|
Log-Analyse und Auswertung: Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-MeldungenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
26.03.2015, 22:49 | #1 |
| Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen Hallo Forum, nachdem ich letztes Mal hier super Hilfe von Schrauber bekommen habe, und den Rechner meines Kumpels "geheilt" wieder abgeben konnte, hat sich das rumgesprochen. Und schwupps bin ich wieder da, mit dem gleichen Problem eines anderen Kumpels. Die Situation ist diesemal folgende: Mein Kumpel hat sich ein gebrauchtes Laptop gekauft, welches vermutlich bereits verseucht war. Da er sich mit Rechnern so gut wie gar nicht auskennt, hat er den gekauften einfach so benutzt wie er war noch ein paar Programme installiert und sich über langsame Reaktionszeiten gewundert. Das so viel "Mist" bereits installiert war, hat er auf den Vorbesitzer geschoben. Nun ist es wieder soweit, dass man ihn eigentlich nicht mehr benutzen kann, da jeder Aufruf einer Internetseite mit Umleitungen quittiert wird, diverse Popups erscheinen usw. Hier nun die Logs: defogger_disable: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 21:27 on 26/03/2015 (ecp) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Ran by ecp (administrator) on ECP-PC on 26-03-2015 21:28:31 Running from C:\Reinigung Loaded Profiles: ecp (Available profiles: ecp) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE () C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe () C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe (Gambali OEM Software) C:\ProgramData\SecurityUtility\Gambali.exe (Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe () C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe () C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe () C:\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe () C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.exe () C:\Program Files\WajaWebEnhancer\wajam_64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe () C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited) C:\Program Files\Lenovo\ZOOM\TpScrex.exe (HQ CinemaV20.03) C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe () C:\Program Files\WajaWebEnhancer\wajam.exe () C:\Program Files\WajaWebEnhancer\wajam_64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Price Fountain) C:\Users\ecp\AppData\Local\PriceFountain\pricefountainw.exe () C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe (Pay By Ads LTD) C:\Users\ecp\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrlte.exe (Price Fountain) C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe () C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\Program Files (x86)\ver0CheckMeUp\CheckMeUp.exe () C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe () C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe () C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe () C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe () C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe () C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe () C:\Program Files (x86)\Search Extensions\Client.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\McUICnt.exe () C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe () C:\ProgramData\bobyzoom\1.1.0.30\bz64.exe () C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe (Microsoft Corporation) C:\Windows\System32\dinotify.exe () C:\Neuer Ordner\FRST64.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [18643560 2013-03-01] (Skype Technologies S.A.) HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [pricefountainw.exe] => C:\Users\ecp\AppData\Local\PriceFountain\pricefountainw.exe [461824 2014-12-07] (Price Fountain) HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [AudialsNotifier] => C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe [2410760 2014-12-17] () HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [Yahoo! Search] => C:\Users\ecp\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrlte.exe [644816 2015-03-20] (Pay By Ads LTD) HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [GoogleChromeAutoLaunch_9478B546DA4E84D7A735A7D0209EA854] => C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [1014272 2015-02-04] () HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\RunOnce: [Wse_binkiland] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\ecp\AppData\Roaming\Wse_binkiland\UpdateProc\bkup.dat" HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\MountPoints2: {56f6912e-919f-11e4-9510-001fe2182534} - E:\LaunchU3.exe -a HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\MountPoints2: {7573f5a7-9695-11e4-9739-001fe2182534} - E:\LaunchU3.exe -a AppInit_DLLs-x32: c:/progra~3/{a8e14~1/171~1.0/sila.dll => c:\ProgramData\{A8E14022-F863-91A4-49E5-E126996732A8}\1.7.1.0\sila.dll [649216 2015-01-01] () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyEnable: [S-1-5-21-1780445102-594666999-3139876592-1000] => Internet Explorer proxy is enabled. ProxyServer: [S-1-5-21-1780445102-594666999-3139876592-1000] => http=127.0.0.1:49338;https=127.0.0.1:49338 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://myhome.vi-view.com/?type=hp&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://myhome.vi-view.com/?type=hp&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms} HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://binkiland.com/?f=1&a=bnk_coinis_15_12&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0CyB0EyE0CzztCyC0C0ByCtN0D0Tzu0StCtCyByCtN1L2XzutAtFzztFtAtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StByD0E0ByBzyyCyEtGtB0E0A0AtGyEtAyEtBtG0FtD0D0EtGtD0A0DyB0BtB0A0A0A0FyDyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0AyCyD0B0E0D0AtGzz0FyDyCtGyEzz0CyEtGzz0D0FyBtGtC0DyE0AtAyC0EyC0C0C0E0E2Q&cr=1970351768&ir= HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://myhome.vi-view.com/?type=hp&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> DefaultScope {C4C5AF64-3082-439A-8C86-5773B579E965} URL = hxxp://binkiland.com/results.php?f=4&q={searchTerms}&a=bnk_coinis_15_12&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0CyB0EyE0CzztCyC0C0ByCtN0D0Tzu0StCtCyByCtN1L2XzutAtFzztFtAtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StByD0E0ByBzyyCyEtGtB0E0A0AtGyEtAyEtBtG0FtD0D0EtGtD0A0DyB0BtB0A0A0A0FyDyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0AyCyD0B0E0D0AtGzz0FyDyCtGyEzz0CyEtGzz0D0FyBtGtC0DyE0AtAyC0EyC0C0C0E0E2Q&cr=1970351768&ir= SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {2D8E4D58-9FF9-4D32-B1A0-E2E493921442} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms} SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {5782EC3E-14E8-402B-BAD6-7FE86EF6484D} URL = hxxp://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ir_15_01_ie&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0CyB0EyE0CzztCyC0C0ByCtN0D0Tzu0StCtDzyyCtN1L2XzutAtFyCtFtCyCtFyCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StBtB0EtD0FtAyEyCtG0FyEtCtCtG0D0Dzy0EtGtB0EzyyBtGyC0FtD0F0EtAyC0B0ByB0E0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0AyCyD0B0E0D0AtGzz0FyDyCtGyEzz0CyEtGzz0D0FyBtGtC0DyE0AtAyC0EyC0C0C0E0E2Q&cr=692593422&ir= SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {9F48D099-769E-460F-8CAD-E870234711DA} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {A44BCBEF-651D-4A25-A802-3938D00F9BEE} URL = hxxp://q.search-simple.com/?affID=na&q={searchTerms}&r=92 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {BC78FFB8-43BE-431A-861E-C6CE3BA30EC0} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {C4C5AF64-3082-439A-8C86-5773B579E965} URL = hxxp://binkiland.com/results.php?f=4&q={searchTerms}&a=bnk_coinis_15_12&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0CyB0EyE0CzztCyC0C0ByCtN0D0Tzu0StCtCyByCtN1L2XzutAtFzztFtAtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StByD0E0ByBzyyCyEtGtB0E0A0AtGyEtAyEtBtG0FtD0D0EtGtD0A0DyB0BtB0A0A0A0FyDyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0AyCyD0B0E0D0AtGzz0FyDyCtGyEzz0CyEtGzz0D0FyBtGtC0DyE0AtAyC0EyC0C0C0E0E2Q&cr=1970351768&ir= SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 BHO: SoaleEsChoeocKeirr -> {007c182f-91dc-485e-a48f-b4ad99086949} -> C:\Program Files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.x64.dll [2015-03-06] () BHO: ddeallpeAuk -> {3dcc325d-9258-4278-ac06-bc06aafb8809} -> C:\Program Files (x86)\ddeallpeAuk\83pi0tURGPEZSW.x64.dll [2015-03-23] () BHO: CheckMeUp -> {B7A5EE16-3FED-399F-55F6-58AF84D02FC4} -> C:\Program Files (x86)\ver0CheckMeUp\190_x64.dll [2015-03-20] () BHO: Saveitkeaep. -> {f1a892aa-d8f1-4a2a-a980-430349d85d2a} -> C:\Program Files (x86)\Saveitkeaep\OUx1yNk71u3K2I.x64.dll [2015-03-23] () BHO-x32: SoaleEsChoeocKeirr -> {007c182f-91dc-485e-a48f-b4ad99086949} -> C:\Program Files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.dll [2015-03-06] () BHO-x32: ddeallpeAuk -> {3dcc325d-9258-4278-ac06-bc06aafb8809} -> C:\Program Files (x86)\ddeallpeAuk\83pi0tURGPEZSW.dll [2015-03-23] () BHO-x32: CheckMeUp -> {B7A5EE16-3FED-399F-55F6-58AF84D02FC4} -> C:\Program Files (x86)\ver0CheckMeUp\190.dll [2015-03-20] () BHO-x32: Saveitkeaep. -> {f1a892aa-d8f1-4a2a-a980-430349d85d2a} -> C:\Program Files (x86)\Saveitkeaep\OUx1yNk71u3K2I.dll [2015-03-23] () Toolbar: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> No Name - {C424171E-592A-415A-9EB1-DFD6D95D3530} - No File Toolbar: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> No Name - {4F524A2D-5350-4500-76A7-7A786E7484D7} - No File Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies) Winsock: Catalog9 01 C:\Windows\SysWOW64\Gambali.dll [335768] (Gambali OEM Software) Winsock: Catalog9 02 C:\Windows\SysWOW64\Gambali.dll [335768] (Gambali OEM Software) Winsock: Catalog9 03 C:\Windows\SysWOW64\Gambali.dll [335768] (Gambali OEM Software) Winsock: Catalog9 04 C:\Windows\SysWOW64\Gambali.dll [335768] (Gambali OEM Software) Winsock: Catalog9 15 C:\Windows\SysWOW64\Gambali.dll [335768] (Gambali OEM Software) Winsock: Catalog9-x64 01 C:\Windows\system32\Gambali64.dll [398808] (Gambali OEM Software) Winsock: Catalog9-x64 02 C:\Windows\system32\Gambali64.dll [398808] (Gambali OEM Software) Winsock: Catalog9-x64 03 C:\Windows\system32\Gambali64.dll [398808] (Gambali OEM Software) Winsock: Catalog9-x64 04 C:\Windows\system32\Gambali64.dll [398808] (Gambali OEM Software) Winsock: Catalog9-x64 15 C:\Windows\system32\Gambali64.dll [398808] (Gambali OEM Software) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default FF NewTab: hxxp://de.search.yahoo.com/?fr=hp-ddc-bd-tab&type=276_pr__alt__ddc_dsssyctab_bd_com FF DefaultSearchEngine: Yahoo! Search FF SelectedSearchEngine: Yahoo! Search FF Homepage: hxxp://de.search.yahoo.com/?fr=hp-ddc-bd&type=276_pr__alt__ddc_dsssyc_bd_com FF Keyword.URL: hxxp://de.search.yahoo.com/yhs/search?hspart=ddc&hsimp=yhs-ddc_bd&type=276_pr__alt__ddc_dss_bd_com&p= FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-05] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] () FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-04] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-04] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2015-03-20] (globalUpdate) FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2015-03-20] (globalUpdate) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF user.js: detected! => C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\user.js [2015-03-23] FF SearchPlugin: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\searchplugins\search-simple.xml [2015-03-22] FF Extension: BobyZoom - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\bbz@bobyzoom.com [2015-03-24] FF Extension: deAli2idealit - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\Rc1@sSvOmat.net [2015-03-23] FF Extension: Dynamo Combo 1.0.1 - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}.xpi [2015-03-22] FF HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Firefox\Extensions: [{969E3CF4-34F8-788A-EDA2-1FF1929946D9}] - C:\Program Files (x86)\ver0CheckMeUp\190.xpi FF Extension: CheckMeUp - C:\Program Files (x86)\ver0CheckMeUp\190.xpi [2015-03-20] FF HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] Chrome: ======= CHR dev: Chrome dev build detected! <======= ATTENTION CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx Opera: ======= OPR Extension: (HQCinema Pro 2.1V20.03) - C:\Users\ecp\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcjifdbedkcdkeegnoenkpiphjldpahf [2015-03-20] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) Locked "tammgF119" service could not be unlocked. <===== ATTENTION Locked "tammgR119" service could not be unlocked. <===== ATTENTION R2 9617fb41; c:\Program Files (x86)\SystemContinue\SystemContinue.dll [1609728 2015-03-22] () [File not signed] R2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation) R2 bobyzoom; C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [0 ] () <==== ATTENTION (zero size file/folder) R2 bzwdg; C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [0 ] () <==== ATTENTION (zero size file/folder) R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2014-12-11] () [File not signed] R2 Gambali; C:\ProgramData\SecurityUtility\Gambali.exe [1793128 2015-03-20] (Gambali OEM Software) [File not signed] S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2015-03-20] (globalUpdate) [File not signed] S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2015-03-20] (globalUpdate) [File not signed] S2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [714624 2014-12-30] () [File not signed] S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation) R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [7410024 2015-01-14] (Reimage®) R2 SecurityUtility Service; C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe [379392 2015-03-20] () [File not signed] S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [49648 2015-01-15] () R2 Update Dynamo Combo; C:\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe [411376 2015-03-24] () R2 Util Dynamo Combo; C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.exe [411376 2015-03-24] () R2 Wajam Web Enhancer; C:\Program Files\WajaWebEnhancer\wajam_64.exe [1594368 2015-03-16] () [File not signed] <==== ATTENTION S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S4 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [473088 2014-12-30] () [File not signed] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation) R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-12-17] (Audials AG) R5 tammgF119; C:\Windows\System32\Drivers\tammgF119.sys [26784 2015-03-20] () [File not signed] R5 tammgR119; C:\Windows\System32\Drivers\tammgR119.sys [26272 2015-03-20] () [File not signed] U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) R2 webTinstMKTN; C:\Windows\system32\Drivers\webTinstMKTN.sys [50800 2015-03-20] () R1 {16a92140-918d-4afb-9edb-46f22437bb10}w64; C:\Windows\System32\drivers\{16a92140-918d-4afb-9edb-46f22437bb10}w64.sys [48792 2015-01-25] (StdLib) R1 {228c1c19-dcaa-4969-9dee-95888fe6a45e}Gw64; C:\Windows\System32\drivers\{228c1c19-dcaa-4969-9dee-95888fe6a45e}Gw64.sys [48792 2014-12-30] (StdLib) R1 {3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64; C:\Windows\System32\drivers\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64.sys [48792 2015-01-28] (StdLib) R1 {641e52b1-3179-43ed-8bcb-f688871e52b0}w64; C:\Windows\System32\drivers\{641e52b1-3179-43ed-8bcb-f688871e52b0}w64.sys [48792 2015-01-19] (StdLib) R1 {8d9208df-94f9-4c96-a224-97b37b0df94e}Gw64; C:\Windows\System32\drivers\{8d9208df-94f9-4c96-a224-97b37b0df94e}Gw64.sys [48792 2015-01-04] (StdLib) R1 {915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64; C:\Windows\System32\drivers\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64.sys [48792 2015-01-22] (StdLib) R1 {bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64; C:\Windows\System32\drivers\{bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64.sys [48792 2015-01-06] (StdLib) R1 {ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}Gw64; C:\Windows\System32\drivers\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}Gw64.sys [48792 2015-01-13] (StdLib) R1 {ecd6aae4-019c-44b2-a0e5-570904275d66}w64; C:\Windows\System32\drivers\{ecd6aae4-019c-44b2-a0e5-570904275d66}w64.sys [48792 2015-01-16] (StdLib) R1 {ef3f84a6-599c-4148-a8eb-9aa938299b3e}Gw64; C:\Windows\System32\drivers\{ef3f84a6-599c-4148-a8eb-9aa938299b3e}Gw64.sys [48792 2014-12-31] (StdLib) R1 {f81878fa-25e9-442d-8ada-79658b6520f2}Gw64; C:\Windows\System32\drivers\{f81878fa-25e9-442d-8ada-79658b6520f2}Gw64.sys [48792 2015-01-10] (StdLib) S3 CAXHWAZL; system32\DRIVERS\CAXHWAZL.sys [X] S3 cpuz134; \??\C:\Users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] S3 HSF_DPV; system32\DRIVERS\CAX_DPV.sys [X] S2 mdmxsdk; system32\DRIVERS\mdmxsdk.sys [X] S3 winachsf; system32\DRIVERS\CAX_CNXT.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-26 21:28 - 2015-03-26 21:29 - 00000000 ____D () C:\FRST 2015-03-26 21:27 - 2015-03-26 21:27 - 00000000 _____ () C:\Users\ecp\defogger_reenable 2015-03-26 21:13 - 2015-03-26 21:28 - 00000000 ____D () C:\Reinigung 2015-03-23 09:18 - 2015-03-23 09:19 - 00000000 ____D () C:\Program Files (x86)\Simple Dictation 2015-03-23 09:18 - 2015-03-23 09:19 - 00000000 ____D () C:\Program Files (x86)\ddeallpeAuk 2015-03-23 09:17 - 2015-03-23 09:19 - 00000000 ____D () C:\Program Files (x86)\Saveitkeaep 2015-03-23 09:17 - 2015-03-23 09:19 - 00000000 ____D () C:\Program Files (x86)\deAli2idealit 2015-03-23 08:18 - 2015-03-24 19:03 - 00003452 _____ () C:\Windows\System32\Tasks\ProPCCleaner_Popup 2015-03-22 09:10 - 2015-03-22 09:10 - 00000000 ____D () C:\Users\ecp\AppData\Local\Macromedia 2015-03-22 09:09 - 2015-03-22 09:09 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-03-22 09:09 - 2015-03-22 09:09 - 00001154 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-03-22 09:09 - 2015-03-22 09:09 - 00000000 ____D () C:\Users\ecp\AppData\Local\Mozilla 2015-03-22 09:08 - 2015-03-22 09:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-03-22 08:52 - 2015-03-22 08:52 - 00002281 _____ () C:\Users\ecp\Desktop\Binkiland.lnk 2015-03-22 08:52 - 2015-03-22 08:52 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Binkiland 2015-03-22 08:52 - 2015-03-22 08:52 - 00000000 ____D () C:\Users\ecp\AppData\Local\Binkiland 2015-03-22 08:51 - 2015-03-24 18:51 - 00000284 _____ () C:\Windows\Tasks\Wse_binkiland.job 2015-03-22 08:51 - 2015-03-22 08:51 - 00003212 _____ () C:\Windows\System32\Tasks\Wse_binkiland 2015-03-22 08:51 - 2015-03-22 08:51 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Wse_binkiland 2015-03-22 08:50 - 2015-03-22 08:51 - 00000000 ____D () C:\Users\ecp\AppData\Local\WSE_Binkiland 2015-03-22 08:32 - 2015-03-22 08:32 - 00004020 _____ () C:\Windows\System32\Tasks\Check for Scheduled Updates 2015-03-22 08:30 - 2015-03-22 08:30 - 00000000 ____D () C:\Users\ecp\AppData\Local\32220c02-c108-4e43-b856-df7d87f70051 2015-03-22 08:10 - 2015-03-22 08:10 - 00000000 ____D () C:\ProgramData\OnlineLowDeals 2015-03-22 08:09 - 2015-03-23 13:04 - 00003122 _____ () C:\Windows\System32\Tasks\DriverDocRunAtStartup 2015-03-22 07:45 - 2015-03-22 07:45 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer 2015-03-22 07:45 - 2015-03-22 07:45 - 00000000 ____D () C:\Program Files\WajaWebEnhancer 2015-03-22 07:43 - 2015-03-22 07:43 - 00000000 ____D () C:\Program Files (x86)\SystemContinue 2015-03-22 07:42 - 2015-03-22 07:42 - 00000000 ____D () C:\ProgramData\1887373585 2015-03-21 18:45 - 2015-03-21 18:45 - 02205072 _____ () C:\Windows\shost.bin 2015-03-21 18:22 - 2015-03-24 18:44 - 00000000 ____D () C:\Users\ecp\Documents\ProPCCleaner 2015-03-20 19:06 - 2015-03-26 21:16 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 2015-03-20 18:52 - 2015-03-20 18:52 - 00004316 _____ () C:\Windows\System32\Tasks\RocketTab Update Task 2015-03-20 18:52 - 2015-03-20 18:52 - 00003530 _____ () C:\Windows\System32\Tasks\RocketTab 2015-03-20 18:52 - 2015-03-20 18:52 - 00003188 _____ () C:\Windows\System32\Tasks\ProPCCleaner_Start 2015-03-20 18:52 - 2015-03-20 18:52 - 00000000 ____D () C:\Users\ecp\AppData\Local\Pro_PC_Cleaner 2015-03-20 18:52 - 2015-03-20 18:52 - 00000000 ____D () C:\Program Files (x86)\Search Extensions 2015-03-20 18:50 - 2015-03-20 18:50 - 00001006 _____ () C:\Users\Public\Desktop\Pro PC Cleaner.lnk 2015-03-20 18:50 - 2015-03-20 18:50 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Pro PC Cleaner 2015-03-20 18:50 - 2015-03-20 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro PC Cleaner 2015-03-20 18:50 - 2015-03-20 18:50 - 00000000 ____D () C:\Program Files (x86)\Pro PC Cleaner 2015-03-20 18:49 - 2015-03-26 21:13 - 00008968 _____ () C:\Windows\SysWOW64\GambaliOff.ini 2015-03-20 18:49 - 2015-03-26 21:13 - 00008968 _____ () C:\Windows\system32\GambaliOff.ini 2015-03-20 18:49 - 2015-03-20 10:33 - 00398808 _____ (Gambali OEM Software) C:\Windows\system32\Gambali64.dll 2015-03-20 18:49 - 2015-03-20 10:33 - 00335768 _____ (Gambali OEM Software) C:\Windows\SysWOW64\Gambali.dll 2015-03-20 18:47 - 2015-03-26 21:16 - 00002444 _____ () C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5_user.job 2015-03-20 18:47 - 2015-03-26 21:16 - 00002444 _____ () C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.job 2015-03-20 18:47 - 2015-03-20 18:49 - 00000000 ____D () C:\ProgramData\SecurityUtility 2015-03-20 18:47 - 2015-03-20 18:47 - 00005474 _____ () C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5 2015-03-20 18:47 - 2015-03-20 18:47 - 00000000 ____D () C:\ProgramData\e314b8475a214ebc973cc42fbf8c6edf 2015-03-20 18:46 - 2015-03-26 21:16 - 00003472 _____ () C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.job 2015-03-20 18:46 - 2015-03-26 21:16 - 00003136 _____ () C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.job 2015-03-20 18:46 - 2015-03-20 18:46 - 00006502 _____ () C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7 2015-03-20 18:46 - 2015-03-20 18:46 - 00006164 _____ () C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6 2015-03-20 18:45 - 2015-03-26 21:16 - 00005182 _____ () C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.job 2015-03-20 18:45 - 2015-03-26 21:16 - 00002248 _____ () C:\Windows\patsearch.bin 2015-03-20 18:45 - 2015-03-26 21:16 - 00002110 _____ () C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10_user.job 2015-03-20 18:45 - 2015-03-26 21:16 - 00000954 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job 2015-03-20 18:45 - 2015-03-26 21:16 - 00000402 _____ () C:\Windows\Tasks\CheckMeUp Update.job 2015-03-20 18:45 - 2015-03-24 18:50 - 00000958 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job 2015-03-20 18:45 - 2015-03-20 18:47 - 00000000 ____D () C:\Program Files (x86)\HQCinema Pro 2.1V20.03 2015-03-20 18:45 - 2015-03-20 18:45 - 00008212 _____ () C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11 2015-03-20 18:45 - 2015-03-20 18:45 - 00003956 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA 2015-03-20 18:45 - 2015-03-20 18:45 - 00003702 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore 2015-03-20 18:45 - 2015-03-20 18:45 - 00003046 _____ () C:\Windows\System32\Tasks\CheckMeUp Update 2015-03-20 18:45 - 2015-03-20 18:45 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webTinstMKTN_01009.Wdf 2015-03-20 18:45 - 2015-03-20 18:45 - 00000000 ____D () C:\Users\ecp\AppData\Local\globalUpdate 2015-03-20 18:45 - 2015-03-20 18:45 - 00000000 ____D () C:\Program Files (x86)\ver0CheckMeUp 2015-03-20 18:45 - 2015-03-20 18:45 - 00000000 ____D () C:\Program Files (x86)\globalUpdate 2015-03-20 18:45 - 2015-03-20 18:44 - 00050800 _____ () C:\Windows\system32\Drivers\webTinstMKTN.sys 2015-03-20 18:43 - 2015-03-20 18:43 - 00026784 _____ () C:\Windows\system32\Drivers\tammgF119.sys 2015-03-20 18:43 - 2015-03-20 18:43 - 00026272 _____ () C:\Windows\system32\Drivers\tammgR119.sys 2015-03-20 18:43 - 2015-03-20 18:43 - 00000000 ____D () C:\ProgramData\bobyzoom 2015-03-20 07:05 - 2015-03-20 07:05 - 00003482 _____ () C:\Windows\System32\Tasks\Yahoo! Search Updater 2015-03-20 07:05 - 2015-03-20 07:05 - 00003478 _____ () C:\Windows\System32\Tasks\Yahoo! Search 2015-03-20 07:05 - 2015-03-20 07:05 - 00000000 ____D () C:\Users\ecp\AppData\Local\Pay-By-Ads 2015-03-18 08:05 - 2015-03-18 08:06 - 00002051 _____ () C:\Users\ecp\Downloads\Henner.txt 2015-03-17 07:53 - 2015-03-16 18:43 - 01274260 _____ () C:\Users\ecp\Documents\bskundenexcel201411.xls_0.ods 2015-03-17 07:53 - 2015-03-16 18:43 - 00017886 _____ () C:\Users\ecp\Documents\TennistrainingWinterHalle201415herren55he55mitersatzregelung.xls_0.ods 2015-03-13 09:11 - 2015-03-13 09:11 - 00959266 _____ () C:\Users\ecp\Downloads\doc.zip 2015-03-13 09:02 - 2015-03-13 09:02 - 00408667 _____ () C:\Users\ecp\Downloads\odt.zip 2015-03-11 08:58 - 2015-03-11 08:59 - 00000832 _____ () C:\Users\ecp\Downloads\download.html 2015-03-11 08:17 - 2015-02-03 04:34 - 05554104 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-03-11 08:17 - 2015-02-03 04:31 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-03-11 08:17 - 2015-02-03 04:31 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2015-03-11 08:17 - 2015-02-03 04:30 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2015-03-11 08:17 - 2015-02-03 04:30 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2015-03-11 08:17 - 2015-02-03 04:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2015-03-11 08:17 - 2015-02-03 04:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll 2015-03-11 08:17 - 2015-02-03 04:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll 2015-03-11 08:17 - 2015-02-03 04:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll 2015-03-11 08:16 - 2015-02-03 04:34 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2015-03-11 08:16 - 2015-02-03 04:34 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2015-03-11 08:16 - 2015-02-03 04:33 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2015-03-11 08:16 - 2015-02-03 04:31 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-03-11 08:16 - 2015-02-03 04:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-03-11 08:16 - 2015-02-03 04:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-03-11 08:16 - 2015-02-03 04:30 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-03-11 08:16 - 2015-02-03 04:30 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2015-03-11 08:16 - 2015-02-03 04:30 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2015-03-11 08:16 - 2015-02-03 04:30 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2015-03-11 08:16 - 2015-02-03 04:30 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2015-03-11 08:16 - 2015-02-03 04:30 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2015-03-11 08:16 - 2015-02-03 04:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2015-03-11 08:16 - 2015-02-03 04:30 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-03-11 08:16 - 2015-02-03 04:30 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2015-03-11 08:16 - 2015-02-03 04:30 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2015-03-11 08:16 - 2015-02-03 04:30 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2015-03-11 08:16 - 2015-02-03 04:30 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2015-03-11 08:16 - 2015-02-03 04:30 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2015-03-11 08:16 - 2015-02-03 04:30 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2015-03-11 08:16 - 2015-02-03 04:30 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-03-11 08:16 - 2015-02-03 04:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll 2015-03-11 08:16 - 2015-02-03 04:30 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2015-03-11 08:16 - 2015-02-03 04:30 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2015-03-11 08:16 - 2015-02-03 04:30 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-03-11 08:16 - 2015-02-03 04:30 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2015-03-11 08:16 - 2015-02-03 04:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2015-03-11 08:16 - 2015-02-03 04:30 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2015-03-11 08:16 - 2015-02-03 04:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe 2015-03-11 08:16 - 2015-02-03 04:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2015-03-11 08:16 - 2015-02-03 04:29 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2015-03-11 08:16 - 2015-02-03 04:28 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-03-11 08:16 - 2015-02-03 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2015-03-11 08:16 - 2015-02-03 04:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys 2015-03-11 08:16 - 2015-02-03 04:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-03-11 08:16 - 2015-02-03 04:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-03-11 08:16 - 2015-02-03 04:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2015-03-11 08:16 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2015-03-11 08:16 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2015-03-11 08:16 - 2015-02-03 04:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2015-03-11 08:16 - 2015-02-03 04:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2015-03-11 08:16 - 2015-02-03 04:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2015-03-11 08:16 - 2015-02-03 04:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2015-03-11 08:16 - 2015-02-03 04:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-03-11 08:16 - 2015-02-03 03:32 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2015-03-11 08:16 - 2014-10-31 23:24 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2015-03-11 08:16 - 2014-06-28 01:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2015-03-11 08:16 - 2014-06-28 01:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2015-03-11 08:15 - 2015-02-20 05:41 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2015-03-11 08:15 - 2015-02-20 05:40 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-03-11 08:15 - 2015-02-20 04:29 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-03-11 08:15 - 2015-02-20 04:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2015-03-11 08:14 - 2015-02-20 05:40 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2015-03-11 08:14 - 2015-02-20 05:40 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2015-03-11 08:14 - 2015-02-20 05:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2015-03-11 08:14 - 2015-02-20 05:13 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2015-03-11 08:14 - 2015-02-20 05:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2015-03-11 08:14 - 2015-02-20 05:12 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2015-03-11 08:14 - 2015-01-31 04:48 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2015-03-11 08:14 - 2015-01-31 04:48 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2015-03-11 08:14 - 2015-01-31 00:56 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2015-03-11 08:13 - 2015-03-06 06:56 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-03-11 08:13 - 2015-03-06 06:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-03-11 08:13 - 2015-03-06 06:42 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-03-11 08:13 - 2015-03-06 06:42 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-03-11 08:13 - 2015-03-06 06:42 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-03-11 08:13 - 2015-03-06 06:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-03-11 08:13 - 2015-03-06 06:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-03-11 08:13 - 2015-03-06 06:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-03-11 08:13 - 2015-03-06 06:42 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-03-11 08:13 - 2015-03-06 06:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-03-11 08:13 - 2015-03-06 06:42 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-03-11 08:13 - 2015-03-06 06:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-03-11 08:13 - 2015-03-06 06:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-03-11 08:13 - 2015-03-06 06:41 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-03-11 08:13 - 2015-03-06 06:41 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-03-11 08:13 - 2015-03-06 06:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-03-11 08:13 - 2015-03-06 06:38 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-03-11 08:13 - 2015-03-06 06:36 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-03-11 08:13 - 2015-03-06 06:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-03-11 08:13 - 2015-03-06 06:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-03-11 08:13 - 2015-03-06 06:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-03-11 08:13 - 2015-03-06 06:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-03-11 08:13 - 2015-03-06 06:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-03-11 08:13 - 2015-03-06 06:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-03-11 08:13 - 2015-03-06 06:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-03-11 08:13 - 2015-03-06 06:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-03-11 08:13 - 2015-03-06 06:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-03-11 08:13 - 2015-03-06 06:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-03-11 08:13 - 2015-03-06 06:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-03-11 08:13 - 2015-03-06 06:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-03-11 08:13 - 2015-03-06 06:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-03-11 08:13 - 2015-02-13 06:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2015-03-11 08:13 - 2015-02-13 06:22 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2015-03-11 08:13 - 2015-02-03 04:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2015-03-11 08:13 - 2015-02-03 04:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll 2015-03-11 08:13 - 2015-01-31 00:56 - 00459336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-03-11 08:12 - 2015-02-26 04:25 - 03204096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-03-11 08:12 - 2015-02-24 04:15 - 00389800 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-03-11 08:12 - 2015-02-24 03:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-03-11 08:12 - 2015-02-21 01:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-03-11 08:12 - 2015-02-21 01:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-03-11 08:12 - 2015-02-21 01:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-03-11 08:12 - 2015-02-21 01:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-03-11 08:12 - 2015-02-21 00:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-03-11 08:12 - 2015-02-20 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-03-11 08:12 - 2015-02-20 04:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-03-11 08:12 - 2015-02-20 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-03-11 08:12 - 2015-02-20 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-03-11 08:12 - 2015-02-20 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-03-11 08:12 - 2015-02-20 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-03-11 08:12 - 2015-02-20 03:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-03-11 08:12 - 2015-02-20 03:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-03-11 08:12 - 2015-02-20 03:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-03-11 08:12 - 2015-02-20 03:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-03-11 08:12 - 2015-02-20 03:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-03-11 08:12 - 2015-02-20 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-03-11 08:12 - 2015-02-20 03:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-03-11 08:12 - 2015-02-20 03:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-03-11 08:12 - 2015-02-20 03:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-03-11 08:12 - 2015-02-20 02:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-03-11 08:12 - 2015-02-20 02:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-03-11 08:12 - 2015-02-20 02:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-03-11 08:12 - 2015-02-20 02:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-03-11 08:12 - 2015-02-20 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-03-11 08:12 - 2015-02-20 02:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-03-11 08:12 - 2015-02-20 02:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-03-11 08:12 - 2015-02-20 02:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-03-11 08:12 - 2015-02-20 02:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-03-11 08:12 - 2015-02-20 01:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-03-11 08:12 - 2015-02-20 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-03-11 08:12 - 2015-02-03 04:31 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-03-11 08:12 - 2015-02-03 04:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2015-03-11 08:12 - 2015-01-17 03:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2015-03-11 08:12 - 2015-01-17 03:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2015-03-11 08:11 - 2015-02-21 02:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-03-11 08:11 - 2015-02-21 00:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-03-11 08:11 - 2015-02-20 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-03-11 08:11 - 2015-02-20 03:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-03-11 08:11 - 2015-02-20 03:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-03-11 08:11 - 2015-02-20 03:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-03-11 08:11 - 2015-02-20 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-03-11 08:11 - 2015-02-20 03:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-03-11 08:11 - 2015-02-20 03:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-03-11 08:11 - 2015-02-20 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-03-11 08:11 - 2015-02-20 03:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-03-11 08:11 - 2015-02-20 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-03-11 08:11 - 2015-02-20 03:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-03-11 08:11 - 2015-02-20 03:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-03-11 08:11 - 2015-02-20 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-03-11 08:11 - 2015-02-20 02:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-03-11 08:11 - 2015-02-20 02:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-03-11 08:11 - 2015-02-20 02:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-03-11 08:11 - 2015-02-20 02:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-03-11 08:11 - 2015-02-20 02:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-03-11 08:11 - 2015-02-20 02:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-03-11 08:11 - 2015-02-20 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-03-11 08:11 - 2015-02-20 02:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-03-11 08:06 - 2015-02-04 04:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2015-03-11 08:06 - 2015-02-04 03:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2015-03-06 07:48 - 2015-03-06 07:51 - 00000000 ____D () C:\Program Files (x86)\SoaleEsChoeocKeirr 2015-03-05 17:07 - 2015-03-05 17:07 - 00000000 ____D () C:\ProgramData\Auslogics 2015-03-05 17:06 - 2015-03-05 17:06 - 00001298 _____ () C:\Users\ecp\Desktop\Auslogics Duplicate File Finder.lnk 2015-03-05 17:06 - 2015-03-05 17:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics 2015-03-05 17:06 - 2015-03-05 17:06 - 00000000 ____D () C:\Program Files (x86)\Auslogics 2015-03-05 17:05 - 2015-03-05 17:05 - 06929688 _____ (Auslogics Labs Pty Ltd ) C:\Users\ecp\Downloads\duplicate-file-finder-setup.exe 2015-03-05 16:57 - 2015-03-05 17:02 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\FreeFileSync 2015-03-05 16:56 - 2015-03-05 16:56 - 00385602 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS 2015-03-05 16:56 - 2015-03-05 16:56 - 00000951 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeFileSync.lnk 2015-03-05 16:56 - 2015-03-05 16:56 - 00000941 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealtimeSync.lnk 2015-03-05 16:56 - 2015-03-05 16:56 - 00000939 _____ () C:\Users\Public\Desktop\FreeFileSync.lnk 2015-03-05 16:56 - 2015-03-05 16:56 - 00000929 _____ () C:\Users\Public\Desktop\RealtimeSync.lnk 2015-03-05 16:56 - 2015-03-05 16:56 - 00000232 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS.part 2015-03-05 16:56 - 2015-03-05 16:56 - 00000000 ____D () C:\Users\ecp\AppData\Local\145842EF_stp 2015-03-05 16:56 - 2015-03-05 16:56 - 00000000 ____D () C:\Program Files\FreeFileSync 2015-03-05 16:55 - 2015-03-05 16:55 - 12653536 _____ (www.FreeFileSync.org ) C:\Users\ecp\Downloads\freefilesync_6.14_windows_setup.exe 2015-03-05 16:55 - 2015-03-05 16:55 - 12653536 _____ (www.FreeFileSync.org ) C:\Users\ecp\Downloads\freefilesync_6.14_windows_setup (1).exe 2015-03-05 16:28 - 2015-03-05 16:28 - 00000000 ___HD () C:\ProgramData\CanonIJScan 2015-03-05 16:28 - 2015-03-05 16:28 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Canon 2015-03-05 08:19 - 2015-03-05 08:19 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-03-05 08:19 - 2015-03-05 08:19 - 00000000 ___HD () C:\ProgramData\CanonIJFAX 2015-03-05 08:19 - 2015-03-05 08:19 - 00000000 ____D () C:\Windows\system32\appraiser 2015-03-05 08:18 - 2011-09-21 05:00 - 00302592 _____ (CANON INC.) C:\Windows\system32\CNCALB0.DLL 2015-03-05 08:17 - 2015-03-05 08:17 - 00000000 ___HD () C:\Windows\system32\CanonIJ Uninstaller Information 2015-03-05 08:17 - 2015-03-05 08:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX370 series 2015-03-05 08:17 - 2011-10-14 11:57 - 00300544 _____ (CANON INC.) C:\Windows\system32\CNC_B0C.dll 2015-03-05 08:17 - 2011-10-14 11:57 - 00102912 _____ (CANON INC.) C:\Windows\SysWOW64\CNC_B0U.dll 2015-03-05 08:17 - 2011-10-14 11:56 - 00109568 _____ (CANON INC.) C:\Windows\system32\CNC_B0I.dll 2015-03-05 08:17 - 2011-09-22 08:59 - 00358912 _____ (CANON INC.) C:\Windows\system32\CNC_B0L.dll 2015-03-05 08:17 - 2011-09-22 08:57 - 00316416 _____ (CANON INC.) C:\Windows\SysWOW64\CNC_B0L.dll 2015-03-05 08:17 - 2011-06-30 13:35 - 00065280 _____ () C:\Windows\SysWOW64\CNC1759D.TBL 2015-03-05 08:17 - 2011-06-30 13:35 - 00065280 _____ () C:\Windows\system32\CNC1759D.TBL 2015-03-05 08:17 - 2008-08-25 18:02 - 00017920 _____ (CANON INC.) C:\Windows\system32\CNHMCA6.dll 2015-03-05 08:17 - 2008-08-25 18:02 - 00015872 _____ (CANON INC.) C:\Windows\SysWOW64\CNHMCA.dll 2015-03-05 08:15 - 2011-11-03 05:00 - 00385024 _____ (CANON INC.) C:\Windows\system32\CNMLMB0.DLL 2015-03-05 07:43 - 2015-01-09 00:44 - 00419936 _____ () C:\Windows\SysWOW64\locale.nls 2015-03-05 07:43 - 2015-01-09 00:43 - 00419936 _____ () C:\Windows\system32\locale.nls 2015-03-05 07:28 - 2014-06-27 03:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2015-03-05 07:28 - 2014-06-27 02:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2015-03-04 09:13 - 2015-03-04 09:17 - 00047447 _____ () C:\Users\ecp\Documents\MyMicroBalance.mmb 2015-03-04 09:13 - 2015-03-04 09:13 - 00000000 ____D () C:\Users\ecp\Documents\backup_MyMicroBalance 2015-03-04 09:12 - 2015-03-04 09:12 - 00000000 ____D () C:\Users\ecp\Documents\BSHTOP332SA 2015-03-04 07:37 - 2015-01-09 04:14 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll 2015-03-04 07:37 - 2015-01-09 04:14 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll 2015-03-04 07:37 - 2015-01-09 04:14 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll 2015-03-04 07:37 - 2015-01-09 03:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdi.dll 2015-03-04 07:36 - 2015-02-04 04:16 - 00894976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-03-04 07:36 - 2015-02-04 04:16 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-03-04 07:36 - 2015-02-04 04:16 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-03-04 07:36 - 2015-02-04 04:16 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-03-04 07:36 - 2015-02-04 04:16 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-03-04 07:36 - 2015-02-04 04:16 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-03-04 07:36 - 2015-02-04 04:13 - 01098752 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-03-04 07:36 - 2015-01-28 00:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2015-03-04 07:36 - 2014-08-01 12:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2015-03-04 07:36 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2015-03-04 07:35 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2015-03-04 07:35 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2015-03-04 07:35 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2015-03-04 07:35 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2015-03-04 07:35 - 2014-07-09 03:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2015-03-04 07:35 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2015-03-04 07:35 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2015-03-04 07:35 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2015-03-04 07:35 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2015-03-04 07:35 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2015-03-04 07:35 - 2014-06-24 04:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2015-03-04 07:35 - 2014-06-24 03:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2015-03-04 07:34 - 2014-11-26 04:53 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2015-03-04 07:34 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2015-03-04 07:34 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2015-03-04 07:34 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2015-03-04 07:34 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2015-03-04 07:34 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe 2015-03-04 07:34 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe 2015-03-04 07:34 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2015-03-04 07:34 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll 2015-03-04 07:34 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll 2015-03-04 07:34 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll 2015-03-04 07:34 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2015-03-04 07:34 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2015-03-04 07:34 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll 2015-03-04 07:34 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll 2015-03-04 07:34 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll 2015-03-04 07:34 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe 2015-03-04 07:33 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2015-03-04 07:33 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2015-03-04 07:31 - 2014-09-05 03:11 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2015-03-04 07:31 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2015-03-02 13:21 - 2015-03-02 13:21 - 00000291 _____ () C:\Users\ecp\Downloads\BK_RHDE_002347DE_LC_64_44100_ster_A2D4MN5C3DWNEX.adh 2015-03-02 13:21 - 2015-03-02 13:21 - 00000291 _____ () C:\Users\ecp\Downloads\admhelper (2).adh 2015-03-02 13:17 - 2015-03-02 13:24 - 00000000 ____D () C:\Users\ecp\AppData\Local\Audible 2015-03-02 13:17 - 2015-03-02 13:17 - 00255352 _____ (Audible, Inc.) C:\Windows\SysWOW64\awrdscdc.ax 2015-03-02 13:17 - 2015-03-02 13:17 - 00001972 _____ () C:\Users\ecp\Desktop\Audible Manager.lnk 2015-03-02 13:17 - 2015-03-02 13:17 - 00000340 _____ () C:\Users\ecp\Downloads\BK_RHDE_002360DE_LC_64_44100_ster_A2D4MN5C3DWNEX.adh 2015-03-02 13:17 - 2015-03-02 13:17 - 00000291 _____ () C:\Users\ecp\Downloads\admhelper.adh 2015-03-02 13:17 - 2015-03-02 13:17 - 00000291 _____ () C:\Users\ecp\Downloads\admhelper (1).adh 2015-03-02 13:17 - 2015-03-02 13:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudibleManager 2015-03-02 13:16 - 2015-03-02 13:17 - 00000000 ____D () C:\Users\ecp\Documents\Audible 2015-03-02 13:16 - 2015-03-02 13:17 - 00000000 ____D () C:\Program Files (x86)\Audible 2015-03-02 13:16 - 2015-03-02 13:16 - 00000000 ____D () C:\Users\Public\Documents\Audible 2015-03-02 13:16 - 2003-03-18 21:20 - 01060864 ____N (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll 2015-03-02 13:16 - 2001-08-17 22:43 - 00024576 ____N (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll 2015-03-02 13:15 - 2015-03-02 13:15 - 01730272 _____ (Audible Inc.) C:\Users\ecp\Downloads\ActiveSetupN (1).exe 2015-03-02 13:14 - 2015-03-02 13:14 - 01730272 _____ (Audible Inc.) C:\Users\ecp\Downloads\ActiveSetupN.exe 2015-03-02 10:54 - 2015-03-17 23:27 - 00000000 ____D () C:\Users\ecp\Documents\Martina60Geburtstag20150406 2015-03-01 12:41 - 2015-03-01 12:41 - 00001047 _____ () C:\Users\ecp\Desktop\Android - Verknüpfung.lnk 2015-02-25 18:42 - 2015-02-25 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2015-02-25 18:42 - 2015-02-25 18:42 - 00000000 ____D () C:\Program Files\7-Zip 2015-02-25 18:41 - 2015-02-25 18:41 - 01376768 _____ () C:\Users\ecp\Documents\7z920-x64.msi ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-26 21:28 - 2015-01-01 11:27 - 00000284 _____ () C:\Windows\Tasks\WSE_Vosteran.job 2015-03-26 21:27 - 2015-01-01 11:26 - 00000284 _____ () C:\Windows\Tasks\Price Fountain.job 2015-03-26 21:27 - 2014-12-30 15:50 - 00000000 ____D () C:\Users\ecp 2015-03-26 21:27 - 2011-04-12 08:43 - 00698926 _____ () C:\Windows\system32\perfh007.dat 2015-03-26 21:27 - 2011-04-12 08:43 - 00149034 _____ () C:\Windows\system32\perfc007.dat 2015-03-26 21:27 - 2009-07-14 06:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-03-26 21:27 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-03-26 21:27 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-03-26 21:26 - 2014-11-25 11:56 - 01737377 _____ () C:\Windows\WindowsUpdate.log 2015-03-26 21:24 - 2009-07-14 05:51 - 00059730 _____ () C:\Windows\setupact.log 2015-03-26 21:13 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-03-26 21:12 - 2014-12-30 16:33 - 00000000 ____D () C:\Program Files (x86)\Dynamo Combo 2015-03-24 19:08 - 2014-07-23 10:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-03-24 18:49 - 2015-01-01 14:35 - 00000000 ____D () C:\Users\ecp\Documents\112 wiederkehrende dateien 1412 2015-03-24 18:19 - 2015-01-01 11:20 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Skype 2015-03-24 17:26 - 2015-01-01 12:26 - 00000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG 2015-03-24 17:22 - 2009-07-14 03:34 - 00000505 _____ () C:\Windows\win.ini 2015-03-24 08:15 - 2015-01-02 12:37 - 00040478 _____ () C:\Windows\system32\ScanResults.xml 2015-03-24 08:08 - 2015-01-02 12:32 - 00000464 _____ () C:\Windows\system32\ScannerSettings 2015-03-24 08:06 - 2014-12-30 16:35 - 00003236 _____ () C:\Windows\System32\Tasks\PC Speed Maximizer Schedule 2015-03-23 09:18 - 2015-02-04 21:49 - 00000000 ____D () C:\ProgramData\15483481001080132652 2015-03-23 07:32 - 2015-01-01 23:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-03-22 09:09 - 2015-01-01 23:29 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Mozilla 2015-03-22 08:50 - 2014-12-31 10:40 - 00000000 ____D () C:\Users\ecp\AppData\Local\Adobe 2015-03-19 20:07 - 2014-12-30 16:38 - 00003848 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1419953902 2015-03-19 20:07 - 2014-12-30 16:37 - 00000000 ____D () C:\Program Files (x86)\Opera 2015-03-19 20:05 - 2015-02-08 12:08 - 00000000 ____D () C:\Users\ecp\Documents\Tennisclub 2015-03-18 12:26 - 2015-02-12 12:26 - 00000274 _____ () C:\Windows\Tasks\DriverDoc_UPDATES.job 2015-03-16 19:21 - 2014-07-23 10:43 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-03-16 19:21 - 2014-07-23 10:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-03-16 19:21 - 2014-07-23 10:43 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-03-16 12:57 - 2015-02-08 12:09 - 00000000 ____D () C:\Users\ecp\Documents\Privates 2015-03-13 08:40 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2015-03-13 08:35 - 2009-07-14 05:45 - 00298232 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-03-13 08:31 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2015-03-13 08:31 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism 2015-03-13 08:15 - 2014-07-22 16:37 - 00000000 ____D () C:\Windows\system32\MRT 2015-03-13 08:06 - 2014-07-22 16:37 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-03-11 21:30 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2015-03-11 08:00 - 2015-01-06 11:05 - 00000000 ____D () C:\Program Files (x86)\GTS 2015-03-09 18:16 - 2015-02-08 12:09 - 00000000 ____D () C:\Users\ecp\Documents\NBV 2015-03-09 11:13 - 2015-02-16 18:42 - 00000000 ____D () C:\Users\ecp\Documents\Camera 2015-03-06 08:02 - 2015-01-21 06:59 - 00000000 ____D () C:\ProgramData\woEbsauVer 2015-03-06 08:02 - 2015-01-20 07:39 - 00000000 ____D () C:\ProgramData\SmaaritCoimepare 2015-03-06 08:02 - 2015-01-20 07:38 - 00000000 ____D () C:\ProgramData\saFerwEb 2015-03-06 07:48 - 2015-02-20 08:19 - 00000000 ____D () C:\Program Files (x86)\SaleisuCheccker 2015-03-06 07:48 - 2015-02-07 03:30 - 00000000 ____D () C:\Program Files (x86)\RoyAlCeOupoen 2015-03-05 08:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing 2015-03-05 08:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat 2015-03-05 08:18 - 2009-07-14 04:20 - 00000000 __RSD () C:\Windows\Media 2015-03-04 09:17 - 2015-02-04 18:15 - 00001874 _____ () C:\Users\ecp\AppData\Roaming\MyMicroBalanceConfig.ini 2015-03-03 14:17 - 2010-11-21 04:27 - 00295552 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-03-01 10:48 - 2015-01-03 01:27 - 00000010 _____ () C:\Users\ecp\AppData\Local\DSI.DAT 2015-02-26 18:09 - 2010-11-21 04:47 - 00028536 _____ () C:\Windows\PFRO.log ==================== Files in the root of some directories ======= 2015-02-04 18:15 - 2015-03-04 09:17 - 0001874 _____ () C:\Users\ecp\AppData\Roaming\MyMicroBalanceConfig.ini 2015-01-01 12:26 - 2015-03-24 17:26 - 0000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG 2015-03-05 16:56 - 2015-03-05 16:56 - 0385602 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS 2015-03-05 16:56 - 2015-03-05 16:56 - 0000232 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS.part 2015-01-03 01:27 - 2015-03-01 10:48 - 0000010 _____ () C:\Users\ecp\AppData\Local\DSI.DAT 2015-01-03 01:27 - 2015-01-03 01:27 - 0022528 _____ () C:\Users\ecp\AppData\Local\dsisetup1374062732.exe Some content of TEMP: ==================== C:\Users\ecp\AppData\Local\Temp\4754A20B-48BD-0A59-3FE0-3CDF5D1052F8.dll C:\Users\ecp\AppData\Local\Temp\4754A20B-48BD-0A59-3FE0-3CDF5D1052F8.exe C:\Users\ecp\AppData\Local\Temp\APNSetup.exe C:\Users\ecp\AppData\Local\Temp\c1ef6.exe C:\Users\ecp\AppData\Local\Temp\dcacabfcdbaj.exe C:\Users\ecp\AppData\Local\Temp\FF28C860-5054-21EF-E5E1-FBD2C802FC5E.exe C:\Users\ecp\AppData\Local\Temp\gmx_mediacenter_setup_a201412.exe C:\Users\ecp\AppData\Local\Temp\ICSW_0A1Q1B1P1T1C1R1M1P1B1V0C0H0N0LtC.exe C:\Users\ecp\AppData\Local\Temp\OnlineBackup.exe C:\Users\ecp\AppData\Local\Temp\optprosetup.exe C:\Users\ecp\AppData\Local\Temp\ReimagePackage.exe C:\Users\ecp\AppData\Local\Temp\Setup.exe C:\Users\ecp\AppData\Local\Temp\SPINT-G.exe C:\Users\ecp\AppData\Local\Temp\SpOrder.dll C:\Users\ecp\AppData\Local\Temp\standaloneupdater-setup.exe C:\Users\ecp\AppData\Local\Temp\System.Data.SQLite.dll C:\Users\ecp\AppData\Local\Temp\System.Data.SQLite9230e067-1b8f-4b92-9e2c-41da44fb0fa8.dll C:\Users\ecp\AppData\Local\Temp\vcredist_x64.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-11 18:40 ==================== End Of Log ============================ Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015 Ran by ecp at 2015-03-26 21:31:35 Running from C:\Reinigung Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A} AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Flash Player 17 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Anzeige am Bildschirm (HKLM\...\OnScreenDisplay) (Version: 6.73.01 - ) Ashampoo Burning Studio 2015 v.1.15.0 (HKLM-x32\...\{91B33C97-21E3-DF34-9630-2EE80DDE1648}_is1) (Version: 1.15.0 - Ashampoo GmbH & Co. KG) Audials (HKLM-x32\...\{AB509249-C384-4607-BED0-8C9167BE74B1}) (Version: 11.0.56100.0 - Audials AG) AudibleManager (HKLM-x32\...\AudibleManager) (Version: 2003188990.48.56.2493674 - Audible, Inc.) Auslogics Duplicate File Finder (HKLM-x32\...\{6845255F-15CC-4DD1-94D5-D38F370118B3}_is1) (Version: 4.3.0.0 - Auslogics Labs Pty Ltd) Binkiland (HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Binkiland) (Version: 31.0.1650.23 - Binkiland) <==== ATTENTION! bobyzoom (HKLM-x32\...\{9D8D5AD9-94C7-40B3-88F2-2B8F227F6381}) (Version: 1.1.0.30 - bobyzoom) Buzzdock (HKLM\...\{ac225167-00fc-452d-94c5-bb93600e7d9a}) (Version: - Alactro LLC) <==== ATTENTION Canon MX370 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX370_series) (Version: - ) Canon MX370 series On-screen Manual (HKLM-x32\...\Canon MX370 series On-screen Manual) (Version: - ) CheckMeUp (HKLM-x32\...\C441D512-F5C2-07AC-8AE0-499C197A5D55) (Version: - CheckMeUp-software) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dienstprogramm "ThinkPad UltraNav" (HKLM-x32\...\{17CBC505-D1AE-459D-B445-3D2000A85842}) (Version: 2.13.0 - Lenovo) DiskBoss 5.1.12 (HKLM-x32\...\DiskBoss) (Version: 5.1.12 - Flexense Computing Systems Ltd.) DriverDoc (HKLM-x32\...\DriverDoc_is1) (Version: 1.52.1086.14425 - Solvusoft Corporation) Dynamo Combo (HKLM\...\Dynamo Combo) (Version: 2014.12.30.132317 - Dynamo Combo) <==== ATTENTION Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden FreeFileSync 6.14 (HKLM-x32\...\FreeFileSync_is1) (Version: 6.14 - www.FreeFileSync.org) GTS (HKLM-x32\...\{29726780-AB28-466D-87E3-678DA41D2264}) (Version: 1.00.17 - vwd AG) HQCinema Pro 2.1V20.03 (HKLM-x32\...\HQCinema Pro 2.1V20.03) (Version: 1.36.01.22 - HQ CinemaV20.03) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.04.05 - ) Lenovo System Interface Driver (HKLM\...\LENOVO.SMIIF) (Version: 1.05 - ) Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.06.0027 - Lenovo) McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.) Metric Collection SDK (x32 Version: 1.1.0005.00 - Lenovo Group Limited) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 36.0.4 (x86 de) (HKLM-x32\...\Mozilla Firefox 36.0.4 (x86 de)) (Version: 36.0.4 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 36.0.4 - Mozilla) Mozilla Thunderbird 31.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.4.0 (x86 de)) (Version: 31.4.0 - Mozilla) MyMicroBalance (HKLM-x32\...\{F508CC9F-A477-4C15-A9FE-59BCE258F839}) (Version: 3.0.3 - startzentrum GmbH & Co KG) OnlineLowDeals (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version: - OnlineLowDeals) <==== ATTENTION OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) Opera Stable 28.0.1750.48 (HKLM-x32\...\Opera 28.0.1750.48) (Version: 28.0.1750.48 - Opera Software ASA) PC Speed Maximizer v4.0 (HKLM-x32\...\PC Speed Maximizer_is1) (Version: 4.0 - Smart PC Solutions) PriceFountain (remove only) (HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\PriceFountain) (Version: 1.0.8.6 - Price Fountain) <==== ATTENTION! Pro PC Cleaner (HKLM-x32\...\{C3060724-6AC7-4BEF-B516-4F6B1D90887D}) (Version: 2.5.5 - Pro PC Cleaner) Reimage Repair (HKLM\...\Reimage Repair) (Version: 1.8.0.4 - Reimage) <==== ATTENTION RICOH R5U8xx Media Driver ver.3.64.02 (HKLM-x32\...\{59F6A514-9813-47A3-948C-8A155460CC2A}) (Version: 3.64.02 - RICOH) RocketTab (HKLM-x32\...\RocketTab) (Version: - RocketTab) <==== ATTENTION! Saveitkeaep. (HKLM-x32\...\{B10BC31B-DBC6-56FE-DD3D-DD4E49A3E6CE}) (Version: - "") <==== ATTENTION SecurityUtility Service (HKLM-x32\...\SecurityUtility Service) (Version: - ) Skype™ 6.3 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.3.105 - Skype Technologies S.A.) SoundMAX (HKLM-x32\...\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 6.10.2.7255 - Analog Devices) SystemContinue (HKLM-x32\...\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{9617fb41}) (Version: - Software Publisher) <==== ATTENTION ThinkPad FullScreen Magnifier (HKLM\...\ThinkPad FullScreen Magnifier) (Version: 2.42 - ) ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.19.7 - ) Update for PriceFountain (HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Price Fountain) (Version: - Update for PriceFountain) <==== ATTENTION vi-view uninstall (HKLM-x32\...\vi-view uninstall) (Version: - vi-view) <==== ATTENTION Vosteran (HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Vosteran) (Version: 31.0.1650.23 - Vosteran) <==== ATTENTION! Wajam (HKLM-x32\...\Wajam Web Enhancer) (Version: 1.41.1.2 (i1.0) - Wajam) <==== ATTENTION Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) WSE_Binkiland (HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\WSE_Binkiland) (Version: - WSE_Binkiland) <==== ATTENTION! WSE_Vosteran (HKLM-x32\...\WSE_Vosteran) (Version: - WSE_Vosteran) <==== ATTENTION! Yahoo! Search (HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Yahoo! Search) (Version: - Pay-By-Ads) <==== ATTENTION ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1780445102-594666999-3139876592-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1780445102-594666999-3139876592-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1780445102-594666999-3139876592-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1780445102-594666999-3139876592-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1780445102-594666999-3139876592-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation) ==================== Restore Points ========================= 11-03-2015 16:47:20 Windows Update 13-03-2015 08:00:07 Windows Update 15-03-2015 19:00:32 Windows-Sicherung 17-03-2015 01:12:29 Windows Update 20-03-2015 19:25:59 Windows Update 23-03-2015 07:20:51 Windows-Sicherung 23-03-2015 08:19:56 Wiederherstellungsvorgang 24-03-2015 08:27:24 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0B21BA66-C60F-4200-8560-804717DAD7FD} - System32\Tasks\Reimage Reminder => C:\Program Files\Reimage\Reimage Repair\ReimageReminder.exe [2015-01-18] () <==== ATTENTION Task: {414B3EBC-9594-4211-8083-6E6540AF2EFC} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe Task: {4455D852-903D-44A8-876D-4358378E4D9E} - System32\Tasks\RocketTab Update Task => C:\Program Files (x86)\Search Extensions\uninstall.exe [2015-03-20] () <==== ATTENTION Task: {55282CB5-1012-4A50-89B5-FAD8E5BDD42A} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-03-20] (globalUpdate) <==== ATTENTION Task: {574481C6-4D86-4C9A-931D-6B5C43CC638B} - System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5 => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.exe [2015-03-20] (HQ CinemaV20.03) <==== ATTENTION Task: {57D8A394-980F-47D4-B751-2D2680575048} - System32\Tasks\Opera scheduled Autoupdate 1419953902 => C:\Program Files (x86)\Opera\launcher.exe [2015-03-16] (Opera Software) Task: {66523849-E0E7-4688-B4DF-6647DBF3D634} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-02-13] (Lenovo) Task: {66EFCD3A-186E-440C-A78D-48E94C27C78C} - System32\Tasks\ProPCCleaner_Popup => C:\Program Files (x86)\Pro PC Cleaner\Splash.exe [2014-07-14] () <==== ATTENTION Task: {67C8C4B8-B53B-474F-BF84-74B85B1A2DE1} - System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7 => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.exe [2015-03-20] (HQ CinemaV20.03) <==== ATTENTION Task: {6BDC9C59-4CEF-45F7-9636-76251F5B3D87} - System32\Tasks\RocketTab => cmd.exe /C start "" "C:\Program Files (x86)\Search Extensions\Client.exe" /Preferred=true <==== ATTENTION Task: {6F28B60D-6818-4A76-B437-A0121AFA54B8} - System32\Tasks\Price Fountain => C:\Users\ecp\AppData\Roaming\PriceFountain\UpdateProc\UpdateTask.exe [2015-01-01] () <==== ATTENTION Task: {6FA935E0-A985-4B73-9D19-84541B6D89B9} - System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10_user => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10.exe [2015-03-20] (HQ CinemaV20.03) <==== ATTENTION Task: {84D26E5B-B196-4696-A46B-580CACB57449} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-03-20] (globalUpdate) <==== ATTENTION Task: {84F8A2C5-F194-41CE-8FC6-26E4E2D52F30} - System32\Tasks\DriverDocRunAtStartup => C:\Program Files (x86)\DriverDoc\Solvusoftdd.exe [2012-10-05] (Solvusoft Corporation) Task: {8BDDE8B0-6B6A-4CD5-A7CE-EAD36E2AB679} - System32\Tasks\Check for Scheduled Updates => C:\Users\ecp\AppData\Local\32220c02-c108-4e43-b856-df7d87f70051\CheckUpdate.exe [2015-03-22] (7ade0034-261e-4998-bb90-451ac52a6732) Task: {967F4A34-78A8-422F-ADFB-63A2A923F8F9} - System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11 => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.exe [2015-03-20] (HQ CinemaV20.03) <==== ATTENTION Task: {A541A9A1-8A3D-46BD-9FEC-049F2C2914E8} - System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6 => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.exe [2015-03-20] (HQ CinemaV20.03) <==== ATTENTION Task: {A6421EDD-8339-423B-92DC-E2868FC40CC1} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\JustCloud\Signup Wizard.exe Task: {ADAA2B28-03F0-493B-87D4-F8985769B4B3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-16] (Adobe Systems Incorporated) Task: {B50B3FC4-6FF9-4EB6-82B1-F5FB7DAA45B5} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2015-01-15] () Task: {B5AF85BA-CD3C-4D50-9158-F6E4408ACEB0} - System32\Tasks\Wse_binkiland => C:\Users\ecp\AppData\Roaming\Wse_binkiland\UpdateProc\UpdateTask.exe [2015-03-22] () <==== ATTENTION Task: {B6A9971E-16C3-400E-8ACB-38B1D07F16A1} - System32\Tasks\PC Speed Maximizer Schedule => C:\Program Files (x86)\PC Speed Maximizer\SPMSchedule.exe [2014-11-20] (Avanquest Software) Task: {BCC3FDEB-E540-48C5-B644-BA8E8980CFAC} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [2015-01-14] (Reimage®) <==== ATTENTION Task: {C7AC4434-F9CE-48BF-A268-DEE29E14B07D} - System32\Tasks\CheckMeUp Update => C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe [2015-03-20] () Task: {C8C6A4AE-5F26-4FD0-875C-508B7FE68A54} - System32\Tasks\WSE_Vosteran => C:\Users\ecp\AppData\Roaming\WSE_Vosteran\UpdateProc\UpdateTask.exe [2015-01-01] () <==== ATTENTION Task: {D3B1594F-167E-4429-B45E-3E9FB1DFCB91} - System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5_user => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.exe [2015-03-20] (HQ CinemaV20.03) <==== ATTENTION Task: {D699591C-6656-49C5-BD87-8860FD43C735} - System32\Tasks\DriverDoc_UPDATES => C:\Program Files (x86)\DriverDoc\Solvusoftdd.exe [2012-10-05] (Solvusoft Corporation) Task: {E0FDBA42-2C94-4380-BC4A-47C538A64A6C} - System32\Tasks\Yahoo! Search => C:\Users\ecp\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrlte.exe [2015-03-20] (Pay By Ads LTD) <==== ATTENTION Task: {E752B85E-45F7-460D-ABCD-AE02F7419B9D} - System32\Tasks\ProPCCleaner_Start => C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe [2014-07-14] (Pro PC Cleaner) <==== ATTENTION Task: {FF95E773-DA1A-4576-87C8-1EDA73422463} - System32\Tasks\Yahoo! Search Updater => C:\Users\ecp\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrsetup.exe [2015-03-20] (Pay By Ads LTD) <==== ATTENTION Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\CheckMeUp Update.job => C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe Task: C:\Windows\Tasks\DriverDoc_UPDATES.job => C:\Program Files (x86)\DriverDoc\Solvusoftdd.exe Task: C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.job => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.exe <==== ATTENTION Task: C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.job => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.exe <==== ATTENTION Task: C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10_user.job => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10.exe <==== ATTENTION Task: C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.job => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.exe <==== ATTENTION Task: C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.job => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.exe <==== ATTENTION Task: C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5_user.job => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.exe <==== ATTENTION Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION Task: C:\Windows\Tasks\Price Fountain.job => C:\Users\ecp\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\Wse_binkiland.job => C:\Users\ecp\AppData\Roaming\WSE_BI~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\WSE_Vosteran.job => C:\Users\ecp\AppData\Roaming\WSE_VO~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION ==================== Loaded Modules (whitelisted) ============== 2014-12-11 11:36 - 2014-12-11 11:36 - 00118784 _____ () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe 2015-03-20 18:48 - 2015-03-20 10:47 - 00379392 _____ () C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe 2015-01-14 11:07 - 2015-01-14 11:07 - 06757728 _____ () C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe 2014-12-30 14:30 - 2015-03-24 17:19 - 00411376 _____ () C:\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe 2014-12-30 16:42 - 2015-03-24 17:22 - 00411376 _____ () C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.exe 2015-03-16 15:34 - 2015-03-16 15:34 - 01594368 _____ () C:\Program Files\WajaWebEnhancer\wajam_64.exe 2015-03-20 18:44 - 2015-03-20 18:44 - 00512512 _____ () C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe 2015-03-16 15:32 - 2015-03-16 15:32 - 01330688 _____ () C:\Program Files\WajaWebEnhancer\wajam.exe 2015-03-26 21:13 - 2015-03-26 21:13 - 01260032 _____ () C:\Program Files\WajaWebEnhancer\dlls\nuyufqlxqyxxwzh.dll 2014-12-17 15:38 - 2014-12-17 15:38 - 02410760 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe 2015-03-22 08:52 - 2015-02-04 12:38 - 01014272 _____ () C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe 2015-03-20 18:44 - 2015-03-20 18:44 - 00745984 _____ () C:\Program Files (x86)\ver0CheckMeUp\CheckMeUp.exe 2015-03-22 07:43 - 2015-03-22 07:43 - 01609728 _____ () c:\Program Files (x86)\SystemContinue\SystemContinue.dll 2014-12-11 11:28 - 2014-12-11 11:28 - 02494464 _____ () C:\Program Files (x86)\DiskBoss\bin\libdbs.dll 2014-12-11 11:26 - 2014-12-11 11:26 - 00724992 _____ () C:\Program Files (x86)\DiskBoss\bin\libpal.dll 2015-03-26 21:13 - 2015-03-26 21:13 - 02962432 _____ () C:\Program Files\WajaWebEnhancer\dlls\exgejjnypksj.dll 2014-12-17 15:38 - 2014-12-17 15:38 - 00046080 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\boost_thread-vc90-mt-1_39.dll 2014-12-17 15:38 - 2014-12-17 15:38 - 00045056 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\boost_date_time-vc90-mt-1_39.dll 2014-12-17 15:38 - 2014-12-17 15:38 - 00545032 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\StreamingClient.dll 2014-12-17 15:38 - 2014-12-17 15:38 - 00012800 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\boost_system-vc90-mt-1_39.dll 2014-12-17 15:38 - 2014-12-17 15:38 - 00068360 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\CrashRpt.dll 2014-12-17 15:38 - 2014-12-17 15:38 - 00409352 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\SQLite3.dll 2014-12-17 15:38 - 2014-12-17 15:38 - 00614912 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\boost_regex-vc90-mt-1_39.dll 2015-01-02 13:15 - 2015-01-02 13:15 - 00295424 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Utils\edd00f558957306a6abccee62d067d37\Utils.ni.dll 2015-01-02 13:15 - 2015-01-02 13:15 - 00589312 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ManagedInterfaces\43353f3d05c807ea3b3c598744f5ffaa\ManagedInterfaces.ni.dll 2015-01-02 13:16 - 2015-01-02 13:16 - 02997248 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\AudialsComponents\d1311eabe3d9a4088615c82fb65ae289\AudialsComponents.ni.dll 2015-01-02 13:16 - 2015-01-02 13:16 - 00178688 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\fastJSON\f82cce18fd1d4175d2aadbdb2d200ec7\fastJSON.ni.dll 2015-03-22 08:52 - 2015-02-04 12:38 - 28006400 _____ () C:\Users\ecp\AppData\Local\Binkiland\Application\31.0.1650.23\chrome.dll 2015-03-22 08:52 - 2015-02-04 12:38 - 34445312 _____ () C:\Users\ecp\AppData\Local\Binkiland\Application\31.0.1650.23\chrome_child.dll 2015-03-22 08:52 - 2015-02-04 12:38 - 00695808 _____ () C:\Users\ecp\AppData\Local\Binkiland\Application\31.0.1650.23\libglesv2.dll 2015-03-22 08:52 - 2015-02-04 12:38 - 00093184 _____ () C:\Users\ecp\AppData\Local\Binkiland\Application\31.0.1650.23\libegl.dll 2015-03-22 08:52 - 2015-02-04 12:38 - 00394240 _____ () C:\Users\ecp\AppData\Local\Binkiland\Application\31.0.1650.23\ppGoogleNaClPluginChrome.dll 2015-03-22 08:52 - 2015-02-04 12:38 - 00788992 _____ () C:\Users\ecp\AppData\Local\Binkiland\Application\31.0.1650.23\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Gambali => ""="service" ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Control Panel\Desktop\\Wallpaper -> DNS Servers: Media is not connected to internet. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: ApnTBMon => "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" MSCONFIG\startupreg: GoogleChromeAutoLaunch_5C8F99C8E2E3047D14C0E718E5A5B373 => "C:\Users\ecp\AppData\Local\Vosteran\Application\vosteran.exe" --auto-launch-at-startup --profile-directory="Default" MSCONFIG\startupreg: MailCheck IE Broker => "C:\Program Files (x86)\GMX MailCheck\IE\GMX_MailCheck_Broker.exe" ==================== Accounts: ============================= Administrator (S-1-5-21-1780445102-594666999-3139876592-500 - Administrator - Disabled) ecp (S-1-5-21-1780445102-594666999-3139876592-1000 - Administrator - Enabled) => C:\Users\ecp Gast (S-1-5-21-1780445102-594666999-3139876592-501 - Limited - Disabled) ==================== Faulty Device Manager Devices ============= Name: Microsoft-Teredo-Tunneling-Adapter Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (03/26/2015 09:14:23 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/24/2015 07:07:08 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 36.0.4.5557, Zeitstempel: 0x550d0883 Name des fehlerhaften Moduls: mozalloc.dll, Version: 36.0.4.5557, Zeitstempel: 0x550cfa82 Ausnahmecode: 0x80000003 Fehleroffset: 0x00001e02 ID des fehlerhaften Prozesses: 0x9bc Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Error: (03/24/2015 07:03:22 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm ProPCCleaner.exe, Version 2.5.5.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1ea4 Startzeit: 01d0665cc44c89d4 Endzeit: 21 Anwendungspfad: C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe Berichts-ID: Error: (03/24/2015 07:03:05 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm Skype.exe, Version 6.3.73.105 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: e00 Startzeit: 01d0656003d46e83 Endzeit: 235 Anwendungspfad: C:\Program Files (x86)\Skype\Phone\Skype.exe Berichts-ID: Error: (03/24/2015 07:03:01 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm ProPCCleaner.exe, Version 2.5.5.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1fec Startzeit: 01d0665a0fba5793 Endzeit: 0 Anwendungspfad: C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe Berichts-ID: Error: (03/24/2015 07:02:33 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm IEXPLORE.EXE, Version 11.0.9600.17689 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1a2c Startzeit: 01d0665af096f995 Endzeit: 28 Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Berichts-ID: Error: (03/24/2015 06:43:39 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm ProPCCleaner.exe, Version 2.5.5.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 12e0 Startzeit: 01d065607abc6214 Endzeit: 0 Anwendungspfad: C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe Berichts-ID: Error: (03/24/2015 05:41:02 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: opera.exe, Version: 28.0.1750.48, Zeitstempel: 0x55039cb1 Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7 Ausnahmecode: 0xc0000374 Fehleroffset: 0x000ce753 ID des fehlerhaften Prozesses: 0x1e50 Startzeit der fehlerhaften Anwendung: 0xopera.exe0 Pfad der fehlerhaften Anwendung: opera.exe1 Pfad des fehlerhaften Moduls: opera.exe2 Berichtskennung: opera.exe3 Error: (03/24/2015 08:27:53 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary tammgR119 service. System Error: Zugriff verweigert . Error: (03/24/2015 08:27:53 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary tammgF119 service. System Error: Zugriff verweigert . System errors: ============= Error: (03/26/2015 09:26:24 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: ) Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt. Neue Signaturversion: Vorherige Signaturversion: 1.195.92.0 Aktualisierungsquelle: %NT-AUTORITÄT59 Aktualisierungsphase: 4.7.0205.00 Quellpfad: 4.7.0205.01 Signaturtyp: %NT-AUTORITÄT602 Aktualisierungstyp: %NT-AUTORITÄT604 Benutzer: NT-AUTORITÄT\SYSTEM Aktuelle Modulversion: %NT-AUTORITÄT605 Vorherige Modulversion: %NT-AUTORITÄT606 Fehlercode: %NT-AUTORITÄT607 Fehlerbeschreibung: %NT-AUTORITÄT608 Error: (03/26/2015 09:13:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "IePlugin Services" wurde aufgrund folgenden Fehlers nicht gestartet: %%5 Error: (03/26/2015 09:12:48 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 24.03.2015 um 19:12:27 unerwartet heruntergefahren. Error: (03/24/2015 07:02:21 PM) (Source: DCOM) (EventID: 10016) (User: ecp-PC) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ecp-PCecpS-1-5-21-1780445102-594666999-3139876592-1000LocalHost (unter Verwendung von LRPC) Error: (03/24/2015 06:59:08 PM) (Source: DCOM) (EventID: 10016) (User: ecp-PC) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ecp-PCecpS-1-5-21-1780445102-594666999-3139876592-1000LocalHost (unter Verwendung von LRPC) Error: (03/24/2015 06:57:39 PM) (Source: DCOM) (EventID: 10016) (User: ecp-PC) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ecp-PCecpS-1-5-21-1780445102-594666999-3139876592-1000LocalHost (unter Verwendung von LRPC) Error: (03/24/2015 06:54:22 PM) (Source: DCOM) (EventID: 10016) (User: ecp-PC) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ecp-PCecpS-1-5-21-1780445102-594666999-3139876592-1000LocalHost (unter Verwendung von LRPC) Error: (03/24/2015 06:54:21 PM) (Source: DCOM) (EventID: 10016) (User: ecp-PC) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ecp-PCecpS-1-5-21-1780445102-594666999-3139876592-1000LocalHost (unter Verwendung von LRPC) Error: (03/24/2015 06:53:09 PM) (Source: DCOM) (EventID: 10016) (User: ecp-PC) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ecp-PCecpS-1-5-21-1780445102-594666999-3139876592-1000LocalHost (unter Verwendung von LRPC) Error: (03/24/2015 06:49:33 PM) (Source: DCOM) (EventID: 10016) (User: ecp-PC) Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ecp-PCecpS-1-5-21-1780445102-594666999-3139876592-1000LocalHost (unter Verwendung von LRPC) Microsoft Office Sessions: ========================= Error: (03/26/2015 09:14:23 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (03/24/2015 07:07:08 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: plugin-container.exe36.0.4.5557550d0883mozalloc.dll36.0.4.5557550cfa828000000300001e029bc01d0665caef4d103C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll9584298b-d250-11e4-8257-001fe2182534 Error: (03/24/2015 07:03:22 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: ProPCCleaner.exe2.5.5.01ea401d0665cc44c89d421C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe Error: (03/24/2015 07:03:05 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Skype.exe6.3.73.105e0001d0656003d46e83235C:\Program Files (x86)\Skype\Phone\Skype.exe Error: (03/24/2015 07:03:01 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: ProPCCleaner.exe2.5.5.01fec01d0665a0fba57930C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe Error: (03/24/2015 07:02:33 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: IEXPLORE.EXE11.0.9600.176891a2c01d0665af096f99528C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Error: (03/24/2015 06:43:39 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: ProPCCleaner.exe2.5.5.012e001d065607abc62140C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe Error: (03/24/2015 05:41:02 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: opera.exe28.0.1750.4855039cb1ntdll.dll6.1.7601.18247521ea8e7c0000374000ce7531e5001d06650fb07ac01C:\Program Files (x86)\Opera\28.0.1750.48\opera.exeC:\Windows\SysWOW64\ntdll.dll8e25c7b2-d244-11e4-8257-001fe2182534 Error: (03/24/2015 08:27:53 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary tammgR119 service. System Error: Zugriff verweigert Error: (03/24/2015 08:27:53 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary tammgF119 service. System Error: Zugriff verweigert ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Duo CPU T7100 @ 1.80GHz Percentage of memory in use: 46% Total physical RAM: 2006.3 MB Available physical RAM: 1077.6 MB Total Pagefile: 4012.59 MB Available Pagefile: 2453.32 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:142.65 GB) (Free:105.12 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 4557C7D5) Partition 1: (Active) - (Size=6.4 GB) - (Type=27) Partition 2: (Not Active) - (Size=142.6 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Vielen Dank für eure/deine Hilfe Gruß Hausmeister |
26.03.2015, 22:49 | #2 |
| Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen .... und hier noch das GMER-Log:
__________________Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2015-03-26 21:48:21 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-2 HITACHI_HTS542516K9SA00 rev.BBCZC3HP 149,05GB Running: Gmer-19357.exe; Driver: C:\Users\ecp\AppData\Local\Temp\ufldapow.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076871401 2 bytes JMP 75a7b21b C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076871419 2 bytes JMP 75a7b346 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076871431 2 bytes JMP 75af8ea9 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007687144a 2 bytes CALL 75a548ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768714dd 2 bytes JMP 75af87a2 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000768714f5 2 bytes JMP 75af8978 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007687150d 2 bytes JMP 75af8698 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076871525 2 bytes JMP 75af8a62 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007687153d 2 bytes JMP 75a6fca8 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076871555 2 bytes JMP 75a768ef C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007687156d 2 bytes JMP 75af8f61 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076871585 2 bytes JMP 75af8ac2 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007687159d 2 bytes JMP 75af865c C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000768715b5 2 bytes JMP 75a6fd41 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000768715cd 2 bytes JMP 75a7b2dc C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000768716b2 2 bytes JMP 75af8e24 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000768716bd 2 bytes JMP 75af85f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076871401 2 bytes JMP 75a7b21b C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076871419 2 bytes JMP 75a7b346 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076871431 2 bytes JMP 75af8ea9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007687144a 2 bytes CALL 75a548ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768714dd 2 bytes JMP 75af87a2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000768714f5 2 bytes JMP 75af8978 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007687150d 2 bytes JMP 75af8698 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076871525 2 bytes JMP 75af8a62 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007687153d 2 bytes JMP 75a6fca8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076871555 2 bytes JMP 75a768ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007687156d 2 bytes JMP 75af8f61 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076871585 2 bytes JMP 75af8ac2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007687159d 2 bytes JMP 75af865c C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000768715b5 2 bytes JMP 75a6fd41 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000768715cd 2 bytes JMP 75a7b2dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000768716b2 2 bytes JMP 75af8e24 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000768716bd 2 bytes JMP 75af85f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe[3504] C:\Windows\syswow64\kernel32.dll!SetFileCompletionNotificationModes 0000000075acb2fe 5 bytes JMP 00000001013191b0 .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076871401 2 bytes JMP 75a7b21b C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076871419 2 bytes JMP 75a7b346 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076871431 2 bytes JMP 75af8ea9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007687144a 2 bytes CALL 75a548ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768714dd 2 bytes JMP 75af87a2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000768714f5 2 bytes JMP 75af8978 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007687150d 2 bytes JMP 75af8698 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076871525 2 bytes JMP 75af8a62 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007687153d 2 bytes JMP 75a6fca8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076871555 2 bytes JMP 75a768ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007687156d 2 bytes JMP 75af8f61 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076871585 2 bytes JMP 75af8ac2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007687159d 2 bytes JMP 75af865c C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000768715b5 2 bytes JMP 75a6fd41 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000768715cd 2 bytes JMP 75a7b2dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000768716b2 2 bytes JMP 75af8e24 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000768716bd 2 bytes JMP 75af85f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076871401 2 bytes JMP 75a7b21b C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076871419 2 bytes JMP 75a7b346 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076871431 2 bytes JMP 75af8ea9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007687144a 2 bytes CALL 75a548ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768714dd 2 bytes JMP 75af87a2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000768714f5 2 bytes JMP 75af8978 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007687150d 2 bytes JMP 75af8698 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076871525 2 bytes JMP 75af8a62 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007687153d 2 bytes JMP 75a6fca8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076871555 2 bytes JMP 75a768ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007687156d 2 bytes JMP 75af8f61 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076871585 2 bytes JMP 75af8ac2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007687159d 2 bytes JMP 75af865c C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000768715b5 2 bytes JMP 75a6fd41 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000768715cd 2 bytes JMP 75a7b2dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000768716b2 2 bytes JMP 75af8e24 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000768716bd 2 bytes JMP 75af85f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe[4320] C:\Windows\syswow64\KERNEL32.dll!SetUnhandledExceptionFilter 0000000075a58791 5 bytes [33, C0, C2, 04, 00] .text C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe[4320] C:\Windows\syswow64\KERNEL32.dll!SetFileCompletionNotificationModes 0000000075acb2fe 5 bytes JMP 00000001063f91b0 .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\kernel32.dll!SetFileCompletionNotificationModes 0000000075acb2fe 5 bytes JMP 0000000101e391b0 .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076871401 2 bytes JMP 75a7b21b C:\Windows\syswow64\kernel32.dll .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076871419 2 bytes JMP 75a7b346 C:\Windows\syswow64\kernel32.dll .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076871431 2 bytes JMP 75af8ea9 C:\Windows\syswow64\kernel32.dll .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007687144a 2 bytes CALL 75a548ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768714dd 2 bytes JMP 75af87a2 C:\Windows\syswow64\kernel32.dll .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000768714f5 2 bytes JMP 75af8978 C:\Windows\syswow64\kernel32.dll .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007687150d 2 bytes JMP 75af8698 C:\Windows\syswow64\kernel32.dll .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076871525 2 bytes JMP 75af8a62 C:\Windows\syswow64\kernel32.dll .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007687153d 2 bytes JMP 75a6fca8 C:\Windows\syswow64\kernel32.dll .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076871555 2 bytes JMP 75a768ef C:\Windows\syswow64\kernel32.dll .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007687156d 2 bytes JMP 75af8f61 C:\Windows\syswow64\kernel32.dll .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076871585 2 bytes JMP 75af8ac2 C:\Windows\syswow64\kernel32.dll .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007687159d 2 bytes JMP 75af865c C:\Windows\syswow64\kernel32.dll .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000768715b5 2 bytes JMP 75a6fd41 C:\Windows\syswow64\kernel32.dll .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000768715cd 2 bytes JMP 75a7b2dc C:\Windows\syswow64\kernel32.dll .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000768716b2 2 bytes JMP 75af8e24 C:\Windows\syswow64\kernel32.dll .text C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000768716bd 2 bytes JMP 75af85f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076871401 2 bytes JMP 75a7b21b C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076871419 2 bytes JMP 75a7b346 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076871431 2 bytes JMP 75af8ea9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007687144a 2 bytes CALL 75a548ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768714dd 2 bytes JMP 75af87a2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000768714f5 2 bytes JMP 75af8978 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007687150d 2 bytes JMP 75af8698 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076871525 2 bytes JMP 75af8a62 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007687153d 2 bytes JMP 75a6fca8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076871555 2 bytes JMP 75a768ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007687156d 2 bytes JMP 75af8f61 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076871585 2 bytes JMP 75af8ac2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007687159d 2 bytes JMP 75af865c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000768715b5 2 bytes JMP 75a6fd41 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000768715cd 2 bytes JMP 75a7b2dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000768716b2 2 bytes JMP 75af8e24 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000768716bd 2 bytes JMP 75af85f1 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe[5220] C:\Windows\syswow64\kernel32.dll!SetFileCompletionNotificationModes 0000000075acb2fe 5 bytes JMP 0000000101e491b0 .text C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe[5376] C:\Windows\syswow64\kernel32.dll!SetFileCompletionNotificationModes 0000000075acb2fe 5 bytes JMP 0000000100a591b0 .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076871401 2 bytes JMP 75a7b21b C:\Windows\syswow64\kernel32.dll .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076871419 2 bytes JMP 75a7b346 C:\Windows\syswow64\kernel32.dll .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076871431 2 bytes JMP 75af8ea9 C:\Windows\syswow64\kernel32.dll .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007687144a 2 bytes CALL 75a548ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000768714dd 2 bytes JMP 75af87a2 C:\Windows\syswow64\kernel32.dll .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000768714f5 2 bytes JMP 75af8978 C:\Windows\syswow64\kernel32.dll .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007687150d 2 bytes JMP 75af8698 C:\Windows\syswow64\kernel32.dll .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076871525 2 bytes JMP 75af8a62 C:\Windows\syswow64\kernel32.dll .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007687153d 2 bytes JMP 75a6fca8 C:\Windows\syswow64\kernel32.dll .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076871555 2 bytes JMP 75a768ef C:\Windows\syswow64\kernel32.dll .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007687156d 2 bytes JMP 75af8f61 C:\Windows\syswow64\kernel32.dll .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076871585 2 bytes JMP 75af8ac2 C:\Windows\syswow64\kernel32.dll .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007687159d 2 bytes JMP 75af865c C:\Windows\syswow64\kernel32.dll .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000768715b5 2 bytes JMP 75a6fd41 C:\Windows\syswow64\kernel32.dll .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000768715cd 2 bytes JMP 75a7b2dc C:\Windows\syswow64\kernel32.dll .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000768716b2 2 bytes JMP 75af8e24 C:\Windows\syswow64\kernel32.dll .text C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000768716bd 2 bytes JMP 75af85f1 C:\Windows\syswow64\kernel32.dll ---- Threads - GMER 2.1 ---- Thread C:\Windows\system32\services.exe [496:3128] 000000000038f170 Thread C:\Windows\system32\services.exe [496:3132] 000000000038f170 Thread C:\Windows\system32\svchost.exe [788:828] 000000000090f170 Thread C:\Windows\system32\svchost.exe [788:832] 000000000090f170 Thread C:\Windows\system32\svchost.exe [468:1372] 0000000000b4f170 Thread C:\Windows\system32\svchost.exe [468:1376] 0000000000b4f170 Thread C:\Windows\System32\spoolsv.exe [1456:2856] 0000000001d3f170 Thread C:\Windows\System32\spoolsv.exe [1456:2672] 0000000001d3f170 Thread C:\Windows\SysWOW64\rundll32.exe [1616:3744] 0000000000b3c470 Thread C:\Windows\SysWOW64\rundll32.exe [1616:976] 0000000000b3c470 ---- Processes - GMER 2.1 ---- Library C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [1700] 0000000000040000 Library C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [1748] 0000000000400000 Process C:\ProgramData\SecurityUtility\Gambali.exe (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (Gambali OEM Software)(2015-0 0000000000400000 Library C:\ProgramData\SecurityUtility\GambaliCrt.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (Gambali OEM Software)( 00000000004e0000 Library C:\ProgramData\SecurityUtility\libnspr4.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (NSPR Library/Mozilla Foundation)(2015-03-20 17:48:48) 0000000072ed0000 Library C:\ProgramData\SecurityUtility\nss3.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (NSS Base Library/Mozilla Foundation)(2015-03-20 17:48:48) 0000000072de0000 Library C:\ProgramData\SecurityUtility\nssutil3.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (NSS Utility Library/Mozilla Foundation)(2015-03-20 17:48:48) 0000000072db0000 Library C:\ProgramData\SecurityUtility\libplc4.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (PLC Library/Mozilla Foundation)(2015-03-20 17:48:48) 0000000072da0000 Library C:\ProgramData\SecurityUtility\libplds4.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (PLDS Library/Mozilla Foundation)(2015-03-20 17:48:48) 0000000072d90000 Library C:\ProgramData\SecurityUtility\smime3.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (NSS S/MIME Library/Mozilla Foundation)(2015-03-20 17:48:49) 0000000072d50000 Library C:\ProgramData\SecurityUtility\freebl3.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (NSS freebl Library/Mozilla Foundation)(2015-03-20 17:48:48) 0000000072800000 Process C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe (*** suspicious ***) @ C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe [2000](2015-03-20 17:48:43) 0000000000400000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\system32\taskhost.exe [676](2015-03-15 12:40:26) 000007fef4ce0000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe [3464](2015-03-15 12:4 0000000061020000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\system32\taskeng.exe [3524](2015-03-15 12:40:26) 000007fef4ce0000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\system32\Dwm.exe [3704](2015-03-15 12:40:26) 000007fef4ce0000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\Explorer.EXE [4068](2015-03-15 12:40:26) 000007fef4ce0000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe [3504](2015-03-15 12:41:26) 0000000061020000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe [3536](2015-03-15 12:41: 0000000061020000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Program Files\Lenovo\Zoom\TpScrex.exe [2172](2015-03-15 12:41:26) 0000000061020000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Program Files\Microsoft Security Client\msseces.exe [4176](2015-03-15 12:40:26) 000007fef4ce0000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [4224](2015-03-15 000007fef4ce0000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\System32\igfxtray.exe [4232](2015-03-15 12:40:26) 000007fef4ce0000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\System32\hkcmd.exe [4244](2015-03-15 12:40:26) 000007fef4ce0000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\System32\igfxpers.exe [4252](2015-03-15 12:40:26) 000007fef4ce0000 Process C:\Users\ecp\AppData\Local\PriceFountain\pricefountainw.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\PriceFountain\pricefountainw.exe [4284] (Price Fountain)(2015-01-01 10:26:11) 0000000000400000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe [4320](2015-03-15 12:41:26) 0000000061020000 Process C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe [4608] (Price Fountain)(2015-01-01 10:26:08) 0000000000400000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe [4608](2015-03-15 12:41:26) 0000000061020000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [4644](2015-03-15 000007fef4ce0000 Process C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [4740](2015-03-22 07:52:51) 0000000001170000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [5084](2015-03-15 12:41:26) 0000000061020000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE [4336](2015- 000007fef4ce0000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Program Files (x86)\ver0CheckMeUp\CheckMeUp.exe [4772](2 0000000061020000 Process C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [4440](2015-03-22 07:52:51) 0000000001170000 Process C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [5668](2015-03-22 07:52:51) 0000000001170000 Process C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [5752](2015-03-22 07:52:51) 0000000001170000 Process C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [5816](2015-03-22 07:52:51) 0000000001170000 Process C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [5824](2015-03-22 07:52:51) 0000000001170000 Process C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [5840](2015-03-22 07:52:51) 0000000001170000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Program Files\McAfee Security Scan\3.8.150\McUicnt.exe [5152](2015-03-15 12:40:26) 000007fef4ce0000 Library C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe [5220] 00000000008a0000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzoomutil32.dll (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe [5220](2015-03-15 0000000062f20000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe [5220](2015-03-15 12:41: 0000000061020000 Library C:\ProgramData\bobyzoom\1.1.0.30\bz64.exe (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bz64.exe [4900](2015-03-15 12:40:58) 000000013f2c0000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bz64.exe [4900](2015-03-15 12:40:26 000007fef4ce0000 Library C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe [5376](2015-03-15 12:42:28) 0000000000d00000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe [5376](2015-03-15 12:41:26 0000000061020000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\System32\dinotify.exe [4508](2015-03-15 12:40:26) 000007fef4ce0000 Library C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Reinigung\Gmer-19357.exe [7296](2015-03-15 12:41:26) 0000000061020000 ---- Services - GMER 2.1 ---- Service C:\Windows\system32\Drivers\tammgF119.sys (*** hidden *** ) [SYSTEM] tammgF119 <-- ROOTKIT !!! Service C:\Windows\system32\Drivers\tammgR119.sys (*** hidden *** ) [SYSTEM] tammgR119 <-- ROOTKIT !!! ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tammgF119.sys@ Driver Reg HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tammgR119.sys@ Driver Reg HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tammgF119.sys@ Driver Reg HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tammgR119.sys@ Driver Reg HKLM\SYSTEM\CurrentControlSet\services\tammgF119@Type 2 Reg HKLM\SYSTEM\CurrentControlSet\services\tammgF119@Start 1 Reg HKLM\SYSTEM\CurrentControlSet\services\tammgF119@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\tammgF119@ImagePath \??\C:\Windows\system32\Drivers\tammgF119.sys Reg HKLM\SYSTEM\CurrentControlSet\services\tammgF119@DisplayName tammgF119 service Reg HKLM\SYSTEM\CurrentControlSet\services\tammgF119@Group FSFilter Activity Monitor Reg HKLM\SYSTEM\CurrentControlSet\services\tammgF119@DependOnService FltMgr? Reg HKLM\SYSTEM\CurrentControlSet\services\tammgF119@WOW64 1 Reg HKLM\SYSTEM\CurrentControlSet\services\tammgF119\Instances Reg HKLM\SYSTEM\CurrentControlSet\services\tammgF119\Instances@DefaultInstance tammgF119 Instance Reg HKLM\SYSTEM\CurrentControlSet\services\tammgF119\Instances\tammgF119 Instance Reg HKLM\SYSTEM\CurrentControlSet\services\tammgF119\Instances\tammgF119 Instance@Altitude 370034 Reg HKLM\SYSTEM\CurrentControlSet\services\tammgF119\Instances\tammgF119 Instance@Flags 0 Reg HKLM\SYSTEM\CurrentControlSet\services\tammgF119 Reg HKLM\SYSTEM\CurrentControlSet\services\tammgR119@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\tammgR119@Start 1 Reg HKLM\SYSTEM\CurrentControlSet\services\tammgR119@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\tammgR119@ImagePath \??\C:\Windows\system32\Drivers\tammgR119.sys Reg HKLM\SYSTEM\CurrentControlSet\services\tammgR119@DisplayName tammgR119 service Reg HKLM\SYSTEM\CurrentControlSet\services\tammgR119@WOW64 1 Reg HKLM\SYSTEM\CurrentControlSet\services\tammgR119 Reg HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\tammgF119.sys@ Driver Reg HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\tammgR119.sys@ Driver Reg HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\tammgF119.sys@ Driver Reg HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\tammgR119.sys@ Driver Reg HKLM\SYSTEM\ControlSet002\services\tammgF119@Type 2 Reg HKLM\SYSTEM\ControlSet002\services\tammgF119@Start 1 Reg HKLM\SYSTEM\ControlSet002\services\tammgF119@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\tammgF119@ImagePath \??\C:\Windows\system32\Drivers\tammgF119.sys Reg HKLM\SYSTEM\ControlSet002\services\tammgF119@DisplayName tammgF119 service Reg HKLM\SYSTEM\ControlSet002\services\tammgF119@Group FSFilter Activity Monitor Reg HKLM\SYSTEM\ControlSet002\services\tammgF119@DependOnService FltMgr? Reg HKLM\SYSTEM\ControlSet002\services\tammgF119@WOW64 1 Reg HKLM\SYSTEM\ControlSet002\services\tammgF119\Instances (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\tammgF119\Instances@DefaultInstance tammgF119 Instance Reg HKLM\SYSTEM\ControlSet002\services\tammgF119\Instances\tammgF119 Instance (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\tammgF119\Instances\tammgF119 Instance@Altitude 370034 Reg HKLM\SYSTEM\ControlSet002\services\tammgF119\Instances\tammgF119 Instance@Flags 0 Reg HKLM\SYSTEM\ControlSet002\services\tammgR119@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\tammgR119@Start 1 Reg HKLM\SYSTEM\ControlSet002\services\tammgR119@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\tammgR119@ImagePath \??\C:\Windows\system32\Drivers\tammgR119.sys Reg HKLM\SYSTEM\ControlSet002\services\tammgR119@DisplayName tammgR119 service Reg HKLM\SYSTEM\ControlSet002\services\tammgR119@WOW64 1 ---- EOF - GMER 2.1 ---- |
27.03.2015, 07:28 | #3 |
/// the machine /// TB-Ausbilder | Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen hi,
__________________Lade Dir bitte von hier Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
Scan mit Combofix
__________________ |
29.03.2015, 22:05 | #4 |
| Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen Hallo Schrauber, alle Schritte durchgeführt. Wobei ich bei der Deinstallation mit RevoUninstaller nicht alle Programme gefunden habe, die du aufgelistet hattest. Ausserdem habe ich mich (glaube ich) einmal verklickt und den Auto-Uninstaller eines Programms abgebrochen. Hier das Log von ComboFix: Code:
ATTFilter ComboFix 15-03-25.01 - ecp 29.03.2015 22:32:55.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.2006.1032 [GMT 2:00] ausgeführt von:: c:\users\ecp\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A} SP: Microsoft Security Essentials *Disabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\ddeallpeAuk c:\program files (x86)\ddeallpeAuk\83pi0tURGPEZSW.dat c:\program files (x86)\ddeallpeAuk\83pi0tURGPEZSW.dll c:\program files (x86)\ddeallpeAuk\83pi0tURGPEZSW.tlb c:\program files (x86)\ddeallpeAuk\83pi0tURGPEZSW.x64.dll c:\program files (x86)\RoyAlCeOupoen c:\program files (x86)\RoyAlCeOupoen\HqWqrhAIb9KXYi.dat c:\program files (x86)\RoyAlCeOupoen\HqWqrhAIb9KXYi.tlb c:\program files (x86)\SaleisuCheccker c:\program files (x86)\SaleisuCheccker\xpyZoe64gi8nWN.dat c:\program files (x86)\SaleisuCheccker\xpyZoe64gi8nWN.tlb c:\program files (x86)\Saveitkeaep c:\program files (x86)\Saveitkeaep\OUx1yNk71u3K2I.dat c:\program files (x86)\Saveitkeaep\OUx1yNk71u3K2I.dll c:\program files (x86)\Saveitkeaep\OUx1yNk71u3K2I.tlb c:\program files (x86)\Saveitkeaep\OUx1yNk71u3K2I.x64.dll c:\program files (x86)\SoaleEsChoeocKeirr c:\program files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.dat c:\program files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.dll c:\program files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.tlb c:\program files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.x64.dll c:\programdata\15483481001080132652 c:\programdata\15483481001080132652\095e64fbe062fb57e00f3b8912a68d76.ini c:\programdata\15483481001080132652\0e950e00e627140ee00f3b8912a68d76.ini c:\programdata\15483481001080132652\1878c1afe37a6843e00f3b8912a68d76.ini c:\programdata\15483481001080132652\5175a0130ed5b449e00f3b8912a68d76.ini c:\programdata\15483481001080132652\73ecd09576ab61e0e00f3b8912a68d76.ini c:\programdata\15483481001080132652\7b454519bbfb9c52e00f3b8912a68d76.ini c:\programdata\15483481001080132652\87b1cffeb795e9ffe00f3b8912a68d76.ini c:\programdata\15483481001080132652\88ca0666a8bc42bce00f3b8912a68d76.ini c:\programdata\15483481001080132652\d236748b2ecd3b60e00f3b8912a68d76.ini c:\programdata\15483481001080132652\d5fe86451e44dffce00f3b8912a68d76.ini c:\programdata\15483481001080132652\f5dc0d0456a8eaf3e00f3b8912a68d76.ini c:\programdata\15483481001080132652\fabe6de3a4ead422e00f3b8912a68d76.ini c:\programdata\1887373585 c:\programdata\1887373585\BITB865.tmp c:\users\ecp\AppData\Local\dsisetup1374062732.exe c:\users\ecp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Dynamo Combo_iels c:\users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\extensions\Rc1@sSvOmat.net c:\users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\extensions\Rc1@sSvOmat.net\bootstrap.js c:\users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\extensions\Rc1@sSvOmat.net\chrome.manifest c:\users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\extensions\Rc1@sSvOmat.net\content\bg.js c:\users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\extensions\Rc1@sSvOmat.net\install.rdf c:\windows\msdownld.tmp . . ((((((((((((((((((((((((((((((((((((((( Treiber/Dienste ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Service_globalUpdate . . ((((((((((((((((((((((( Dateien erstellt von 2015-02-28 bis 2015-03-29 )))))))))))))))))))))))))))))) . . 2015-03-29 20:46 . 2015-03-29 20:46 -------- d-----w- c:\users\Default\AppData\Local\temp 2015-03-27 17:46 . 2015-03-27 17:46 -------- d-----w- c:\program files (x86)\VS Revo Group 2015-03-26 21:38 . 2015-03-26 21:38 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{20B94202-BEA6-40D1-BBCA-E264E8CFB3AA}\offreg.dll 2015-03-26 21:16 . 2015-03-14 10:02 12002392 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{20B94202-BEA6-40D1-BBCA-E264E8CFB3AA}\mpengine.dll 2015-03-26 20:28 . 2015-03-26 20:33 -------- d-----w- C:\FRST 2015-03-26 20:13 . 2015-03-29 20:22 -------- d-----w- C:\Reinigung 2015-03-23 08:18 . 2015-03-23 08:19 -------- d-----w- c:\program files (x86)\Simple Dictation 2015-03-23 08:17 . 2015-03-23 08:19 -------- d-----w- c:\program files (x86)\deAli2idealit 2015-03-23 06:51 . 2015-01-29 09:07 11910896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2015-03-22 08:10 . 2015-03-22 08:10 -------- d-----w- c:\users\ecp\AppData\Local\Macromedia 2015-03-22 08:09 . 2015-03-22 08:09 -------- d-----w- c:\users\ecp\AppData\Local\Mozilla 2015-03-22 07:30 . 2015-03-22 07:30 -------- d-----w- c:\users\ecp\AppData\Local\32220c02-c108-4e43-b856-df7d87f70051 2015-03-22 06:43 . 2015-03-22 06:43 -------- d-----w- c:\program files (x86)\SystemContinue 2015-03-21 17:45 . 2015-03-21 17:45 2205072 ----a-w- c:\windows\shost.bin 2015-03-20 17:52 . 2015-03-20 17:52 -------- d-----w- c:\users\ecp\AppData\Local\Pro_PC_Cleaner 2015-03-20 17:50 . 2015-03-20 17:50 -------- d-----w- c:\program files (x86)\Pro PC Cleaner 2015-03-20 17:50 . 2015-03-20 17:50 -------- d-----w- c:\users\ecp\AppData\Roaming\Pro PC Cleaner 2015-03-20 17:49 . 2015-03-20 09:33 335768 ----a-w- c:\windows\SysWow64\Gambali.dll 2015-03-20 17:49 . 2015-03-20 09:33 398808 ----a-w- c:\windows\system32\Gambali64.dll 2015-03-20 17:47 . 2015-03-20 17:47 -------- d-----w- c:\programdata\e314b8475a214ebc973cc42fbf8c6edf 2015-03-20 17:47 . 2015-03-20 17:49 -------- d-----w- c:\programdata\SecurityUtility 2015-03-20 17:45 . 2015-03-20 17:45 -------- d-----w- c:\program files (x86)\globalUpdate 2015-03-20 17:45 . 2015-03-20 17:45 -------- d-----w- c:\users\ecp\AppData\Local\globalUpdate 2015-03-20 17:45 . 2015-03-29 20:16 2248 ----a-w- c:\windows\patsearch.bin 2015-03-20 17:45 . 2015-03-20 17:44 50800 ----a-w- c:\windows\system32\drivers\webTinstMKTN.sys 2015-03-20 17:45 . 2015-03-20 17:45 -------- d-----w- c:\program files (x86)\ver0CheckMeUp 2015-03-20 17:45 . 2015-03-20 17:47 -------- d-----w- c:\program files (x86)\HQCinema Pro 2.1V20.03 2015-03-20 06:05 . 2015-03-20 06:05 -------- d-----w- c:\users\ecp\AppData\Local\Pay-By-Ads 2015-03-11 07:17 . 2015-02-03 03:30 1202176 ----a-w- c:\windows\system32\drmv2clt.dll 2015-03-11 07:17 . 2015-02-03 03:30 842240 ----a-w- c:\windows\system32\blackbox.dll 2015-03-11 07:17 . 2015-02-03 03:12 744960 ----a-w- c:\windows\SysWow64\blackbox.dll 2015-03-11 07:17 . 2015-02-03 03:12 988160 ----a-w- c:\windows\SysWow64\drmv2clt.dll 2015-03-11 07:17 . 2015-02-03 03:31 14632960 ----a-w- c:\windows\system32\wmp.dll 2015-03-11 07:17 . 2015-02-03 03:31 782848 ----a-w- c:\windows\system32\wmdrmsdk.dll 2015-03-11 07:17 . 2015-02-03 03:12 617984 ----a-w- c:\windows\SysWow64\wmdrmsdk.dll 2015-03-11 07:17 . 2015-02-03 03:12 3209728 ----a-w- c:\windows\SysWow64\mf.dll 2015-03-11 07:17 . 2015-02-03 03:34 5554104 ----a-w- c:\windows\system32\ntoskrnl.exe 2015-03-11 07:15 . 2015-02-20 04:41 41984 ----a-w- c:\windows\system32\lpk.dll 2015-03-11 07:15 . 2015-02-20 04:40 46080 ----a-w- c:\windows\system32\atmlib.dll 2015-03-11 07:15 . 2015-02-20 03:29 372224 ----a-w- c:\windows\system32\atmfd.dll 2015-03-11 07:15 . 2015-02-20 03:09 299008 ----a-w- c:\windows\SysWow64\atmfd.dll 2015-03-11 07:14 . 2015-02-20 04:40 100864 ----a-w- c:\windows\system32\fontsub.dll 2015-03-11 07:14 . 2015-02-20 04:40 14336 ----a-w- c:\windows\system32\dciman32.dll 2015-03-11 07:14 . 2015-02-20 04:13 70656 ----a-w- c:\windows\SysWow64\fontsub.dll 2015-03-11 07:14 . 2015-02-20 04:13 10240 ----a-w- c:\windows\SysWow64\dciman32.dll 2015-03-11 07:14 . 2015-02-20 04:13 34304 ----a-w- c:\windows\SysWow64\atmlib.dll 2015-03-11 07:14 . 2015-02-20 04:12 25600 ----a-w- c:\windows\SysWow64\lpk.dll 2015-03-11 07:14 . 2015-01-31 03:48 3179520 ----a-w- c:\windows\system32\rdpcorets.dll 2015-03-11 07:14 . 2015-01-31 03:48 16384 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll 2015-03-11 07:14 . 2015-01-30 23:56 243200 ----a-w- c:\windows\system32\rdpudd.dll 2015-03-11 07:12 . 2015-01-17 02:48 1067520 ----a-w- c:\windows\system32\msctf.dll 2015-03-11 07:11 . 2015-02-20 02:50 66560 ----a-w- c:\windows\system32\iesetup.dll 2015-03-11 07:06 . 2015-02-04 03:16 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2015-03-11 07:06 . 2015-02-04 02:54 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2015-03-05 16:07 . 2015-03-05 16:07 -------- d-----w- c:\programdata\Auslogics 2015-03-05 16:06 . 2015-03-05 16:06 -------- d-----w- c:\program files (x86)\Auslogics 2015-03-05 15:57 . 2015-03-05 16:02 -------- d-----w- c:\users\ecp\AppData\Roaming\FreeFileSync 2015-03-05 15:56 . 2015-03-05 15:56 -------- d-----w- c:\program files\FreeFileSync 2015-03-05 15:56 . 2015-03-05 15:56 -------- d-----w- c:\users\ecp\AppData\Local\145842EF_stp 2015-03-05 15:28 . 2015-03-05 15:28 -------- d--h--w- c:\programdata\CanonIJScan 2015-03-05 15:28 . 2015-03-05 15:28 -------- d-----w- c:\users\ecp\AppData\Roaming\Canon 2015-03-05 07:19 . 2015-03-05 07:19 -------- d-s---w- c:\windows\system32\CompatTel 2015-03-05 07:19 . 2015-03-05 07:19 -------- d-----w- c:\windows\system32\appraiser 2015-03-05 07:19 . 2015-03-05 07:19 -------- d--h--w- c:\programdata\CanonIJFAX 2015-03-05 07:18 . 2011-09-21 04:00 302592 ----a-w- c:\windows\system32\CNCALB0.DLL 2015-03-05 07:17 . 2011-09-22 07:59 358912 ----a-w- c:\windows\system32\CNC_B0L.dll 2015-03-05 07:17 . 2011-10-14 10:57 300544 ----a-w- c:\windows\system32\CNC_B0C.dll 2015-03-05 07:17 . 2011-10-14 10:56 109568 ----a-w- c:\windows\system32\CNC_B0I.dll 2015-03-05 07:17 . 2008-08-25 17:02 17920 ----a-w- c:\windows\system32\CNHMCA6.dll 2015-03-05 07:17 . 2011-10-14 10:57 102912 ----a-w- c:\windows\SysWow64\CNC_B0U.dll 2015-03-05 07:17 . 2011-09-22 07:57 316416 ----a-w- c:\windows\SysWow64\CNC_B0L.dll 2015-03-05 07:17 . 2008-08-25 17:02 15872 ----a-w- c:\windows\SysWow64\CNHMCA.dll 2015-03-05 07:17 . 2015-03-05 07:17 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information 2015-03-05 07:16 . 2011-11-03 04:00 99840 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPPB0.DLL 2015-03-05 07:16 . 2011-11-03 04:00 30208 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPDB0.DLL 2015-03-05 07:15 . 2011-11-03 04:00 385024 ----a-w- c:\windows\system32\CNMLMB0.DLL 2015-03-05 06:28 . 2014-06-27 02:08 2777088 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2015-03-05 06:28 . 2014-06-27 01:45 2285056 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2015-03-04 06:37 . 2015-01-09 03:14 29696 ----a-w- c:\windows\system32\powertracker.dll 2015-03-04 06:37 . 2015-01-09 03:14 91136 ----a-w- c:\windows\system32\wdi.dll 2015-03-04 06:37 . 2015-01-09 03:14 950272 ----a-w- c:\windows\system32\perftrack.dll 2015-03-04 06:37 . 2015-01-09 02:48 76800 ----a-w- c:\windows\SysWow64\wdi.dll 2015-03-04 06:36 . 2015-01-27 23:36 1239720 ----a-w- c:\windows\system32\aitstatic.exe 2015-03-04 06:36 . 2015-02-04 03:16 609280 ----a-w- c:\windows\system32\generaltel.dll 2015-03-04 06:36 . 2015-02-04 03:16 762368 ----a-w- c:\windows\system32\invagent.dll 2015-03-04 06:36 . 2015-02-04 03:16 414720 ----a-w- c:\windows\system32\devinv.dll 2015-03-04 06:36 . 2015-02-04 03:16 192000 ----a-w- c:\windows\system32\aepic.dll 2015-03-04 06:36 . 2015-02-04 03:13 1098752 ----a-w- c:\windows\system32\aeinv.dll 2015-03-04 06:36 . 2015-02-04 03:16 227328 ----a-w- c:\windows\system32\aepdu.dll 2015-03-04 06:36 . 2014-08-01 11:53 1031168 ----a-w- c:\windows\system32\TSWorkspace.dll 2015-03-04 06:36 . 2014-08-01 11:35 793600 ----a-w- c:\windows\SysWow64\TSWorkspace.dll 2015-03-04 06:35 . 2014-06-24 03:29 2565120 ----a-w- c:\windows\system32\d3d10warp.dll 2015-03-04 06:35 . 2014-06-24 02:59 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll 2015-03-04 06:35 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDYAK.DLL 2015-03-04 06:35 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDTAT.DLL 2015-03-04 06:35 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDRU1.DLL 2015-03-04 06:35 . 2014-07-09 02:03 6656 ----a-w- c:\windows\system32\KBDRU.DLL 2015-03-04 06:35 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDBASH.DLL 2015-03-04 06:35 . 2014-07-09 01:31 7168 ----a-w- c:\windows\SysWow64\KBDYAK.DLL 2015-03-04 06:35 . 2014-07-09 01:31 6656 ----a-w- c:\windows\SysWow64\KBDBASH.DLL 2015-03-04 06:33 . 2014-10-14 02:13 3241984 ----a-w- c:\windows\system32\msi.dll 2015-03-04 06:33 . 2014-10-14 01:50 2363904 ----a-w- c:\windows\SysWow64\msi.dll 2015-03-04 06:31 . 2014-09-05 02:11 6584320 ----a-w- c:\windows\system32\mstscax.dll 2015-03-04 06:31 . 2014-09-05 01:52 5703168 ----a-w- c:\windows\SysWow64\mstscax.dll 2015-03-02 12:17 . 2015-03-02 12:24 -------- d-----w- c:\users\ecp\AppData\Local\Audible 2015-03-02 12:17 . 2015-03-02 12:17 255352 ----a-w- c:\windows\SysWow64\awrdscdc.ax 2015-03-02 12:16 . 2001-08-17 21:43 24576 ------w- c:\windows\SysWow64\msxml3a.dll 2015-03-02 12:16 . 2003-03-18 20:20 1060864 ------w- c:\windows\SysWow64\mfc71.dll 2015-03-02 12:16 . 2015-03-02 12:17 -------- d-----w- c:\program files (x86)\Audible . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-03-16 18:21 . 2014-07-23 09:43 778928 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2015-03-16 18:21 . 2014-07-23 09:43 142512 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2015-03-13 07:06 . 2014-07-22 15:37 122905848 ----a-w- c:\windows\system32\MRT.exe 2015-03-03 13:17 . 2010-11-21 03:27 295552 ------w- c:\windows\system32\MpSigStub.exe 2015-02-27 10:02 . 2015-01-20 08:11 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2015-02-27 10:02 . 2015-01-20 08:11 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2015-02-27 07:59 . 2015-01-05 04:08 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2015-02-26 08:36 . 2015-01-01 10:55 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2015-02-26 08:36 . 2015-01-01 10:55 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2015-02-22 19:12 . 2015-01-01 10:55 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2015-02-04 17:18 . 2015-02-04 17:19 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2015-01-28 17:26 . 2015-01-29 06:15 48792 ----a-w- c:\windows\system32\drivers\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64.sys 2015-01-25 04:44 . 2015-01-25 20:02 48792 ----a-w- c:\windows\system32\drivers\{16a92140-918d-4afb-9edb-46f22437bb10}w64.sys 2015-01-22 11:54 . 2015-01-22 22:12 48792 ----a-w- c:\windows\system32\drivers\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64.sys 2015-01-19 05:40 . 2015-01-19 18:36 48792 ----a-w- c:\windows\system32\drivers\{641e52b1-3179-43ed-8bcb-f688871e52b0}w64.sys 2015-01-16 12:38 . 2015-01-17 08:06 48792 ----a-w- c:\windows\system32\drivers\{ecd6aae4-019c-44b2-a0e5-570904275d66}w64.sys 2015-01-13 06:41 . 2015-01-13 19:33 48792 ----a-w- c:\windows\system32\drivers\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}Gw64.sys 2015-01-10 00:41 . 2015-01-10 13:37 48792 ----a-w- c:\windows\system32\drivers\{f81878fa-25e9-442d-8ada-79658b6520f2}Gw64.sys 2015-01-06 18:52 . 2015-01-07 06:22 48792 ----a-w- c:\windows\system32\drivers\{bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64.sys 2015-01-04 01:46 . 2015-01-04 19:13 48792 ----a-w- c:\windows\system32\drivers\{8d9208df-94f9-4c96-a224-97b37b0df94e}Gw64.sys 2014-12-31 19:43 . 2015-01-01 09:21 48792 ----a-w- c:\windows\system32\drivers\{ef3f84a6-599c-4148-a8eb-9aa938299b3e}Gw64.sys 2014-12-31 15:40 . 2012-07-17 13:37 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2014-12-30 14:58 . 2015-02-22 08:34 1188440 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{263C914A-5E35-4A9C-A155-3F86BB10CC63}\gapaengine.dll 2014-12-30 14:58 . 2014-12-30 14:58 1188440 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2014-12-30 04:47 . 2014-12-30 15:44 48792 ----a-w- c:\windows\system32\drivers\{228c1c19-dcaa-4969-9dee-95888fe6a45e}Gw64.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}] 2015-03-20 17:44 495616 ----a-w- c:\program files (x86)\ver0CheckMeUp\190.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2014-12-31 15:30 223432 ----a-w- c:\users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2014-12-31 15:30 223432 ----a-w- c:\users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2014-12-31 15:30 223432 ----a-w- c:\users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-03-01 18643560] "AudialsNotifier"="c:\program files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe" [2014-12-17 2410760] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-12-19 1022152] "SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2009-05-18 1314816] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.150\SSScheduler.exe [2014-4-9 332016] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "RequireSignedAppInit_DLLs"=0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 IePluginServices;IePlugin Services;c:\programdata\IePluginServices\PluginService.exe;c:\programdata\IePluginServices\PluginService.exe [x] R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys;c:\windows\SYSNATIVE\DRIVERS\CAXHWAZL.sys [x] R3 cpuz134;cpuz134;c:\users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys;c:\users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x] R3 globalUpdatem;globalUpdate Update Service (globalUpdatem);c:\program files (x86)\globalUpdate\Update\GoogleUpdate.exe;c:\program files (x86)\globalUpdate\Update\GoogleUpdate.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.150\McCHSvc.exe;c:\program files\McAfee Security Scan\3.8.150\McCHSvc.exe [x] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] S0 tammgF119;tammgF119 service;tammgF119 service [x] S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiifx64.sys;c:\windows\SYSNATIVE\DRIVERS\smiifx64.sys [x] S1 RrNetCapFilterDriver;RadioRip Filter Driver;c:\windows\system32\DRIVERS\RrNetCapFilterDriver.sys;c:\windows\SYSNATIVE\DRIVERS\RrNetCapFilterDriver.sys [x] S2 9617fb41;SystemContinue;c:\windows\system32\rundll32.exe;c:\windows\SYSNATIVE\rundll32.exe [x] S2 bobyzoom;bobyzoom;c:\programdata\bobyzoom\1.1.0.30\bzagnt.exe;c:\programdata\bobyzoom\1.1.0.30\bzagnt.exe [x] S2 bzwdg;bzwdg;c:\programdata\bobyzoom\1.1.0.30\bzwdg.exe;c:\programdata\bobyzoom\1.1.0.30\bzwdg.exe [x] S2 DiskBoss Service;DiskBoss Service;c:\program files (x86)\DiskBoss\bin\diskbsa.exe;c:\program files (x86)\DiskBoss\bin\diskbsa.exe [x] S2 Gambali;Gambali;c:\programdata\SecurityUtility\Gambali.exe;c:\programdata\SecurityUtility\Gambali.exe [x] S2 ReimageRealTimeProtector;Reimage Real Time Protector;c:\program files\Reimage\Reimage Protector\ReiGuard.exe;c:\program files\Reimage\Reimage Protector\ReiGuard.exe [x] S2 SecurityUtility Service;SecurityUtility Service;c:\programdata\SecurityUtility\SecurityUtilitySrv.exe;c:\programdata\SecurityUtility\SecurityUtilitySrv.exe [x] S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series - Adaptertreiber für Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x] S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x] . . Inhalt des "geplante Tasks" Ordners . 2015-03-27 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-23 18:21] . 2015-03-29 c:\windows\Tasks\CheckMeUp Update.job - c:\program files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe [2015-03-20 17:44] . 2015-03-18 c:\windows\Tasks\DriverDoc_UPDATES.job - c:\program files (x86)\DriverDoc\Solvusoftdd.exe [2015-02-12 18:06] . 2015-03-29 c:\windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.job - c:\program files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.exe [2015-03-20 17:46] . 2015-03-29 c:\windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.job - c:\program files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.exe [2015-03-20 17:46] . 2015-03-29 c:\windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10_user.job - c:\program files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10.exe [2015-03-20 17:45] . 2015-03-29 c:\windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.job - c:\program files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.exe [2015-03-20 17:45] . 2015-03-29 c:\windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.job - c:\program files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.exe [2015-03-20 17:47] . 2015-03-29 c:\windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5_user.job - c:\program files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.exe [2015-03-20 17:47] . 2015-03-29 c:\windows\Tasks\globalUpdateUpdateTaskMachineCore.job - c:\program files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-03-20 17:45] . 2015-03-27 c:\windows\Tasks\globalUpdateUpdateTaskMachineUA.job - c:\program files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-03-20 17:45] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}] 2015-03-20 17:44 237568 ----a-w- c:\program files (x86)\ver0CheckMeUp\190_x64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1] @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}] 2014-12-31 15:30 262344 ----a-w- c:\users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2] @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}] 2014-12-31 15:30 262344 ----a-w- c:\users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3] @="{BBACC218-34EA-4666-9D7A-C78F2274A524}" [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}] 2014-12-31 15:30 262344 ----a-w- c:\users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2015-01-30 1332296] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 165912] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 385560] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 363544] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mDefault_Search_URL = hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms} mDefault_Page_URL = about:blank mStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms} uInternet Settings,ProxyOverride = <-loopback> uInternet Settings,ProxyServer = http=127.0.0.1:49207;https=127.0.0.1:49207 TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\ FF - prefs.js: keyword.URL - . - - - - Entfernte verwaiste Registrierungseinträge - - - - . BHO-{007c182f-91dc-485e-a48f-b4ad99086949} - c:\program files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.dll BHO-{3dcc325d-9258-4278-ac06-bc06aafb8809} - c:\program files (x86)\ddeallpeAuk\83pi0tURGPEZSW.dll BHO-{f1a892aa-d8f1-4a2a-a980-430349d85d2a} - c:\program files (x86)\Saveitkeaep\OUx1yNk71u3K2I.dll BHO-{007c182f-91dc-485e-a48f-b4ad99086949} - c:\program files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.x64.dll BHO-{3dcc325d-9258-4278-ac06-bc06aafb8809} - c:\program files (x86)\ddeallpeAuk\83pi0tURGPEZSW.x64.dll BHO-{f1a892aa-d8f1-4a2a-a980-430349d85d2a} - c:\program files (x86)\Saveitkeaep\OUx1yNk71u3K2I.x64.dll WebBrowser-{4F524A2D-5350-4500-76A7-7A786E7484D7} - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-{9D8D5AD9-94C7-40B3-88F2-2B8F227F6381} - c:\programdata\bobyzoom\1.1.0.30\Uninstaller.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tammgF119] "ImagePath"="\??\c:\windows\system32\Drivers\tammgF119.sys" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tammgR119] "ImagePath"="\??\c:\windows\system32\Drivers\tammgR119.sys" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (S-1-5-21-1780445102-594666999-3139876592-1000) @Denied: (2) (LocalSystem) "Progid"="ThunderbirdEML" . [HKEY_USERS\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.16" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\windows\SysWOW64\rundll32.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files\LENOVO\HOTKEY\TPHKSVC.exe c:\program files (x86)\Dynamo Combo\updateDynamoCombo.exe c:\program files (x86)\PC Speed Maximizer\SPMSchedule.exe c:\program files (x86)\Dynamo Combo\bin\utilDynamoCombo.exe c:\program files\LENOVO\HOTKEY\tposdsvc.exe c:\program files\Lenovo\HOTKEY\TPONSCR.exe c:\program files\Lenovo\Zoom\TpScrex.exe c:\program files (x86)\ver0CheckMeUp\CheckMeUp.exe c:\programdata\bobyzoom\1.1.0.30\bz32.exe c:\programdata\bobyzoom\1.1.0.30\bzdap.exe . ************************************************************************** . Zeit der Fertigstellung: 2015-03-29 22:58:39 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2015-03-29 20:58 . Vor Suchlauf: 12 Verzeichnis(se), 112.684.433.408 Bytes frei Nach Suchlauf: 17 Verzeichnis(se), 113.349.279.744 Bytes frei . - - End Of File - - C7BC35C7B82A05D44931358E53FE5B24 A36C5E4F47E84449FF07ED3517B43A31 Gruß Hausmeister |
30.03.2015, 17:08 | #5 |
/// the machine /// TB-Ausbilder | Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.04.2015, 22:50 | #6 |
| Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen Hallo Schrauber, alles ausgeführt, hier die Logs: MBAM: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 04.04.2015 Suchlauf-Zeit: 22:27:23 Logdatei: mbam.txt Administrator: Ja Version: 2.01.4.1018 Malware Datenbank: v2015.03.09.05 Rootkit Datenbank: v2015.02.25.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: ecp Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 358184 Verstrichene Zeit: 32 Min, 30 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 7 PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe, 2584, Löschen bei Neustart, [df9a8ab91e6cc175d1a63cce9a6807f9] PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.exe, 2704, Löschen bei Neustart, [126763e03654dd59b5c295757d857090] PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.exe, 4012, Löschen bei Neustart, [c0b9f35014769b9bca1628edd63055ab] PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe, 2092, Löschen bei Neustart, [552441022961fb3bcb83d9d02bd802fe] PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\CheckMeUp.exe, 3244, Löschen bei Neustart, [6d0c67dcf496ba7c5c765740cd365da3] PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe, 4092, Löschen bei Neustart, [6d0c67dcf496ba7c5c765740cd365da3] PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\Gambali.exe, 1900, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02] Module: 9 PUP.Optional.Multiplug, C:\Program Files (x86)\SystemContinue\SystemContinue.dll, Löschen bei Neustart, [4039fc47f8920a2c6d5d73b92dd5a957], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\freebl3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\GambaliCrt.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libnspr4.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplc4.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplds4.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nss3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssutil3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\smime3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], Registrierungsschlüssel: 166 PUP.Optional.DynamoCombo.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Dynamo Combo, In Quarantäne, [df9a8ab91e6cc175d1a63cce9a6807f9], PUP.Optional.DynamoCombo.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util Dynamo Combo, In Quarantäne, [126763e03654dd59b5c295757d857090], PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, In Quarantäne, [0c6d2221107a0036e369705d649dcf31], PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, In Quarantäne, [7405cf74a6e4b6808396bec32bd6bc44], PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [72074ff42a60af876d0a163f2bd811ef], PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [72074ff42a60af876d0a163f2bd811ef], PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [72074ff42a60af876d0a163f2bd811ef], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{986c37a1-7b65-476f-80dc-54f80bd4b0d6}, In Quarantäne, [3247073c94f6ce68e4d876a1ce35e31d], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{986c37a1-7b65-476f-80dc-54f80bd4b0d6}, In Quarantäne, [3247073c94f6ce68e4d876a1ce35e31d], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{1278437a-a623-4925-a09a-001a2a616d48}, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\P1278437a_a623_4925_a09a_001a2a616d48_.P1278437a_a623_4925_a09a_001a2a616d48_, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\P1278437a_a623_4925_a09a_001a2a616d48_.P1278437a_a623_4925_a09a_001a2a616d48_.9, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P1278437a_a623_4925_a09a_001a2a616d48_.P1278437a_a623_4925_a09a_001a2a616d48_, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P1278437a_a623_4925_a09a_001a2a616d48_.P1278437a_a623_4925_a09a_001a2a616d48_.9, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P1278437a_a623_4925_a09a_001a2a616d48_.P1278437a_a623_4925_a09a_001a2a616d48_, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P1278437a_a623_4925_a09a_001a2a616d48_.P1278437a_a623_4925_a09a_001a2a616d48_.9, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{00d11864-a77a-4c9a-a436-b273b7a94da2}, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\P00d11864_a77a_4c9a_a436_b273b7a94da2_.P00d11864_a77a_4c9a_a436_b273b7a94da2_, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\P00d11864_a77a_4c9a_a436_b273b7a94da2_.P00d11864_a77a_4c9a_a436_b273b7a94da2_.9, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P00d11864_a77a_4c9a_a436_b273b7a94da2_.P00d11864_a77a_4c9a_a436_b273b7a94da2_, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P00d11864_a77a_4c9a_a436_b273b7a94da2_.P00d11864_a77a_4c9a_a436_b273b7a94da2_.9, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P00d11864_a77a_4c9a_a436_b273b7a94da2_.P00d11864_a77a_4c9a_a436_b273b7a94da2_, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P00d11864_a77a_4c9a_a436_b273b7a94da2_.P00d11864_a77a_4c9a_a436_b273b7a94da2_.9, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{54ebf294-2ffa-4467-8cad-bc8048be7f9c}, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.P54ebf294_2ffa_4467_8cad_bc8048be7f9c_, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.9, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.P54ebf294_2ffa_4467_8cad_bc8048be7f9c_, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.9, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.P54ebf294_2ffa_4467_8cad_bc8048be7f9c_, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.9, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], PUP.Optional.WebTInst.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\webTinstMKTN, In Quarantäne, [2d4cc57e583206307da0ccdc8e757e82], PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{228c1c19-dcaa-4969-9dee-95888fe6a45e}Gw64, In Quarantäne, [443575cef49637ff1950fbd1c73c51af], PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{8d9208df-94f9-4c96-a224-97b37b0df94e}Gw64, In Quarantäne, [1b5e89ba008a61d52841af1d3fc47888], PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64, In Quarantäne, [1f5a02418307fe3894d515b7bf44956b], PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}Gw64, In Quarantäne, [abcef54e7c0ed06677f2c40821e2d12f], PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{ef3f84a6-599c-4148-a8eb-9aa938299b3e}Gw64, In Quarantäne, [abcec182c0cad85e14554686fb08ec14], PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{f81878fa-25e9-442d-8ada-79658b6520f2}Gw64, In Quarantäne, [0772e162aedceb4b2b3ef9d325dec937], PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{16a92140-918d-4afb-9edb-46f22437bb10}w64, In Quarantäne, [7207dd66adddd066d4bf1d0d669f6f91], PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64, In Quarantäne, [2554fb486f1bdc5a573ca78354b17c84], PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{641e52b1-3179-43ed-8bcb-f688871e52b0}w64, In Quarantäne, [5524dc6791f9b87e553e989239cc57a9], PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64, In Quarantäne, [1e5b93b05634c571326149e146bfe11f], PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{ecd6aae4-019c-44b2-a0e5-570904275d66}w64, In Quarantäne, [3d3cfe457c0e64d2f0a31515778e43bd], PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, In Quarantäne, [cfaaa89bf49688aec95401e8fe0559a7], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\WOW6432NODE\Dynamo Combo, In Quarantäne, [64151b281f6b082ea0958f23e023e818], PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\HQCinema Pro 2.1V20.03, In Quarantäne, [d9a086bd8efc68ce543202b87c873bc5], PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\HQCinema Pro 2.1V20.03-nv-ie, In Quarantäne, [2950b58e791196a03f4742780102f60a], PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [abce98ab2f5b3afcf3e23ceec93ca060], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, In Quarantäne, [c8b1f74ccfbb181e8d10b0167e85ae52], PUP.Optional.ViView.A, HKLM\SOFTWARE\WOW6432NODE\vi-viewSoftware, In Quarantäne, [32479ca715758da95835654df310fa06], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, In Quarantäne, [631689ba8bffa096a7cfc905d52e07f9], PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\30935, In Quarantäne, [1069e063503a1026908dfdec63a035cb], PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, In Quarantäne, [b7c2dc67c3c763d30f8551dcb64f40c0], PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, In Quarantäne, [2851a49f7f0bca6c1a7b9a9330d5a35d], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, In Quarantäne, [b5c47ec51872e056425a2a9cb44f59a7], PUP.Optional.SystemContinue.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\9617fb41, In Quarantäne, [582120236f1b14228cf18b1c82816799], PUP.Optional.SecurityUtility.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SecurityUtility Service, In Quarantäne, [552441022961fb3bcb83d9d02bd802fe], PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginServices, In Quarantäne, [0c6dd66d2e5c44f2c3138635897aa35d], PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, In Quarantäne, [4a2f57ecd3b70e2807d0605b8a7928d8], PUP.Optional.CrossRider.A, HKU\S-1-5-18\SOFTWARE\HQCinema Pro 2.1V20.03-nv-ie, In Quarantäne, [b9c085bee7a34fe7ea9d407a40c3768a], PUP.Optional.Binkiland.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Binkiland Browser, In Quarantäne, [0673a79cec9ed066d340cf68f11453ad], PUP.Optional.DynamoCombo.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Dynamo Combo, In Quarantäne, [fe7bcd762a600e28e452c0f22dd6629e], PUP.Optional.CrossRider.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\HQCinema Pro 2.1V20.03, In Quarantäne, [2158d86b6f1b84b2f7902e8c9b68ea16], PUP.Optional.CrossRider.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\HQCinema Pro 2.1V20.03-nv-ie, In Quarantäne, [5326192a6d1d989e3750407aff045ea2], PUP.Optional.RocketTab.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\RocketTabInstalled, In Quarantäne, [5e1b9aa9dcae4aec2002dfe505feca36], PUP.Optional.Vosteran.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Vosteran Browser, In Quarantäne, [51287bc8d0ba58de8a75f6ba37cc9a66], PUP.Optional.InstallCore.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [8decf94a83076acce2578e67c93a669a], PUP.Optional.InstallCore.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\INSTALLCORE, In Quarantäne, [324703406e1c013536e0759626df8a76], PUP.Optional.CrossRider.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, In Quarantäne, [1b5e68dbaedc0135c1faa022ad565da3], PUP.Optional.CrossRider.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\HQ CinemaV20.03, In Quarantäne, [7aff5ce7f199bb7bf557dfd855ae3fc1], PUP.Optional.RocketTab.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\SEARCH EXTENSIONS, In Quarantäne, [a3d65fe4f09a61d5515c250c51b432ce], PUP.Optional.KeepMySearch.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000_Classes\keepmysearch, In Quarantäne, [89f0a3a02f5bac8a053011a5659e758b], PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickCtrl.10, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\globalUpdate.OneClickCtrl.10, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.Update3WebControl.4, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\globalUpdate.Update3WebControl.4, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\HQCinema Pro 2.1V20.03, In Quarantäne, [0d6ceb587d0d68ce8c8097fe2cd7ce32], PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{72C9F141-C00A-616D-EE9D-69F082519D04}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E35B177E-4F63-BC4D-20BA-4FD509C6144B}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E35B177E-4F63-BC4D-20BA-4FD509C6144B}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{E35B177E-4F63-BC4D-20BA-4FD509C6144B}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{72C9F141-C00A-616D-EE9D-69F082519D04}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{72C9F141-C00A-616D-EE9D-69F082519D04}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\CLASSES\CLSID\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\CLASSES\CLSID\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}\INPROCSERVER32, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\C441D512-F5C2-07AC-8AE0-499C197A5D55, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Dynamo Combo, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{ac225167-00fc-452d-94c5-bb93600e7d9a}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.SecurityUtility.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Gambali, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{CD6F4F21-2287-4B46-82E5-530F4739C2B7}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{17B22A43-07EE-45AC-852C-BE612516B3FF}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{376B5603-A82C-41C6-8295-FE987FAAFFC0}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4351B7B4-6877-4868-8086-5810EEF0E6BF}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{45815B84-A33A-4144-A0F5-1F8FA0FBDD5A}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5A4ADDA0-6AF3-4FD1-B449-CA4156C4005C}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5ACB2FB1-ADB6-4B3A-ACA6-B47D213453C6}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{70A68E56-76A5-4870-8445-BC19846CF6AD}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{79B39846-AAF0-448E-A69C-BD8DD17C9354}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{87CA5D07-F5A7-4A3C-B18C-52028A56A378}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8E0A9D44-E2B9-40DC-8734-8DE53E362806}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B009BABC-3F0C-4255-9C4D-00E2836CA4C6}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F3DA2DA3-22C3-46E4-A3BE-B4A13185E6B0}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F7515862-DFE9-4673-BC9E-4A091B43F2F1}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{17B22A43-07EE-45AC-852C-BE612516B3FF}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{376B5603-A82C-41C6-8295-FE987FAAFFC0}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4351B7B4-6877-4868-8086-5810EEF0E6BF}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{45815B84-A33A-4144-A0F5-1F8FA0FBDD5A}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5A4ADDA0-6AF3-4FD1-B449-CA4156C4005C}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5ACB2FB1-ADB6-4B3A-ACA6-B47D213453C6}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{70A68E56-76A5-4870-8445-BC19846CF6AD}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{79B39846-AAF0-448E-A69C-BD8DD17C9354}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{87CA5D07-F5A7-4A3C-B18C-52028A56A378}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8E0A9D44-E2B9-40DC-8734-8DE53E362806}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B009BABC-3F0C-4255-9C4D-00E2836CA4C6}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F3DA2DA3-22C3-46E4-A3BE-B4A13185E6B0}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F7515862-DFE9-4673-BC9E-4A091B43F2F1}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{17B22A43-07EE-45AC-852C-BE612516B3FF}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{376B5603-A82C-41C6-8295-FE987FAAFFC0}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{4351B7B4-6877-4868-8086-5810EEF0E6BF}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{45815B84-A33A-4144-A0F5-1F8FA0FBDD5A}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{5A4ADDA0-6AF3-4FD1-B449-CA4156C4005C}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{5ACB2FB1-ADB6-4B3A-ACA6-B47D213453C6}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{70A68E56-76A5-4870-8445-BC19846CF6AD}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{79B39846-AAF0-448E-A69C-BD8DD17C9354}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{87CA5D07-F5A7-4A3C-B18C-52028A56A378}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{8E0A9D44-E2B9-40DC-8734-8DE53E362806}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B009BABC-3F0C-4255-9C4D-00E2836CA4C6}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F3DA2DA3-22C3-46E4-A3BE-B4A13185E6B0}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F7515862-DFE9-4673-BC9E-4A091B43F2F1}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{CD6F4F21-2287-4B46-82E5-530F4739C2B7}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{CD6F4F21-2287-4B46-82E5-530F4739C2B7}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SecurityUtility Service, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], Registrierungswerte: 7 PUP.Optional.Ask.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{4F524A2D-5350-4500-76A7-7A786E7484D7}, In Quarantäne, [d9a0b093d0ba290da75b180353b033cd], PUP.Optional.Ask.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{4F524A2D-5350-4500-76A7-7A786E7484D7}, ä¨*ä½?åä??ê¶ç¡ºç?®í??, In Quarantäne, [d9a0b093d0ba290da75b180353b033cd] PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, In Quarantäne, [631689ba8bffa096a7cfc905d52e07f9] PUP.Optional.Vosteran, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\WSE_Vosteran\\, In Quarantäne, [e495d66dbccec76f0e2c3302b35227d9] PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, cor, In Quarantäne, [b5c47ec51872e056425a2a9cb44f59a7] PUP.Optional.InstallCore.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\INSTALLCORE|tb, zr2X2X1G1S1F2V1S2Q0V, In Quarantäne, [324703406e1c013536e0759626df8a76] PUP.Optional.RocketTab.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\SEARCH EXTENSIONS|RocketTab, 1, In Quarantäne, [a3d65fe4f09a61d5515c250c51b432ce] Registrierungsdaten: 2 PUP.Optional.ViView.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms}),Ersetzt,[8decf3502268bf772f30fbda18ed60a0] PUP.Optional.ViView.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms}),Ersetzt,[2a4f271c2e5ca78f9cc16a6b8e77e31d] Ordner: 25 PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, In Quarantäne, [bfba74cf1278a78ff1890f6fdf2415eb], PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [bfba74cf1278a78ff1890f6fdf2415eb], PUP.Optional.PayByAds.A, C:\Users\ecp\AppData\Local\Pay-By-Ads, In Quarantäne, [740549fae4a69b9b520100809e653ec2], PUP.Optional.PayByAds.A, C:\Users\ecp\AppData\Local\Pay-By-Ads\Yahoo! Search, In Quarantäne, [740549fae4a69b9b520100809e653ec2], PUP.Optional.PayByAds.A, C:\Users\ecp\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2, In Quarantäne, [740549fae4a69b9b520100809e653ec2], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, In Quarantäne, [8beea49f6f1bec4a9609324e31d21de3], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [8beea49f6f1bec4a9609324e31d21de3], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Download, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Install, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline\{FD96D83D-E3C2-4F6E-AE7A-36DA9A3C8148}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.PriceFountain.A, C:\Users\ecp\AppData\Roaming\PriceFountain, In Quarantäne, [e8912c175d2db2843045d5b85ca7df21], PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03, Löschen bei Neustart, [0d6ceb587d0d68ce8c8097fe2cd7ce32], PUP.Optional.Vosteran.A, C:\Users\ecp\AppData\Local\Vosteran, In Quarantäne, [c3b676cdee9c35013e874254966dce32], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp, Löschen bei Neustart, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\x64, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.LowPricesApp.A, C:\ProgramData\LowPricesApp, In Quarantäne, [493068dbeb9fcf678e0a3863e2217888], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo, Löschen bei Neustart, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin, Löschen bei Neustart, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\TEMP, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.WorldWideCoupon.A, C:\ProgramData\WorldWideCoupon, In Quarantäne, [077212315832b68059358f0d0bf86997], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], Dateien: 185 PUP.Optional.Multiplug, C:\Program Files (x86)\SystemContinue\SystemContinue.dll, Löschen bei Neustart, [4039fc47f8920a2c6d5d73b92dd5a957], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe, Löschen bei Neustart, [df9a8ab91e6cc175d1a63cce9a6807f9], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.exe, Löschen bei Neustart, [126763e03654dd59b5c295757d857090], PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.exe, Löschen bei Neustart, [c0b9f35014769b9bca1628edd63055ab], PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, In Quarantäne, [0c6d2221107a0036e369705d649dcf31], PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, In Quarantäne, [7405cf74a6e4b6808396bec32bd6bc44], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\DynamoComboBHO.dll, In Quarantäne, [3247073c94f6ce68e4d876a1ce35e31d], PUP.Optional.Multiplug, C:\ProgramData\saFerwEb\cf5LUq4nBR5ThG.x64.dll, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], PUP.Optional.Multiplug, C:\ProgramData\SmaaritCoimepare\XFAYI1dRVqhfLA.x64.dll, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], PUP.Optional.Multiplug, C:\ProgramData\woEbsauVer\IB67JLTGvVSAqw.x64.dll, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.exe, In Quarantäne, [780102412961bd79f1eff1240ef819e7], PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10.exe, In Quarantäne, [f584a69dec9e76c059877a9b59ad33cd], PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.exe, In Quarantäne, [f28770d396f44fe7fae638ddc541669a], PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.exe, In Quarantäne, [1465e261d5b59f97ab3530e5877f57a9], PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\UninstallBrw.exe, In Quarantäne, [1f5a0d36cfbbd3638b559184828451af], PUP.Optional.Gambali.A, C:\Windows\System32\GambaliOff.ini, In Quarantäne, [8bee7cc7eb9ff046998355520bf832ce], PUP.Optional.Gambali.A, C:\Windows\SysWOW64\GambaliOff.ini, In Quarantäne, [f584172c9bef280e60bc7136ad5622de], PUP.Optional.Gambali.A, C:\Windows\Temp\Gambali.log, Löschen bei Neustart, [a0d994aff892c96dd746a8ffb84b9c64], PUP.Optional.Gambali.A, C:\Windows\Temp\Gambalir.log, In Quarantäne, [a0d9ed56c2c810260915fdaa20e30df3], PUP.Optional.WebTInst.A, C:\Windows\System32\drivers\Msft_Kernel_webTinstMKTN_01009.Wdf, In Quarantäne, [9ddc182b3b4f3df91b01a701e71cb050], PUP.Optional.WebTInst.A, C:\Windows\System32\drivers\webTinstMKTN.sys, In Quarantäne, [2d4cc57e583206307da0ccdc8e757e82], PUP.Optional.Patsearch.A, C:\Windows\patsearch.bin, In Quarantäne, [a0d93c07a0ea3afc5ab55d525aa9ff01], PUP.Optional.Shost.A, C:\Windows\shost.bin, In Quarantäne, [91e83e05731703330bd8446b01029e62], PUP.Optional.CheckMeUp.A, C:\Windows\Tasks\CheckMeUp Update.job, In Quarantäne, [7affe55eff8b1b1b97ed8630c73c1de3], PUP.Optional.CheckMeUp.A, C:\Windows\System32\Tasks\CheckMeUp Update, In Quarantäne, [b9c06ad9f5950630473e2c8a699a2cd4], PUP.Optional.RocketTab.A, C:\Windows\System32\Tasks\RocketTab, In Quarantäne, [542563e02961e650c75d8d379c6731cf], PUP.Optional.RocketTab.A, C:\Windows\System32\Tasks\RocketTab Update Task, In Quarantäne, [a2d787bc266449ede242299bed16867a], PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{228c1c19-dcaa-4969-9dee-95888fe6a45e}Gw64.sys, In Quarantäne, [443575cef49637ff1950fbd1c73c51af], PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{8d9208df-94f9-4c96-a224-97b37b0df94e}Gw64.sys, In Quarantäne, [1b5e89ba008a61d52841af1d3fc47888], PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64.sys, In Quarantäne, [1f5a02418307fe3894d515b7bf44956b], PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}Gw64.sys, In Quarantäne, [abcef54e7c0ed06677f2c40821e2d12f], PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{ef3f84a6-599c-4148-a8eb-9aa938299b3e}Gw64.sys, In Quarantäne, [abcec182c0cad85e14554686fb08ec14], PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{f81878fa-25e9-442d-8ada-79658b6520f2}Gw64.sys, In Quarantäne, [0772e162aedceb4b2b3ef9d325dec937], PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6, In Quarantäne, [cbae9da6d5b5b97dbcb5ffcf07fc02fe], PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7, In Quarantäne, [bcbd57ec27636dc97af7cc027d860ef2], PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10_user, In Quarantäne, [cfaab48f08820432680996389a6911ef], PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11, In Quarantäne, [88f1d86b3d4daa8c6b06ba14b350837d], PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5, In Quarantäne, [e4950a3998f28fa7fe73eee0976c7d83], PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5_user, In Quarantäne, [95e48fb48cfe5fd77bf6319d9370f010], PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{16a92140-918d-4afb-9edb-46f22437bb10}w64.sys, In Quarantäne, [7207dd66adddd066d4bf1d0d669f6f91], PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64.sys, In Quarantäne, [2554fb486f1bdc5a573ca78354b17c84], PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{641e52b1-3179-43ed-8bcb-f688871e52b0}w64.sys, In Quarantäne, [5524dc6791f9b87e553e989239cc57a9], PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64.sys, In Quarantäne, [1e5b93b05634c571326149e146bfe11f], PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{ecd6aae4-019c-44b2-a0e5-570904275d66}w64.sys, In Quarantäne, [3d3cfe457c0e64d2f0a31515778e43bd], PUP.Optional.CrossRider.T, C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.job, In Quarantäne, [7009e75cf793191db0bda2891beabd43], PUP.Optional.CrossRider.T, C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.job, In Quarantäne, [fd7ca59e0981a393f37a71ba8283b14f], PUP.Optional.CrossRider.T, C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10_user.job, In Quarantäne, [2a4fc083632790a60c6163c8b0557789], PUP.Optional.CrossRider.T, C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.job, In Quarantäne, [c0b9fe45abdf5cdae7861e0d1fe63ec2], PUP.Optional.CrossRider.T, C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.job, In Quarantäne, [d0a9291acac0d75f105da48728ddfb05], PUP.Optional.CrossRider.T, C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5_user.job, In Quarantäne, [4a2fb093e5a55dd965087ab16b9af20e], PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, In Quarantäne, [493040035832063080fca18a7c89d729], PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, In Quarantäne, [1b5ec67d4c3e63d3c6b728037491c838], PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, In Quarantäne, [2c4d0043d9b17db97707bb702dd8b64a], PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, In Quarantäne, [2059c57eff8bdf57bcc3191253b207f9], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe, Löschen bei Neustart, [552441022961fb3bcb83d9d02bd802fe], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [8beea49f6f1bec4a9609324e31d21de3], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdate.dll, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psmachine.dll, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psuser.dll, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\bgNova.html, In Quarantäne, [0d6ceb587d0d68ce8c8097fe2cd7ce32], PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a.crx, In Quarantäne, [0d6ceb587d0d68ce8c8097fe2cd7ce32], PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\Uninstall.exe, In Quarantäne, [0d6ceb587d0d68ce8c8097fe2cd7ce32], PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\utils.exe, In Quarantäne, [0d6ceb587d0d68ce8c8097fe2cd7ce32], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\190.crx, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\190.dat, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\190.dll, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\190_x64.dll, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\190.xpi, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\CheckMeUp.exe, Löschen bei Neustart, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.dll, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe, Löschen bei Neustart, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\sqlite3.dll, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\Uninstall.exe, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\x64\TandemRunner.exe, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\x64\WdfCoInstaller01009.dll, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\x64\webinstr.inf, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\x64\webTinstMKTN.sys, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], PUP.Optional.LowPricesApp.A, C:\ProgramData\LowPricesApp\LowPricesApp.exe, In Quarantäne, [493068dbeb9fcf678e0a3863e2217888], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\ccbonclchokkgohppbnobaohohhldpap.crx, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\DynamoCombo.ico, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\DynamoComboUn.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\DynamoComboUninstall.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\updateDynamoCombo.InstallState, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\16a92140918d4afb9edb.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\16a92140918d4afb9edb46f22437bb10.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\16a92140918d4afb9edb46f22437bb1064.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\16a92140918d4afb9edb64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\228c1c19dcaa49699dee.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\228c1c19dcaa49699dee64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\3bcf4f2c0bbb4d4cbf1f.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\3bcf4f2c0bbb4d4cbf1f11bbe6d501ea.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\3bcf4f2c0bbb4d4cbf1f11bbe6d501ea64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\3bcf4f2c0bbb4d4cbf1f64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcb.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcb64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcbf688871e52b0.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcbf688871e52b064.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BrowserAdapter.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BrowserAdapter64.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.expext.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.expext.zip, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.expextdll.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.PurBrowse.zip, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.PurBrowse64.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ebd8d0c0e0224b76a1f2.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ebd8d0c0e0224b76a1f264.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\sqlite3.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.InstallState, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\915cb94bb4d84c0e83b4.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\915cb94bb4d84c0e83b461409471b1c3.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\915cb94bb4d84c0e83b461409471b1c364.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\915cb94bb4d84c0e83b464.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\bf5001a3ae7a4910925a.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\bf5001a3ae7a4910925a64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\8d9208df94f94c96a224.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\8d9208df94f94c96a22464.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{228c1c19-dcaa-4969-9dee-95888fe6a45e}64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{8d9208df-94f9-4c96-a224-97b37b0df94e}.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{8d9208df-94f9-4c96-a224-97b37b0df94e}64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{bf5001a3-ae7a-4910-925a-5060ef2c0508}.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{bf5001a3-ae7a-4910-925a-5060ef2c0508}64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{ef3f84a6-599c-4148-a8eb-9aa938299b3e}.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{ef3f84a6-599c-4148-a8eb-9aa938299b3e}64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{f81878fa-25e9-442d-8ada-79658b6520f2}.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{f81878fa-25e9-442d-8ada-79658b6520f2}64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\7za.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BOASPRT.exe.PendingOverwrite, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{228c1c19-dcaa-4969-9dee-95888fe6a45e}.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ecd6aae4019c44b2a0e5.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ecd6aae4019c44b2a0e5570904275d66.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ecd6aae4019c44b2a0e5570904275d6664.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ecd6aae4019c44b2a0e564.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ef3f84a6599c4148a8eb.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ef3f84a6599c4148a8eb64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\eula.txt, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\f81878fa25e9442d8ada.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\f81878fa25e9442d8ada64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\BrowserAdapter.7z, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BOAS.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BOAS.zip, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BOASHelper.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BOASPRT.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.BOAS.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.BrowserAdapter.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.CompatibilityChecker.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.ExpExt.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.FFUpdate.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.GCUpdate.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.OfSvc.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.OptChecker.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.PurBrowse.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.Repmon.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], PUP.Optional.WorldWideCoupon.A, C:\ProgramData\WorldWideCoupon\WorldWideCoupon.exe, In Quarantäne, [077212315832b68059358f0d0bf86997], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\freebl3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\Gambali.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\Gambali.exe, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\Gambali.tlb, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\Gambali64.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\GambaliCrt.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libnspr4.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplc4.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplds4.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nss3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssckbi.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssdbm3.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssutil3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RfndNSIS.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RgsBTMedia.exe, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RgsBTMedia.ini, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RgsBTMedia64.exe, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\smime3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\SoftConfigTest.exe, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\softokn3.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\sqlite3.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ssl3.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], Physische Sektoren: 0 (Keine schädliche Elemente gefunden) (end) und hier noch ein zweites MBAM Log-File. Ich glaube das wurde geschrieben weil der Rechner keinen Zugriff aufs Netz hat und die Software nicht aktualisiert werden konnte. zur Sicherheit füge ich es aber mal bei: MBAM 2: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Update, 04.04.2015 22:27:04, SYSTEM, ECP-PC, Manual, Failed, Unable to access update server, Update, 04.04.2015 22:27:23, SYSTEM, ECP-PC, Manual, Failed, Unable to access update server, Scan, 04.04.2015 23:03:37, SYSTEM, ECP-PC, Manual, Start: 04.04.2015 22:27:23, Dauer: 32 Minuten 30 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, "401" nicht-Malwareerkennung, Error, 04.04.2015 23:05:31, SYSTEM, ECP-PC, Protection, IsLicensed, 13, Protection, 04.04.2015 23:05:32, SYSTEM, ECP-PC, Protection, Malware Protection, Stopping, Protection, 04.04.2015 23:05:32, SYSTEM, ECP-PC, Protection, Malware Protection, Stopped, (end) AdwCleaner Code:
ATTFilter # AdwCleaner v4.200 - Bericht erstellt 04/04/2015 um 23:20:11 # Aktualisiert 29/03/2015 von Xplode # Datenbank : 2015-03-29.1 [Lokal] # Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64) # Benutzername : ecp - ECP-PC # Gestarted von : C:\Reinigung\dritteRunde\AdwCleaner_4.200.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : bobyzoom [#] Dienst Gelöscht : ReimageRealTimeProtector [#] Dienst Gelöscht : tammgF119 [#] Dienst Gelöscht : tammgR119 ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\apn Ordner Gelöscht : C:\ProgramData\Reimage Protector [/!\] Nicht Gelöscht ( Junction ) : C:\ProgramData\bobyzoom Ordner Gelöscht : C:\ProgramData\d6e05fef7be4142c Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Maximizer Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro PC Cleaner Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reimage repair Ordner Gelöscht : C:\Program Files (x86)\globalUpdate Ordner Gelöscht : C:\Program Files (x86)\PC Speed Maximizer Ordner Gelöscht : C:\Program Files (x86)\Pro PC Cleaner Ordner Gelöscht : C:\Program Files (x86)\deAli2idealit Ordner Gelöscht : C:\Program Files (x86)\LuuCkYCoupon Ordner Gelöscht : C:\Program Files (x86)\SalesMAgnet Ordner Gelöscht : C:\Program Files\Reimage Ordner Gelöscht : C:\Users\ecp\AppData\Local\globalUpdate Ordner Gelöscht : C:\Users\ecp\AppData\Local\Pro_PC_Cleaner [/!\] Nicht Gelöscht ( Junction ) : C:\Users\ecp\AppData\LocalLow\bobyzoom Ordner Gelöscht : C:\Users\ecp\AppData\Roaming\DesktopIconForAmazon Ordner Gelöscht : C:\Users\ecp\AppData\Roaming\PC Speed Maximizer Ordner Gelöscht : C:\Users\ecp\AppData\Roaming\Solvusoft Ordner Gelöscht : C:\Users\ecp\AppData\Roaming\Pro PC Cleaner Ordner Gelöscht : C:\Users\ecp\Documents\ProPCCleaner Ordner Gelöscht : C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\bbz@bobyzoom.com Datei Gelöscht : C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk Datei Gelöscht : C:\Users\Public\Desktop\Pro PC Cleaner.lnk Datei Gelöscht : C:\Windows\Reimage.ini Datei Gelöscht : C:\Windows\SysWOW64\Gambali.dll Datei Gelöscht : C:\Windows\System32\Gambali64.dll Datei Gelöscht : C:\Windows\System32\drivers\tammgf119.sys Datei Gelöscht : C:\Windows\System32\drivers\tammgr119.sys Datei Gelöscht : C:\Users\ecp\Desktop\PC Speed Maximizer.lnk Datei Gelöscht : C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\user.js ***** [ Geplante Tasks ] ***** Task Gelöscht : LaunchSignup Task Gelöscht : PC Speed Maximizer Schedule Task Gelöscht : ProPCCleaner_Start Task Gelöscht : Reimage Reminder Task Gelöscht : ReimageUpdater Task Gelöscht : RocketTab Task Gelöscht : RocketTab Update Task ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{969E3CF4-34F8-788A-EDA2-1FF1929946D9}] Schlüssel Gelöscht : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P007c182f_91dc_485e_a48f_b4ad99086949_.P007c182f_91dc_485e_a48f_b4ad99086949_ Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P007c182f_91dc_485e_a48f_b4ad99086949_.P007c182f_91dc_485e_a48f_b4ad99086949_.9 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P3dcc325d_9258_4278_ac06_bc06aafb8809_.P3dcc325d_9258_4278_ac06_bc06aafb8809_ Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P3dcc325d_9258_4278_ac06_bc06aafb8809_.P3dcc325d_9258_4278_ac06_bc06aafb8809_.9 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Pf1a892aa_d8f1_4a2a_a980_430349d85d2a_.Pf1a892aa_d8f1_4a2a_a980_430349d85d2a_ Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Pf1a892aa_d8f1_4a2a_a980_430349d85d2a_.Pf1a892aa_d8f1_4a2a_a980_430349d85d2a_.9 Schlüssel Gelöscht : HKLM\SOFTWARE\5761f2e3-af05-346d-e953-e340e50c8a7d Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007c182f-91dc-485e-a48f-b4ad99086949} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3dcc325d-9258-4278-ac06-bc06aafb8809} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{f1a892aa-d8f1-4a2a-a980-430349d85d2a} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{079E2F0F-FCA0-4163-BC82-5355B879E86E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{41F978F3-431A-4464-A789-5C0692D562FB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DD1CFE82-CC89-497D-9573-B8B1867DDA09} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{007c182f-91dc-485e-a48f-b4ad99086949} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3dcc325d-9258-4278-ac06-bc06aafb8809} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f1a892aa-d8f1-4a2a-a980-430349d85d2a} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{007c182f-91dc-485e-a48f-b4ad99086949} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dcc325d-9258-4278-ac06-bc06aafb8809} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{f1a892aa-d8f1-4a2a-a980-430349d85d2a} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{C424171E-592A-415A-9EB1-DFD6D95D3530}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{5782EC3E-14E8-402B-BAD6-7FE86EF6484D} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C4C5AF64-3082-439A-8C86-5773B579E965} Schlüssel Gelöscht : HKCU\Software\Ciuvo Schlüssel Gelöscht : HKCU\Software\GlobalUpdate Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions Schlüssel Gelöscht : HKCU\Software\nuevos-programas.com Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\Optimizer Pro Schlüssel Gelöscht : HKCU\Software\pc speed maximizer Schlüssel Gelöscht : HKCU\Software\Solvusoft Schlüssel Gelöscht : HKCU\Software\Reimage Schlüssel Gelöscht : HKCU\Software\Pro PC Cleaner Schlüssel Gelöscht : HKCU\Software\ProPCCleanerLanguage Schlüssel Gelöscht : HKCU\Software\ProPCCleanerConfig Schlüssel Gelöscht : HKCU\Software\rttasks Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\CheckMeUp Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\bobyzoom Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate Schlüssel Gelöscht : HKLM\SOFTWARE\InstalledBrowserExtensions Schlüssel Gelöscht : HKLM\SOFTWARE\Solvusoft Schlüssel Gelöscht : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Pro PC Cleaner Schlüssel Gelöscht : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Speed Maximizer_is1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C3060724-6AC7-4BEF-B516-4F6B1D90887D} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9D8D5AD9-94C7-40B3-88F2-2B8F227F6381} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Reimage Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Reimage Repair Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Features\4270603C7CA6FEB45B61F4B6D10988D7 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Products\4270603C7CA6FEB45B61F4B6D10988D7 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4270603C7CA6FEB45B61F4B6D10988D7 Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\binkiland.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\gboxapp.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\myhome.vi-view.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\vi-view.com Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\vosteran.com Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback> Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - hxxp=127.0.0.1:49207;hxxps=127.0.0.1:49207 ***** [ Internetbrowser ] ***** -\\ Internet Explorer v11.0.9600.17689 -\\ Mozilla Firefox v36.0.4 (x86 de) [jr56lqw0.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.jDHKQdNvDBH9mSIy.scode", "(function(){try{if(window.self.location.href.indexOf(\"rjgFqdkFpdY7qdUEqjk4pda4rjY\")>-1){return;}}catch(e){}try{var d=[[\"trianglecash.com\",\"acebook\[...] -\\ Opera v28.0.1750.48 ************************* AdwCleaner[R0].txt - [15708 Bytes] - [04/04/2015 23:17:18] AdwCleaner[S0].txt - [14681 Bytes] - [04/04/2015 23:20:11] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14741 Bytes] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.5.1 (04.02.2015:1) OS: Windows 7 Home Premium x64 Ran by ecp on 04.04.2015 at 23:29:19,86 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files Successfully deleted: [Task] DriverDoc_UPDATES.job ~~~ Folders Successfully deleted: [Folder] C:\ProgramData\saFerwEb Successfully deleted: [Folder] C:\ProgramData\SmaaritCoimepare Successfully deleted: [Folder] C:\ProgramData\woEbsauVer ~~~ FireFox Successfully deleted the following from C:\Users\ecp\AppData\Roaming\mozilla\firefox\profiles\jr56lqw0.default\prefs.js user_pref("extensions.jDHKQdNvDBH9mSIy.url", "hxxp://downloadusaweb.us/sync2/?q=hfZ9oenGhchEAen0rihTB6lKDzt4okmxtNtVh7n0rjkErHsHrdC8rdsHtMFHhd9FqjaHrTrEpdrEqdUMDMlGojUMAe4Uojk ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 04.04.2015 at 23:37:02,63 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Gruß Hausmeister |
04.04.2015, 22:52 | #7 |
| Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen und hier das FRST Log: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Ran by ecp (administrator) on ECP-PC on 04-04-2015 23:39:44 Running from C:\Reinigung Loaded Profiles: ecp (Available profiles: ecp) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE () C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited) C:\Program Files\Lenovo\ZOOM\TpScrex.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe () C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe (Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe () C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe () C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe () C:\ProgramData\bobyzoom\1.1.0.30\bz64.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [AudialsNotifier] => C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe [2410760 2014-12-17] () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {2D8E4D58-9FF9-4D32-B1A0-E2E493921442} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {9F48D099-769E-460F-8CAD-E870234711DA} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {A44BCBEF-651D-4A25-A802-3938D00F9BEE} URL = hxxp://q.search-simple.com/?affID=na&q={searchTerms}&r=92 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {BC78FFB8-43BE-431A-861E-C6CE3BA30EC0} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default FF NewTab: FF DefaultSearchEngine: Yahoo! Search FF Keyword.URL: FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-05] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] () FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-04] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-04] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF SearchPlugin: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\searchplugins\search-simple.xml [2015-03-22] FF Extension: Dynamo Combo 1.0.1 - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}.xpi [2015-03-22] FF HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] Chrome: ======= CHR dev: Chrome dev build detected! <======= ATTENTION CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx Opera: ======= OPR Extension: (HQCinema Pro 2.1V20.03) - C:\Users\ecp\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcjifdbedkcdkeegnoenkpiphjldpahf [2015-03-20] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) Locked "tammgF119" service could not be unlocked. <===== ATTENTION Locked "tammgR119" service could not be unlocked. <===== ATTENTION R2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation) R2 bobyzoom; C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [0 ] () <==== ATTENTION (zero size file/folder) R2 bzwdg; C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [0 ] () <==== ATTENTION (zero size file/folder) R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2014-12-11] () [File not signed] S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation) S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation) S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [49648 2015-01-15] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation) R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-12-17] (Audials AG) R5 tammgF119; C:\Windows\System32\Drivers\tammgF119.sys [26784 2015-03-20] () [File not signed] R5 tammgR119; C:\Windows\System32\Drivers\tammgR119.sys [26272 2015-03-20] () [File not signed] U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 CAXHWAZL; system32\DRIVERS\CAXHWAZL.sys [X] S3 cpuz134; \??\C:\Users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] S3 HSF_DPV; system32\DRIVERS\CAX_DPV.sys [X] S2 mdmxsdk; system32\DRIVERS\mdmxsdk.sys [X] S3 winachsf; system32\DRIVERS\CAX_CNXT.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-04 23:37 - 2015-04-04 23:37 - 00001178 _____ () C:\Users\ecp\Desktop\JRT.txt 2015-04-04 23:30 - 2015-04-04 23:30 - 00003008 _____ () C:\Windows\System32\Tasks\DriverDoc_UPDATES 2015-04-04 23:30 - 2015-04-04 23:30 - 00000274 _____ () C:\Windows\Tasks\DriverDoc_UPDATES.job 2015-04-04 23:29 - 2015-04-04 23:29 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ECP-PC-Windows-7-Home-Premium-(64-bit).dat 2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\RegBackup 2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Windows\pss 2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Solvusoft 2015-04-04 23:17 - 2015-04-04 23:20 - 00000000 ____D () C:\AdwCleaner 2015-04-04 23:16 - 2015-04-04 23:16 - 00000703 _____ () C:\Users\ecp\Desktop\Reinigung - Verknüpfung.lnk 2015-04-04 22:27 - 2015-04-04 23:13 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-04-04 22:22 - 2015-04-04 22:22 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-04-04 22:22 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-04-04 22:22 - 2015-03-17 06:15 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-04-04 22:22 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-03-29 22:28 - 2015-03-29 22:58 - 00000000 ____D () C:\Qoobox 2015-03-29 22:28 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-03-29 22:28 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-03-29 22:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2015-03-29 22:27 - 2015-03-29 22:54 - 00000000 ____D () C:\Windows\erdnt 2015-03-29 22:25 - 2015-03-27 19:41 - 05615749 ____R (Swearware) C:\Users\ecp\Desktop\ComboFix.exe 2015-03-27 19:46 - 2015-03-27 19:46 - 00001271 _____ () C:\Users\ecp\Desktop\Revo Uninstaller.lnk 2015-03-27 19:46 - 2015-03-27 19:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2015-03-26 22:28 - 2015-04-04 23:39 - 00000000 ____D () C:\FRST 2015-03-26 22:27 - 2015-03-26 22:27 - 00000000 _____ () C:\Users\ecp\defogger_reenable 2015-03-26 22:13 - 2015-04-04 23:39 - 00000000 ____D () C:\Reinigung 2015-03-23 10:18 - 2015-03-23 10:19 - 00000000 ____D () C:\Program Files (x86)\Simple Dictation 2015-03-22 10:10 - 2015-03-22 10:10 - 00000000 ____D () C:\Users\ecp\AppData\Local\Macromedia 2015-03-22 10:09 - 2015-03-22 10:09 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-03-22 10:09 - 2015-03-22 10:09 - 00001154 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-03-22 10:09 - 2015-03-22 10:09 - 00000000 ____D () C:\Users\ecp\AppData\Local\Mozilla 2015-03-22 10:08 - 2015-03-22 10:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-03-22 09:32 - 2015-03-22 09:32 - 00004020 _____ () C:\Windows\System32\Tasks\Check for Scheduled Updates 2015-03-22 09:30 - 2015-03-22 09:30 - 00000000 ____D () C:\Users\ecp\AppData\Local\32220c02-c108-4e43-b856-df7d87f70051 2015-03-22 08:43 - 2015-04-04 23:04 - 00000000 ____D () C:\Program Files (x86)\SystemContinue 2015-03-20 20:06 - 2015-04-04 22:45 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 2015-03-20 19:47 - 2015-03-20 19:47 - 00000000 ____D () C:\ProgramData\e314b8475a214ebc973cc42fbf8c6edf 2015-03-20 19:43 - 2015-03-20 19:43 - 00026784 _____ () C:\Windows\system32\Drivers\tammgF119.sys 2015-03-20 19:43 - 2015-03-20 19:43 - 00026272 _____ () C:\Windows\system32\Drivers\tammgR119.sys 2015-03-20 19:43 - 2015-03-20 19:43 - 00000000 ____D () C:\ProgramData\bobyzoom 2015-03-18 09:05 - 2015-03-18 09:06 - 00002051 _____ () C:\Users\ecp\Downloads\Henner.txt 2015-03-17 08:53 - 2015-03-16 19:43 - 01274260 _____ () C:\Users\ecp\Documents\bskundenexcel201411.xls_0.ods 2015-03-17 08:53 - 2015-03-16 19:43 - 00017886 _____ () C:\Users\ecp\Documents\TennistrainingWinterHalle201415herren55he55mitersatzregelung.xls_0.ods 2015-03-13 10:11 - 2015-03-13 10:11 - 00959266 _____ () C:\Users\ecp\Downloads\doc.zip 2015-03-13 10:02 - 2015-03-13 10:02 - 00408667 _____ () C:\Users\ecp\Downloads\odt.zip 2015-03-11 09:58 - 2015-03-11 09:59 - 00000832 _____ () C:\Users\ecp\Downloads\download.html 2015-03-11 09:17 - 2015-02-03 05:34 - 05554104 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-03-11 09:17 - 2015-02-03 05:31 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-03-11 09:17 - 2015-02-03 05:31 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2015-03-11 09:17 - 2015-02-03 05:30 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2015-03-11 09:17 - 2015-02-03 05:30 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2015-03-11 09:17 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2015-03-11 09:17 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll 2015-03-11 09:17 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll 2015-03-11 09:17 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll 2015-03-11 09:16 - 2015-02-03 05:34 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2015-03-11 09:16 - 2015-02-03 05:34 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2015-03-11 09:16 - 2015-02-03 05:33 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2015-03-11 09:16 - 2015-02-03 05:31 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-03-11 09:16 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-03-11 09:16 - 2015-02-03 05:30 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2015-03-11 09:16 - 2015-02-03 05:29 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2015-03-11 09:16 - 2015-02-03 05:28 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-03-11 09:16 - 2015-02-03 05:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2015-03-11 09:16 - 2015-02-03 05:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys 2015-03-11 09:16 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-03-11 09:16 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-03-11 09:16 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2015-03-11 09:16 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2015-03-11 09:16 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2015-03-11 09:16 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2015-03-11 09:16 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2015-03-11 09:16 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2015-03-11 09:16 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-03-11 09:16 - 2015-02-03 04:32 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2015-03-11 09:16 - 2014-11-01 00:24 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2015-03-11 09:16 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2015-03-11 09:16 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2015-03-11 09:15 - 2015-02-20 06:41 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2015-03-11 09:15 - 2015-02-20 06:40 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-03-11 09:15 - 2015-02-20 05:29 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-03-11 09:15 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2015-03-11 09:14 - 2015-02-20 06:40 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2015-03-11 09:14 - 2015-02-20 06:40 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2015-03-11 09:14 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2015-03-11 09:14 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2015-03-11 09:14 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2015-03-11 09:14 - 2015-02-20 06:12 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2015-03-11 09:14 - 2015-01-31 05:48 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2015-03-11 09:14 - 2015-01-31 05:48 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2015-03-11 09:14 - 2015-01-31 01:56 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2015-03-11 09:13 - 2015-03-06 07:56 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-03-11 09:13 - 2015-03-06 07:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-03-11 09:13 - 2015-03-06 07:42 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-03-11 09:13 - 2015-03-06 07:41 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-03-11 09:13 - 2015-03-06 07:41 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-03-11 09:13 - 2015-03-06 07:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-03-11 09:13 - 2015-03-06 07:38 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-03-11 09:13 - 2015-03-06 07:36 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-03-11 09:13 - 2015-03-06 07:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-03-11 09:13 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-03-11 09:13 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-03-11 09:13 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-03-11 09:13 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-03-11 09:13 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2015-03-11 09:13 - 2015-02-13 07:22 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2015-03-11 09:13 - 2015-02-03 05:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2015-03-11 09:13 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll 2015-03-11 09:13 - 2015-01-31 01:56 - 00459336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-03-11 09:12 - 2015-02-26 05:25 - 03204096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-03-11 09:12 - 2015-02-24 05:15 - 00389800 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-03-11 09:12 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-03-11 09:12 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-03-11 09:12 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-03-11 09:12 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-03-11 09:12 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-03-11 09:12 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-03-11 09:12 - 2015-02-20 05:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-03-11 09:12 - 2015-02-20 05:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-03-11 09:12 - 2015-02-20 04:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-03-11 09:12 - 2015-02-20 04:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-03-11 09:12 - 2015-02-20 04:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-03-11 09:12 - 2015-02-20 04:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-03-11 09:12 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-03-11 09:12 - 2015-02-20 04:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-03-11 09:12 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-03-11 09:12 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-03-11 09:12 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-03-11 09:12 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-03-11 09:12 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-03-11 09:12 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-03-11 09:12 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-03-11 09:12 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-03-11 09:12 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-03-11 09:12 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-03-11 09:12 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-03-11 09:12 - 2015-02-20 03:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-03-11 09:12 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-03-11 09:12 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-03-11 09:12 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-03-11 09:12 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-03-11 09:12 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-03-11 09:12 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-03-11 09:12 - 2015-02-03 05:31 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-03-11 09:12 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2015-03-11 09:12 - 2015-01-17 04:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2015-03-11 09:12 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2015-03-11 09:11 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-03-11 09:11 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-03-11 09:11 - 2015-02-20 04:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-03-11 09:11 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-03-11 09:11 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-03-11 09:11 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-03-11 09:11 - 2015-02-20 04:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-03-11 09:11 - 2015-02-20 04:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-03-11 09:11 - 2015-02-20 04:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-03-11 09:11 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-03-11 09:11 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-03-11 09:11 - 2015-02-20 04:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-03-11 09:11 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-03-11 09:11 - 2015-02-20 04:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-03-11 09:11 - 2015-02-20 03:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-03-11 09:11 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-03-11 09:11 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-03-11 09:11 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-03-11 09:11 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-03-11 09:11 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-03-11 09:11 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-03-11 09:11 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-03-11 09:11 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-03-11 09:06 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2015-03-11 09:06 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll 2015-03-05 18:07 - 2015-03-05 18:07 - 00000000 ____D () C:\ProgramData\Auslogics 2015-03-05 18:06 - 2015-03-05 18:06 - 00001298 _____ () C:\Users\ecp\Desktop\Auslogics Duplicate File Finder.lnk 2015-03-05 18:06 - 2015-03-05 18:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics 2015-03-05 18:06 - 2015-03-05 18:06 - 00000000 ____D () C:\Program Files (x86)\Auslogics 2015-03-05 18:05 - 2015-03-05 18:05 - 06929688 _____ (Auslogics Labs Pty Ltd ) C:\Users\ecp\Downloads\duplicate-file-finder-setup.exe 2015-03-05 17:57 - 2015-03-05 18:02 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\FreeFileSync 2015-03-05 17:56 - 2015-03-05 17:56 - 00385602 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS 2015-03-05 17:56 - 2015-03-05 17:56 - 00000951 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeFileSync.lnk 2015-03-05 17:56 - 2015-03-05 17:56 - 00000941 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealtimeSync.lnk 2015-03-05 17:56 - 2015-03-05 17:56 - 00000939 _____ () C:\Users\Public\Desktop\FreeFileSync.lnk 2015-03-05 17:56 - 2015-03-05 17:56 - 00000929 _____ () C:\Users\Public\Desktop\RealtimeSync.lnk 2015-03-05 17:56 - 2015-03-05 17:56 - 00000232 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS.part 2015-03-05 17:56 - 2015-03-05 17:56 - 00000000 ____D () C:\Users\ecp\AppData\Local\145842EF_stp 2015-03-05 17:56 - 2015-03-05 17:56 - 00000000 ____D () C:\Program Files\FreeFileSync 2015-03-05 17:55 - 2015-03-05 17:55 - 12653536 _____ (www.FreeFileSync.org ) C:\Users\ecp\Downloads\freefilesync_6.14_windows_setup.exe 2015-03-05 17:55 - 2015-03-05 17:55 - 12653536 _____ (www.FreeFileSync.org ) C:\Users\ecp\Downloads\freefilesync_6.14_windows_setup (1).exe 2015-03-05 17:28 - 2015-03-05 17:28 - 00000000 ___HD () C:\ProgramData\CanonIJScan 2015-03-05 17:28 - 2015-03-05 17:28 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Canon 2015-03-05 09:19 - 2015-03-05 09:19 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-03-05 09:19 - 2015-03-05 09:19 - 00000000 ___HD () C:\ProgramData\CanonIJFAX 2015-03-05 09:19 - 2015-03-05 09:19 - 00000000 ____D () C:\Windows\system32\appraiser 2015-03-05 09:18 - 2011-09-21 06:00 - 00302592 _____ (CANON INC.) C:\Windows\system32\CNCALB0.DLL 2015-03-05 09:17 - 2015-03-05 09:17 - 00000000 ___HD () C:\Windows\system32\CanonIJ Uninstaller Information 2015-03-05 09:17 - 2015-03-05 09:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX370 series 2015-03-05 09:17 - 2011-10-14 12:57 - 00300544 _____ (CANON INC.) C:\Windows\system32\CNC_B0C.dll 2015-03-05 09:17 - 2011-10-14 12:57 - 00102912 _____ (CANON INC.) C:\Windows\SysWOW64\CNC_B0U.dll 2015-03-05 09:17 - 2011-10-14 12:56 - 00109568 _____ (CANON INC.) C:\Windows\system32\CNC_B0I.dll 2015-03-05 09:17 - 2011-09-22 09:59 - 00358912 _____ (CANON INC.) C:\Windows\system32\CNC_B0L.dll 2015-03-05 09:17 - 2011-09-22 09:57 - 00316416 _____ (CANON INC.) C:\Windows\SysWOW64\CNC_B0L.dll 2015-03-05 09:17 - 2011-06-30 14:35 - 00065280 _____ () C:\Windows\SysWOW64\CNC1759D.TBL 2015-03-05 09:17 - 2011-06-30 14:35 - 00065280 _____ () C:\Windows\system32\CNC1759D.TBL 2015-03-05 09:17 - 2008-08-25 19:02 - 00017920 _____ (CANON INC.) C:\Windows\system32\CNHMCA6.dll 2015-03-05 09:17 - 2008-08-25 19:02 - 00015872 _____ (CANON INC.) C:\Windows\SysWOW64\CNHMCA.dll 2015-03-05 09:15 - 2011-11-03 06:00 - 00385024 _____ (CANON INC.) C:\Windows\system32\CNMLMB0.DLL 2015-03-05 08:43 - 2015-01-09 01:44 - 00419936 _____ () C:\Windows\SysWOW64\locale.nls 2015-03-05 08:43 - 2015-01-09 01:43 - 00419936 _____ () C:\Windows\system32\locale.nls 2015-03-05 08:28 - 2014-06-27 04:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2015-03-05 08:28 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-04 23:33 - 2014-11-25 12:56 - 01959715 _____ () C:\Windows\WindowsUpdate.log 2015-04-04 23:33 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-04 23:33 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-04 23:29 - 2011-04-12 09:43 - 00698926 _____ () C:\Windows\system32\perfh007.dat 2015-04-04 23:29 - 2011-04-12 09:43 - 00149034 _____ () C:\Windows\system32\perfc007.dat 2015-04-04 23:29 - 2009-07-14 07:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-04-04 23:26 - 2015-01-01 12:20 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Skype 2015-04-04 23:22 - 2010-11-21 05:47 - 00084124 _____ () C:\Windows\PFRO.log 2015-04-04 23:22 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-04-04 23:22 - 2009-07-14 06:51 - 00060122 _____ () C:\Windows\setupact.log 2015-04-04 23:08 - 2014-07-23 11:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-04-04 23:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Speech 2015-03-29 22:58 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2015-03-29 22:50 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2015-03-29 22:48 - 2009-07-14 04:34 - 61079552 _____ () C:\Windows\system32\config\SOFTWARE.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 13631488 _____ () C:\Windows\system32\config\SYSTEM.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak 2015-03-26 22:27 - 2014-12-30 16:50 - 00000000 ____D () C:\Users\ecp 2015-03-24 19:49 - 2015-01-01 15:35 - 00000000 ____D () C:\Users\ecp\Documents\112 wiederkehrende dateien 1412 2015-03-24 18:26 - 2015-01-01 13:26 - 00000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG 2015-03-24 18:22 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini 2015-03-24 09:15 - 2015-01-02 13:37 - 00040478 _____ () C:\Windows\system32\ScanResults.xml 2015-03-24 09:08 - 2015-01-02 13:32 - 00000464 _____ () C:\Windows\system32\ScannerSettings 2015-03-23 08:32 - 2015-01-02 00:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-03-22 10:09 - 2015-01-02 00:29 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Mozilla 2015-03-22 09:50 - 2014-12-31 11:40 - 00000000 ____D () C:\Users\ecp\AppData\Local\Adobe 2015-03-19 21:07 - 2014-12-30 17:38 - 00003848 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1419953902 2015-03-19 21:07 - 2014-12-30 17:37 - 00000000 ____D () C:\Program Files (x86)\Opera 2015-03-19 21:05 - 2015-02-08 13:08 - 00000000 ____D () C:\Users\ecp\Documents\Tennisclub 2015-03-18 00:27 - 2015-03-02 11:54 - 00000000 ____D () C:\Users\ecp\Documents\Martina60Geburtstag20150406 2015-03-16 20:21 - 2014-07-23 11:43 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-03-16 20:21 - 2014-07-23 11:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-03-16 20:21 - 2014-07-23 11:43 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-03-16 13:57 - 2015-02-08 13:09 - 00000000 ____D () C:\Users\ecp\Documents\Privates 2015-03-13 09:40 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2015-03-13 09:35 - 2009-07-14 06:45 - 00298232 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-03-13 09:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2015-03-13 09:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism 2015-03-13 09:15 - 2014-07-22 17:37 - 00000000 ____D () C:\Windows\system32\MRT 2015-03-13 09:06 - 2014-07-22 17:37 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-03-11 22:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2015-03-11 09:00 - 2015-01-06 12:05 - 00000000 ____D () C:\Program Files (x86)\GTS 2015-03-09 19:16 - 2015-02-08 13:09 - 00000000 ____D () C:\Users\ecp\Documents\NBV 2015-03-09 12:13 - 2015-02-16 19:42 - 00000000 ____D () C:\Users\ecp\Documents\Camera 2015-03-05 09:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing 2015-03-05 09:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat 2015-03-05 09:18 - 2009-07-14 05:20 - 00000000 __RSD () C:\Windows\Media ==================== Files in the root of some directories ======= 2015-02-04 19:15 - 2015-03-04 10:17 - 0001874 _____ () C:\Users\ecp\AppData\Roaming\MyMicroBalanceConfig.ini 2015-01-01 13:26 - 2015-03-24 18:26 - 0000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG 2015-03-05 17:56 - 2015-03-05 17:56 - 0385602 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS 2015-03-05 17:56 - 2015-03-05 17:56 - 0000232 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS.part 2015-01-03 02:27 - 2015-03-01 11:48 - 0000010 _____ () C:\Users\ecp\AppData\Local\DSI.DAT Some content of TEMP: ==================== C:\Users\ecp\AppData\Local\Temp\Quarantine.exe C:\Users\ecp\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-11 19:40 ==================== End Of Log ============================ |
05.04.2015, 13:09 | #8 |
/// the machine /// TB-Ausbilder | Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-MeldungenESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.04.2015, 21:06 | #9 |
| Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen Hallo Schrauber, auf den ersten kurzen Blick, sieht's gut aus. Hier die Log's: ESET: Code:
ATTFilter ESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: Can not open internet# product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=92942c69ec6da34699ce507475401de9 # engine=23268 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-04-07 07:41:01 # local_time=2015-04-07 09:41:01 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Microsoft Security Essentials' # compatibility_mode=5895 16777213 100 100 4803045 51419655 0 0 # scanned=143102 # found=31 # cleaned=0 # scan_time=7644 sh=9776ABD023F32FA294649DACBB4C3B03A06D338B ft=1 fh=e67507526245a101 vn="Variante von Win32/ReImageRepair.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Reimage\Reimage Repair\LanguageSelect.exe.vir" sh=22ECD449555340E5819AA967396703E21A023725 ft=1 fh=4a37b67564886534 vn="Variante von Win32/ReImageRepair.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Reimage\Reimage Repair\ReimageRepair.exe.vir" sh=FCF577CE410A72FFC34D688E419673B9E6C1EA54 ft=1 fh=5e7dc4dd398e10f6 vn="Variante von Win32/AdWare.SpeedingUpMyPC.S Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\PC Speed Maximizer\PCSpeedMaximizer.exe.vir" sh=C53BA75319D3B04C6038FDA254602EE923336C83 ft=1 fh=489be472cf683e79 vn="Variante von MSIL/Rebrand.LittleRegClean.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Pro PC Cleaner\Helper.dll.vir" sh=E19E7C0C67095FC1785E27A24FA1D1D1ACF475A2 ft=1 fh=3b7a18a4c46967c7 vn="Variante von MSIL/Rebrand.LittleRegClean.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe.vir" sh=D843B61EA88F2C2EA53AE43F11CB5B0367BB3C4B ft=1 fh=a0c68fca525ad6d4 vn="Variante von MSIL/Rebrand.LittleRegClean.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Pro PC Cleaner\Uninst000.CA.dll.vir" sh=C53BA75319D3B04C6038FDA254602EE923336C83 ft=1 fh=489be472cf683e79 vn="Variante von MSIL/Rebrand.LittleRegClean.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\ecp\AppData\Roaming\Pro PC Cleaner\Pro PC Cleaner 2.5.5\install\D90887D\Helper.dll.vir" sh=E19E7C0C67095FC1785E27A24FA1D1D1ACF475A2 ft=1 fh=3b7a18a4c46967c7 vn="Variante von MSIL/Rebrand.LittleRegClean.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\ecp\AppData\Roaming\Pro PC Cleaner\Pro PC Cleaner 2.5.5\install\D90887D\ProPCCleaner.exe.vir" sh=D843B61EA88F2C2EA53AE43F11CB5B0367BB3C4B ft=1 fh=a0c68fca525ad6d4 vn="Variante von MSIL/Rebrand.LittleRegClean.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\ecp\AppData\Roaming\Pro PC Cleaner\Pro PC Cleaner 2.5.5\install\D90887D\Uninst000.CA.dll.vir" sh=3F623FE0765DBE35AFB81F756EB3BD10CABA33CD ft=1 fh=11c9bfb384d8c8cc vn="Variante von Win32/Systweak.H evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\DriverDoc\Solvusoftdd.exe" sh=F00161BCB1F9D847C3A9EA502BC32F2CA9D6B08B ft=1 fh=c71c001125519aae vn="Variante von Win32/Adware.MultiPlug.FL Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\ddeallpeAuk\83pi0tURGPEZSW.dll.vir" sh=03D1B31F6C684652CEA2295012ECBE0188DC1BD7 ft=1 fh=cecc82c612b87102 vn="Variante von Win64/Adware.MultiPlug.G Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\ddeallpeAuk\83pi0tURGPEZSW.x64.dll.vir" sh=D1E48307906270C02BB06DFE4EF57272CDABD863 ft=1 fh=c71c0011688eab1a vn="Variante von Win32/Adware.MultiPlug.FL Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\Saveitkeaep\OUx1yNk71u3K2I.dll.vir" sh=079C296D746516934BA78D7727513D5833D3648D ft=1 fh=cecc82c60dc57089 vn="Variante von Win64/Adware.MultiPlug.G Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\Saveitkeaep\OUx1yNk71u3K2I.x64.dll.vir" sh=2835D716C7EF345CC975AF422DD294D71339F17E ft=1 fh=c71c0011645a00f9 vn="Variante von Win32/Adware.MultiPlug.FL Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.dll.vir" sh=911857E970A56D2B74E8998C005FE78C82BC7FB1 ft=1 fh=cecc82c6f132d637 vn="Variante von Win64/Adware.MultiPlug.G Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.x64.dll.vir" sh=3C2602FD6A84F062471A39CA77BE907203267D2F ft=1 fh=c71c0011c0508110 vn="Variante von Win32/SProtector.P evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\1887373585\BITB865.tmp.vir" sh=6408D61C9809E743126596AF762ABA61C67626F2 ft=1 fh=11b2d7f1750c67b8 vn="Win32/Adware.DsiLoad.A Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\ecp\AppData\Local\dsisetup1374062732.exe.vir" sh=334A2EAAB05C2F93FE080247FC8E7E3630B3D4EE ft=1 fh=c5a015ee52b21e12 vn="Variante von Win32/Adware.AddLyrics.DX Anwendung" ac=I fn="C:\Users\ecp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1U8J5FUQ\3333-6051_CheckMeUp[1].exe" sh=A2E11E8244547DB71255DA4E8FDD6EF03EA1BEFA ft=1 fh=0f69dedb8ec7e46a vn="Variante von Win32/TrojanDropper.Addrop.A Trojaner" ac=I fn="C:\Users\ecp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1U8J5FUQ\setup[1].exe" sh=F3F8CBDD982D2C88F3FA1BB224BBABCF1762671A ft=1 fh=2993682ffbda0bfc vn="Variante von Win32/OutBrowse.AZ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3FZGGY9P\SPGeneric_2711[1].exe" sh=1EA4BC9F2923CFE96237E21C95926160E6632C82 ft=1 fh=e47e93cd69f96f1a vn="Variante von Win32/Adware.PicColor.Z Anwendung" ac=I fn="C:\Users\ecp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5WJJVJO\SUChecker[1].exe" sh=E229581816FACD3C49C62076D5B3B75A962541CC ft=1 fh=5e608d1f4294683e vn="Variante von Win32/SoftPulse.S evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\SW37FAT3\Player Setup[1].exe" sh=624AD9BD15C70FD83A62D7B2C38082BD907F5541 ft=0 fh=0000000000000000 vn="JS/TrojanDownloader.Iframe.NKE Trojaner" ac=I fn="C:\Users\ecp\AppData\Local\Mozilla\Firefox\Profiles\jr56lqw0.default\cache2\entries\3409AE3C6DBC75676F8231C97E8190B8A6F10DD6" sh=E12AEBE0494D17494B59B058C14D793D22BBAC0D ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcjifdbedkcdkeegnoenkpiphjldpahf\1.26.36_0\extensionData\plugins\91.js" sh=7BD80FF13EC07828520C12E63C392CE0D50CD047 ft=1 fh=de54c131acd09d5f vn="Variante von Win32/InstallCore.UF evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\Downloads\EF_Duplicate_Files_Manager_7.10_CB-DL-Manager.exe" sh=9AA13F99E1BA7E0009D469E6344CAF1D81D1DB5E ft=1 fh=679f9d6e01d5f029 vn="Win32/FusionCore.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\Downloads\freefilesync_6.14_windows_setup (1).exe" sh=9AA13F99E1BA7E0009D469E6344CAF1D81D1DB5E ft=1 fh=679f9d6e01d5f029 vn="Win32/FusionCore.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\Downloads\freefilesync_6.14_windows_setup.exe" sh=AEE0B5F1AE8564D7E4CCD032EDF7AD88339BFF4E ft=1 fh=88c3bdc65b0afccf vn="Variante von Win32/Systweak.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\Downloads\HP_(Hewlett_Packard)_Deskjet_970cxi_Treiber_Update_10-2014.exe" sh=1C5CCF6D5160EFE16B13DA0807F8F4DEC47579A7 ft=1 fh=382583589961532b vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\Downloads\OpenOffice - CHIP-Installer (1).exe" sh=AFA265189B1C24E7BCF0DA0368A244DB25F3FBC2 ft=1 fh=483f7b57349533cc vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\Downloads\OpenOffice - CHIP-Installer.exe" Code:
ATTFilter Results of screen317's Security Check version 0.99.99 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials (On Access scanning disabled!) Error obtaining update status for antivirus! `````````Anti-malware/Other Utilities Check:````````` Java 8 Update 31 Java version 32-bit out of Date! Adobe Flash Player 16.0.0.305 Flash Player out of Date! Adobe Reader XI Mozilla Firefox (36.0.4) Mozilla Thunderbird (31.4.0) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Ran by ecp (administrator) on ECP-PC on 07-04-2015 21:54:57 Running from C:\Reinigung Loaded Profiles: ecp (Available profiles: ecp) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE () C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe () C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe (Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited) C:\Program Files\Lenovo\ZOOM\TpScrex.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe () C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\ProgramData\bobyzoom\1.1.0.30\bz64.exe () C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe () C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [AudialsNotifier] => C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe [2410760 2014-12-17] () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {2D8E4D58-9FF9-4D32-B1A0-E2E493921442} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {9F48D099-769E-460F-8CAD-E870234711DA} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {A44BCBEF-651D-4A25-A802-3938D00F9BEE} URL = hxxp://q.search-simple.com/?affID=na&q={searchTerms}&r=92 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {BC78FFB8-43BE-431A-861E-C6CE3BA30EC0} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default FF NewTab: FF DefaultSearchEngine: Yahoo! Search FF Keyword.URL: FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-05] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] () FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-04] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-04] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF SearchPlugin: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\searchplugins\search-simple.xml [2015-03-22] FF Extension: BobyZoom - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\bbz@bobyzoom.com [2015-04-07] FF Extension: Dynamo Combo 1.0.1 - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}.xpi [2015-03-22] FF HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] Chrome: ======= CHR dev: Chrome dev build detected! <======= ATTENTION CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx Opera: ======= OPR Extension: (HQCinema Pro 2.1V20.03) - C:\Users\ecp\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcjifdbedkcdkeegnoenkpiphjldpahf [2015-03-20] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) Locked "tammgF119" service could not be unlocked. <===== ATTENTION Locked "tammgR119" service could not be unlocked. <===== ATTENTION R2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation) R2 bobyzoom; C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [0 ] () <==== ATTENTION (zero size file/folder) R2 bzwdg; C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [0 ] () <==== ATTENTION (zero size file/folder) R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2014-12-11] () [File not signed] S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation) S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation) S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [49648 2015-01-15] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation) R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-12-17] (Audials AG) R5 tammgF119; C:\Windows\System32\Drivers\tammgF119.sys [26784 2015-03-20] () [File not signed] R5 tammgR119; C:\Windows\System32\Drivers\tammgR119.sys [26272 2015-03-20] () [File not signed] U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 CAXHWAZL; system32\DRIVERS\CAXHWAZL.sys [X] S3 cpuz134; \??\C:\Users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] S3 HSF_DPV; system32\DRIVERS\CAX_DPV.sys [X] S2 mdmxsdk; system32\DRIVERS\mdmxsdk.sys [X] S3 winachsf; system32\DRIVERS\CAX_CNXT.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-04 23:37 - 2015-04-04 23:37 - 00001178 _____ () C:\Users\ecp\Desktop\JRT.txt 2015-04-04 23:30 - 2015-04-04 23:46 - 00000274 _____ () C:\Windows\Tasks\DriverDoc_UPDATES.job 2015-04-04 23:30 - 2015-04-04 23:30 - 00003008 _____ () C:\Windows\System32\Tasks\DriverDoc_UPDATES 2015-04-04 23:29 - 2015-04-04 23:29 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ECP-PC-Windows-7-Home-Premium-(64-bit).dat 2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\RegBackup 2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Windows\pss 2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Solvusoft 2015-04-04 23:17 - 2015-04-04 23:20 - 00000000 ____D () C:\AdwCleaner 2015-04-04 23:16 - 2015-04-04 23:16 - 00000703 _____ () C:\Users\ecp\Desktop\Reinigung - Verknüpfung.lnk 2015-04-04 22:27 - 2015-04-04 23:13 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-04-04 22:22 - 2015-04-04 22:22 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-04-04 22:22 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-04-04 22:22 - 2015-03-17 06:15 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-04-04 22:22 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-03-29 22:28 - 2015-03-29 22:58 - 00000000 ____D () C:\Qoobox 2015-03-29 22:28 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-03-29 22:28 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-03-29 22:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2015-03-29 22:27 - 2015-03-29 22:54 - 00000000 ____D () C:\Windows\erdnt 2015-03-29 22:25 - 2015-03-27 19:41 - 05615749 ____R (Swearware) C:\Users\ecp\Desktop\ComboFix.exe 2015-03-27 19:46 - 2015-03-27 19:46 - 00001271 _____ () C:\Users\ecp\Desktop\Revo Uninstaller.lnk 2015-03-27 19:46 - 2015-03-27 19:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2015-03-26 22:28 - 2015-04-07 21:55 - 00000000 ____D () C:\FRST 2015-03-26 22:27 - 2015-03-26 22:27 - 00000000 _____ () C:\Users\ecp\defogger_reenable 2015-03-26 22:13 - 2015-04-07 21:54 - 00000000 ____D () C:\Reinigung 2015-03-23 10:18 - 2015-03-23 10:19 - 00000000 ____D () C:\Program Files (x86)\Simple Dictation 2015-03-22 10:10 - 2015-03-22 10:10 - 00000000 ____D () C:\Users\ecp\AppData\Local\Macromedia 2015-03-22 10:09 - 2015-03-22 10:09 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-03-22 10:09 - 2015-03-22 10:09 - 00001154 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-03-22 10:09 - 2015-03-22 10:09 - 00000000 ____D () C:\Users\ecp\AppData\Local\Mozilla 2015-03-22 10:08 - 2015-03-22 10:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-03-22 09:32 - 2015-03-22 09:32 - 00004020 _____ () C:\Windows\System32\Tasks\Check for Scheduled Updates 2015-03-22 09:30 - 2015-03-22 09:30 - 00000000 ____D () C:\Users\ecp\AppData\Local\32220c02-c108-4e43-b856-df7d87f70051 2015-03-22 08:43 - 2015-04-04 23:04 - 00000000 ____D () C:\Program Files (x86)\SystemContinue 2015-03-20 20:06 - 2015-04-04 22:45 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 2015-03-20 19:47 - 2015-03-20 19:47 - 00000000 ____D () C:\ProgramData\e314b8475a214ebc973cc42fbf8c6edf 2015-03-20 19:43 - 2015-03-20 19:43 - 00026784 _____ () C:\Windows\system32\Drivers\tammgF119.sys 2015-03-20 19:43 - 2015-03-20 19:43 - 00026272 _____ () C:\Windows\system32\Drivers\tammgR119.sys 2015-03-20 19:43 - 2015-03-20 19:43 - 00000000 ____D () C:\ProgramData\bobyzoom 2015-03-18 09:05 - 2015-03-18 09:06 - 00002051 _____ () C:\Users\ecp\Downloads\Henner.txt 2015-03-17 08:53 - 2015-03-16 19:43 - 01274260 _____ () C:\Users\ecp\Documents\bskundenexcel201411.xls_0.ods 2015-03-17 08:53 - 2015-03-16 19:43 - 00017886 _____ () C:\Users\ecp\Documents\TennistrainingWinterHalle201415herren55he55mitersatzregelung.xls_0.ods 2015-03-13 10:11 - 2015-03-13 10:11 - 00959266 _____ () C:\Users\ecp\Downloads\doc.zip 2015-03-13 10:02 - 2015-03-13 10:02 - 00408667 _____ () C:\Users\ecp\Downloads\odt.zip 2015-03-11 09:58 - 2015-03-11 09:59 - 00000832 _____ () C:\Users\ecp\Downloads\download.html 2015-03-11 09:17 - 2015-02-03 05:34 - 05554104 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-03-11 09:17 - 2015-02-03 05:31 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2015-03-11 09:17 - 2015-02-03 05:31 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2015-03-11 09:17 - 2015-02-03 05:30 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2015-03-11 09:17 - 2015-02-03 05:30 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2015-03-11 09:17 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2015-03-11 09:17 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll 2015-03-11 09:17 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll 2015-03-11 09:17 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll 2015-03-11 09:16 - 2015-02-03 05:34 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2015-03-11 09:16 - 2015-02-03 05:34 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys 2015-03-11 09:16 - 2015-02-03 05:33 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2015-03-11 09:16 - 2015-02-03 05:31 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2015-03-11 09:16 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2015-03-11 09:16 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2015-03-11 09:16 - 2015-02-03 05:30 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2015-03-11 09:16 - 2015-02-03 05:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe 2015-03-11 09:16 - 2015-02-03 05:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2015-03-11 09:16 - 2015-02-03 05:29 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2015-03-11 09:16 - 2015-02-03 05:28 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-03-11 09:16 - 2015-02-03 05:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2015-03-11 09:16 - 2015-02-03 05:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys 2015-03-11 09:16 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-03-11 09:16 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-03-11 09:16 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2015-03-11 09:16 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2015-03-11 09:16 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2015-03-11 09:16 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2015-03-11 09:16 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2015-03-11 09:16 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2015-03-11 09:16 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2015-03-11 09:16 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-03-11 09:16 - 2015-02-03 04:32 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2015-03-11 09:16 - 2014-11-01 00:24 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2015-03-11 09:16 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2015-03-11 09:16 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2015-03-11 09:15 - 2015-02-20 06:41 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2015-03-11 09:15 - 2015-02-20 06:40 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2015-03-11 09:15 - 2015-02-20 05:29 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2015-03-11 09:15 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2015-03-11 09:14 - 2015-02-20 06:40 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2015-03-11 09:14 - 2015-02-20 06:40 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2015-03-11 09:14 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2015-03-11 09:14 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2015-03-11 09:14 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2015-03-11 09:14 - 2015-02-20 06:12 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2015-03-11 09:14 - 2015-01-31 05:48 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2015-03-11 09:14 - 2015-01-31 05:48 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2015-03-11 09:14 - 2015-01-31 01:56 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2015-03-11 09:13 - 2015-03-06 07:56 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-03-11 09:13 - 2015-03-06 07:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-03-11 09:13 - 2015-03-06 07:42 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-03-11 09:13 - 2015-03-06 07:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-03-11 09:13 - 2015-03-06 07:41 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-03-11 09:13 - 2015-03-06 07:41 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-03-11 09:13 - 2015-03-06 07:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-03-11 09:13 - 2015-03-06 07:38 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-03-11 09:13 - 2015-03-06 07:36 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-03-11 09:13 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-03-11 09:13 - 2015-03-06 07:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-03-11 09:13 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-03-11 09:13 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-03-11 09:13 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-03-11 09:13 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-03-11 09:13 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2015-03-11 09:13 - 2015-02-13 07:22 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2015-03-11 09:13 - 2015-02-03 05:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll 2015-03-11 09:13 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll 2015-03-11 09:13 - 2015-01-31 01:56 - 00459336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-03-11 09:12 - 2015-02-26 05:25 - 03204096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-03-11 09:12 - 2015-02-24 05:15 - 00389800 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-03-11 09:12 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-03-11 09:12 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-03-11 09:12 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-03-11 09:12 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-03-11 09:12 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-03-11 09:12 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-03-11 09:12 - 2015-02-20 05:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-03-11 09:12 - 2015-02-20 05:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-03-11 09:12 - 2015-02-20 04:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-03-11 09:12 - 2015-02-20 04:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-03-11 09:12 - 2015-02-20 04:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-03-11 09:12 - 2015-02-20 04:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-03-11 09:12 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-03-11 09:12 - 2015-02-20 04:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-03-11 09:12 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-03-11 09:12 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-03-11 09:12 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-03-11 09:12 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-03-11 09:12 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-03-11 09:12 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-03-11 09:12 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-03-11 09:12 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-03-11 09:12 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-03-11 09:12 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-03-11 09:12 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-03-11 09:12 - 2015-02-20 03:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-03-11 09:12 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-03-11 09:12 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-03-11 09:12 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-03-11 09:12 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-03-11 09:12 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-03-11 09:12 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-03-11 09:12 - 2015-02-03 05:31 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-03-11 09:12 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2015-03-11 09:12 - 2015-01-17 04:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2015-03-11 09:12 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2015-03-11 09:11 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-03-11 09:11 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-03-11 09:11 - 2015-02-20 04:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-03-11 09:11 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-03-11 09:11 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-03-11 09:11 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-03-11 09:11 - 2015-02-20 04:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-03-11 09:11 - 2015-02-20 04:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-03-11 09:11 - 2015-02-20 04:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-03-11 09:11 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-03-11 09:11 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-03-11 09:11 - 2015-02-20 04:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-03-11 09:11 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-03-11 09:11 - 2015-02-20 04:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-03-11 09:11 - 2015-02-20 03:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-03-11 09:11 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-03-11 09:11 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-03-11 09:11 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-03-11 09:11 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-03-11 09:11 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-03-11 09:11 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-03-11 09:11 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-03-11 09:11 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-03-11 09:06 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2015-03-11 09:06 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-07 21:22 - 2014-11-25 12:56 - 02079730 _____ () C:\Windows\WindowsUpdate.log 2015-04-07 21:08 - 2014-07-23 11:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-04-07 19:35 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-07 19:35 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-07 19:28 - 2011-04-12 09:43 - 00698926 _____ () C:\Windows\system32\perfh007.dat 2015-04-07 19:28 - 2011-04-12 09:43 - 00149034 _____ () C:\Windows\system32\perfc007.dat 2015-04-07 19:28 - 2009-07-14 07:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-04-07 19:22 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-04-07 19:22 - 2009-07-14 06:51 - 00060234 _____ () C:\Windows\setupact.log 2015-04-04 23:26 - 2015-01-01 12:20 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Skype 2015-04-04 23:22 - 2010-11-21 05:47 - 00084124 _____ () C:\Windows\PFRO.log 2015-04-04 23:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Speech 2015-03-29 22:58 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2015-03-29 22:50 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2015-03-29 22:48 - 2009-07-14 04:34 - 61079552 _____ () C:\Windows\system32\config\SOFTWARE.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 13631488 _____ () C:\Windows\system32\config\SYSTEM.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak 2015-03-26 22:27 - 2014-12-30 16:50 - 00000000 ____D () C:\Users\ecp 2015-03-24 19:49 - 2015-01-01 15:35 - 00000000 ____D () C:\Users\ecp\Documents\112 wiederkehrende dateien 1412 2015-03-24 18:26 - 2015-01-01 13:26 - 00000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG 2015-03-24 18:22 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini 2015-03-24 09:15 - 2015-01-02 13:37 - 00040478 _____ () C:\Windows\system32\ScanResults.xml 2015-03-24 09:08 - 2015-01-02 13:32 - 00000464 _____ () C:\Windows\system32\ScannerSettings 2015-03-23 08:32 - 2015-01-02 00:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-03-22 10:09 - 2015-01-02 00:29 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Mozilla 2015-03-22 09:50 - 2014-12-31 11:40 - 00000000 ____D () C:\Users\ecp\AppData\Local\Adobe 2015-03-19 21:07 - 2014-12-30 17:38 - 00003848 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1419953902 2015-03-19 21:07 - 2014-12-30 17:37 - 00000000 ____D () C:\Program Files (x86)\Opera 2015-03-19 21:05 - 2015-02-08 13:08 - 00000000 ____D () C:\Users\ecp\Documents\Tennisclub 2015-03-18 00:27 - 2015-03-02 11:54 - 00000000 ____D () C:\Users\ecp\Documents\Martina60Geburtstag20150406 2015-03-16 20:21 - 2014-07-23 11:43 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-03-16 20:21 - 2014-07-23 11:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-03-16 20:21 - 2014-07-23 11:43 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-03-16 13:57 - 2015-02-08 13:09 - 00000000 ____D () C:\Users\ecp\Documents\Privates 2015-03-13 09:40 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2015-03-13 09:35 - 2009-07-14 06:45 - 00298232 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-03-13 09:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2015-03-13 09:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism 2015-03-13 09:15 - 2014-07-22 17:37 - 00000000 ____D () C:\Windows\system32\MRT 2015-03-13 09:06 - 2014-07-22 17:37 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-03-11 22:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2015-03-11 09:00 - 2015-01-06 12:05 - 00000000 ____D () C:\Program Files (x86)\GTS 2015-03-09 19:16 - 2015-02-08 13:09 - 00000000 ____D () C:\Users\ecp\Documents\NBV 2015-03-09 12:13 - 2015-02-16 19:42 - 00000000 ____D () C:\Users\ecp\Documents\Camera ==================== Files in the root of some directories ======= 2015-02-04 19:15 - 2015-03-04 10:17 - 0001874 _____ () C:\Users\ecp\AppData\Roaming\MyMicroBalanceConfig.ini 2015-01-01 13:26 - 2015-03-24 18:26 - 0000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG 2015-03-05 17:56 - 2015-03-05 17:56 - 0385602 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS 2015-03-05 17:56 - 2015-03-05 17:56 - 0000232 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS.part 2015-01-03 02:27 - 2015-03-01 11:48 - 0000010 _____ () C:\Users\ecp\AppData\Local\DSI.DAT Some content of TEMP: ==================== C:\Users\ecp\AppData\Local\Temp\Quarantine.exe C:\Users\ecp\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-11 19:40 ==================== End Of Log ============================ |
08.04.2015, 14:04 | #10 | |
/// the machine /// TB-Ausbilder | Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen Java und Flash updaten. Zitat:
kennst Du das?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
16.04.2015, 21:47 | #11 |
| Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen Hallo Schrauber, Updates sind gemacht. Probleme gibt es immer noch. Fenster die sich selbständig öffnen, Umleitungen im Browser, Einblendungen usw. Weiterhin ist der Rechner unendlich langsam. Das Öffnen des IE oder FF dauert Minuten. (Zumindest beim ersten Mal) Nach einem Neustart habe ich mal die Prozesse beobachtet die automatisch aktiv sind. Auffällig war, das die Prozesse bz32.exe, bz64.exe, bzdap.exe aktiv waren als das erste Werbe-Fenster autom. eingeblendet wurden. Und das sind ja auch genau die Programme die sich in dem von dir angefragten Verzeichnis befinden. Ich kann dir aber nicht sagen was das ist oder wo es her kommt. Ich kann das Verzeichnis auch nicht öffnen. Wenn ich das versuche bekomme ich Meldung "Auf C:\ProgramData\bobyzoom kann nicht zugegriffen werden. Falscher Parameter" Hier ein aktuelles FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-04-2015 04 Ran by ecp (administrator) on ECP-PC on 16-04-2015 22:10:41 Running from C:\Users\ecp\Desktop Loaded Profiles: ecp (Available profiles: ecp) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE () C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe () C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe () C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe () C:\ProgramData\bobyzoom\1.1.0.30\bz64.exe () C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe () C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe (Microsoft Corporation) C:\Windows\System32\taskmgr.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [AudialsNotifier] => C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe [2410760 2014-12-17] () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {2D8E4D58-9FF9-4D32-B1A0-E2E493921442} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {9F48D099-769E-460F-8CAD-E870234711DA} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {A44BCBEF-651D-4A25-A802-3938D00F9BEE} URL = hxxp://q.search-simple.com/?affID=na&q={searchTerms}&r=92 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {BC78FFB8-43BE-431A-861E-C6CE3BA30EC0} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-16] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-16] (Oracle Corporation) Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default FF NewTab: FF DefaultSearchEngine: Yahoo! Search FF Keyword.URL: FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-16] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-16] () FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-16] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-16] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF SearchPlugin: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\searchplugins\search-simple.xml [2015-03-22] FF Extension: BobyZoom - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\bbz@bobyzoom.com [2015-04-07] Chrome: ======= CHR dev: Chrome dev build detected! <======= ATTENTION ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) Locked "tammgF119" service could not be unlocked. <===== ATTENTION Locked "tammgR119" service could not be unlocked. <===== ATTENTION R2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation) R2 bobyzoom; C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [0 ] () <==== ATTENTION (zero size file/folder) R2 bzwdg; C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [0 ] () <==== ATTENTION (zero size file/folder) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation) S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [49648 2015-01-15] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation) R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-12-17] (Audials AG) R5 tammgF119; C:\Windows\System32\Drivers\tammgF119.sys [26784 2015-03-20] () [File not signed] R5 tammgR119; C:\Windows\System32\Drivers\tammgR119.sys [26272 2015-03-20] () [File not signed] U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 CAXHWAZL; system32\DRIVERS\CAXHWAZL.sys [X] S3 cpuz134; \??\C:\Users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] S3 HSF_DPV; system32\DRIVERS\CAX_DPV.sys [X] S2 mdmxsdk; system32\DRIVERS\mdmxsdk.sys [X] S3 winachsf; system32\DRIVERS\CAX_CNXT.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-16 22:10 - 2015-04-16 22:13 - 00011243 _____ () C:\Users\ecp\Desktop\FRST.txt 2015-04-16 21:10 - 2015-04-16 21:10 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-04-16 21:10 - 2015-04-16 21:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-04-16 21:09 - 2015-04-16 21:09 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-04-16 20:37 - 2015-03-25 05:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-04-16 20:37 - 2015-03-25 05:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-04-16 20:37 - 2015-03-25 05:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-04-16 20:37 - 2015-03-25 05:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-04-16 20:37 - 2015-03-25 05:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-04-16 20:37 - 2015-03-25 05:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-04-16 20:37 - 2015-03-25 05:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-04-16 20:37 - 2015-03-25 05:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-04-16 20:37 - 2015-03-25 05:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-04-16 20:37 - 2015-03-25 05:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-04-16 20:37 - 2015-03-25 05:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-04-16 20:37 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-04-16 20:37 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-04-16 20:37 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-04-16 20:37 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-04-16 20:37 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-04-16 20:36 - 2015-03-23 05:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-04-16 20:36 - 2015-03-23 05:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-04-16 20:36 - 2015-03-23 05:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-04-16 20:36 - 2015-03-23 05:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-04-16 20:36 - 2015-03-23 05:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-04-16 20:36 - 2015-03-23 05:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-04-16 20:36 - 2015-03-23 05:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-04-16 20:36 - 2015-03-23 05:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-04-16 20:35 - 2015-03-05 07:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-04-16 20:35 - 2015-03-05 06:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2015-04-16 20:35 - 2015-03-04 06:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2015-04-16 20:35 - 2015-02-25 05:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2015-04-16 20:34 - 2015-03-04 06:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll 2015-04-16 20:34 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll 2015-04-07 22:09 - 2015-04-07 22:09 - 00000000 ___SD () C:\Windows\SysWOW64\GWX 2015-04-07 22:09 - 2015-04-07 22:09 - 00000000 ___SD () C:\Windows\system32\GWX 2015-04-04 23:37 - 2015-04-04 23:37 - 00001178 _____ () C:\Users\ecp\Desktop\JRT.txt 2015-04-04 23:29 - 2015-04-04 23:29 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ECP-PC-Windows-7-Home-Premium-(64-bit).dat 2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\RegBackup 2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Windows\pss 2015-04-04 23:17 - 2015-04-04 23:20 - 00000000 ____D () C:\AdwCleaner 2015-04-04 23:16 - 2015-04-04 23:16 - 00000703 _____ () C:\Users\ecp\Desktop\Reinigung - Verknüpfung.lnk 2015-04-04 22:27 - 2015-04-04 23:13 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-04-04 22:22 - 2015-04-04 22:22 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-04-04 22:22 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-04-04 22:22 - 2015-03-17 06:15 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-04-04 22:22 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-03-29 22:28 - 2015-03-29 22:58 - 00000000 ____D () C:\Qoobox 2015-03-29 22:28 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-03-29 22:28 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-03-29 22:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2015-03-29 22:27 - 2015-03-29 22:54 - 00000000 ____D () C:\Windows\erdnt 2015-03-29 22:25 - 2015-03-27 19:41 - 05615749 ____R (Swearware) C:\Users\ecp\Desktop\ComboFix.exe 2015-03-27 19:46 - 2015-03-27 19:46 - 00001271 _____ () C:\Users\ecp\Desktop\Revo Uninstaller.lnk 2015-03-27 19:46 - 2015-03-27 19:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2015-03-26 22:28 - 2015-04-16 22:10 - 00000000 ____D () C:\FRST 2015-03-26 22:27 - 2015-03-26 22:27 - 00000000 _____ () C:\Users\ecp\defogger_reenable 2015-03-26 22:18 - 2015-04-16 20:17 - 02097664 _____ (Farbar) C:\Users\ecp\Desktop\FRST64.exe 2015-03-26 22:13 - 2015-04-16 22:08 - 00000000 ____D () C:\Reinigung 2015-03-23 10:18 - 2015-03-23 10:19 - 00000000 ____D () C:\Program Files (x86)\Simple Dictation 2015-03-22 10:10 - 2015-03-22 10:10 - 00000000 ____D () C:\Users\ecp\AppData\Local\Macromedia 2015-03-22 10:09 - 2015-03-22 10:09 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2015-03-22 10:09 - 2015-03-22 10:09 - 00001154 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-03-22 10:09 - 2015-03-22 10:09 - 00000000 ____D () C:\Users\ecp\AppData\Local\Mozilla 2015-03-22 10:08 - 2015-03-22 10:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-03-22 09:32 - 2015-03-22 09:32 - 00004020 _____ () C:\Windows\System32\Tasks\Check for Scheduled Updates 2015-03-22 09:30 - 2015-03-22 09:30 - 00000000 ____D () C:\Users\ecp\AppData\Local\32220c02-c108-4e43-b856-df7d87f70051 2015-03-22 08:43 - 2015-04-04 23:04 - 00000000 ____D () C:\Program Files (x86)\SystemContinue 2015-03-20 20:06 - 2015-04-04 22:45 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 2015-03-20 19:47 - 2015-03-20 19:47 - 00000000 ____D () C:\ProgramData\e314b8475a214ebc973cc42fbf8c6edf 2015-03-20 19:43 - 2015-03-20 19:43 - 00026784 _____ () C:\Windows\system32\Drivers\tammgF119.sys 2015-03-20 19:43 - 2015-03-20 19:43 - 00026272 _____ () C:\Windows\system32\Drivers\tammgR119.sys 2015-03-20 19:43 - 2015-03-20 19:43 - 00000000 ____D () C:\ProgramData\bobyzoom 2015-03-18 09:05 - 2015-03-18 09:06 - 00002051 _____ () C:\Users\ecp\Downloads\Henner.txt 2015-03-17 08:53 - 2015-03-16 19:43 - 01274260 _____ () C:\Users\ecp\Documents\bskundenexcel201411.xls_0.ods 2015-03-17 08:53 - 2015-03-16 19:43 - 00017886 _____ () C:\Users\ecp\Documents\TennistrainingWinterHalle201415herren55he55mitersatzregelung.xls_0.ods ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-16 22:08 - 2014-07-23 11:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-04-16 22:05 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-16 22:05 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-16 22:02 - 2014-11-25 12:56 - 01464411 _____ () C:\Windows\WindowsUpdate.log 2015-04-16 21:55 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-04-16 21:54 - 2009-07-14 06:51 - 00060346 _____ () C:\Windows\setupact.log 2015-04-16 21:53 - 2015-03-05 09:19 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-04-16 21:53 - 2015-03-05 09:19 - 00000000 ____D () C:\Windows\system32\appraiser 2015-04-16 21:53 - 2014-07-23 12:22 - 00000000 ____D () C:\Program Files\Lenovo 2015-04-16 21:53 - 2010-11-21 05:47 - 00088206 _____ () C:\Windows\PFRO.log 2015-04-16 21:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2015-04-16 21:13 - 2014-07-22 18:47 - 01592824 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2015-04-16 21:13 - 2011-04-12 09:43 - 00699160 _____ () C:\Windows\system32\perfh007.dat 2015-04-16 21:13 - 2011-04-12 09:43 - 00149268 _____ () C:\Windows\system32\perfc007.dat 2015-04-16 21:12 - 2009-07-14 07:13 - 01592824 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-04-16 21:09 - 2015-01-01 11:41 - 00000000 ____D () C:\ProgramData\Skype 2015-04-16 21:08 - 2014-07-22 17:37 - 00000000 ____D () C:\Windows\system32\MRT 2015-04-16 21:01 - 2014-07-22 17:37 - 128913832 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-04-16 20:16 - 2014-07-23 11:43 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-04-16 20:16 - 2014-07-23 11:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-04-16 20:16 - 2014-07-23 11:43 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-04-16 19:51 - 2015-02-04 19:19 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-04-16 19:50 - 2015-02-04 19:16 - 00000000 ____D () C:\Program Files (x86)\Java 2015-04-16 19:46 - 2014-12-31 11:40 - 00000000 ____D () C:\Users\ecp\AppData\Local\Adobe 2015-04-07 21:59 - 2014-12-30 17:39 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Opera Software 2015-04-07 21:59 - 2014-12-30 17:39 - 00000000 ____D () C:\Users\ecp\AppData\Local\Opera Software 2015-04-07 21:59 - 2014-12-30 17:37 - 00000000 ____D () C:\Program Files (x86)\Opera 2015-04-04 23:26 - 2015-01-01 12:20 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Skype 2015-04-04 23:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Speech 2015-03-29 22:58 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2015-03-29 22:50 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2015-03-29 22:48 - 2009-07-14 04:34 - 61079552 _____ () C:\Windows\system32\config\SOFTWARE.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 13631488 _____ () C:\Windows\system32\config\SYSTEM.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak 2015-03-26 22:27 - 2014-12-30 16:50 - 00000000 ____D () C:\Users\ecp 2015-03-24 19:49 - 2015-01-01 15:35 - 00000000 ____D () C:\Users\ecp\Documents\112 wiederkehrende dateien 1412 2015-03-24 18:26 - 2015-01-01 13:26 - 00000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG 2015-03-24 18:22 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini 2015-03-24 09:15 - 2015-01-02 13:37 - 00040478 _____ () C:\Windows\system32\ScanResults.xml 2015-03-24 09:08 - 2015-01-02 13:32 - 00000464 _____ () C:\Windows\system32\ScannerSettings 2015-03-23 08:32 - 2015-01-02 00:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-03-22 10:09 - 2015-01-02 00:29 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Mozilla 2015-03-19 21:05 - 2015-02-08 13:08 - 00000000 ____D () C:\Users\ecp\Documents\Tennisclub 2015-03-18 00:27 - 2015-03-02 11:54 - 00000000 ____D () C:\Users\ecp\Documents\Martina60Geburtstag20150406 ==================== Files in the root of some directories ======= 2015-02-04 19:15 - 2015-03-04 10:17 - 0001874 _____ () C:\Users\ecp\AppData\Roaming\MyMicroBalanceConfig.ini 2015-01-01 13:26 - 2015-03-24 18:26 - 0000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG 2015-03-05 17:56 - 2015-03-05 17:56 - 0385602 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS 2015-03-05 17:56 - 2015-03-05 17:56 - 0000232 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS.part 2015-01-03 02:27 - 2015-03-01 11:48 - 0000010 _____ () C:\Users\ecp\AppData\Local\DSI.DAT Some content of TEMP: ==================== C:\Users\ecp\AppData\Local\Temp\jre-8u45-windows-au.exe C:\Users\ecp\AppData\Local\Temp\Quarantine.exe C:\Users\ecp\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-11 19:40 ==================== End Of Log ============================ Gruß Hausmeister |
17.04.2015, 19:15 | #12 |
/// the machine /// TB-Ausbilder | Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen Ok, da gehen wir jetzt mal kurz von Aussen ran: Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8) Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.04.2015, 19:29 | #13 |
| Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen Hallo Schrauber, erledigt ! Hier das log: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-04-2015 Ran by SYSTEM on MININT-11DFE0G on 21-04-2015 20:21:08 Running from F:\ Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log. Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\ecp\...\Run: [AudialsNotifier] => C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe [2410760 2014-12-17] () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation) S2 bobyzoom; C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [643856 2015-03-15] () S2 bzwdg; C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [241424 2015-03-15] () S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation) S2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation) S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation) S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [49648 2015-01-15] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation) S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation) S2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation) S1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-12-17] (Audials AG) S1 tammgF119; C:\Windows\system32\Drivers\tammgF119.sys [26784 2015-03-20] (AG Solutions) S1 tammgR119; C:\Windows\system32\Drivers\tammgR119.sys [26272 2015-03-20] (AG Solutions) S5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 CAXHWAZL; system32\DRIVERS\CAXHWAZL.sys [X] S3 cpuz134; \??\C:\Users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] S3 HSF_DPV; system32\DRIVERS\CAX_DPV.sys [X] S2 mdmxsdk; system32\DRIVERS\mdmxsdk.sys [X] S3 winachsf; system32\DRIVERS\CAX_CNXT.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-21 19:15 - 2015-04-21 19:16 - 00002712 _____ () C:\Windows\System32\Tasks\Tempo Runner bz64 2015-04-21 19:15 - 2015-04-21 19:16 - 00000412 _____ () C:\Windows\Tasks\Tempo Runner bz64.job 2015-04-16 21:14 - 2015-04-16 21:16 - 00026419 _____ () C:\Users\ecp\Desktop\Addition.txt 2015-04-16 21:10 - 2015-04-16 21:41 - 00026278 _____ () C:\Users\ecp\Desktop\FRST.txt 2015-04-16 20:10 - 2015-04-16 20:10 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-04-16 20:09 - 2015-04-16 20:09 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-04-16 19:37 - 2015-03-25 04:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2015-04-16 19:37 - 2015-03-25 04:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2015-04-16 19:37 - 2015-03-25 04:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2015-04-16 19:37 - 2015-03-25 04:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2015-04-16 19:37 - 2015-03-25 04:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2015-04-16 19:37 - 2015-03-25 04:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\WinSetupUI.dll 2015-04-16 19:37 - 2015-03-25 04:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\System32\wups2.dll 2015-04-16 19:37 - 2015-03-25 04:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll 2015-04-16 19:37 - 2015-03-25 04:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2015-04-16 19:37 - 2015-03-25 04:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2015-04-16 19:37 - 2015-03-25 04:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\System32\wu.upgrade.ps.dll 2015-04-16 19:37 - 2015-03-25 04:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-04-16 19:37 - 2015-03-25 04:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-04-16 19:37 - 2015-03-25 04:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-04-16 19:37 - 2015-03-25 04:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-04-16 19:37 - 2015-03-25 04:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-04-16 19:36 - 2015-03-23 04:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\System32\invagent.dll 2015-04-16 19:36 - 2015-03-23 04:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\System32\generaltel.dll 2015-04-16 19:36 - 2015-03-23 04:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\System32\appraiser.dll 2015-04-16 19:36 - 2015-03-23 04:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\System32\devinv.dll 2015-04-16 19:36 - 2015-03-23 04:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\System32\aepdu.dll 2015-04-16 19:36 - 2015-03-23 04:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\System32\aepic.dll 2015-04-16 19:36 - 2015-03-23 04:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\acmigration.dll 2015-04-16 19:36 - 2015-03-23 04:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\System32\aeinv.dll 2015-04-16 19:35 - 2015-03-05 06:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll 2015-04-16 19:35 - 2015-03-05 05:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2015-04-16 19:35 - 2015-03-04 05:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\System32\clfs.sys 2015-04-16 19:35 - 2015-02-25 04:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys 2015-04-16 19:34 - 2015-03-04 05:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\System32\clfsw32.dll 2015-04-16 19:34 - 2015-03-04 05:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll 2015-04-07 21:09 - 2015-04-07 21:09 - 00000000 ___SD () C:\Windows\SysWOW64\GWX 2015-04-07 21:09 - 2015-04-07 21:09 - 00000000 ___SD () C:\Windows\System32\GWX 2015-04-04 22:37 - 2015-04-04 22:37 - 00001178 _____ () C:\Users\ecp\Desktop\JRT.txt 2015-04-04 22:29 - 2015-04-04 22:29 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ECP-PC-Windows-7-Home-Premium-(64-bit).dat 2015-04-04 22:29 - 2015-04-04 22:29 - 00000000 ____D () C:\RegBackup 2015-04-04 22:28 - 2015-04-04 22:28 - 00000000 ____D () C:\Windows\pss 2015-04-04 22:17 - 2015-04-04 22:20 - 00000000 ____D () C:\AdwCleaner 2015-04-04 22:16 - 2015-04-04 22:16 - 00000703 _____ () C:\Users\ecp\Desktop\Reinigung - Verknüpfung.lnk 2015-04-04 21:27 - 2015-04-04 22:13 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\MBAMSwissArmy.sys 2015-04-04 21:22 - 2015-04-04 21:22 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-04-04 21:22 - 2015-04-04 21:22 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-04-04 21:22 - 2015-04-04 21:22 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-04-04 21:22 - 2015-03-17 05:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamchameleon.sys 2015-04-04 21:22 - 2015-03-17 05:15 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mwac.sys 2015-04-04 21:22 - 2015-03-17 05:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2015-03-29 21:28 - 2015-03-29 21:58 - 00000000 ____D () C:\Qoobox 2015-03-29 21:28 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-03-29 21:28 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-03-29 21:28 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-03-29 21:28 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-03-29 21:28 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-03-29 21:28 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2015-03-29 21:28 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2015-03-29 21:28 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2015-03-29 21:27 - 2015-03-29 21:54 - 00000000 ____D () C:\Windows\erdnt 2015-03-29 21:25 - 2015-03-27 18:41 - 05615749 ____R (Swearware) C:\Users\ecp\Desktop\ComboFix.exe 2015-03-27 18:46 - 2015-03-27 18:46 - 00001271 _____ () C:\Users\ecp\Desktop\Revo Uninstaller.lnk 2015-03-27 18:46 - 2015-03-27 18:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2015-03-26 21:28 - 2015-04-21 20:21 - 00000000 ____D () C:\FRST 2015-03-26 21:27 - 2015-03-26 21:27 - 00000000 _____ () C:\Users\ecp\defogger_reenable 2015-03-26 21:18 - 2015-04-16 19:17 - 02097664 _____ (Farbar) C:\Users\ecp\Desktop\FRST64.exe 2015-03-26 21:13 - 2015-04-16 21:08 - 00000000 ____D () C:\Reinigung 2015-03-23 09:18 - 2015-03-23 09:19 - 00000000 ____D () C:\Program Files (x86)\Simple Dictation 2015-03-22 09:10 - 2015-03-22 09:10 - 00000000 ____D () C:\Users\ecp\AppData\Local\Macromedia 2015-03-22 09:09 - 2015-03-22 09:09 - 00001154 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2015-03-22 09:09 - 2015-03-22 09:09 - 00000000 ____D () C:\Users\ecp\AppData\Local\Mozilla 2015-03-22 09:08 - 2015-03-22 09:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-03-22 08:32 - 2015-03-22 08:32 - 00004020 _____ () C:\Windows\System32\Tasks\Check for Scheduled Updates 2015-03-22 08:30 - 2015-03-22 08:30 - 00000000 ____D () C:\Users\ecp\AppData\Local\32220c02-c108-4e43-b856-df7d87f70051 2015-03-22 07:43 - 2015-04-04 22:04 - 00000000 ____D () C:\Program Files (x86)\SystemContinue ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-21 19:15 - 2009-07-14 05:51 - 00062048 _____ () C:\Windows\setupact.log 2015-04-21 19:14 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-04-21 19:13 - 2014-11-25 11:56 - 01537382 _____ () C:\Windows\WindowsUpdate.log 2015-04-21 19:08 - 2014-07-23 10:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-04-21 18:57 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-21 18:57 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-21 18:42 - 2011-04-12 08:43 - 00699340 _____ () C:\Windows\System32\perfh007.dat 2015-04-21 18:42 - 2011-04-12 08:43 - 00149448 _____ () C:\Windows\System32\perfc007.dat 2015-04-21 18:42 - 2009-07-14 06:13 - 01619272 _____ () C:\Windows\System32\PerfStringBackup.INI 2015-04-16 20:53 - 2015-03-05 08:19 - 00000000 ___SD () C:\Windows\System32\CompatTel 2015-04-16 20:53 - 2015-03-05 08:19 - 00000000 ____D () C:\Windows\System32\appraiser 2015-04-16 20:53 - 2014-07-23 11:22 - 00000000 ____D () C:\Program Files\Lenovo 2015-04-16 20:53 - 2010-11-21 04:47 - 00088206 _____ () C:\Windows\PFRO.log 2015-04-16 20:53 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2015-04-16 20:13 - 2014-07-22 17:47 - 01592824 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2015-04-16 20:09 - 2015-01-01 10:41 - 00000000 ____D () C:\ProgramData\Skype 2015-04-16 20:08 - 2014-07-22 16:37 - 00000000 ____D () C:\Windows\System32\MRT 2015-04-16 20:01 - 2014-07-22 16:37 - 128913832 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe 2015-04-16 19:16 - 2014-07-23 10:43 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-04-16 19:16 - 2014-07-23 10:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-04-16 19:16 - 2014-07-23 10:43 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-04-16 18:51 - 2015-02-04 18:19 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-04-16 18:50 - 2015-02-04 18:16 - 00000000 ____D () C:\Program Files (x86)\Java 2015-04-16 18:46 - 2014-12-31 10:40 - 00000000 ____D () C:\Users\ecp\AppData\Local\Adobe 2015-04-07 20:59 - 2014-12-30 16:39 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Opera Software 2015-04-07 20:59 - 2014-12-30 16:39 - 00000000 ____D () C:\Users\ecp\AppData\Local\Opera Software 2015-04-07 20:59 - 2014-12-30 16:37 - 00000000 ____D () C:\Program Files (x86)\Opera 2015-04-04 22:26 - 2015-01-01 11:20 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Skype 2015-04-04 22:04 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Speech 2015-04-04 21:45 - 2015-03-20 19:06 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 2015-03-29 21:58 - 2009-07-14 04:20 - 00000000 __RHD () C:\users\Default 2015-03-29 21:50 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2015-03-29 21:48 - 2009-07-14 03:34 - 61079552 _____ () C:\Windows\System32\config\SOFTWARE.bak 2015-03-29 21:48 - 2009-07-14 03:34 - 13631488 _____ () C:\Windows\System32\config\SYSTEM.bak 2015-03-29 21:48 - 2009-07-14 03:34 - 00524288 _____ () C:\Windows\System32\config\DEFAULT.bak 2015-03-29 21:48 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\System32\config\SECURITY.bak 2015-03-29 21:48 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\System32\config\SAM.bak 2015-03-26 21:27 - 2014-12-30 15:50 - 00000000 ____D () C:\users\ecp 2015-03-24 18:49 - 2015-01-01 14:35 - 00000000 ____D () C:\Users\ecp\Documents\112 wiederkehrende dateien 1412 2015-03-24 17:26 - 2015-01-01 12:26 - 00000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG 2015-03-24 17:22 - 2009-07-14 03:34 - 00000505 _____ () C:\Windows\win.ini 2015-03-24 08:15 - 2015-01-02 12:37 - 00040478 _____ () C:\Windows\System32\ScanResults.xml 2015-03-24 08:08 - 2015-01-02 12:32 - 00000464 _____ () C:\Windows\System32\ScannerSettings 2015-03-23 07:32 - 2015-01-01 23:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-03-22 09:09 - 2015-01-01 23:29 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Mozilla Some content of TEMP: ==================== C:\Users\ecp\AppData\Local\Temp\jre-8u45-windows-au.exe C:\Users\ecp\AppData\Local\Temp\Quarantine.exe C:\Users\ecp\AppData\Local\Temp\sqlite3.dll ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== Restore Points ========================= Restore point made on: 2015-03-20 19:27:03 Restore point made on: 2015-03-23 07:22:01 Restore point made on: 2015-03-23 08:20:23 Restore point made on: 2015-03-24 08:28:40 Restore point made on: 2015-03-27 18:49:08 Restore point made on: 2015-03-27 18:54:31 Restore point made on: 2015-03-27 18:57:30 Restore point made on: 2015-03-27 18:58:37 Restore point made on: 2015-03-27 19:00:31 Restore point made on: 2015-03-27 19:02:37 Restore point made on: 2015-03-27 19:03:34 Restore point made on: 2015-03-27 19:04:39 Restore point made on: 2015-03-27 19:05:44 Restore point made on: 2015-03-27 19:08:41 Restore point made on: 2015-03-27 19:10:57 Restore point made on: 2015-03-27 19:14:18 Restore point made on: 2015-03-27 19:16:06 Restore point made on: 2015-03-27 19:17:01 Restore point made on: 2015-03-27 19:18:33 Restore point made on: 2015-03-29 21:29:47 Restore point made on: 2015-03-29 22:00:02 Restore point made on: 2015-04-07 18:45:46 Restore point made on: 2015-04-07 18:59:51 Restore point made on: 2015-04-07 21:08:55 Restore point made on: 2015-04-16 18:56:47 Restore point made on: 2015-04-16 19:26:15 Restore point made on: 2015-04-16 19:59:23 Restore point made on: 2015-04-21 18:35:28 ==================== Memory info =========================== Percentage of memory in use: 22% Total physical RAM: 2006.3 MB Available physical RAM: 1550.5 MB Total Pagefile: 2006.3 MB Available Pagefile: 1527.93 MB Total Virtual: 8192 MB Available Virtual: 8191.9 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:142.65 GB) (Free:107.76 GB) NTFS Drive d: (System) (Fixed) (Total:6.4 GB) (Free:0.59 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: () (Removable) (Total:0.25 GB) (Free:0.24 GB) FAT Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 4557C7D5) Partition 1: (Active) - (Size=6.4 GB) - (Type=27) Partition 2: (Not Active) - (Size=142.6 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 252 MB) (Disk ID: 0D0C0B0A) Partition 1: (Active) - (Size=252 MB) - (Type=06) LastRegBack: 2015-03-11 18:40 ==================== End Of Log ============================ |
22.04.2015, 08:49 | #14 |
/// the machine /// TB-Ausbilder | Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter S2 bobyzoom; C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [643856 2015-03-15] () S2 bzwdg; C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [241424 2015-03-15] () C:\ProgramData\bobyzoom
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier. Frisches FRST log aus dem normalen Modus bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.04.2015, 18:24 | #15 |
| Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen Hallo Schrauber, alles durchgeführt. Hier das Fixlog: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-04-2015 Ran by SYSTEM at 2015-04-22 18:59:45 Run:1 Running from F:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** S2 bobyzoom; C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [643856 2015-03-15] () S2 bzwdg; C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [241424 2015-03-15] () C:\ProgramData\bobyzoom ***************** bobyzoom => Service deleted successfully. bzwdg => Service deleted successfully. C:\ProgramData\bobyzoom => Moved successfully. ==== End of Fixlog 18:59:45 ==== FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-04-2015 04 Ran by ecp (administrator) on ECP-PC on 22-04-2015 19:18:08 Running from C:\Users\ecp\Desktop Loaded Profiles: ecp (Available profiles: ecp) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Lenovo.) C:\Windows\System32\ibmpmsvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe () C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [AudialsNotifier] => C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe [2410760 2014-12-17] () GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {2D8E4D58-9FF9-4D32-B1A0-E2E493921442} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {9F48D099-769E-460F-8CAD-E870234711DA} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {A44BCBEF-651D-4A25-A802-3938D00F9BEE} URL = hxxp://q.search-simple.com/?affID=na&q={searchTerms}&r=92 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {BC78FFB8-43BE-431A-861E-C6CE3BA30EC0} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8 BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-16] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-16] (Oracle Corporation) Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default FF NewTab: FF DefaultSearchEngine: Yahoo! Search FF Keyword.URL: FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-16] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-16] () FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-16] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-16] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF SearchPlugin: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\searchplugins\search-simple.xml [2015-03-22] FF Extension: BobyZoom - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\bbz@bobyzoom.com [2015-04-07] Chrome: ======= CHR dev: Chrome dev build detected! <======= ATTENTION ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation) S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [49648 2015-01-15] () S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation) R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-12-17] (Audials AG) R1 tammgF119; C:\Windows\system32\Drivers\tammgF119.sys [26784 2015-03-20] (AG Solutions) R1 tammgR119; C:\Windows\system32\Drivers\tammgR119.sys [26272 2015-03-20] (AG Solutions) U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 CAXHWAZL; system32\DRIVERS\CAXHWAZL.sys [X] S3 cpuz134; \??\C:\Users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] S3 HSF_DPV; system32\DRIVERS\CAX_DPV.sys [X] S2 mdmxsdk; system32\DRIVERS\mdmxsdk.sys [X] S3 winachsf; system32\DRIVERS\CAX_CNXT.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-22 19:18 - 2015-04-22 19:19 - 00010424 _____ () C:\Users\ecp\Desktop\FRST.txt 2015-04-21 20:15 - 2015-04-21 20:16 - 00002712 _____ () C:\Windows\System32\Tasks\Tempo Runner bz64 2015-04-21 20:15 - 2015-04-21 20:16 - 00000412 _____ () C:\Windows\Tasks\Tempo Runner bz64.job 2015-04-16 21:10 - 2015-04-16 21:10 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2015-04-16 21:10 - 2015-04-16 21:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-04-16 21:09 - 2015-04-16 21:09 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-04-16 20:37 - 2015-03-25 05:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-04-16 20:37 - 2015-03-25 05:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-04-16 20:37 - 2015-03-25 05:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-04-16 20:37 - 2015-03-25 05:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-04-16 20:37 - 2015-03-25 05:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-04-16 20:37 - 2015-03-25 05:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-04-16 20:37 - 2015-03-25 05:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-04-16 20:37 - 2015-03-25 05:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-04-16 20:37 - 2015-03-25 05:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-04-16 20:37 - 2015-03-25 05:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-04-16 20:37 - 2015-03-25 05:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-04-16 20:37 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-04-16 20:37 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-04-16 20:37 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-04-16 20:37 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-04-16 20:37 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-04-16 20:36 - 2015-03-23 05:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-04-16 20:36 - 2015-03-23 05:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-04-16 20:36 - 2015-03-23 05:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-04-16 20:36 - 2015-03-23 05:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-04-16 20:36 - 2015-03-23 05:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-04-16 20:36 - 2015-03-23 05:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-04-16 20:36 - 2015-03-23 05:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-04-16 20:36 - 2015-03-23 05:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-04-16 20:35 - 2015-03-05 07:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-04-16 20:35 - 2015-03-05 06:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2015-04-16 20:35 - 2015-03-04 06:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2015-04-16 20:35 - 2015-02-25 05:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2015-04-16 20:34 - 2015-03-04 06:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll 2015-04-16 20:34 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll 2015-04-07 22:09 - 2015-04-07 22:09 - 00000000 ___SD () C:\Windows\SysWOW64\GWX 2015-04-07 22:09 - 2015-04-07 22:09 - 00000000 ___SD () C:\Windows\system32\GWX 2015-04-04 23:37 - 2015-04-04 23:37 - 00001178 _____ () C:\Users\ecp\Desktop\JRT.txt 2015-04-04 23:29 - 2015-04-04 23:29 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ECP-PC-Windows-7-Home-Premium-(64-bit).dat 2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\RegBackup 2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Windows\pss 2015-04-04 23:17 - 2015-04-04 23:20 - 00000000 ____D () C:\AdwCleaner 2015-04-04 23:16 - 2015-04-04 23:16 - 00000703 _____ () C:\Users\ecp\Desktop\Reinigung - Verknüpfung.lnk 2015-04-04 22:27 - 2015-04-04 23:13 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-04-04 22:22 - 2015-04-04 22:22 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-04-04 22:22 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-04-04 22:22 - 2015-03-17 06:15 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-04-04 22:22 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-03-29 22:28 - 2015-03-29 22:58 - 00000000 ____D () C:\Qoobox 2015-03-29 22:28 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-03-29 22:28 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-03-29 22:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2015-03-29 22:28 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2015-03-29 22:27 - 2015-03-29 22:54 - 00000000 ____D () C:\Windows\erdnt 2015-03-29 22:25 - 2015-03-27 19:41 - 05615749 ____R (Swearware) C:\Users\ecp\Desktop\ComboFix.exe 2015-03-27 19:46 - 2015-03-27 19:46 - 00001271 _____ () C:\Users\ecp\Desktop\Revo Uninstaller.lnk 2015-03-27 19:46 - 2015-03-27 19:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2015-03-26 22:28 - 2015-04-22 19:18 - 00000000 ____D () C:\FRST 2015-03-26 22:27 - 2015-03-26 22:27 - 00000000 _____ () C:\Users\ecp\defogger_reenable 2015-03-26 22:18 - 2015-04-16 20:17 - 02097664 _____ (Farbar) C:\Users\ecp\Desktop\FRST64.exe 2015-03-26 22:13 - 2015-04-16 22:08 - 00000000 ____D () C:\Reinigung 2015-03-23 10:18 - 2015-03-23 10:19 - 00000000 ____D () C:\Program Files (x86)\Simple Dictation ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-22 19:11 - 2014-11-25 12:56 - 01566859 _____ () C:\Windows\WindowsUpdate.log 2015-04-22 19:09 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-22 19:09 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-22 19:08 - 2014-07-23 11:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-04-22 19:06 - 2011-04-12 09:43 - 00699340 _____ () C:\Windows\system32\perfh007.dat 2015-04-22 19:06 - 2011-04-12 09:43 - 00149448 _____ () C:\Windows\system32\perfc007.dat 2015-04-22 19:06 - 2009-07-14 07:13 - 01619272 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-04-22 19:01 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-04-22 19:01 - 2009-07-14 06:51 - 00062104 _____ () C:\Windows\setupact.log 2015-04-16 21:53 - 2015-03-05 09:19 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-04-16 21:53 - 2015-03-05 09:19 - 00000000 ____D () C:\Windows\system32\appraiser 2015-04-16 21:53 - 2014-07-23 12:22 - 00000000 ____D () C:\Program Files\Lenovo 2015-04-16 21:53 - 2010-11-21 05:47 - 00088206 _____ () C:\Windows\PFRO.log 2015-04-16 21:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2015-04-16 21:13 - 2014-07-22 18:47 - 01592824 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2015-04-16 21:09 - 2015-01-01 11:41 - 00000000 ____D () C:\ProgramData\Skype 2015-04-16 21:08 - 2014-07-22 17:37 - 00000000 ____D () C:\Windows\system32\MRT 2015-04-16 21:01 - 2014-07-22 17:37 - 128913832 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-04-16 20:16 - 2014-07-23 11:43 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-04-16 20:16 - 2014-07-23 11:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-04-16 20:16 - 2014-07-23 11:43 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-04-16 19:51 - 2015-02-04 19:19 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-04-16 19:50 - 2015-02-04 19:16 - 00000000 ____D () C:\Program Files (x86)\Java 2015-04-16 19:46 - 2014-12-31 11:40 - 00000000 ____D () C:\Users\ecp\AppData\Local\Adobe 2015-04-07 21:59 - 2014-12-30 17:39 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Opera Software 2015-04-07 21:59 - 2014-12-30 17:39 - 00000000 ____D () C:\Users\ecp\AppData\Local\Opera Software 2015-04-07 21:59 - 2014-12-30 17:37 - 00000000 ____D () C:\Program Files (x86)\Opera 2015-04-04 23:26 - 2015-01-01 12:20 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Skype 2015-04-04 23:04 - 2015-03-22 08:43 - 00000000 ____D () C:\Program Files (x86)\SystemContinue 2015-04-04 23:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Speech 2015-04-04 22:45 - 2015-03-20 20:06 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 2015-03-29 22:58 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2015-03-29 22:50 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2015-03-29 22:48 - 2009-07-14 04:34 - 61079552 _____ () C:\Windows\system32\config\SOFTWARE.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 13631488 _____ () C:\Windows\system32\config\SYSTEM.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak 2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak 2015-03-26 22:27 - 2014-12-30 16:50 - 00000000 ____D () C:\Users\ecp 2015-03-24 19:49 - 2015-01-01 15:35 - 00000000 ____D () C:\Users\ecp\Documents\112 wiederkehrende dateien 1412 2015-03-24 18:26 - 2015-01-01 13:26 - 00000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG 2015-03-24 18:22 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini 2015-03-24 09:15 - 2015-01-02 13:37 - 00040478 _____ () C:\Windows\system32\ScanResults.xml 2015-03-24 09:08 - 2015-01-02 13:32 - 00000464 _____ () C:\Windows\system32\ScannerSettings 2015-03-23 08:32 - 2015-01-02 00:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service ==================== Files in the root of some directories ======= 2015-02-04 19:15 - 2015-03-04 10:17 - 0001874 _____ () C:\Users\ecp\AppData\Roaming\MyMicroBalanceConfig.ini 2015-01-01 13:26 - 2015-03-24 18:26 - 0000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG 2015-03-05 17:56 - 2015-03-05 17:56 - 0385602 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS 2015-03-05 17:56 - 2015-03-05 17:56 - 0000232 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS.part 2015-01-03 02:27 - 2015-03-01 11:48 - 0000010 _____ () C:\Users\ecp\AppData\Local\DSI.DAT Some content of TEMP: ==================== C:\Users\ecp\AppData\Local\Temp\jre-8u45-windows-au.exe C:\Users\ecp\AppData\Local\Temp\Quarantine.exe C:\Users\ecp\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-03-11 19:40 ==================== End Of Log ============================ Gruß Hausmeister |
Themen zu Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen |
adobe, adware, bildschirm, bobyzoom, browser, defender, desktop, excel, failed, feedback, flash player, home, homepage, iexplore.exe, install.exe, mozilla, newtab, onedrive, popups, problem, protectwindowsmanager.exe, registry, reimagerealtimeprotector, rundll, scan, security, securityutility, services.exe, software, super, svchost.exe, system, temp, wiederkehrende dateien, windows |