Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 26.03.2015, 22:49   #1
Haus meister
 
Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Standard

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen



Hallo Forum,

nachdem ich letztes Mal hier super Hilfe von Schrauber bekommen habe, und den Rechner meines Kumpels "geheilt" wieder abgeben konnte, hat sich das rumgesprochen. Und schwupps bin ich wieder da, mit dem gleichen Problem eines anderen Kumpels.

Die Situation ist diesemal folgende: Mein Kumpel hat sich ein gebrauchtes Laptop gekauft, welches vermutlich bereits verseucht war. Da er sich mit Rechnern so gut wie gar nicht auskennt, hat er den gekauften einfach so benutzt wie er war noch ein paar Programme installiert und sich über langsame Reaktionszeiten gewundert. Das so viel "Mist" bereits installiert war, hat er auf den Vorbesitzer geschoben. Nun ist es wieder soweit, dass man ihn eigentlich nicht mehr benutzen kann, da jeder Aufruf einer Internetseite mit Umleitungen quittiert wird, diverse Popups erscheinen usw.


Hier nun die Logs:


defogger_disable:
Code:
ATTFilter
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 21:27 on 26/03/2015 (ecp)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-
         

FRST:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by ecp (administrator) on ECP-PC on 26-03-2015 21:28:31
Running from C:\Reinigung
Loaded Profiles: ecp (Available profiles: ecp)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE
() C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe
() C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
(Gambali OEM Software) C:\ProgramData\SecurityUtility\Gambali.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
() C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe
() C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
() C:\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe
() C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.exe
() C:\Program Files\WajaWebEnhancer\wajam_64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
() C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ZOOM\TpScrex.exe
(HQ CinemaV20.03) C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
() C:\Program Files\WajaWebEnhancer\wajam.exe
() C:\Program Files\WajaWebEnhancer\wajam_64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Price Fountain) C:\Users\ecp\AppData\Local\PriceFountain\pricefountainw.exe
() C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe
(Pay By Ads LTD) C:\Users\ecp\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrlte.exe
(Price Fountain) C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
() C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files (x86)\ver0CheckMeUp\CheckMeUp.exe
() C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe
() C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe
() C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe
() C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe
() C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe
() C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe
() C:\Program Files (x86)\Search Extensions\Client.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\McUICnt.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bz64.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe
(Microsoft Corporation) C:\Windows\System32\dinotify.exe
() C:\Neuer Ordner\FRST64.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [18643560 2013-03-01] (Skype Technologies S.A.)
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [pricefountainw.exe] => C:\Users\ecp\AppData\Local\PriceFountain\pricefountainw.exe [461824 2014-12-07] (Price Fountain)
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [AudialsNotifier] => C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe [2410760 2014-12-17] ()
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [Yahoo! Search] => C:\Users\ecp\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrlte.exe [644816 2015-03-20] (Pay By Ads LTD)
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [GoogleChromeAutoLaunch_9478B546DA4E84D7A735A7D0209EA854] => C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [1014272 2015-02-04] ()
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\RunOnce: [Wse_binkiland] => C:\Windows\SysWOW64\wscript.exe /E:vbscript /B "C:\Users\ecp\AppData\Roaming\Wse_binkiland\UpdateProc\bkup.dat"
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\MountPoints2: {56f6912e-919f-11e4-9510-001fe2182534} - E:\LaunchU3.exe -a
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\MountPoints2: {7573f5a7-9695-11e4-9739-001fe2182534} - E:\LaunchU3.exe -a
AppInit_DLLs-x32: c:/progra~3/{a8e14~1/171~1.0/sila.dll => c:\ProgramData\{A8E14022-F863-91A4-49E5-E126996732A8}\1.7.1.0\sila.dll [649216 2015-01-01] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [S-1-5-21-1780445102-594666999-3139876592-1000] => Internet Explorer proxy is enabled.
ProxyServer: [S-1-5-21-1780445102-594666999-3139876592-1000] => http=127.0.0.1:49338;https=127.0.0.1:49338
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://myhome.vi-view.com/?type=hp&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://myhome.vi-view.com/?type=hp&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms}
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://binkiland.com/?f=1&a=bnk_coinis_15_12&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0CyB0EyE0CzztCyC0C0ByCtN0D0Tzu0StCtCyByCtN1L2XzutAtFzztFtAtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StByD0E0ByBzyyCyEtGtB0E0A0AtGyEtAyEtBtG0FtD0D0EtGtD0A0DyB0BtB0A0A0A0FyDyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0AyCyD0B0E0D0AtGzz0FyDyCtGyEzz0CyEtGzz0D0FyBtGtC0DyE0AtAyC0EyC0C0C0E0E2Q&cr=1970351768&ir=
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://myhome.vi-view.com/?type=hp&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> DefaultScope {C4C5AF64-3082-439A-8C86-5773B579E965} URL = hxxp://binkiland.com/results.php?f=4&q={searchTerms}&a=bnk_coinis_15_12&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0CyB0EyE0CzztCyC0C0ByCtN0D0Tzu0StCtCyByCtN1L2XzutAtFzztFtAtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StByD0E0ByBzyyCyEtGtB0E0A0AtGyEtAyEtBtG0FtD0D0EtGtD0A0DyB0BtB0A0A0A0FyDyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0AyCyD0B0E0D0AtGzz0FyDyCtGyEzz0CyEtGzz0D0FyBtGtC0DyE0AtAyC0EyC0C0C0E0E2Q&cr=1970351768&ir=
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {2D8E4D58-9FF9-4D32-B1A0-E2E493921442} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {5782EC3E-14E8-402B-BAD6-7FE86EF6484D} URL = hxxp://Vosteran.com/results.php?f=4&q={searchTerms}&a=vst_ir_15_01_ie&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0CyB0EyE0CzztCyC0C0ByCtN0D0Tzu0StCtDzyyCtN1L2XzutAtFyCtFtCyCtFyCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StBtB0EtD0FtAyEyCtG0FyEtCtCtG0D0Dzy0EtGtB0EzyyBtGyC0FtD0F0EtAyC0B0ByB0E0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0AyCyD0B0E0D0AtGzz0FyDyCtGyEzz0CyEtGzz0D0FyBtGtC0DyE0AtAyC0EyC0C0C0E0E2Q&cr=692593422&ir=
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {9F48D099-769E-460F-8CAD-E870234711DA} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {A44BCBEF-651D-4A25-A802-3938D00F9BEE} URL = hxxp://q.search-simple.com/?affID=na&q={searchTerms}&r=92
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {BC78FFB8-43BE-431A-861E-C6CE3BA30EC0} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {C4C5AF64-3082-439A-8C86-5773B579E965} URL = hxxp://binkiland.com/results.php?f=4&q={searchTerms}&a=bnk_coinis_15_12&cd=2XzuyEtN2Y1L1QzutDtDtBtCyD0CyB0EyE0CzztCyC0C0ByCtN0D0Tzu0StCtCyByCtN1L2XzutAtFzztFtAtFtCtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StByD0E0ByBzyyCyEtGtB0E0A0AtGyEtAyEtBtG0FtD0D0EtGtD0A0DyB0BtB0A0A0A0FyDyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0AyCyD0B0E0D0AtGzz0FyDyCtGyEzz0CyEtGzz0D0FyBtGtC0DyE0AtAyC0EyC0C0C0E0E2Q&cr=1970351768&ir=
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
BHO: SoaleEsChoeocKeirr -> {007c182f-91dc-485e-a48f-b4ad99086949} -> C:\Program Files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.x64.dll [2015-03-06] ()
BHO: ddeallpeAuk -> {3dcc325d-9258-4278-ac06-bc06aafb8809} -> C:\Program Files (x86)\ddeallpeAuk\83pi0tURGPEZSW.x64.dll [2015-03-23] ()
BHO: CheckMeUp -> {B7A5EE16-3FED-399F-55F6-58AF84D02FC4} -> C:\Program Files (x86)\ver0CheckMeUp\190_x64.dll [2015-03-20] ()
BHO: Saveitkeaep. -> {f1a892aa-d8f1-4a2a-a980-430349d85d2a} -> C:\Program Files (x86)\Saveitkeaep\OUx1yNk71u3K2I.x64.dll [2015-03-23] ()
BHO-x32: SoaleEsChoeocKeirr -> {007c182f-91dc-485e-a48f-b4ad99086949} -> C:\Program Files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.dll [2015-03-06] ()
BHO-x32: ddeallpeAuk -> {3dcc325d-9258-4278-ac06-bc06aafb8809} -> C:\Program Files (x86)\ddeallpeAuk\83pi0tURGPEZSW.dll [2015-03-23] ()
BHO-x32: CheckMeUp -> {B7A5EE16-3FED-399F-55F6-58AF84D02FC4} -> C:\Program Files (x86)\ver0CheckMeUp\190.dll [2015-03-20] ()
BHO-x32: Saveitkeaep. -> {f1a892aa-d8f1-4a2a-a980-430349d85d2a} -> C:\Program Files (x86)\Saveitkeaep\OUx1yNk71u3K2I.dll [2015-03-23] ()
Toolbar: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> No Name - {C424171E-592A-415A-9EB1-DFD6D95D3530} -  No File
Toolbar: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> No Name - {4F524A2D-5350-4500-76A7-7A786E7484D7} -  No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Winsock: Catalog9 01 C:\Windows\SysWOW64\Gambali.dll [335768] (Gambali OEM Software)
Winsock: Catalog9 02 C:\Windows\SysWOW64\Gambali.dll [335768] (Gambali OEM Software)
Winsock: Catalog9 03 C:\Windows\SysWOW64\Gambali.dll [335768] (Gambali OEM Software)
Winsock: Catalog9 04 C:\Windows\SysWOW64\Gambali.dll [335768] (Gambali OEM Software)
Winsock: Catalog9 15 C:\Windows\SysWOW64\Gambali.dll [335768] (Gambali OEM Software)
Winsock: Catalog9-x64 01 C:\Windows\system32\Gambali64.dll [398808] (Gambali OEM Software)
Winsock: Catalog9-x64 02 C:\Windows\system32\Gambali64.dll [398808] (Gambali OEM Software)
Winsock: Catalog9-x64 03 C:\Windows\system32\Gambali64.dll [398808] (Gambali OEM Software)
Winsock: Catalog9-x64 04 C:\Windows\system32\Gambali64.dll [398808] (Gambali OEM Software)
Winsock: Catalog9-x64 15 C:\Windows\system32\Gambali64.dll [398808] (Gambali OEM Software)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default
FF NewTab: hxxp://de.search.yahoo.com/?fr=hp-ddc-bd-tab&type=276_pr__alt__ddc_dsssyctab_bd_com
FF DefaultSearchEngine: Yahoo! Search
FF SelectedSearchEngine: Yahoo! Search
FF Homepage: hxxp://de.search.yahoo.com/?fr=hp-ddc-bd&type=276_pr__alt__ddc_dsssyc_bd_com
FF Keyword.URL: hxxp://de.search.yahoo.com/yhs/search?hspart=ddc&hsimp=yhs-ddc_bd&type=276_pr__alt__ddc_dss_bd_com&p=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-05] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-04] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-04] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2015-03-20] (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll [2015-03-20] (globalUpdate)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\user.js [2015-03-23]
FF SearchPlugin: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\searchplugins\search-simple.xml [2015-03-22]
FF Extension: BobyZoom - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\bbz@bobyzoom.com [2015-03-24]
FF Extension: deAli2idealit - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\Rc1@sSvOmat.net [2015-03-23]
FF Extension: Dynamo Combo 1.0.1 - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}.xpi [2015-03-22]
FF HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Firefox\Extensions: [{969E3CF4-34F8-788A-EDA2-1FF1929946D9}] - C:\Program Files (x86)\ver0CheckMeUp\190.xpi
FF Extension: CheckMeUp - C:\Program Files (x86)\ver0CheckMeUp\190.xpi [2015-03-20]
FF HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]

Chrome: 
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx

Opera: 
=======
OPR Extension: (HQCinema Pro 2.1V20.03) - C:\Users\ecp\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcjifdbedkcdkeegnoenkpiphjldpahf [2015-03-20]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

Locked "tammgF119" service could not be unlocked. <===== ATTENTION
Locked "tammgR119" service could not be unlocked. <===== ATTENTION

R2 9617fb41; c:\Program Files (x86)\SystemContinue\SystemContinue.dll [1609728 2015-03-22] () [File not signed]
R2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation)
R2 bobyzoom; C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [0 ] () <==== ATTENTION (zero size file/folder)
R2 bzwdg; C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [0 ] () <==== ATTENTION (zero size file/folder)
R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2014-12-11] () [File not signed]
R2 Gambali; C:\ProgramData\SecurityUtility\Gambali.exe [1793128 2015-03-20] (Gambali OEM Software) [File not signed]
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2015-03-20] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2015-03-20] (globalUpdate) [File not signed]
S2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [714624 2014-12-30] () [File not signed]
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation)
R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [7410024 2015-01-14] (Reimage®)
R2 SecurityUtility Service; C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe [379392 2015-03-20] () [File not signed]
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [49648 2015-01-15] ()
R2 Update Dynamo Combo; C:\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe [411376 2015-03-24] ()
R2 Util Dynamo Combo; C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.exe [411376 2015-03-24] ()
R2 Wajam Web Enhancer; C:\Program Files\WajaWebEnhancer\wajam_64.exe [1594368 2015-03-16] () [File not signed] <==== ATTENTION
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S4 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [473088 2014-12-30] () [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation)
R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-12-17] (Audials AG)
R5 tammgF119; C:\Windows\System32\Drivers\tammgF119.sys [26784 2015-03-20] () [File not signed]
R5 tammgR119; C:\Windows\System32\Drivers\tammgR119.sys [26272 2015-03-20] () [File not signed]
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
R2 webTinstMKTN; C:\Windows\system32\Drivers\webTinstMKTN.sys [50800 2015-03-20] ()
R1 {16a92140-918d-4afb-9edb-46f22437bb10}w64; C:\Windows\System32\drivers\{16a92140-918d-4afb-9edb-46f22437bb10}w64.sys [48792 2015-01-25] (StdLib)
R1 {228c1c19-dcaa-4969-9dee-95888fe6a45e}Gw64; C:\Windows\System32\drivers\{228c1c19-dcaa-4969-9dee-95888fe6a45e}Gw64.sys [48792 2014-12-30] (StdLib)
R1 {3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64; C:\Windows\System32\drivers\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64.sys [48792 2015-01-28] (StdLib)
R1 {641e52b1-3179-43ed-8bcb-f688871e52b0}w64; C:\Windows\System32\drivers\{641e52b1-3179-43ed-8bcb-f688871e52b0}w64.sys [48792 2015-01-19] (StdLib)
R1 {8d9208df-94f9-4c96-a224-97b37b0df94e}Gw64; C:\Windows\System32\drivers\{8d9208df-94f9-4c96-a224-97b37b0df94e}Gw64.sys [48792 2015-01-04] (StdLib)
R1 {915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64; C:\Windows\System32\drivers\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64.sys [48792 2015-01-22] (StdLib)
R1 {bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64; C:\Windows\System32\drivers\{bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64.sys [48792 2015-01-06] (StdLib)
R1 {ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}Gw64; C:\Windows\System32\drivers\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}Gw64.sys [48792 2015-01-13] (StdLib)
R1 {ecd6aae4-019c-44b2-a0e5-570904275d66}w64; C:\Windows\System32\drivers\{ecd6aae4-019c-44b2-a0e5-570904275d66}w64.sys [48792 2015-01-16] (StdLib)
R1 {ef3f84a6-599c-4148-a8eb-9aa938299b3e}Gw64; C:\Windows\System32\drivers\{ef3f84a6-599c-4148-a8eb-9aa938299b3e}Gw64.sys [48792 2014-12-31] (StdLib)
R1 {f81878fa-25e9-442d-8ada-79658b6520f2}Gw64; C:\Windows\System32\drivers\{f81878fa-25e9-442d-8ada-79658b6520f2}Gw64.sys [48792 2015-01-10] (StdLib)
S3 CAXHWAZL; system32\DRIVERS\CAXHWAZL.sys [X]
S3 cpuz134; \??\C:\Users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 HSF_DPV; system32\DRIVERS\CAX_DPV.sys [X]
S2 mdmxsdk; system32\DRIVERS\mdmxsdk.sys [X]
S3 winachsf; system32\DRIVERS\CAX_CNXT.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-26 21:28 - 2015-03-26 21:29 - 00000000 ____D () C:\FRST
2015-03-26 21:27 - 2015-03-26 21:27 - 00000000 _____ () C:\Users\ecp\defogger_reenable
2015-03-26 21:13 - 2015-03-26 21:28 - 00000000 ____D () C:\Reinigung
2015-03-23 09:18 - 2015-03-23 09:19 - 00000000 ____D () C:\Program Files (x86)\Simple Dictation
2015-03-23 09:18 - 2015-03-23 09:19 - 00000000 ____D () C:\Program Files (x86)\ddeallpeAuk
2015-03-23 09:17 - 2015-03-23 09:19 - 00000000 ____D () C:\Program Files (x86)\Saveitkeaep
2015-03-23 09:17 - 2015-03-23 09:19 - 00000000 ____D () C:\Program Files (x86)\deAli2idealit
2015-03-23 08:18 - 2015-03-24 19:03 - 00003452 _____ () C:\Windows\System32\Tasks\ProPCCleaner_Popup
2015-03-22 09:10 - 2015-03-22 09:10 - 00000000 ____D () C:\Users\ecp\AppData\Local\Macromedia
2015-03-22 09:09 - 2015-03-22 09:09 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-03-22 09:09 - 2015-03-22 09:09 - 00001154 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-03-22 09:09 - 2015-03-22 09:09 - 00000000 ____D () C:\Users\ecp\AppData\Local\Mozilla
2015-03-22 09:08 - 2015-03-22 09:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-22 08:52 - 2015-03-22 08:52 - 00002281 _____ () C:\Users\ecp\Desktop\Binkiland.lnk
2015-03-22 08:52 - 2015-03-22 08:52 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Binkiland
2015-03-22 08:52 - 2015-03-22 08:52 - 00000000 ____D () C:\Users\ecp\AppData\Local\Binkiland
2015-03-22 08:51 - 2015-03-24 18:51 - 00000284 _____ () C:\Windows\Tasks\Wse_binkiland.job
2015-03-22 08:51 - 2015-03-22 08:51 - 00003212 _____ () C:\Windows\System32\Tasks\Wse_binkiland
2015-03-22 08:51 - 2015-03-22 08:51 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Wse_binkiland
2015-03-22 08:50 - 2015-03-22 08:51 - 00000000 ____D () C:\Users\ecp\AppData\Local\WSE_Binkiland
2015-03-22 08:32 - 2015-03-22 08:32 - 00004020 _____ () C:\Windows\System32\Tasks\Check for Scheduled Updates
2015-03-22 08:30 - 2015-03-22 08:30 - 00000000 ____D () C:\Users\ecp\AppData\Local\32220c02-c108-4e43-b856-df7d87f70051
2015-03-22 08:10 - 2015-03-22 08:10 - 00000000 ____D () C:\ProgramData\OnlineLowDeals
2015-03-22 08:09 - 2015-03-23 13:04 - 00003122 _____ () C:\Windows\System32\Tasks\DriverDocRunAtStartup
2015-03-22 07:45 - 2015-03-22 07:45 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam Web Enhancer
2015-03-22 07:45 - 2015-03-22 07:45 - 00000000 ____D () C:\Program Files\WajaWebEnhancer
2015-03-22 07:43 - 2015-03-22 07:43 - 00000000 ____D () C:\Program Files (x86)\SystemContinue
2015-03-22 07:42 - 2015-03-22 07:42 - 00000000 ____D () C:\ProgramData\1887373585
2015-03-21 18:45 - 2015-03-21 18:45 - 02205072 _____ () C:\Windows\shost.bin
2015-03-21 18:22 - 2015-03-24 18:44 - 00000000 ____D () C:\Users\ecp\Documents\ProPCCleaner
2015-03-20 19:06 - 2015-03-26 21:16 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-03-20 18:52 - 2015-03-20 18:52 - 00004316 _____ () C:\Windows\System32\Tasks\RocketTab Update Task
2015-03-20 18:52 - 2015-03-20 18:52 - 00003530 _____ () C:\Windows\System32\Tasks\RocketTab
2015-03-20 18:52 - 2015-03-20 18:52 - 00003188 _____ () C:\Windows\System32\Tasks\ProPCCleaner_Start
2015-03-20 18:52 - 2015-03-20 18:52 - 00000000 ____D () C:\Users\ecp\AppData\Local\Pro_PC_Cleaner
2015-03-20 18:52 - 2015-03-20 18:52 - 00000000 ____D () C:\Program Files (x86)\Search Extensions
2015-03-20 18:50 - 2015-03-20 18:50 - 00001006 _____ () C:\Users\Public\Desktop\Pro PC Cleaner.lnk
2015-03-20 18:50 - 2015-03-20 18:50 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Pro PC Cleaner
2015-03-20 18:50 - 2015-03-20 18:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro PC Cleaner
2015-03-20 18:50 - 2015-03-20 18:50 - 00000000 ____D () C:\Program Files (x86)\Pro PC Cleaner
2015-03-20 18:49 - 2015-03-26 21:13 - 00008968 _____ () C:\Windows\SysWOW64\GambaliOff.ini
2015-03-20 18:49 - 2015-03-26 21:13 - 00008968 _____ () C:\Windows\system32\GambaliOff.ini
2015-03-20 18:49 - 2015-03-20 10:33 - 00398808 _____ (Gambali OEM Software) C:\Windows\system32\Gambali64.dll
2015-03-20 18:49 - 2015-03-20 10:33 - 00335768 _____ (Gambali OEM Software) C:\Windows\SysWOW64\Gambali.dll
2015-03-20 18:47 - 2015-03-26 21:16 - 00002444 _____ () C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5_user.job
2015-03-20 18:47 - 2015-03-26 21:16 - 00002444 _____ () C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.job
2015-03-20 18:47 - 2015-03-20 18:49 - 00000000 ____D () C:\ProgramData\SecurityUtility
2015-03-20 18:47 - 2015-03-20 18:47 - 00005474 _____ () C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5
2015-03-20 18:47 - 2015-03-20 18:47 - 00000000 ____D () C:\ProgramData\e314b8475a214ebc973cc42fbf8c6edf
2015-03-20 18:46 - 2015-03-26 21:16 - 00003472 _____ () C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.job
2015-03-20 18:46 - 2015-03-26 21:16 - 00003136 _____ () C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.job
2015-03-20 18:46 - 2015-03-20 18:46 - 00006502 _____ () C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7
2015-03-20 18:46 - 2015-03-20 18:46 - 00006164 _____ () C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6
2015-03-20 18:45 - 2015-03-26 21:16 - 00005182 _____ () C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.job
2015-03-20 18:45 - 2015-03-26 21:16 - 00002248 _____ () C:\Windows\patsearch.bin
2015-03-20 18:45 - 2015-03-26 21:16 - 00002110 _____ () C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10_user.job
2015-03-20 18:45 - 2015-03-26 21:16 - 00000954 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2015-03-20 18:45 - 2015-03-26 21:16 - 00000402 _____ () C:\Windows\Tasks\CheckMeUp Update.job
2015-03-20 18:45 - 2015-03-24 18:50 - 00000958 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2015-03-20 18:45 - 2015-03-20 18:47 - 00000000 ____D () C:\Program Files (x86)\HQCinema Pro 2.1V20.03
2015-03-20 18:45 - 2015-03-20 18:45 - 00008212 _____ () C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11
2015-03-20 18:45 - 2015-03-20 18:45 - 00003956 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2015-03-20 18:45 - 2015-03-20 18:45 - 00003702 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2015-03-20 18:45 - 2015-03-20 18:45 - 00003046 _____ () C:\Windows\System32\Tasks\CheckMeUp Update
2015-03-20 18:45 - 2015-03-20 18:45 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webTinstMKTN_01009.Wdf
2015-03-20 18:45 - 2015-03-20 18:45 - 00000000 ____D () C:\Users\ecp\AppData\Local\globalUpdate
2015-03-20 18:45 - 2015-03-20 18:45 - 00000000 ____D () C:\Program Files (x86)\ver0CheckMeUp
2015-03-20 18:45 - 2015-03-20 18:45 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2015-03-20 18:45 - 2015-03-20 18:44 - 00050800 _____ () C:\Windows\system32\Drivers\webTinstMKTN.sys
2015-03-20 18:43 - 2015-03-20 18:43 - 00026784 _____ () C:\Windows\system32\Drivers\tammgF119.sys
2015-03-20 18:43 - 2015-03-20 18:43 - 00026272 _____ () C:\Windows\system32\Drivers\tammgR119.sys
2015-03-20 18:43 - 2015-03-20 18:43 - 00000000 ____D () C:\ProgramData\bobyzoom
2015-03-20 07:05 - 2015-03-20 07:05 - 00003482 _____ () C:\Windows\System32\Tasks\Yahoo! Search Updater
2015-03-20 07:05 - 2015-03-20 07:05 - 00003478 _____ () C:\Windows\System32\Tasks\Yahoo! Search
2015-03-20 07:05 - 2015-03-20 07:05 - 00000000 ____D () C:\Users\ecp\AppData\Local\Pay-By-Ads
2015-03-18 08:05 - 2015-03-18 08:06 - 00002051 _____ () C:\Users\ecp\Downloads\Henner.txt
2015-03-17 07:53 - 2015-03-16 18:43 - 01274260 _____ () C:\Users\ecp\Documents\bskundenexcel201411.xls_0.ods
2015-03-17 07:53 - 2015-03-16 18:43 - 00017886 _____ () C:\Users\ecp\Documents\TennistrainingWinterHalle201415herren55he55mitersatzregelung.xls_0.ods
2015-03-13 09:11 - 2015-03-13 09:11 - 00959266 _____ () C:\Users\ecp\Downloads\doc.zip
2015-03-13 09:02 - 2015-03-13 09:02 - 00408667 _____ () C:\Users\ecp\Downloads\odt.zip
2015-03-11 08:58 - 2015-03-11 08:59 - 00000832 _____ () C:\Users\ecp\Downloads\download.html
2015-03-11 08:17 - 2015-02-03 04:34 - 05554104 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-11 08:17 - 2015-02-03 04:31 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-03-11 08:17 - 2015-02-03 04:31 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-03-11 08:17 - 2015-02-03 04:30 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-03-11 08:17 - 2015-02-03 04:30 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-03-11 08:17 - 2015-02-03 04:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2015-03-11 08:17 - 2015-02-03 04:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2015-03-11 08:17 - 2015-02-03 04:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2015-03-11 08:17 - 2015-02-03 04:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2015-03-11 08:16 - 2015-02-03 04:34 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-03-11 08:16 - 2015-02-03 04:34 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-03-11 08:16 - 2015-02-03 04:33 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-03-11 08:16 - 2015-02-03 04:31 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-03-11 08:16 - 2015-02-03 04:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-03-11 08:16 - 2015-02-03 04:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-03-11 08:16 - 2015-02-03 04:30 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-03-11 08:16 - 2015-02-03 04:30 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-03-11 08:16 - 2015-02-03 04:30 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-03-11 08:16 - 2015-02-03 04:30 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-03-11 08:16 - 2015-02-03 04:30 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-03-11 08:16 - 2015-02-03 04:30 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-03-11 08:16 - 2015-02-03 04:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-03-11 08:16 - 2015-02-03 04:30 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-03-11 08:16 - 2015-02-03 04:30 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-03-11 08:16 - 2015-02-03 04:30 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-03-11 08:16 - 2015-02-03 04:30 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-03-11 08:16 - 2015-02-03 04:30 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-03-11 08:16 - 2015-02-03 04:30 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-03-11 08:16 - 2015-02-03 04:30 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-03-11 08:16 - 2015-02-03 04:30 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-03-11 08:16 - 2015-02-03 04:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-03-11 08:16 - 2015-02-03 04:30 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-03-11 08:16 - 2015-02-03 04:30 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-03-11 08:16 - 2015-02-03 04:30 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-03-11 08:16 - 2015-02-03 04:30 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-03-11 08:16 - 2015-02-03 04:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-03-11 08:16 - 2015-02-03 04:30 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-03-11 08:16 - 2015-02-03 04:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2015-03-11 08:16 - 2015-02-03 04:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2015-03-11 08:16 - 2015-02-03 04:29 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2015-03-11 08:16 - 2015-02-03 04:28 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-03-11 08:16 - 2015-02-03 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-03-11 08:16 - 2015-02-03 04:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-03-11 08:16 - 2015-02-03 04:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-03-11 08:16 - 2015-02-03 04:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-03-11 08:16 - 2015-02-03 04:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2015-03-11 08:16 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2015-03-11 08:16 - 2015-02-03 04:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2015-03-11 08:16 - 2015-02-03 04:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2015-03-11 08:16 - 2015-02-03 04:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2015-03-11 08:16 - 2015-02-03 04:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2015-03-11 08:16 - 2015-02-03 04:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2015-03-11 08:16 - 2015-02-03 04:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-03-11 08:16 - 2015-02-03 03:32 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-03-11 08:16 - 2014-10-31 23:24 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-03-11 08:16 - 2014-06-28 01:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-03-11 08:16 - 2014-06-28 01:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-03-11 08:15 - 2015-02-20 05:41 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-03-11 08:15 - 2015-02-20 05:40 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-11 08:15 - 2015-02-20 04:29 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-11 08:15 - 2015-02-20 04:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-03-11 08:14 - 2015-02-20 05:40 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-03-11 08:14 - 2015-02-20 05:40 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-03-11 08:14 - 2015-02-20 05:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-03-11 08:14 - 2015-02-20 05:13 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-03-11 08:14 - 2015-02-20 05:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-03-11 08:14 - 2015-02-20 05:12 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-03-11 08:14 - 2015-01-31 04:48 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-03-11 08:14 - 2015-01-31 04:48 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 08:14 - 2015-01-31 00:56 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-03-11 08:13 - 2015-03-06 06:56 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-03-11 08:13 - 2015-03-06 06:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-03-11 08:13 - 2015-03-06 06:42 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-03-11 08:13 - 2015-03-06 06:42 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-03-11 08:13 - 2015-03-06 06:42 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-11 08:13 - 2015-03-06 06:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-03-11 08:13 - 2015-03-06 06:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-03-11 08:13 - 2015-03-06 06:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-03-11 08:13 - 2015-03-06 06:42 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-03-11 08:13 - 2015-03-06 06:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-03-11 08:13 - 2015-03-06 06:42 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-03-11 08:13 - 2015-03-06 06:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-03-11 08:13 - 2015-03-06 06:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-03-11 08:13 - 2015-03-06 06:41 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-03-11 08:13 - 2015-03-06 06:41 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-03-11 08:13 - 2015-03-06 06:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-03-11 08:13 - 2015-03-06 06:38 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-03-11 08:13 - 2015-03-06 06:36 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-03-11 08:13 - 2015-03-06 06:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-03-11 08:13 - 2015-03-06 06:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-03-11 08:13 - 2015-03-06 06:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-03-11 08:13 - 2015-03-06 06:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-03-11 08:13 - 2015-03-06 06:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-03-11 08:13 - 2015-03-06 06:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-03-11 08:13 - 2015-03-06 06:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-03-11 08:13 - 2015-03-06 06:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-03-11 08:13 - 2015-03-06 06:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-03-11 08:13 - 2015-03-06 06:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-03-11 08:13 - 2015-03-06 06:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-03-11 08:13 - 2015-03-06 06:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-03-11 08:13 - 2015-03-06 06:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-03-11 08:13 - 2015-02-13 06:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-03-11 08:13 - 2015-02-13 06:22 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-11 08:13 - 2015-02-03 04:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-11 08:13 - 2015-02-03 04:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
2015-03-11 08:13 - 2015-01-31 00:56 - 00459336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-03-11 08:12 - 2015-02-26 04:25 - 03204096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-11 08:12 - 2015-02-24 04:15 - 00389800 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-11 08:12 - 2015-02-24 03:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-03-11 08:12 - 2015-02-21 01:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-03-11 08:12 - 2015-02-21 01:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-03-11 08:12 - 2015-02-21 01:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-03-11 08:12 - 2015-02-21 01:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-03-11 08:12 - 2015-02-21 00:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-03-11 08:12 - 2015-02-20 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-03-11 08:12 - 2015-02-20 04:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 08:12 - 2015-02-20 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-03-11 08:12 - 2015-02-20 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-03-11 08:12 - 2015-02-20 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-03-11 08:12 - 2015-02-20 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 08:12 - 2015-02-20 03:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-03-11 08:12 - 2015-02-20 03:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 08:12 - 2015-02-20 03:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-03-11 08:12 - 2015-02-20 03:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-03-11 08:12 - 2015-02-20 03:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-03-11 08:12 - 2015-02-20 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-11 08:12 - 2015-02-20 03:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-03-11 08:12 - 2015-02-20 03:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-03-11 08:12 - 2015-02-20 03:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-03-11 08:12 - 2015-02-20 02:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-03-11 08:12 - 2015-02-20 02:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-03-11 08:12 - 2015-02-20 02:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-03-11 08:12 - 2015-02-20 02:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-11 08:12 - 2015-02-20 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-03-11 08:12 - 2015-02-20 02:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-03-11 08:12 - 2015-02-20 02:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-03-11 08:12 - 2015-02-20 02:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-03-11 08:12 - 2015-02-20 02:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-11 08:12 - 2015-02-20 01:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-03-11 08:12 - 2015-02-20 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-03-11 08:12 - 2015-02-03 04:31 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-11 08:12 - 2015-02-03 04:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-03-11 08:12 - 2015-01-17 03:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-11 08:12 - 2015-01-17 03:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2015-03-11 08:11 - 2015-02-21 02:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-11 08:11 - 2015-02-21 00:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-11 08:11 - 2015-02-20 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-03-11 08:11 - 2015-02-20 03:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-11 08:11 - 2015-02-20 03:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-11 08:11 - 2015-02-20 03:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-11 08:11 - 2015-02-20 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-03-11 08:11 - 2015-02-20 03:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-03-11 08:11 - 2015-02-20 03:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-03-11 08:11 - 2015-02-20 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-11 08:11 - 2015-02-20 03:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-11 08:11 - 2015-02-20 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-03-11 08:11 - 2015-02-20 03:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-03-11 08:11 - 2015-02-20 03:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-03-11 08:11 - 2015-02-20 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-03-11 08:11 - 2015-02-20 02:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-11 08:11 - 2015-02-20 02:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-11 08:11 - 2015-02-20 02:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-03-11 08:11 - 2015-02-20 02:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-03-11 08:11 - 2015-02-20 02:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-11 08:11 - 2015-02-20 02:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-03-11 08:11 - 2015-02-20 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-11 08:11 - 2015-02-20 02:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-03-11 08:06 - 2015-02-04 04:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-11 08:06 - 2015-02-04 03:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2015-03-06 07:48 - 2015-03-06 07:51 - 00000000 ____D () C:\Program Files (x86)\SoaleEsChoeocKeirr
2015-03-05 17:07 - 2015-03-05 17:07 - 00000000 ____D () C:\ProgramData\Auslogics
2015-03-05 17:06 - 2015-03-05 17:06 - 00001298 _____ () C:\Users\ecp\Desktop\Auslogics Duplicate File Finder.lnk
2015-03-05 17:06 - 2015-03-05 17:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
2015-03-05 17:06 - 2015-03-05 17:06 - 00000000 ____D () C:\Program Files (x86)\Auslogics
2015-03-05 17:05 - 2015-03-05 17:05 - 06929688 _____ (Auslogics Labs Pty Ltd ) C:\Users\ecp\Downloads\duplicate-file-finder-setup.exe
2015-03-05 16:57 - 2015-03-05 17:02 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\FreeFileSync
2015-03-05 16:56 - 2015-03-05 16:56 - 00385602 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS
2015-03-05 16:56 - 2015-03-05 16:56 - 00000951 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeFileSync.lnk
2015-03-05 16:56 - 2015-03-05 16:56 - 00000941 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealtimeSync.lnk
2015-03-05 16:56 - 2015-03-05 16:56 - 00000939 _____ () C:\Users\Public\Desktop\FreeFileSync.lnk
2015-03-05 16:56 - 2015-03-05 16:56 - 00000929 _____ () C:\Users\Public\Desktop\RealtimeSync.lnk
2015-03-05 16:56 - 2015-03-05 16:56 - 00000232 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS.part
2015-03-05 16:56 - 2015-03-05 16:56 - 00000000 ____D () C:\Users\ecp\AppData\Local\145842EF_stp
2015-03-05 16:56 - 2015-03-05 16:56 - 00000000 ____D () C:\Program Files\FreeFileSync
2015-03-05 16:55 - 2015-03-05 16:55 - 12653536 _____ (www.FreeFileSync.org ) C:\Users\ecp\Downloads\freefilesync_6.14_windows_setup.exe
2015-03-05 16:55 - 2015-03-05 16:55 - 12653536 _____ (www.FreeFileSync.org ) C:\Users\ecp\Downloads\freefilesync_6.14_windows_setup (1).exe
2015-03-05 16:28 - 2015-03-05 16:28 - 00000000 ___HD () C:\ProgramData\CanonIJScan
2015-03-05 16:28 - 2015-03-05 16:28 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Canon
2015-03-05 08:19 - 2015-03-05 08:19 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-03-05 08:19 - 2015-03-05 08:19 - 00000000 ___HD () C:\ProgramData\CanonIJFAX
2015-03-05 08:19 - 2015-03-05 08:19 - 00000000 ____D () C:\Windows\system32\appraiser
2015-03-05 08:18 - 2011-09-21 05:00 - 00302592 _____ (CANON INC.) C:\Windows\system32\CNCALB0.DLL
2015-03-05 08:17 - 2015-03-05 08:17 - 00000000 ___HD () C:\Windows\system32\CanonIJ Uninstaller Information
2015-03-05 08:17 - 2015-03-05 08:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX370 series
2015-03-05 08:17 - 2011-10-14 11:57 - 00300544 _____ (CANON INC.) C:\Windows\system32\CNC_B0C.dll
2015-03-05 08:17 - 2011-10-14 11:57 - 00102912 _____ (CANON INC.) C:\Windows\SysWOW64\CNC_B0U.dll
2015-03-05 08:17 - 2011-10-14 11:56 - 00109568 _____ (CANON INC.) C:\Windows\system32\CNC_B0I.dll
2015-03-05 08:17 - 2011-09-22 08:59 - 00358912 _____ (CANON INC.) C:\Windows\system32\CNC_B0L.dll
2015-03-05 08:17 - 2011-09-22 08:57 - 00316416 _____ (CANON INC.) C:\Windows\SysWOW64\CNC_B0L.dll
2015-03-05 08:17 - 2011-06-30 13:35 - 00065280 _____ () C:\Windows\SysWOW64\CNC1759D.TBL
2015-03-05 08:17 - 2011-06-30 13:35 - 00065280 _____ () C:\Windows\system32\CNC1759D.TBL
2015-03-05 08:17 - 2008-08-25 18:02 - 00017920 _____ (CANON INC.) C:\Windows\system32\CNHMCA6.dll
2015-03-05 08:17 - 2008-08-25 18:02 - 00015872 _____ (CANON INC.) C:\Windows\SysWOW64\CNHMCA.dll
2015-03-05 08:15 - 2011-11-03 05:00 - 00385024 _____ (CANON INC.) C:\Windows\system32\CNMLMB0.DLL
2015-03-05 07:43 - 2015-01-09 00:44 - 00419936 _____ () C:\Windows\SysWOW64\locale.nls
2015-03-05 07:43 - 2015-01-09 00:43 - 00419936 _____ () C:\Windows\system32\locale.nls
2015-03-05 07:28 - 2014-06-27 03:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2015-03-05 07:28 - 2014-06-27 02:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2015-03-04 09:13 - 2015-03-04 09:17 - 00047447 _____ () C:\Users\ecp\Documents\MyMicroBalance.mmb
2015-03-04 09:13 - 2015-03-04 09:13 - 00000000 ____D () C:\Users\ecp\Documents\backup_MyMicroBalance
2015-03-04 09:12 - 2015-03-04 09:12 - 00000000 ____D () C:\Users\ecp\Documents\BSHTOP332SA
2015-03-04 07:37 - 2015-01-09 04:14 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
2015-03-04 07:37 - 2015-01-09 04:14 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll
2015-03-04 07:37 - 2015-01-09 04:14 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll
2015-03-04 07:37 - 2015-01-09 03:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdi.dll
2015-03-04 07:36 - 2015-02-04 04:16 - 00894976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-03-04 07:36 - 2015-02-04 04:16 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-03-04 07:36 - 2015-02-04 04:16 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-03-04 07:36 - 2015-02-04 04:16 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-03-04 07:36 - 2015-02-04 04:16 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-03-04 07:36 - 2015-02-04 04:16 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-03-04 07:36 - 2015-02-04 04:13 - 01098752 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-03-04 07:36 - 2015-01-28 00:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-03-04 07:36 - 2014-08-01 12:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2015-03-04 07:36 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2015-03-04 07:35 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2015-03-04 07:35 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2015-03-04 07:35 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2015-03-04 07:35 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2015-03-04 07:35 - 2014-07-09 03:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2015-03-04 07:35 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2015-03-04 07:35 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2015-03-04 07:35 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2015-03-04 07:35 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2015-03-04 07:35 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2015-03-04 07:35 - 2014-06-24 04:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-03-04 07:35 - 2014-06-24 03:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2015-03-04 07:34 - 2014-11-26 04:53 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-03-04 07:34 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2015-03-04 07:34 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-03-04 07:34 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-03-04 07:34 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-03-04 07:34 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2015-03-04 07:34 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2015-03-04 07:34 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2015-03-04 07:34 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2015-03-04 07:34 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2015-03-04 07:34 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2015-03-04 07:34 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2015-03-04 07:34 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2015-03-04 07:34 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2015-03-04 07:34 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2015-03-04 07:34 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2015-03-04 07:34 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2015-03-04 07:33 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-03-04 07:33 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2015-03-04 07:31 - 2014-09-05 03:11 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-03-04 07:31 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-03-02 13:21 - 2015-03-02 13:21 - 00000291 _____ () C:\Users\ecp\Downloads\BK_RHDE_002347DE_LC_64_44100_ster_A2D4MN5C3DWNEX.adh
2015-03-02 13:21 - 2015-03-02 13:21 - 00000291 _____ () C:\Users\ecp\Downloads\admhelper (2).adh
2015-03-02 13:17 - 2015-03-02 13:24 - 00000000 ____D () C:\Users\ecp\AppData\Local\Audible
2015-03-02 13:17 - 2015-03-02 13:17 - 00255352 _____ (Audible, Inc.) C:\Windows\SysWOW64\awrdscdc.ax
2015-03-02 13:17 - 2015-03-02 13:17 - 00001972 _____ () C:\Users\ecp\Desktop\Audible Manager.lnk
2015-03-02 13:17 - 2015-03-02 13:17 - 00000340 _____ () C:\Users\ecp\Downloads\BK_RHDE_002360DE_LC_64_44100_ster_A2D4MN5C3DWNEX.adh
2015-03-02 13:17 - 2015-03-02 13:17 - 00000291 _____ () C:\Users\ecp\Downloads\admhelper.adh
2015-03-02 13:17 - 2015-03-02 13:17 - 00000291 _____ () C:\Users\ecp\Downloads\admhelper (1).adh
2015-03-02 13:17 - 2015-03-02 13:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudibleManager
2015-03-02 13:16 - 2015-03-02 13:17 - 00000000 ____D () C:\Users\ecp\Documents\Audible
2015-03-02 13:16 - 2015-03-02 13:17 - 00000000 ____D () C:\Program Files (x86)\Audible
2015-03-02 13:16 - 2015-03-02 13:16 - 00000000 ____D () C:\Users\Public\Documents\Audible
2015-03-02 13:16 - 2003-03-18 21:20 - 01060864 ____N (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
2015-03-02 13:16 - 2001-08-17 22:43 - 00024576 ____N (Microsoft Corporation) C:\Windows\SysWOW64\msxml3a.dll
2015-03-02 13:15 - 2015-03-02 13:15 - 01730272 _____ (Audible Inc.) C:\Users\ecp\Downloads\ActiveSetupN (1).exe
2015-03-02 13:14 - 2015-03-02 13:14 - 01730272 _____ (Audible Inc.) C:\Users\ecp\Downloads\ActiveSetupN.exe
2015-03-02 10:54 - 2015-03-17 23:27 - 00000000 ____D () C:\Users\ecp\Documents\Martina60Geburtstag20150406
2015-03-01 12:41 - 2015-03-01 12:41 - 00001047 _____ () C:\Users\ecp\Desktop\Android - Verknüpfung.lnk
2015-02-25 18:42 - 2015-02-25 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2015-02-25 18:42 - 2015-02-25 18:42 - 00000000 ____D () C:\Program Files\7-Zip
2015-02-25 18:41 - 2015-02-25 18:41 - 01376768 _____ () C:\Users\ecp\Documents\7z920-x64.msi

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-26 21:28 - 2015-01-01 11:27 - 00000284 _____ () C:\Windows\Tasks\WSE_Vosteran.job
2015-03-26 21:27 - 2015-01-01 11:26 - 00000284 _____ () C:\Windows\Tasks\Price Fountain.job
2015-03-26 21:27 - 2014-12-30 15:50 - 00000000 ____D () C:\Users\ecp
2015-03-26 21:27 - 2011-04-12 08:43 - 00698926 _____ () C:\Windows\system32\perfh007.dat
2015-03-26 21:27 - 2011-04-12 08:43 - 00149034 _____ () C:\Windows\system32\perfc007.dat
2015-03-26 21:27 - 2009-07-14 06:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-26 21:27 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-26 21:27 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-26 21:26 - 2014-11-25 11:56 - 01737377 _____ () C:\Windows\WindowsUpdate.log
2015-03-26 21:24 - 2009-07-14 05:51 - 00059730 _____ () C:\Windows\setupact.log
2015-03-26 21:13 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-26 21:12 - 2014-12-30 16:33 - 00000000 ____D () C:\Program Files (x86)\Dynamo Combo
2015-03-24 19:08 - 2014-07-23 10:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-24 18:49 - 2015-01-01 14:35 - 00000000 ____D () C:\Users\ecp\Documents\112 wiederkehrende dateien 1412
2015-03-24 18:19 - 2015-01-01 11:20 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Skype
2015-03-24 17:26 - 2015-01-01 12:26 - 00000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG
2015-03-24 17:22 - 2009-07-14 03:34 - 00000505 _____ () C:\Windows\win.ini
2015-03-24 08:15 - 2015-01-02 12:37 - 00040478 _____ () C:\Windows\system32\ScanResults.xml
2015-03-24 08:08 - 2015-01-02 12:32 - 00000464 _____ () C:\Windows\system32\ScannerSettings
2015-03-24 08:06 - 2014-12-30 16:35 - 00003236 _____ () C:\Windows\System32\Tasks\PC Speed Maximizer Schedule
2015-03-23 09:18 - 2015-02-04 21:49 - 00000000 ____D () C:\ProgramData\15483481001080132652
2015-03-23 07:32 - 2015-01-01 23:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-22 09:09 - 2015-01-01 23:29 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Mozilla
2015-03-22 08:50 - 2014-12-31 10:40 - 00000000 ____D () C:\Users\ecp\AppData\Local\Adobe
2015-03-19 20:07 - 2014-12-30 16:38 - 00003848 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1419953902
2015-03-19 20:07 - 2014-12-30 16:37 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-03-19 20:05 - 2015-02-08 12:08 - 00000000 ____D () C:\Users\ecp\Documents\Tennisclub
2015-03-18 12:26 - 2015-02-12 12:26 - 00000274 _____ () C:\Windows\Tasks\DriverDoc_UPDATES.job
2015-03-16 19:21 - 2014-07-23 10:43 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-03-16 19:21 - 2014-07-23 10:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-03-16 19:21 - 2014-07-23 10:43 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-03-16 12:57 - 2015-02-08 12:09 - 00000000 ____D () C:\Users\ecp\Documents\Privates
2015-03-13 08:40 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2015-03-13 08:35 - 2009-07-14 05:45 - 00298232 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-13 08:31 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2015-03-13 08:31 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\Dism
2015-03-13 08:15 - 2014-07-22 16:37 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-13 08:06 - 2014-07-22 16:37 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-03-11 21:30 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2015-03-11 08:00 - 2015-01-06 11:05 - 00000000 ____D () C:\Program Files (x86)\GTS
2015-03-09 18:16 - 2015-02-08 12:09 - 00000000 ____D () C:\Users\ecp\Documents\NBV
2015-03-09 11:13 - 2015-02-16 18:42 - 00000000 ____D () C:\Users\ecp\Documents\Camera
2015-03-06 08:02 - 2015-01-21 06:59 - 00000000 ____D () C:\ProgramData\woEbsauVer
2015-03-06 08:02 - 2015-01-20 07:39 - 00000000 ____D () C:\ProgramData\SmaaritCoimepare
2015-03-06 08:02 - 2015-01-20 07:38 - 00000000 ____D () C:\ProgramData\saFerwEb
2015-03-06 07:48 - 2015-02-20 08:19 - 00000000 ____D () C:\Program Files (x86)\SaleisuCheccker
2015-03-06 07:48 - 2015-02-07 03:30 - 00000000 ____D () C:\Program Files (x86)\RoyAlCeOupoen
2015-03-05 08:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing
2015-03-05 08:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2015-03-05 08:18 - 2009-07-14 04:20 - 00000000 __RSD () C:\Windows\Media
2015-03-04 09:17 - 2015-02-04 18:15 - 00001874 _____ () C:\Users\ecp\AppData\Roaming\MyMicroBalanceConfig.ini
2015-03-03 14:17 - 2010-11-21 04:27 - 00295552 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-03-01 10:48 - 2015-01-03 01:27 - 00000010 _____ () C:\Users\ecp\AppData\Local\DSI.DAT
2015-02-26 18:09 - 2010-11-21 04:47 - 00028536 _____ () C:\Windows\PFRO.log

==================== Files in the root of some directories =======

2015-02-04 18:15 - 2015-03-04 09:17 - 0001874 _____ () C:\Users\ecp\AppData\Roaming\MyMicroBalanceConfig.ini
2015-01-01 12:26 - 2015-03-24 17:26 - 0000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG
2015-03-05 16:56 - 2015-03-05 16:56 - 0385602 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS
2015-03-05 16:56 - 2015-03-05 16:56 - 0000232 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS.part
2015-01-03 01:27 - 2015-03-01 10:48 - 0000010 _____ () C:\Users\ecp\AppData\Local\DSI.DAT
2015-01-03 01:27 - 2015-01-03 01:27 - 0022528 _____ () C:\Users\ecp\AppData\Local\dsisetup1374062732.exe

Some content of TEMP:
====================
C:\Users\ecp\AppData\Local\Temp\4754A20B-48BD-0A59-3FE0-3CDF5D1052F8.dll
C:\Users\ecp\AppData\Local\Temp\4754A20B-48BD-0A59-3FE0-3CDF5D1052F8.exe
C:\Users\ecp\AppData\Local\Temp\APNSetup.exe
C:\Users\ecp\AppData\Local\Temp\c1ef6.exe
C:\Users\ecp\AppData\Local\Temp\dcacabfcdbaj.exe
C:\Users\ecp\AppData\Local\Temp\FF28C860-5054-21EF-E5E1-FBD2C802FC5E.exe
C:\Users\ecp\AppData\Local\Temp\gmx_mediacenter_setup_a201412.exe
C:\Users\ecp\AppData\Local\Temp\ICSW_0A1Q1B1P1T1C1R1M1P1B1V0C0H0N0LtC.exe
C:\Users\ecp\AppData\Local\Temp\OnlineBackup.exe
C:\Users\ecp\AppData\Local\Temp\optprosetup.exe
C:\Users\ecp\AppData\Local\Temp\ReimagePackage.exe
C:\Users\ecp\AppData\Local\Temp\Setup.exe
C:\Users\ecp\AppData\Local\Temp\SPINT-G.exe
C:\Users\ecp\AppData\Local\Temp\SpOrder.dll
C:\Users\ecp\AppData\Local\Temp\standaloneupdater-setup.exe
C:\Users\ecp\AppData\Local\Temp\System.Data.SQLite.dll
C:\Users\ecp\AppData\Local\Temp\System.Data.SQLite9230e067-1b8f-4b92-9e2c-41da44fb0fa8.dll
C:\Users\ecp\AppData\Local\Temp\vcredist_x64.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-11 18:40

==================== End Of Log ============================
         

Addition:
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
Ran by ecp at 2015-03-26 21:31:35
Running from C:\Reinigung
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 17 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Anzeige am Bildschirm (HKLM\...\OnScreenDisplay) (Version: 6.73.01 - )
Ashampoo Burning Studio 2015 v.1.15.0 (HKLM-x32\...\{91B33C97-21E3-DF34-9630-2EE80DDE1648}_is1) (Version: 1.15.0 - Ashampoo GmbH & Co. KG)
Audials (HKLM-x32\...\{AB509249-C384-4607-BED0-8C9167BE74B1}) (Version: 11.0.56100.0 - Audials AG)
AudibleManager (HKLM-x32\...\AudibleManager) (Version: 2003188990.48.56.2493674 - Audible, Inc.)
Auslogics Duplicate File Finder (HKLM-x32\...\{6845255F-15CC-4DD1-94D5-D38F370118B3}_is1) (Version: 4.3.0.0 - Auslogics Labs Pty Ltd)
Binkiland (HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Binkiland) (Version: 31.0.1650.23 - Binkiland) <==== ATTENTION!
bobyzoom (HKLM-x32\...\{9D8D5AD9-94C7-40B3-88F2-2B8F227F6381}) (Version: 1.1.0.30 - bobyzoom)
Buzzdock (HKLM\...\{ac225167-00fc-452d-94c5-bb93600e7d9a}) (Version:  - Alactro LLC) <==== ATTENTION
Canon MX370 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX370_series) (Version:  - )
Canon MX370 series On-screen Manual (HKLM-x32\...\Canon MX370 series On-screen Manual) (Version:  - )
CheckMeUp (HKLM-x32\...\C441D512-F5C2-07AC-8AE0-499C197A5D55) (Version:  - CheckMeUp-software)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dienstprogramm "ThinkPad UltraNav" (HKLM-x32\...\{17CBC505-D1AE-459D-B445-3D2000A85842}) (Version: 2.13.0 - Lenovo)
DiskBoss 5.1.12 (HKLM-x32\...\DiskBoss) (Version: 5.1.12 - Flexense Computing Systems Ltd.)
DriverDoc (HKLM-x32\...\DriverDoc_is1) (Version: 1.52.1086.14425 - Solvusoft Corporation)
Dynamo Combo (HKLM\...\Dynamo Combo) (Version: 2014.12.30.132317 - Dynamo Combo) <==== ATTENTION
Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
FreeFileSync 6.14 (HKLM-x32\...\FreeFileSync_is1) (Version: 6.14 - www.FreeFileSync.org)
GTS  (HKLM-x32\...\{29726780-AB28-466D-87E3-678DA41D2264}) (Version: 1.00.17 - vwd AG)
HQCinema Pro 2.1V20.03 (HKLM-x32\...\HQCinema Pro 2.1V20.03) (Version: 1.36.01.22 - HQ CinemaV20.03)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.04.05 - )
Lenovo System Interface Driver (HKLM\...\LENOVO.SMIIF) (Version: 1.05 - )
Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.06.0027 - Lenovo)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.150.1 - McAfee, Inc.)
Metric Collection SDK (x32 Version: 1.1.0005.00 - Lenovo Group Limited) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.7.205.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 36.0.4 (x86 de) (HKLM-x32\...\Mozilla Firefox 36.0.4 (x86 de)) (Version: 36.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 36.0.4 - Mozilla)
Mozilla Thunderbird 31.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.4.0 (x86 de)) (Version: 31.4.0 - Mozilla)
MyMicroBalance (HKLM-x32\...\{F508CC9F-A477-4C15-A9FE-59BCE258F839}) (Version: 3.0.3 - startzentrum GmbH & Co KG)
OnlineLowDeals (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version:  - OnlineLowDeals) <==== ATTENTION
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
Opera Stable 28.0.1750.48 (HKLM-x32\...\Opera 28.0.1750.48) (Version: 28.0.1750.48 - Opera Software ASA)
PC Speed Maximizer v4.0 (HKLM-x32\...\PC Speed Maximizer_is1) (Version: 4.0 - Smart PC Solutions)
PriceFountain (remove only) (HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\PriceFountain) (Version: 1.0.8.6 - Price Fountain) <==== ATTENTION!
Pro PC Cleaner (HKLM-x32\...\{C3060724-6AC7-4BEF-B516-4F6B1D90887D}) (Version: 2.5.5 - Pro PC Cleaner)
Reimage Repair (HKLM\...\Reimage Repair) (Version: 1.8.0.4 - Reimage) <==== ATTENTION
RICOH R5U8xx Media Driver ver.3.64.02 (HKLM-x32\...\{59F6A514-9813-47A3-948C-8A155460CC2A}) (Version: 3.64.02 - RICOH)
RocketTab (HKLM-x32\...\RocketTab) (Version:  - RocketTab) <==== ATTENTION!
Saveitkeaep. (HKLM-x32\...\{B10BC31B-DBC6-56FE-DD3D-DD4E49A3E6CE}) (Version:  - "") <==== ATTENTION
SecurityUtility Service (HKLM-x32\...\SecurityUtility Service) (Version:  - )
Skype™ 6.3 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.3.105 - Skype Technologies S.A.)
SoundMAX (HKLM-x32\...\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 6.10.2.7255 - Analog Devices)
SystemContinue (HKLM-x32\...\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{9617fb41}) (Version:  - Software Publisher) <==== ATTENTION
ThinkPad FullScreen Magnifier (HKLM\...\ThinkPad FullScreen Magnifier) (Version: 2.42 - )
ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.19.7 - )
Update for PriceFountain (HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Price Fountain) (Version:  - Update for PriceFountain) <==== ATTENTION
vi-view uninstall (HKLM-x32\...\vi-view uninstall) (Version:  - vi-view) <==== ATTENTION
Vosteran (HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Vosteran) (Version: 31.0.1650.23 - Vosteran) <==== ATTENTION!
Wajam (HKLM-x32\...\Wajam Web Enhancer) (Version: 1.41.1.2 (i1.0) - Wajam) <==== ATTENTION
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WSE_Binkiland (HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\WSE_Binkiland) (Version:  - WSE_Binkiland) <==== ATTENTION!
WSE_Vosteran (HKLM-x32\...\WSE_Vosteran) (Version:  - WSE_Vosteran) <==== ATTENTION!
Yahoo! Search (HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Yahoo! Search) (Version:  - Pay-By-Ads) <==== ATTENTION

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-1780445102-594666999-3139876592-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1780445102-594666999-3139876592-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1780445102-594666999-3139876592-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1780445102-594666999-3139876592-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1780445102-594666999-3139876592-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation)

==================== Restore Points  =========================

11-03-2015 16:47:20 Windows Update
13-03-2015 08:00:07 Windows Update
15-03-2015 19:00:32 Windows-Sicherung
17-03-2015 01:12:29 Windows Update
20-03-2015 19:25:59 Windows Update
23-03-2015 07:20:51 Windows-Sicherung
23-03-2015 08:19:56 Wiederherstellungsvorgang
24-03-2015 08:27:24 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0B21BA66-C60F-4200-8560-804717DAD7FD} - System32\Tasks\Reimage Reminder => C:\Program Files\Reimage\Reimage Repair\ReimageReminder.exe [2015-01-18] () <==== ATTENTION
Task: {414B3EBC-9594-4211-8083-6E6540AF2EFC} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe
Task: {4455D852-903D-44A8-876D-4358378E4D9E} - System32\Tasks\RocketTab Update Task => C:\Program Files (x86)\Search Extensions\uninstall.exe [2015-03-20] () <==== ATTENTION
Task: {55282CB5-1012-4A50-89B5-FAD8E5BDD42A} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-03-20] (globalUpdate) <==== ATTENTION
Task: {574481C6-4D86-4C9A-931D-6B5C43CC638B} - System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5 => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.exe [2015-03-20] (HQ CinemaV20.03) <==== ATTENTION
Task: {57D8A394-980F-47D4-B751-2D2680575048} - System32\Tasks\Opera scheduled Autoupdate 1419953902 => C:\Program Files (x86)\Opera\launcher.exe [2015-03-16] (Opera Software)
Task: {66523849-E0E7-4688-B4DF-6647DBF3D634} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-02-13] (Lenovo)
Task: {66EFCD3A-186E-440C-A78D-48E94C27C78C} - System32\Tasks\ProPCCleaner_Popup => C:\Program Files (x86)\Pro PC Cleaner\Splash.exe [2014-07-14] () <==== ATTENTION
Task: {67C8C4B8-B53B-474F-BF84-74B85B1A2DE1} - System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7 => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.exe [2015-03-20] (HQ CinemaV20.03) <==== ATTENTION
Task: {6BDC9C59-4CEF-45F7-9636-76251F5B3D87} - System32\Tasks\RocketTab => cmd.exe /C start "" "C:\Program Files (x86)\Search Extensions\Client.exe" /Preferred=true <==== ATTENTION
Task: {6F28B60D-6818-4A76-B437-A0121AFA54B8} - System32\Tasks\Price Fountain => C:\Users\ecp\AppData\Roaming\PriceFountain\UpdateProc\UpdateTask.exe [2015-01-01] () <==== ATTENTION
Task: {6FA935E0-A985-4B73-9D19-84541B6D89B9} - System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10_user => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10.exe [2015-03-20] (HQ CinemaV20.03) <==== ATTENTION
Task: {84D26E5B-B196-4696-A46B-580CACB57449} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-03-20] (globalUpdate) <==== ATTENTION
Task: {84F8A2C5-F194-41CE-8FC6-26E4E2D52F30} - System32\Tasks\DriverDocRunAtStartup => C:\Program Files (x86)\DriverDoc\Solvusoftdd.exe [2012-10-05] (Solvusoft Corporation)
Task: {8BDDE8B0-6B6A-4CD5-A7CE-EAD36E2AB679} - System32\Tasks\Check for Scheduled Updates => C:\Users\ecp\AppData\Local\32220c02-c108-4e43-b856-df7d87f70051\CheckUpdate.exe [2015-03-22] (7ade0034-261e-4998-bb90-451ac52a6732)
Task: {967F4A34-78A8-422F-ADFB-63A2A923F8F9} - System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11 => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.exe [2015-03-20] (HQ CinemaV20.03) <==== ATTENTION
Task: {A541A9A1-8A3D-46BD-9FEC-049F2C2914E8} - System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6 => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.exe [2015-03-20] (HQ CinemaV20.03) <==== ATTENTION
Task: {A6421EDD-8339-423B-92DC-E2868FC40CC1} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\JustCloud\Signup Wizard.exe
Task: {ADAA2B28-03F0-493B-87D4-F8985769B4B3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-03-16] (Adobe Systems Incorporated)
Task: {B50B3FC4-6FF9-4EB6-82B1-F5FB7DAA45B5} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2015-01-15] ()
Task: {B5AF85BA-CD3C-4D50-9158-F6E4408ACEB0} - System32\Tasks\Wse_binkiland => C:\Users\ecp\AppData\Roaming\Wse_binkiland\UpdateProc\UpdateTask.exe [2015-03-22] () <==== ATTENTION
Task: {B6A9971E-16C3-400E-8ACB-38B1D07F16A1} - System32\Tasks\PC Speed Maximizer Schedule => C:\Program Files (x86)\PC Speed Maximizer\SPMSchedule.exe [2014-11-20] (Avanquest Software)
Task: {BCC3FDEB-E540-48C5-B644-BA8E8980CFAC} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [2015-01-14] (Reimage®) <==== ATTENTION
Task: {C7AC4434-F9CE-48BF-A268-DEE29E14B07D} - System32\Tasks\CheckMeUp Update => C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe [2015-03-20] ()
Task: {C8C6A4AE-5F26-4FD0-875C-508B7FE68A54} - System32\Tasks\WSE_Vosteran => C:\Users\ecp\AppData\Roaming\WSE_Vosteran\UpdateProc\UpdateTask.exe [2015-01-01] () <==== ATTENTION
Task: {D3B1594F-167E-4429-B45E-3E9FB1DFCB91} - System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5_user => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.exe [2015-03-20] (HQ CinemaV20.03) <==== ATTENTION
Task: {D699591C-6656-49C5-BD87-8860FD43C735} - System32\Tasks\DriverDoc_UPDATES => C:\Program Files (x86)\DriverDoc\Solvusoftdd.exe [2012-10-05] (Solvusoft Corporation)
Task: {E0FDBA42-2C94-4380-BC4A-47C538A64A6C} - System32\Tasks\Yahoo! Search => C:\Users\ecp\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrlte.exe [2015-03-20] (Pay By Ads LTD) <==== ATTENTION
Task: {E752B85E-45F7-460D-ABCD-AE02F7419B9D} - System32\Tasks\ProPCCleaner_Start => C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe [2014-07-14] (Pro PC Cleaner) <==== ATTENTION
Task: {FF95E773-DA1A-4576-87C8-1EDA73422463} - System32\Tasks\Yahoo! Search Updater => C:\Users\ecp\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\dsrsetup.exe [2015-03-20] (Pay By Ads LTD) <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\CheckMeUp Update.job => C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe
Task: C:\Windows\Tasks\DriverDoc_UPDATES.job => C:\Program Files (x86)\DriverDoc\Solvusoftdd.exe
Task: C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.job => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.job => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10_user.job => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10.exe <==== ATTENTION
Task: C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.job => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.exe <==== ATTENTION
Task: C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.job => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5_user.job => C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\Price Fountain.job => C:\Users\ecp\AppData\Roaming\PRICEF~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\Wse_binkiland.job => C:\Users\ecp\AppData\Roaming\WSE_BI~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\WSE_Vosteran.job => C:\Users\ecp\AppData\Roaming\WSE_VO~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION

==================== Loaded Modules (whitelisted) ==============

2014-12-11 11:36 - 2014-12-11 11:36 - 00118784 _____ () C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
2015-03-20 18:48 - 2015-03-20 10:47 - 00379392 _____ () C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe
2015-01-14 11:07 - 2015-01-14 11:07 - 06757728 _____ () C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe
2014-12-30 14:30 - 2015-03-24 17:19 - 00411376 _____ () C:\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe
2014-12-30 16:42 - 2015-03-24 17:22 - 00411376 _____ () C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.exe
2015-03-16 15:34 - 2015-03-16 15:34 - 01594368 _____ () C:\Program Files\WajaWebEnhancer\wajam_64.exe
2015-03-20 18:44 - 2015-03-20 18:44 - 00512512 _____ () C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe
2015-03-16 15:32 - 2015-03-16 15:32 - 01330688 _____ () C:\Program Files\WajaWebEnhancer\wajam.exe
2015-03-26 21:13 - 2015-03-26 21:13 - 01260032 _____ () C:\Program Files\WajaWebEnhancer\dlls\nuyufqlxqyxxwzh.dll
2014-12-17 15:38 - 2014-12-17 15:38 - 02410760 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe
2015-03-22 08:52 - 2015-02-04 12:38 - 01014272 _____ () C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe
2015-03-20 18:44 - 2015-03-20 18:44 - 00745984 _____ () C:\Program Files (x86)\ver0CheckMeUp\CheckMeUp.exe
2015-03-22 07:43 - 2015-03-22 07:43 - 01609728 _____ () c:\Program Files (x86)\SystemContinue\SystemContinue.dll
2014-12-11 11:28 - 2014-12-11 11:28 - 02494464 _____ () C:\Program Files (x86)\DiskBoss\bin\libdbs.dll
2014-12-11 11:26 - 2014-12-11 11:26 - 00724992 _____ () C:\Program Files (x86)\DiskBoss\bin\libpal.dll
2015-03-26 21:13 - 2015-03-26 21:13 - 02962432 _____ () C:\Program Files\WajaWebEnhancer\dlls\exgejjnypksj.dll
2014-12-17 15:38 - 2014-12-17 15:38 - 00046080 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\boost_thread-vc90-mt-1_39.dll
2014-12-17 15:38 - 2014-12-17 15:38 - 00045056 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\boost_date_time-vc90-mt-1_39.dll
2014-12-17 15:38 - 2014-12-17 15:38 - 00545032 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\StreamingClient.dll
2014-12-17 15:38 - 2014-12-17 15:38 - 00012800 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\boost_system-vc90-mt-1_39.dll
2014-12-17 15:38 - 2014-12-17 15:38 - 00068360 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\CrashRpt.dll
2014-12-17 15:38 - 2014-12-17 15:38 - 00409352 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\SQLite3.dll
2014-12-17 15:38 - 2014-12-17 15:38 - 00614912 _____ () C:\Program Files (x86)\RapidSolution\Audials 11\boost_regex-vc90-mt-1_39.dll
2015-01-02 13:15 - 2015-01-02 13:15 - 00295424 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Utils\edd00f558957306a6abccee62d067d37\Utils.ni.dll
2015-01-02 13:15 - 2015-01-02 13:15 - 00589312 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ManagedInterfaces\43353f3d05c807ea3b3c598744f5ffaa\ManagedInterfaces.ni.dll
2015-01-02 13:16 - 2015-01-02 13:16 - 02997248 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\AudialsComponents\d1311eabe3d9a4088615c82fb65ae289\AudialsComponents.ni.dll
2015-01-02 13:16 - 2015-01-02 13:16 - 00178688 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\fastJSON\f82cce18fd1d4175d2aadbdb2d200ec7\fastJSON.ni.dll
2015-03-22 08:52 - 2015-02-04 12:38 - 28006400 _____ () C:\Users\ecp\AppData\Local\Binkiland\Application\31.0.1650.23\chrome.dll
2015-03-22 08:52 - 2015-02-04 12:38 - 34445312 _____ () C:\Users\ecp\AppData\Local\Binkiland\Application\31.0.1650.23\chrome_child.dll
2015-03-22 08:52 - 2015-02-04 12:38 - 00695808 _____ () C:\Users\ecp\AppData\Local\Binkiland\Application\31.0.1650.23\libglesv2.dll
2015-03-22 08:52 - 2015-02-04 12:38 - 00093184 _____ () C:\Users\ecp\AppData\Local\Binkiland\Application\31.0.1650.23\libegl.dll
2015-03-22 08:52 - 2015-02-04 12:38 - 00394240 _____ () C:\Users\ecp\AppData\Local\Binkiland\Application\31.0.1650.23\ppGoogleNaClPluginChrome.dll
2015-03-22 08:52 - 2015-02-04 12:38 - 00788992 _____ () C:\Users\ecp\AppData\Local\Binkiland\Application\31.0.1650.23\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Gambali => ""="service"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: Media is not connected to internet.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: ApnTBMon => "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
MSCONFIG\startupreg: GoogleChromeAutoLaunch_5C8F99C8E2E3047D14C0E718E5A5B373 => "C:\Users\ecp\AppData\Local\Vosteran\Application\vosteran.exe" --auto-launch-at-startup --profile-directory="Default"
MSCONFIG\startupreg: MailCheck IE Broker => "C:\Program Files (x86)\GMX MailCheck\IE\GMX_MailCheck_Broker.exe"

==================== Accounts: =============================

Administrator (S-1-5-21-1780445102-594666999-3139876592-500 - Administrator - Disabled)
ecp (S-1-5-21-1780445102-594666999-3139876592-1000 - Administrator - Enabled) => C:\Users\ecp
Gast (S-1-5-21-1780445102-594666999-3139876592-501 - Limited - Disabled)

==================== Faulty Device Manager Devices =============

Name: Microsoft-Teredo-Tunneling-Adapter
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/26/2015 09:14:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/24/2015 07:07:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 36.0.4.5557, Zeitstempel: 0x550d0883
Name des fehlerhaften Moduls: mozalloc.dll, Version: 36.0.4.5557, Zeitstempel: 0x550cfa82
Ausnahmecode: 0x80000003
Fehleroffset: 0x00001e02
ID des fehlerhaften Prozesses: 0x9bc
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3

Error: (03/24/2015 07:03:22 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm ProPCCleaner.exe, Version 2.5.5.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1ea4

Startzeit: 01d0665cc44c89d4

Endzeit: 21

Anwendungspfad: C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe

Berichts-ID:

Error: (03/24/2015 07:03:05 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Skype.exe, Version 6.3.73.105 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: e00

Startzeit: 01d0656003d46e83

Endzeit: 235

Anwendungspfad: C:\Program Files (x86)\Skype\Phone\Skype.exe

Berichts-ID:

Error: (03/24/2015 07:03:01 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm ProPCCleaner.exe, Version 2.5.5.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1fec

Startzeit: 01d0665a0fba5793

Endzeit: 0

Anwendungspfad: C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe

Berichts-ID:

Error: (03/24/2015 07:02:33 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm IEXPLORE.EXE, Version 11.0.9600.17689 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1a2c

Startzeit: 01d0665af096f995

Endzeit: 28

Anwendungspfad: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Berichts-ID:

Error: (03/24/2015 06:43:39 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm ProPCCleaner.exe, Version 2.5.5.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 12e0

Startzeit: 01d065607abc6214

Endzeit: 0

Anwendungspfad: C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe

Berichts-ID:

Error: (03/24/2015 05:41:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: opera.exe, Version: 28.0.1750.48, Zeitstempel: 0x55039cb1
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7
Ausnahmecode: 0xc0000374
Fehleroffset: 0x000ce753
ID des fehlerhaften Prozesses: 0x1e50
Startzeit der fehlerhaften Anwendung: 0xopera.exe0
Pfad der fehlerhaften Anwendung: opera.exe1
Pfad des fehlerhaften Moduls: opera.exe2
Berichtskennung: opera.exe3

Error: (03/24/2015 08:27:53 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary tammgR119 service.

System Error:
Zugriff verweigert
.

Error: (03/24/2015 08:27:53 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".


Details:
AddLegacyDriverFiles: Unable to back up image of binary tammgF119 service.

System Error:
Zugriff verweigert
.


System errors:
=============
Error: (03/26/2015 09:26:24 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT-AUTORITÄT60 ein Fehler festgestellt.

	Neue Signaturversion: 

	Vorherige Signaturversion: 1.195.92.0

	Aktualisierungsquelle: %NT-AUTORITÄT59

	Aktualisierungsphase: 4.7.0205.00

	Quellpfad: 4.7.0205.01

	Signaturtyp: %NT-AUTORITÄT602

	Aktualisierungstyp: %NT-AUTORITÄT604

	Benutzer: NT-AUTORITÄT\SYSTEM

	Aktuelle Modulversion: %NT-AUTORITÄT605

	Vorherige Modulversion: %NT-AUTORITÄT606

	Fehlercode: %NT-AUTORITÄT607

	Fehlerbeschreibung: %NT-AUTORITÄT608

Error: (03/26/2015 09:13:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "IePlugin Services" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%5

Error: (03/26/2015 09:12:48 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am ‎24.‎03.‎2015 um 19:12:27 unerwartet heruntergefahren.

Error: (03/24/2015 07:02:21 PM) (Source: DCOM) (EventID: 10016) (User: ecp-PC)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ecp-PCecpS-1-5-21-1780445102-594666999-3139876592-1000LocalHost (unter Verwendung von LRPC)

Error: (03/24/2015 06:59:08 PM) (Source: DCOM) (EventID: 10016) (User: ecp-PC)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ecp-PCecpS-1-5-21-1780445102-594666999-3139876592-1000LocalHost (unter Verwendung von LRPC)

Error: (03/24/2015 06:57:39 PM) (Source: DCOM) (EventID: 10016) (User: ecp-PC)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ecp-PCecpS-1-5-21-1780445102-594666999-3139876592-1000LocalHost (unter Verwendung von LRPC)

Error: (03/24/2015 06:54:22 PM) (Source: DCOM) (EventID: 10016) (User: ecp-PC)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ecp-PCecpS-1-5-21-1780445102-594666999-3139876592-1000LocalHost (unter Verwendung von LRPC)

Error: (03/24/2015 06:54:21 PM) (Source: DCOM) (EventID: 10016) (User: ecp-PC)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ecp-PCecpS-1-5-21-1780445102-594666999-3139876592-1000LocalHost (unter Verwendung von LRPC)

Error: (03/24/2015 06:53:09 PM) (Source: DCOM) (EventID: 10016) (User: ecp-PC)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ecp-PCecpS-1-5-21-1780445102-594666999-3139876592-1000LocalHost (unter Verwendung von LRPC)

Error: (03/24/2015 06:49:33 PM) (Source: DCOM) (EventID: 10016) (User: ecp-PC)
Description: ComputerstandardLokalAktivierung{9BA05972-F6A8-11CF-A442-00A0C90A8F39}{9BA05972-F6A8-11CF-A442-00A0C90A8F39}ecp-PCecpS-1-5-21-1780445102-594666999-3139876592-1000LocalHost (unter Verwendung von LRPC)


Microsoft Office Sessions:
=========================
Error: (03/26/2015 09:14:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (03/24/2015 07:07:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe36.0.4.5557550d0883mozalloc.dll36.0.4.5557550cfa828000000300001e029bc01d0665caef4d103C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll9584298b-d250-11e4-8257-001fe2182534

Error: (03/24/2015 07:03:22 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: ProPCCleaner.exe2.5.5.01ea401d0665cc44c89d421C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe

Error: (03/24/2015 07:03:05 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Skype.exe6.3.73.105e0001d0656003d46e83235C:\Program Files (x86)\Skype\Phone\Skype.exe

Error: (03/24/2015 07:03:01 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: ProPCCleaner.exe2.5.5.01fec01d0665a0fba57930C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe

Error: (03/24/2015 07:02:33 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.176891a2c01d0665af096f99528C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

Error: (03/24/2015 06:43:39 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: ProPCCleaner.exe2.5.5.012e001d065607abc62140C:\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe

Error: (03/24/2015 05:41:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: opera.exe28.0.1750.4855039cb1ntdll.dll6.1.7601.18247521ea8e7c0000374000ce7531e5001d06650fb07ac01C:\Program Files (x86)\Opera\28.0.1750.48\opera.exeC:\Windows\SysWOW64\ntdll.dll8e25c7b2-d244-11e4-8257-001fe2182534

Error: (03/24/2015 08:27:53 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: 
Details:
AddLegacyDriverFiles: Unable to back up image of binary tammgR119 service.

System Error:
Zugriff verweigert

Error: (03/24/2015 08:27:53 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: 
Details:
AddLegacyDriverFiles: Unable to back up image of binary tammgF119 service.

System Error:
Zugriff verweigert


==================== Memory info =========================== 

Processor: Intel(R) Core(TM)2 Duo CPU T7100 @ 1.80GHz
Percentage of memory in use: 46%
Total physical RAM: 2006.3 MB
Available physical RAM: 1077.6 MB
Total Pagefile: 4012.59 MB
Available Pagefile: 2453.32 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:142.65 GB) (Free:105.12 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 4557C7D5)
Partition 1: (Active) - (Size=6.4 GB) - (Type=27)
Partition 2: (Not Active) - (Size=142.6 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         

Vielen Dank für eure/deine Hilfe

Gruß Hausmeister

Alt 26.03.2015, 22:49   #2
Haus meister
 
Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Standard

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen



.... und hier noch das GMER-Log:
Code:
ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-03-26 21:48:21
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-2 HITACHI_HTS542516K9SA00 rev.BBCZC3HP 149,05GB
Running: Gmer-19357.exe; Driver: C:\Users\ecp\AppData\Local\Temp\ufldapow.sys


---- User code sections - GMER 2.1 ----

.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                                               0000000076871401 2 bytes JMP 75a7b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                                                 0000000076871419 2 bytes JMP 75a7b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                                               0000000076871431 2 bytes JMP 75af8ea9 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                                               000000007687144a 2 bytes CALL 75a548ad C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                                                          * 9
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                                                  00000000768714dd 2 bytes JMP 75af87a2 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                                                           00000000768714f5 2 bytes JMP 75af8978 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                                                  000000007687150d 2 bytes JMP 75af8698 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                                                           0000000076871525 2 bytes JMP 75af8a62 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                                                 000000007687153d 2 bytes JMP 75a6fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                                                      0000000076871555 2 bytes JMP 75a768ef C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                                               000000007687156d 2 bytes JMP 75af8f61 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                                                 0000000076871585 2 bytes JMP 75af8ac2 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                                                    000000007687159d 2 bytes JMP 75af865c C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                                                 00000000768715b5 2 bytes JMP 75a6fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                                               00000000768715cd 2 bytes JMP 75a7b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                                                           00000000768716b2 2 bytes JMP 75af8e24 C:\Windows\syswow64\kernel32.dll
.text    C:\Windows\SysWOW64\rundll32.exe[1616] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                                                           00000000768716bd 2 bytes JMP 75af85f1 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                                    0000000076871401 2 bytes JMP 75a7b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                                      0000000076871419 2 bytes JMP 75a7b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                                    0000000076871431 2 bytes JMP 75af8ea9 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                                    000000007687144a 2 bytes CALL 75a548ad C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                                                          * 9
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                                       00000000768714dd 2 bytes JMP 75af87a2 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                                                00000000768714f5 2 bytes JMP 75af8978 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                                       000000007687150d 2 bytes JMP 75af8698 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                                                0000000076871525 2 bytes JMP 75af8a62 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                                      000000007687153d 2 bytes JMP 75a6fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                                           0000000076871555 2 bytes JMP 75a768ef C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                                    000000007687156d 2 bytes JMP 75af8f61 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                                      0000000076871585 2 bytes JMP 75af8ac2 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                                         000000007687159d 2 bytes JMP 75af865c C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                                      00000000768715b5 2 bytes JMP 75a6fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                                    00000000768715cd 2 bytes JMP 75a7b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                                                00000000768716b2 2 bytes JMP 75af8e24 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe[3464] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                                                00000000768716bd 2 bytes JMP 75af85f1 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe[3504] C:\Windows\syswow64\kernel32.dll!SetFileCompletionNotificationModes                                                            0000000075acb2fe 5 bytes JMP 00000001013191b0
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                                     0000000076871401 2 bytes JMP 75a7b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                                       0000000076871419 2 bytes JMP 75a7b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                                     0000000076871431 2 bytes JMP 75af8ea9 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                                     000000007687144a 2 bytes CALL 75a548ad C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                                                          * 9
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                                        00000000768714dd 2 bytes JMP 75af87a2 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                                                 00000000768714f5 2 bytes JMP 75af8978 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                                        000000007687150d 2 bytes JMP 75af8698 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                                                 0000000076871525 2 bytes JMP 75af8a62 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                                       000000007687153d 2 bytes JMP 75a6fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                                            0000000076871555 2 bytes JMP 75a768ef C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                                     000000007687156d 2 bytes JMP 75af8f61 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                                       0000000076871585 2 bytes JMP 75af8ac2 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                                          000000007687159d 2 bytes JMP 75af865c C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                                       00000000768715b5 2 bytes JMP 75a6fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                                     00000000768715cd 2 bytes JMP 75a7b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                                                 00000000768716b2 2 bytes JMP 75af8e24 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe[3536] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                                                 00000000768716bd 2 bytes JMP 75af85f1 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                                       0000000076871401 2 bytes JMP 75a7b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                                         0000000076871419 2 bytes JMP 75a7b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                                       0000000076871431 2 bytes JMP 75af8ea9 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                                       000000007687144a 2 bytes CALL 75a548ad C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                                                          * 9
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                                          00000000768714dd 2 bytes JMP 75af87a2 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                                                   00000000768714f5 2 bytes JMP 75af8978 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                                          000000007687150d 2 bytes JMP 75af8698 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                                                   0000000076871525 2 bytes JMP 75af8a62 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                                         000000007687153d 2 bytes JMP 75a6fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                                              0000000076871555 2 bytes JMP 75a768ef C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                                       000000007687156d 2 bytes JMP 75af8f61 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                                         0000000076871585 2 bytes JMP 75af8ac2 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                                            000000007687159d 2 bytes JMP 75af865c C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                                         00000000768715b5 2 bytes JMP 75a6fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                                       00000000768715cd 2 bytes JMP 75a7b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                                                   00000000768716b2 2 bytes JMP 75af8e24 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files\Lenovo\Zoom\TpScrex.exe[2172] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                                                   00000000768716bd 2 bytes JMP 75af85f1 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe[4320] C:\Windows\syswow64\KERNEL32.dll!SetUnhandledExceptionFilter                                                       0000000075a58791 5 bytes [33, C0, C2, 04, 00]
.text    C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe[4320] C:\Windows\syswow64\KERNEL32.dll!SetFileCompletionNotificationModes                                                0000000075acb2fe 5 bytes JMP 00000001063f91b0
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\kernel32.dll!SetFileCompletionNotificationModes                                                         0000000075acb2fe 5 bytes JMP 0000000101e391b0
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                     0000000076871401 2 bytes JMP 75a7b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                       0000000076871419 2 bytes JMP 75a7b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                     0000000076871431 2 bytes JMP 75af8ea9 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                     000000007687144a 2 bytes CALL 75a548ad C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                                                          * 9
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                        00000000768714dd 2 bytes JMP 75af87a2 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                                 00000000768714f5 2 bytes JMP 75af8978 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                        000000007687150d 2 bytes JMP 75af8698 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                                 0000000076871525 2 bytes JMP 75af8a62 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                       000000007687153d 2 bytes JMP 75a6fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                            0000000076871555 2 bytes JMP 75a768ef C:\Windows\syswow64\kernel32.dll
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                     000000007687156d 2 bytes JMP 75af8f61 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                       0000000076871585 2 bytes JMP 75af8ac2 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                          000000007687159d 2 bytes JMP 75af865c C:\Windows\syswow64\kernel32.dll
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                       00000000768715b5 2 bytes JMP 75a6fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                     00000000768715cd 2 bytes JMP 75a7b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                                 00000000768716b2 2 bytes JMP 75af8e24 C:\Windows\syswow64\kernel32.dll
.text    C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe[4608] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                                 00000000768716bd 2 bytes JMP 75af85f1 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                        0000000076871401 2 bytes JMP 75a7b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                          0000000076871419 2 bytes JMP 75a7b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                        0000000076871431 2 bytes JMP 75af8ea9 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                        000000007687144a 2 bytes CALL 75a548ad C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                                                          * 9
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                           00000000768714dd 2 bytes JMP 75af87a2 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                                    00000000768714f5 2 bytes JMP 75af8978 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                           000000007687150d 2 bytes JMP 75af8698 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                                    0000000076871525 2 bytes JMP 75af8a62 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                          000000007687153d 2 bytes JMP 75a6fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                               0000000076871555 2 bytes JMP 75a768ef C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                        000000007687156d 2 bytes JMP 75af8f61 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                          0000000076871585 2 bytes JMP 75af8ac2 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                             000000007687159d 2 bytes JMP 75af865c C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                          00000000768715b5 2 bytes JMP 75a6fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                        00000000768715cd 2 bytes JMP 75a7b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                                    00000000768716b2 2 bytes JMP 75af8e24 C:\Windows\syswow64\kernel32.dll
.text    C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[5084] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                                    00000000768716bd 2 bytes JMP 75af85f1 C:\Windows\syswow64\kernel32.dll
.text    C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe[5220] C:\Windows\syswow64\kernel32.dll!SetFileCompletionNotificationModes                                                                         0000000075acb2fe 5 bytes JMP 0000000101e491b0
.text    C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe[5376] C:\Windows\syswow64\kernel32.dll!SetFileCompletionNotificationModes                                                                          0000000075acb2fe 5 bytes JMP 0000000100a591b0
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                                                    0000000076871401 2 bytes JMP 75a7b21b C:\Windows\syswow64\kernel32.dll
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                                                      0000000076871419 2 bytes JMP 75a7b346 C:\Windows\syswow64\kernel32.dll
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                                                    0000000076871431 2 bytes JMP 75af8ea9 C:\Windows\syswow64\kernel32.dll
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                                                    000000007687144a 2 bytes CALL 75a548ad C:\Windows\syswow64\kernel32.dll
.text    ...                                                                                                                                                                                          * 9
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                                                       00000000768714dd 2 bytes JMP 75af87a2 C:\Windows\syswow64\kernel32.dll
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                                                                00000000768714f5 2 bytes JMP 75af8978 C:\Windows\syswow64\kernel32.dll
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                                                       000000007687150d 2 bytes JMP 75af8698 C:\Windows\syswow64\kernel32.dll
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                                                                0000000076871525 2 bytes JMP 75af8a62 C:\Windows\syswow64\kernel32.dll
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                                                      000000007687153d 2 bytes JMP 75a6fca8 C:\Windows\syswow64\kernel32.dll
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                                                           0000000076871555 2 bytes JMP 75a768ef C:\Windows\syswow64\kernel32.dll
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                                                    000000007687156d 2 bytes JMP 75af8f61 C:\Windows\syswow64\kernel32.dll
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                                                      0000000076871585 2 bytes JMP 75af8ac2 C:\Windows\syswow64\kernel32.dll
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                                                         000000007687159d 2 bytes JMP 75af865c C:\Windows\syswow64\kernel32.dll
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                                                      00000000768715b5 2 bytes JMP 75a6fd41 C:\Windows\syswow64\kernel32.dll
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                                                    00000000768715cd 2 bytes JMP 75a7b2dc C:\Windows\syswow64\kernel32.dll
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                                                                00000000768716b2 2 bytes JMP 75af8e24 C:\Windows\syswow64\kernel32.dll
.text    C:\Reinigung\Gmer-19357.exe[7296] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                                                                00000000768716bd 2 bytes JMP 75af85f1 C:\Windows\syswow64\kernel32.dll

---- Threads - GMER 2.1 ----

Thread   C:\Windows\system32\services.exe [496:3128]                                                                                                                                                  000000000038f170
Thread   C:\Windows\system32\services.exe [496:3132]                                                                                                                                                  000000000038f170
Thread   C:\Windows\system32\svchost.exe [788:828]                                                                                                                                                    000000000090f170
Thread   C:\Windows\system32\svchost.exe [788:832]                                                                                                                                                    000000000090f170
Thread   C:\Windows\system32\svchost.exe [468:1372]                                                                                                                                                   0000000000b4f170
Thread   C:\Windows\system32\svchost.exe [468:1376]                                                                                                                                                   0000000000b4f170
Thread   C:\Windows\System32\spoolsv.exe [1456:2856]                                                                                                                                                  0000000001d3f170
Thread   C:\Windows\System32\spoolsv.exe [1456:2672]                                                                                                                                                  0000000001d3f170
Thread   C:\Windows\SysWOW64\rundll32.exe [1616:3744]                                                                                                                                                 0000000000b3c470
Thread   C:\Windows\SysWOW64\rundll32.exe [1616:976]                                                                                                                                                  0000000000b3c470
---- Processes - GMER 2.1 ----

Library  C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [1700]                                                                        0000000000040000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [1748]                                                                          0000000000400000
Process  C:\ProgramData\SecurityUtility\Gambali.exe (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (Gambali OEM Software)(2015-0                                            0000000000400000
Library  C:\ProgramData\SecurityUtility\GambaliCrt.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (Gambali OEM Software)(                                               00000000004e0000
Library  C:\ProgramData\SecurityUtility\libnspr4.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (NSPR Library/Mozilla Foundation)(2015-03-20 17:48:48)                  0000000072ed0000
Library  C:\ProgramData\SecurityUtility\nss3.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (NSS Base Library/Mozilla Foundation)(2015-03-20 17:48:48)                  0000000072de0000
Library  C:\ProgramData\SecurityUtility\nssutil3.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (NSS Utility Library/Mozilla Foundation)(2015-03-20 17:48:48)           0000000072db0000
Library  C:\ProgramData\SecurityUtility\libplc4.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (PLC Library/Mozilla Foundation)(2015-03-20 17:48:48)                    0000000072da0000
Library  C:\ProgramData\SecurityUtility\libplds4.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (PLDS Library/Mozilla Foundation)(2015-03-20 17:48:48)                  0000000072d90000
Library  C:\ProgramData\SecurityUtility\smime3.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (NSS S/MIME Library/Mozilla Foundation)(2015-03-20 17:48:49)              0000000072d50000
Library  C:\ProgramData\SecurityUtility\freebl3.dll (*** suspicious ***) @ C:\ProgramData\SecurityUtility\Gambali.exe [1852] (NSS freebl Library/Mozilla Foundation)(2015-03-20 17:48:48)             0000000072800000
Process  C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe (*** suspicious ***) @ C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe [2000](2015-03-20 17:48:43)                               0000000000400000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\system32\taskhost.exe [676](2015-03-15 12:40:26)                                                          000007fef4ce0000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe [3464](2015-03-15 12:4                                                   0000000061020000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\system32\taskeng.exe [3524](2015-03-15 12:40:26)                                                          000007fef4ce0000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\system32\Dwm.exe [3704](2015-03-15 12:40:26)                                                              000007fef4ce0000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\Explorer.EXE [4068](2015-03-15 12:40:26)                                                                  000007fef4ce0000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe [3504](2015-03-15 12:41:26)                                  0000000061020000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe [3536](2015-03-15 12:41:                                                  0000000061020000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Program Files\Lenovo\Zoom\TpScrex.exe [2172](2015-03-15 12:41:26)                                                 0000000061020000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Program Files\Microsoft Security Client\msseces.exe [4176](2015-03-15 12:40:26)                                   000007fef4ce0000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [4224](2015-03-15                                                      000007fef4ce0000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\System32\igfxtray.exe [4232](2015-03-15 12:40:26)                                                         000007fef4ce0000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\System32\hkcmd.exe [4244](2015-03-15 12:40:26)                                                            000007fef4ce0000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\System32\igfxpers.exe [4252](2015-03-15 12:40:26)                                                         000007fef4ce0000
Process  C:\Users\ecp\AppData\Local\PriceFountain\pricefountainw.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\PriceFountain\pricefountainw.exe [4284] (Price Fountain)(2015-01-01 10:26:11)  0000000000400000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe [4320](2015-03-15 12:41:26)                      0000000061020000
Process  C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe [4608] (Price Fountain)(2015-01-01 10:26:08)    0000000000400000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Users\ecp\AppData\Local\PriceFountain\pricefountain.exe [4608](2015-03-15 12:41:26)                               0000000061020000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [4644](2015-03-15                                                      000007fef4ce0000
Process  C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [4740](2015-03-22 07:52:51)             0000000001170000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [5084](2015-03-15 12:41:26)                                  0000000061020000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE [4336](2015-                                                        000007fef4ce0000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Program Files (x86)\ver0CheckMeUp\CheckMeUp.exe [4772](2                                                          0000000061020000
Process  C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [4440](2015-03-22 07:52:51)             0000000001170000
Process  C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [5668](2015-03-22 07:52:51)             0000000001170000
Process  C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [5752](2015-03-22 07:52:51)             0000000001170000
Process  C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [5816](2015-03-22 07:52:51)             0000000001170000
Process  C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [5824](2015-03-22 07:52:51)             0000000001170000
Process  C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe (*** suspicious ***) @ C:\Users\ecp\AppData\Local\Binkiland\Application\binkiland.exe [5840](2015-03-22 07:52:51)             0000000001170000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Program Files\McAfee Security Scan\3.8.150\McUicnt.exe [5152](2015-03-15 12:40:26)                                000007fef4ce0000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe [5220]                                                                          00000000008a0000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzoomutil32.dll (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe [5220](2015-03-15                                                      0000000062f20000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe [5220](2015-03-15 12:41:                                                  0000000061020000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bz64.exe (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bz64.exe [4900](2015-03-15 12:40:58)                                                       000000013f2c0000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bz64.exe [4900](2015-03-15 12:40:26                                                 000007fef4ce0000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe [5376](2015-03-15 12:42:28)                                                       0000000000d00000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe [5376](2015-03-15 12:41:26                                                 0000000061020000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml64.dll (*** suspicious ***) @ C:\Windows\System32\dinotify.exe [4508](2015-03-15 12:40:26)                                                         000007fef4ce0000
Library  C:\ProgramData\bobyzoom\1.1.0.30\bobyzooml32.dll (*** suspicious ***) @ C:\Reinigung\Gmer-19357.exe [7296](2015-03-15 12:41:26)                                                              0000000061020000

---- Services - GMER 2.1 ----

Service  C:\Windows\system32\Drivers\tammgF119.sys (*** hidden *** )                                                                                                                                  [SYSTEM] tammgF119                                                        <-- ROOTKIT !!!
Service  C:\Windows\system32\Drivers\tammgR119.sys (*** hidden *** )                                                                                                                                  [SYSTEM] tammgR119                                                        <-- ROOTKIT !!!

---- Registry - GMER 2.1 ----

Reg      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tammgF119.sys@                                                                                                                        Driver
Reg      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tammgR119.sys@                                                                                                                        Driver
Reg      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tammgF119.sys@                                                                                                                        Driver
Reg      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tammgR119.sys@                                                                                                                        Driver
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgF119@Type                                                                                                                                        2
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgF119@Start                                                                                                                                       1
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgF119@ErrorControl                                                                                                                                1
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgF119@ImagePath                                                                                                                                   \??\C:\Windows\system32\Drivers\tammgF119.sys
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgF119@DisplayName                                                                                                                                 tammgF119 service
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgF119@Group                                                                                                                                       FSFilter Activity Monitor
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgF119@DependOnService                                                                                                                             FltMgr?
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgF119@WOW64                                                                                                                                       1
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgF119\Instances                                                                                                                                   
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgF119\Instances@DefaultInstance                                                                                                                   tammgF119 Instance
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgF119\Instances\tammgF119 Instance                                                                                                                
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgF119\Instances\tammgF119 Instance@Altitude                                                                                                       370034
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgF119\Instances\tammgF119 Instance@Flags                                                                                                          0
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgF119                                                                                                                                             
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgR119@Type                                                                                                                                        1
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgR119@Start                                                                                                                                       1
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgR119@ErrorControl                                                                                                                                1
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgR119@ImagePath                                                                                                                                   \??\C:\Windows\system32\Drivers\tammgR119.sys
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgR119@DisplayName                                                                                                                                 tammgR119 service
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgR119@WOW64                                                                                                                                       1
Reg      HKLM\SYSTEM\CurrentControlSet\services\tammgR119                                                                                                                                             
Reg      HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\tammgF119.sys@                                                                                                                            Driver
Reg      HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\tammgR119.sys@                                                                                                                            Driver
Reg      HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\tammgF119.sys@                                                                                                                            Driver
Reg      HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\tammgR119.sys@                                                                                                                            Driver
Reg      HKLM\SYSTEM\ControlSet002\services\tammgF119@Type                                                                                                                                            2
Reg      HKLM\SYSTEM\ControlSet002\services\tammgF119@Start                                                                                                                                           1
Reg      HKLM\SYSTEM\ControlSet002\services\tammgF119@ErrorControl                                                                                                                                    1
Reg      HKLM\SYSTEM\ControlSet002\services\tammgF119@ImagePath                                                                                                                                       \??\C:\Windows\system32\Drivers\tammgF119.sys
Reg      HKLM\SYSTEM\ControlSet002\services\tammgF119@DisplayName                                                                                                                                     tammgF119 service
Reg      HKLM\SYSTEM\ControlSet002\services\tammgF119@Group                                                                                                                                           FSFilter Activity Monitor
Reg      HKLM\SYSTEM\ControlSet002\services\tammgF119@DependOnService                                                                                                                                 FltMgr?
Reg      HKLM\SYSTEM\ControlSet002\services\tammgF119@WOW64                                                                                                                                           1
Reg      HKLM\SYSTEM\ControlSet002\services\tammgF119\Instances (not active ControlSet)                                                                                                               
Reg      HKLM\SYSTEM\ControlSet002\services\tammgF119\Instances@DefaultInstance                                                                                                                       tammgF119 Instance
Reg      HKLM\SYSTEM\ControlSet002\services\tammgF119\Instances\tammgF119 Instance (not active ControlSet)                                                                                            
Reg      HKLM\SYSTEM\ControlSet002\services\tammgF119\Instances\tammgF119 Instance@Altitude                                                                                                           370034
Reg      HKLM\SYSTEM\ControlSet002\services\tammgF119\Instances\tammgF119 Instance@Flags                                                                                                              0
Reg      HKLM\SYSTEM\ControlSet002\services\tammgR119@Type                                                                                                                                            1
Reg      HKLM\SYSTEM\ControlSet002\services\tammgR119@Start                                                                                                                                           1
Reg      HKLM\SYSTEM\ControlSet002\services\tammgR119@ErrorControl                                                                                                                                    1
Reg      HKLM\SYSTEM\ControlSet002\services\tammgR119@ImagePath                                                                                                                                       \??\C:\Windows\system32\Drivers\tammgR119.sys
Reg      HKLM\SYSTEM\ControlSet002\services\tammgR119@DisplayName                                                                                                                                     tammgR119 service
Reg      HKLM\SYSTEM\ControlSet002\services\tammgR119@WOW64                                                                                                                                           1

---- EOF - GMER 2.1 ----
         
__________________


Alt 27.03.2015, 07:28   #3
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Standard

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen



hi,

Lade Dir bitte von hier Revo Uninstaller Download Revo Uninstaller (alternativ portable Revo Uninstaller) herunter.
  • Installiere und starte das Programm. (Bebilderte Anleitung zu Revo Uninstaller)
  • Klicke auf Optionen und wähle als Sprache Deutsch.
  • Suche im Uninstallerfeld nach den Programmen:

    Binkiland

    Buzzdock

    Dynamo Combo

    OnlineLowDeals

    PriceFountain

    Reimage Repair

    RocketTab

    Saveitkeaep.

    SystemContinue

    Update for PriceFountain

    vi-view uninstall

    Vosteran

    Wajam

    WSE_Binkiland

    WSE_Vosteran

    Yahoo! Search


  • Wähle die Programme nacheinander aus und klicke jedes Mal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .

 





Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________
__________________

Alt 29.03.2015, 22:05   #4
Haus meister
 
Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Standard

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen



Hallo Schrauber,

alle Schritte durchgeführt. Wobei ich bei der Deinstallation mit RevoUninstaller nicht alle Programme gefunden habe, die du aufgelistet hattest.
Ausserdem habe ich mich (glaube ich) einmal verklickt und den Auto-Uninstaller eines Programms abgebrochen.

Hier das Log von ComboFix:

Code:
ATTFilter
ComboFix 15-03-25.01 - ecp 29.03.2015  22:32:55.1.2 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.2006.1032 [GMT 2:00]
ausgeführt von:: c:\users\ecp\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
SP: Microsoft Security Essentials *Disabled/Updated* {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\ddeallpeAuk
c:\program files (x86)\ddeallpeAuk\83pi0tURGPEZSW.dat
c:\program files (x86)\ddeallpeAuk\83pi0tURGPEZSW.dll
c:\program files (x86)\ddeallpeAuk\83pi0tURGPEZSW.tlb
c:\program files (x86)\ddeallpeAuk\83pi0tURGPEZSW.x64.dll
c:\program files (x86)\RoyAlCeOupoen
c:\program files (x86)\RoyAlCeOupoen\HqWqrhAIb9KXYi.dat
c:\program files (x86)\RoyAlCeOupoen\HqWqrhAIb9KXYi.tlb
c:\program files (x86)\SaleisuCheccker
c:\program files (x86)\SaleisuCheccker\xpyZoe64gi8nWN.dat
c:\program files (x86)\SaleisuCheccker\xpyZoe64gi8nWN.tlb
c:\program files (x86)\Saveitkeaep
c:\program files (x86)\Saveitkeaep\OUx1yNk71u3K2I.dat
c:\program files (x86)\Saveitkeaep\OUx1yNk71u3K2I.dll
c:\program files (x86)\Saveitkeaep\OUx1yNk71u3K2I.tlb
c:\program files (x86)\Saveitkeaep\OUx1yNk71u3K2I.x64.dll
c:\program files (x86)\SoaleEsChoeocKeirr
c:\program files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.dat
c:\program files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.dll
c:\program files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.tlb
c:\program files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.x64.dll
c:\programdata\15483481001080132652
c:\programdata\15483481001080132652\095e64fbe062fb57e00f3b8912a68d76.ini
c:\programdata\15483481001080132652\0e950e00e627140ee00f3b8912a68d76.ini
c:\programdata\15483481001080132652\1878c1afe37a6843e00f3b8912a68d76.ini
c:\programdata\15483481001080132652\5175a0130ed5b449e00f3b8912a68d76.ini
c:\programdata\15483481001080132652\73ecd09576ab61e0e00f3b8912a68d76.ini
c:\programdata\15483481001080132652\7b454519bbfb9c52e00f3b8912a68d76.ini
c:\programdata\15483481001080132652\87b1cffeb795e9ffe00f3b8912a68d76.ini
c:\programdata\15483481001080132652\88ca0666a8bc42bce00f3b8912a68d76.ini
c:\programdata\15483481001080132652\d236748b2ecd3b60e00f3b8912a68d76.ini
c:\programdata\15483481001080132652\d5fe86451e44dffce00f3b8912a68d76.ini
c:\programdata\15483481001080132652\f5dc0d0456a8eaf3e00f3b8912a68d76.ini
c:\programdata\15483481001080132652\fabe6de3a4ead422e00f3b8912a68d76.ini
c:\programdata\1887373585
c:\programdata\1887373585\BITB865.tmp
c:\users\ecp\AppData\Local\dsisetup1374062732.exe
c:\users\ecp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Dynamo Combo_iels
c:\users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\extensions\Rc1@sSvOmat.net
c:\users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\extensions\Rc1@sSvOmat.net\bootstrap.js
c:\users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\extensions\Rc1@sSvOmat.net\chrome.manifest
c:\users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\extensions\Rc1@sSvOmat.net\content\bg.js
c:\users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\extensions\Rc1@sSvOmat.net\install.rdf
c:\windows\msdownld.tmp
.
.
(((((((((((((((((((((((((((((((((((((((   Treiber/Dienste   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_globalUpdate
.
.
(((((((((((((((((((((((   Dateien erstellt von 2015-02-28 bis 2015-03-29  ))))))))))))))))))))))))))))))
.
.
2015-03-29 20:46 . 2015-03-29 20:46	--------	d-----w-	c:\users\Default\AppData\Local\temp
2015-03-27 17:46 . 2015-03-27 17:46	--------	d-----w-	c:\program files (x86)\VS Revo Group
2015-03-26 21:38 . 2015-03-26 21:38	75888	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{20B94202-BEA6-40D1-BBCA-E264E8CFB3AA}\offreg.dll
2015-03-26 21:16 . 2015-03-14 10:02	12002392	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{20B94202-BEA6-40D1-BBCA-E264E8CFB3AA}\mpengine.dll
2015-03-26 20:28 . 2015-03-26 20:33	--------	d-----w-	C:\FRST
2015-03-26 20:13 . 2015-03-29 20:22	--------	d-----w-	C:\Reinigung
2015-03-23 08:18 . 2015-03-23 08:19	--------	d-----w-	c:\program files (x86)\Simple Dictation
2015-03-23 08:17 . 2015-03-23 08:19	--------	d-----w-	c:\program files (x86)\deAli2idealit
2015-03-23 06:51 . 2015-01-29 09:07	11910896	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2015-03-22 08:10 . 2015-03-22 08:10	--------	d-----w-	c:\users\ecp\AppData\Local\Macromedia
2015-03-22 08:09 . 2015-03-22 08:09	--------	d-----w-	c:\users\ecp\AppData\Local\Mozilla
2015-03-22 07:30 . 2015-03-22 07:30	--------	d-----w-	c:\users\ecp\AppData\Local\32220c02-c108-4e43-b856-df7d87f70051
2015-03-22 06:43 . 2015-03-22 06:43	--------	d-----w-	c:\program files (x86)\SystemContinue
2015-03-21 17:45 . 2015-03-21 17:45	2205072	----a-w-	c:\windows\shost.bin
2015-03-20 17:52 . 2015-03-20 17:52	--------	d-----w-	c:\users\ecp\AppData\Local\Pro_PC_Cleaner
2015-03-20 17:50 . 2015-03-20 17:50	--------	d-----w-	c:\program files (x86)\Pro PC Cleaner
2015-03-20 17:50 . 2015-03-20 17:50	--------	d-----w-	c:\users\ecp\AppData\Roaming\Pro PC Cleaner
2015-03-20 17:49 . 2015-03-20 09:33	335768	----a-w-	c:\windows\SysWow64\Gambali.dll
2015-03-20 17:49 . 2015-03-20 09:33	398808	----a-w-	c:\windows\system32\Gambali64.dll
2015-03-20 17:47 . 2015-03-20 17:47	--------	d-----w-	c:\programdata\e314b8475a214ebc973cc42fbf8c6edf
2015-03-20 17:47 . 2015-03-20 17:49	--------	d-----w-	c:\programdata\SecurityUtility
2015-03-20 17:45 . 2015-03-20 17:45	--------	d-----w-	c:\program files (x86)\globalUpdate
2015-03-20 17:45 . 2015-03-20 17:45	--------	d-----w-	c:\users\ecp\AppData\Local\globalUpdate
2015-03-20 17:45 . 2015-03-29 20:16	2248	----a-w-	c:\windows\patsearch.bin
2015-03-20 17:45 . 2015-03-20 17:44	50800	----a-w-	c:\windows\system32\drivers\webTinstMKTN.sys
2015-03-20 17:45 . 2015-03-20 17:45	--------	d-----w-	c:\program files (x86)\ver0CheckMeUp
2015-03-20 17:45 . 2015-03-20 17:47	--------	d-----w-	c:\program files (x86)\HQCinema Pro 2.1V20.03
2015-03-20 06:05 . 2015-03-20 06:05	--------	d-----w-	c:\users\ecp\AppData\Local\Pay-By-Ads
2015-03-11 07:17 . 2015-02-03 03:30	1202176	----a-w-	c:\windows\system32\drmv2clt.dll
2015-03-11 07:17 . 2015-02-03 03:30	842240	----a-w-	c:\windows\system32\blackbox.dll
2015-03-11 07:17 . 2015-02-03 03:12	744960	----a-w-	c:\windows\SysWow64\blackbox.dll
2015-03-11 07:17 . 2015-02-03 03:12	988160	----a-w-	c:\windows\SysWow64\drmv2clt.dll
2015-03-11 07:17 . 2015-02-03 03:31	14632960	----a-w-	c:\windows\system32\wmp.dll
2015-03-11 07:17 . 2015-02-03 03:31	782848	----a-w-	c:\windows\system32\wmdrmsdk.dll
2015-03-11 07:17 . 2015-02-03 03:12	617984	----a-w-	c:\windows\SysWow64\wmdrmsdk.dll
2015-03-11 07:17 . 2015-02-03 03:12	3209728	----a-w-	c:\windows\SysWow64\mf.dll
2015-03-11 07:17 . 2015-02-03 03:34	5554104	----a-w-	c:\windows\system32\ntoskrnl.exe
2015-03-11 07:15 . 2015-02-20 04:41	41984	----a-w-	c:\windows\system32\lpk.dll
2015-03-11 07:15 . 2015-02-20 04:40	46080	----a-w-	c:\windows\system32\atmlib.dll
2015-03-11 07:15 . 2015-02-20 03:29	372224	----a-w-	c:\windows\system32\atmfd.dll
2015-03-11 07:15 . 2015-02-20 03:09	299008	----a-w-	c:\windows\SysWow64\atmfd.dll
2015-03-11 07:14 . 2015-02-20 04:40	100864	----a-w-	c:\windows\system32\fontsub.dll
2015-03-11 07:14 . 2015-02-20 04:40	14336	----a-w-	c:\windows\system32\dciman32.dll
2015-03-11 07:14 . 2015-02-20 04:13	70656	----a-w-	c:\windows\SysWow64\fontsub.dll
2015-03-11 07:14 . 2015-02-20 04:13	10240	----a-w-	c:\windows\SysWow64\dciman32.dll
2015-03-11 07:14 . 2015-02-20 04:13	34304	----a-w-	c:\windows\SysWow64\atmlib.dll
2015-03-11 07:14 . 2015-02-20 04:12	25600	----a-w-	c:\windows\SysWow64\lpk.dll
2015-03-11 07:14 . 2015-01-31 03:48	3179520	----a-w-	c:\windows\system32\rdpcorets.dll
2015-03-11 07:14 . 2015-01-31 03:48	16384	----a-w-	c:\windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 07:14 . 2015-01-30 23:56	243200	----a-w-	c:\windows\system32\rdpudd.dll
2015-03-11 07:12 . 2015-01-17 02:48	1067520	----a-w-	c:\windows\system32\msctf.dll
2015-03-11 07:11 . 2015-02-20 02:50	66560	----a-w-	c:\windows\system32\iesetup.dll
2015-03-11 07:06 . 2015-02-04 03:16	465920	----a-w-	c:\windows\system32\WMPhoto.dll
2015-03-11 07:06 . 2015-02-04 02:54	417792	----a-w-	c:\windows\SysWow64\WMPhoto.dll
2015-03-05 16:07 . 2015-03-05 16:07	--------	d-----w-	c:\programdata\Auslogics
2015-03-05 16:06 . 2015-03-05 16:06	--------	d-----w-	c:\program files (x86)\Auslogics
2015-03-05 15:57 . 2015-03-05 16:02	--------	d-----w-	c:\users\ecp\AppData\Roaming\FreeFileSync
2015-03-05 15:56 . 2015-03-05 15:56	--------	d-----w-	c:\program files\FreeFileSync
2015-03-05 15:56 . 2015-03-05 15:56	--------	d-----w-	c:\users\ecp\AppData\Local\145842EF_stp
2015-03-05 15:28 . 2015-03-05 15:28	--------	d--h--w-	c:\programdata\CanonIJScan
2015-03-05 15:28 . 2015-03-05 15:28	--------	d-----w-	c:\users\ecp\AppData\Roaming\Canon
2015-03-05 07:19 . 2015-03-05 07:19	--------	d-s---w-	c:\windows\system32\CompatTel
2015-03-05 07:19 . 2015-03-05 07:19	--------	d-----w-	c:\windows\system32\appraiser
2015-03-05 07:19 . 2015-03-05 07:19	--------	d--h--w-	c:\programdata\CanonIJFAX
2015-03-05 07:18 . 2011-09-21 04:00	302592	----a-w-	c:\windows\system32\CNCALB0.DLL
2015-03-05 07:17 . 2011-09-22 07:59	358912	----a-w-	c:\windows\system32\CNC_B0L.dll
2015-03-05 07:17 . 2011-10-14 10:57	300544	----a-w-	c:\windows\system32\CNC_B0C.dll
2015-03-05 07:17 . 2011-10-14 10:56	109568	----a-w-	c:\windows\system32\CNC_B0I.dll
2015-03-05 07:17 . 2008-08-25 17:02	17920	----a-w-	c:\windows\system32\CNHMCA6.dll
2015-03-05 07:17 . 2011-10-14 10:57	102912	----a-w-	c:\windows\SysWow64\CNC_B0U.dll
2015-03-05 07:17 . 2011-09-22 07:57	316416	----a-w-	c:\windows\SysWow64\CNC_B0L.dll
2015-03-05 07:17 . 2008-08-25 17:02	15872	----a-w-	c:\windows\SysWow64\CNHMCA.dll
2015-03-05 07:17 . 2015-03-05 07:17	--------	d--h--w-	c:\windows\system32\CanonIJ Uninstaller Information
2015-03-05 07:16 . 2011-11-03 04:00	99840	----a-w-	c:\windows\system32\Spool\prtprocs\x64\CNMPPB0.DLL
2015-03-05 07:16 . 2011-11-03 04:00	30208	----a-w-	c:\windows\system32\Spool\prtprocs\x64\CNMPDB0.DLL
2015-03-05 07:15 . 2011-11-03 04:00	385024	----a-w-	c:\windows\system32\CNMLMB0.DLL
2015-03-05 06:28 . 2014-06-27 02:08	2777088	----a-w-	c:\windows\system32\msmpeg2vdec.dll
2015-03-05 06:28 . 2014-06-27 01:45	2285056	----a-w-	c:\windows\SysWow64\msmpeg2vdec.dll
2015-03-04 06:37 . 2015-01-09 03:14	29696	----a-w-	c:\windows\system32\powertracker.dll
2015-03-04 06:37 . 2015-01-09 03:14	91136	----a-w-	c:\windows\system32\wdi.dll
2015-03-04 06:37 . 2015-01-09 03:14	950272	----a-w-	c:\windows\system32\perftrack.dll
2015-03-04 06:37 . 2015-01-09 02:48	76800	----a-w-	c:\windows\SysWow64\wdi.dll
2015-03-04 06:36 . 2015-01-27 23:36	1239720	----a-w-	c:\windows\system32\aitstatic.exe
2015-03-04 06:36 . 2015-02-04 03:16	609280	----a-w-	c:\windows\system32\generaltel.dll
2015-03-04 06:36 . 2015-02-04 03:16	762368	----a-w-	c:\windows\system32\invagent.dll
2015-03-04 06:36 . 2015-02-04 03:16	414720	----a-w-	c:\windows\system32\devinv.dll
2015-03-04 06:36 . 2015-02-04 03:16	192000	----a-w-	c:\windows\system32\aepic.dll
2015-03-04 06:36 . 2015-02-04 03:13	1098752	----a-w-	c:\windows\system32\aeinv.dll
2015-03-04 06:36 . 2015-02-04 03:16	227328	----a-w-	c:\windows\system32\aepdu.dll
2015-03-04 06:36 . 2014-08-01 11:53	1031168	----a-w-	c:\windows\system32\TSWorkspace.dll
2015-03-04 06:36 . 2014-08-01 11:35	793600	----a-w-	c:\windows\SysWow64\TSWorkspace.dll
2015-03-04 06:35 . 2014-06-24 03:29	2565120	----a-w-	c:\windows\system32\d3d10warp.dll
2015-03-04 06:35 . 2014-06-24 02:59	1987584	----a-w-	c:\windows\SysWow64\d3d10warp.dll
2015-03-04 06:35 . 2014-07-09 02:03	7168	----a-w-	c:\windows\system32\KBDYAK.DLL
2015-03-04 06:35 . 2014-07-09 02:03	7168	----a-w-	c:\windows\system32\KBDTAT.DLL
2015-03-04 06:35 . 2014-07-09 02:03	7168	----a-w-	c:\windows\system32\KBDRU1.DLL
2015-03-04 06:35 . 2014-07-09 02:03	6656	----a-w-	c:\windows\system32\KBDRU.DLL
2015-03-04 06:35 . 2014-07-09 02:03	7168	----a-w-	c:\windows\system32\KBDBASH.DLL
2015-03-04 06:35 . 2014-07-09 01:31	7168	----a-w-	c:\windows\SysWow64\KBDYAK.DLL
2015-03-04 06:35 . 2014-07-09 01:31	6656	----a-w-	c:\windows\SysWow64\KBDBASH.DLL
2015-03-04 06:33 . 2014-10-14 02:13	3241984	----a-w-	c:\windows\system32\msi.dll
2015-03-04 06:33 . 2014-10-14 01:50	2363904	----a-w-	c:\windows\SysWow64\msi.dll
2015-03-04 06:31 . 2014-09-05 02:11	6584320	----a-w-	c:\windows\system32\mstscax.dll
2015-03-04 06:31 . 2014-09-05 01:52	5703168	----a-w-	c:\windows\SysWow64\mstscax.dll
2015-03-02 12:17 . 2015-03-02 12:24	--------	d-----w-	c:\users\ecp\AppData\Local\Audible
2015-03-02 12:17 . 2015-03-02 12:17	255352	----a-w-	c:\windows\SysWow64\awrdscdc.ax
2015-03-02 12:16 . 2001-08-17 21:43	24576	------w-	c:\windows\SysWow64\msxml3a.dll
2015-03-02 12:16 . 2003-03-18 20:20	1060864	------w-	c:\windows\SysWow64\mfc71.dll
2015-03-02 12:16 . 2015-03-02 12:17	--------	d-----w-	c:\program files (x86)\Audible
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-03-16 18:21 . 2014-07-23 09:43	778928	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2015-03-16 18:21 . 2014-07-23 09:43	142512	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-03-13 07:06 . 2014-07-22 15:37	122905848	----a-w-	c:\windows\system32\MRT.exe
2015-03-03 13:17 . 2010-11-21 03:27	295552	------w-	c:\windows\system32\MpSigStub.exe
2015-02-27 10:02 . 2015-01-20 08:11	893552	----a-w-	c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2015-02-27 10:02 . 2015-01-20 08:11	42168	----a-w-	c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2015-02-27 07:59 . 2015-01-05 04:08	1236816	----a-w-	c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2015-02-26 08:36 . 2015-01-01 10:55	893552	----a-w-	c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2015-02-26 08:36 . 2015-01-01 10:55	42168	----a-w-	c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2015-02-22 19:12 . 2015-01-01 10:55	1236816	----a-w-	c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2015-02-04 17:18 . 2015-02-04 17:19	98216	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
2015-01-28 17:26 . 2015-01-29 06:15	48792	----a-w-	c:\windows\system32\drivers\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64.sys
2015-01-25 04:44 . 2015-01-25 20:02	48792	----a-w-	c:\windows\system32\drivers\{16a92140-918d-4afb-9edb-46f22437bb10}w64.sys
2015-01-22 11:54 . 2015-01-22 22:12	48792	----a-w-	c:\windows\system32\drivers\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64.sys
2015-01-19 05:40 . 2015-01-19 18:36	48792	----a-w-	c:\windows\system32\drivers\{641e52b1-3179-43ed-8bcb-f688871e52b0}w64.sys
2015-01-16 12:38 . 2015-01-17 08:06	48792	----a-w-	c:\windows\system32\drivers\{ecd6aae4-019c-44b2-a0e5-570904275d66}w64.sys
2015-01-13 06:41 . 2015-01-13 19:33	48792	----a-w-	c:\windows\system32\drivers\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}Gw64.sys
2015-01-10 00:41 . 2015-01-10 13:37	48792	----a-w-	c:\windows\system32\drivers\{f81878fa-25e9-442d-8ada-79658b6520f2}Gw64.sys
2015-01-06 18:52 . 2015-01-07 06:22	48792	----a-w-	c:\windows\system32\drivers\{bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64.sys
2015-01-04 01:46 . 2015-01-04 19:13	48792	----a-w-	c:\windows\system32\drivers\{8d9208df-94f9-4c96-a224-97b37b0df94e}Gw64.sys
2014-12-31 19:43 . 2015-01-01 09:21	48792	----a-w-	c:\windows\system32\drivers\{ef3f84a6-599c-4148-a8eb-9aa938299b3e}Gw64.sys
2014-12-31 15:40 . 2012-07-17 13:37	23256	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-12-30 14:58 . 2015-02-22 08:34	1188440	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{263C914A-5E35-4A9C-A155-3F86BB10CC63}\gapaengine.dll
2014-12-30 14:58 . 2014-12-30 14:58	1188440	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-12-30 04:47 . 2014-12-30 15:44	48792	----a-w-	c:\windows\system32\drivers\{228c1c19-dcaa-4969-9dee-95888fe6a45e}Gw64.sys
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}]
2015-03-20 17:44	495616	----a-w-	c:\program files (x86)\ver0CheckMeUp\190.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-12-31 15:30	223432	----a-w-	c:\users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-12-31 15:30	223432	----a-w-	c:\users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-12-31 15:30	223432	----a-w-	c:\users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\SkyDriveShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-03-01 18643560]
"AudialsNotifier"="c:\program files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe" [2014-12-17 2410760]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-12-19 1022152]
"SoundMAXPnP"="c:\program files (x86)\Analog Devices\Core\smax4pnp.exe" [2009-05-18 1314816]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.150\SSScheduler.exe [2014-4-9 332016]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"RequireSignedAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 IePluginServices;IePlugin Services;c:\programdata\IePluginServices\PluginService.exe;c:\programdata\IePluginServices\PluginService.exe [x]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys;c:\windows\SYSNATIVE\DRIVERS\CAXHWAZL.sys [x]
R3 cpuz134;cpuz134;c:\users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys;c:\users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [x]
R3 globalUpdatem;globalUpdate Update Service (globalUpdatem);c:\program files (x86)\globalUpdate\Update\GoogleUpdate.exe;c:\program files (x86)\globalUpdate\Update\GoogleUpdate.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.150\McCHSvc.exe;c:\program files\McAfee Security Scan\3.8.150\McCHSvc.exe [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
S0 tammgF119;tammgF119 service;tammgF119 service [x]
S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiifx64.sys;c:\windows\SYSNATIVE\DRIVERS\smiifx64.sys [x]
S1 RrNetCapFilterDriver;RadioRip Filter Driver;c:\windows\system32\DRIVERS\RrNetCapFilterDriver.sys;c:\windows\SYSNATIVE\DRIVERS\RrNetCapFilterDriver.sys [x]
S2 9617fb41;SystemContinue;c:\windows\system32\rundll32.exe;c:\windows\SYSNATIVE\rundll32.exe [x]
S2 bobyzoom;bobyzoom;c:\programdata\bobyzoom\1.1.0.30\bzagnt.exe;c:\programdata\bobyzoom\1.1.0.30\bzagnt.exe [x]
S2 bzwdg;bzwdg;c:\programdata\bobyzoom\1.1.0.30\bzwdg.exe;c:\programdata\bobyzoom\1.1.0.30\bzwdg.exe [x]
S2 DiskBoss Service;DiskBoss Service;c:\program files (x86)\DiskBoss\bin\diskbsa.exe;c:\program files (x86)\DiskBoss\bin\diskbsa.exe [x]
S2 Gambali;Gambali;c:\programdata\SecurityUtility\Gambali.exe;c:\programdata\SecurityUtility\Gambali.exe [x]
S2 ReimageRealTimeProtector;Reimage Real Time Protector;c:\program files\Reimage\Reimage Protector\ReiGuard.exe;c:\program files\Reimage\Reimage Protector\ReiGuard.exe [x]
S2 SecurityUtility Service;SecurityUtility Service;c:\programdata\SecurityUtility\SecurityUtilitySrv.exe;c:\programdata\SecurityUtility\SecurityUtilitySrv.exe [x]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series - Adaptertreiber für Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys;c:\windows\SYSNATIVE\DRIVERS\netw5v64.sys [x]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2015-03-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-23 18:21]
.
2015-03-29 c:\windows\Tasks\CheckMeUp Update.job
- c:\program files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe [2015-03-20 17:44]
.
2015-03-18 c:\windows\Tasks\DriverDoc_UPDATES.job
- c:\program files (x86)\DriverDoc\Solvusoftdd.exe [2015-02-12 18:06]
.
2015-03-29 c:\windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.job
- c:\program files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.exe [2015-03-20 17:46]
.
2015-03-29 c:\windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.job
- c:\program files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.exe [2015-03-20 17:46]
.
2015-03-29 c:\windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10_user.job
- c:\program files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10.exe [2015-03-20 17:45]
.
2015-03-29 c:\windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.job
- c:\program files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.exe [2015-03-20 17:45]
.
2015-03-29 c:\windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.job
- c:\program files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.exe [2015-03-20 17:47]
.
2015-03-29 c:\windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5_user.job
- c:\program files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.exe [2015-03-20 17:47]
.
2015-03-29 c:\windows\Tasks\globalUpdateUpdateTaskMachineCore.job
- c:\program files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-03-20 17:45]
.
2015-03-27 c:\windows\Tasks\globalUpdateUpdateTaskMachineUA.job
- c:\program files (x86)\globalUpdate\Update\GoogleUpdate.exe [2015-03-20 17:45]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}]
2015-03-20 17:44	237568	----a-w-	c:\program files (x86)\ver0CheckMeUp\190_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-12-31 15:30	262344	----a-w-	c:\users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-12-31 15:30	262344	----a-w-	c:\users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-12-31 15:30	262344	----a-w-	c:\users\ecp\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2015-01-30 1332296]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 165912]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 385560]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 363544]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mDefault_Search_URL = hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms}
mDefault_Page_URL = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms}
uInternet Settings,ProxyOverride = <-loopback>
uInternet Settings,ProxyServer = http=127.0.0.1:49207;https=127.0.0.1:49207
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\
FF - prefs.js: keyword.URL - 
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
BHO-{007c182f-91dc-485e-a48f-b4ad99086949} - c:\program files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.dll
BHO-{3dcc325d-9258-4278-ac06-bc06aafb8809} - c:\program files (x86)\ddeallpeAuk\83pi0tURGPEZSW.dll
BHO-{f1a892aa-d8f1-4a2a-a980-430349d85d2a} - c:\program files (x86)\Saveitkeaep\OUx1yNk71u3K2I.dll
BHO-{007c182f-91dc-485e-a48f-b4ad99086949} - c:\program files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.x64.dll
BHO-{3dcc325d-9258-4278-ac06-bc06aafb8809} - c:\program files (x86)\ddeallpeAuk\83pi0tURGPEZSW.x64.dll
BHO-{f1a892aa-d8f1-4a2a-a980-430349d85d2a} - c:\program files (x86)\Saveitkeaep\OUx1yNk71u3K2I.x64.dll
WebBrowser-{4F524A2D-5350-4500-76A7-7A786E7484D7} - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-{9D8D5AD9-94C7-40B3-88F2-2B8F227F6381} - c:\programdata\bobyzoom\1.1.0.30\Uninstaller.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tammgF119]
"ImagePath"="\??\c:\windows\system32\Drivers\tammgF119.sys"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\tammgR119]
"ImagePath"="\??\c:\windows\system32\Drivers\tammgR119.sys"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (S-1-5-21-1780445102-594666999-3139876592-1000)
@Denied: (2) (LocalSystem)
"Progid"="ThunderbirdEML"
.
[HKEY_USERS\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.16"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\SysWOW64\rundll32.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\LENOVO\HOTKEY\TPHKSVC.exe
c:\program files (x86)\Dynamo Combo\updateDynamoCombo.exe
c:\program files (x86)\PC Speed Maximizer\SPMSchedule.exe
c:\program files (x86)\Dynamo Combo\bin\utilDynamoCombo.exe
c:\program files\LENOVO\HOTKEY\tposdsvc.exe
c:\program files\Lenovo\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\Zoom\TpScrex.exe
c:\program files (x86)\ver0CheckMeUp\CheckMeUp.exe
c:\programdata\bobyzoom\1.1.0.30\bz32.exe
c:\programdata\bobyzoom\1.1.0.30\bzdap.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2015-03-29  22:58:39 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2015-03-29 20:58
.
Vor Suchlauf: 12 Verzeichnis(se), 112.684.433.408 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 113.349.279.744 Bytes frei
.
- - End Of File - - C7BC35C7B82A05D44931358E53FE5B24
A36C5E4F47E84449FF07ED3517B43A31
         

Gruß Hausmeister

Alt 30.03.2015, 17:08   #5
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Standard

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 04.04.2015, 22:50   #6
Haus meister
 
Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Standard

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen



Hallo Schrauber,

alles ausgeführt, hier die Logs:

MBAM:
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 04.04.2015
Suchlauf-Zeit: 22:27:23
Logdatei: mbam.txt
Administrator: Ja

Version: 2.01.4.1018
Malware Datenbank: v2015.03.09.05
Rootkit Datenbank: v2015.02.25.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: ecp

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 358184
Verstrichene Zeit: 32 Min, 30 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 7
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe, 2584, Löschen bei Neustart, [df9a8ab91e6cc175d1a63cce9a6807f9]
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.exe, 2704, Löschen bei Neustart, [126763e03654dd59b5c295757d857090]
PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.exe, 4012, Löschen bei Neustart, [c0b9f35014769b9bca1628edd63055ab]
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe, 2092, Löschen bei Neustart, [552441022961fb3bcb83d9d02bd802fe]
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\CheckMeUp.exe, 3244, Löschen bei Neustart, [6d0c67dcf496ba7c5c765740cd365da3]
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe, 4092, Löschen bei Neustart, [6d0c67dcf496ba7c5c765740cd365da3]
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\Gambali.exe, 1900, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02]

Module: 9
PUP.Optional.Multiplug, C:\Program Files (x86)\SystemContinue\SystemContinue.dll, Löschen bei Neustart, [4039fc47f8920a2c6d5d73b92dd5a957], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\freebl3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\GambaliCrt.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libnspr4.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplc4.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplds4.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nss3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssutil3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\smime3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 

Registrierungsschlüssel: 166
PUP.Optional.DynamoCombo.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Dynamo Combo, In Quarantäne, [df9a8ab91e6cc175d1a63cce9a6807f9], 
PUP.Optional.DynamoCombo.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util Dynamo Combo, In Quarantäne, [126763e03654dd59b5c295757d857090], 
PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, In Quarantäne, [0c6d2221107a0036e369705d649dcf31], 
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, In Quarantäne, [7405cf74a6e4b6808396bec32bd6bc44], 
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [72074ff42a60af876d0a163f2bd811ef], 
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [72074ff42a60af876d0a163f2bd811ef], 
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [72074ff42a60af876d0a163f2bd811ef], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{986c37a1-7b65-476f-80dc-54f80bd4b0d6}, In Quarantäne, [3247073c94f6ce68e4d876a1ce35e31d], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{986c37a1-7b65-476f-80dc-54f80bd4b0d6}, In Quarantäne, [3247073c94f6ce68e4d876a1ce35e31d], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{1278437a-a623-4925-a09a-001a2a616d48}, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\P1278437a_a623_4925_a09a_001a2a616d48_.P1278437a_a623_4925_a09a_001a2a616d48_, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\P1278437a_a623_4925_a09a_001a2a616d48_.P1278437a_a623_4925_a09a_001a2a616d48_.9, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P1278437a_a623_4925_a09a_001a2a616d48_.P1278437a_a623_4925_a09a_001a2a616d48_, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P1278437a_a623_4925_a09a_001a2a616d48_.P1278437a_a623_4925_a09a_001a2a616d48_.9, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P1278437a_a623_4925_a09a_001a2a616d48_.P1278437a_a623_4925_a09a_001a2a616d48_, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P1278437a_a623_4925_a09a_001a2a616d48_.P1278437a_a623_4925_a09a_001a2a616d48_.9, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{00d11864-a77a-4c9a-a436-b273b7a94da2}, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\P00d11864_a77a_4c9a_a436_b273b7a94da2_.P00d11864_a77a_4c9a_a436_b273b7a94da2_, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\P00d11864_a77a_4c9a_a436_b273b7a94da2_.P00d11864_a77a_4c9a_a436_b273b7a94da2_.9, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P00d11864_a77a_4c9a_a436_b273b7a94da2_.P00d11864_a77a_4c9a_a436_b273b7a94da2_, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P00d11864_a77a_4c9a_a436_b273b7a94da2_.P00d11864_a77a_4c9a_a436_b273b7a94da2_.9, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P00d11864_a77a_4c9a_a436_b273b7a94da2_.P00d11864_a77a_4c9a_a436_b273b7a94da2_, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P00d11864_a77a_4c9a_a436_b273b7a94da2_.P00d11864_a77a_4c9a_a436_b273b7a94da2_.9, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{54ebf294-2ffa-4467-8cad-bc8048be7f9c}, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.P54ebf294_2ffa_4467_8cad_bc8048be7f9c_, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.9, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.P54ebf294_2ffa_4467_8cad_bc8048be7f9c_, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.9, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.P54ebf294_2ffa_4467_8cad_bc8048be7f9c_, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], 
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.P54ebf294_2ffa_4467_8cad_bc8048be7f9c_.9, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], 
PUP.Optional.WebTInst.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\webTinstMKTN, In Quarantäne, [2d4cc57e583206307da0ccdc8e757e82], 
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{228c1c19-dcaa-4969-9dee-95888fe6a45e}Gw64, In Quarantäne, [443575cef49637ff1950fbd1c73c51af], 
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{8d9208df-94f9-4c96-a224-97b37b0df94e}Gw64, In Quarantäne, [1b5e89ba008a61d52841af1d3fc47888], 
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64, In Quarantäne, [1f5a02418307fe3894d515b7bf44956b], 
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}Gw64, In Quarantäne, [abcef54e7c0ed06677f2c40821e2d12f], 
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{ef3f84a6-599c-4148-a8eb-9aa938299b3e}Gw64, In Quarantäne, [abcec182c0cad85e14554686fb08ec14], 
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{f81878fa-25e9-442d-8ada-79658b6520f2}Gw64, In Quarantäne, [0772e162aedceb4b2b3ef9d325dec937], 
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{16a92140-918d-4afb-9edb-46f22437bb10}w64, In Quarantäne, [7207dd66adddd066d4bf1d0d669f6f91], 
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64, In Quarantäne, [2554fb486f1bdc5a573ca78354b17c84], 
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{641e52b1-3179-43ed-8bcb-f688871e52b0}w64, In Quarantäne, [5524dc6791f9b87e553e989239cc57a9], 
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64, In Quarantäne, [1e5b93b05634c571326149e146bfe11f], 
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{ecd6aae4-019c-44b2-a0e5-570904275d66}w64, In Quarantäne, [3d3cfe457c0e64d2f0a31515778e43bd], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, In Quarantäne, [cfaaa89bf49688aec95401e8fe0559a7], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\WOW6432NODE\Dynamo Combo, In Quarantäne, [64151b281f6b082ea0958f23e023e818], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\HQCinema Pro 2.1V20.03, In Quarantäne, [d9a086bd8efc68ce543202b87c873bc5], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\HQCinema Pro 2.1V20.03-nv-ie, In Quarantäne, [2950b58e791196a03f4742780102f60a], 
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [abce98ab2f5b3afcf3e23ceec93ca060], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, In Quarantäne, [c8b1f74ccfbb181e8d10b0167e85ae52], 
PUP.Optional.ViView.A, HKLM\SOFTWARE\WOW6432NODE\vi-viewSoftware, In Quarantäne, [32479ca715758da95835654df310fa06], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, In Quarantäne, [631689ba8bffa096a7cfc905d52e07f9], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\30935, In Quarantäne, [1069e063503a1026908dfdec63a035cb], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, In Quarantäne, [b7c2dc67c3c763d30f8551dcb64f40c0], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, In Quarantäne, [2851a49f7f0bca6c1a7b9a9330d5a35d], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, In Quarantäne, [b5c47ec51872e056425a2a9cb44f59a7], 
PUP.Optional.SystemContinue.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\9617fb41, In Quarantäne, [582120236f1b14228cf18b1c82816799], 
PUP.Optional.SecurityUtility.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SecurityUtility Service, In Quarantäne, [552441022961fb3bcb83d9d02bd802fe], 
PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginServices, In Quarantäne, [0c6dd66d2e5c44f2c3138635897aa35d], 
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, In Quarantäne, [4a2f57ecd3b70e2807d0605b8a7928d8], 
PUP.Optional.CrossRider.A, HKU\S-1-5-18\SOFTWARE\HQCinema Pro 2.1V20.03-nv-ie, In Quarantäne, [b9c085bee7a34fe7ea9d407a40c3768a], 
PUP.Optional.Binkiland.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Binkiland Browser, In Quarantäne, [0673a79cec9ed066d340cf68f11453ad], 
PUP.Optional.DynamoCombo.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Dynamo Combo, In Quarantäne, [fe7bcd762a600e28e452c0f22dd6629e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\HQCinema Pro 2.1V20.03, In Quarantäne, [2158d86b6f1b84b2f7902e8c9b68ea16], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\HQCinema Pro 2.1V20.03-nv-ie, In Quarantäne, [5326192a6d1d989e3750407aff045ea2], 
PUP.Optional.RocketTab.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\RocketTabInstalled, In Quarantäne, [5e1b9aa9dcae4aec2002dfe505feca36], 
PUP.Optional.Vosteran.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Vosteran Browser, In Quarantäne, [51287bc8d0ba58de8a75f6ba37cc9a66], 
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [8decf94a83076acce2578e67c93a669a], 
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\INSTALLCORE, In Quarantäne, [324703406e1c013536e0759626df8a76], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, In Quarantäne, [1b5e68dbaedc0135c1faa022ad565da3], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\HQ CinemaV20.03, In Quarantäne, [7aff5ce7f199bb7bf557dfd855ae3fc1], 
PUP.Optional.RocketTab.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\SEARCH EXTENSIONS, In Quarantäne, [a3d65fe4f09a61d5515c250c51b432ce], 
PUP.Optional.KeepMySearch.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000_Classes\keepmysearch, In Quarantäne, [89f0a3a02f5bac8a053011a5659e758b], 
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickCtrl.10, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\globalUpdate.OneClickCtrl.10, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.Update3WebControl.4, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\globalUpdate.Update3WebControl.4, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\HQCinema Pro 2.1V20.03, In Quarantäne, [0d6ceb587d0d68ce8c8097fe2cd7ce32], 
PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{72C9F141-C00A-616D-EE9D-69F082519D04}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E35B177E-4F63-BC4D-20BA-4FD509C6144B}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E35B177E-4F63-BC4D-20BA-4FD509C6144B}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{E35B177E-4F63-BC4D-20BA-4FD509C6144B}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{72C9F141-C00A-616D-EE9D-69F082519D04}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{72C9F141-C00A-616D-EE9D-69F082519D04}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\CLASSES\CLSID\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\CLASSES\CLSID\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}\INPROCSERVER32, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{B7A5EE16-3FED-399F-55F6-58AF84D02FC4}, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\C441D512-F5C2-07AC-8AE0-499C197A5D55, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Dynamo Combo, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{ac225167-00fc-452d-94c5-bb93600e7d9a}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.SecurityUtility.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Gambali, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{CD6F4F21-2287-4B46-82E5-530F4739C2B7}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{17B22A43-07EE-45AC-852C-BE612516B3FF}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{376B5603-A82C-41C6-8295-FE987FAAFFC0}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4351B7B4-6877-4868-8086-5810EEF0E6BF}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{45815B84-A33A-4144-A0F5-1F8FA0FBDD5A}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5A4ADDA0-6AF3-4FD1-B449-CA4156C4005C}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5ACB2FB1-ADB6-4B3A-ACA6-B47D213453C6}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{70A68E56-76A5-4870-8445-BC19846CF6AD}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{79B39846-AAF0-448E-A69C-BD8DD17C9354}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{87CA5D07-F5A7-4A3C-B18C-52028A56A378}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8E0A9D44-E2B9-40DC-8734-8DE53E362806}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B009BABC-3F0C-4255-9C4D-00E2836CA4C6}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F3DA2DA3-22C3-46E4-A3BE-B4A13185E6B0}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F7515862-DFE9-4673-BC9E-4A091B43F2F1}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{17B22A43-07EE-45AC-852C-BE612516B3FF}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{376B5603-A82C-41C6-8295-FE987FAAFFC0}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4351B7B4-6877-4868-8086-5810EEF0E6BF}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{45815B84-A33A-4144-A0F5-1F8FA0FBDD5A}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5A4ADDA0-6AF3-4FD1-B449-CA4156C4005C}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5ACB2FB1-ADB6-4B3A-ACA6-B47D213453C6}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{70A68E56-76A5-4870-8445-BC19846CF6AD}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{79B39846-AAF0-448E-A69C-BD8DD17C9354}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{87CA5D07-F5A7-4A3C-B18C-52028A56A378}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8E0A9D44-E2B9-40DC-8734-8DE53E362806}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B009BABC-3F0C-4255-9C4D-00E2836CA4C6}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F3DA2DA3-22C3-46E4-A3BE-B4A13185E6B0}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F7515862-DFE9-4673-BC9E-4A091B43F2F1}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{17B22A43-07EE-45AC-852C-BE612516B3FF}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{376B5603-A82C-41C6-8295-FE987FAAFFC0}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{4351B7B4-6877-4868-8086-5810EEF0E6BF}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{45815B84-A33A-4144-A0F5-1F8FA0FBDD5A}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{5A4ADDA0-6AF3-4FD1-B449-CA4156C4005C}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{5ACB2FB1-ADB6-4B3A-ACA6-B47D213453C6}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{70A68E56-76A5-4870-8445-BC19846CF6AD}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{79B39846-AAF0-448E-A69C-BD8DD17C9354}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{87CA5D07-F5A7-4A3C-B18C-52028A56A378}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{8E0A9D44-E2B9-40DC-8734-8DE53E362806}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B009BABC-3F0C-4255-9C4D-00E2836CA4C6}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F3DA2DA3-22C3-46E4-A3BE-B4A13185E6B0}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F7515862-DFE9-4673-BC9E-4A091B43F2F1}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{CD6F4F21-2287-4B46-82E5-530F4739C2B7}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{CD6F4F21-2287-4B46-82E5-530F4739C2B7}, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SecurityUtility Service, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 

Registrierungswerte: 7
PUP.Optional.Ask.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{4F524A2D-5350-4500-76A7-7A786E7484D7}, In Quarantäne, [d9a0b093d0ba290da75b180353b033cd], 
PUP.Optional.Ask.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{4F524A2D-5350-4500-76A7-7A786E7484D7}, ä¨*ä½?åä??ê¶ç¡ºç?®í??, In Quarantäne, [d9a0b093d0ba290da75b180353b033cd]
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, In Quarantäne, [631689ba8bffa096a7cfc905d52e07f9]
PUP.Optional.Vosteran, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\WSE_Vosteran\\, In Quarantäne, [e495d66dbccec76f0e2c3302b35227d9]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, cor, In Quarantäne, [b5c47ec51872e056425a2a9cb44f59a7]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\INSTALLCORE|tb, zr2X2X1G1S1F2V1S2Q0V, In Quarantäne, [324703406e1c013536e0759626df8a76]
PUP.Optional.RocketTab.A, HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\SEARCH EXTENSIONS|RocketTab, 1, In Quarantäne, [a3d65fe4f09a61d5515c250c51b432ce]

Registrierungsdaten: 2
PUP.Optional.ViView.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms}),Ersetzt,[8decf3502268bf772f30fbda18ed60a0]
PUP.Optional.ViView.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://myhome.vi-view.com/web/?type=ds&ts=1419953421&from=cor&uid=HITACHIXHTS542516K9SA00_080730BB6C025GG0AVKFX&q={searchTerms}),Ersetzt,[2a4f271c2e5ca78f9cc16a6b8e77e31d]

Ordner: 25
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, In Quarantäne, [bfba74cf1278a78ff1890f6fdf2415eb], 
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [bfba74cf1278a78ff1890f6fdf2415eb], 
PUP.Optional.PayByAds.A, C:\Users\ecp\AppData\Local\Pay-By-Ads, In Quarantäne, [740549fae4a69b9b520100809e653ec2], 
PUP.Optional.PayByAds.A, C:\Users\ecp\AppData\Local\Pay-By-Ads\Yahoo! Search, In Quarantäne, [740549fae4a69b9b520100809e653ec2], 
PUP.Optional.PayByAds.A, C:\Users\ecp\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2, In Quarantäne, [740549fae4a69b9b520100809e653ec2], 
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, In Quarantäne, [8beea49f6f1bec4a9609324e31d21de3], 
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [8beea49f6f1bec4a9609324e31d21de3], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Download, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Install, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline\{FD96D83D-E3C2-4F6E-AE7A-36DA9A3C8148}, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.PriceFountain.A, C:\Users\ecp\AppData\Roaming\PriceFountain, In Quarantäne, [e8912c175d2db2843045d5b85ca7df21], 
PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03, Löschen bei Neustart, [0d6ceb587d0d68ce8c8097fe2cd7ce32], 
PUP.Optional.Vosteran.A, C:\Users\ecp\AppData\Local\Vosteran, In Quarantäne, [c3b676cdee9c35013e874254966dce32], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp, Löschen bei Neustart, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\x64, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.LowPricesApp.A, C:\ProgramData\LowPricesApp, In Quarantäne, [493068dbeb9fcf678e0a3863e2217888], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo, Löschen bei Neustart, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin, Löschen bei Neustart, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\TEMP, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.WorldWideCoupon.A, C:\ProgramData\WorldWideCoupon, In Quarantäne, [077212315832b68059358f0d0bf86997], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 

Dateien: 185
PUP.Optional.Multiplug, C:\Program Files (x86)\SystemContinue\SystemContinue.dll, Löschen bei Neustart, [4039fc47f8920a2c6d5d73b92dd5a957], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\updateDynamoCombo.exe, Löschen bei Neustart, [df9a8ab91e6cc175d1a63cce9a6807f9], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.exe, Löschen bei Neustart, [126763e03654dd59b5c295757d857090], 
PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.exe, Löschen bei Neustart, [c0b9f35014769b9bca1628edd63055ab], 
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, In Quarantäne, [0c6d2221107a0036e369705d649dcf31], 
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, In Quarantäne, [7405cf74a6e4b6808396bec32bd6bc44], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\DynamoComboBHO.dll, In Quarantäne, [3247073c94f6ce68e4d876a1ce35e31d], 
PUP.Optional.Multiplug, C:\ProgramData\saFerwEb\cf5LUq4nBR5ThG.x64.dll, In Quarantäne, [6019a1a26c1eb97d86f13df3f50dc53b], 
PUP.Optional.Multiplug, C:\ProgramData\SmaaritCoimepare\XFAYI1dRVqhfLA.x64.dll, In Quarantäne, [a6d39ca78406e15580f71a164cb606fa], 
PUP.Optional.Multiplug, C:\ProgramData\woEbsauVer\IB67JLTGvVSAqw.x64.dll, In Quarantäne, [2a4fef547416a393b6c1949cd52d41bf], 
PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.exe, In Quarantäne, [780102412961bd79f1eff1240ef819e7], 
PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10.exe, In Quarantäne, [f584a69dec9e76c059877a9b59ad33cd], 
PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.exe, In Quarantäne, [f28770d396f44fe7fae638ddc541669a], 
PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.exe, In Quarantäne, [1465e261d5b59f97ab3530e5877f57a9], 
PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\UninstallBrw.exe, In Quarantäne, [1f5a0d36cfbbd3638b559184828451af], 
PUP.Optional.Gambali.A, C:\Windows\System32\GambaliOff.ini, In Quarantäne, [8bee7cc7eb9ff046998355520bf832ce], 
PUP.Optional.Gambali.A, C:\Windows\SysWOW64\GambaliOff.ini, In Quarantäne, [f584172c9bef280e60bc7136ad5622de], 
PUP.Optional.Gambali.A, C:\Windows\Temp\Gambali.log, Löschen bei Neustart, [a0d994aff892c96dd746a8ffb84b9c64], 
PUP.Optional.Gambali.A, C:\Windows\Temp\Gambalir.log, In Quarantäne, [a0d9ed56c2c810260915fdaa20e30df3], 
PUP.Optional.WebTInst.A, C:\Windows\System32\drivers\Msft_Kernel_webTinstMKTN_01009.Wdf, In Quarantäne, [9ddc182b3b4f3df91b01a701e71cb050], 
PUP.Optional.WebTInst.A, C:\Windows\System32\drivers\webTinstMKTN.sys, In Quarantäne, [2d4cc57e583206307da0ccdc8e757e82], 
PUP.Optional.Patsearch.A, C:\Windows\patsearch.bin, In Quarantäne, [a0d93c07a0ea3afc5ab55d525aa9ff01], 
PUP.Optional.Shost.A, C:\Windows\shost.bin, In Quarantäne, [91e83e05731703330bd8446b01029e62], 
PUP.Optional.CheckMeUp.A, C:\Windows\Tasks\CheckMeUp Update.job, In Quarantäne, [7affe55eff8b1b1b97ed8630c73c1de3], 
PUP.Optional.CheckMeUp.A, C:\Windows\System32\Tasks\CheckMeUp Update, In Quarantäne, [b9c06ad9f5950630473e2c8a699a2cd4], 
PUP.Optional.RocketTab.A, C:\Windows\System32\Tasks\RocketTab, In Quarantäne, [542563e02961e650c75d8d379c6731cf], 
PUP.Optional.RocketTab.A, C:\Windows\System32\Tasks\RocketTab Update Task, In Quarantäne, [a2d787bc266449ede242299bed16867a], 
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{228c1c19-dcaa-4969-9dee-95888fe6a45e}Gw64.sys, In Quarantäne, [443575cef49637ff1950fbd1c73c51af], 
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{8d9208df-94f9-4c96-a224-97b37b0df94e}Gw64.sys, In Quarantäne, [1b5e89ba008a61d52841af1d3fc47888], 
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{bf5001a3-ae7a-4910-925a-5060ef2c0508}Gw64.sys, In Quarantäne, [1f5a02418307fe3894d515b7bf44956b], 
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}Gw64.sys, In Quarantäne, [abcef54e7c0ed06677f2c40821e2d12f], 
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{ef3f84a6-599c-4148-a8eb-9aa938299b3e}Gw64.sys, In Quarantäne, [abcec182c0cad85e14554686fb08ec14], 
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{f81878fa-25e9-442d-8ada-79658b6520f2}Gw64.sys, In Quarantäne, [0772e162aedceb4b2b3ef9d325dec937], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6, In Quarantäne, [cbae9da6d5b5b97dbcb5ffcf07fc02fe], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7, In Quarantäne, [bcbd57ec27636dc97af7cc027d860ef2], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10_user, In Quarantäne, [cfaab48f08820432680996389a6911ef], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11, In Quarantäne, [88f1d86b3d4daa8c6b06ba14b350837d], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5, In Quarantäne, [e4950a3998f28fa7fe73eee0976c7d83], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5_user, In Quarantäne, [95e48fb48cfe5fd77bf6319d9370f010], 
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{16a92140-918d-4afb-9edb-46f22437bb10}w64.sys, In Quarantäne, [7207dd66adddd066d4bf1d0d669f6f91], 
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64.sys, In Quarantäne, [2554fb486f1bdc5a573ca78354b17c84], 
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{641e52b1-3179-43ed-8bcb-f688871e52b0}w64.sys, In Quarantäne, [5524dc6791f9b87e553e989239cc57a9], 
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}w64.sys, In Quarantäne, [1e5b93b05634c571326149e146bfe11f], 
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{ecd6aae4-019c-44b2-a0e5-570904275d66}w64.sys, In Quarantäne, [3d3cfe457c0e64d2f0a31515778e43bd], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-6.job, In Quarantäne, [7009e75cf793191db0bda2891beabd43], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-1-7.job, In Quarantäne, [fd7ca59e0981a393f37a71ba8283b14f], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-10_user.job, In Quarantäne, [2a4fc083632790a60c6163c8b0557789], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-11.job, In Quarantäne, [c0b9fe45abdf5cdae7861e0d1fe63ec2], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5.job, In Quarantäne, [d0a9291acac0d75f105da48728ddfb05], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\ea435ecc-472f-4e7b-afe0-dce5baec5f6a-5_user.job, In Quarantäne, [4a2fb093e5a55dd965087ab16b9af20e], 
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, In Quarantäne, [493040035832063080fca18a7c89d729], 
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, In Quarantäne, [1b5ec67d4c3e63d3c6b728037491c838], 
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, In Quarantäne, [2c4d0043d9b17db97707bb702dd8b64a], 
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, In Quarantäne, [2059c57eff8bdf57bcc3191253b207f9], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe, Löschen bei Neustart, [552441022961fb3bcb83d9d02bd802fe], 
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [8beea49f6f1bec4a9609324e31d21de3], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdate.dll, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psmachine.dll, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psuser.dll, In Quarantäne, [c8b19aa9fc8ec1755a13443ebe451ee2], 
PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\bgNova.html, In Quarantäne, [0d6ceb587d0d68ce8c8097fe2cd7ce32], 
PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\ea435ecc-472f-4e7b-afe0-dce5baec5f6a.crx, In Quarantäne, [0d6ceb587d0d68ce8c8097fe2cd7ce32], 
PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\Uninstall.exe, In Quarantäne, [0d6ceb587d0d68ce8c8097fe2cd7ce32], 
PUP.Optional.CrossRider.A, C:\Program Files (x86)\HQCinema Pro 2.1V20.03\utils.exe, In Quarantäne, [0d6ceb587d0d68ce8c8097fe2cd7ce32], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\190.crx, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\190.dat, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\190.dll, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\190_x64.dll, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\190.xpi, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\CheckMeUp.exe, Löschen bei Neustart, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.dll, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\j4CheckMeUpK09.exe, Löschen bei Neustart, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\sqlite3.dll, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\Uninstall.exe, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\x64\TandemRunner.exe, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\x64\WdfCoInstaller01009.dll, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\x64\webinstr.inf, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.CheckMeUp.A, C:\Program Files (x86)\ver0CheckMeUp\x64\webTinstMKTN.sys, In Quarantäne, [6d0c67dcf496ba7c5c765740cd365da3], 
PUP.Optional.LowPricesApp.A, C:\ProgramData\LowPricesApp\LowPricesApp.exe, In Quarantäne, [493068dbeb9fcf678e0a3863e2217888], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\ccbonclchokkgohppbnobaohohhldpap.crx, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\DynamoCombo.ico, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\DynamoComboUn.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\DynamoComboUninstall.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\updateDynamoCombo.InstallState, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\16a92140918d4afb9edb.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\16a92140918d4afb9edb46f22437bb10.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\16a92140918d4afb9edb46f22437bb1064.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\16a92140918d4afb9edb64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\228c1c19dcaa49699dee.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\228c1c19dcaa49699dee64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\3bcf4f2c0bbb4d4cbf1f.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\3bcf4f2c0bbb4d4cbf1f11bbe6d501ea.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\3bcf4f2c0bbb4d4cbf1f11bbe6d501ea64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\3bcf4f2c0bbb4d4cbf1f64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcb.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcb64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcbf688871e52b0.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\641e52b1317943ed8bcbf688871e52b064.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BrowserAdapter.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BrowserAdapter64.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.expext.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.expext.zip, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.expextdll.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.PurBrowse.zip, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.PurBrowse64.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ebd8d0c0e0224b76a1f2.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ebd8d0c0e0224b76a1f264.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\sqlite3.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\utilDynamoCombo.InstallState, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\915cb94bb4d84c0e83b4.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\915cb94bb4d84c0e83b461409471b1c3.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\915cb94bb4d84c0e83b461409471b1c364.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\915cb94bb4d84c0e83b464.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\bf5001a3ae7a4910925a.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\bf5001a3ae7a4910925a64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\8d9208df94f94c96a224.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\8d9208df94f94c96a22464.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{228c1c19-dcaa-4969-9dee-95888fe6a45e}64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{8d9208df-94f9-4c96-a224-97b37b0df94e}.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{8d9208df-94f9-4c96-a224-97b37b0df94e}64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{bf5001a3-ae7a-4910-925a-5060ef2c0508}.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{bf5001a3-ae7a-4910-925a-5060ef2c0508}64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{ebd8d0c0-e022-4b76-a1f2-bc2963e3a147}64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{ef3f84a6-599c-4148-a8eb-9aa938299b3e}.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{ef3f84a6-599c-4148-a8eb-9aa938299b3e}64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{f81878fa-25e9-442d-8ada-79658b6520f2}.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{f81878fa-25e9-442d-8ada-79658b6520f2}64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\7za.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BOASPRT.exe.PendingOverwrite, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\{228c1c19-dcaa-4969-9dee-95888fe6a45e}.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ecd6aae4019c44b2a0e5.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ecd6aae4019c44b2a0e5570904275d66.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ecd6aae4019c44b2a0e5570904275d6664.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ecd6aae4019c44b2a0e564.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ef3f84a6599c4148a8eb.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\ef3f84a6599c4148a8eb64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\eula.txt, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\f81878fa25e9442d8ada.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\f81878fa25e9442d8ada64.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\BrowserAdapter.7z, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BOAS.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BOAS.zip, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BOASHelper.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BOASPRT.exe, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.BOAS.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.BrowserAdapter.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.CompatibilityChecker.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.ExpExt.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.FFUpdate.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.GCUpdate.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.OfSvc.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.OptChecker.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.PurBrowse.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.DynamoCombo.A, C:\Program Files (x86)\Dynamo Combo\bin\plugins\DynamoCombo.Repmon.dll, In Quarantäne, [e7921f248bff50e6432df0acb94a08f8], 
PUP.Optional.WorldWideCoupon.A, C:\ProgramData\WorldWideCoupon\WorldWideCoupon.exe, In Quarantäne, [077212315832b68059358f0d0bf86997], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\freebl3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\Gambali.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\Gambali.exe, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\Gambali.tlb, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\Gambali64.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\GambaliCrt.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libnspr4.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplc4.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplds4.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nss3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssckbi.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssdbm3.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssutil3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RfndNSIS.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RgsBTMedia.exe, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RgsBTMedia.ini, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RgsBTMedia64.exe, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\smime3.dll, Löschen bei Neustart, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\SoftConfigTest.exe, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\softokn3.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\sqlite3.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 
PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ssl3.dll, In Quarantäne, [f0896bd83d4de6500dbb623f62a1fe02], 

Physische Sektoren: 0
(Keine schädliche Elemente gefunden)


(end)
         

und hier noch ein zweites MBAM Log-File. Ich glaube das wurde geschrieben weil der Rechner keinen Zugriff aufs Netz hat und die Software nicht aktualisiert werden konnte. zur Sicherheit füge ich es aber mal bei:

MBAM 2:
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org


Update, 04.04.2015 22:27:04, SYSTEM, ECP-PC, Manual, Failed, Unable to access update server, 
Update, 04.04.2015 22:27:23, SYSTEM, ECP-PC, Manual, Failed, Unable to access update server, 
Scan, 04.04.2015 23:03:37, SYSTEM, ECP-PC, Manual, Start: 04.04.2015 22:27:23, Dauer: 32 Minuten 30 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, "401" nicht-Malwareerkennung, 
Error, 04.04.2015 23:05:31, SYSTEM, ECP-PC, Protection, IsLicensed, 13, 
Protection, 04.04.2015 23:05:32, SYSTEM, ECP-PC, Protection, Malware Protection, Stopping, 
Protection, 04.04.2015 23:05:32, SYSTEM, ECP-PC, Protection, Malware Protection, Stopped, 

(end)
         

AdwCleaner
Code:
ATTFilter
# AdwCleaner v4.200 - Bericht erstellt 04/04/2015 um 23:20:11
# Aktualisiert 29/03/2015 von Xplode
# Datenbank : 2015-03-29.1 [Lokal]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : ecp - ECP-PC
# Gestarted von : C:\Reinigung\dritteRunde\AdwCleaner_4.200.exe
# Option : Löschen

***** [ Dienste ] *****

[#] Dienst Gelöscht : bobyzoom
[#] Dienst Gelöscht : ReimageRealTimeProtector
[#] Dienst Gelöscht : tammgF119
[#] Dienst Gelöscht : tammgR119

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\apn
Ordner Gelöscht : C:\ProgramData\Reimage Protector
[/!\] Nicht Gelöscht ( Junction ) : C:\ProgramData\bobyzoom
Ordner Gelöscht : C:\ProgramData\d6e05fef7be4142c
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Maximizer
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pro PC Cleaner
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reimage repair
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Program Files (x86)\PC Speed Maximizer
Ordner Gelöscht : C:\Program Files (x86)\Pro PC Cleaner
Ordner Gelöscht : C:\Program Files (x86)\deAli2idealit
Ordner Gelöscht : C:\Program Files (x86)\LuuCkYCoupon
Ordner Gelöscht : C:\Program Files (x86)\SalesMAgnet
Ordner Gelöscht : C:\Program Files\Reimage
Ordner Gelöscht : C:\Users\ecp\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\ecp\AppData\Local\Pro_PC_Cleaner
[/!\] Nicht Gelöscht ( Junction ) : C:\Users\ecp\AppData\LocalLow\bobyzoom
Ordner Gelöscht : C:\Users\ecp\AppData\Roaming\DesktopIconForAmazon
Ordner Gelöscht : C:\Users\ecp\AppData\Roaming\PC Speed Maximizer
Ordner Gelöscht : C:\Users\ecp\AppData\Roaming\Solvusoft
Ordner Gelöscht : C:\Users\ecp\AppData\Roaming\Pro PC Cleaner
Ordner Gelöscht : C:\Users\ecp\Documents\ProPCCleaner
Ordner Gelöscht : C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\bbz@bobyzoom.com
Datei Gelöscht : C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
Datei Gelöscht : C:\Users\Public\Desktop\Pro PC Cleaner.lnk
Datei Gelöscht : C:\Windows\Reimage.ini
Datei Gelöscht : C:\Windows\SysWOW64\Gambali.dll
Datei Gelöscht : C:\Windows\System32\Gambali64.dll
Datei Gelöscht : C:\Windows\System32\drivers\tammgf119.sys
Datei Gelöscht : C:\Windows\System32\drivers\tammgr119.sys
Datei Gelöscht : C:\Users\ecp\Desktop\PC Speed Maximizer.lnk
Datei Gelöscht : C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\user.js

***** [ Geplante Tasks ] *****

Task Gelöscht : LaunchSignup
Task Gelöscht : PC Speed Maximizer Schedule
Task Gelöscht : ProPCCleaner_Start
Task Gelöscht : Reimage Reminder
Task Gelöscht : ReimageUpdater
Task Gelöscht : RocketTab
Task Gelöscht : RocketTab Update Task

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{969E3CF4-34F8-788A-EDA2-1FF1929946D9}]
Schlüssel Gelöscht : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P007c182f_91dc_485e_a48f_b4ad99086949_.P007c182f_91dc_485e_a48f_b4ad99086949_
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P007c182f_91dc_485e_a48f_b4ad99086949_.P007c182f_91dc_485e_a48f_b4ad99086949_.9
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P3dcc325d_9258_4278_ac06_bc06aafb8809_.P3dcc325d_9258_4278_ac06_bc06aafb8809_
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P3dcc325d_9258_4278_ac06_bc06aafb8809_.P3dcc325d_9258_4278_ac06_bc06aafb8809_.9
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Pf1a892aa_d8f1_4a2a_a980_430349d85d2a_.Pf1a892aa_d8f1_4a2a_a980_430349d85d2a_
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Pf1a892aa_d8f1_4a2a_a980_430349d85d2a_.Pf1a892aa_d8f1_4a2a_a980_430349d85d2a_.9
Schlüssel Gelöscht : HKLM\SOFTWARE\5761f2e3-af05-346d-e953-e340e50c8a7d
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007c182f-91dc-485e-a48f-b4ad99086949}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3dcc325d-9258-4278-ac06-bc06aafb8809}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{f1a892aa-d8f1-4a2a-a980-430349d85d2a}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{079E2F0F-FCA0-4163-BC82-5355B879E86E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{41F978F3-431A-4464-A789-5C0692D562FB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DD1CFE82-CC89-497D-9573-B8B1867DDA09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{007c182f-91dc-485e-a48f-b4ad99086949}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3dcc325d-9258-4278-ac06-bc06aafb8809}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f1a892aa-d8f1-4a2a-a980-430349d85d2a}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{007c182f-91dc-485e-a48f-b4ad99086949}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dcc325d-9258-4278-ac06-bc06aafb8809}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{f1a892aa-d8f1-4a2a-a980-430349d85d2a}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{C424171E-592A-415A-9EB1-DFD6D95D3530}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{5782EC3E-14E8-402B-BAD6-7FE86EF6484D}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C4C5AF64-3082-439A-8C86-5773B579E965}
Schlüssel Gelöscht : HKCU\Software\Ciuvo
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\nuevos-programas.com
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\pc speed maximizer
Schlüssel Gelöscht : HKCU\Software\Solvusoft
Schlüssel Gelöscht : HKCU\Software\Reimage
Schlüssel Gelöscht : HKCU\Software\Pro PC Cleaner
Schlüssel Gelöscht : HKCU\Software\ProPCCleanerLanguage
Schlüssel Gelöscht : HKCU\Software\ProPCCleanerConfig
Schlüssel Gelöscht : HKCU\Software\rttasks
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\CheckMeUp
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\bobyzoom
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gelöscht : HKLM\SOFTWARE\Solvusoft
Schlüssel Gelöscht : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Pro PC Cleaner
Schlüssel Gelöscht : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC Speed Maximizer_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C3060724-6AC7-4BEF-B516-4F6B1D90887D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9D8D5AD9-94C7-40B3-88F2-2B8F227F6381}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Reimage
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Reimage Repair
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Features\4270603C7CA6FEB45B61F4B6D10988D7
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Products\4270603C7CA6FEB45B61F4B6D10988D7
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4270603C7CA6FEB45B61F4B6D10988D7
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\binkiland.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\gboxapp.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\myhome.vi-view.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\vi-view.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\vosteran.com
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - hxxp=127.0.0.1:49207;hxxps=127.0.0.1:49207

***** [ Internetbrowser ] *****

-\\ Internet Explorer v11.0.9600.17689


-\\ Mozilla Firefox v36.0.4 (x86 de)

[jr56lqw0.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.jDHKQdNvDBH9mSIy.scode", "(function(){try{if(window.self.location.href.indexOf(\"rjgFqdkFpdY7qdUEqjk4pda4rjY\")>-1){return;}}catch(e){}try{var d=[[\"trianglecash.com\",\"acebook\[...]

-\\ Opera v28.0.1750.48


*************************

AdwCleaner[R0].txt - [15708 Bytes] - [04/04/2015 23:17:18]
AdwCleaner[S0].txt - [14681 Bytes] - [04/04/2015 23:20:11]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [14741  Bytes] ##########
         
JRT:
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.5.1 (04.02.2015:1)
OS: Windows 7 Home Premium x64
Ran by ecp on 04.04.2015 at 23:29:19,86
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files

Successfully deleted: [Task] DriverDoc_UPDATES.job



~~~ Folders

Successfully deleted: [Folder] C:\ProgramData\saFerwEb
Successfully deleted: [Folder] C:\ProgramData\SmaaritCoimepare
Successfully deleted: [Folder] C:\ProgramData\woEbsauVer



~~~ FireFox

Successfully deleted the following from C:\Users\ecp\AppData\Roaming\mozilla\firefox\profiles\jr56lqw0.default\prefs.js

user_pref("extensions.jDHKQdNvDBH9mSIy.url", "hxxp://downloadusaweb.us/sync2/?q=hfZ9oenGhchEAen0rihTB6lKDzt4okmxtNtVh7n0rjkErHsHrdC8rdsHtMFHhd9FqjaHrTrEpdrEqdUMDMlGojUMAe4Uojk



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 04.04.2015 at 23:37:02,63
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         



Gruß Hausmeister

Alt 04.04.2015, 22:52   #7
Haus meister
 
Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Standard

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen



und hier das FRST Log:


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by ecp (administrator) on ECP-PC on 04-04-2015 23:39:44
Running from C:\Reinigung
Loaded Profiles: ecp (Available profiles: ecp)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE
() C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe
() C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ZOOM\TpScrex.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
() C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe
(Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bz64.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [AudialsNotifier] => C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe [2410760 2014-12-17] ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {2D8E4D58-9FF9-4D32-B1A0-E2E493921442} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {9F48D099-769E-460F-8CAD-E870234711DA} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {A44BCBEF-651D-4A25-A802-3938D00F9BEE} URL = hxxp://q.search-simple.com/?affID=na&q={searchTerms}&r=92
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {BC78FFB8-43BE-431A-861E-C6CE3BA30EC0} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default
FF NewTab: 
FF DefaultSearchEngine: Yahoo! Search
FF Keyword.URL: 
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-05] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-04] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-04] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\searchplugins\search-simple.xml [2015-03-22]
FF Extension: Dynamo Combo 1.0.1 - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}.xpi [2015-03-22]
FF HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]

Chrome: 
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx

Opera: 
=======
OPR Extension: (HQCinema Pro 2.1V20.03) - C:\Users\ecp\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcjifdbedkcdkeegnoenkpiphjldpahf [2015-03-20]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

Locked "tammgF119" service could not be unlocked. <===== ATTENTION
Locked "tammgR119" service could not be unlocked. <===== ATTENTION

R2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation)
R2 bobyzoom; C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [0 ] () <==== ATTENTION (zero size file/folder)
R2 bzwdg; C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [0 ] () <==== ATTENTION (zero size file/folder)
R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2014-12-11] () [File not signed]
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation)
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [49648 2015-01-15] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation)
R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-12-17] (Audials AG)
R5 tammgF119; C:\Windows\System32\Drivers\tammgF119.sys [26784 2015-03-20] () [File not signed]
R5 tammgR119; C:\Windows\System32\Drivers\tammgR119.sys [26272 2015-03-20] () [File not signed]
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 CAXHWAZL; system32\DRIVERS\CAXHWAZL.sys [X]
S3 cpuz134; \??\C:\Users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 HSF_DPV; system32\DRIVERS\CAX_DPV.sys [X]
S2 mdmxsdk; system32\DRIVERS\mdmxsdk.sys [X]
S3 winachsf; system32\DRIVERS\CAX_CNXT.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-04 23:37 - 2015-04-04 23:37 - 00001178 _____ () C:\Users\ecp\Desktop\JRT.txt
2015-04-04 23:30 - 2015-04-04 23:30 - 00003008 _____ () C:\Windows\System32\Tasks\DriverDoc_UPDATES
2015-04-04 23:30 - 2015-04-04 23:30 - 00000274 _____ () C:\Windows\Tasks\DriverDoc_UPDATES.job
2015-04-04 23:29 - 2015-04-04 23:29 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ECP-PC-Windows-7-Home-Premium-(64-bit).dat
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\RegBackup
2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Windows\pss
2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Solvusoft
2015-04-04 23:17 - 2015-04-04 23:20 - 00000000 ____D () C:\AdwCleaner
2015-04-04 23:16 - 2015-04-04 23:16 - 00000703 _____ () C:\Users\ecp\Desktop\Reinigung - Verknüpfung.lnk
2015-04-04 22:27 - 2015-04-04 23:13 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-04 22:22 - 2015-04-04 22:22 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-04-04 22:22 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-04 22:22 - 2015-03-17 06:15 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-04 22:22 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-03-29 22:28 - 2015-03-29 22:58 - 00000000 ____D () C:\Qoobox
2015-03-29 22:28 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-03-29 22:28 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-03-29 22:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-03-29 22:27 - 2015-03-29 22:54 - 00000000 ____D () C:\Windows\erdnt
2015-03-29 22:25 - 2015-03-27 19:41 - 05615749 ____R (Swearware) C:\Users\ecp\Desktop\ComboFix.exe
2015-03-27 19:46 - 2015-03-27 19:46 - 00001271 _____ () C:\Users\ecp\Desktop\Revo Uninstaller.lnk
2015-03-27 19:46 - 2015-03-27 19:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-03-26 22:28 - 2015-04-04 23:39 - 00000000 ____D () C:\FRST
2015-03-26 22:27 - 2015-03-26 22:27 - 00000000 _____ () C:\Users\ecp\defogger_reenable
2015-03-26 22:13 - 2015-04-04 23:39 - 00000000 ____D () C:\Reinigung
2015-03-23 10:18 - 2015-03-23 10:19 - 00000000 ____D () C:\Program Files (x86)\Simple Dictation
2015-03-22 10:10 - 2015-03-22 10:10 - 00000000 ____D () C:\Users\ecp\AppData\Local\Macromedia
2015-03-22 10:09 - 2015-03-22 10:09 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-03-22 10:09 - 2015-03-22 10:09 - 00001154 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-03-22 10:09 - 2015-03-22 10:09 - 00000000 ____D () C:\Users\ecp\AppData\Local\Mozilla
2015-03-22 10:08 - 2015-03-22 10:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-22 09:32 - 2015-03-22 09:32 - 00004020 _____ () C:\Windows\System32\Tasks\Check for Scheduled Updates
2015-03-22 09:30 - 2015-03-22 09:30 - 00000000 ____D () C:\Users\ecp\AppData\Local\32220c02-c108-4e43-b856-df7d87f70051
2015-03-22 08:43 - 2015-04-04 23:04 - 00000000 ____D () C:\Program Files (x86)\SystemContinue
2015-03-20 20:06 - 2015-04-04 22:45 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-03-20 19:47 - 2015-03-20 19:47 - 00000000 ____D () C:\ProgramData\e314b8475a214ebc973cc42fbf8c6edf
2015-03-20 19:43 - 2015-03-20 19:43 - 00026784 _____ () C:\Windows\system32\Drivers\tammgF119.sys
2015-03-20 19:43 - 2015-03-20 19:43 - 00026272 _____ () C:\Windows\system32\Drivers\tammgR119.sys
2015-03-20 19:43 - 2015-03-20 19:43 - 00000000 ____D () C:\ProgramData\bobyzoom
2015-03-18 09:05 - 2015-03-18 09:06 - 00002051 _____ () C:\Users\ecp\Downloads\Henner.txt
2015-03-17 08:53 - 2015-03-16 19:43 - 01274260 _____ () C:\Users\ecp\Documents\bskundenexcel201411.xls_0.ods
2015-03-17 08:53 - 2015-03-16 19:43 - 00017886 _____ () C:\Users\ecp\Documents\TennistrainingWinterHalle201415herren55he55mitersatzregelung.xls_0.ods
2015-03-13 10:11 - 2015-03-13 10:11 - 00959266 _____ () C:\Users\ecp\Downloads\doc.zip
2015-03-13 10:02 - 2015-03-13 10:02 - 00408667 _____ () C:\Users\ecp\Downloads\odt.zip
2015-03-11 09:58 - 2015-03-11 09:59 - 00000832 _____ () C:\Users\ecp\Downloads\download.html
2015-03-11 09:17 - 2015-02-03 05:34 - 05554104 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-11 09:17 - 2015-02-03 05:31 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-03-11 09:17 - 2015-02-03 05:31 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-03-11 09:17 - 2015-02-03 05:30 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-03-11 09:17 - 2015-02-03 05:30 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-03-11 09:17 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2015-03-11 09:17 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2015-03-11 09:17 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2015-03-11 09:17 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2015-03-11 09:16 - 2015-02-03 05:34 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-03-11 09:16 - 2015-02-03 05:34 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-03-11 09:16 - 2015-02-03 05:33 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-03-11 09:16 - 2015-02-03 05:31 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-03-11 09:16 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-03-11 09:16 - 2015-02-03 05:30 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2015-03-11 09:16 - 2015-02-03 05:29 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2015-03-11 09:16 - 2015-02-03 05:28 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-03-11 09:16 - 2015-02-03 05:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-03-11 09:16 - 2015-02-03 05:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-03-11 09:16 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-03-11 09:16 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-03-11 09:16 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2015-03-11 09:16 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2015-03-11 09:16 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2015-03-11 09:16 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2015-03-11 09:16 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2015-03-11 09:16 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2015-03-11 09:16 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-03-11 09:16 - 2015-02-03 04:32 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-03-11 09:16 - 2014-11-01 00:24 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-03-11 09:16 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-03-11 09:16 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-03-11 09:15 - 2015-02-20 06:41 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-03-11 09:15 - 2015-02-20 06:40 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-11 09:15 - 2015-02-20 05:29 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-11 09:15 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-03-11 09:14 - 2015-02-20 06:40 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-03-11 09:14 - 2015-02-20 06:40 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-03-11 09:14 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-03-11 09:14 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-03-11 09:14 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-03-11 09:14 - 2015-02-20 06:12 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-03-11 09:14 - 2015-01-31 05:48 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-03-11 09:14 - 2015-01-31 05:48 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 09:14 - 2015-01-31 01:56 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-03-11 09:13 - 2015-03-06 07:56 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-03-11 09:13 - 2015-03-06 07:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-03-11 09:13 - 2015-03-06 07:42 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-03-11 09:13 - 2015-03-06 07:41 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-03-11 09:13 - 2015-03-06 07:41 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-03-11 09:13 - 2015-03-06 07:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-03-11 09:13 - 2015-03-06 07:38 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-03-11 09:13 - 2015-03-06 07:36 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-03-11 09:13 - 2015-03-06 07:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-03-11 09:13 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-03-11 09:13 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-03-11 09:13 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-03-11 09:13 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-03-11 09:13 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-03-11 09:13 - 2015-02-13 07:22 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-11 09:13 - 2015-02-03 05:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-11 09:13 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
2015-03-11 09:13 - 2015-01-31 01:56 - 00459336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-03-11 09:12 - 2015-02-26 05:25 - 03204096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-11 09:12 - 2015-02-24 05:15 - 00389800 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-11 09:12 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-03-11 09:12 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-03-11 09:12 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-03-11 09:12 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-03-11 09:12 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-03-11 09:12 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-03-11 09:12 - 2015-02-20 05:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-03-11 09:12 - 2015-02-20 05:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 09:12 - 2015-02-20 04:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-03-11 09:12 - 2015-02-20 04:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-03-11 09:12 - 2015-02-20 04:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-03-11 09:12 - 2015-02-20 04:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 09:12 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-03-11 09:12 - 2015-02-20 04:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 09:12 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-03-11 09:12 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-03-11 09:12 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-03-11 09:12 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-11 09:12 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-03-11 09:12 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-03-11 09:12 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-03-11 09:12 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-03-11 09:12 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-03-11 09:12 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-03-11 09:12 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-11 09:12 - 2015-02-20 03:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-03-11 09:12 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-03-11 09:12 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-03-11 09:12 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-03-11 09:12 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-11 09:12 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-03-11 09:12 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-03-11 09:12 - 2015-02-03 05:31 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-11 09:12 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-03-11 09:12 - 2015-01-17 04:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-11 09:12 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2015-03-11 09:11 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-11 09:11 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-11 09:11 - 2015-02-20 04:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-03-11 09:11 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-11 09:11 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-11 09:11 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-11 09:11 - 2015-02-20 04:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-03-11 09:11 - 2015-02-20 04:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-03-11 09:11 - 2015-02-20 04:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-03-11 09:11 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-11 09:11 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-11 09:11 - 2015-02-20 04:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-03-11 09:11 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-03-11 09:11 - 2015-02-20 04:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-03-11 09:11 - 2015-02-20 03:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-03-11 09:11 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-11 09:11 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-11 09:11 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-03-11 09:11 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-03-11 09:11 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-11 09:11 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-03-11 09:11 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-11 09:11 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-03-11 09:06 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-11 09:06 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2015-03-05 18:07 - 2015-03-05 18:07 - 00000000 ____D () C:\ProgramData\Auslogics
2015-03-05 18:06 - 2015-03-05 18:06 - 00001298 _____ () C:\Users\ecp\Desktop\Auslogics Duplicate File Finder.lnk
2015-03-05 18:06 - 2015-03-05 18:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
2015-03-05 18:06 - 2015-03-05 18:06 - 00000000 ____D () C:\Program Files (x86)\Auslogics
2015-03-05 18:05 - 2015-03-05 18:05 - 06929688 _____ (Auslogics Labs Pty Ltd ) C:\Users\ecp\Downloads\duplicate-file-finder-setup.exe
2015-03-05 17:57 - 2015-03-05 18:02 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\FreeFileSync
2015-03-05 17:56 - 2015-03-05 17:56 - 00385602 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS
2015-03-05 17:56 - 2015-03-05 17:56 - 00000951 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeFileSync.lnk
2015-03-05 17:56 - 2015-03-05 17:56 - 00000941 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealtimeSync.lnk
2015-03-05 17:56 - 2015-03-05 17:56 - 00000939 _____ () C:\Users\Public\Desktop\FreeFileSync.lnk
2015-03-05 17:56 - 2015-03-05 17:56 - 00000929 _____ () C:\Users\Public\Desktop\RealtimeSync.lnk
2015-03-05 17:56 - 2015-03-05 17:56 - 00000232 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS.part
2015-03-05 17:56 - 2015-03-05 17:56 - 00000000 ____D () C:\Users\ecp\AppData\Local\145842EF_stp
2015-03-05 17:56 - 2015-03-05 17:56 - 00000000 ____D () C:\Program Files\FreeFileSync
2015-03-05 17:55 - 2015-03-05 17:55 - 12653536 _____ (www.FreeFileSync.org ) C:\Users\ecp\Downloads\freefilesync_6.14_windows_setup.exe
2015-03-05 17:55 - 2015-03-05 17:55 - 12653536 _____ (www.FreeFileSync.org ) C:\Users\ecp\Downloads\freefilesync_6.14_windows_setup (1).exe
2015-03-05 17:28 - 2015-03-05 17:28 - 00000000 ___HD () C:\ProgramData\CanonIJScan
2015-03-05 17:28 - 2015-03-05 17:28 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Canon
2015-03-05 09:19 - 2015-03-05 09:19 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-03-05 09:19 - 2015-03-05 09:19 - 00000000 ___HD () C:\ProgramData\CanonIJFAX
2015-03-05 09:19 - 2015-03-05 09:19 - 00000000 ____D () C:\Windows\system32\appraiser
2015-03-05 09:18 - 2011-09-21 06:00 - 00302592 _____ (CANON INC.) C:\Windows\system32\CNCALB0.DLL
2015-03-05 09:17 - 2015-03-05 09:17 - 00000000 ___HD () C:\Windows\system32\CanonIJ Uninstaller Information
2015-03-05 09:17 - 2015-03-05 09:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX370 series
2015-03-05 09:17 - 2011-10-14 12:57 - 00300544 _____ (CANON INC.) C:\Windows\system32\CNC_B0C.dll
2015-03-05 09:17 - 2011-10-14 12:57 - 00102912 _____ (CANON INC.) C:\Windows\SysWOW64\CNC_B0U.dll
2015-03-05 09:17 - 2011-10-14 12:56 - 00109568 _____ (CANON INC.) C:\Windows\system32\CNC_B0I.dll
2015-03-05 09:17 - 2011-09-22 09:59 - 00358912 _____ (CANON INC.) C:\Windows\system32\CNC_B0L.dll
2015-03-05 09:17 - 2011-09-22 09:57 - 00316416 _____ (CANON INC.) C:\Windows\SysWOW64\CNC_B0L.dll
2015-03-05 09:17 - 2011-06-30 14:35 - 00065280 _____ () C:\Windows\SysWOW64\CNC1759D.TBL
2015-03-05 09:17 - 2011-06-30 14:35 - 00065280 _____ () C:\Windows\system32\CNC1759D.TBL
2015-03-05 09:17 - 2008-08-25 19:02 - 00017920 _____ (CANON INC.) C:\Windows\system32\CNHMCA6.dll
2015-03-05 09:17 - 2008-08-25 19:02 - 00015872 _____ (CANON INC.) C:\Windows\SysWOW64\CNHMCA.dll
2015-03-05 09:15 - 2011-11-03 06:00 - 00385024 _____ (CANON INC.) C:\Windows\system32\CNMLMB0.DLL
2015-03-05 08:43 - 2015-01-09 01:44 - 00419936 _____ () C:\Windows\SysWOW64\locale.nls
2015-03-05 08:43 - 2015-01-09 01:43 - 00419936 _____ () C:\Windows\system32\locale.nls
2015-03-05 08:28 - 2014-06-27 04:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2015-03-05 08:28 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-04 23:33 - 2014-11-25 12:56 - 01959715 _____ () C:\Windows\WindowsUpdate.log
2015-04-04 23:33 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-04 23:33 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-04 23:29 - 2011-04-12 09:43 - 00698926 _____ () C:\Windows\system32\perfh007.dat
2015-04-04 23:29 - 2011-04-12 09:43 - 00149034 _____ () C:\Windows\system32\perfc007.dat
2015-04-04 23:29 - 2009-07-14 07:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-04 23:26 - 2015-01-01 12:20 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Skype
2015-04-04 23:22 - 2010-11-21 05:47 - 00084124 _____ () C:\Windows\PFRO.log
2015-04-04 23:22 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-04 23:22 - 2009-07-14 06:51 - 00060122 _____ () C:\Windows\setupact.log
2015-04-04 23:08 - 2014-07-23 11:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-04 23:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Speech
2015-03-29 22:58 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2015-03-29 22:50 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2015-03-29 22:48 - 2009-07-14 04:34 - 61079552 _____ () C:\Windows\system32\config\SOFTWARE.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 13631488 _____ () C:\Windows\system32\config\SYSTEM.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2015-03-26 22:27 - 2014-12-30 16:50 - 00000000 ____D () C:\Users\ecp
2015-03-24 19:49 - 2015-01-01 15:35 - 00000000 ____D () C:\Users\ecp\Documents\112 wiederkehrende dateien 1412
2015-03-24 18:26 - 2015-01-01 13:26 - 00000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG
2015-03-24 18:22 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini
2015-03-24 09:15 - 2015-01-02 13:37 - 00040478 _____ () C:\Windows\system32\ScanResults.xml
2015-03-24 09:08 - 2015-01-02 13:32 - 00000464 _____ () C:\Windows\system32\ScannerSettings
2015-03-23 08:32 - 2015-01-02 00:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-22 10:09 - 2015-01-02 00:29 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Mozilla
2015-03-22 09:50 - 2014-12-31 11:40 - 00000000 ____D () C:\Users\ecp\AppData\Local\Adobe
2015-03-19 21:07 - 2014-12-30 17:38 - 00003848 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1419953902
2015-03-19 21:07 - 2014-12-30 17:37 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-03-19 21:05 - 2015-02-08 13:08 - 00000000 ____D () C:\Users\ecp\Documents\Tennisclub
2015-03-18 00:27 - 2015-03-02 11:54 - 00000000 ____D () C:\Users\ecp\Documents\Martina60Geburtstag20150406
2015-03-16 20:21 - 2014-07-23 11:43 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-03-16 20:21 - 2014-07-23 11:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-03-16 20:21 - 2014-07-23 11:43 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-03-16 13:57 - 2015-02-08 13:09 - 00000000 ____D () C:\Users\ecp\Documents\Privates
2015-03-13 09:40 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2015-03-13 09:35 - 2009-07-14 06:45 - 00298232 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-13 09:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2015-03-13 09:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2015-03-13 09:15 - 2014-07-22 17:37 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-13 09:06 - 2014-07-22 17:37 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-03-11 22:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2015-03-11 09:00 - 2015-01-06 12:05 - 00000000 ____D () C:\Program Files (x86)\GTS
2015-03-09 19:16 - 2015-02-08 13:09 - 00000000 ____D () C:\Users\ecp\Documents\NBV
2015-03-09 12:13 - 2015-02-16 19:42 - 00000000 ____D () C:\Users\ecp\Documents\Camera
2015-03-05 09:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2015-03-05 09:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat
2015-03-05 09:18 - 2009-07-14 05:20 - 00000000 __RSD () C:\Windows\Media

==================== Files in the root of some directories =======

2015-02-04 19:15 - 2015-03-04 10:17 - 0001874 _____ () C:\Users\ecp\AppData\Roaming\MyMicroBalanceConfig.ini
2015-01-01 13:26 - 2015-03-24 18:26 - 0000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG
2015-03-05 17:56 - 2015-03-05 17:56 - 0385602 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS
2015-03-05 17:56 - 2015-03-05 17:56 - 0000232 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS.part
2015-01-03 02:27 - 2015-03-01 11:48 - 0000010 _____ () C:\Users\ecp\AppData\Local\DSI.DAT

Some content of TEMP:
====================
C:\Users\ecp\AppData\Local\Temp\Quarantine.exe
C:\Users\ecp\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-11 19:40

==================== End Of Log ============================
         
--- --- ---

Alt 05.04.2015, 13:09   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Standard

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 07.04.2015, 21:06   #9
Haus meister
 
Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Standard

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen



Hallo Schrauber,

auf den ersten kurzen Blick, sieht's gut aus.
Hier die Log's:

ESET:
Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internet# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=92942c69ec6da34699ce507475401de9
# engine=23268
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-04-07 07:41:01
# local_time=2015-04-07 09:41:01 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 4803045 51419655 0 0
# scanned=143102
# found=31
# cleaned=0
# scan_time=7644
sh=9776ABD023F32FA294649DACBB4C3B03A06D338B ft=1 fh=e67507526245a101 vn="Variante von Win32/ReImageRepair.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Reimage\Reimage Repair\LanguageSelect.exe.vir"
sh=22ECD449555340E5819AA967396703E21A023725 ft=1 fh=4a37b67564886534 vn="Variante von Win32/ReImageRepair.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Reimage\Reimage Repair\ReimageRepair.exe.vir"
sh=FCF577CE410A72FFC34D688E419673B9E6C1EA54 ft=1 fh=5e7dc4dd398e10f6 vn="Variante von Win32/AdWare.SpeedingUpMyPC.S Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\PC Speed Maximizer\PCSpeedMaximizer.exe.vir"
sh=C53BA75319D3B04C6038FDA254602EE923336C83 ft=1 fh=489be472cf683e79 vn="Variante von MSIL/Rebrand.LittleRegClean.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Pro PC Cleaner\Helper.dll.vir"
sh=E19E7C0C67095FC1785E27A24FA1D1D1ACF475A2 ft=1 fh=3b7a18a4c46967c7 vn="Variante von MSIL/Rebrand.LittleRegClean.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Pro PC Cleaner\ProPCCleaner.exe.vir"
sh=D843B61EA88F2C2EA53AE43F11CB5B0367BB3C4B ft=1 fh=a0c68fca525ad6d4 vn="Variante von MSIL/Rebrand.LittleRegClean.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Pro PC Cleaner\Uninst000.CA.dll.vir"
sh=C53BA75319D3B04C6038FDA254602EE923336C83 ft=1 fh=489be472cf683e79 vn="Variante von MSIL/Rebrand.LittleRegClean.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\ecp\AppData\Roaming\Pro PC Cleaner\Pro PC Cleaner 2.5.5\install\D90887D\Helper.dll.vir"
sh=E19E7C0C67095FC1785E27A24FA1D1D1ACF475A2 ft=1 fh=3b7a18a4c46967c7 vn="Variante von MSIL/Rebrand.LittleRegClean.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\ecp\AppData\Roaming\Pro PC Cleaner\Pro PC Cleaner 2.5.5\install\D90887D\ProPCCleaner.exe.vir"
sh=D843B61EA88F2C2EA53AE43F11CB5B0367BB3C4B ft=1 fh=a0c68fca525ad6d4 vn="Variante von MSIL/Rebrand.LittleRegClean.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\ecp\AppData\Roaming\Pro PC Cleaner\Pro PC Cleaner 2.5.5\install\D90887D\Uninst000.CA.dll.vir"
sh=3F623FE0765DBE35AFB81F756EB3BD10CABA33CD ft=1 fh=11c9bfb384d8c8cc vn="Variante von Win32/Systweak.H evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\DriverDoc\Solvusoftdd.exe"
sh=F00161BCB1F9D847C3A9EA502BC32F2CA9D6B08B ft=1 fh=c71c001125519aae vn="Variante von Win32/Adware.MultiPlug.FL Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\ddeallpeAuk\83pi0tURGPEZSW.dll.vir"
sh=03D1B31F6C684652CEA2295012ECBE0188DC1BD7 ft=1 fh=cecc82c612b87102 vn="Variante von Win64/Adware.MultiPlug.G Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\ddeallpeAuk\83pi0tURGPEZSW.x64.dll.vir"
sh=D1E48307906270C02BB06DFE4EF57272CDABD863 ft=1 fh=c71c0011688eab1a vn="Variante von Win32/Adware.MultiPlug.FL Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\Saveitkeaep\OUx1yNk71u3K2I.dll.vir"
sh=079C296D746516934BA78D7727513D5833D3648D ft=1 fh=cecc82c60dc57089 vn="Variante von Win64/Adware.MultiPlug.G Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\Saveitkeaep\OUx1yNk71u3K2I.x64.dll.vir"
sh=2835D716C7EF345CC975AF422DD294D71339F17E ft=1 fh=c71c0011645a00f9 vn="Variante von Win32/Adware.MultiPlug.FL Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.dll.vir"
sh=911857E970A56D2B74E8998C005FE78C82BC7FB1 ft=1 fh=cecc82c6f132d637 vn="Variante von Win64/Adware.MultiPlug.G Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\SoaleEsChoeocKeirr\i8SYzNWiH7jcTI.x64.dll.vir"
sh=3C2602FD6A84F062471A39CA77BE907203267D2F ft=1 fh=c71c0011c0508110 vn="Variante von Win32/SProtector.P evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\1887373585\BITB865.tmp.vir"
sh=6408D61C9809E743126596AF762ABA61C67626F2 ft=1 fh=11b2d7f1750c67b8 vn="Win32/Adware.DsiLoad.A Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\ecp\AppData\Local\dsisetup1374062732.exe.vir"
sh=334A2EAAB05C2F93FE080247FC8E7E3630B3D4EE ft=1 fh=c5a015ee52b21e12 vn="Variante von Win32/Adware.AddLyrics.DX Anwendung" ac=I fn="C:\Users\ecp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1U8J5FUQ\3333-6051_CheckMeUp[1].exe"
sh=A2E11E8244547DB71255DA4E8FDD6EF03EA1BEFA ft=1 fh=0f69dedb8ec7e46a vn="Variante von Win32/TrojanDropper.Addrop.A Trojaner" ac=I fn="C:\Users\ecp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1U8J5FUQ\setup[1].exe"
sh=F3F8CBDD982D2C88F3FA1BB224BBABCF1762671A ft=1 fh=2993682ffbda0bfc vn="Variante von Win32/OutBrowse.AZ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3FZGGY9P\SPGeneric_2711[1].exe"
sh=1EA4BC9F2923CFE96237E21C95926160E6632C82 ft=1 fh=e47e93cd69f96f1a vn="Variante von Win32/Adware.PicColor.Z Anwendung" ac=I fn="C:\Users\ecp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5WJJVJO\SUChecker[1].exe"
sh=E229581816FACD3C49C62076D5B3B75A962541CC ft=1 fh=5e608d1f4294683e vn="Variante von Win32/SoftPulse.S evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\SW37FAT3\Player Setup[1].exe"
sh=624AD9BD15C70FD83A62D7B2C38082BD907F5541 ft=0 fh=0000000000000000 vn="JS/TrojanDownloader.Iframe.NKE Trojaner" ac=I fn="C:\Users\ecp\AppData\Local\Mozilla\Firefox\Profiles\jr56lqw0.default\cache2\entries\3409AE3C6DBC75676F8231C97E8190B8A6F10DD6"
sh=E12AEBE0494D17494B59B058C14D793D22BBAC0D ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcjifdbedkcdkeegnoenkpiphjldpahf\1.26.36_0\extensionData\plugins\91.js"
sh=7BD80FF13EC07828520C12E63C392CE0D50CD047 ft=1 fh=de54c131acd09d5f vn="Variante von Win32/InstallCore.UF evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\Downloads\EF_Duplicate_Files_Manager_7.10_CB-DL-Manager.exe"
sh=9AA13F99E1BA7E0009D469E6344CAF1D81D1DB5E ft=1 fh=679f9d6e01d5f029 vn="Win32/FusionCore.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\Downloads\freefilesync_6.14_windows_setup (1).exe"
sh=9AA13F99E1BA7E0009D469E6344CAF1D81D1DB5E ft=1 fh=679f9d6e01d5f029 vn="Win32/FusionCore.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\Downloads\freefilesync_6.14_windows_setup.exe"
sh=AEE0B5F1AE8564D7E4CCD032EDF7AD88339BFF4E ft=1 fh=88c3bdc65b0afccf vn="Variante von Win32/Systweak.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\Downloads\HP_(Hewlett_Packard)_Deskjet_970cxi_Treiber_Update_10-2014.exe"
sh=1C5CCF6D5160EFE16B13DA0807F8F4DEC47579A7 ft=1 fh=382583589961532b vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\Downloads\OpenOffice - CHIP-Installer (1).exe"
sh=AFA265189B1C24E7BCF0DA0368A244DB25F3FBC2 ft=1 fh=483f7b57349533cc vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\ecp\Downloads\OpenOffice - CHIP-Installer.exe"
         
SecurityCheck:

Code:
ATTFilter
 Results of screen317's Security Check version 0.99.99  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
Microsoft Security Essentials   
  (On Access scanning disabled!) 
 Error obtaining update status for antivirus!  
`````````Anti-malware/Other Utilities Check:````````` 
 Java 8 Update 31  
 Java version 32-bit out of Date! 
  Adobe Flash Player 16.0.0.305 Flash Player out of Date!  
 Adobe Reader XI  
 Mozilla Firefox (36.0.4) 
 Mozilla Thunderbird (31.4.0) 
````````Process Check: objlist.exe by Laurent````````  
 Microsoft Security Essentials MSMpEng.exe 
 Microsoft Security Essentials msseces.exe 
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         

FRST:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by ecp (administrator) on ECP-PC on 07-04-2015 21:54:57
Running from C:\Reinigung
Loaded Profiles: ecp (Available profiles: ecp)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE
() C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe
() C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ZOOM\TpScrex.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bz64.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [AudialsNotifier] => C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe [2410760 2014-12-17] ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {2D8E4D58-9FF9-4D32-B1A0-E2E493921442} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {9F48D099-769E-460F-8CAD-E870234711DA} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {A44BCBEF-651D-4A25-A802-3938D00F9BEE} URL = hxxp://q.search-simple.com/?affID=na&q={searchTerms}&r=92
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {BC78FFB8-43BE-431A-861E-C6CE3BA30EC0} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default
FF NewTab: 
FF DefaultSearchEngine: Yahoo! Search
FF Keyword.URL: 
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-05] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-04] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-04] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\searchplugins\search-simple.xml [2015-03-22]
FF Extension: BobyZoom - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\bbz@bobyzoom.com [2015-04-07]
FF Extension: Dynamo Combo 1.0.1 - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}.xpi [2015-03-22]
FF HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]

Chrome: 
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx

Opera: 
=======
OPR Extension: (HQCinema Pro 2.1V20.03) - C:\Users\ecp\AppData\Roaming\Opera Software\Opera Stable\Extensions\kcjifdbedkcdkeegnoenkpiphjldpahf [2015-03-20]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

Locked "tammgF119" service could not be unlocked. <===== ATTENTION
Locked "tammgR119" service could not be unlocked. <===== ATTENTION

R2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation)
R2 bobyzoom; C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [0 ] () <==== ATTENTION (zero size file/folder)
R2 bzwdg; C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [0 ] () <==== ATTENTION (zero size file/folder)
R2 DiskBoss Service; C:\Program Files (x86)\DiskBoss\bin\diskbsa.exe [118784 2014-12-11] () [File not signed]
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation)
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [49648 2015-01-15] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation)
R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-12-17] (Audials AG)
R5 tammgF119; C:\Windows\System32\Drivers\tammgF119.sys [26784 2015-03-20] () [File not signed]
R5 tammgR119; C:\Windows\System32\Drivers\tammgR119.sys [26272 2015-03-20] () [File not signed]
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 CAXHWAZL; system32\DRIVERS\CAXHWAZL.sys [X]
S3 cpuz134; \??\C:\Users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 HSF_DPV; system32\DRIVERS\CAX_DPV.sys [X]
S2 mdmxsdk; system32\DRIVERS\mdmxsdk.sys [X]
S3 winachsf; system32\DRIVERS\CAX_CNXT.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-04 23:37 - 2015-04-04 23:37 - 00001178 _____ () C:\Users\ecp\Desktop\JRT.txt
2015-04-04 23:30 - 2015-04-04 23:46 - 00000274 _____ () C:\Windows\Tasks\DriverDoc_UPDATES.job
2015-04-04 23:30 - 2015-04-04 23:30 - 00003008 _____ () C:\Windows\System32\Tasks\DriverDoc_UPDATES
2015-04-04 23:29 - 2015-04-04 23:29 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ECP-PC-Windows-7-Home-Premium-(64-bit).dat
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\RegBackup
2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Windows\pss
2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Solvusoft
2015-04-04 23:17 - 2015-04-04 23:20 - 00000000 ____D () C:\AdwCleaner
2015-04-04 23:16 - 2015-04-04 23:16 - 00000703 _____ () C:\Users\ecp\Desktop\Reinigung - Verknüpfung.lnk
2015-04-04 22:27 - 2015-04-04 23:13 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-04 22:22 - 2015-04-04 22:22 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-04-04 22:22 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-04 22:22 - 2015-03-17 06:15 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-04 22:22 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-03-29 22:28 - 2015-03-29 22:58 - 00000000 ____D () C:\Qoobox
2015-03-29 22:28 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-03-29 22:28 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-03-29 22:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-03-29 22:27 - 2015-03-29 22:54 - 00000000 ____D () C:\Windows\erdnt
2015-03-29 22:25 - 2015-03-27 19:41 - 05615749 ____R (Swearware) C:\Users\ecp\Desktop\ComboFix.exe
2015-03-27 19:46 - 2015-03-27 19:46 - 00001271 _____ () C:\Users\ecp\Desktop\Revo Uninstaller.lnk
2015-03-27 19:46 - 2015-03-27 19:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-03-26 22:28 - 2015-04-07 21:55 - 00000000 ____D () C:\FRST
2015-03-26 22:27 - 2015-03-26 22:27 - 00000000 _____ () C:\Users\ecp\defogger_reenable
2015-03-26 22:13 - 2015-04-07 21:54 - 00000000 ____D () C:\Reinigung
2015-03-23 10:18 - 2015-03-23 10:19 - 00000000 ____D () C:\Program Files (x86)\Simple Dictation
2015-03-22 10:10 - 2015-03-22 10:10 - 00000000 ____D () C:\Users\ecp\AppData\Local\Macromedia
2015-03-22 10:09 - 2015-03-22 10:09 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-03-22 10:09 - 2015-03-22 10:09 - 00001154 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-03-22 10:09 - 2015-03-22 10:09 - 00000000 ____D () C:\Users\ecp\AppData\Local\Mozilla
2015-03-22 10:08 - 2015-03-22 10:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-22 09:32 - 2015-03-22 09:32 - 00004020 _____ () C:\Windows\System32\Tasks\Check for Scheduled Updates
2015-03-22 09:30 - 2015-03-22 09:30 - 00000000 ____D () C:\Users\ecp\AppData\Local\32220c02-c108-4e43-b856-df7d87f70051
2015-03-22 08:43 - 2015-04-04 23:04 - 00000000 ____D () C:\Program Files (x86)\SystemContinue
2015-03-20 20:06 - 2015-04-04 22:45 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-03-20 19:47 - 2015-03-20 19:47 - 00000000 ____D () C:\ProgramData\e314b8475a214ebc973cc42fbf8c6edf
2015-03-20 19:43 - 2015-03-20 19:43 - 00026784 _____ () C:\Windows\system32\Drivers\tammgF119.sys
2015-03-20 19:43 - 2015-03-20 19:43 - 00026272 _____ () C:\Windows\system32\Drivers\tammgR119.sys
2015-03-20 19:43 - 2015-03-20 19:43 - 00000000 ____D () C:\ProgramData\bobyzoom
2015-03-18 09:05 - 2015-03-18 09:06 - 00002051 _____ () C:\Users\ecp\Downloads\Henner.txt
2015-03-17 08:53 - 2015-03-16 19:43 - 01274260 _____ () C:\Users\ecp\Documents\bskundenexcel201411.xls_0.ods
2015-03-17 08:53 - 2015-03-16 19:43 - 00017886 _____ () C:\Users\ecp\Documents\TennistrainingWinterHalle201415herren55he55mitersatzregelung.xls_0.ods
2015-03-13 10:11 - 2015-03-13 10:11 - 00959266 _____ () C:\Users\ecp\Downloads\doc.zip
2015-03-13 10:02 - 2015-03-13 10:02 - 00408667 _____ () C:\Users\ecp\Downloads\odt.zip
2015-03-11 09:58 - 2015-03-11 09:59 - 00000832 _____ () C:\Users\ecp\Downloads\download.html
2015-03-11 09:17 - 2015-02-03 05:34 - 05554104 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-11 09:17 - 2015-02-03 05:31 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-03-11 09:17 - 2015-02-03 05:31 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-03-11 09:17 - 2015-02-03 05:30 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-03-11 09:17 - 2015-02-03 05:30 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-03-11 09:17 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2015-03-11 09:17 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2015-03-11 09:17 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2015-03-11 09:17 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2015-03-11 09:16 - 2015-02-03 05:34 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-03-11 09:16 - 2015-02-03 05:34 - 00094656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-03-11 09:16 - 2015-02-03 05:33 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-03-11 09:16 - 2015-02-03 05:31 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-03-11 09:16 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-03-11 09:16 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-03-11 09:16 - 2015-02-03 05:30 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-03-11 09:16 - 2015-02-03 05:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2015-03-11 09:16 - 2015-02-03 05:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2015-03-11 09:16 - 2015-02-03 05:29 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2015-03-11 09:16 - 2015-02-03 05:28 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-03-11 09:16 - 2015-02-03 05:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-03-11 09:16 - 2015-02-03 05:19 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-03-11 09:16 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-03-11 09:16 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-03-11 09:16 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2015-03-11 09:16 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2015-03-11 09:16 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2015-03-11 09:16 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2015-03-11 09:16 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2015-03-11 09:16 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2015-03-11 09:16 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2015-03-11 09:16 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-03-11 09:16 - 2015-02-03 04:32 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-03-11 09:16 - 2014-11-01 00:24 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-03-11 09:16 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-03-11 09:16 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-03-11 09:15 - 2015-02-20 06:41 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-03-11 09:15 - 2015-02-20 06:40 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-11 09:15 - 2015-02-20 05:29 - 00372224 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-11 09:15 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-03-11 09:14 - 2015-02-20 06:40 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-03-11 09:14 - 2015-02-20 06:40 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-03-11 09:14 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-03-11 09:14 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-03-11 09:14 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-03-11 09:14 - 2015-02-20 06:12 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-03-11 09:14 - 2015-01-31 05:48 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-03-11 09:14 - 2015-01-31 05:48 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 09:14 - 2015-01-31 01:56 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-03-11 09:13 - 2015-03-06 07:56 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-03-11 09:13 - 2015-03-06 07:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-03-11 09:13 - 2015-03-06 07:42 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-03-11 09:13 - 2015-03-06 07:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-03-11 09:13 - 2015-03-06 07:41 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-03-11 09:13 - 2015-03-06 07:41 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-03-11 09:13 - 2015-03-06 07:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-03-11 09:13 - 2015-03-06 07:38 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-03-11 09:13 - 2015-03-06 07:36 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-03-11 09:13 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-03-11 09:13 - 2015-03-06 07:09 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-03-11 09:13 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-03-11 09:13 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-03-11 09:13 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-03-11 09:13 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-03-11 09:13 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-03-11 09:13 - 2015-02-13 07:22 - 14177280 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-11 09:13 - 2015-02-03 05:31 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-11 09:13 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
2015-03-11 09:13 - 2015-01-31 01:56 - 00459336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-03-11 09:12 - 2015-02-26 05:25 - 03204096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-11 09:12 - 2015-02-24 05:15 - 00389800 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-11 09:12 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-03-11 09:12 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-03-11 09:12 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-03-11 09:12 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-03-11 09:12 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-03-11 09:12 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-03-11 09:12 - 2015-02-20 05:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-03-11 09:12 - 2015-02-20 05:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 09:12 - 2015-02-20 04:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-03-11 09:12 - 2015-02-20 04:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-03-11 09:12 - 2015-02-20 04:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-03-11 09:12 - 2015-02-20 04:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 09:12 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-03-11 09:12 - 2015-02-20 04:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 09:12 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-03-11 09:12 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-03-11 09:12 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-03-11 09:12 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-11 09:12 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-03-11 09:12 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-03-11 09:12 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-03-11 09:12 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-03-11 09:12 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-03-11 09:12 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-03-11 09:12 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-11 09:12 - 2015-02-20 03:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-03-11 09:12 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-03-11 09:12 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-03-11 09:12 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-03-11 09:12 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-11 09:12 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-03-11 09:12 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-03-11 09:12 - 2015-02-03 05:31 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-11 09:12 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-03-11 09:12 - 2015-01-17 04:48 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-11 09:12 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2015-03-11 09:11 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-11 09:11 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-11 09:11 - 2015-02-20 04:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-03-11 09:11 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-11 09:11 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-11 09:11 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-11 09:11 - 2015-02-20 04:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-03-11 09:11 - 2015-02-20 04:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-03-11 09:11 - 2015-02-20 04:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-03-11 09:11 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-11 09:11 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-11 09:11 - 2015-02-20 04:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-03-11 09:11 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-03-11 09:11 - 2015-02-20 04:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-03-11 09:11 - 2015-02-20 03:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-03-11 09:11 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-11 09:11 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-11 09:11 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-03-11 09:11 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-03-11 09:11 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-11 09:11 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-03-11 09:11 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-11 09:11 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-03-11 09:06 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-11 09:06 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-07 21:22 - 2014-11-25 12:56 - 02079730 _____ () C:\Windows\WindowsUpdate.log
2015-04-07 21:08 - 2014-07-23 11:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-07 19:35 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-07 19:35 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-07 19:28 - 2011-04-12 09:43 - 00698926 _____ () C:\Windows\system32\perfh007.dat
2015-04-07 19:28 - 2011-04-12 09:43 - 00149034 _____ () C:\Windows\system32\perfc007.dat
2015-04-07 19:28 - 2009-07-14 07:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-07 19:22 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-07 19:22 - 2009-07-14 06:51 - 00060234 _____ () C:\Windows\setupact.log
2015-04-04 23:26 - 2015-01-01 12:20 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Skype
2015-04-04 23:22 - 2010-11-21 05:47 - 00084124 _____ () C:\Windows\PFRO.log
2015-04-04 23:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Speech
2015-03-29 22:58 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2015-03-29 22:50 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2015-03-29 22:48 - 2009-07-14 04:34 - 61079552 _____ () C:\Windows\system32\config\SOFTWARE.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 13631488 _____ () C:\Windows\system32\config\SYSTEM.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2015-03-26 22:27 - 2014-12-30 16:50 - 00000000 ____D () C:\Users\ecp
2015-03-24 19:49 - 2015-01-01 15:35 - 00000000 ____D () C:\Users\ecp\Documents\112 wiederkehrende dateien 1412
2015-03-24 18:26 - 2015-01-01 13:26 - 00000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG
2015-03-24 18:22 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini
2015-03-24 09:15 - 2015-01-02 13:37 - 00040478 _____ () C:\Windows\system32\ScanResults.xml
2015-03-24 09:08 - 2015-01-02 13:32 - 00000464 _____ () C:\Windows\system32\ScannerSettings
2015-03-23 08:32 - 2015-01-02 00:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-22 10:09 - 2015-01-02 00:29 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Mozilla
2015-03-22 09:50 - 2014-12-31 11:40 - 00000000 ____D () C:\Users\ecp\AppData\Local\Adobe
2015-03-19 21:07 - 2014-12-30 17:38 - 00003848 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1419953902
2015-03-19 21:07 - 2014-12-30 17:37 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-03-19 21:05 - 2015-02-08 13:08 - 00000000 ____D () C:\Users\ecp\Documents\Tennisclub
2015-03-18 00:27 - 2015-03-02 11:54 - 00000000 ____D () C:\Users\ecp\Documents\Martina60Geburtstag20150406
2015-03-16 20:21 - 2014-07-23 11:43 - 00778928 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-03-16 20:21 - 2014-07-23 11:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-03-16 20:21 - 2014-07-23 11:43 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-03-16 13:57 - 2015-02-08 13:09 - 00000000 ____D () C:\Users\ecp\Documents\Privates
2015-03-13 09:40 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2015-03-13 09:35 - 2009-07-14 06:45 - 00298232 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-13 09:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2015-03-13 09:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2015-03-13 09:15 - 2014-07-22 17:37 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-13 09:06 - 2014-07-22 17:37 - 122905848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-03-11 22:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2015-03-11 09:00 - 2015-01-06 12:05 - 00000000 ____D () C:\Program Files (x86)\GTS
2015-03-09 19:16 - 2015-02-08 13:09 - 00000000 ____D () C:\Users\ecp\Documents\NBV
2015-03-09 12:13 - 2015-02-16 19:42 - 00000000 ____D () C:\Users\ecp\Documents\Camera

==================== Files in the root of some directories =======

2015-02-04 19:15 - 2015-03-04 10:17 - 0001874 _____ () C:\Users\ecp\AppData\Roaming\MyMicroBalanceConfig.ini
2015-01-01 13:26 - 2015-03-24 18:26 - 0000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG
2015-03-05 17:56 - 2015-03-05 17:56 - 0385602 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS
2015-03-05 17:56 - 2015-03-05 17:56 - 0000232 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS.part
2015-01-03 02:27 - 2015-03-01 11:48 - 0000010 _____ () C:\Users\ecp\AppData\Local\DSI.DAT

Some content of TEMP:
====================
C:\Users\ecp\AppData\Local\Temp\Quarantine.exe
C:\Users\ecp\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-11 19:40

==================== End Of Log ============================
         
--- --- ---

Alt 08.04.2015, 14:04   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Standard

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen



Java und Flash updaten.

Zitat:
() C:\ProgramData\bobyzoom\1.1.0.30\bz64.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe

kennst Du das?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 16.04.2015, 21:47   #11
Haus meister
 
Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Standard

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen



Hallo Schrauber,

Updates sind gemacht.
Probleme gibt es immer noch. Fenster die sich selbständig öffnen, Umleitungen im Browser, Einblendungen usw.

Weiterhin ist der Rechner unendlich langsam. Das Öffnen des IE oder FF dauert Minuten. (Zumindest beim ersten Mal)

Nach einem Neustart habe ich mal die Prozesse beobachtet die automatisch aktiv sind. Auffällig war, das die Prozesse bz32.exe, bz64.exe, bzdap.exe aktiv waren als das erste Werbe-Fenster autom. eingeblendet wurden. Und das sind ja auch genau die Programme die sich in dem von dir angefragten Verzeichnis befinden.
Ich kann dir aber nicht sagen was das ist oder wo es her kommt.
Ich kann das Verzeichnis auch nicht öffnen. Wenn ich das versuche bekomme ich Meldung "Auf C:\ProgramData\bobyzoom kann nicht zugegriffen werden. Falscher Parameter"


Hier ein aktuelles FRST:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-04-2015 04
Ran by ecp (administrator) on ECP-PC on 16-04-2015 22:10:41
Running from C:\Users\ecp\Desktop
Loaded Profiles: ecp (Available profiles: ecp)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE
() C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
() C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bz64.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bz32.exe
() C:\ProgramData\bobyzoom\1.1.0.30\bzdap.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [AudialsNotifier] => C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe [2410760 2014-12-17] ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {2D8E4D58-9FF9-4D32-B1A0-E2E493921442} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {9F48D099-769E-460F-8CAD-E870234711DA} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {A44BCBEF-651D-4A25-A802-3938D00F9BEE} URL = hxxp://q.search-simple.com/?affID=na&q={searchTerms}&r=92
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {BC78FFB8-43BE-431A-861E-C6CE3BA30EC0} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-16] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-16] (Oracle Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default
FF NewTab: 
FF DefaultSearchEngine: Yahoo! Search
FF Keyword.URL: 
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-16] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-16] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-16] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-16] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\searchplugins\search-simple.xml [2015-03-22]
FF Extension: BobyZoom - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\bbz@bobyzoom.com [2015-04-07]

Chrome: 
=======
CHR dev: Chrome dev build detected! <======= ATTENTION

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

Locked "tammgF119" service could not be unlocked. <===== ATTENTION
Locked "tammgR119" service could not be unlocked. <===== ATTENTION

R2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation)
R2 bobyzoom; C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [0 ] () <==== ATTENTION (zero size file/folder)
R2 bzwdg; C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [0 ] () <==== ATTENTION (zero size file/folder)
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation)
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [49648 2015-01-15] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation)
R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-12-17] (Audials AG)
R5 tammgF119; C:\Windows\System32\Drivers\tammgF119.sys [26784 2015-03-20] () [File not signed]
R5 tammgR119; C:\Windows\System32\Drivers\tammgR119.sys [26272 2015-03-20] () [File not signed]
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 CAXHWAZL; system32\DRIVERS\CAXHWAZL.sys [X]
S3 cpuz134; \??\C:\Users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 HSF_DPV; system32\DRIVERS\CAX_DPV.sys [X]
S2 mdmxsdk; system32\DRIVERS\mdmxsdk.sys [X]
S3 winachsf; system32\DRIVERS\CAX_CNXT.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-16 22:10 - 2015-04-16 22:13 - 00011243 _____ () C:\Users\ecp\Desktop\FRST.txt
2015-04-16 21:10 - 2015-04-16 21:10 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk
2015-04-16 21:10 - 2015-04-16 21:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-04-16 21:09 - 2015-04-16 21:09 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-04-16 20:37 - 2015-03-25 05:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-16 20:37 - 2015-03-25 05:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-16 20:37 - 2015-03-25 05:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-16 20:37 - 2015-03-25 05:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-16 20:37 - 2015-03-25 05:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-16 20:37 - 2015-03-25 05:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-16 20:37 - 2015-03-25 05:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-16 20:37 - 2015-03-25 05:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-16 20:37 - 2015-03-25 05:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-16 20:37 - 2015-03-25 05:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-16 20:37 - 2015-03-25 05:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-16 20:37 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-04-16 20:37 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-04-16 20:37 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-04-16 20:37 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-04-16 20:37 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-04-16 20:36 - 2015-03-23 05:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-16 20:36 - 2015-03-23 05:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-16 20:36 - 2015-03-23 05:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-16 20:36 - 2015-03-23 05:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-16 20:36 - 2015-03-23 05:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-16 20:36 - 2015-03-23 05:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-16 20:36 - 2015-03-23 05:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-16 20:36 - 2015-03-23 05:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-16 20:35 - 2015-03-05 07:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-16 20:35 - 2015-03-05 06:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-04-16 20:35 - 2015-03-04 06:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-16 20:35 - 2015-02-25 05:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-16 20:34 - 2015-03-04 06:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-16 20:34 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
2015-04-07 22:09 - 2015-04-07 22:09 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-04-07 22:09 - 2015-04-07 22:09 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-04 23:37 - 2015-04-04 23:37 - 00001178 _____ () C:\Users\ecp\Desktop\JRT.txt
2015-04-04 23:29 - 2015-04-04 23:29 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ECP-PC-Windows-7-Home-Premium-(64-bit).dat
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\RegBackup
2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Windows\pss
2015-04-04 23:17 - 2015-04-04 23:20 - 00000000 ____D () C:\AdwCleaner
2015-04-04 23:16 - 2015-04-04 23:16 - 00000703 _____ () C:\Users\ecp\Desktop\Reinigung - Verknüpfung.lnk
2015-04-04 22:27 - 2015-04-04 23:13 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-04 22:22 - 2015-04-04 22:22 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-04-04 22:22 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-04 22:22 - 2015-03-17 06:15 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-04 22:22 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-03-29 22:28 - 2015-03-29 22:58 - 00000000 ____D () C:\Qoobox
2015-03-29 22:28 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-03-29 22:28 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-03-29 22:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-03-29 22:27 - 2015-03-29 22:54 - 00000000 ____D () C:\Windows\erdnt
2015-03-29 22:25 - 2015-03-27 19:41 - 05615749 ____R (Swearware) C:\Users\ecp\Desktop\ComboFix.exe
2015-03-27 19:46 - 2015-03-27 19:46 - 00001271 _____ () C:\Users\ecp\Desktop\Revo Uninstaller.lnk
2015-03-27 19:46 - 2015-03-27 19:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-03-26 22:28 - 2015-04-16 22:10 - 00000000 ____D () C:\FRST
2015-03-26 22:27 - 2015-03-26 22:27 - 00000000 _____ () C:\Users\ecp\defogger_reenable
2015-03-26 22:18 - 2015-04-16 20:17 - 02097664 _____ (Farbar) C:\Users\ecp\Desktop\FRST64.exe
2015-03-26 22:13 - 2015-04-16 22:08 - 00000000 ____D () C:\Reinigung
2015-03-23 10:18 - 2015-03-23 10:19 - 00000000 ____D () C:\Program Files (x86)\Simple Dictation
2015-03-22 10:10 - 2015-03-22 10:10 - 00000000 ____D () C:\Users\ecp\AppData\Local\Macromedia
2015-03-22 10:09 - 2015-03-22 10:09 - 00001166 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-03-22 10:09 - 2015-03-22 10:09 - 00001154 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-03-22 10:09 - 2015-03-22 10:09 - 00000000 ____D () C:\Users\ecp\AppData\Local\Mozilla
2015-03-22 10:08 - 2015-03-22 10:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-22 09:32 - 2015-03-22 09:32 - 00004020 _____ () C:\Windows\System32\Tasks\Check for Scheduled Updates
2015-03-22 09:30 - 2015-03-22 09:30 - 00000000 ____D () C:\Users\ecp\AppData\Local\32220c02-c108-4e43-b856-df7d87f70051
2015-03-22 08:43 - 2015-04-04 23:04 - 00000000 ____D () C:\Program Files (x86)\SystemContinue
2015-03-20 20:06 - 2015-04-04 22:45 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-03-20 19:47 - 2015-03-20 19:47 - 00000000 ____D () C:\ProgramData\e314b8475a214ebc973cc42fbf8c6edf
2015-03-20 19:43 - 2015-03-20 19:43 - 00026784 _____ () C:\Windows\system32\Drivers\tammgF119.sys
2015-03-20 19:43 - 2015-03-20 19:43 - 00026272 _____ () C:\Windows\system32\Drivers\tammgR119.sys
2015-03-20 19:43 - 2015-03-20 19:43 - 00000000 ____D () C:\ProgramData\bobyzoom
2015-03-18 09:05 - 2015-03-18 09:06 - 00002051 _____ () C:\Users\ecp\Downloads\Henner.txt
2015-03-17 08:53 - 2015-03-16 19:43 - 01274260 _____ () C:\Users\ecp\Documents\bskundenexcel201411.xls_0.ods
2015-03-17 08:53 - 2015-03-16 19:43 - 00017886 _____ () C:\Users\ecp\Documents\TennistrainingWinterHalle201415herren55he55mitersatzregelung.xls_0.ods

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-16 22:08 - 2014-07-23 11:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-16 22:05 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-16 22:05 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-16 22:02 - 2014-11-25 12:56 - 01464411 _____ () C:\Windows\WindowsUpdate.log
2015-04-16 21:55 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-16 21:54 - 2009-07-14 06:51 - 00060346 _____ () C:\Windows\setupact.log
2015-04-16 21:53 - 2015-03-05 09:19 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-16 21:53 - 2015-03-05 09:19 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-16 21:53 - 2014-07-23 12:22 - 00000000 ____D () C:\Program Files\Lenovo
2015-04-16 21:53 - 2010-11-21 05:47 - 00088206 _____ () C:\Windows\PFRO.log
2015-04-16 21:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-04-16 21:13 - 2014-07-22 18:47 - 01592824 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-04-16 21:13 - 2011-04-12 09:43 - 00699160 _____ () C:\Windows\system32\perfh007.dat
2015-04-16 21:13 - 2011-04-12 09:43 - 00149268 _____ () C:\Windows\system32\perfc007.dat
2015-04-16 21:12 - 2009-07-14 07:13 - 01592824 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-16 21:09 - 2015-01-01 11:41 - 00000000 ____D () C:\ProgramData\Skype
2015-04-16 21:08 - 2014-07-22 17:37 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-16 21:01 - 2014-07-22 17:37 - 128913832 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-16 20:16 - 2014-07-23 11:43 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-04-16 20:16 - 2014-07-23 11:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-16 20:16 - 2014-07-23 11:43 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-04-16 19:51 - 2015-02-04 19:19 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-04-16 19:50 - 2015-02-04 19:16 - 00000000 ____D () C:\Program Files (x86)\Java
2015-04-16 19:46 - 2014-12-31 11:40 - 00000000 ____D () C:\Users\ecp\AppData\Local\Adobe
2015-04-07 21:59 - 2014-12-30 17:39 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Opera Software
2015-04-07 21:59 - 2014-12-30 17:39 - 00000000 ____D () C:\Users\ecp\AppData\Local\Opera Software
2015-04-07 21:59 - 2014-12-30 17:37 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-04-04 23:26 - 2015-01-01 12:20 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Skype
2015-04-04 23:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Speech
2015-03-29 22:58 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2015-03-29 22:50 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2015-03-29 22:48 - 2009-07-14 04:34 - 61079552 _____ () C:\Windows\system32\config\SOFTWARE.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 13631488 _____ () C:\Windows\system32\config\SYSTEM.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2015-03-26 22:27 - 2014-12-30 16:50 - 00000000 ____D () C:\Users\ecp
2015-03-24 19:49 - 2015-01-01 15:35 - 00000000 ____D () C:\Users\ecp\Documents\112 wiederkehrende dateien 1412
2015-03-24 18:26 - 2015-01-01 13:26 - 00000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG
2015-03-24 18:22 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini
2015-03-24 09:15 - 2015-01-02 13:37 - 00040478 _____ () C:\Windows\system32\ScanResults.xml
2015-03-24 09:08 - 2015-01-02 13:32 - 00000464 _____ () C:\Windows\system32\ScannerSettings
2015-03-23 08:32 - 2015-01-02 00:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-22 10:09 - 2015-01-02 00:29 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Mozilla
2015-03-19 21:05 - 2015-02-08 13:08 - 00000000 ____D () C:\Users\ecp\Documents\Tennisclub
2015-03-18 00:27 - 2015-03-02 11:54 - 00000000 ____D () C:\Users\ecp\Documents\Martina60Geburtstag20150406

==================== Files in the root of some directories =======

2015-02-04 19:15 - 2015-03-04 10:17 - 0001874 _____ () C:\Users\ecp\AppData\Roaming\MyMicroBalanceConfig.ini
2015-01-01 13:26 - 2015-03-24 18:26 - 0000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG
2015-03-05 17:56 - 2015-03-05 17:56 - 0385602 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS
2015-03-05 17:56 - 2015-03-05 17:56 - 0000232 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS.part
2015-01-03 02:27 - 2015-03-01 11:48 - 0000010 _____ () C:\Users\ecp\AppData\Local\DSI.DAT

Some content of TEMP:
====================
C:\Users\ecp\AppData\Local\Temp\jre-8u45-windows-au.exe
C:\Users\ecp\AppData\Local\Temp\Quarantine.exe
C:\Users\ecp\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-11 19:40

==================== End Of Log ============================
         
--- --- ---


Gruß Hausmeister

Alt 17.04.2015, 19:15   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Standard

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen



Ok, da gehen wir jetzt mal kurz von Aussen ran:

Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8)
Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
  • Downloade dir bitte die passende Version des Tools (im Zweifel beide) und speichere diese auf einen USB Stick: FRST Download FRST 32-Bit | FRST 64-Bit
  • Schließe den USB Stick an das infizierte System an und boote das System in die System Reparatur Option.
  • Scanne jetzt nach der bebilderten Anleitung oder verwende die folgende Kurzanleitung:
Über den Boot Manager:
  • Starte den Rechner neu.
  • Während dem Hochfahren drücke mehrmals die F8 Taste
  • Wähle nun Computer reparieren.
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Mit Windows CD/DVD (auch bei Windows 8 möglich):
  • Lege die Windows CD in dein Laufwerk.
  • Starte den Rechner neu und starte von der CD.
  • Wähle die Spracheinstellungen und klicke "Weiter".
  • Klicke auf Computerreparaturoptionen !
  • Wähle dein Betriebssystem und Benutzerkonto und klicke jeweils "Weiter".
Wähle in den Reparaturoptionen: Eingabeaufforderung
  • Gib nun bitte notepad ein und drücke Enter.
  • Im öffnenden Textdokument: Datei > Speichern unter... und wähle Computer.
    Hier wird dir der Laufwerksbuchstabe deines USB Sticks angezeigt, merke ihn dir.
  • Schließe Notepad wieder
  • Gib nun bitte folgenden Befehl ein.
    e:\frst.exe bzw. e:\frst64.exe
    Hinweis: e steht für den Laufwerksbuchstaben deines USB Sticks, den du dir gemerkt hast. Gegebenfalls anpassen.
  • Akzeptiere den Disclaimer mit Ja und klicke Untersuchen
Das Tool erstellt eine FRST.txt auf deinem USB Stick. Poste den Inhalt bitte hier nach Möglichkeit in Code-Tags (Anleitung).

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 21.04.2015, 19:29   #13
Haus meister
 
Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Standard

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen



Hallo Schrauber,

erledigt !
Hier das log:


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-04-2015
Ran by SYSTEM on MININT-11DFE0G on 21-04-2015 20:21:08
Running from F:\
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\ecp\...\Run: [AudialsNotifier] => C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe [2410760 2014-12-17] ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation)
S2 bobyzoom; C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [643856 2015-03-15] ()
S2 bzwdg; C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [241424 2015-03-15] ()
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
S2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation)
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [49648 2015-01-15] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation)
S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation)
S2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation)
S1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-12-17] (Audials AG)
S1 tammgF119; C:\Windows\system32\Drivers\tammgF119.sys [26784 2015-03-20] (AG Solutions)
S1 tammgR119; C:\Windows\system32\Drivers\tammgR119.sys [26272 2015-03-20] (AG Solutions)
S5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 CAXHWAZL; system32\DRIVERS\CAXHWAZL.sys [X]
S3 cpuz134; \??\C:\Users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 HSF_DPV; system32\DRIVERS\CAX_DPV.sys [X]
S2 mdmxsdk; system32\DRIVERS\mdmxsdk.sys [X]
S3 winachsf; system32\DRIVERS\CAX_CNXT.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-21 19:15 - 2015-04-21 19:16 - 00002712 _____ () C:\Windows\System32\Tasks\Tempo Runner bz64
2015-04-21 19:15 - 2015-04-21 19:16 - 00000412 _____ () C:\Windows\Tasks\Tempo Runner bz64.job
2015-04-16 21:14 - 2015-04-16 21:16 - 00026419 _____ () C:\Users\ecp\Desktop\Addition.txt
2015-04-16 21:10 - 2015-04-16 21:41 - 00026278 _____ () C:\Users\ecp\Desktop\FRST.txt
2015-04-16 20:10 - 2015-04-16 20:10 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk
2015-04-16 20:09 - 2015-04-16 20:09 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-04-16 19:37 - 2015-03-25 04:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2015-04-16 19:37 - 2015-03-25 04:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2015-04-16 19:37 - 2015-03-25 04:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2015-04-16 19:37 - 2015-03-25 04:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2015-04-16 19:37 - 2015-03-25 04:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2015-04-16 19:37 - 2015-03-25 04:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\WinSetupUI.dll
2015-04-16 19:37 - 2015-03-25 04:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\System32\wups2.dll
2015-04-16 19:37 - 2015-03-25 04:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll
2015-04-16 19:37 - 2015-03-25 04:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2015-04-16 19:37 - 2015-03-25 04:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2015-04-16 19:37 - 2015-03-25 04:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\System32\wu.upgrade.ps.dll
2015-04-16 19:37 - 2015-03-25 04:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-04-16 19:37 - 2015-03-25 04:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-04-16 19:37 - 2015-03-25 04:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-04-16 19:37 - 2015-03-25 04:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-04-16 19:37 - 2015-03-25 04:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-04-16 19:36 - 2015-03-23 04:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\System32\invagent.dll
2015-04-16 19:36 - 2015-03-23 04:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\System32\generaltel.dll
2015-04-16 19:36 - 2015-03-23 04:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\System32\appraiser.dll
2015-04-16 19:36 - 2015-03-23 04:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\System32\devinv.dll
2015-04-16 19:36 - 2015-03-23 04:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\System32\aepdu.dll
2015-04-16 19:36 - 2015-03-23 04:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\System32\aepic.dll
2015-04-16 19:36 - 2015-03-23 04:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\acmigration.dll
2015-04-16 19:36 - 2015-03-23 04:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\System32\aeinv.dll
2015-04-16 19:35 - 2015-03-05 06:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll
2015-04-16 19:35 - 2015-03-05 05:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-04-16 19:35 - 2015-03-04 05:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\System32\clfs.sys
2015-04-16 19:35 - 2015-02-25 04:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\http.sys
2015-04-16 19:34 - 2015-03-04 05:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\System32\clfsw32.dll
2015-04-16 19:34 - 2015-03-04 05:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
2015-04-07 21:09 - 2015-04-07 21:09 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-04-07 21:09 - 2015-04-07 21:09 - 00000000 ___SD () C:\Windows\System32\GWX
2015-04-04 22:37 - 2015-04-04 22:37 - 00001178 _____ () C:\Users\ecp\Desktop\JRT.txt
2015-04-04 22:29 - 2015-04-04 22:29 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ECP-PC-Windows-7-Home-Premium-(64-bit).dat
2015-04-04 22:29 - 2015-04-04 22:29 - 00000000 ____D () C:\RegBackup
2015-04-04 22:28 - 2015-04-04 22:28 - 00000000 ____D () C:\Windows\pss
2015-04-04 22:17 - 2015-04-04 22:20 - 00000000 ____D () C:\AdwCleaner
2015-04-04 22:16 - 2015-04-04 22:16 - 00000703 _____ () C:\Users\ecp\Desktop\Reinigung - Verknüpfung.lnk
2015-04-04 21:27 - 2015-04-04 22:13 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\MBAMSwissArmy.sys
2015-04-04 21:22 - 2015-04-04 21:22 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-04-04 21:22 - 2015-04-04 21:22 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-04 21:22 - 2015-04-04 21:22 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-04-04 21:22 - 2015-03-17 05:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamchameleon.sys
2015-04-04 21:22 - 2015-03-17 05:15 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mwac.sys
2015-04-04 21:22 - 2015-03-17 05:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2015-03-29 21:28 - 2015-03-29 21:58 - 00000000 ____D () C:\Qoobox
2015-03-29 21:28 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-03-29 21:28 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-03-29 21:28 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-03-29 21:28 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-03-29 21:28 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-03-29 21:28 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-03-29 21:28 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-03-29 21:28 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-03-29 21:27 - 2015-03-29 21:54 - 00000000 ____D () C:\Windows\erdnt
2015-03-29 21:25 - 2015-03-27 18:41 - 05615749 ____R (Swearware) C:\Users\ecp\Desktop\ComboFix.exe
2015-03-27 18:46 - 2015-03-27 18:46 - 00001271 _____ () C:\Users\ecp\Desktop\Revo Uninstaller.lnk
2015-03-27 18:46 - 2015-03-27 18:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-03-26 21:28 - 2015-04-21 20:21 - 00000000 ____D () C:\FRST
2015-03-26 21:27 - 2015-03-26 21:27 - 00000000 _____ () C:\Users\ecp\defogger_reenable
2015-03-26 21:18 - 2015-04-16 19:17 - 02097664 _____ (Farbar) C:\Users\ecp\Desktop\FRST64.exe
2015-03-26 21:13 - 2015-04-16 21:08 - 00000000 ____D () C:\Reinigung
2015-03-23 09:18 - 2015-03-23 09:19 - 00000000 ____D () C:\Program Files (x86)\Simple Dictation
2015-03-22 09:10 - 2015-03-22 09:10 - 00000000 ____D () C:\Users\ecp\AppData\Local\Macromedia
2015-03-22 09:09 - 2015-03-22 09:09 - 00001154 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-03-22 09:09 - 2015-03-22 09:09 - 00000000 ____D () C:\Users\ecp\AppData\Local\Mozilla
2015-03-22 09:08 - 2015-03-22 09:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-22 08:32 - 2015-03-22 08:32 - 00004020 _____ () C:\Windows\System32\Tasks\Check for Scheduled Updates
2015-03-22 08:30 - 2015-03-22 08:30 - 00000000 ____D () C:\Users\ecp\AppData\Local\32220c02-c108-4e43-b856-df7d87f70051
2015-03-22 07:43 - 2015-04-04 22:04 - 00000000 ____D () C:\Program Files (x86)\SystemContinue

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-21 19:15 - 2009-07-14 05:51 - 00062048 _____ () C:\Windows\setupact.log
2015-04-21 19:14 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-21 19:13 - 2014-11-25 11:56 - 01537382 _____ () C:\Windows\WindowsUpdate.log
2015-04-21 19:08 - 2014-07-23 10:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-21 18:57 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-21 18:57 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-21 18:42 - 2011-04-12 08:43 - 00699340 _____ () C:\Windows\System32\perfh007.dat
2015-04-21 18:42 - 2011-04-12 08:43 - 00149448 _____ () C:\Windows\System32\perfc007.dat
2015-04-21 18:42 - 2009-07-14 06:13 - 01619272 _____ () C:\Windows\System32\PerfStringBackup.INI
2015-04-16 20:53 - 2015-03-05 08:19 - 00000000 ___SD () C:\Windows\System32\CompatTel
2015-04-16 20:53 - 2015-03-05 08:19 - 00000000 ____D () C:\Windows\System32\appraiser
2015-04-16 20:53 - 2014-07-23 11:22 - 00000000 ____D () C:\Program Files\Lenovo
2015-04-16 20:53 - 2010-11-21 04:47 - 00088206 _____ () C:\Windows\PFRO.log
2015-04-16 20:53 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-04-16 20:13 - 2014-07-22 17:47 - 01592824 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-04-16 20:09 - 2015-01-01 10:41 - 00000000 ____D () C:\ProgramData\Skype
2015-04-16 20:08 - 2014-07-22 16:37 - 00000000 ____D () C:\Windows\System32\MRT
2015-04-16 20:01 - 2014-07-22 16:37 - 128913832 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2015-04-16 19:16 - 2014-07-23 10:43 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-04-16 19:16 - 2014-07-23 10:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-16 19:16 - 2014-07-23 10:43 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-04-16 18:51 - 2015-02-04 18:19 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-04-16 18:50 - 2015-02-04 18:16 - 00000000 ____D () C:\Program Files (x86)\Java
2015-04-16 18:46 - 2014-12-31 10:40 - 00000000 ____D () C:\Users\ecp\AppData\Local\Adobe
2015-04-07 20:59 - 2014-12-30 16:39 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Opera Software
2015-04-07 20:59 - 2014-12-30 16:39 - 00000000 ____D () C:\Users\ecp\AppData\Local\Opera Software
2015-04-07 20:59 - 2014-12-30 16:37 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-04-04 22:26 - 2015-01-01 11:20 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Skype
2015-04-04 22:04 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Speech
2015-04-04 21:45 - 2015-03-20 19:06 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-03-29 21:58 - 2009-07-14 04:20 - 00000000 __RHD () C:\users\Default
2015-03-29 21:50 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-03-29 21:48 - 2009-07-14 03:34 - 61079552 _____ () C:\Windows\System32\config\SOFTWARE.bak
2015-03-29 21:48 - 2009-07-14 03:34 - 13631488 _____ () C:\Windows\System32\config\SYSTEM.bak
2015-03-29 21:48 - 2009-07-14 03:34 - 00524288 _____ () C:\Windows\System32\config\DEFAULT.bak
2015-03-29 21:48 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\System32\config\SECURITY.bak
2015-03-29 21:48 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\System32\config\SAM.bak
2015-03-26 21:27 - 2014-12-30 15:50 - 00000000 ____D () C:\users\ecp
2015-03-24 18:49 - 2015-01-01 14:35 - 00000000 ____D () C:\Users\ecp\Documents\112 wiederkehrende dateien 1412
2015-03-24 17:26 - 2015-01-01 12:26 - 00000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG
2015-03-24 17:22 - 2009-07-14 03:34 - 00000505 _____ () C:\Windows\win.ini
2015-03-24 08:15 - 2015-01-02 12:37 - 00040478 _____ () C:\Windows\System32\ScanResults.xml
2015-03-24 08:08 - 2015-01-02 12:32 - 00000464 _____ () C:\Windows\System32\ScannerSettings
2015-03-23 07:32 - 2015-01-01 23:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-22 09:09 - 2015-01-01 23:29 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Mozilla

Some content of TEMP:
====================
C:\Users\ecp\AppData\Local\Temp\jre-8u45-windows-au.exe
C:\Users\ecp\AppData\Local\Temp\Quarantine.exe
C:\Users\ecp\AppData\Local\Temp\sqlite3.dll


==================== Known DLLs (Whitelisted) ================


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Restore Points  =========================

Restore point made on: 2015-03-20 19:27:03
Restore point made on: 2015-03-23 07:22:01
Restore point made on: 2015-03-23 08:20:23
Restore point made on: 2015-03-24 08:28:40
Restore point made on: 2015-03-27 18:49:08
Restore point made on: 2015-03-27 18:54:31
Restore point made on: 2015-03-27 18:57:30
Restore point made on: 2015-03-27 18:58:37
Restore point made on: 2015-03-27 19:00:31
Restore point made on: 2015-03-27 19:02:37
Restore point made on: 2015-03-27 19:03:34
Restore point made on: 2015-03-27 19:04:39
Restore point made on: 2015-03-27 19:05:44
Restore point made on: 2015-03-27 19:08:41
Restore point made on: 2015-03-27 19:10:57
Restore point made on: 2015-03-27 19:14:18
Restore point made on: 2015-03-27 19:16:06
Restore point made on: 2015-03-27 19:17:01
Restore point made on: 2015-03-27 19:18:33
Restore point made on: 2015-03-29 21:29:47
Restore point made on: 2015-03-29 22:00:02
Restore point made on: 2015-04-07 18:45:46
Restore point made on: 2015-04-07 18:59:51
Restore point made on: 2015-04-07 21:08:55
Restore point made on: 2015-04-16 18:56:47
Restore point made on: 2015-04-16 19:26:15
Restore point made on: 2015-04-16 19:59:23
Restore point made on: 2015-04-21 18:35:28

==================== Memory info =========================== 

Percentage of memory in use: 22%
Total physical RAM: 2006.3 MB
Available physical RAM: 1550.5 MB
Total Pagefile: 2006.3 MB
Available Pagefile: 1527.93 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:142.65 GB) (Free:107.76 GB) NTFS
Drive d: (System) (Fixed) (Total:6.4 GB) (Free:0.59 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive f: () (Removable) (Total:0.25 GB) (Free:0.24 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149.1 GB) (Disk ID: 4557C7D5)
Partition 1: (Active) - (Size=6.4 GB) - (Type=27)
Partition 2: (Not Active) - (Size=142.6 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 252 MB) (Disk ID: 0D0C0B0A)
Partition 1: (Active) - (Size=252 MB) - (Type=06)


LastRegBack: 2015-03-11 18:40

==================== End Of Log ============================
         
--- --- ---

Alt 22.04.2015, 08:49   #14
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Standard

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen



Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
S2 bobyzoom; C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [643856 2015-03-15] ()
S2 bzwdg; C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [241424 2015-03-15] ()
C:\ProgramData\bobyzoom
         
Speichere diese bitte als Fixlist.txt auf deinem USB Stick.
  • Starte deinen Rechner erneut in die Reparaturoptionen
  • Starte nun die FRST.exe erneut und klicke den Entfernen Button.

Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.



Frisches FRST log aus dem normalen Modus bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 22.04.2015, 18:24   #15
Haus meister
 
Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Standard

Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen



Hallo Schrauber,

alles durchgeführt.

Hier das Fixlog:
Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-04-2015
Ran by SYSTEM at 2015-04-22 18:59:45 Run:1
Running from F:\
Boot Mode: Recovery
==============================================

Content of fixlist:
*****************
S2 bobyzoom; C:\ProgramData\bobyzoom\1.1.0.30\bzagnt.exe [643856 2015-03-15] ()
S2 bzwdg; C:\ProgramData\bobyzoom\1.1.0.30\bzwdg.exe [241424 2015-03-15] ()
C:\ProgramData\bobyzoom
*****************

bobyzoom => Service deleted successfully.
bzwdg => Service deleted successfully.
C:\ProgramData\bobyzoom => Moved successfully.

==== End of Fixlog 18:59:45 ====
         
Und hier das neue FRST aus normalem Modus (ich denke du meintest damit, das ich den Rechner normal starte und dann von der Festplatte aus das FRST starte). So habe ich es nun zumindest gemacht:


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-04-2015 04
Ran by ecp (administrator) on ECP-PC on 22-04-2015 19:18:08
Running from C:\Users\ecp\Desktop
Loaded Profiles: ecp (Available profiles: ecp)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Andrea Electronics Corporation) C:\Windows\System32\AEADISRV.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
() C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-05-18] (Analog Devices, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\...\Run: [AudialsNotifier] => C:\Program Files (x86)\RapidSolution\Audials 11\AudialsNotifier.exe [2410760 2014-12-17] ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-1780445102-594666999-3139876592-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1780445102-594666999-3139876592-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = 
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {0b4d26f6-61a8-4463-99dd-5f2fe0400fa6} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {2D8E4D58-9FF9-4D32-B1A0-E2E493921442} URL = hxxp://go.mail.com/tb/en-us/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {9F48D099-769E-460F-8CAD-E870234711DA} URL = hxxp://go.1und1.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {A44BCBEF-651D-4A25-A802-3938D00F9BEE} URL = hxxp://q.search-simple.com/?affID=na&q={searchTerms}&r=92
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {BC78FFB8-43BE-431A-861E-C6CE3BA30EC0} URL = hxxp://go.web.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
SearchScopes: HKU\S-1-5-21-1780445102-594666999-3139876592-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://go.gmx.de/tb/ie_searchplugin/?q={searchTerms}&enc=UTF-8
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-16] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-16] (Oracle Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default
FF NewTab: 
FF DefaultSearchEngine: Yahoo! Search
FF Keyword.URL: 
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-16] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-16] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-16] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-16] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\searchplugins\search-simple.xml [2015-03-22]
FF Extension: BobyZoom - C:\Users\ecp\AppData\Roaming\Mozilla\Firefox\Profiles\jr56lqw0.default\Extensions\bbz@bobyzoom.com [2015-04-07]

Chrome: 
=======
CHR dev: Chrome dev build detected! <======= ATTENTION

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AEADIFilters; C:\Windows\system32\AEADISRV.EXE [111616 2008-07-15] (Andrea Electronics Corporation)
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation)
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [49648 2015-01-15] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-03-17] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation)
R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-12-17] (Audials AG)
R1 tammgF119; C:\Windows\system32\Drivers\tammgF119.sys [26784 2015-03-20] (AG Solutions)
R1 tammgR119; C:\Windows\system32\Drivers\tammgR119.sys [26272 2015-03-20] (AG Solutions)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 CAXHWAZL; system32\DRIVERS\CAXHWAZL.sys [X]
S3 cpuz134; \??\C:\Users\ecp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 HSF_DPV; system32\DRIVERS\CAX_DPV.sys [X]
S2 mdmxsdk; system32\DRIVERS\mdmxsdk.sys [X]
S3 winachsf; system32\DRIVERS\CAX_CNXT.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-22 19:18 - 2015-04-22 19:19 - 00010424 _____ () C:\Users\ecp\Desktop\FRST.txt
2015-04-21 20:15 - 2015-04-21 20:16 - 00002712 _____ () C:\Windows\System32\Tasks\Tempo Runner bz64
2015-04-21 20:15 - 2015-04-21 20:16 - 00000412 _____ () C:\Windows\Tasks\Tempo Runner bz64.job
2015-04-16 21:10 - 2015-04-16 21:10 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk
2015-04-16 21:10 - 2015-04-16 21:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-04-16 21:09 - 2015-04-16 21:09 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-04-16 20:37 - 2015-03-25 05:24 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-16 20:37 - 2015-03-25 05:24 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-16 20:37 - 2015-03-25 05:24 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-16 20:37 - 2015-03-25 05:24 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-16 20:37 - 2015-03-25 05:24 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-16 20:37 - 2015-03-25 05:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-16 20:37 - 2015-03-25 05:24 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-16 20:37 - 2015-03-25 05:24 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-16 20:37 - 2015-03-25 05:23 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-16 20:37 - 2015-03-25 05:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-16 20:37 - 2015-03-25 05:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-16 20:37 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-04-16 20:37 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-04-16 20:37 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-04-16 20:37 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-04-16 20:37 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-04-16 20:36 - 2015-03-23 05:25 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-16 20:36 - 2015-03-23 05:25 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-16 20:36 - 2015-03-23 05:24 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-16 20:36 - 2015-03-23 05:24 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-16 20:36 - 2015-03-23 05:24 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-16 20:36 - 2015-03-23 05:24 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-16 20:36 - 2015-03-23 05:24 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-16 20:36 - 2015-03-23 05:17 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-16 20:35 - 2015-03-05 07:12 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-16 20:35 - 2015-03-05 06:05 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-04-16 20:35 - 2015-03-04 06:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-16 20:35 - 2015-02-25 05:18 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-16 20:34 - 2015-03-04 06:41 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-16 20:34 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll
2015-04-07 22:09 - 2015-04-07 22:09 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-04-07 22:09 - 2015-04-07 22:09 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-04 23:37 - 2015-04-04 23:37 - 00001178 _____ () C:\Users\ecp\Desktop\JRT.txt
2015-04-04 23:29 - 2015-04-04 23:29 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ECP-PC-Windows-7-Home-Premium-(64-bit).dat
2015-04-04 23:29 - 2015-04-04 23:29 - 00000000 ____D () C:\RegBackup
2015-04-04 23:28 - 2015-04-04 23:28 - 00000000 ____D () C:\Windows\pss
2015-04-04 23:17 - 2015-04-04 23:20 - 00000000 ____D () C:\AdwCleaner
2015-04-04 23:16 - 2015-04-04 23:16 - 00000703 _____ () C:\Users\ecp\Desktop\Reinigung - Verknüpfung.lnk
2015-04-04 22:27 - 2015-04-04 23:13 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-04 22:22 - 2015-04-04 22:22 - 00001109 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-04 22:22 - 2015-04-04 22:22 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-04-04 22:22 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-04 22:22 - 2015-03-17 06:15 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-04 22:22 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-03-29 22:28 - 2015-03-29 22:58 - 00000000 ____D () C:\Qoobox
2015-03-29 22:28 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-03-29 22:28 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-03-29 22:28 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-03-29 22:28 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-03-29 22:27 - 2015-03-29 22:54 - 00000000 ____D () C:\Windows\erdnt
2015-03-29 22:25 - 2015-03-27 19:41 - 05615749 ____R (Swearware) C:\Users\ecp\Desktop\ComboFix.exe
2015-03-27 19:46 - 2015-03-27 19:46 - 00001271 _____ () C:\Users\ecp\Desktop\Revo Uninstaller.lnk
2015-03-27 19:46 - 2015-03-27 19:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-03-26 22:28 - 2015-04-22 19:18 - 00000000 ____D () C:\FRST
2015-03-26 22:27 - 2015-03-26 22:27 - 00000000 _____ () C:\Users\ecp\defogger_reenable
2015-03-26 22:18 - 2015-04-16 20:17 - 02097664 _____ (Farbar) C:\Users\ecp\Desktop\FRST64.exe
2015-03-26 22:13 - 2015-04-16 22:08 - 00000000 ____D () C:\Reinigung
2015-03-23 10:18 - 2015-03-23 10:19 - 00000000 ____D () C:\Program Files (x86)\Simple Dictation

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-22 19:11 - 2014-11-25 12:56 - 01566859 _____ () C:\Windows\WindowsUpdate.log
2015-04-22 19:09 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-22 19:09 - 2009-07-14 06:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-22 19:08 - 2014-07-23 11:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-22 19:06 - 2011-04-12 09:43 - 00699340 _____ () C:\Windows\system32\perfh007.dat
2015-04-22 19:06 - 2011-04-12 09:43 - 00149448 _____ () C:\Windows\system32\perfc007.dat
2015-04-22 19:06 - 2009-07-14 07:13 - 01619272 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-22 19:01 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-22 19:01 - 2009-07-14 06:51 - 00062104 _____ () C:\Windows\setupact.log
2015-04-16 21:53 - 2015-03-05 09:19 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-16 21:53 - 2015-03-05 09:19 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-16 21:53 - 2014-07-23 12:22 - 00000000 ____D () C:\Program Files\Lenovo
2015-04-16 21:53 - 2010-11-21 05:47 - 00088206 _____ () C:\Windows\PFRO.log
2015-04-16 21:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2015-04-16 21:13 - 2014-07-22 18:47 - 01592824 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-04-16 21:09 - 2015-01-01 11:41 - 00000000 ____D () C:\ProgramData\Skype
2015-04-16 21:08 - 2014-07-22 17:37 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-16 21:01 - 2014-07-22 17:37 - 128913832 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-16 20:16 - 2014-07-23 11:43 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-04-16 20:16 - 2014-07-23 11:43 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-16 20:16 - 2014-07-23 11:43 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-04-16 19:51 - 2015-02-04 19:19 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-04-16 19:50 - 2015-02-04 19:16 - 00000000 ____D () C:\Program Files (x86)\Java
2015-04-16 19:46 - 2014-12-31 11:40 - 00000000 ____D () C:\Users\ecp\AppData\Local\Adobe
2015-04-07 21:59 - 2014-12-30 17:39 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Opera Software
2015-04-07 21:59 - 2014-12-30 17:39 - 00000000 ____D () C:\Users\ecp\AppData\Local\Opera Software
2015-04-07 21:59 - 2014-12-30 17:37 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-04-04 23:26 - 2015-01-01 12:20 - 00000000 ____D () C:\Users\ecp\AppData\Roaming\Skype
2015-04-04 23:04 - 2015-03-22 08:43 - 00000000 ____D () C:\Program Files (x86)\SystemContinue
2015-04-04 23:04 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Speech
2015-04-04 22:45 - 2015-03-20 20:06 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-03-29 22:58 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2015-03-29 22:50 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2015-03-29 22:48 - 2009-07-14 04:34 - 61079552 _____ () C:\Windows\system32\config\SOFTWARE.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 13631488 _____ () C:\Windows\system32\config\SYSTEM.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2015-03-29 22:48 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2015-03-26 22:27 - 2014-12-30 16:50 - 00000000 ____D () C:\Users\ecp
2015-03-24 19:49 - 2015-01-01 15:35 - 00000000 ____D () C:\Users\ecp\Documents\112 wiederkehrende dateien 1412
2015-03-24 18:26 - 2015-01-01 13:26 - 00000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG
2015-03-24 18:22 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini
2015-03-24 09:15 - 2015-01-02 13:37 - 00040478 _____ () C:\Windows\system32\ScanResults.xml
2015-03-24 09:08 - 2015-01-02 13:32 - 00000464 _____ () C:\Windows\system32\ScannerSettings
2015-03-23 08:32 - 2015-01-02 00:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service

==================== Files in the root of some directories =======

2015-02-04 19:15 - 2015-03-04 10:17 - 0001874 _____ () C:\Users\ecp\AppData\Roaming\MyMicroBalanceConfig.ini
2015-01-01 13:26 - 2015-03-24 18:26 - 0000169 _____ () C:\Users\ecp\AppData\Roaming\WB.CFG
2015-03-05 17:56 - 2015-03-05 17:56 - 0385602 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS
2015-03-05 17:56 - 2015-03-05 17:56 - 0000232 _____ () C:\Users\ecp\AppData\Local\145842EF_stp.CIS.part
2015-01-03 02:27 - 2015-03-01 11:48 - 0000010 _____ () C:\Users\ecp\AppData\Local\DSI.DAT

Some content of TEMP:
====================
C:\Users\ecp\AppData\Local\Temp\jre-8u45-windows-au.exe
C:\Users\ecp\AppData\Local\Temp\Quarantine.exe
C:\Users\ecp\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-11 19:40

==================== End Of Log ============================
         
--- --- ---


Gruß Hausmeister

Antwort

Themen zu Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen
adobe, adware, bildschirm, bobyzoom, browser, defender, desktop, excel, failed, feedback, flash player, home, homepage, iexplore.exe, install.exe, mozilla, newtab, onedrive, popups, problem, protectwindowsmanager.exe, registry, reimagerealtimeprotector, rundll, scan, security, securityutility, services.exe, software, super, svchost.exe, system, temp, wiederkehrende dateien, windows




Ähnliche Themen: Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen


  1. Programme installieren sich ständig neu - Meldungen und Werbung
    Plagegeister aller Art und deren Bekämpfung - 04.09.2015 (5)
  2. Windows 7 Firefox,IE stürzt ab, Meldungen das Programme nicht funktionieren nach Verschlüsselungstrojaner
    Plagegeister aller Art und deren Bekämpfung - 31.08.2015 (30)
  3. ads by name sowie selbst installierte programme CoolncheAAP, Naruto Ultimate Battle 2, rrocCketSAlei, salEofFerr und LighterInit
    Log-Analyse und Auswertung - 14.05.2015 (25)
  4. Programme werden nicht mehr ausgeführt/Umleitung auf IE
    Log-Analyse und Auswertung - 02.12.2014 (7)
  5. Win7 64bit: Firefox neue Tabs mit Werbung, Umleitung von Seitenaurufen, Popup Fenster
    Log-Analyse und Auswertung - 21.11.2014 (10)
  6. Werbefenster, Umleitung von Webseitenaufrufen bzw. win64/adware.adpeak.c nach Klick auf E-Mail-Attachment
    Log-Analyse und Auswertung - 27.06.2014 (9)
  7. Free System Utilities installierte verdächtige Programme
    Plagegeister aller Art und deren Bekämpfung - 20.01.2014 (10)
  8. Ständigen Popup-Meldungen, neue Tabs, keine WLAN-Verbindung mehr möglich
    Plagegeister aller Art und deren Bekämpfung - 09.12.2013 (13)
  9. Programme schließen sich von selbst
    Plagegeister aller Art und deren Bekämpfung - 10.11.2012 (9)
  10. Unnötig Installierte Programme ?
    Alles rund um Windows - 01.01.2011 (6)
  11. Installierte Programme lassen sich nicht mehr starten
    Plagegeister aller Art und deren Bekämpfung - 19.11.2010 (7)
  12. Umleitung auf windowsclick.com , Programme funktionieren nicht etc.
    Plagegeister aller Art und deren Bekämpfung - 25.08.2009 (31)
  13. Batch - Installierte Programme Auslesen
    Alles rund um Windows - 30.03.2009 (9)
  14. Programme beenden sich selbst...
    Log-Analyse und Auswertung - 28.07.2008 (1)
  15. WinAntiVirusPro2006 PopUp & Co - Selbst nach Formatieren noch da?!
    Plagegeister aller Art und deren Bekämpfung - 31.08.2007 (9)
  16. av programme lockieren sich selbst
    Antiviren-, Firewall- und andere Schutzprogramme - 02.09.2005 (3)
  17. Programme beenden sich von selbst !!!
    Log-Analyse und Auswertung - 07.06.2005 (8)

Zum Thema Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen - Hallo Forum, nachdem ich letztes Mal hier super Hilfe von Schrauber bekommen habe, und den Rechner meines Kumpels "geheilt" wieder abgeben konnte, hat sich das rumgesprochen. Und schwupps bin ich - Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen...
Archiv
Du betrachtest: Win 7 64-bit: Umleitung von Webseitenaufrufen, selbst installierte Programme, Popup-Meldungen auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.