudioPrivate", "webrtcLoggingPrivate", "system.cpu" ], "manifest_permissions": [ ] }, "commands": { }, "content_settings": [ ], "creation_flags": 1, "events": [ "runtime.onConnectExternal", "runtime.onMessageExternal" ], "from_bookmark": false, "from_webstore": false, "incognito_content_settings": [ ], "incognito_preferences": { }, "initial_keybindings_set": true, "install_time": "13072961118897255", "location": 5, "manifest": { "background": { "page": "background.html", "persistent": false }, "externally_connectable": { "matches": [ "https://*.google.com/hangouts*", "*://localhost/*" ] }, "incognito": "split", "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDAQt2ZDdPfoSe/JI6ID5bgLHRCnCu9T36aYczmhw/tnv6QZB2I6WnOCMZXJZlRdqWc7w9jo4BWhYS50Vb4weMfh/I0On7VcRwJUgfAxW2cHB+EkmtI1v4v/OU24OqIa1Nmv9uRVeX0GjhQukdLNhAE6ACWooaf5kqKlCeK+1GOkQIDAQAB", "manifest_version": 2, "name": "Google+ Hangouts", "permissions": [ "alarms", "desktopCapture", "processes", "system.cpu", "webrtcAudioPrivate", "webrtcLoggingPrivate" ], "version": "1.0" }, "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\hangout_services", "preferences": { }, "regular_only_preferences": { }, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false }, "nmmhkkegccagdldgiimedpiccmgmieda": { "ack_external": true, "active_permissions": { "api": [ "identity", "webview" ], "explicit_host": [ "https://wallet-web.sandbox.google.com/*", "https://wallet.google.com/*", "https://www.google.com/*", "https://www.googleapis.com/*" ], "manifest_permissions": [ ] }, "commands": { }, "content_settings": [ ], "creation_flags": 137, "events": [ "app.runtime.onLaunched", "runtime.onConnectExternal" ], "from_bookmark": false, "from_webstore": true, "incognito_content_settings": [ ], "incognito_preferences": { }, "initial_keybindings_set": true, "install_time": "13072961131802230", "lastpingday": "13073036401510834", "location": 10, "manifest": { "app": { "background": { "scripts": [ "craw_background.js" ] } }, "current_locale": "de", "default_locale": "en", "description": "Google Wallet für digitale Produkte", "display_in_launcher": false, "display_in_new_tab_page": false, "icons": { "128": "images/icon_128.png", "16": "images/icon_16.png" }, "key": "MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCrKfMnLqViEyokd1wk57FxJtW2XXpGXzIHBzv9vQI/01UsuP0IV5/lj0wx7zJ/xcibUgDeIxobvv9XD+zO1MdjMWuqJFcKuSS4Suqkje6u+pMrTSGOSHq1bmBVh0kpToN8YoJs/P/yrRd7FEtAXTaFTGxQL4C385MeXSjaQfiRiQIDAQAB", "manifest_version": 2, "minimum_chrome_version": "29", "name": "Google Wallet", "oauth2": { "auto_approve": true, "client_id": "203784468217.apps.googleusercontent.com", "scopes": [ "https://www.googleapis.com/auth/sierra", "https://www.googleapis.com/auth/sierrasandbox", "https://www.googleapis.com/auth/chromewebstore", "https://www.googleapis.com/auth/chromewebstore.readonly" ] }, "permissions": [ "identity", "webview", "https://wallet.google.com/", "https://wallet-web.sandbox.google.com/", "https://www.google.com/", "https://www.googleapis.com/*" ], "update_url": "https://clients2.google.com/service/update2/crx", "version": "0.1.0.0" }, "path": "nmmhkkegccagdldgiimedpiccmgmieda\\0.1.0.0_0", "preferences": { }, "regular_only_preferences": { }, "running": false, "state": 1, "was_installed_by_default": true, "was_installed_by_oem": false }, "ohgndokldibnndfnjnagojmheejlengn": { "ack_external": true, "active_permissions": { "api": [ "contextMenus", "nativeMessaging", "tabs" ], "explicit_host": [ "hxxp://*.citavi.com/*", "hxxp://*/*", "https://*/*" ], "manifest_permissions": [ ], "scriptable_host": [ "hxxp://*/*", "https://*/*" ] }, "commands": { }, "content_settings": [ ], "creation_flags": 9, "events": [ ], "from_bookmark": false, "from_webstore": true, "incognito_content_settings": [ ], "incognito_preferences": { }, "initial_keybindings_set": true, "install_time": "13072961125713361", "install_warning_on_enable": false, "lastpingday": "13073036401510834", "location": 6, "manifest": { "background": { "page": "background.html" }, "content_scripts": [ { "all_frames": true, "css": [ "libs/css/jquery.css", "libs/css/jsonSuggest.css" ], "js": [ "libs/jquery/jquery.js", "libs/jquery/jquery-ui-1.8.23.custom.js", "libs/jquery/jquery.effects.bounce.js", "libs/jquery/jquery.effects.clip.js", "libs/jquery/jquery.effects.core.js", "libs/jquery/jquery.effects.drop.js", "libs/jquery/jquery.effects.explode.js", "libs/jquery/jquery.effects.fade.js", "libs/jquery/jquery.effects.fold.js", "libs/jquery/jquery.effects.highlight.js", "libs/jquery/jquery.effects.pulsate.js", "libs/jquery/jquery.effects.scale.js", "libs/jquery/jquery.effects.shake.js", "libs/jquery/jquery.effects.slide.js", "libs/jquery/jquery.effects.transfer.js", "libs/jquery/jquery.ui.accordion.js", "libs/jquery/jquery.ui.autocomplete.js", "libs/jquery/jquery.ui.button.js", "libs/jquery/jquery.ui.core.js", "libs/jquery/jquery.ui.dialog.js", "libs/jquery/jquery.ui.draggable.js", "libs/jquery/jquery.ui.droppable.js", "libs/jquery/jquery.ui.mouse.js", "libs/jquery/jquery.ui.position.js", "libs/jquery/jquery.ui.progressbar.js", "libs/jquery/jquery.ui.resizable.js", "libs/jquery/jquery.ui.selectable.js", "libs/jquery/jquery.ui.slider.js", "libs/jquery/jquery.ui.sortable.js", "libs/jquery/jquery.ui.tabs.js", "libs/jquery/jquery.ui.widget.js", "libs/jquery/jquery.effects.blind.js", "libs/jquery/jquery.jsonSuggest-dev.js", "libs/jquery/jquery.jsonSuggest.js", "libs/jquery/json2.js", "citaviPickerLogger.js", "jqueryHelper.js", "html/onlineSearchProgressDialog.js", "html/optionsDialog.js", "html/importDialog.js", "isbnValidator.js", "Hunter/kindleHunter.js", "pageModifier.js", "Base64.js", "Hunter/hunterManager.js", "citaviPicker.js", "Webservice/references.js", "Webservice/transformer.js", "Webservice/fetcher.js" ], "matches": [ "hxxp://*/*", "https://*/*" ] } ], "current_locale": "de", "default_locale": "en", "description": "Citavi Picker für Google Chrome", "homepage_url": "hxxp://www.citavi.com", "icons": { "128": "icon.ico", "16": "icon.ico", "48": "icon.ico" }, "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA6hZz7lcASmfJcGJQ3x/ZYvKCCKLpkBkx9IVqjsmTDvE+MjXh6Kp3+giPAIFZGfGycQ7DSD7x8PtecKDvsSB+xY7P6CdN3kEDernWIfuh8GEpPo0Q1CZ2Sj2mrb+ftvdIrhXygLU+PPCVimtDgBRNbKLzopARxKzqta1MtSEOYqn35kyWFFGN1FPRG26izgBlM9dO3ud39F5ZUcpOt6Wt6vosoiHGwefaHjWqI21b59MebjGE8vwKvWmHUSMoyFgYRB1o+iTZF9bbYM0X885QP7e5GZrbee5R+M6waQteDRSvSDyqegXye+wf3nUNo7rMArA6GY4sajUAHqeKD+2AHwIDAQAB", "manifest_version": 2, "name": "Citavi Picker", "permissions": [ "nativeMessaging", "hxxp://*/*", "https://*/*", "tabs", "contextMenus", "hxxp://*.citavi.com/" ], "update_url": "https://clients2.google.com/service/update2/crx", "version": "2015.1.27.2", "web_accessible_resources": [ "html/importDialog.html", "html/onlineSearchProgressDialog.html", "html/optionsDialog.html", "html/images/*.png" ] }, "path": "ohgndokldibnndfnjnagojmheejlengn\\2015.1.27.2_1", "preferences": { }, "regular_only_preferences": { }, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false }, "pafkbggdmjlpgkdkcbjmhmfcdpncadgh": { "active_permissions": { "api": [ "alarms", "background", "identity", "metricsPrivate", "notifications", "pushMessaging", "storage", "tabs", "webstorePrivate" ], "explicit_host": [ "*://*.google.com/*", "*://*.gstatic.com/*", "https://*.googleapis.com/*", "https://*.googleusercontent.com/*" ], "manifest_permissions": [ ] }, "commands": { }, "content_settings": [ ], "creation_flags": 1, "events": [ "alarms.onAlarm", "identity.onSignInChanged", "notifications.onButtonClicked", "notifications.onClicked", "notifications.onClosed", "notifications.onPermissionLevelChanged", "notifications.onShowSettings", "pushMessaging.onMessage", "runtime.onInstalled", "runtime.onStartup", "runtime.onSuspend", "storage.onChanged" ], "from_bookmark": false, "from_webstore": false, "incognito_content_settings": [ ], "incognito_preferences": { }, "initial_keybindings_set": true, "install_time": "13072961118900829", "location": 5, "manifest": { "background": { "persistent": false, "scripts": [ "utility.js", "cards.js", "background.js" ] }, "description": "Integrates Google Now into Chrome.", "icons": { "128": "images/icon128.png", "16": "images/icon16.png", "48": "images/icon48.png" }, "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkhqJr32OFD/bMXW4Md7jMfd7LbwHXVc6x5bBQG5U+dloofoxrICDR20yur/40mQ8O//0sS1b8srvbab1CRlSrxoNCr9T80NAkfzx0gHyVS+p1Zow+1FzLMu9PiGwwFyN80HIB7GI/dIa0wC9K/2OrrzcHEhVH96DacTtWQqjfDVtZPjT7Xwv23dgoWcpbkRC86jMJot3dmX9xnn0KzoVc9gDOHSIkBLbkkr6Sp3LGXCCM4L0DJgxdFwaLr5WBzgC3y5x0/wwPIwN4PtIaK3BhH6njlksfnKwwIJ9iRT41V4BqbWu4mszO/7VJ3HJyw2DBpIc2grU9ZRRxrV3fRQG4wIDAQAB", "manifest_version": 2, "name": "Google Now", "oauth2": { "auto_approve": true, "scopes": [ "https://www.googleapis.com/auth/googlenow" ] }, "optional_permissions": [ "background" ], "permissions": [ "alarms", "identity", "metricsPrivate", "notifications", "pushMessaging", "storage", "tabs", "webstorePrivate", "*://*.google.com/*", "*://*.gstatic.com/*", "https://*.googleapis.com/chromenow/v1/*", "https://*.googleusercontent.com/*" ], "version": "1.2.0.1" }, "path": "C:\\Program Files (x86)\\Google\\Chrome\\Application\\41.0.2272.118\\resources\\google_now", "preferences": { }, "regular_only_preferences": { }, "state": 1, "was_installed_by_default": false, "was_installed_by_oem": false } } }, "google": { "services": { "last_username": "basil.eberle@googlemail.com", "username": "basil.eberle@googlemail.com" } }, "homepage": "hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M5D03F840-0A34-4EF1-B1D2-7A24EF265FAD&SearchSource=55&CUI=&UM=5&UP=SPDD7AE828-8266-469E-A82F-77BE9505BDA3&SSPV=", "homepage_is_newtabpage": true, "pinned_tabs": [ ], "protection": { "macs": { "browser": { "show_home_button": "6AA2DA8BFDD25445ABB24BB8CDC07A4AFB70477DACA1A1985105F64B71056501" }, "default_search_provider": { "keyword": "AA349BD6AE8FA3A0D6F3B9FEC6FDBF5D8175E8F5F2C1A684A2A0F3B4393D28EA", "name": "7B21C10AE38BE315ED7E49700B5346971B3C9850FEA5A186DA1D5B1F2963F28B", "search_url": "BD963AF047FA53A193678C8BA019FEB52ECECF9A842709675A9B7DC9D59A5CF1" }, "default_search_provider_data": { "template_url_data": "B456F8E89A12855FE3C9926B8A6EDE2293293C8FE7794E759222B45A8C388DC8" }, "extensions": { "settings": { "ahfgeienlihckogmohjhadlkjgocpleb": "774A225DEE5C9442CE48BAAE01FBCD92A6FBA8E0586D6395460D09506A0A1097", "bepbmhgboaologfdajaanbcjmnhjmhfn": "207BD5DFED379137BD933816AC834B774A41C133E0C7437CDD971465CF0D8C3D", "cfhdojbkjhnklbpkdaibdccddilifddb": "0F0DD27E03ED960A97CB61FCC90F098D771D577D2C3A999C249623D353311AD8", "eemcgdkfndhakfknompkggombfjjjeno": "52669445A6C9D00C4A47BA446F1244D1B313D8F12D765C4CE0089FEA9206906A", "ennkphjdgehloodpbhlhldgbnhmacadg": "044125F679AE5667E9CE7C3168E76DDFF24F50BD0801B5786E0142C39874DE61", "gfdkimpbcpahaombhbimeihdjnejgicl": "52C4DE3992DF5F8FD827E2A2ECF75821B8174B9BB6EBEB15B0321D2A8A346EFA", "gomekmidlodglbbmalcneegieacbdmki": "30C32E036F21684D6E0395391FC7DD824C63B2A1DFEF5511A4561E0CE7D257C8", "kmendfapggjehodndflmmgagdbamhnfd": "5C8B21D6DDD93B9C04BBFF2E1BE1BBB9ED4B483FB48BE03ACA302B4880BD6C67", "lccekmodgklaepjeofjdjpbminllajkg": "73A826F89E85DE6B4A2CF67E8EFA1E56206457DBBDB54BC7BEF68EEE7A4EFD83", "lifbcibllhkdhoafpjfnlhfpfgnpldfl": "984A1480435E8821FEAED5DABD21BBBCDED39F9340CEB2C36952A5E6F482F36B", "mbolhellljccdahaeelobbojpfdgjgco": "2E1E3BBC0D896905AA48D55174CCA3C15E96CA53FC585FF75334A120C345D33F", "mfehgcgbbipciphmccgaenjidiccnmng": "D956FDB3201D97A8B100DD285BC7C001D1A4A56A9DCEB7499DC766B42227AC26", "mfffpogegjflfpflabcdkioaeobkgjik": "CEB733D3DC6EB63BB1C4C6FC3AF48D228DC239496B6F8BEA841287B27FC912EA", "mgndgikekgjfcpckkfioiadnlibdjbkf": "FC28759E122AC25C1176ED21F17022AF5D7AC40CA6FC35FDCE198161DA2FF3D8", "nbpagnldghgfoolbancepceaanlmhfmd": "41C59F111B70B509F70C77637BD8A18D431382EFAD4334BA875A57EAE62FC122", "nckgahadagoaajjgafhacjanaoiihapd": "5210BF1C1FF1175E722818FB6621F35228C19A0B39C93404B3D4A37718F80582", "neajdppkdcdipfabeoofebfddakdcjhd": "D1B4FE342F47B8D3EBDA594FBDB61C9BA7F0534FF75DF2FD00A786A1CDCE401E", "nkeimhogjdpnpccoofpliimaahmaaome": "A94A9CE3823DB636F99B0FA893342F69070151CAC0D2137C42F2AF20FE5C5591", "nmmhkkegccagdldgiimedpiccmgmieda": "919E5AC76696856915CE7203E5DF3576745E002930E0689B16324686E90A9AF5", "ohgndokldibnndfnjnagojmheejlengn": "A8F9FAFF47DA042FC64DD7BCC9D5E74B3F0F81E6F537238C4C1E9D2203A788C5", "pafkbggdmjlpgkdkcbjmhmfcdpncadgh": "80CC01A8324B3F0BCFB62FF123A964638DB937EB44A3990274BB20D8BCC8F171" } }, "google": { "services": { "last_username": "71F476FD6D124F81795640BE2483F35D5E108500FF5D5497081F4B2CC9B1BF5D", "username": "2899B25FC0807D8E3CF3FBFF0B07547E6B3DFCD5C9AF8C59BB288772C07E3CD1" } }, "homepage": "6B79359431C3CB91DFFADD9D3EB7487E02D9A4D6B34F6F1C00B302EEDE106A2F", "homepage_is_newtabpage": "F09724F9195F838BD833309BE572472E658C5AF1503762BECF280C93D581C15F", "pinned_tabs": "A1A9C32317B879FE82B6ED6A6512D089789F05E30745B5CCCB76F1091DEE0717", "prefs": { "preference_reset_time": "0B408FF304A04908220B9ECD3E02F3577F681868FEF6230296D0AF605616FC4E" }, "profile": { "reset_prompt_memento": "B04F84352991A271405CC3FAF236922D6A5E51181026CADBEBC245321582827F" }, "safebrowsing": { "incidents_sent": "157A7080E8A63C89AC91EFBDCA9880B6B8C005C13D7AA68551AEC29EEA38B5CA" }, "search_provider_overrides": "9D9C5947F6F4F9C0FF0DD7461D5359DD0A470290E107EBE0243F1AD973A52D5F", "session": { "restore_on_startup": "BF6C9B361E54C4393973A2B5968F75EE35C4C060E68D8B3C4FF99D553254C695", "startup_urls": "005FE60B4E4F327B992CC86B41DEB6041935CF94E69A83284FC77B687F683039" }, "software_reporter": { "prompt_reason": "98F3E73884FBF4B6208ACDF770ADA749D9498FD0A06D7F039511C6225A985188", "prompt_version": "CA77F2CB73FF3ADEA6FABE97AB700FD33BF10D35F0AE1686B9B92B38E2CDB7F5" }, "sync": { "remaining_rollback_tries": "23C1ECFD0AB13169B1679B3492AC4632C1377062BFB728BE088E087688C75320" } }, "super_mac": "2B98B2019F8B235A8359AE2610A7F96A43DBF0394480F9F78FB8C26D6736E1E4" }, "session": { "restore_on_startup": 5, "startup_urls": [ "hxxp://www.jura.uni-muenchen.de/index.html" ] }, "sync": { "remaining_rollback_tries": 0 } } |
10.04.2015, 15:30 | #77 |
/// the machine /// TB-Ausbilder | Adware Roll around eingefangen Äusserst merkwürdig. Verbindest Du Chrome mit einem Google Konto?
__________________Lade SystemLook von jpshortstuff von einem der folgenden Spiegel herunter und speichere das Tool auf dem Desktop. SystemLook (64 bit)
__________________ |
10.04.2015, 16:33 | #78 |
Adware Roll around eingefangen Ja, ich verbinde Chrome mit einem Google Konto. Wird von dort aus der trovi "nachgeladen"??
__________________Code:
ATTFilter SystemLook 30.07.11 by jpshortstuff Log created at 17:29 on 10/04/2015 by Basiliuws Eber Administrator - Elevation successful ========== filefind ========== Searching for "*trovi*" C:\Games\World_of_Tanks\res\scripts\client\gui\scaleform\daapi\view\lobby\cybersport\cybersportintroview.pyc --a---- 5508 bytes [17:19 26/08/2014] [14:49 05/02/2015] 592B7F2ED889887BE884400D10D40917 C:\Games\World_of_Tanks\res\scripts\client\gui\scaleform\daapi\view\lobby\fortifications\components\fortintroview.pyc --a---- 5280 bytes [17:19 26/08/2014] [21:37 17/12/2014] E4733374A202919010675792E3328974 C:\Games\World_of_Tanks\res\scripts\client\gui\scaleform\daapi\view\lobby\rally\baserallyintroview.pyc --a---- 760 bytes [17:19 26/08/2014] [17:59 22/07/2014] E93DBE44F43A17FBDE1CC62594374155 C:\Games\World_of_Tanks\res\scripts\client\gui\scaleform\daapi\view\meta\baserallyintroviewmeta.pyc --a---- 491 bytes [17:19 26/08/2014] [17:59 22/07/2014] CA9FEFE565AA0A2BE00E9EA34B322108 ========== regfind ========== Searching for "trovi" No data found. -= EOF =- |
11.04.2015, 07:23 | #79 |
/// the machine /// TB-Ausbilder | Adware Roll around eingefangen Dann verbinde Chrome mit dem Google Konto, dann den Browser komplett zurücksetzen und die EInstellungen und erweiterten Einstellungen von Hand durchgehen, ob noch irgendwo was ist. Ebenso mal die Datei bei verbundenem Konto löschen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
11.04.2015, 19:36 | #80 |
Adware Roll around eingefangen Habe ich beides schon probiert, ohne Erfolg... |
12.04.2015, 07:57 | #81 |
/// the machine /// TB-Ausbilder | Adware Roll around eingefangen Chrome nochmal komplett mit Revo deinstallieren, NICHT neu installieren, dann ein frisches FRST log bitte.
__________________ --> Adware Roll around eingefangen |
12.04.2015, 15:20 | #82 |
Adware Roll around eingefangen Interessant: Habe Chrome mit dem Revon Uninstaller auf der sichersten Stufe komplett deinstalliert. Revo und CC Cleaner finden ihn jetzt nicht mehr. Das Icon auf dem Desktop ist aber immer noch da und er läßt sich immer nocht starten. Im Chrome Ordner gibt es 2 Unterordner mit 2 Programmversionen?? |
12.04.2015, 16:29 | #83 |
Adware Roll around eingefangen Aktuelle FRST Log: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Ran by Basiliuws Eber (administrator) on BASILGAMING on 12-04-2015 16:35:52 Running from C:\Users\Basiliuws Eber\Downloads Loaded Profiles: Basiliuws Eber & Basilius Eberle (Available profiles: Basiliuws Eber & Basilius Eberle) Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Creative Technology Ltd) C:\Windows\SysWOW64\CtHdaSvc.exe (devolo AG) C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe () C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe () C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe (IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe () C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe (Dropbox, Inc.) C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\Dropbox.exe (Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\SBRcni.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\CTJckCfg.exe (Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Gigabyte Technology CO., LTD.) C:\Program Files (x86)\GIGABYTE\Smart TimeLock\AlarmClock.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corporation) C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) C:\Windows\System32\SnippingTool.exe (Swiss Academic Software) C:\Program Files (x86)\Citavi 4\bin\Citavi.exe (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe () C:\Program Files (x86)\Opera\28.0.1750.51\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe (Opera Software) C:\Program Files (x86)\Opera\28.0.1750.51\opera.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2014-04-11] (Intel Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-02-13] (Apple Inc.) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [590144 2015-03-12] (Razer Inc.) HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.) HKLM-x32\...\Run: [Sound Blaster Recon3Di SBX Control Panel] => C:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\SBRcni.exe [976896 2012-11-28] (Creative Technology Ltd) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5511352 2015-03-22] (Avast Software s.r.o.) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [335232 2015-03-07] (Oracle Corporation) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707984 2014-11-19] (Cisco Systems, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [Google Update] => C:\Users\Basiliuws Eber\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-12-07] (Google Inc.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [MusicManager] => C:\Users\Basiliuws Eber\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7475200 2015-04-01] (Google Inc.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2015-01-28] (Garmin Ltd or its subsidiaries) HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\MountPoints2: {39a7bf0b-76dd-11e4-8299-001109e5f38b} - "H:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\MountPoints2: {3aed501f-9b74-11e4-82a3-001109e5f38b} - "H:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-2245731289-3221781707-2474736645-1001\...\MountPoints2: {8cb957cc-cd4d-11e4-82b6-001109e5f38b} - "H:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-2245731289-3221781707-2474736645-1004\...\Run: [GoogleChromeAutoLaunch_480223198B15635E392F8E5BDE9F021E] => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window HKU\S-1-5-21-2245731289-3221781707-2474736645-1004\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11776 2014-10-29] (Microsoft Corporation) AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [178512 2015-03-13] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [164568 2015-03-13] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE OC_GURU.lnk ShortcutTarget: GIGABYTE OC_GURU.lnk -> C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe (GIGABYTE Technology Co.,Ltd.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{401FADAA-1C16-4721-9F02-19067E1A1CA8}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC) Startup: C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (Avast Software s.r.o.) ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft) ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft) BootExecute: autocheck autochk * bootdelete ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2245731289-3221781707-2474736645-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft) BHO: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\system32\mscoree.dll [2013-08-22] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_40\bin\ssv.dll [2015-03-24] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-03-22] (Avast Software s.r.o.) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-24] (Oracle Corporation) BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2014-04-20] (IvoSoft) BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft) BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\SysWOW64\mscoree.dll [2013-08-22] (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-03-22] (Avast Software s.r.o.) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation) BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2014-04-20] (IvoSoft) Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20] (IvoSoft) Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20] (IvoSoft) DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-22] () FF Plugin: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-24] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-24] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-22] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2013-04-19] (CANON INC.) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-03-13] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-03-13] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2245731289-3221781707-2474736645-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Basiliuws Eber\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.) FF Plugin HKU\S-1-5-21-2245731289-3221781707-2474736645-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Basiliuws Eber\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.) FF Plugin HKU\S-1-5-21-2245731289-3221781707-2474736645-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-04-04] () FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-31] Chrome: ======= CHR StartupUrls: Default -> "hxxp://www.jura.uni-muenchen.de/index.html" CHR Profile: C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Adblock Plus) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-04-08] CHR Extension: (Avast Online Security) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-03-31] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-31] CHR Extension: (KML, KMZ Viewer with Drive) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbolhellljccdahaeelobbojpfdgjgco [2015-04-08] CHR Extension: (Hangouts) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2015-04-08] CHR Extension: (Google Wallet) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-03-31] CHR Extension: (Citavi Picker) - C:\Users\Basiliuws Eber\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohgndokldibnndfnjnagojmheejlengn [2015-04-04] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-22] CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14] CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn] - https://clients2.google.com/service/update2/crx Opera: ======= OPR Extension: (Adblock Plus) - C:\Users\Basiliuws Eber\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2015-03-20] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.) S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] () R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-03-22] (Avast Software s.r.o.) R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4030800 2015-03-22] (Avast Software) S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2014-05-31] (Creative Labs) [File not signed] S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2014-05-31] (Creative Labs) [File not signed] R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [423424 2012-10-08] (Creative Technology Ltd) [File not signed] R2 CtHdaSvc; C:\Windows\sysWow64\CtHdaSvc.exe [103936 2014-04-29] (Creative Technology Ltd) R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [3736520 2015-01-29] (devolo AG) S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [528096 2014-06-08] (Futuremark) R2 gadjservice; C:\Program Files (x86)\Gigabyte\AppCenter\AdjustService.exe [16384 2014-04-16] () [File not signed] S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [517464 2015-01-28] (Garmin Ltd or its subsidiaries) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation) R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2014-06-27] (Nero AG) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-04-11] (Intel Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed] R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-03-20] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-03-17] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation) R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed] R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-06-01] () R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [343040 2013-08-08] (Qualcomm Atheros) [File not signed] R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187072 2015-02-05] () R2 Smart TimeLock; C:\Program Files (x86)\GIGABYTE\Smart TimeLock\TimeMgmtDaemon.exe [102400 2013-02-22] (Gigabyte Technology CO., LTD.) [File not signed] S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation) Code:
ATTFilter ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.) R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [150440 2014-12-23] (SlySoft, Inc.) R3 AnyDVD; C:\Windows\SysWOW64\Drivers\AnyDVD.sys [150440 2014-12-23] (SlySoft, Inc.) R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22240 2013-10-28] () R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-03-22] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [88408 2015-03-22] (Avast Software s.r.o.) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-03-22] (Avast Software s.r.o.) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-03-22] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-03-22] (Avast Software s.r.o.) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [441728 2015-03-22] (Avast Software s.r.o.) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [136752 2015-03-22] (Avast Software s.r.o.) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [268640 2015-03-22] () S3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices) R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [75056 2013-02-13] (Qualcomm Atheros, Inc.) R3 cthda; C:\Windows\system32\drivers\cthda.sys [1050904 2014-04-29] (Creative Technology Ltd) R2 DRHARD64; C:\Windows\system32\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software) R2 DRHARD64; C:\Windows\SysWOW64\drivers\DRHARD64.sys [21984 2011-11-03] (Licensed for Gebhard Software) R2 DRHMSR64; C:\Windows\system32\drivers\DRHMSR64.sys [13760 2013-07-21] () R2 DRHMSR64; C:\Windows\SysWOW64\drivers\DRHMSR64.sys [13760 2013-07-21] () S3 etocdrv; C:\Windows\etocdrv.sys [15584 2013-10-30] (Giga-Byte Technology CO., LTD.) S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] () S3 HtcVCom32; C:\Windows\system32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated) R3 Ke2200; C:\Windows\system32\DRIVERS\e22w8x64.sys [163536 2013-03-20] (Qualcomm Atheros, Inc.) R1 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [107736 2015-03-17] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-04-12] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-03-17] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [118272 2014-03-20] (Intel Corporation) R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2015-01-29] (CACE Technologies) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation) S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] () S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] () R3 rzdaendpt; C:\Windows\System32\drivers\rzdaendpt.sys [33448 2014-09-05] (Razer Inc) R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2015-02-05] (Razer, Inc.) R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129600 2014-10-23] (Razer, Inc.) R3 rzvkeyboard; C:\Windows\System32\drivers\rzvkeyboard.sys [31912 2014-12-30] (Razer Inc) S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2014-05-17] (Anchorfree Inc.) S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2013-03-18] (Apple, Inc.) [File not signed] S1 UsbCharger; C:\Windows\System32\DRIVERS\UsbCharger.sys [22240 2013-10-24] () R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-03-22] (Avast Software) S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52592 2014-11-19] (Cisco Systems, Inc.) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation) S3 DRHARD; \??\C:\Windows\system32\DRIVERS\DRHARD.SYS [X] S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X] Code:
ATTFilter ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-12 16:30 - 2015-04-12 16:30 - 00053168 _____ () C:\Users\Basiliuws Eber\Desktop\HitmanPro_20150412_1630.log 2015-04-12 16:30 - 2015-04-12 16:30 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe 2015-04-12 16:30 - 2015-04-12 16:30 - 00000258 _____ () C:\Windows\system32\bootdelete.lst 2015-04-11 20:44 - 2015-04-11 20:44 - 00000000 ____D () C:\ProgramData\DAEMON Tools Lite 2015-04-11 16:51 - 2015-04-11 16:51 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Bewerbungen 2015-04-11 13:12 - 2015-04-12 16:23 - 00000000 ____D () C:\AdwCleaner 2015-04-11 13:12 - 2015-04-11 13:12 - 02217984 _____ () C:\Users\Basiliuws Eber\Downloads\AdwCleaner_4.201.exe 2015-04-10 19:20 - 2015-04-10 19:20 - 00000710 _____ () C:\Users\Basiliuws Eber\Desktop\World of Tanks.lnk 2015-04-10 19:20 - 2015-04-10 19:20 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\World of Tanks 2015-04-10 19:19 - 2015-04-10 19:19 - 05995160 _____ (Wargaming.net ) C:\Users\Basiliuws Eber\Downloads\WoT_internet_install_eu.exe 2015-04-10 17:29 - 2015-04-10 17:29 - 00165376 _____ () C:\Users\Basiliuws Eber\Desktop\SystemLook_x64.exe 2015-04-08 21:23 - 2015-04-08 21:23 - 00000000 ____D () C:\Users\Basiliuws Eber\.pdfsam 2015-04-08 21:18 - 2015-04-08 21:18 - 30843037 _____ () C:\Users\Basiliuws Eber\Downloads\PDFsam_224 (1).zip 2015-04-08 21:18 - 2015-04-08 21:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Split And Merge Basic 2015-04-08 21:18 - 2015-04-08 21:18 - 00000000 ____D () C:\Program Files\PDF Split And Merge Basic 2015-04-08 21:18 - 2014-06-26 09:23 - 16358440 _____ () C:\Users\Basiliuws Eber\Downloads\pdfsam-x64-v2_2_4.msi 2015-04-08 21:18 - 2014-06-26 09:22 - 16358452 _____ () C:\Users\Basiliuws Eber\Downloads\pdfsam-x86-v2_2_4.msi 2015-04-08 21:14 - 2015-04-08 21:14 - 30843037 _____ () C:\Users\Basiliuws Eber\Downloads\PDFsam_224.zip 2015-04-08 18:34 - 2015-04-08 18:34 - 02209056 _____ () C:\Users\Basiliuws Eber\Downloads\avira-eu-cleaner_de.exe 2015-04-06 18:05 - 2015-04-06 18:05 - 00000201 _____ () C:\Users\Basiliuws Eber\Downloads\fhsexport_endnote.enw 2015-04-06 17:02 - 2015-04-06 17:02 - 36450560 _____ (NVIDIA Corporation) C:\Users\Basiliuws Eber\Downloads\GeForce_Experience_v2.4.1.21 (1).exe 2015-04-06 17:02 - 2015-04-06 17:02 - 00002160 _____ () C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk 2015-04-06 17:01 - 2015-04-12 16:08 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-04-06 17:01 - 2015-03-13 18:16 - 06861968 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2015-04-06 17:01 - 2015-03-13 18:16 - 03526856 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2015-04-06 17:01 - 2015-03-13 18:16 - 02559808 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2015-04-06 17:01 - 2015-03-13 18:16 - 00935056 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2015-04-06 17:01 - 2015-03-13 18:16 - 00386248 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2015-04-06 17:01 - 2015-03-13 18:16 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2015-04-06 17:01 - 2015-03-13 17:38 - 00622224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2015-04-06 17:01 - 2015-03-11 15:10 - 04246327 _____ () C:\Windows\system32\nvcoproc.bin 2015-04-06 17:00 - 2015-04-06 17:00 - 00000000 ____D () C:\NVIDIA 2015-04-06 17:00 - 2015-03-13 21:41 - 32114888 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 25460880 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 24775368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 20466376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 18580512 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 17258024 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 16022016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 14121624 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 13297144 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 13210080 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 10775080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 10715864 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 10262160 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2015-04-06 17:00 - 2015-03-13 21:41 - 03611792 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 03303448 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 03249352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 02906928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 01896136 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434788.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434788.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 01556624 _____ (NVIDIA Corporation) C:\Windows\system32\nvir3dgenco64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 01540240 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00997856 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00970384 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00944784 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00930448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00909512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00878328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00833680 _____ () C:\Windows\system32\nvmcumd.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00496272 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00452424 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstusb.sys 2015-04-06 17:00 - 2015-03-13 21:41 - 00400584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00390288 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00354112 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00346824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00306208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00195728 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2015-04-06 17:00 - 2015-03-13 21:41 - 00178512 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00164568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00030536 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2015-04-06 17:00 - 2015-03-13 21:41 - 00027441 _____ () C:\Windows\system32\nvinfo.pb 2015-04-06 16:57 - 2015-04-06 16:59 - 309143408 _____ (NVIDIA Corporation) C:\Users\Basiliuws Eber\Downloads\347.88-desktop-win8-win7-winvista-64bit-international-whql.exe 2015-04-05 16:35 - 2015-04-05 16:35 - 00046575 _____ () C:\Users\Basiliuws Eber\Downloads\Addition.txt 2015-04-05 16:34 - 2015-04-12 16:35 - 00030706 _____ () C:\Users\Basiliuws Eber\Downloads\FRST.txt 2015-04-05 16:34 - 2015-04-12 16:35 - 00000000 ____D () C:\FRST 2015-04-05 16:34 - 2015-04-05 16:34 - 02095616 _____ (Farbar) C:\Users\Basiliuws Eber\Downloads\FRST64.exe 2015-04-04 20:59 - 2015-04-04 20:59 - 00003619 _____ () C:\Users\Basiliuws Eber\Downloads\download.ris 2015-04-04 17:35 - 2015-04-04 17:35 - 00166325 _____ () C:\Users\Basiliuws Eber\Downloads\sackpfeife_tief_c_ein_bordun_trichter.mp4 2015-04-04 17:34 - 2015-04-04 17:34 - 00194216 _____ () C:\Users\Basiliuws Eber\Downloads\sackpfeife_1_in_g_ein_bordun_trichter.mp4 2015-04-04 17:10 - 2015-04-06 22:13 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Mp3tag 2015-04-04 17:09 - 2015-04-04 17:09 - 00001002 _____ () C:\Users\Public\Desktop\Mp3tag.lnk 2015-04-04 17:09 - 2015-04-04 17:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag 2015-04-04 17:09 - 2015-04-04 17:09 - 00000000 ____D () C:\Program Files (x86)\Mp3tag 2015-04-04 17:08 - 2015-04-04 17:08 - 02802944 _____ () C:\Users\Basiliuws Eber\Downloads\mp3tagv269setup.exe 2015-04-04 16:53 - 2015-04-04 16:53 - 00000823 _____ () C:\Users\Basiliuws Eber\Desktop\Far Cry 4 Gold Edition.lnk 2015-04-04 12:37 - 2015-04-04 12:37 - 00000000 ___SD () C:\Windows\SysWOW64\GWX 2015-04-04 12:37 - 2015-04-04 12:37 - 00000000 ___SD () C:\Windows\system32\GWX 2015-04-04 11:06 - 2015-04-04 16:57 - 00037174 _____ () C:\Windows\DirectX.log 2015-04-04 11:01 - 2015-04-06 17:11 - 00001404 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk 2015-04-04 11:01 - 2015-04-04 11:01 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\NVIDIA 2015-04-04 11:01 - 2015-03-28 05:44 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2015-04-04 11:01 - 2015-03-28 05:44 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll 2015-04-04 11:01 - 2015-03-28 05:43 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll 2015-04-04 11:01 - 2015-03-28 05:43 - 01570672 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2015-04-04 11:01 - 2014-11-22 12:46 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2015-04-04 11:01 - 2014-11-22 12:46 - 00035472 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2015-04-04 11:01 - 2014-11-22 12:46 - 00032400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2015-04-04 11:00 - 2015-04-04 11:00 - 36450560 _____ (NVIDIA Corporation) C:\Users\Basiliuws Eber\Downloads\GeForce_Experience_v2.4.1.21.exe 2015-04-03 16:08 - 2015-04-03 16:08 - 00000222 _____ () C:\Users\Basiliuws Eber\Desktop\Far Cry 3 Blood Dragon.url 2015-04-02 14:57 - 2015-04-02 14:57 - 00000000 ____D () C:\ProgramData\Gibraltar 2015-04-02 13:48 - 2015-04-02 13:48 - 00002267 _____ () C:\Users\Basiliuws Eber\Downloads\Lesch2014deutsche.bib 2015-04-01 21:23 - 2015-04-01 21:23 - 00001846 _____ () C:\DelFix.txt 2015-04-01 21:23 - 2015-04-01 21:23 - 00000000 ____D () C:\Windows\ERUNT 2015-04-01 20:55 - 2015-04-01 20:55 - 00781312 _____ () C:\Users\Basiliuws Eber\Downloads\delfix_10.9.exe 2015-04-01 20:29 - 2015-04-01 20:29 - 00000000 ____D () C:\Users\Basiliuws Eber\Desktop\ProcessExplorer 2015-04-01 20:28 - 2015-04-01 20:29 - 01125626 _____ () C:\Users\Basiliuws Eber\Downloads\ProcessExplorer.zip 2015-04-01 18:30 - 2015-03-16 16:38 - 01713824 _____ (techPowerUp (www.techpowerup.com)) C:\Users\Basiliuws Eber\Downloads\GPU-Z.0.8.2.exe 2015-04-01 18:30 - 2007-02-18 04:34 - 00000140 _____ () C:\Users\Basiliuws Eber\Downloads\SysProfile.de--Dein_Systemprofil_online.url 2015-04-01 18:29 - 2015-04-01 18:29 - 00109549 _____ () C:\Users\Basiliuws Eber\Documents\BASILGAMING.txt 2015-04-01 18:25 - 2015-04-01 18:26 - 01582736 _____ ( ) C:\Users\Basiliuws Eber\Downloads\cpu-z_1.72-en.exe 2015-04-01 18:11 - 2015-04-01 18:11 - 08146560 _____ (TeamViewer GmbH) C:\Users\Basiliuws Eber\Downloads\TeamViewer_Setup.exe 2015-03-31 13:20 - 2015-03-31 13:22 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\2015-03-31 2015-03-31 11:17 - 2015-03-31 11:17 - 00000504 _____ () C:\Users\Basiliuws Eber\Downloads\Chip.txt 2015-03-31 10:51 - 2015-03-31 10:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-03-31 10:50 - 2015-03-31 10:50 - 00880208 _____ (Google Inc.) C:\Users\Basiliuws Eber\Downloads\ChromeSetup.exe 2015-03-31 10:45 - 2015-03-31 10:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Basiliuws Eber\Downloads\revosetup95.exe 2015-03-31 10:45 - 2015-03-31 10:45 - 00001291 _____ () C:\Users\Basiliuws Eber\Desktop\Revo Uninstaller.lnk 2015-03-31 10:45 - 2015-03-31 10:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2015-03-30 19:35 - 2015-03-30 19:35 - 00008793 _____ () C:\Users\Basiliuws Eber\Downloads\28.3.2015 10-07.kmz 2015-03-30 18:33 - 2015-03-30 18:35 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\2015-03-30 2015-03-30 16:24 - 2015-03-30 16:24 - 13087456 _____ (Microsoft Corporation) C:\Users\Basiliuws Eber\Downloads\Silverlight_x64.exe 2015-03-30 14:23 - 2015-03-30 14:23 - 00000165 _____ () C:\Users\Basiliuws Eber\Downloads\scholar.enw 2015-03-30 08:39 - 2015-04-01 20:49 - 00000000 ____D () C:\Program Files (x86)\Universal Media Server 2015-03-30 08:39 - 2015-04-01 18:09 - 00000000 ____D () C:\ProgramData\UMS 2015-03-30 08:39 - 2015-03-30 09:01 - 00001951 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Universal Media Server.lnk 2015-03-30 08:39 - 2015-03-30 09:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Universal Media Server 2015-03-30 08:39 - 2015-03-30 08:39 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AviSynth 2015-03-30 08:39 - 2015-03-30 08:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviSynth 2015-03-30 08:38 - 2015-03-30 08:38 - 60871278 _____ () C:\Users\Basiliuws Eber\Downloads\UMS-5.1.0-Java7.exe 2015-03-29 22:09 - 2015-03-29 22:09 - 00000000 ____D () C:\ProgramData\Creative Labs 2015-03-29 22:02 - 2015-03-29 22:02 - 00000000 ____D () C:\Program Files (x86)\OpenAL 2015-03-28 19:41 - 2015-03-28 19:41 - 00000504 _____ () C:\Users\Basiliuws Eber\Downloads\regfix.reg 2015-03-27 01:46 - 2015-03-27 01:46 - 00001209 _____ () C:\Users\Basiliuws Eber\Downloads\HTC Support Chat.txt 2015-03-26 09:47 - 2015-03-26 09:52 - 00000000 ____D () C:\Users\Basiliuws Eber\Downloads\Garmin Blitzer 2015-03-26 09:31 - 2015-03-26 09:31 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Garmin 2015-03-26 09:23 - 2015-03-26 09:23 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Mein Garmin 2015-03-26 09:23 - 2015-03-26 09:23 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Garmin 2015-03-26 09:20 - 2015-03-26 09:20 - 00003556 _____ () C:\Windows\System32\Tasks\GarminUpdaterTask 2015-03-26 09:20 - 2015-03-26 09:20 - 00001911 _____ () C:\Users\Public\Desktop\Garmin Express.lnk 2015-03-26 09:19 - 2015-03-26 09:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin 2015-03-26 09:16 - 2015-03-26 09:16 - 00000319 _____ () C:\Users\Basiliuws Eber\Downloads\Garmin-InternetExplorer-Shortcut.vbs 2015-03-26 09:03 - 2015-04-12 16:08 - 00007356 _____ () C:\Windows\PFRO.log 2015-03-25 22:37 - 2015-03-26 00:45 - 00000000 ____D () C:\ProgramData\boost_interprocess 2015-03-25 22:33 - 2015-03-25 22:33 - 00001364 _____ () C:\Users\Public\Desktop\NAVIGON Fresh.lnk 2015-03-25 22:33 - 2015-03-25 22:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NAVIGON 2015-03-25 22:33 - 2015-03-25 22:33 - 00000000 ____D () C:\Program Files (x86)\NAVIGON 2015-03-25 22:30 - 2015-03-25 22:30 - 24192080 _____ (GARMIN Würzburg GmbH) C:\Users\Basiliuws Eber\Downloads\ud_setup_win_351.exe 2015-03-25 22:13 - 2015-03-25 22:13 - 01917440 _____ () C:\Users\Basiliuws Eber\Downloads\XmlNotepad25.msi 2015-03-25 22:13 - 2015-03-25 22:13 - 00001950 _____ () C:\Users\Basiliuws Eber\Desktop\XML Notepad 2007.lnk 2015-03-25 22:13 - 2015-03-25 22:13 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XML Notepad 2007 2015-03-25 22:13 - 2015-03-25 22:13 - 00000000 ____D () C:\Program Files (x86)\XML Notepad 2007 2015-03-25 15:15 - 2015-03-25 15:15 - 00030950 _____ () C:\Windows\DPINST.LOG 2015-03-25 15:04 - 2015-04-12 16:08 - 00009963 _____ () C:\Windows\setupact.log 2015-03-25 15:04 - 2015-03-25 15:04 - 03344552 _____ (Cisco Systems, Inc.) C:\Users\Basiliuws Eber\Downloads\anyconnect-win-3.1.06073-web-deploy-k9.exe 2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Cisco 2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco 2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\ProgramData\Cisco 2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 ____D () C:\Program Files (x86)\Cisco 2015-03-25 15:04 - 2015-03-25 15:04 - 00000000 _____ () C:\Windows\setuperr.log 2015-03-25 15:04 - 2014-11-19 17:09 - 00112496 ____R (Cisco Systems, Inc.) C:\Windows\system32\Drivers\acsock64.sys 2015-03-25 14:53 - 2015-04-12 16:30 - 01445431 _____ () C:\Windows\WindowsUpdate.log 2015-03-25 10:26 - 2015-03-11 04:38 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 01107456 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 00943104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-03-25 10:26 - 2015-03-11 00:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-03-24 18:02 - 2015-03-24 18:02 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Swiss Academic Software Code:
ATTFilter 2015-03-24 17:54 - 2015-04-12 16:23 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Citavi 4 2015-03-24 17:54 - 2015-04-10 01:21 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Swiss Academic Software 2015-03-24 17:54 - 2015-04-02 13:43 - 00000000 ____D () C:\ProgramData\Swiss Academic Software 2015-03-24 17:51 - 2015-03-24 17:51 - 00001972 _____ () C:\Users\Public\Desktop\Citavi 4.lnk 2015-03-24 17:51 - 2015-03-24 17:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citavi 4 2015-03-24 17:51 - 2015-03-24 17:51 - 00000000 ____D () C:\Program Files (x86)\Citavi 4 2015-03-24 17:40 - 2015-03-24 17:41 - 81307064 _____ (Swiss Academic Software) C:\Users\Basiliuws Eber\Downloads\Citavi4Setup.exe 2015-03-24 13:33 - 2007-08-11 15:38 - 00810952 _____ (Charles DeWeese) C:\Users\Basiliuws Eber\Downloads\FlashSfv.exe 2015-03-24 13:13 - 2015-03-24 13:13 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2015-03-24 13:13 - 2015-03-24 13:13 - 00000000 ____D () C:\Program Files\Java 2015-03-24 13:12 - 2015-03-24 13:12 - 42925480 _____ (Oracle Corporation) C:\Users\Basiliuws Eber\Downloads\jre-8u40-windows-x64.exe 2015-03-24 12:35 - 2015-03-24 15:26 - 00000000 ____D () C:\Program Files (x86)\Dr. Hardware 2015 2015-03-24 12:35 - 2015-03-24 12:35 - 00001003 _____ () C:\Users\Basiliuws Eber\Desktop\Dr. Hardware 2015.lnk 2015-03-24 12:35 - 2015-03-24 12:35 - 00001003 _____ () C:\Users\Basilius Eberle\Desktop\Dr. Hardware 2015.lnk 2015-03-24 12:35 - 2015-03-24 12:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dr. Hardware 2015 2015-03-24 12:35 - 2013-07-21 18:41 - 00013760 _____ () C:\Windows\SysWOW64\Drivers\DRHMSR64.sys 2015-03-24 12:35 - 2013-07-21 18:41 - 00013760 _____ () C:\Windows\system32\Drivers\DRHMSR64.sys 2015-03-24 12:35 - 2011-11-03 19:05 - 00021984 _____ (Licensed for Gebhard Software) C:\Windows\SysWOW64\Drivers\DRHARD64.sys 2015-03-24 12:35 - 2011-11-03 19:05 - 00021984 _____ (Licensed for Gebhard Software) C:\Windows\system32\Drivers\DRHARD64.sys 2015-03-24 11:37 - 2015-03-24 11:37 - 11800240 _____ () C:\Users\Basiliuws Eber\Downloads\SetupAnyDVD7590.exe 2015-03-23 09:48 - 2015-03-23 09:48 - 00001732 _____ () C:\Users\Public\Desktop\iTunes.lnk 2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7 2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\Program Files\iTunes 2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\Program Files\iPod 2015-03-23 09:48 - 2015-03-23 09:48 - 00000000 ____D () C:\Program Files (x86)\iTunes 2015-03-22 23:27 - 2015-03-22 23:27 - 00364472 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe 2015-03-22 23:27 - 2015-03-22 23:27 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr 2015-03-20 09:53 - 2015-03-20 09:53 - 00000197 _____ () C:\Windows\system32\2015-03-20-07-53-19.037-AvastVBoxSVC.exe-3568.log 2015-03-20 09:09 - 2015-03-20 09:09 - 00000197 _____ () C:\Windows\system32\2015-03-20-07-09-20.093-AvastVBoxSVC.exe-3640.log 2015-03-20 00:56 - 2015-03-20 00:56 - 00000247 _____ () C:\Windows\system32\2015-03-19-22-56-47.018-aswFe.exe-5100.log 2015-03-20 00:55 - 2015-03-20 00:56 - 00000247 _____ () C:\Windows\system32\2015-03-19-22-55-00.053-aswFe.exe-892.log 2015-03-20 00:54 - 2015-03-20 00:54 - 00000197 _____ () C:\Windows\system32\2015-03-19-22-54-59.047-AvastVBoxSVC.exe-3240.log 2015-03-20 00:44 - 2015-03-20 00:44 - 00588816 _____ () C:\Users\Basiliuws Eber\Downloads\Autoruns.zip 2015-03-20 00:44 - 2015-03-20 00:44 - 00000000 ____D () C:\Users\Basiliuws Eber\Downloads\Autoruns 2015-03-20 00:27 - 2015-03-20 00:27 - 05325696 _____ (Piriform Ltd) C:\Users\Basiliuws Eber\Downloads\ccsetup503.exe 2015-03-18 15:06 - 2015-03-20 00:49 - 00001540 _____ () C:\Users\Basiliuws Eber\Downloads\malwarebytes.txt 2015-03-18 14:54 - 2015-03-18 14:54 - 00000197 _____ () C:\Windows\system32\2015-03-18-12-54-46.089-AvastVBoxSVC.exe-3700.log 2015-03-18 14:53 - 2015-03-18 14:53 - 00000358 _____ () C:\Windows\system32\.crusader 2015-03-18 14:23 - 2015-03-18 14:23 - 00000247 _____ () C:\Windows\system32\2015-03-18-12-23-15.080-aswFe.exe-7992.log 2015-03-18 14:21 - 2015-03-18 14:23 - 00000247 _____ () C:\Windows\system32\2015-03-18-12-21-12.001-aswFe.exe-3104.log 2015-03-18 14:21 - 2015-03-18 14:21 - 00000197 _____ () C:\Windows\system32\2015-03-18-12-21-10.073-AvastVBoxSVC.exe-956.log 2015-03-18 13:04 - 2015-03-18 13:04 - 02953520 _____ (AVAST Software) C:\Users\Basiliuws Eber\Downloads\avast-browser-cleanup.exe 2015-03-18 12:31 - 2015-01-29 15:24 - 00221184 _____ (CACE Technologies) C:\Windows\SysWOW64\devolopcap.dll 2015-03-18 12:31 - 2015-01-29 15:24 - 00081920 _____ (CACE Technologies) C:\Windows\SysWOW64\devolopacket.dll 2015-03-18 12:31 - 2015-01-29 15:24 - 00034048 _____ (CACE Technologies) C:\Windows\SysWOW64\Drivers\npf_devolo.sys 2015-03-18 11:04 - 2015-03-18 11:05 - 00000197 _____ () C:\Windows\system32\2015-03-18-09-04-59.098-AvastVBoxSVC.exe-3500.log 2015-03-18 10:50 - 2015-03-18 10:50 - 00000197 _____ () C:\Windows\system32\2015-03-18-08-50-08.045-AvastVBoxSVC.exe-3460.log 2015-03-18 10:46 - 2015-03-18 10:46 - 00001178 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk 2015-03-18 10:46 - 2015-03-18 10:46 - 00001128 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk 2015-03-18 10:46 - 2015-03-18 10:46 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Canneverbe Limited 2015-03-18 10:46 - 2015-03-18 10:46 - 00000000 ____D () C:\ProgramData\Canneverbe Limited 2015-03-18 10:46 - 2015-03-18 10:46 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP 2015-03-18 10:45 - 2015-03-18 10:45 - 05409016 _____ (Canneverbe Limited ) C:\Users\Basiliuws Eber\Downloads\cdbxp_setup_4.5.4.5306_minimal.exe 2015-03-17 23:37 - 2015-03-17 23:36 - 03312872 _____ (DVDVideoSoft Ltd. ) C:\Users\Basiliuws 2015-03-17 23:36 - 2015-03-18 09:55 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\DVDVideoSoft 2015-03-17 11:03 - 2015-03-17 11:03 - 00005364 _____ () C:\Users\Basiliuws Eber\Downloads\13.3.2015 19-50.kmz 2015-03-16 19:43 - 2015-03-16 19:43 - 00000197 _____ () C:\Windows\system32\2015-03-16-17-43-42.097-AvastVBoxSVC.exe-3712.log 2015-03-16 11:50 - 2015-03-16 11:50 - 19759661 _____ () C:\Users\Basiliuws Eber\Downloads\SpringBloomsRebeccaHeigel.themepack 2015-03-15 21:35 - 2015-03-15 21:35 - 00000197 _____ () C:\Windows\system32\2015-03-15-19-35-41.095-AvastVBoxSVC.exe-3548.log 2015-03-15 21:26 - 2015-03-15 21:26 - 00000000 ____D () C:\Users\Basiliuws Eber\Tracing 2015-03-15 21:24 - 2015-03-15 21:26 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-03-15 21:24 - 2015-03-15 21:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-03-15 21:06 - 2015-03-15 21:07 - 00000197 _____ () C:\Windows\system32\2015-03-15-19-06-30.070-AvastVBoxSVC.exe-3456.log 2015-03-15 20:57 - 2015-03-15 20:58 - 00000197 _____ () C:\Windows\system32\2015-03-15-18-57-47.015-AvastVBoxSVC.exe-3552.log 2015-03-14 19:09 - 2015-03-06 04:53 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-03-14 19:09 - 2015-03-06 04:33 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-03-14 19:09 - 2015-02-26 01:26 - 04178944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-03-14 19:09 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-03-14 19:09 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-03-14 19:09 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-03-14 19:09 - 2015-02-21 02:27 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2015-03-14 19:09 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-03-14 19:09 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-03-14 19:09 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-03-14 19:09 - 2015-02-20 05:03 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-03-14 19:09 - 2015-02-20 04:58 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-03-14 19:09 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-03-14 19:09 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-03-14 19:09 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-03-14 19:09 - 2015-02-20 04:35 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-03-14 19:09 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-03-14 19:09 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-03-14 19:09 - 2015-02-20 04:20 - 00301056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2015-03-14 19:09 - 2015-02-20 04:15 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2015-03-14 19:09 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-03-14 19:09 - 2015-02-20 04:07 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2015-03-14 19:09 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-03-14 19:09 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-03-14 19:09 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-03-14 19:09 - 2015-02-20 03:59 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2015-03-14 19:09 - 2015-02-20 03:56 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2015-03-14 19:09 - 2015-02-20 03:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-03-14 19:09 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-03-14 19:09 - 2015-02-20 03:49 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-03-14 19:09 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-03-14 19:09 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-03-14 19:09 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-03-14 19:09 - 2015-02-20 03:30 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2015-03-14 19:09 - 2015-02-20 03:29 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2015-03-14 19:09 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-03-14 19:09 - 2015-02-20 03:26 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2015-03-14 19:09 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-03-14 19:09 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-03-14 19:09 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-03-14 19:09 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-03-14 19:09 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-03-14 19:09 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-03-14 19:09 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-03-14 19:09 - 2015-02-07 01:09 - 00396419 _____ () C:\Windows\system32\ApnDatabase.xml 2015-03-14 19:09 - 2015-02-06 03:28 - 02257408 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2015-03-14 19:09 - 2015-02-06 03:08 - 01943040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2015-03-14 19:09 - 2015-02-05 22:24 - 01113920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2015-03-14 19:09 - 2015-02-04 01:58 - 00264000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys 2015-03-14 19:09 - 2015-02-04 01:58 - 00114496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdNisDrv.sys 2015-03-14 19:09 - 2015-02-04 01:58 - 00044024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys 2015-03-14 19:09 - 2015-02-03 02:03 - 03551744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll 2015-03-14 19:09 - 2015-02-03 02:02 - 04298240 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll 2015-03-14 19:09 - 2015-02-03 01:53 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\winshfhc.dll 2015-03-14 19:09 - 2015-02-03 01:53 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winshfhc.dll 2015-03-14 19:09 - 2015-01-31 01:42 - 03097600 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll 2015-03-14 19:09 - 2015-01-31 01:29 - 02484224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll 2015-03-14 19:09 - 2015-01-31 01:20 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2015-03-14 19:09 - 2015-01-30 05:01 - 00097792 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidbth.sys 2015-03-14 19:09 - 2015-01-30 05:00 - 00167424 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\rfcomm.sys 2015-03-14 19:09 - 2015-01-30 04:03 - 01488896 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll 2015-03-14 19:09 - 2015-01-30 04:03 - 01464832 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll 2015-03-14 19:09 - 2015-01-30 04:02 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll 2015-03-14 19:09 - 2015-01-30 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42u.dll 2015-03-14 19:09 - 2015-01-30 03:42 - 01204224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc42.dll 2015-03-14 19:09 - 2015-01-30 03:40 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappgnui.dll 2015-03-14 19:09 - 2015-01-30 03:37 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll 2015-03-14 19:09 - 2015-01-30 03:29 - 00035840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atlthunk.dll 2015-03-14 19:09 - 2015-01-30 03:24 - 00339456 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll 2015-03-14 19:09 - 2015-01-30 03:24 - 00250880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapp3hst.dll 2015-03-14 19:09 - 2015-01-30 03:16 - 00266752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eapphost.dll 2015-03-14 19:09 - 2015-01-30 03:08 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\eappcfg.dll 2015-03-14 19:09 - 2015-01-30 03:06 - 00278016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\eappcfg.dll 2015-03-14 19:09 - 2015-01-29 03:58 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll 2015-03-14 19:09 - 2015-01-29 03:29 - 00290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\photowiz.dll 2015-03-14 19:09 - 2015-01-29 03:11 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2015-03-14 19:09 - 2015-01-29 03:04 - 01091072 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2015-03-14 19:09 - 2015-01-29 03:04 - 00864256 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2015-03-14 19:09 - 2015-01-29 03:00 - 00210944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2015-03-14 19:09 - 2015-01-29 02:59 - 02773504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2015-03-14 19:09 - 2015-01-29 02:55 - 00971776 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2015-03-14 19:09 - 2015-01-29 02:50 - 00811008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2015-03-14 19:09 - 2015-01-29 02:49 - 02459136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2015-03-14 19:09 - 2015-01-28 17:41 - 07472960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-03-14 19:09 - 2015-01-28 17:41 - 01733440 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-03-14 19:09 - 2015-01-28 17:41 - 01498360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-03-14 19:09 - 2015-01-28 04:24 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\StorageContextHandler.dll 2015-03-14 19:09 - 2015-01-28 03:47 - 00060928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StorageContextHandler.dll 2015-03-14 19:09 - 2015-01-27 06:22 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2015-03-14 19:09 - 2015-01-27 05:44 - 00933888 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe 2015-03-14 19:09 - 2015-01-27 04:11 - 03547648 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2015-03-14 19:09 - 2015-01-24 03:51 - 00816128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\calc.exe 2015-03-14 19:09 - 2015-01-23 09:17 - 00723072 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2015-03-14 19:09 - 2015-01-23 07:02 - 00560392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2015-03-14 19:08 - 2015-02-12 19:40 - 22291584 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2015-03-14 19:08 - 2015-02-12 19:34 - 19731824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2015-03-14 19:08 - 2015-02-08 01:57 - 01090048 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll 2015-03-14 19:08 - 2015-02-08 01:49 - 00791040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll 2015-03-14 19:08 - 2015-01-29 20:45 - 01763352 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-03-14 19:08 - 2015-01-29 20:34 - 01488040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2015-03-14 19:08 - 2015-01-28 03:31 - 00402432 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2015-03-14 19:08 - 2015-01-28 03:11 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2015-03-14 19:08 - 2015-01-28 01:47 - 02501368 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2015-03-14 19:08 - 2015-01-28 01:41 - 02207488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2015-03-14 19:08 - 2015-01-21 07:54 - 01384712 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2015-03-14 19:08 - 2015-01-21 07:15 - 01123848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2015-03-14 19:08 - 2014-12-11 07:36 - 00046456 _____ (Microsoft Corporation) C:\Windows\system32\LockScreenContentServer.exe 2015-03-14 19:06 - 2015-03-14 19:06 - 00000197 _____ () C:\Windows\system32\2015-03-14-17-06-15.019-AvastVBoxSVC.exe-3404.log 2015-03-14 07:49 - 2015-03-14 07:49 - 00009728 _____ (Razer Inc.) C:\Windows\SysWOW64\RzStats.IPC.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-12 16:34 - 2014-05-31 12:19 - 00000000 ____D () C:\Program Files (x86)\Google 2015-04-12 16:22 - 2014-09-15 21:39 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-04-12 16:19 - 2014-05-31 15:38 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\ClassicShell 2015-04-12 16:14 - 2014-05-31 17:26 - 01789004 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-04-12 16:14 - 2014-05-31 11:30 - 00003978 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{ADF8F266-BC9E-412C-B8EE-DDA5E6A3C8C5} 2015-04-12 16:14 - 2013-08-23 01:24 - 00768888 _____ () C:\Windows\system32\perfh007.dat 2015-04-12 16:14 - 2013-08-23 01:24 - 00160706 _____ () C:\Windows\system32\perfc007.dat 2015-04-12 16:10 - 2014-12-25 15:31 - 00006533 _____ () C:\Windows\SysWOW64\Gms.log 2015-04-12 16:09 - 2014-11-30 14:35 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\HTC MediaHub 2015-04-12 16:09 - 2014-05-31 17:23 - 00000000 ____D () C:\Users\Basiliuws Eber 2015-04-12 16:09 - 2014-05-31 13:33 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Dropbox 2015-04-12 16:09 - 2014-05-31 12:28 - 00000000 ___DO () C:\Users\Basiliuws Eber\SkyDrive 2015-04-12 16:09 - 2014-05-31 12:19 - 00001138 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-04-12 16:09 - 2014-05-31 11:33 - 00000000 ____D () C:\Users\Basilius Eberle 2015-04-12 16:08 - 2014-05-31 12:22 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys 2015-04-12 16:08 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-04-12 16:04 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru 2015-04-12 01:58 - 2014-12-07 16:02 - 00001180 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2245731289-3221781707-2474736645-1001UA.job 2015-04-12 01:44 - 2014-05-31 12:19 - 00001142 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-04-12 01:43 - 2014-08-03 20:04 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-04-11 22:58 - 2014-12-07 16:02 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2245731289-3221781707-2474736645-1001Core.job 2015-04-11 20:44 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2015-04-11 20:00 - 2015-03-03 11:18 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\JDownloader 2.0 2015-04-11 13:15 - 2014-06-03 16:35 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\vlc 2015-04-11 01:26 - 2014-05-31 16:21 - 00000000 ____D () C:\Program Files (x86)\Steam 2015-04-11 01:24 - 2014-06-01 12:04 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr 2015-04-11 01:24 - 2014-06-01 12:00 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.exe 2015-04-11 00:34 - 2014-05-31 17:28 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2245731289-3221781707-2474736645-1001 2015-04-10 09:36 - 2014-05-31 13:37 - 00001105 _____ () C:\Users\Basiliuws Eber\Desktop\Dropbox.lnk 2015-04-10 09:36 - 2014-05-31 13:35 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-04-10 04:40 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\LiveKernelReports 2015-04-09 19:49 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF 2015-04-08 13:22 - 2015-01-11 20:23 - 00003858 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1421000576 2015-04-08 13:22 - 2015-01-11 20:22 - 00001070 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2015-04-08 13:22 - 2015-01-11 20:22 - 00000000 ____D () C:\Program Files (x86)\Opera 2015-04-06 17:02 - 2014-08-23 19:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2015-04-06 17:01 - 2014-08-23 19:21 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2015-04-06 17:01 - 2014-08-23 19:20 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2015-04-06 17:01 - 2014-05-31 17:47 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2015-04-06 17:01 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\Help 2015-04-06 08:45 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness 2015-04-05 18:24 - 2014-06-01 10:42 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\my games 2015-04-04 12:37 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp 2015-04-04 11:37 - 2014-06-01 15:26 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\My Games 2015-04-04 11:01 - 2014-08-23 19:44 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\NVIDIA Corporation 2015-04-03 23:39 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\Vss 2015-04-03 16:08 - 2014-05-31 16:49 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2015-04-01 18:26 - 2014-06-01 16:00 - 00000852 _____ () C:\Users\Public\Desktop\CPUID CPU-Z.lnk 2015-04-01 18:20 - 2014-06-01 10:50 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-04-01 18:20 - 2014-06-01 10:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-04-01 18:20 - 2014-06-01 10:50 - 00000000 ____D () C:\Program Files\WinRAR 2015-04-01 18:12 - 2014-10-20 21:45 - 00001201 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk 2015-04-01 18:12 - 2014-10-20 21:45 - 00001189 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk 2015-03-31 13:21 - 2014-07-08 21:58 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Canon 2015-03-31 11:04 - 2014-06-01 20:09 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Skype 2015-03-31 10:51 - 2014-05-31 12:19 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Google 2015-03-31 10:44 - 2014-08-04 09:41 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Adobe 2015-03-31 10:44 - 2014-08-03 20:04 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-03-30 22:51 - 2014-07-08 21:58 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\2014-07-08 2015-03-30 22:48 - 2015-01-25 13:42 - 00000000 ____D () C:\Users\Basiliuws Eber\Documents\Congstar Rechnungen 2015-03-30 08:39 - 2014-06-03 13:58 - 00000000 ____D () C:\Program Files (x86)\AviSynth 2.5 2015-03-27 01:12 - 2014-09-15 21:39 - 00001125 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-03-27 01:12 - 2014-09-15 21:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-03-27 01:12 - 2014-09-15 21:39 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-03-26 23:49 - 2014-08-22 00:44 - 00005468 _____ () C:\Users\Basiliuws Eber\Documents\Database.kdb 2015-03-26 09:23 - 2014-06-09 10:10 - 00000000 ____D () C:\ProgramData\Garmin 2015-03-26 09:23 - 2014-06-09 09:58 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Garmin 2015-03-26 09:23 - 2014-06-09 09:58 - 00000000 ____D () C:\Program Files (x86)\Garmin 2015-03-26 09:20 - 2014-06-09 10:10 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Garmin 2015-03-26 09:20 - 2014-05-31 11:35 - 00000000 ____D () C:\ProgramData\Package Cache 2015-03-26 00:52 - 2014-12-10 00:39 - 00000000 ____D () C:\Windows\system32\appraiser 2015-03-26 00:52 - 2014-07-12 10:21 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-03-25 23:27 - 2014-05-31 17:23 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Adobe 2015-03-25 15:16 - 2014-11-30 14:34 - 00002054 _____ () C:\Users\Public\Desktop\HTC Sync Manager.lnk 2015-03-25 15:15 - 2014-05-31 11:59 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Local\Downloaded Installations 2015-03-25 14:24 - 2014-11-24 15:43 - 00031232 ___SH () C:\Users\Basiliuws Eber\Desktop\Thumbs.db 2015-03-25 14:09 - 2014-06-16 17:11 - 00000000 ____D () C:\Windows\Minidump 2015-03-25 14:09 - 2014-06-01 20:03 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\TS3Client 2015-03-24 13:33 - 2014-06-16 12:00 - 00000000 ____D () C:\Users\Basiliuws Eber\Downloads\CyberLink PowerDVD Ultra 14.0.4028.58 2015-03-24 13:30 - 2014-06-09 11:37 - 00000000 ____D () C:\Users\Basiliuws Eber\AppData\Roaming\Microsoft\Windows\Start Menu\OMC ModPack 2015-03-24 13:13 - 2014-10-26 21:18 - 00000000 ____D () C:\Program Files (x86)\Java 2015-03-24 12:44 - 2014-06-01 18:41 - 00000000 ____D () C:\Program Files (x86)\SpeedFan 2015-03-24 11:37 - 2014-06-03 13:50 - 00001128 _____ () C:\Users\Public\Desktop\AnyDVD.lnk 2015-03-24 11:33 - 2014-05-31 12:04 - 00000000 ____D () C:\ProgramData\CyberLink 2015-03-24 11:32 - 2014-06-16 12:23 - 00000000 ____D () C:\ProgramData\SUPPORTDIR 2015-03-23 09:48 - 2014-06-20 10:52 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2015-03-23 09:48 - 2014-06-20 10:51 - 00000000 ____D () C:\Program Files\Common Files\Apple 2015-03-22 23:27 - 2014-05-31 13:31 - 01047320 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00441728 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00268640 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00136752 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00093528 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00088408 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00065736 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00029168 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2015-03-22 23:27 - 2014-05-31 13:31 - 00003924 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2015-03-22 23:12 - 2014-06-01 15:26 - 00125664 _____ () C:\Users\Basiliuws Eber\AppData\Local\GDIPFONTCACHEV1.DAT 2015-03-20 11:16 - 2014-05-31 11:46 - 01807894 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2015-03-20 09:07 - 2013-08-22 16:44 - 00492672 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-03-20 01:08 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache 2015-03-20 00:27 - 2014-05-31 16:19 - 00000801 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2015-03-20 00:27 - 2014-05-31 16:19 - 00000000 ____D () C:\Program Files\CCleaner 2015-03-18 14:53 - 2014-09-15 21:53 - 00000000 ____D () C:\ProgramData\HitmanPro 2015-03-18 14:17 - 2014-08-24 18:44 - 00000000 ____D () C:\Temp 2015-03-18 12:32 - 2015-01-24 13:45 - 00000000 ____D () C:\Program Files (x86)\devolo 2015-03-18 10:47 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\Performance 2015-03-18 09:56 - 2014-05-31 11:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer 2015-03-17 11:17 - 2014-09-16 19:05 - 00019968 _____ () C:\Users\Basiliuws Eber\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-03-17 07:15 - 2014-09-15 21:39 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-03-17 07:15 - 2014-09-15 21:39 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-03-17 07:15 - 2014-09-15 21:39 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\WinStore 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\PolicyDefinitions 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender 2015-03-15 21:33 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender 2015-03-15 21:26 - 2014-06-01 20:09 - 00000000 ____D () C:\ProgramData\Skype 2015-03-15 21:24 - 2014-06-01 20:09 - 00002715 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-03-14 23:21 - 2014-05-31 18:34 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-03-14 23:21 - 2014-05-31 14:17 - 00000000 ____D () C:\Windows\system32\MRT 2015-03-14 23:18 - 2014-05-31 14:17 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe ==================== Files in the root of some directories ======= 2014-09-16 19:05 - 2015-03-17 11:17 - 0019968 _____ () C:\Users\Basiliuws Eber\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-06-03 13:55 - 2014-06-16 14:35 - 0000040 ___SH () C:\ProgramData\.zreglib Some content of TEMP: ==================== C:\Users\Basiliuws Eber\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp7zqszu.dll C:\Users\Basiliuws Eber\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Basiliuws Eber\AppData\Local\Temp\nvSCPAPI64.dll C:\Users\Basiliuws Eber\AppData\Local\Temp\nvStInst.exe C:\Users\Basiliuws Eber\AppData\Local\Temp\proxy_vole846848495695807889.dll C:\Users\Basiliuws Eber\AppData\Local\Temp\Quarantine.exe C:\Users\Basiliuws Eber\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-04-11 13:36 ==================== End Of Log ============================ |
13.04.2015, 08:27 | #84 |
/// the machine /// TB-Ausbilder | Adware Roll around eingefangen Wenn Du Chrome nochmal neu installiert hast, nochmal deinstallieren mit Revo, dann die Ordner von Hand löschen. Alles von Chrome löschen was Du findest. Dann neu installierne und testen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
13.04.2015, 15:27 | #85 |
Adware Roll around eingefangen Habe ich soeben gemacht. Sabald ich Chroma aber neu installiere, findet er den Triovi wieder... Nochmal zurück zu der Fehlermeldung ShellEecutEx fehlgeschlagen: Hatte heute wieder ca. 100 Pop Ups, besonders wenn der Geforce Treiber sich meldet. Hier gibt es noch einen Thread dazu: hxxp://www.modernboard.de/windows-7-probleme/117388-shellexecuteex-schlug-fehl-code-1155-a.html und hier: hxxp://www.gutefrage.net/frage/fehlermeldung-shellexecuteex-fehlgeschlagen-code-1155-hilfe#answers Nur bringt mich das auch nicht weiter... |
14.04.2015, 06:29 | #86 |
/// the machine /// TB-Ausbilder | Adware Roll around eingefangen Mach bitte nochmal Systemlook: :filefind *Basiliuws Eber*
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.04.2015, 07:32 | #87 |
Adware Roll around eingefangen Alles klar, hier die Ergebnisse... Code:
ATTFilter SystemLook 30.07.11 by jpshortstuff Log created at 08:31 on 14/04/2015 by Basiliuws Eber Administrator - Elevation successful ========== filefind ========== Searching for "*Basiliuws Eber*" C:\ProgramData\AVAST Software\Avast\RemoteCache\Basiliuws Eber.zip --a---- 26624 bytes [11:32 31/05/2014] [16:36 19/08/2014] D456A3050CE1793C5F8A46A55759CE8B C:\ProgramData\CanonBJ\IJPrinter\CNMWindows\Canon iP4800 series\Basiliuws Eber.pst --a---- 3180 bytes [10:00 08/07/2014] [08:55 15/07/2014] AFB0B04272510F060BDA332FBCF06173 C:\ProgramData\CanonBJ\IJPrinter\CNMWindows\Canon iP4800 series\Canon iP4800 series\0002\cnmsm_Basiliuws Eber.dat --a---- 364 bytes [08:06 18/06/2014] [16:21 31/07/2014] D8FDF9D9935913F5EB7D9A8000A752F0 C:\ProgramData\Microsoft\User Account Pictures\Basiliuws Eber.dat --a---- 0 bytes [15:23 31/05/2014] [15:23 31/05/2014] D41D8CD98F00B204E9800998ECF8427E C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log --a---- 3751583 bytes [08:56 14/11/2014] [08:08 02/04/2015] 220CD66C8054081D75DC20B9725351F0 C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.01 --a---- 10000088 bytes [08:56 14/11/2014] [11:21 16/03/2015] BF9C976EF292AA9546AA213761872224 C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.02 --a---- 10000198 bytes [08:56 14/11/2014] [14:17 04/03/2015] 080780B938860EFDBCDC53AF84DF3C65 C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.03 --a---- 10000232 bytes [08:56 14/11/2014] [19:49 21/02/2015] C1982A85C27CC5E95FA6FC0E5BD7C766 C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.04 --a---- 10000220 bytes [08:56 14/11/2014] [20:07 07/02/2015] 4DE66B9401E90DE21F0438DF80B52B0B C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.05 --a---- 10000106 bytes [08:56 14/11/2014] [15:03 23/01/2015] AD5FC300894A878CF7FA3A2D6F788846 C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.06 --a---- 10000016 bytes [08:56 14/11/2014] [22:37 16/01/2015] 6F670A19D062B03A4E14CF8C03315FC1 C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.07 --a---- 10000164 bytes [08:56 14/11/2014] [21:38 05/01/2015] 943BA12435A23713C903F297E5D9071F C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.08 --a---- 10000116 bytes [08:56 14/11/2014] [14:07 30/12/2014] 5B32EC7F2D1B3EBD571533C50FACEB26 C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.09 --a---- 10000067 bytes [08:56 14/11/2014] [13:54 20/12/2014] B2EF72F7FE9537D91BCF610B88BAAB89 C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.10 --a---- 10000039 bytes [08:56 14/11/2014] [19:08 08/12/2014] A87863B94675B78685D38A414A4083B7 C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RzCefRenderProcess.log --a---- 408719 bytes [08:57 14/11/2014] [07:54 18/03/2015] E55D7415DF87975F98569D8410580C42 C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RzStats.Manager.log --a---- 5430049 bytes [08:57 14/11/2014] [07:55 18/03/2015] 9BD5520B456E058DD27D29FA469708E3 C:\ProgramData\Razer\InGameEngine\logs\Basiliuws Eber_RzStats.Manager.log.01 --a---- 10000130 bytes [08:57 14/11/2014] [15:50 23/01/2015] 8E7E7C922AFBB68F8D9CB08410733A99 C:\ProgramData\Razer\Synapse\Logs\RzWizard_Basiliuws Eber.log --a---- 1104 bytes [09:32 31/05/2014] [09:32 31/05/2014] 6AA1925076A785F440823EEC29598101 C:\ProgramData\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log --a---- 3101866 bytes [10:22 31/05/2014] [06:15 14/04/2015] 84BBD5382961011C9EF67E6D48FE8C77 C:\ProgramData\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log.1 --a---- 5242895 bytes [10:22 31/05/2014] [21:02 23/03/2015] 2EE1C0FC802611909B3F4A94F3D64C5A C:\ProgramData\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log.2 --a---- 5242939 bytes [10:22 31/05/2014] [21:53 06/02/2015] F37C36BCC94159082F1673DB0F30B7BE C:\ProgramData\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log.3 --a---- 5242984 bytes [10:22 31/05/2014] [21:12 18/12/2014] 8EDDD4C9D827A8806D8D05CDAE78D8E4 C:\Users\All Users\AVAST Software\Avast\RemoteCache\Basiliuws Eber.zip --a---- 26624 bytes [11:32 31/05/2014] [16:36 19/08/2014] D456A3050CE1793C5F8A46A55759CE8B C:\Users\All Users\CanonBJ\IJPrinter\CNMWindows\Canon iP4800 series\Basiliuws Eber.pst --a---- 3180 bytes [10:00 08/07/2014] [08:55 15/07/2014] AFB0B04272510F060BDA332FBCF06173 C:\Users\All Users\CanonBJ\IJPrinter\CNMWindows\Canon iP4800 series\Canon iP4800 series\0002\cnmsm_Basiliuws Eber.dat --a---- 364 bytes [08:06 18/06/2014] [16:21 31/07/2014] D8FDF9D9935913F5EB7D9A8000A752F0 C:\Users\All Users\Microsoft\User Account Pictures\Basiliuws Eber.dat --a---- 0 bytes [15:23 31/05/2014] [15:23 31/05/2014] D41D8CD98F00B204E9800998ECF8427E C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log --a---- 3751583 bytes [08:56 14/11/2014] [08:08 02/04/2015] 220CD66C8054081D75DC20B9725351F0 C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.01 --a---- 10000088 bytes [08:56 14/11/2014] [11:21 16/03/2015] BF9C976EF292AA9546AA213761872224 C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.02 --a---- 10000198 bytes [08:56 14/11/2014] [14:17 04/03/2015] 080780B938860EFDBCDC53AF84DF3C65 C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.03 --a---- 10000232 bytes [08:56 14/11/2014] [19:49 21/02/2015] C1982A85C27CC5E95FA6FC0E5BD7C766 C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.04 --a---- 10000220 bytes [08:56 14/11/2014] [20:07 07/02/2015] 4DE66B9401E90DE21F0438DF80B52B0B C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.05 --a---- 10000106 bytes [08:56 14/11/2014] [15:03 23/01/2015] AD5FC300894A878CF7FA3A2D6F788846 C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.06 --a---- 10000016 bytes [08:56 14/11/2014] [22:37 16/01/2015] 6F670A19D062B03A4E14CF8C03315FC1 C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.07 --a---- 10000164 bytes [08:56 14/11/2014] [21:38 05/01/2015] 943BA12435A23713C903F297E5D9071F C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.08 --a---- 10000116 bytes [08:56 14/11/2014] [14:07 30/12/2014] 5B32EC7F2D1B3EBD571533C50FACEB26 C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.09 --a---- 10000067 bytes [08:56 14/11/2014] [13:54 20/12/2014] B2EF72F7FE9537D91BCF610B88BAAB89 C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RazerIngameEngine.log.10 --a---- 10000039 bytes [08:56 14/11/2014] [19:08 08/12/2014] A87863B94675B78685D38A414A4083B7 C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RzCefRenderProcess.log --a---- 408719 bytes [08:57 14/11/2014] [07:54 18/03/2015] E55D7415DF87975F98569D8410580C42 C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RzStats.Manager.log --a---- 5430049 bytes [08:57 14/11/2014] [07:55 18/03/2015] 9BD5520B456E058DD27D29FA469708E3 C:\Users\All Users\Razer\InGameEngine\logs\Basiliuws Eber_RzStats.Manager.log.01 --a---- 10000130 bytes [08:57 14/11/2014] [15:50 23/01/2015] 8E7E7C922AFBB68F8D9CB08410733A99 C:\Users\All Users\Razer\Synapse\Logs\RzWizard_Basiliuws Eber.log --a---- 1104 bytes [09:32 31/05/2014] [09:32 31/05/2014] 6AA1925076A785F440823EEC29598101 C:\Users\All Users\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log --a---- 3101866 bytes [10:22 31/05/2014] [06:15 14/04/2015] 84BBD5382961011C9EF67E6D48FE8C77 C:\Users\All Users\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log.1 --a---- 5242895 bytes [10:22 31/05/2014] [21:02 23/03/2015] 2EE1C0FC802611909B3F4A94F3D64C5A C:\Users\All Users\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log.2 --a---- 5242939 bytes [10:22 31/05/2014] [21:53 06/02/2015] F37C36BCC94159082F1673DB0F30B7BE C:\Users\All Users\Razer\Synapse\Logs\Synapse_Basiliuws Eber.log.3 --a---- 5242984 bytes [10:22 31/05/2014] [21:12 18/12/2014] 8EDDD4C9D827A8806D8D05CDAE78D8E4 C:\Users\Basiliuws Eber\AppData\Local\Temp\Basiliuws Eber.bmp --a---- 31832 bytes [09:59 06/04/2015] [22:42 13/04/2015] 8D6650CF35779429CC9D098BBED9133C -= EOF =- |
14.04.2015, 16:39 | #88 |
/// the machine /// TB-Ausbilder | Adware Roll around eingefangen Komisch. Es muss in deinem Userordner ne Datei geben die einfach so heisst wie dein Benutzerkonto....
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.04.2015, 09:48 | #89 |
Adware Roll around eingefangen Keine Ahnung. Jedenfalls öffnen Sich bei jedem Systemstart ca. 70-80 Prozesse: Setup/Uninstall. Alle verweisen auf .tmp Dateien in C:\Users\Basiliuws Eber\AppData\Local\Temp Jeweils in Unterordnern wie is-0OGNV.tmp liegen dann immer Dateien, die gleich heißen: Basiliuws.tmp Es werden aber auch noch andere Prozesse gestartet:FreeYoutubeToMp3 Converter Setup. Sie verweisen alle auf: C:\Users\basiliuws Diese Datei hat keine Dateinamenerweiterung. Werde sie jetzt einmal löschen und schauen was passiert. Bisher ist noch Ruhe mit den Pop Ups... |
15.04.2015, 19:28 | #90 |
/// the machine /// TB-Ausbilder | Adware Roll around eingefangen Die hatte keine Dateiendung?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |