|
Log-Analyse und Auswertung: Win 7: konnte ShopGlider Deals bis jetzt nicht entfernenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
05.04.2015, 13:53 | #1 |
| Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen Hallo, vorab vielen Dank für die Möglichkeit, hier Hilfe zu finden. Und ein Wort zu mir. Ich bezeichne mich generell als DAU, da ich nur in ganz bestimmten Gebieten Teilwissen habe, dafür in vielen anderen Bereichen so gut wie Null Ahnung. Da kann es also auch vorkommen dass ich Anweisungen ohne Verzögerung nachkomme und im nächsten Moment nachfrage, wie ich was zu machen hätte. Bitte seht es mir nach. Problem: ich habe mir ein Browser-Programm gefangen, das mir dauernd Alternativen aufzeigt, sobald ich auf käufliche Waren gehe (z.b. in Amazon.de oder ebay.de). Es bezeichnet sich selbst als "ShopGlider Deals", hat auch angeblich eine Möglichkeit zum Deaktivieren, die aber nicht funktioniert. Bereits versucht: im Browser direkt habe ich es zwar "scheinbar" gelöscht, aber es ist immer noch da. Revo Uninstaller führt es nicht auf, daher konnte ich es da auch nicht löschen. Mit Agent Ransack habe ich versucht es manuell zu finden und zu löschen, hat aber leider auch nichts gebracht. Das Rücksetzen des Systems auf einen früheren Zeitpunkt brachte auch nichts. avast! konnte auch nichts finden. Daher habe ich auch keine weiteren logs. Als Browser nutze ich SRWare Iron 39.0.2100.0 [...]Die folgenden Fehler traten bei der Verarbeitung auf: Der Text, den Sie eingegeben haben, besteht aus 354686 Zeichen und ist damit zu lang. Bitte die Logs auf mehrere Beiträge aufspalten mit maximaler Länge von 120000 Zeichen.[...] Die logs, die ich laut Anleitung machen sollte: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 12:59 on 05/04/2015 (mse13ssd) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Ran by mse13ssd (administrator) on MSE13SSD-PC on 05-04-2015 13:02:19 Running from G:\Users\mse13ssd\Downloads Loaded Profiles: mse13ssd (Available profiles: mse13ssd) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) G:\Windows\System32\atiesrxx.exe (Logitech Inc.) G:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (AMD) G:\Windows\System32\atieclxx.exe (AVAST Software) G:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) G:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) G:\Program Files\Bonjour\mDNSResponder.exe (Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe (Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe (Logitech Inc.) G:\Program Files\Logitech Gaming Software\LCore.exe (Microsoft Corporation) G:\Program Files\Windows Sidebar\sidebar.exe (AVAST Software) G:\Program Files\AVAST Software\Avast\avastui.exe () G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Advanced Micro Devices Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (Skype Technologies S.A.) G:\Program Files (x86)\Skype\Phone\Skype.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe () G:\Users\mse13ssd\Downloads\Defogger.exe (Farbar) G:\Users\mse13ssd\Downloads\FRST64 (1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Launch LCore] => G:\Program Files\Logitech Gaming Software\LCore.exe [10801944 2014-07-28] (Logitech Inc.) HKLM-x32\...\Run: [AvastUI.exe] => G:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software) HKLM-x32\...\Run: [DivXMediaServer] => G:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [StartCCC] => G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Raptr] => G:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-03-25] (Raptr, Inc) HKU\S-1-5-21-3243151774-2580435505-251407729-1001\...\MountPoints2: {0a347fcb-dd9c-11e3-bf5d-806e6f6e6963} - F:\autorun.exe ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => G:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-15] (AVAST Software) BHO-x32: PDF Architect Helper -> {691B33B0-B86E-47F3-81C7-56E4FE3B929C} -> G:\Program Files (x86)\PDF Architect 2\creator-ie-helper.dll [2014-10-10] (pdfforge GmbH) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-26] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-15] (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-26] (Oracle Corporation) Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - G:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll [2014-10-10] (pdfforge GmbH) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0 FireFox: ======== FF ProfilePath: G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default FF Plugin: @adobe.com/FlashPlayer -> G:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-15] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> G:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-15] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> G:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2012-04-05] () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> G:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-26] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-26] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> G:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.) FF Plugin-x32: Adobe Reader -> G:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Extension: Download videos and MP3s from YouTube - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-11-21] FF Extension: Adblock Plus - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-09] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - G:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - G:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-17] FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension FF Extension: PDF Architect 2 Creator - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2014-12-09] FF HKU\S-1-5-21-3243151774-2580435505-251407729-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff FF Extension: Download videos and MP3s from YouTube - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-11-21] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Profile: G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-09] CHR Extension: (Google Docs) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-09] CHR Extension: (Google Drive) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-09] CHR Extension: (Google Voice Search Hotword (Beta)) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-09] CHR Extension: (YouTube) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-09] CHR Extension: (Google Search) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-09] CHR Extension: (Google Sheets) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-09] CHR Extension: (Google Wallet) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-09] CHR Extension: (Gmail) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-09] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - G:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-15] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; G:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-15] (AVAST Software) S2 PDF Architect 2 Creator; G:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH) S3 SandraAgentSrv; G:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3c\RpcAgentSrv.exe [73712 2014-09-19] (SiSoftware) [File not signed] R2 WinDefend; G:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 aswHwid; G:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-15] () R2 aswMonFlt; G:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-15] (AVAST Software) R1 aswRdr; G:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-15] (AVAST Software) R0 aswRvrt; G:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-15] () R1 aswSnx; G:\Windows\system32\drivers\aswSnx.sys [1041168 2014-11-21] (AVAST Software) R1 aswSP; G:\Windows\system32\drivers\aswSP.sys [427360 2014-07-15] (AVAST Software) R2 aswStm; G:\Windows\system32\drivers\aswStm.sys [92008 2014-07-15] (AVAST Software) R0 aswVmm; G:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-15] () R3 LGSHidFilt; G:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-05 13:02 - 2015-04-05 13:02 - 00012421 _____ () G:\Users\mse13ssd\Downloads\FRST.txt 2015-04-05 13:02 - 2015-04-05 13:02 - 00000000 ____D () G:\FRST 2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Downloads\FRST64.exe 2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Downloads\FRST64 (1).exe 2015-04-05 12:59 - 2015-04-05 12:59 - 00000478 _____ () G:\Users\mse13ssd\Downloads\defogger_disable.log 2015-04-05 12:59 - 2015-04-05 12:59 - 00000000 _____ () G:\Users\mse13ssd\defogger_reenable 2015-04-05 12:57 - 2015-04-05 12:57 - 00050477 _____ () G:\Users\mse13ssd\Downloads\Defogger.exe 2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (2).exe 2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (1).exe 2015-04-05 03:38 - 2015-04-05 03:47 - 00000000 ____D () G:\AdwCleaner 2015-04-05 03:37 - 2015-04-05 03:38 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200.exe 2015-03-31 05:26 - 2015-03-31 05:26 - 00008930 _____ () G:\Users\mse13ssd\Downloads\smime (1).p7s 2015-03-31 02:41 - 2015-03-31 02:41 - 00000069 _____ () G:\Users\mse13ssd\Desktop\BADLOGIC (German Fandub) - YouTube.url 2015-03-28 00:47 - 2015-03-28 00:47 - 00012288 _____ () G:\Users\mse13ssd\Downloads\Qual-Fraktal.xls 2015-03-27 07:14 - 2015-03-27 07:14 - 00000000 ____D () G:\Users\mse13ssd\Desktop\SciLor's Grooveshark.com Downloader 2015-03-26 21:20 - 2015-03-26 21:20 - 671367548 _____ () G:\Windows\MEMORY.DMP 2015-03-26 21:20 - 2015-03-26 21:20 - 00274624 _____ () G:\Windows\Minidump\032615-29718-01.dmp 2015-03-25 04:31 - 2015-03-25 04:31 - 00002123 _____ () G:\Users\Public\Desktop\CONTRACT J.A.C.K. .lnk 2015-03-25 04:05 - 2015-03-25 04:05 - 00000000 ____D () G:\Program Files (x86)\Sierra 2015-03-25 04:04 - 2015-03-25 04:04 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra 2015-03-25 04:00 - 2003-06-26 10:45 - 00499712 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcp71.dll 2015-03-25 04:00 - 2003-06-26 10:45 - 00348160 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcr71.dll 2015-03-25 04:00 - 2003-03-19 07:20 - 01060864 ____N (Microsoft Corporation) G:\Windows\SysWOW64\mfc71.dll 2015-03-22 18:27 - 2015-03-22 18:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in 2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files\Microsoft Silverlight 2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files (x86)\Microsoft Silverlight 2015-03-21 10:33 - 2015-03-21 10:33 - 13087456 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\Silverlight_x64.exe 2015-03-18 17:29 - 2015-03-18 17:29 - 00002023 _____ () G:\Users\mse13ssd\Desktop\Windows Phone-Desktopanwendung.lnk 2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Phone 2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\Program Files (x86)\Windows Phone 2015-03-18 17:25 - 2015-03-18 17:25 - 06745792 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\WindowsPhone.exe 2015-03-18 17:25 - 2015-03-18 17:25 - 00000000 ____D () G:\ProgramData\Applications 2015-03-16 19:19 - 2015-03-16 19:19 - 00001535 _____ () G:\Users\mse13ssd\Free YouTube to MP3 Converter.lnk 2015-03-15 17:32 - 2015-04-05 12:37 - 00001114 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-03-15 17:32 - 2015-04-05 03:49 - 00001110 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-15 17:32 - 2015-03-15 17:32 - 00004110 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-03-15 17:32 - 2015-03-15 17:32 - 00003858 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-03-15 17:32 - 2015-03-15 17:32 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2015-03-15 17:31 - 2015-03-15 17:31 - 00880208 _____ (Google Inc.) G:\Users\mse13ssd\Downloads\GoogleEarthSetup.exe 2015-03-14 07:06 - 2015-03-14 07:33 - 82044588 _____ () G:\Users\mse13ssd\Downloads\ES-X_DE.rar.crdownload 2015-03-12 09:28 - 2015-02-03 05:34 - 05554104 _____ (Microsoft Corporation) G:\Windows\system32\ntoskrnl.exe 2015-03-12 09:28 - 2015-02-03 05:34 - 00693176 _____ (Microsoft Corporation) G:\Windows\system32\winload.efi 2015-03-12 09:28 - 2015-02-03 05:34 - 00094656 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\mountmgr.sys 2015-03-12 09:28 - 2015-02-03 05:33 - 00616360 _____ (Microsoft Corporation) G:\Windows\system32\winresume.efi 2015-03-12 09:28 - 2015-02-03 05:31 - 14632960 _____ (Microsoft Corporation) G:\Windows\system32\wmp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 04121600 _____ (Microsoft Corporation) G:\Windows\system32\mf.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 01574400 _____ (Microsoft Corporation) G:\Windows\system32\quartz.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00782848 _____ (Microsoft Corporation) G:\Windows\system32\wmdrmsdk.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00641024 _____ (Microsoft Corporation) G:\Windows\system32\msscp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00503808 _____ (Microsoft Corporation) G:\Windows\system32\srcore.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00500224 _____ (Microsoft Corporation) G:\Windows\system32\AUDIOKSE.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00432128 _____ (Microsoft Corporation) G:\Windows\system32\mfplat.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00371712 _____ (Microsoft Corporation) G:\Windows\system32\qdvd.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00325632 _____ (Microsoft Corporation) G:\Windows\system32\msnetobj.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00229376 _____ (Microsoft Corporation) G:\Windows\system32\wintrust.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00206848 _____ (Microsoft Corporation) G:\Windows\system32\mfps.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00188416 _____ (Microsoft Corporation) G:\Windows\system32\pcasvc.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00063488 _____ (Microsoft Corporation) G:\Windows\system32\setbcdlocale.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00050176 _____ (Microsoft Corporation) G:\Windows\system32\srclient.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00037376 _____ (Microsoft Corporation) G:\Windows\system32\pcadm.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\msmmsp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\spwmp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\msdxm.ocx 2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\dxmasf.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 12625920 _____ (Microsoft Corporation) G:\Windows\system32\wmploc.DLL 2015-03-12 09:28 - 2015-02-03 05:30 - 01480192 _____ (Microsoft Corporation) G:\Windows\system32\crypt32.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 01202176 _____ (Microsoft Corporation) G:\Windows\system32\drmv2clt.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 01069056 _____ (Microsoft Corporation) G:\Windows\system32\cryptui.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00842240 _____ (Microsoft Corporation) G:\Windows\system32\blackbox.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00680960 _____ (Microsoft Corporation) G:\Windows\system32\audiosrv.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00631808 _____ (Microsoft Corporation) G:\Windows\system32\evr.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00497664 _____ (Microsoft Corporation) G:\Windows\system32\drmmgrtn.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00440832 _____ (Microsoft Corporation) G:\Windows\system32\AudioEng.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00296960 _____ (Microsoft Corporation) G:\Windows\system32\rstrui.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00296448 _____ (Microsoft Corporation) G:\Windows\system32\AudioSes.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00284672 _____ (Microsoft Corporation) G:\Windows\system32\EncDump.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00187904 _____ (Microsoft Corporation) G:\Windows\system32\cryptsvc.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00146944 _____ (Microsoft Corporation) G:\Windows\system32\appidpolicyconverter.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00140288 _____ (Microsoft Corporation) G:\Windows\system32\cryptnet.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00126464 _____ (Microsoft Corporation) G:\Windows\system32\audiodg.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00112640 _____ (Microsoft Corporation) G:\Windows\system32\smss.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00082432 _____ (Microsoft Corporation) G:\Windows\system32\cryptsp.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00058880 _____ (Microsoft Corporation) G:\Windows\system32\appidapi.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00055808 _____ (Microsoft Corporation) G:\Windows\system32\rrinstaller.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00043520 _____ (Microsoft Corporation) G:\Windows\system32\csrsrv.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00032256 _____ (Microsoft Corporation) G:\Windows\system32\appidsvc.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00024576 _____ (Microsoft Corporation) G:\Windows\system32\mfpmp.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00017920 _____ (Microsoft Corporation) G:\Windows\system32\appidcertstorecheck.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\pcawrk.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\pcalua.exe 2015-03-12 09:28 - 2015-02-03 05:29 - 00008704 _____ (Microsoft Corporation) G:\Windows\system32\pcaevts.dll 2015-03-12 09:28 - 2015-02-03 05:28 - 00006656 _____ (Microsoft Corporation) G:\Windows\system32\apisetschema.dll 2015-03-12 09:28 - 2015-02-03 05:28 - 00002048 _____ (Microsoft Corporation) G:\Windows\system32\mferror.dll 2015-03-12 09:28 - 2015-02-03 05:19 - 00663552 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\PEAuth.sys 2015-03-12 09:28 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntkrnlpa.exe 2015-03-12 09:28 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntoskrnl.exe 2015-03-12 09:28 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mf.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) G:\Windows\SysWOW64\quartz.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) G:\Windows\SysWOW64\crypt32.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptui.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmv2clt.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\blackbox.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmdrmsdk.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) G:\Windows\SysWOW64\qdvd.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msscp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\evr.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AUDIOKSE.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmmgrtn.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioEng.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfplat.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msnetobj.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioSes.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wintrust.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsvc.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptnet.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfps.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) G:\Windows\SysWOW64\appidapi.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) G:\Windows\SysWOW64\srclient.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\spwmp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msdxm.ocx 2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxmasf.dll 2015-03-12 09:28 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmploc.DLL 2015-03-12 09:28 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\rrinstaller.exe 2015-03-12 09:28 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfpmp.exe 2015-03-12 09:28 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mferror.dll 2015-03-12 09:28 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\apisetschema.dll 2015-03-12 09:28 - 2015-02-03 04:32 - 00061440 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\appid.sys 2015-03-12 09:28 - 2014-11-01 00:24 - 00619056 _____ (Microsoft Corporation) G:\Windows\system32\winload.exe 2015-03-12 09:28 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) G:\Windows\system32\winresume.exe 2015-03-12 09:28 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) G:\Windows\system32\ci.dll 2015-03-12 09:27 - 2015-03-06 07:56 - 00155576 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecpkg.sys 2015-03-12 09:27 - 2015-03-06 07:56 - 00095680 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecdd.sys 2015-03-12 09:27 - 2015-03-06 07:42 - 01461760 _____ (Microsoft Corporation) G:\Windows\system32\lsasrv.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00728064 _____ (Microsoft Corporation) G:\Windows\system32\kerberos.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00341504 _____ (Microsoft Corporation) G:\Windows\system32\schannel.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00314880 _____ (Microsoft Corporation) G:\Windows\system32\msv1_0.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00309760 _____ (Microsoft Corporation) G:\Windows\system32\ncrypt.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00210944 _____ (Microsoft Corporation) G:\Windows\system32\wdigest.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00136192 _____ (Microsoft Corporation) G:\Windows\system32\sspicli.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00086528 _____ (Microsoft Corporation) G:\Windows\system32\TSpkg.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00029184 _____ (Microsoft Corporation) G:\Windows\system32\sspisrv.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00028160 _____ (Microsoft Corporation) G:\Windows\system32\secur32.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00022016 _____ (Microsoft Corporation) G:\Windows\system32\credssp.dll 2015-03-12 09:27 - 2015-03-06 07:41 - 00064000 _____ (Microsoft Corporation) G:\Windows\system32\auditpol.exe 2015-03-12 09:27 - 2015-03-06 07:41 - 00031232 _____ (Microsoft Corporation) G:\Windows\system32\lsass.exe 2015-03-12 09:27 - 2015-03-06 07:39 - 00060416 _____ (Microsoft Corporation) G:\Windows\system32\msobjs.dll 2015-03-12 09:27 - 2015-03-06 07:38 - 00146432 _____ (Microsoft Corporation) G:\Windows\system32\msaudite.dll 2015-03-12 09:27 - 2015-03-06 07:36 - 00686080 _____ (Microsoft Corporation) G:\Windows\system32\adtschema.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) G:\Windows\SysWOW64\kerberos.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msv1_0.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) G:\Windows\SysWOW64\schannel.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ncrypt.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wdigest.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) G:\Windows\SysWOW64\TSpkg.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\secur32.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\credssp.dll 2015-03-12 09:27 - 2015-03-06 07:09 - 00096768 _____ (Microsoft Corporation) G:\Windows\SysWOW64\sspicli.dll 2015-03-12 09:27 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\auditpol.exe 2015-03-12 09:27 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msaudite.dll 2015-03-12 09:27 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msobjs.dll 2015-03-12 09:27 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) G:\Windows\SysWOW64\adtschema.dll 2015-03-12 09:27 - 2015-02-24 05:15 - 00389800 _____ (Microsoft Corporation) G:\Windows\system32\iedkcs32.dll 2015-03-12 09:27 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iedkcs32.dll 2015-03-12 09:27 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.dll 2015-03-12 09:27 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieframe.dll 2015-03-12 09:27 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtmsft.dll 2015-03-12 09:27 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtrans.dll 2015-03-12 09:27 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.dll 2015-03-12 09:27 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) G:\Windows\system32\mshtmled.dll 2015-03-12 09:27 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmled.dll 2015-03-12 09:27 - 2015-02-20 06:41 - 00041984 _____ (Microsoft Corporation) G:\Windows\system32\lpk.dll 2015-03-12 09:27 - 2015-02-20 06:40 - 00100864 _____ (Microsoft Corporation) G:\Windows\system32\fontsub.dll 2015-03-12 09:27 - 2015-02-20 06:40 - 00046080 _____ (Adobe Systems) G:\Windows\system32\atmlib.dll 2015-03-12 09:27 - 2015-02-20 06:40 - 00014336 _____ (Microsoft Corporation) G:\Windows\system32\dciman32.dll 2015-03-12 09:27 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\fontsub.dll 2015-03-12 09:27 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) G:\Windows\SysWOW64\atmlib.dll 2015-03-12 09:27 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dciman32.dll 2015-03-12 09:27 - 2015-02-20 06:12 - 00025600 _____ (Microsoft Corporation) G:\Windows\SysWOW64\lpk.dll 2015-03-12 09:27 - 2015-02-20 05:29 - 00372224 _____ (Adobe Systems Incorporated) G:\Windows\system32\atmfd.dll 2015-03-12 09:27 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\atmfd.dll 2015-03-12 09:27 - 2015-02-20 05:06 - 02724864 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.tlb 2015-03-12 09:27 - 2015-02-20 05:05 - 00004096 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollectorres.dll 2015-03-12 09:27 - 2015-02-20 04:50 - 00066560 _____ (Microsoft Corporation) G:\Windows\system32\iesetup.dll 2015-03-12 09:27 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) G:\Windows\system32\vbscript.dll 2015-03-12 09:27 - 2015-02-20 04:49 - 00048640 _____ (Microsoft Corporation) G:\Windows\system32\ieetwproxystub.dll 2015-03-12 09:27 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) G:\Windows\system32\iertutil.dll 2015-03-12 09:27 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) G:\Windows\system32\MshtmlDac.dll 2015-03-12 09:27 - 2015-02-20 04:41 - 00054784 _____ (Microsoft Corporation) G:\Windows\system32\jsproxy.dll 2015-03-12 09:27 - 2015-02-20 04:40 - 00034304 _____ (Microsoft Corporation) G:\Windows\system32\iernonce.dll 2015-03-12 09:27 - 2015-02-20 04:36 - 00633856 _____ (Microsoft Corporation) G:\Windows\system32\ieui.dll 2015-03-12 09:27 - 2015-02-20 04:35 - 00144384 _____ (Microsoft Corporation) G:\Windows\system32\ieUnatt.exe 2015-03-12 09:27 - 2015-02-20 04:35 - 00114688 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollector.exe 2015-03-12 09:27 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) G:\Windows\system32\jscript9diag.dll 2015-03-12 09:27 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) G:\Windows\system32\jscript9.dll 2015-03-12 09:27 - 2015-02-20 04:26 - 00968704 _____ (Microsoft Corporation) G:\Windows\system32\MsSpellCheckingFacility.exe 2015-03-12 09:27 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.tlb 2015-03-12 09:27 - 2015-02-20 04:22 - 00490496 _____ (Microsoft Corporation) G:\Windows\system32\dxtmsft.dll 2015-03-12 09:27 - 2015-02-20 04:13 - 00077824 _____ (Microsoft Corporation) G:\Windows\system32\JavaScriptCollectionAgent.dll 2015-03-12 09:27 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) G:\Windows\SysWOW64\vbscript.dll 2015-03-12 09:27 - 2015-02-20 04:08 - 00199680 _____ (Microsoft Corporation) G:\Windows\system32\msrating.dll 2015-03-12 09:27 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iesetup.dll 2015-03-12 09:27 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieetwproxystub.dll 2015-03-12 09:27 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) G:\Windows\SysWOW64\MshtmlDac.dll 2015-03-12 09:27 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) G:\Windows\system32\dxtrans.dll 2015-03-12 09:27 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iertutil.dll 2015-03-12 09:27 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jsproxy.dll 2015-03-12 09:27 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iernonce.dll 2015-03-12 09:27 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieui.dll 2015-03-12 09:27 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9diag.dll 2015-03-12 09:27 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieUnatt.exe 2015-03-12 09:27 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) G:\Windows\system32\msfeeds.dll 2015-03-12 09:27 - 2015-02-20 03:49 - 00718848 _____ (Microsoft Corporation) G:\Windows\system32\ie4uinit.exe 2015-03-12 09:27 - 2015-02-20 03:47 - 01359360 _____ (Microsoft Corporation) G:\Windows\system32\mshtmlmedia.dll 2015-03-12 09:27 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) G:\Windows\system32\inetcpl.cpl 2015-03-12 09:27 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) G:\Windows\system32\ieframe.dll 2015-03-12 09:27 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-03-12 09:27 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msrating.dll 2015-03-12 09:27 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9.dll 2015-03-12 09:27 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) G:\Windows\system32\wininet.dll 2015-03-12 09:27 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) G:\Windows\SysWOW64\inetcpl.cpl 2015-03-12 09:27 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msfeeds.dll 2015-03-12 09:27 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmlmedia.dll 2015-03-12 09:27 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) G:\Windows\system32\urlmon.dll 2015-03-12 09:27 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) G:\Windows\system32\ieapfltr.dll 2015-03-12 09:27 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wininet.dll 2015-03-12 09:27 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) G:\Windows\SysWOW64\urlmon.dll 2015-03-12 09:27 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieapfltr.dll 2015-03-12 09:27 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) G:\Windows\SysWOW64\shell32.dll 2015-03-12 09:27 - 2015-02-13 07:22 - 14177280 _____ (Microsoft Corporation) G:\Windows\system32\shell32.dll 2015-03-12 09:27 - 2015-02-03 05:31 - 01424896 _____ (Microsoft Corporation) G:\Windows\system32\WindowsCodecs.dll 2015-03-12 09:27 - 2015-02-03 05:31 - 00215552 _____ (Microsoft Corporation) G:\Windows\system32\ubpm.dll 2015-03-12 09:27 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WindowsCodecs.dll 2015-03-12 09:27 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ubpm.dll 2015-03-12 09:27 - 2015-01-31 05:48 - 03179520 _____ (Microsoft Corporation) G:\Windows\system32\rdpcorets.dll 2015-03-12 09:27 - 2015-01-31 05:48 - 00016384 _____ (Microsoft Corporation) G:\Windows\system32\RdpGroupPolicyExtension.dll 2015-03-12 09:27 - 2015-01-31 01:56 - 00459336 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\cng.sys 2015-03-12 09:27 - 2015-01-31 01:56 - 00243200 _____ (Microsoft Corporation) G:\Windows\system32\rdpudd.dll 2015-03-12 09:27 - 2015-01-17 04:48 - 01067520 _____ (Microsoft Corporation) G:\Windows\system32\msctf.dll 2015-03-12 09:27 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msctf.dll 2015-03-12 09:26 - 2015-02-26 05:25 - 03204096 _____ (Microsoft Corporation) G:\Windows\system32\win32k.sys 2015-03-12 09:26 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) G:\Windows\system32\WMPhoto.dll 2015-03-12 09:26 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WMPhoto.dll 2015-03-10 01:20 - 2015-03-10 01:20 - 00001002 _____ () G:\Users\mse13ssd\Downloads\BAHN_Fahrplan_20150609.ics 2015-03-09 11:16 - 2015-03-09 11:56 - 124202474 _____ () G:\Users\mse13ssd\Downloads\#0325#.rar 2015-03-08 09:43 - 2015-03-08 09:43 - 01230365 _____ () G:\Users\mse13ssd\Downloads\2 (1).wmv 2015-03-08 09:43 - 2015-03-08 09:43 - 01222357 _____ () G:\Users\mse13ssd\Downloads\3.wmv 2015-03-06 16:14 - 2015-03-06 16:51 - 111138743 _____ () G:\Users\mse13ssd\Downloads\julins2014.rar ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-05 12:59 - 2014-05-17 11:54 - 00000000 ____D () G:\Users\mse13ssd 2015-04-05 12:46 - 2014-05-17 22:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Skype 2015-04-05 07:05 - 2014-05-17 10:22 - 01367011 _____ () G:\Windows\WindowsUpdate.log 2015-04-05 03:57 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-05 03:57 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-05 03:54 - 2009-07-14 19:58 - 00700986 _____ () G:\Windows\system32\perfh007.dat 2015-04-05 03:54 - 2009-07-14 19:58 - 00149886 _____ () G:\Windows\system32\perfc007.dat 2015-04-05 03:54 - 2009-07-14 07:13 - 01619284 _____ () G:\Windows\system32\PerfStringBackup.INI 2015-04-05 03:50 - 2014-07-13 00:21 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Raptr 2015-04-05 03:49 - 2014-05-17 22:03 - 00000000 _____ () G:\Windows\system32\Drivers\lvuvc.hs 2015-04-05 03:49 - 2014-05-17 15:20 - 00032476 _____ () G:\Windows\PFRO.log 2015-04-05 03:49 - 2009-07-14 07:08 - 00000006 ____H () G:\Windows\Tasks\SA.DAT 2015-04-05 03:49 - 2009-07-14 06:51 - 00055467 _____ () G:\Windows\setupact.log 2015-04-05 03:33 - 2015-03-05 14:19 - 00129752 _____ (Malwarebytes Corporation) G:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-04-05 03:26 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\Web 2015-04-05 02:39 - 2014-05-17 15:57 - 00004182 _____ () G:\Windows\System32\Tasks\avast! Emergency Update 2015-04-04 14:30 - 2014-05-17 20:13 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\TS3Client 2015-04-02 01:34 - 2009-07-14 07:32 - 00000000 ____D () G:\Windows\system32\FxsTmp 2015-03-30 21:24 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\NDF 2015-03-30 17:36 - 2015-02-28 05:38 - 00000000 ____D () G:\Users\mse13ssd\Desktop\aufgeräumt 2015-03-30 08:10 - 2014-11-01 08:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\25372 2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\DivX 2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX 2015-03-30 04:33 - 2014-08-24 02:00 - 00000000 ____D () G:\ProgramData\DivX 2015-03-30 04:33 - 2014-05-17 15:57 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast 2015-03-30 04:33 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\AppCompat 2015-03-30 04:32 - 2014-08-24 02:01 - 00000000 ____D () G:\Program Files\DivX 2015-03-30 04:32 - 2014-08-24 02:00 - 00000000 ____D () G:\Program Files (x86)\DivX 2015-03-30 04:32 - 2014-06-18 17:31 - 00000000 ____D () G:\Program Files (x86)\Microsoft Office 2015-03-30 04:32 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\registration 2015-03-30 03:27 - 2009-07-14 20:18 - 00000000 ___RD () G:\Users\Public\Recorded TV 2015-03-26 21:20 - 2014-10-12 12:01 - 00000000 ____D () G:\Windows\Minidump 2015-03-26 18:51 - 2014-07-13 00:21 - 00000000 ____D () G:\Program Files (x86)\Raptr 2015-03-26 09:13 - 2014-06-18 17:31 - 00000000 ____D () G:\ProgramData\Microsoft Help 2015-03-22 18:29 - 2014-05-17 12:40 - 00070368 _____ () G:\Users\mse13ssd\AppData\Local\GDIPFONTCACHEV1.DAT 2015-03-22 18:29 - 2009-07-14 06:45 - 00307752 _____ () G:\Windows\system32\FNTCACHE.DAT 2015-03-22 18:25 - 2014-06-18 17:32 - 00000000 ____D () G:\Program Files (x86)\Microsoft Works 2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Google 2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Program Files (x86)\Google 2015-03-15 14:09 - 2014-08-24 13:49 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Adobe 2015-03-15 14:09 - 2014-05-17 15:53 - 00778928 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerApp.exe 2015-03-15 14:09 - 2014-05-17 15:53 - 00142512 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-03-15 05:05 - 2014-06-21 18:28 - 00000000 ____D () G:\Program Files (x86)\Steam 2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Glyph 2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glyph 2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Program Files (x86)\Glyph 2015-03-13 10:32 - 2009-07-14 07:09 - 00000000 ____D () G:\Windows\System32\Tasks\WPD 2015-03-12 12:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\rescache 2015-03-12 09:37 - 2015-02-28 09:01 - 00000000 ___RD () G:\Users\mse13ssd\Virtual Machines 2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\SysWOW64\Dism 2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\Dism 2015-03-12 09:31 - 2014-05-17 20:36 - 00000000 ____D () G:\Windows\system32\MRT 2015-03-12 09:29 - 2014-05-17 20:36 - 122905848 _____ (Microsoft Corporation) G:\Windows\system32\MRT.exe 2015-03-06 13:47 - 2014-10-13 17:23 - 00000000 ___RD () G:\Program Files (x86)\Skype 2015-03-06 13:47 - 2014-05-17 22:15 - 00000000 ____D () G:\ProgramData\Skype ==================== Files in the root of some directories ======= 2014-10-02 16:29 - 2015-02-28 12:40 - 14286848 _____ () G:\Users\mse13ssd\AppData\Roaming\Sandra.mdb 2015-01-23 13:40 - 2015-01-23 13:40 - 0003584 _____ () G:\Users\mse13ssd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-01-01 14:58 - 2015-01-01 14:58 - 0007605 _____ () G:\Users\mse13ssd\AppData\Local\Resmon.ResmonCfg Some content of TEMP: ==================== G:\Users\mse13ssd\AppData\Local\Temp\CmdLineExt03.dll G:\Users\mse13ssd\AppData\Local\Temp\cres.dll G:\Users\mse13ssd\AppData\Local\Temp\cshell.dll G:\Users\mse13ssd\AppData\Local\Temp\DivXSetup.exe G:\Users\mse13ssd\AppData\Local\Temp\DJAPI.dll G:\Users\mse13ssd\AppData\Local\Temp\drm_dialogs.dll G:\Users\mse13ssd\AppData\Local\Temp\drm_dyndata_7270006.dll G:\Users\mse13ssd\AppData\Local\Temp\drm_dyndata_7340007.dll G:\Users\mse13ssd\AppData\Local\Temp\FreeYouTubeDownload.exe G:\Users\mse13ssd\AppData\Local\Temp\jre-8u31-windows-au.exe G:\Users\mse13ssd\AppData\Local\Temp\MSETUP4.EXE G:\Users\mse13ssd\AppData\Local\Temp\ose00000.exe G:\Users\mse13ssd\AppData\Local\Temp\PamelaSetup_54845e3c.exe G:\Users\mse13ssd\AppData\Local\Temp\PamFaxSetup.exe G:\Users\mse13ssd\AppData\Local\Temp\Quarantine.exe G:\Users\mse13ssd\AppData\Local\Temp\raptrpatch.exe G:\Users\mse13ssd\AppData\Local\Temp\raptr_stub.exe G:\Users\mse13ssd\AppData\Local\Temp\SIntf16.dll G:\Users\mse13ssd\AppData\Local\Temp\SIntf32.dll G:\Users\mse13ssd\AppData\Local\Temp\SIntfNT.dll G:\Users\mse13ssd\AppData\Local\Temp\SkypeSetup.exe G:\Users\mse13ssd\AppData\Local\Temp\sqlite3.dll G:\Users\mse13ssd\AppData\Local\Temp\sres.dll G:\Users\mse13ssd\AppData\Local\Temp\tmd_34011292.exe G:\Users\mse13ssd\AppData\Local\Temp\tmd_34012212.exe G:\Users\mse13ssd\AppData\Local\Temp\tmd_34012979.exe G:\Users\mse13ssd\AppData\Local\Temp\tmd_34013116.exe G:\Users\mse13ssd\AppData\Local\Temp\tmd_34013851.exe G:\Users\mse13ssd\AppData\Local\Temp\tmd_34017196.exe G:\Users\mse13ssd\AppData\Local\Temp\tmd_34018551.exe G:\Users\mse13ssd\AppData\Local\Temp\tmp34C5.exe G:\Users\mse13ssd\AppData\Local\Temp\tmp8B1F.exe G:\Users\mse13ssd\AppData\Local\Temp\_is962D.exe G:\Users\mse13ssd\AppData\Local\Temp\_isD8E7.exe G:\Users\mse13ssd\AppData\Local\Temp\_isFC9.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) G:\Windows\System32\winlogon.exe => File is digitally signed G:\Windows\System32\wininit.exe => File is digitally signed G:\Windows\SysWOW64\wininit.exe => File is digitally signed G:\Windows\explorer.exe => File is digitally signed G:\Windows\SysWOW64\explorer.exe => File is digitally signed G:\Windows\System32\svchost.exe => File is digitally signed G:\Windows\SysWOW64\svchost.exe => File is digitally signed G:\Windows\System32\services.exe => File is digitally signed G:\Windows\System32\User32.dll => File is digitally signed G:\Windows\SysWOW64\User32.dll => File is digitally signed G:\Windows\System32\userinit.exe => File is digitally signed G:\Windows\SysWOW64\userinit.exe => File is digitally signed G:\Windows\System32\rpcss.dll => File is digitally signed G:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-04-04 00:45 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015 Ran by mse13ssd at 2015-04-05 13:02:54 Running from G:\Users\mse13ssd\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) AGEIA PhysX v7.11.13 (HKLM-x32\...\{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}) (Version: 7.11.13 - AGEIA Technologies, Inc.) Agent Ransack x64 (HKLM\...\{58C0AC50-8FA1-4A95-AEC6-5B2727E5CC6A}) (Version: 7.0.820.1 - Mythicsoft Ltd) AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) Apple Application Support (HKLM-x32\...\{122ADF8C-DDA1-480C-9936-C88F2825B265}) (Version: 2.1.9 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}) (Version: 5.2.0.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Archeage (HKLM-x32\...\Glyph Archeage) (Version: - Trion Worlds, Inc.) ArtMoney SE v7.43 (HKLM-x32\...\ArtMoney SE_is1) (Version: 7.43 - System SoftLab) avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software) Avery Wizard 5.0 (HKLM-x32\...\{FC3B3A5D-7058-4627-9F1E-F95CC38B6054}) (Version: 5.0.5 - Avery) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software) Canon iP7200 series Benutzerregistrierung (HKLM-x32\...\Canon iP7200 series Benutzerregistrierung) (Version: - Canon Inc.) Canon iP7200 series Printer Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP7200_series) (Version: - Canon Inc.) Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - ) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.0.0 - Canon Inc.) CanoScan LiDE 110 Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2414) (Version: - Canon Inc.) ClipboardManager 1.6 (HKLM-x32\...\ClipboardManager_is1) (Version: - ) Contract Jack (HKLM-x32\...\{374CAB30-2F61-4439-9A4A-24D3AEA2960A}) (Version: - ) CPUID CPU-Z 1.70 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) Die Siedler II - Die nächste Generation (HKLM-x32\...\S2TNG) (Version: - ) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.7.0.31 - DivX, LLC) Free YouTube Download version 3.2.53.128 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.53.128 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.50.1111 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.50.1111 - DVDVideoSoft Ltd.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden GUILD WARS (HKLM-x32\...\Guild Wars) (Version: - ) iTunes (HKLM\...\{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}) (Version: 10.6.3.25 - Apple Inc.) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) Logitech Gaming Software 8.55 (HKLM\...\Logitech Gaming Software) (Version: 8.55.137 - Logitech Inc.) Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Mozilla Firefox 36.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 36.0 (x86 de)) (Version: 36.0 - Mozilla) paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC) Pamela Pro 4.9 (HKLM-x32\...\Pamela) (Version: 4.9 - PamConsult GmbH) PDF Architect 2 Create Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.0 - pdfforge) Raptr (HKLM-x32\...\Raptr) (Version: - ) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) SciLor's grooveshark™.com Downloader 0.4.15 (HKLM-x32\...\{DDEAE484-D5FB-49CB-BD47-9512E8ACCA65}_is1) (Version: 0.4.15 - SciLor) SiSoftware Sandra Lite 2014.SP3c (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2496}_is1) (Version: 20.47.2014.10 - SiSoftware) Skype™ 7.1 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.) SRWare Iron Version SRWare Iron 39.2100.0 (HKLM-x32\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: SRWare Iron 39.2100.0 - SRWare) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden Windows Phone app for desktop (HKLM-x32\...\{19773614-FC22-4ACC-AAA3-E6BDA81ACF92}) (Version: 1.1.2726.0 - Microsoft Corporation) WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 29-03-2015 08:56:50 Revo Uninstaller's restore point - Archeage 30-03-2015 03:26:17 Wiederherstellungsvorgang 30-03-2015 04:29:37 avast! antivirus system restore point 30-03-2015 04:32:01 Wiederherstellungsvorgang 30-03-2015 18:28:06 Windows Update 01-04-2015 19:32:07 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A G:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {1FC3D3B2-F254-4B57-9695-FFF62B3AC150} - System32\Tasks\GoogleUpdateTaskMachineCore => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15] (Google Inc.) Task: {34D4B971-AD1B-4F8D-8ED4-6F6BF7ABE60D} - System32\Tasks\avast! Emergency Update => G:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-07-15] (AVAST Software) Task: {BD6EFB7D-29B9-4725-B4CB-C2F47B685F42} - System32\Tasks\Abelssoft\Updater scan => G:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe Task: {DB431844-F8D5-409D-A115-BB442A487B85} - System32\Tasks\GoogleUpdateTaskMachineUA => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15] (Google Inc.) Task: {E57F8AB1-453C-45BC-BF7F-E700E5C6EBA9} - System32\Tasks\Adobe Acrobat Update Task => G:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2014-07-28 20:29 - 2014-07-28 20:29 - 00866584 _____ () G:\Program Files\Logitech Gaming Software\libGLESv2.dll 2014-07-28 20:32 - 2014-07-28 20:32 - 01050904 _____ () G:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2014-07-28 20:29 - 2014-07-28 20:29 - 00059160 _____ () G:\Program Files\Logitech Gaming Software\libEGL.dll 2014-07-28 20:31 - 2014-07-28 20:31 - 00242456 _____ () G:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2014-01-10 07:26 - 2014-01-10 07:26 - 01861968 _____ () G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 2015-04-05 12:57 - 2015-04-05 12:57 - 00050477 _____ () G:\Users\mse13ssd\Downloads\Defogger.exe 2014-07-15 08:28 - 2014-07-15 08:28 - 00301152 _____ () G:\Program Files\AVAST Software\Avast\aswProperty.dll 2015-04-05 02:39 - 2015-04-05 02:39 - 02923520 _____ () G:\Program Files\AVAST Software\Avast\defs\15040401\algo.dll 2015-04-05 11:50 - 2015-04-05 11:50 - 02923520 _____ () G:\Program Files\AVAST Software\Avast\defs\15040500\algo.dll 2012-05-30 20:06 - 2012-05-30 20:06 - 00087912 _____ () G:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2012-05-30 20:06 - 2012-05-30 20:06 - 01242512 _____ () G:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-07-15 08:28 - 2014-07-15 08:28 - 19329904 _____ () G:\Program Files\AVAST Software\Avast\libcef.dll 2014-01-10 07:28 - 2014-01-10 07:28 - 00100688 _____ () G:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2014-05-17 12:27 - 2014-12-05 20:30 - 01359360 _____ () G:\Program Files (x86)\SRWare Iron\libglesv2.dll 2014-05-17 12:27 - 2014-12-05 20:31 - 00212992 _____ () G:\Program Files (x86)\SRWare Iron\libegl.dll 2015-01-08 21:01 - 2014-12-05 20:53 - 09299968 _____ () G:\Program Files (x86)\SRWare Iron\pdf.dll 2014-05-17 12:27 - 2014-12-05 20:32 - 00984576 _____ () G:\Program Files (x86)\SRWare Iron\ffmpegsumo.dll 2015-03-15 14:09 - 2015-03-15 14:09 - 16858288 _____ () G:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: G:\Users\mse13ssd\Downloads\email_5937_20150205205259.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Control Panel\Desktop\\Wallpaper -> G:\Users\mse13ssd\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.0.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: bthserv => 3 MSCONFIG\Services: DPS => 2 MSCONFIG\Services: SensrSvc => 3 MSCONFIG\startupreg: Adobe ARM => "G:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: APSDaemon => "G:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: iTunesHelper => "G:\Program Files (x86)\iTunes\iTunesHelper.exe" ==================== Accounts: ============================= Administrator (S-1-5-21-3243151774-2580435505-251407729-500 - Administrator - Disabled) Gast (S-1-5-21-3243151774-2580435505-251407729-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3243151774-2580435505-251407729-1002 - Limited - Enabled) mse13ssd (S-1-5-21-3243151774-2580435505-251407729-1001 - Administrator - Enabled) => G:\Users\mse13ssd ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/05/2015 03:49:52 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x530 Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 Error: (04/05/2015 03:26:38 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x790 Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 Error: (04/05/2015 02:39:20 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x510 Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 Error: (04/03/2015 09:22:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x1bec Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 Error: (04/02/2015 01:44:27 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x1a9c Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 Error: (04/01/2015 07:55:08 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x7e8 Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 Error: (04/01/2015 06:57:16 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x818 Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 Error: (04/01/2015 06:29:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0xf84 Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 Error: (04/01/2015 07:02:36 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x5dc Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 Error: (04/01/2015 04:31:52 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x430 Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 System errors: ============= Error: (04/05/2015 03:49:58 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (04/05/2015 03:49:31 AM) (Source: Ntfs) (EventID: 137) (User: ) Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (04/05/2015 03:47:42 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/05/2015 03:47:41 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/05/2015 03:47:41 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/05/2015 03:47:41 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Dienst "Bonjour"" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (04/05/2015 03:47:41 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Apple Mobile Device" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/05/2015 03:47:41 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Adobe Acrobat Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (04/05/2015 03:47:41 AM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: Der Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts. Error: (04/05/2015 03:47:41 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "UMVPFSrv" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz Percentage of memory in use: 24% Total physical RAM: 16384 MB Available physical RAM: 12434.16 MB Total Pagefile: 32766.19 MB Available Pagefile: 28666.01 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.5 GB) (Free:736.3 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:0.01 GB) (Free:0 GB) NTFS Drive f: (Nolf2xp_1) (CDROM) (Total:0.64 GB) (Free:0 GB) CDFS Drive g: (SSD) (Fixed) (Total:119.24 GB) (Free:13.21 GB) NTFS Drive m: (SAMSUNG) (Fixed) (Total:1396.92 GB) (Free:815.44 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: 7E008421) Partition 1: (Active) - (Size=119.2 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 1CA61CA5) Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=7 MB) - (Type=07 NTFS) ======================================================== Disk: 6 (Size: 1397.3 GB) (Disk ID: 5C9C6FA9) Partition 1: (Not Active) - (Size=1397.3 GB) - (Type=0C) ==================== End Of Log ============================ |
05.04.2015, 13:57 | #2 |
/// the machine /// TB-Ausbilder | Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen hi,
__________________Scan mit Combofix
__________________ |
05.04.2015, 13:57 | #3 |
| Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen Wow, das ging ja schnell. Brauche ich das logfile von GMER jetzt nicht mehr zu posten? Das muss ich nämlich auf drei Beiträge splitten.
__________________Ich mach mich erstmal an Combofix. Danke für das superschnelle Reagieren. Fehlermeldung kam keine, allerdings konnte ich ComboFix nicht auf den Desktop speichern. Code:
ATTFilter Dateien erstellt von 2015-03-05 bis 2015-04-05 )))))))))))))))))))))))))))))) . . 2015-04-05 13:09 . 2015-04-05 13:09 -------- d-----w- g:\users\Default\AppData\Local\temp 2015-04-05 11:02 . 2015-04-05 11:03 -------- d-----w- G:\FRST 2015-04-05 01:38 . 2015-04-05 01:47 -------- d-----w- G:\AdwCleaner 2015-04-01 17:58 . 2015-03-23 00:32 12002392 ----a-w- g:\programdata\Microsoft\Windows Defender\Definition Updates\{0B4005F3-08BC-4508-9E4D-9F90FAABE072}\mpengine.dll 2015-03-25 02:05 . 2015-03-25 02:05 -------- d-----w- g:\program files (x86)\Sierra 2015-03-25 02:00 . 2003-06-26 08:45 499712 ------w- g:\windows\SysWow64\msvcp71.dll 2015-03-25 02:00 . 2003-06-26 08:45 348160 ------w- g:\windows\SysWow64\msvcr71.dll 2015-03-25 02:00 . 2003-03-19 05:20 1060864 ------w- g:\windows\SysWow64\mfc71.dll 2015-03-25 01:59 . 2001-09-05 03:18 77824 ----a-w- g:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll 2015-03-25 01:59 . 2001-09-05 03:18 225280 ----a-w- g:\program files (x86)\Common Files\InstallShield\IScript\iscript.dll 2015-03-25 01:59 . 2001-09-05 03:14 176128 ----a-w- g:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll 2015-03-25 01:59 . 2001-09-05 03:13 32768 ----a-w- g:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll 2015-03-22 16:27 . 2015-03-22 16:27 -------- d-----w- g:\program files (x86)\Microsoft 2015-03-21 08:34 . 2015-03-21 08:34 -------- d-----w- g:\program files\Microsoft Silverlight 2015-03-21 08:34 . 2015-03-21 08:34 -------- d-----w- g:\program files (x86)\Microsoft Silverlight 2015-03-18 15:27 . 2015-03-18 15:27 -------- d-----w- g:\program files (x86)\Windows Phone 2015-03-18 15:25 . 2015-03-18 15:25 -------- d-----w- g:\programdata\Applications 2015-03-12 07:27 . 2015-03-06 05:56 95680 ----a-w- g:\windows\system32\drivers\ksecdd.sys 2015-03-12 07:26 . 2015-02-26 03:25 3204096 ----a-w- g:\windows\system32\win32k.sys 2015-03-12 07:26 . 2015-02-04 03:16 465920 ----a-w- g:\windows\system32\WMPhoto.dll 2015-03-12 07:26 . 2015-02-04 02:54 417792 ----a-w- g:\windows\SysWow64\WMPhoto.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-04-05 01:33 . 2015-03-05 12:19 129752 ----a-w- g:\windows\system32\drivers\MBAMSwissArmy.sys 2015-03-15 12:09 . 2014-05-17 13:53 778928 ----a-w- g:\windows\SysWow64\FlashPlayerApp.exe 2015-03-15 12:09 . 2014-05-17 13:53 142512 ----a-w- g:\windows\SysWow64\FlashPlayerCPLApp.cpl 2015-03-12 07:29 . 2014-05-17 18:36 122905848 ----a-w- g:\windows\system32\MRT.exe 2015-02-24 02:17 . 2014-05-17 10:10 295552 ------w- g:\windows\system32\MpSigStub.exe 2015-02-17 15:04 . 2015-02-17 15:04 1202848 ----a-w- g:\windows\SysWow64\FM20.DLL 2015-01-26 06:25 . 2014-10-01 11:55 98216 ----a-w- g:\windows\SysWow64\WindowsAccessBridge-32.dll 2015-01-09 03:14 . 2015-02-16 05:18 91136 ----a-w- g:\windows\system32\wdi.dll 2015-01-09 03:14 . 2015-02-16 05:18 950272 ----a-w- g:\windows\system32\perftrack.dll 2015-01-09 03:14 . 2015-02-16 05:18 29696 ----a-w- g:\windows\system32\powertracker.dll 2015-01-09 02:48 . 2015-02-16 05:18 76800 ----a-w- g:\windows\SysWow64\wdi.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{691B33B0-B86E-47F3-81C7-56E4FE3B929C}] 2014-10-10 15:03 37928 ----a-w- g:\program files (x86)\PDF Architect 2\creator-ie-helper.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{DEEB13D7-CEA9-45FB-B77C-E039BEC85221}"= "g:\program files (x86)\PDF Architect 2\creator-ie-plugin.dll" [2014-10-10 478760] . [HKEY_CLASSES_ROOT\clsid\{deeb13d7-cea9-45fb-b77c-e039bec85221}] [HKEY_CLASSES_ROOT\PDFIEPlugin.PDFIEConverter.1] [HKEY_CLASSES_ROOT\TypeLib\{30CEDC3C-254F-4827-9A25-A4AA041826CC}] [HKEY_CLASSES_ROOT\PDFIEPlugin.PDFIEConverter] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="g:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "AvastUI.exe"="g:\program files\AVAST Software\Avast\AvastUI.exe" [2014-07-31 4085896] "DivXMediaServer"="g:\program files (x86)\DivX\DivX Media Server\DivXMediaServer.exe" [2014-11-17 448856] "DivXUpdate"="g:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2014-01-10 1861968] "StartCCC"="g:\program files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-11-20 767176] "Raptr"="g:\program files (x86)\Raptr\raptrstub.exe" [2015-03-25 55568] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . R2 aswStm;aswStm;g:\windows\system32\drivers\aswStm.sys;g:\windows\SYSNATIVE\drivers\aswStm.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;g:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;g:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 PDF Architect 2 Creator;PDF Architect 2 Creator;g:\program files (x86)\PDF Architect 2\creator-ws.exe;g:\program files (x86)\PDF Architect 2\creator-ws.exe [x] R2 SkypeUpdate;Skype Updater;g:\program files (x86)\Skype\Updater\Updater.exe;g:\program files (x86)\Skype\Updater\Updater.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;g:\windows\system32\IEEtwCollector.exe;g:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;g:\windows\system32\drivers\rdpvideominiport.sys;g:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 SandraAgentSrv;SiSoftware Deployment Agent Service;g:\program files\SiSoftware\SiSoftware Sandra Lite 2014.SP3c\RpcAgentSrv.exe;g:\program files\SiSoftware\SiSoftware Sandra Lite 2014.SP3c\RpcAgentSrv.exe [x] R3 TsUsbFlt;TsUsbFlt;g:\windows\system32\drivers\tsusbflt.sys;g:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;g:\windows\system32\Drivers\usbaapl64.sys;g:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] S0 aswRvrt;avast! Revert; [x] S0 aswVmm;avast! VM Monitor; [x] S1 aswSnx;aswSnx;g:\windows\system32\drivers\aswSnx.sys;g:\windows\SYSNATIVE\drivers\aswSnx.sys [x] S1 aswSP;aswSP;g:\windows\system32\drivers\aswSP.sys;g:\windows\SYSNATIVE\drivers\aswSP.sys [x] S2 AMD External Events Utility;AMD External Events Utility;g:\windows\system32\atiesrxx.exe;g:\windows\SYSNATIVE\atiesrxx.exe [x] S2 aswHwid;avast! HardwareID;g:\windows\system32\drivers\aswHwid.sys;g:\windows\SYSNATIVE\drivers\aswHwid.sys [x] S2 aswMonFlt;aswMonFlt;g:\windows\system32\drivers\aswMonFlt.sys;g:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 UMVPFSrv;UMVPFSrv;g:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;g:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;g:\windows\system32\drivers\AtihdW76.sys;g:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;g:\windows\system32\drivers\LGBusEnum.sys;g:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x] S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;g:\windows\system32\DRIVERS\LGSHidFilt.Sys;g:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x] S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;g:\windows\system32\drivers\LGVirHid.sys;g:\windows\SYSNATIVE\drivers\LGVirHid.sys [x] S3 LVUVC64;Logitech Webcam 120(UVC);g:\windows\system32\DRIVERS\lvuvc64.sys;g:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;g:\windows\system32\DRIVERS\Rt64win7.sys;g:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2015-04-05 g:\windows\Tasks\GoogleUpdateTaskMachineCore.job - g:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15 15:32] . 2015-04-05 g:\windows\Tasks\GoogleUpdateTaskMachineUA.job - g:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15 15:32] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2014-07-15 06:28 634872 ----a-w- g:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Launch LCore"="g:\program files\Logitech Gaming Software\LCore.exe" [2014-07-28 10801944] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = g:\windows\system32\blank.htm mLocal Page = g:\windows\SysWOW64\blank.htm IE: Free YouTube to MP3 Converter - g:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm IE: Nach Microsoft E&xel exportieren - g:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.0.1 0.0.0.0 FF - ProfilePath - g:\users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start AddRemove-Glyph Archeage - g:\program files (x86)\Glyph\GlyphClient.exe AddRemove-{DDEAE484-D5FB-49CB-BD47-9512E8ACCA65}_is1 - g:\users\mse13ssd\Desktop\SciLor's Grooveshark.com Downloader\SciLor's grooveshark(tm).com Downloader\unins000.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-3243151774-2580435505-251407729-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] @Allowed: (Read) (RestrictedCode) "??"=hex:68,4b,29,37,4b,5c,4a,61,7c,26,e4,9e,c9,7c,95,7f,e2,70,84,b1,dd,0c,5d, 6a,eb,18,0b,04,fb,b2,7f,1d,ec,62,0f,d4,49,95,2a,59,64,6e,68,ba,1e,c7,4a,ed,\ "??"=hex:23,25,64,46,71,6e,29,53,78,10,63,87,6d,b7,18,a6 . [HKEY_USERS\S-1-5-21-3243151774-2580435505-251407729-1001\Software\SecuROM\License information*] "datasecu"=hex:9d,0b,4f,33,80,34,ba,75,1a,06,4c,eb,99,ec,a4,2d,eb,60,70,f3,ff, d9,4e,91,85,01,2f,88,03,ef,a9,91,b6,36,fd,c0,a3,1d,36,4d,88,b8,8f,5b,0e,3a,\ "rkeysecu"=hex:33,cd,9a,d6,e9,4d,7b,53,58,90,40,9b,f8,82,34,9f . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2015-04-05 15:10:54 ComboFix-quarantined-files.txt 2015-04-05 13:10 . Vor Suchlauf: 9 Verzeichnis(se), 24.165.081.088 Bytes frei Nach Suchlauf: 13 Verzeichnis(se), 26.069.192.704 Bytes frei . - - End Of File - - CD247D1AF0BBA8CE1711B6CAB0FC58E0 A36C5E4F47E84449FF07ED3517B43A31 Geändert von MSE XIII (05.04.2015 um 14:17 Uhr) |
05.04.2015, 17:00 | #4 |
/// the machine /// TB-Ausbilder | Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
05.04.2015, 18:43 | #5 |
| Win 7: konnte ShopGlider Deals bis jetzt nicht entfernenCode:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 05.04.2015 Suchlauf-Zeit: 18:22:20 Logdatei: Malwarebytes.txt Administrator: Ja Version: 2.00.4.1028 Malware Datenbank: v2015.04.05.02 Rootkit Datenbank: v2015.03.31.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: mse13ssd Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 351386 Verstrichene Zeit: 5 Min, 1 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente erkannt) Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 0 (Keine schädliche Elemente erkannt) Registrierungswerte: 0 (Keine schädliche Elemente erkannt) Registrierungsdaten: 0 (Keine schädliche Elemente erkannt) Ordner: 0 (Keine schädliche Elemente erkannt) Dateien: 0 (Keine schädliche Elemente erkannt) Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) Code:
ATTFilter # AdwCleaner v4.200 - Bericht erstellt 05/04/2015 um 18:38:15 # Aktualisiert 29/03/2015 von Xplode # Datenbank : 2015-03-29.1 [Server] # Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64) # Benutzername : mse13ssd - MSE13SSD-PC # Gestarted von : G:\Users\mse13ssd\Desktop\adwcleaner_4.200.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik Datei Gelöscht : G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\Local Extension Settings\npnkeeiehehhefofiekoflfedgehcdhl Datei Gelöscht : G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\Local Storage\chrome-extension_jpfpebmajhhopeonhlcgidhclcccjcik_0.localstorage Datei Gelöscht : G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\Local Storage\chrome-extension_jpfpebmajhhopeonhlcgidhclcccjcik_0.localstorage-journal Datei Gelöscht : G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\databases\chrome-extension_jpfpebmajhhopeonhlcgidhclcccjcik_0 ***** [ Geplante Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Internetbrowser ] ***** -\\ Internet Explorer v11.0.9600.17689 -\\ Mozilla Firefox v36.0 (x86 de) -\\ Google Chrome v -\\ Chromium v [G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\Secure Preferences] - Gelöscht [Extension] : jpfpebmajhhopeonhlcgidhclcccjcik ************************* AdwCleaner[R0].txt - [4105 Bytes] - [05/04/2015 03:46:08] AdwCleaner[R1].txt - [1819 Bytes] - [05/04/2015 18:37:27] AdwCleaner[S0].txt - [4067 Bytes] - [05/04/2015 03:47:41] AdwCleaner[S1].txt - [1739 Bytes] - [05/04/2015 18:38:15] ########## EOF - G:\AdwCleaner\AdwCleaner[S1].txt - [1798 Bytes] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.5.1 (04.02.2015:1) OS: Windows 7 Home Premium x64 Ran by mse13ssd on 05.04.2015 at 19:33:40,14 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{691B33B0-B86E-47F3-81C7-56E4FE3B929C} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{691B33B0-B86E-47F3-81C7-56E4FE3B929C} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{691B33B0-B86E-47F3-81C7-56E4FE3B929C} ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 05.04.2015 at 19:36:06,44 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Ran by mse13ssd (administrator) on MSE13SSD-PC on 05-04-2015 19:37:00 Running from G:\Users\mse13ssd\Desktop Loaded Profiles: mse13ssd (Available profiles: mse13ssd) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) G:\Windows\System32\atiesrxx.exe (Logitech Inc.) G:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (AMD) G:\Windows\System32\atieclxx.exe (AVAST Software) G:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) G:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) G:\Program Files\Bonjour\mDNSResponder.exe (Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe (Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe (Logitech Inc.) G:\Program Files\Logitech Gaming Software\LCore.exe (Microsoft Corporation) G:\Program Files\Windows Sidebar\sidebar.exe (AVAST Software) G:\Program Files\AVAST Software\Avast\avastui.exe () G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Advanced Micro Devices Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Launch LCore] => G:\Program Files\Logitech Gaming Software\LCore.exe [10801944 2014-07-28] (Logitech Inc.) HKLM-x32\...\Run: [AvastUI.exe] => G:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software) HKLM-x32\...\Run: [DivXMediaServer] => G:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [StartCCC] => G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Raptr] => G:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-03-25] (Raptr, Inc) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => G:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-3243151774-2580435505-251407729-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland ? mit Hotmail Nachfolger Outlook und Messenger Skype HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-15] (AVAST Software) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-26] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-15] (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-26] (Oracle Corporation) Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - G:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll [2014-10-10] (pdfforge GmbH) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0 FireFox: ======== FF ProfilePath: G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default FF Plugin: @adobe.com/FlashPlayer -> G:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-15] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> G:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-15] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> G:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2012-04-05] () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> G:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-26] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-26] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> G:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.) FF Plugin-x32: Adobe Reader -> G:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Extension: Download videos and MP3s from YouTube - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-11-21] FF Extension: Adblock Plus - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-09] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - G:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - G:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-17] FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension FF Extension: PDF Architect 2 Creator - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2014-12-09] FF HKU\S-1-5-21-3243151774-2580435505-251407729-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff FF Extension: Download videos and MP3s from YouTube - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-11-21] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Profile: G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-09] CHR Extension: (Google Docs) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-09] CHR Extension: (Google Drive) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-09] CHR Extension: (Google Voice Search Hotword (Beta)) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-09] CHR Extension: (YouTube) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-09] CHR Extension: (Google Search) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-09] CHR Extension: (Google Sheets) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-09] CHR Extension: (Google Wallet) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-09] CHR Extension: (Gmail) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-09] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - G:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-15] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; G:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-15] (AVAST Software) S2 PDF Architect 2 Creator; G:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH) S3 SandraAgentSrv; G:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3c\RpcAgentSrv.exe [73712 2014-09-19] (SiSoftware) [File not signed] R2 WinDefend; G:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; G:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 aswHwid; G:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-15] () R2 aswMonFlt; G:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-15] (AVAST Software) R1 aswRdr; G:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-15] (AVAST Software) R0 aswRvrt; G:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-15] () R1 aswSnx; G:\Windows\system32\drivers\aswSnx.sys [1041168 2014-11-21] (AVAST Software) R1 aswSP; G:\Windows\system32\drivers\aswSP.sys [427360 2014-07-15] (AVAST Software) S2 aswStm; G:\Windows\system32\drivers\aswStm.sys [92008 2014-07-15] (AVAST Software) R0 aswVmm; G:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-15] () R3 LGSHidFilt; G:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) S3 catchme; \??\G:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-05 19:37 - 2015-04-05 19:37 - 00012050 _____ () G:\Users\mse13ssd\Desktop\FRST.txt 2015-04-05 19:36 - 2015-04-05 19:36 - 00001083 _____ () G:\Users\mse13ssd\Desktop\JRT.txt 2015-04-05 19:33 - 2015-04-05 19:33 - 00000207 _____ () G:\Windows\tweaking.com-regbackup-MSE13SSD-PC-Windows-7-Home-Premium-(64-bit).dat 2015-04-05 19:33 - 2015-04-05 19:33 - 00000000 ____D () G:\RegBackup 2015-04-05 18:40 - 2015-04-05 18:40 - 00001878 _____ () G:\Users\mse13ssd\Desktop\AdwCleaner[S1].txt 2015-04-05 18:35 - 2015-04-05 18:35 - 02690981 _____ (Thisisu) G:\Users\mse13ssd\Desktop\JRT.exe 2015-04-05 18:30 - 2015-04-05 18:30 - 00001212 _____ () G:\Users\mse13ssd\Desktop\Malwarebytes.txt 2015-04-05 15:10 - 2015-04-05 15:10 - 00011639 _____ () G:\ComboFix.txt 2015-04-05 15:03 - 2015-04-05 15:10 - 00000000 ____D () G:\Qoobox 2015-04-05 15:03 - 2015-04-05 15:09 - 00000000 ____D () G:\Windows\erdnt 2015-04-05 15:03 - 2011-06-26 08:45 - 00256000 _____ () G:\Windows\PEV.exe 2015-04-05 15:03 - 2010-11-07 19:20 - 00208896 _____ () G:\Windows\MBR.exe 2015-04-05 15:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) G:\Windows\NIRCMD.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) G:\Windows\SWREG.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) G:\Windows\SWSC.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00098816 _____ () G:\Windows\sed.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00080412 _____ () G:\Windows\grep.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00068096 _____ () G:\Windows\zip.exe 2015-04-05 15:01 - 2015-04-05 15:01 - 05617096 ____R (Swearware) G:\Users\mse13ssd\Desktop\ComboFix.exe 2015-04-05 13:19 - 2015-04-05 13:19 - 00279353 _____ () G:\Users\mse13ssd\Desktop\Gmer.txt 2015-04-05 13:10 - 2015-04-05 13:11 - 00380416 _____ () G:\Users\mse13ssd\Downloads\liqvrrec.exe 2015-04-05 13:02 - 2015-04-05 19:37 - 00000000 ____D () G:\FRST 2015-04-05 13:02 - 2015-04-05 13:03 - 00048734 _____ () G:\Users\mse13ssd\Downloads\FRST.txt 2015-04-05 13:02 - 2015-04-05 13:03 - 00024876 _____ () G:\Users\mse13ssd\Downloads\Addition.txt 2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Downloads\FRST64 (1).exe 2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Desktop\FRST64.exe 2015-04-05 12:59 - 2015-04-05 12:59 - 00000478 _____ () G:\Users\mse13ssd\Downloads\defogger_disable.log 2015-04-05 12:59 - 2015-04-05 12:59 - 00000000 _____ () G:\Users\mse13ssd\defogger_reenable 2015-04-05 12:57 - 2015-04-05 12:57 - 00050477 _____ () G:\Users\mse13ssd\Downloads\Defogger.exe 2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (2).exe 2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (1).exe 2015-04-05 03:38 - 2015-04-05 18:38 - 00000000 ____D () G:\AdwCleaner 2015-04-05 03:37 - 2015-04-05 03:38 - 02208768 _____ () G:\Users\mse13ssd\Desktop\adwcleaner_4.200.exe 2015-03-31 05:26 - 2015-03-31 05:26 - 00008930 _____ () G:\Users\mse13ssd\Downloads\smime (1).p7s 2015-03-31 02:41 - 2015-03-31 02:41 - 00000069 _____ () G:\Users\mse13ssd\Desktop\BADLOGIC (German Fandub) - YouTube.url 2015-03-28 00:47 - 2015-03-28 00:47 - 00012288 _____ () G:\Users\mse13ssd\Downloads\Qual-Fraktal.xls 2015-03-27 07:14 - 2015-03-27 07:14 - 00000000 ____D () G:\Users\mse13ssd\Desktop\SciLor's Grooveshark.com Downloader 2015-03-26 21:20 - 2015-03-26 21:20 - 671367548 _____ () G:\Windows\MEMORY.DMP 2015-03-26 21:20 - 2015-03-26 21:20 - 00274624 _____ () G:\Windows\Minidump\032615-29718-01.dmp 2015-03-25 04:31 - 2015-03-25 04:31 - 00002123 _____ () G:\Users\Public\Desktop\CONTRACT J.A.C.K. .lnk 2015-03-25 04:05 - 2015-03-25 04:05 - 00000000 ____D () G:\Program Files (x86)\Sierra 2015-03-25 04:04 - 2015-03-25 04:04 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra 2015-03-25 04:00 - 2003-06-26 10:45 - 00499712 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcp71.dll 2015-03-25 04:00 - 2003-06-26 10:45 - 00348160 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcr71.dll 2015-03-25 04:00 - 2003-03-19 07:20 - 01060864 ____N (Microsoft Corporation) G:\Windows\SysWOW64\mfc71.dll 2015-03-22 18:27 - 2015-03-22 18:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in 2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files\Microsoft Silverlight 2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files (x86)\Microsoft Silverlight 2015-03-21 10:33 - 2015-03-21 10:33 - 13087456 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\Silverlight_x64.exe 2015-03-18 17:29 - 2015-03-18 17:29 - 00002023 _____ () G:\Users\mse13ssd\Desktop\Windows Phone-Desktopanwendung.lnk 2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Phone 2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\Program Files (x86)\Windows Phone 2015-03-18 17:25 - 2015-03-18 17:25 - 06745792 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\WindowsPhone.exe 2015-03-18 17:25 - 2015-03-18 17:25 - 00000000 ____D () G:\ProgramData\Applications 2015-03-16 19:19 - 2015-03-16 19:19 - 00001535 _____ () G:\Users\mse13ssd\Free YouTube to MP3 Converter.lnk 2015-03-15 17:32 - 2015-04-05 19:37 - 00001114 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-03-15 17:32 - 2015-04-05 18:39 - 00001110 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-15 17:32 - 2015-03-15 17:32 - 00004110 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-03-15 17:32 - 2015-03-15 17:32 - 00003858 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-03-15 17:32 - 2015-03-15 17:32 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2015-03-15 17:31 - 2015-03-15 17:31 - 00880208 _____ (Google Inc.) G:\Users\mse13ssd\Downloads\GoogleEarthSetup.exe 2015-03-14 07:06 - 2015-03-14 07:33 - 82044588 _____ () G:\Users\mse13ssd\Downloads\ES-X_DE.rar.crdownload 2015-03-12 09:28 - 2015-02-03 05:34 - 05554104 _____ (Microsoft Corporation) G:\Windows\system32\ntoskrnl.exe 2015-03-12 09:28 - 2015-02-03 05:34 - 00693176 _____ (Microsoft Corporation) G:\Windows\system32\winload.efi 2015-03-12 09:28 - 2015-02-03 05:34 - 00094656 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\mountmgr.sys 2015-03-12 09:28 - 2015-02-03 05:33 - 00616360 _____ (Microsoft Corporation) G:\Windows\system32\winresume.efi 2015-03-12 09:28 - 2015-02-03 05:31 - 14632960 _____ (Microsoft Corporation) G:\Windows\system32\wmp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 04121600 _____ (Microsoft Corporation) G:\Windows\system32\mf.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 01574400 _____ (Microsoft Corporation) G:\Windows\system32\quartz.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00782848 _____ (Microsoft Corporation) G:\Windows\system32\wmdrmsdk.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00641024 _____ (Microsoft Corporation) G:\Windows\system32\msscp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00503808 _____ (Microsoft Corporation) G:\Windows\system32\srcore.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00500224 _____ (Microsoft Corporation) G:\Windows\system32\AUDIOKSE.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00432128 _____ (Microsoft Corporation) G:\Windows\system32\mfplat.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00371712 _____ (Microsoft Corporation) G:\Windows\system32\qdvd.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00325632 _____ (Microsoft Corporation) G:\Windows\system32\msnetobj.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00229376 _____ (Microsoft Corporation) G:\Windows\system32\wintrust.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00206848 _____ (Microsoft Corporation) G:\Windows\system32\mfps.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00188416 _____ (Microsoft Corporation) G:\Windows\system32\pcasvc.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00063488 _____ (Microsoft Corporation) G:\Windows\system32\setbcdlocale.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00050176 _____ (Microsoft Corporation) G:\Windows\system32\srclient.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00037376 _____ (Microsoft Corporation) G:\Windows\system32\pcadm.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\msmmsp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\spwmp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\msdxm.ocx 2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\dxmasf.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 12625920 _____ (Microsoft Corporation) G:\Windows\system32\wmploc.DLL 2015-03-12 09:28 - 2015-02-03 05:30 - 01480192 _____ (Microsoft Corporation) G:\Windows\system32\crypt32.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 01202176 _____ (Microsoft Corporation) G:\Windows\system32\drmv2clt.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 01069056 _____ (Microsoft Corporation) G:\Windows\system32\cryptui.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00842240 _____ (Microsoft Corporation) G:\Windows\system32\blackbox.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00680960 _____ (Microsoft Corporation) G:\Windows\system32\audiosrv.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00631808 _____ (Microsoft Corporation) G:\Windows\system32\evr.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00497664 _____ (Microsoft Corporation) G:\Windows\system32\drmmgrtn.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00440832 _____ (Microsoft Corporation) G:\Windows\system32\AudioEng.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00296960 _____ (Microsoft Corporation) G:\Windows\system32\rstrui.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00296448 _____ (Microsoft Corporation) G:\Windows\system32\AudioSes.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00284672 _____ (Microsoft Corporation) G:\Windows\system32\EncDump.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00187904 _____ (Microsoft Corporation) G:\Windows\system32\cryptsvc.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00146944 _____ (Microsoft Corporation) G:\Windows\system32\appidpolicyconverter.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00140288 _____ (Microsoft Corporation) G:\Windows\system32\cryptnet.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00126464 _____ (Microsoft Corporation) G:\Windows\system32\audiodg.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00112640 _____ (Microsoft Corporation) G:\Windows\system32\smss.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00082432 _____ (Microsoft Corporation) G:\Windows\system32\cryptsp.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00058880 _____ (Microsoft Corporation) G:\Windows\system32\appidapi.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00055808 _____ (Microsoft Corporation) G:\Windows\system32\rrinstaller.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00043520 _____ (Microsoft Corporation) G:\Windows\system32\csrsrv.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00032256 _____ (Microsoft Corporation) G:\Windows\system32\appidsvc.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00024576 _____ (Microsoft Corporation) G:\Windows\system32\mfpmp.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00017920 _____ (Microsoft Corporation) G:\Windows\system32\appidcertstorecheck.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\pcawrk.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\pcalua.exe 2015-03-12 09:28 - 2015-02-03 05:29 - 00008704 _____ (Microsoft Corporation) G:\Windows\system32\pcaevts.dll 2015-03-12 09:28 - 2015-02-03 05:28 - 00006656 _____ (Microsoft Corporation) G:\Windows\system32\apisetschema.dll 2015-03-12 09:28 - 2015-02-03 05:28 - 00002048 _____ (Microsoft Corporation) G:\Windows\system32\mferror.dll 2015-03-12 09:28 - 2015-02-03 05:19 - 00663552 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\PEAuth.sys 2015-03-12 09:28 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntkrnlpa.exe 2015-03-12 09:28 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntoskrnl.exe 2015-03-12 09:28 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mf.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) G:\Windows\SysWOW64\quartz.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) G:\Windows\SysWOW64\crypt32.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptui.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmv2clt.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\blackbox.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmdrmsdk.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) G:\Windows\SysWOW64\qdvd.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msscp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\evr.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AUDIOKSE.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmmgrtn.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioEng.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfplat.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msnetobj.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioSes.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wintrust.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsvc.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptnet.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfps.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) G:\Windows\SysWOW64\appidapi.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) G:\Windows\SysWOW64\srclient.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\spwmp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msdxm.ocx 2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxmasf.dll 2015-03-12 09:28 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmploc.DLL 2015-03-12 09:28 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\rrinstaller.exe 2015-03-12 09:28 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfpmp.exe 2015-03-12 09:28 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mferror.dll 2015-03-12 09:28 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\apisetschema.dll 2015-03-12 09:28 - 2015-02-03 04:32 - 00061440 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\appid.sys 2015-03-12 09:28 - 2014-11-01 00:24 - 00619056 _____ (Microsoft Corporation) G:\Windows\system32\winload.exe 2015-03-12 09:28 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) G:\Windows\system32\winresume.exe 2015-03-12 09:28 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) G:\Windows\system32\ci.dll 2015-03-12 09:27 - 2015-03-06 07:56 - 00155576 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecpkg.sys 2015-03-12 09:27 - 2015-03-06 07:56 - 00095680 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecdd.sys 2015-03-12 09:27 - 2015-03-06 07:42 - 01461760 _____ (Microsoft Corporation) G:\Windows\system32\lsasrv.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00728064 _____ (Microsoft Corporation) G:\Windows\system32\kerberos.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00341504 _____ (Microsoft Corporation) G:\Windows\system32\schannel.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00314880 _____ (Microsoft Corporation) G:\Windows\system32\msv1_0.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00309760 _____ (Microsoft Corporation) G:\Windows\system32\ncrypt.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00210944 _____ (Microsoft Corporation) G:\Windows\system32\wdigest.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00136192 _____ (Microsoft Corporation) G:\Windows\system32\sspicli.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00086528 _____ (Microsoft Corporation) G:\Windows\system32\TSpkg.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00029184 _____ (Microsoft Corporation) G:\Windows\system32\sspisrv.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00028160 _____ (Microsoft Corporation) G:\Windows\system32\secur32.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00022016 _____ (Microsoft Corporation) G:\Windows\system32\credssp.dll 2015-03-12 09:27 - 2015-03-06 07:41 - 00064000 _____ (Microsoft Corporation) G:\Windows\system32\auditpol.exe 2015-03-12 09:27 - 2015-03-06 07:41 - 00031232 _____ (Microsoft Corporation) G:\Windows\system32\lsass.exe 2015-03-12 09:27 - 2015-03-06 07:39 - 00060416 _____ (Microsoft Corporation) G:\Windows\system32\msobjs.dll 2015-03-12 09:27 - 2015-03-06 07:38 - 00146432 _____ (Microsoft Corporation) G:\Windows\system32\msaudite.dll 2015-03-12 09:27 - 2015-03-06 07:36 - 00686080 _____ (Microsoft Corporation) G:\Windows\system32\adtschema.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) G:\Windows\SysWOW64\kerberos.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msv1_0.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) G:\Windows\SysWOW64\schannel.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ncrypt.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wdigest.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) G:\Windows\SysWOW64\TSpkg.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\secur32.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\credssp.dll 2015-03-12 09:27 - 2015-03-06 07:09 - 00096768 _____ (Microsoft Corporation) G:\Windows\SysWOW64\sspicli.dll 2015-03-12 09:27 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\auditpol.exe 2015-03-12 09:27 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msaudite.dll 2015-03-12 09:27 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msobjs.dll 2015-03-12 09:27 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) G:\Windows\SysWOW64\adtschema.dll 2015-03-12 09:27 - 2015-02-24 05:15 - 00389800 _____ (Microsoft Corporation) G:\Windows\system32\iedkcs32.dll 2015-03-12 09:27 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iedkcs32.dll 2015-03-12 09:27 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.dll 2015-03-12 09:27 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieframe.dll 2015-03-12 09:27 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtmsft.dll 2015-03-12 09:27 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtrans.dll 2015-03-12 09:27 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.dll 2015-03-12 09:27 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) G:\Windows\system32\mshtmled.dll 2015-03-12 09:27 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmled.dll 2015-03-12 09:27 - 2015-02-20 06:41 - 00041984 _____ (Microsoft Corporation) G:\Windows\system32\lpk.dll 2015-03-12 09:27 - 2015-02-20 06:40 - 00100864 _____ (Microsoft Corporation) G:\Windows\system32\fontsub.dll 2015-03-12 09:27 - 2015-02-20 06:40 - 00046080 _____ (Adobe Systems) G:\Windows\system32\atmlib.dll 2015-03-12 09:27 - 2015-02-20 06:40 - 00014336 _____ (Microsoft Corporation) G:\Windows\system32\dciman32.dll 2015-03-12 09:27 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\fontsub.dll 2015-03-12 09:27 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) G:\Windows\SysWOW64\atmlib.dll 2015-03-12 09:27 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dciman32.dll 2015-03-12 09:27 - 2015-02-20 06:12 - 00025600 _____ (Microsoft Corporation) G:\Windows\SysWOW64\lpk.dll 2015-03-12 09:27 - 2015-02-20 05:29 - 00372224 _____ (Adobe Systems Incorporated) G:\Windows\system32\atmfd.dll 2015-03-12 09:27 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\atmfd.dll 2015-03-12 09:27 - 2015-02-20 05:06 - 02724864 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.tlb 2015-03-12 09:27 - 2015-02-20 05:05 - 00004096 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollectorres.dll 2015-03-12 09:27 - 2015-02-20 04:50 - 00066560 _____ (Microsoft Corporation) G:\Windows\system32\iesetup.dll 2015-03-12 09:27 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) G:\Windows\system32\vbscript.dll 2015-03-12 09:27 - 2015-02-20 04:49 - 00048640 _____ (Microsoft Corporation) G:\Windows\system32\ieetwproxystub.dll 2015-03-12 09:27 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) G:\Windows\system32\iertutil.dll 2015-03-12 09:27 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) G:\Windows\system32\MshtmlDac.dll 2015-03-12 09:27 - 2015-02-20 04:41 - 00054784 _____ (Microsoft Corporation) G:\Windows\system32\jsproxy.dll 2015-03-12 09:27 - 2015-02-20 04:40 - 00034304 _____ (Microsoft Corporation) G:\Windows\system32\iernonce.dll 2015-03-12 09:27 - 2015-02-20 04:36 - 00633856 _____ (Microsoft Corporation) G:\Windows\system32\ieui.dll 2015-03-12 09:27 - 2015-02-20 04:35 - 00144384 _____ (Microsoft Corporation) G:\Windows\system32\ieUnatt.exe 2015-03-12 09:27 - 2015-02-20 04:35 - 00114688 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollector.exe 2015-03-12 09:27 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) G:\Windows\system32\jscript9diag.dll 2015-03-12 09:27 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) G:\Windows\system32\jscript9.dll 2015-03-12 09:27 - 2015-02-20 04:26 - 00968704 _____ (Microsoft Corporation) G:\Windows\system32\MsSpellCheckingFacility.exe 2015-03-12 09:27 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.tlb 2015-03-12 09:27 - 2015-02-20 04:22 - 00490496 _____ (Microsoft Corporation) G:\Windows\system32\dxtmsft.dll 2015-03-12 09:27 - 2015-02-20 04:13 - 00077824 _____ (Microsoft Corporation) G:\Windows\system32\JavaScriptCollectionAgent.dll 2015-03-12 09:27 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) G:\Windows\SysWOW64\vbscript.dll 2015-03-12 09:27 - 2015-02-20 04:08 - 00199680 _____ (Microsoft Corporation) G:\Windows\system32\msrating.dll 2015-03-12 09:27 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iesetup.dll 2015-03-12 09:27 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieetwproxystub.dll 2015-03-12 09:27 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) G:\Windows\SysWOW64\MshtmlDac.dll 2015-03-12 09:27 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) G:\Windows\system32\dxtrans.dll 2015-03-12 09:27 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iertutil.dll 2015-03-12 09:27 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jsproxy.dll 2015-03-12 09:27 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iernonce.dll 2015-03-12 09:27 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieui.dll 2015-03-12 09:27 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9diag.dll 2015-03-12 09:27 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieUnatt.exe 2015-03-12 09:27 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) G:\Windows\system32\msfeeds.dll 2015-03-12 09:27 - 2015-02-20 03:49 - 00718848 _____ (Microsoft Corporation) G:\Windows\system32\ie4uinit.exe 2015-03-12 09:27 - 2015-02-20 03:47 - 01359360 _____ (Microsoft Corporation) G:\Windows\system32\mshtmlmedia.dll 2015-03-12 09:27 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) G:\Windows\system32\inetcpl.cpl 2015-03-12 09:27 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) G:\Windows\system32\ieframe.dll 2015-03-12 09:27 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-03-12 09:27 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msrating.dll 2015-03-12 09:27 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9.dll 2015-03-12 09:27 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) G:\Windows\system32\wininet.dll 2015-03-12 09:27 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) G:\Windows\SysWOW64\inetcpl.cpl 2015-03-12 09:27 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msfeeds.dll 2015-03-12 09:27 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmlmedia.dll 2015-03-12 09:27 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) G:\Windows\system32\urlmon.dll 2015-03-12 09:27 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) G:\Windows\system32\ieapfltr.dll 2015-03-12 09:27 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wininet.dll 2015-03-12 09:27 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) G:\Windows\SysWOW64\urlmon.dll 2015-03-12 09:27 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieapfltr.dll 2015-03-12 09:27 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) G:\Windows\SysWOW64\shell32.dll 2015-03-12 09:27 - 2015-02-13 07:22 - 14177280 _____ (Microsoft Corporation) G:\Windows\system32\shell32.dll 2015-03-12 09:27 - 2015-02-03 05:31 - 01424896 _____ (Microsoft Corporation) G:\Windows\system32\WindowsCodecs.dll 2015-03-12 09:27 - 2015-02-03 05:31 - 00215552 _____ (Microsoft Corporation) G:\Windows\system32\ubpm.dll 2015-03-12 09:27 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WindowsCodecs.dll 2015-03-12 09:27 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ubpm.dll 2015-03-12 09:27 - 2015-01-31 05:48 - 03179520 _____ (Microsoft Corporation) G:\Windows\system32\rdpcorets.dll 2015-03-12 09:27 - 2015-01-31 05:48 - 00016384 _____ (Microsoft Corporation) G:\Windows\system32\RdpGroupPolicyExtension.dll 2015-03-12 09:27 - 2015-01-31 01:56 - 00459336 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\cng.sys 2015-03-12 09:27 - 2015-01-31 01:56 - 00243200 _____ (Microsoft Corporation) G:\Windows\system32\rdpudd.dll 2015-03-12 09:27 - 2015-01-17 04:48 - 01067520 _____ (Microsoft Corporation) G:\Windows\system32\msctf.dll 2015-03-12 09:27 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msctf.dll 2015-03-12 09:26 - 2015-02-26 05:25 - 03204096 _____ (Microsoft Corporation) G:\Windows\system32\win32k.sys 2015-03-12 09:26 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) G:\Windows\system32\WMPhoto.dll 2015-03-12 09:26 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WMPhoto.dll 2015-03-10 01:20 - 2015-03-10 01:20 - 00001002 _____ () G:\Users\mse13ssd\Downloads\BAHN_Fahrplan_20150609.ics 2015-03-09 11:16 - 2015-03-09 11:56 - 124202474 _____ () G:\Users\mse13ssd\Downloads\#0325#.rar 2015-03-08 09:43 - 2015-03-08 09:43 - 01230365 _____ () G:\Users\mse13ssd\Downloads\2 (1).wmv 2015-03-08 09:43 - 2015-03-08 09:43 - 01222357 _____ () G:\Users\mse13ssd\Downloads\3.wmv 2015-03-06 16:14 - 2015-03-06 16:51 - 111138743 _____ () G:\Users\mse13ssd\Downloads\julins2014.rar ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-05 18:47 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-05 18:47 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-05 18:45 - 2009-07-14 19:58 - 00700986 _____ () G:\Windows\system32\perfh007.dat 2015-04-05 18:45 - 2009-07-14 19:58 - 00149886 _____ () G:\Windows\system32\perfc007.dat 2015-04-05 18:45 - 2009-07-14 07:13 - 01619284 _____ () G:\Windows\system32\PerfStringBackup.INI 2015-04-05 18:43 - 2014-05-17 10:22 - 01378372 _____ () G:\Windows\WindowsUpdate.log 2015-04-05 18:40 - 2014-07-13 00:21 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Raptr 2015-04-05 18:39 - 2014-05-17 22:03 - 00000000 _____ () G:\Windows\system32\Drivers\lvuvc.hs 2015-04-05 18:39 - 2014-05-17 15:20 - 00033022 _____ () G:\Windows\PFRO.log 2015-04-05 18:39 - 2009-07-14 07:08 - 00000006 ____H () G:\Windows\Tasks\SA.DAT 2015-04-05 18:39 - 2009-07-14 06:51 - 00055579 _____ () G:\Windows\setupact.log 2015-04-05 18:19 - 2015-03-05 14:19 - 00129752 _____ (Malwarebytes Corporation) G:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-04-05 15:10 - 2009-07-14 05:20 - 00000000 __RHD () G:\Users\Default 2015-04-05 15:09 - 2009-07-14 04:34 - 00000215 _____ () G:\Windows\system.ini 2015-04-05 13:19 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\NDF 2015-04-05 13:06 - 2014-05-17 22:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Skype 2015-04-05 12:59 - 2014-05-17 11:54 - 00000000 ____D () G:\Users\mse13ssd 2015-04-05 03:26 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\Web 2015-04-05 02:39 - 2014-05-17 15:57 - 00004182 _____ () G:\Windows\System32\Tasks\avast! Emergency Update 2015-04-04 14:30 - 2014-05-17 20:13 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\TS3Client 2015-04-02 01:34 - 2009-07-14 07:32 - 00000000 ____D () G:\Windows\system32\FxsTmp 2015-03-30 17:36 - 2015-02-28 05:38 - 00000000 ____D () G:\Users\mse13ssd\Desktop\aufgeräumt 2015-03-30 08:10 - 2014-11-01 08:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\25372 2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\DivX 2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX 2015-03-30 04:33 - 2014-08-24 02:00 - 00000000 ____D () G:\ProgramData\DivX 2015-03-30 04:33 - 2014-05-17 15:57 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast 2015-03-30 04:33 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\AppCompat 2015-03-30 04:32 - 2014-08-24 02:01 - 00000000 ____D () G:\Program Files\DivX 2015-03-30 04:32 - 2014-08-24 02:00 - 00000000 ____D () G:\Program Files (x86)\DivX 2015-03-30 04:32 - 2014-06-18 17:31 - 00000000 ____D () G:\Program Files (x86)\Microsoft Office 2015-03-30 04:32 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\registration 2015-03-30 03:27 - 2009-07-14 20:18 - 00000000 ___RD () G:\Users\Public\Recorded TV 2015-03-26 21:20 - 2014-10-12 12:01 - 00000000 ____D () G:\Windows\Minidump 2015-03-26 18:51 - 2014-07-13 00:21 - 00000000 ____D () G:\Program Files (x86)\Raptr 2015-03-26 09:13 - 2014-06-18 17:31 - 00000000 ____D () G:\ProgramData\Microsoft Help 2015-03-22 18:29 - 2014-05-17 12:40 - 00070368 _____ () G:\Users\mse13ssd\AppData\Local\GDIPFONTCACHEV1.DAT 2015-03-22 18:29 - 2009-07-14 06:45 - 00307752 _____ () G:\Windows\system32\FNTCACHE.DAT 2015-03-22 18:25 - 2014-06-18 17:32 - 00000000 ____D () G:\Program Files (x86)\Microsoft Works 2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Google 2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Program Files (x86)\Google 2015-03-15 14:09 - 2014-08-24 13:49 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Adobe 2015-03-15 14:09 - 2014-05-17 15:53 - 00778928 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerApp.exe 2015-03-15 14:09 - 2014-05-17 15:53 - 00142512 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-03-15 05:05 - 2014-06-21 18:28 - 00000000 ____D () G:\Program Files (x86)\Steam 2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Glyph 2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glyph 2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Program Files (x86)\Glyph 2015-03-13 10:32 - 2009-07-14 07:09 - 00000000 ____D () G:\Windows\System32\Tasks\WPD 2015-03-12 12:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\rescache 2015-03-12 09:37 - 2015-02-28 09:01 - 00000000 ___RD () G:\Users\mse13ssd\Virtual Machines 2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\SysWOW64\Dism 2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\Dism 2015-03-12 09:31 - 2014-05-17 20:36 - 00000000 ____D () G:\Windows\system32\MRT 2015-03-12 09:29 - 2014-05-17 20:36 - 122905848 _____ (Microsoft Corporation) G:\Windows\system32\MRT.exe 2015-03-06 13:47 - 2014-10-13 17:23 - 00000000 ___RD () G:\Program Files (x86)\Skype 2015-03-06 13:47 - 2014-05-17 22:15 - 00000000 ____D () G:\ProgramData\Skype ==================== Files in the root of some directories ======= 2014-10-02 16:29 - 2015-02-28 12:40 - 14286848 _____ () G:\Users\mse13ssd\AppData\Roaming\Sandra.mdb 2015-01-23 13:40 - 2015-01-23 13:40 - 0003584 _____ () G:\Users\mse13ssd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-01-01 14:58 - 2015-01-01 14:58 - 0007605 _____ () G:\Users\mse13ssd\AppData\Local\Resmon.ResmonCfg Some content of TEMP: ==================== G:\Users\mse13ssd\AppData\Local\Temp\Quarantine.exe G:\Users\mse13ssd\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) G:\Windows\System32\winlogon.exe => File is digitally signed G:\Windows\System32\wininit.exe => File is digitally signed G:\Windows\SysWOW64\wininit.exe => File is digitally signed G:\Windows\explorer.exe => File is digitally signed G:\Windows\SysWOW64\explorer.exe => File is digitally signed G:\Windows\System32\svchost.exe => File is digitally signed G:\Windows\SysWOW64\svchost.exe => File is digitally signed G:\Windows\System32\services.exe => File is digitally signed G:\Windows\System32\User32.dll => File is digitally signed G:\Windows\SysWOW64\User32.dll => File is digitally signed G:\Windows\System32\userinit.exe => File is digitally signed G:\Windows\SysWOW64\userinit.exe => File is digitally signed G:\Windows\System32\rpcss.dll => File is digitally signed G:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-04-04 00:45 ==================== End Of Log ============================ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Ran by mse13ssd (administrator) on MSE13SSD-PC on 05-04-2015 19:37:00 Running from G:\Users\mse13ssd\Desktop Loaded Profiles: mse13ssd (Available profiles: mse13ssd) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) G:\Windows\System32\atiesrxx.exe (Logitech Inc.) G:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (AMD) G:\Windows\System32\atieclxx.exe (AVAST Software) G:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) G:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) G:\Program Files\Bonjour\mDNSResponder.exe (Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe (Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe (Logitech Inc.) G:\Program Files\Logitech Gaming Software\LCore.exe (Microsoft Corporation) G:\Program Files\Windows Sidebar\sidebar.exe (AVAST Software) G:\Program Files\AVAST Software\Avast\avastui.exe () G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Advanced Micro Devices Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Launch LCore] => G:\Program Files\Logitech Gaming Software\LCore.exe [10801944 2014-07-28] (Logitech Inc.) HKLM-x32\...\Run: [AvastUI.exe] => G:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software) HKLM-x32\...\Run: [DivXMediaServer] => G:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [StartCCC] => G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Raptr] => G:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-03-25] (Raptr, Inc) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => G:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-3243151774-2580435505-251407729-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland ? mit Hotmail Nachfolger Outlook und Messenger Skype HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-15] (AVAST Software) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-26] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-15] (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-26] (Oracle Corporation) Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - G:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll [2014-10-10] (pdfforge GmbH) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0 FireFox: ======== FF ProfilePath: G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default FF Plugin: @adobe.com/FlashPlayer -> G:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-15] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> G:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-15] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> G:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2012-04-05] () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> G:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-26] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-26] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> G:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.) FF Plugin-x32: Adobe Reader -> G:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Extension: Download videos and MP3s from YouTube - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-11-21] FF Extension: Adblock Plus - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-09] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - G:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - G:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-17] FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension FF Extension: PDF Architect 2 Creator - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2014-12-09] FF HKU\S-1-5-21-3243151774-2580435505-251407729-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff FF Extension: Download videos and MP3s from YouTube - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-11-21] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Profile: G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-09] CHR Extension: (Google Docs) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-09] CHR Extension: (Google Drive) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-09] CHR Extension: (Google Voice Search Hotword (Beta)) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-09] CHR Extension: (YouTube) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-09] CHR Extension: (Google Search) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-09] CHR Extension: (Google Sheets) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-09] CHR Extension: (Google Wallet) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-09] CHR Extension: (Gmail) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-09] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - G:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-15] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; G:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-15] (AVAST Software) S2 PDF Architect 2 Creator; G:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH) S3 SandraAgentSrv; G:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3c\RpcAgentSrv.exe [73712 2014-09-19] (SiSoftware) [File not signed] R2 WinDefend; G:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; G:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 aswHwid; G:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-15] () R2 aswMonFlt; G:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-15] (AVAST Software) R1 aswRdr; G:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-15] (AVAST Software) R0 aswRvrt; G:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-15] () R1 aswSnx; G:\Windows\system32\drivers\aswSnx.sys [1041168 2014-11-21] (AVAST Software) R1 aswSP; G:\Windows\system32\drivers\aswSP.sys [427360 2014-07-15] (AVAST Software) S2 aswStm; G:\Windows\system32\drivers\aswStm.sys [92008 2014-07-15] (AVAST Software) R0 aswVmm; G:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-15] () R3 LGSHidFilt; G:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) S3 catchme; \??\G:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-05 19:37 - 2015-04-05 19:37 - 00012050 _____ () G:\Users\mse13ssd\Desktop\FRST.txt 2015-04-05 19:36 - 2015-04-05 19:36 - 00001083 _____ () G:\Users\mse13ssd\Desktop\JRT.txt 2015-04-05 19:33 - 2015-04-05 19:33 - 00000207 _____ () G:\Windows\tweaking.com-regbackup-MSE13SSD-PC-Windows-7-Home-Premium-(64-bit).dat 2015-04-05 19:33 - 2015-04-05 19:33 - 00000000 ____D () G:\RegBackup 2015-04-05 18:40 - 2015-04-05 18:40 - 00001878 _____ () G:\Users\mse13ssd\Desktop\AdwCleaner[S1].txt 2015-04-05 18:35 - 2015-04-05 18:35 - 02690981 _____ (Thisisu) G:\Users\mse13ssd\Desktop\JRT.exe 2015-04-05 18:30 - 2015-04-05 18:30 - 00001212 _____ () G:\Users\mse13ssd\Desktop\Malwarebytes.txt 2015-04-05 15:10 - 2015-04-05 15:10 - 00011639 _____ () G:\ComboFix.txt 2015-04-05 15:03 - 2015-04-05 15:10 - 00000000 ____D () G:\Qoobox 2015-04-05 15:03 - 2015-04-05 15:09 - 00000000 ____D () G:\Windows\erdnt 2015-04-05 15:03 - 2011-06-26 08:45 - 00256000 _____ () G:\Windows\PEV.exe 2015-04-05 15:03 - 2010-11-07 19:20 - 00208896 _____ () G:\Windows\MBR.exe 2015-04-05 15:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) G:\Windows\NIRCMD.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) G:\Windows\SWREG.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) G:\Windows\SWSC.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00098816 _____ () G:\Windows\sed.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00080412 _____ () G:\Windows\grep.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00068096 _____ () G:\Windows\zip.exe 2015-04-05 15:01 - 2015-04-05 15:01 - 05617096 ____R (Swearware) G:\Users\mse13ssd\Desktop\ComboFix.exe 2015-04-05 13:19 - 2015-04-05 13:19 - 00279353 _____ () G:\Users\mse13ssd\Desktop\Gmer.txt 2015-04-05 13:10 - 2015-04-05 13:11 - 00380416 _____ () G:\Users\mse13ssd\Downloads\liqvrrec.exe 2015-04-05 13:02 - 2015-04-05 19:37 - 00000000 ____D () G:\FRST 2015-04-05 13:02 - 2015-04-05 13:03 - 00048734 _____ () G:\Users\mse13ssd\Downloads\FRST.txt 2015-04-05 13:02 - 2015-04-05 13:03 - 00024876 _____ () G:\Users\mse13ssd\Downloads\Addition.txt 2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Downloads\FRST64 (1).exe 2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Desktop\FRST64.exe 2015-04-05 12:59 - 2015-04-05 12:59 - 00000478 _____ () G:\Users\mse13ssd\Downloads\defogger_disable.log 2015-04-05 12:59 - 2015-04-05 12:59 - 00000000 _____ () G:\Users\mse13ssd\defogger_reenable 2015-04-05 12:57 - 2015-04-05 12:57 - 00050477 _____ () G:\Users\mse13ssd\Downloads\Defogger.exe 2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (2).exe 2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (1).exe 2015-04-05 03:38 - 2015-04-05 18:38 - 00000000 ____D () G:\AdwCleaner 2015-04-05 03:37 - 2015-04-05 03:38 - 02208768 _____ () G:\Users\mse13ssd\Desktop\adwcleaner_4.200.exe 2015-03-31 05:26 - 2015-03-31 05:26 - 00008930 _____ () G:\Users\mse13ssd\Downloads\smime (1).p7s 2015-03-31 02:41 - 2015-03-31 02:41 - 00000069 _____ () G:\Users\mse13ssd\Desktop\BADLOGIC (German Fandub) - YouTube.url 2015-03-28 00:47 - 2015-03-28 00:47 - 00012288 _____ () G:\Users\mse13ssd\Downloads\Qual-Fraktal.xls 2015-03-27 07:14 - 2015-03-27 07:14 - 00000000 ____D () G:\Users\mse13ssd\Desktop\SciLor's Grooveshark.com Downloader 2015-03-26 21:20 - 2015-03-26 21:20 - 671367548 _____ () G:\Windows\MEMORY.DMP 2015-03-26 21:20 - 2015-03-26 21:20 - 00274624 _____ () G:\Windows\Minidump\032615-29718-01.dmp 2015-03-25 04:31 - 2015-03-25 04:31 - 00002123 _____ () G:\Users\Public\Desktop\CONTRACT J.A.C.K. .lnk 2015-03-25 04:05 - 2015-03-25 04:05 - 00000000 ____D () G:\Program Files (x86)\Sierra 2015-03-25 04:04 - 2015-03-25 04:04 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra 2015-03-25 04:00 - 2003-06-26 10:45 - 00499712 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcp71.dll 2015-03-25 04:00 - 2003-06-26 10:45 - 00348160 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcr71.dll 2015-03-25 04:00 - 2003-03-19 07:20 - 01060864 ____N (Microsoft Corporation) G:\Windows\SysWOW64\mfc71.dll 2015-03-22 18:27 - 2015-03-22 18:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in 2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files\Microsoft Silverlight 2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files (x86)\Microsoft Silverlight 2015-03-21 10:33 - 2015-03-21 10:33 - 13087456 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\Silverlight_x64.exe 2015-03-18 17:29 - 2015-03-18 17:29 - 00002023 _____ () G:\Users\mse13ssd\Desktop\Windows Phone-Desktopanwendung.lnk 2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Phone 2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\Program Files (x86)\Windows Phone 2015-03-18 17:25 - 2015-03-18 17:25 - 06745792 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\WindowsPhone.exe 2015-03-18 17:25 - 2015-03-18 17:25 - 00000000 ____D () G:\ProgramData\Applications 2015-03-16 19:19 - 2015-03-16 19:19 - 00001535 _____ () G:\Users\mse13ssd\Free YouTube to MP3 Converter.lnk 2015-03-15 17:32 - 2015-04-05 19:37 - 00001114 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-03-15 17:32 - 2015-04-05 18:39 - 00001110 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-15 17:32 - 2015-03-15 17:32 - 00004110 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-03-15 17:32 - 2015-03-15 17:32 - 00003858 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-03-15 17:32 - 2015-03-15 17:32 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2015-03-15 17:31 - 2015-03-15 17:31 - 00880208 _____ (Google Inc.) G:\Users\mse13ssd\Downloads\GoogleEarthSetup.exe 2015-03-14 07:06 - 2015-03-14 07:33 - 82044588 _____ () G:\Users\mse13ssd\Downloads\ES-X_DE.rar.crdownload 2015-03-12 09:28 - 2015-02-03 05:34 - 05554104 _____ (Microsoft Corporation) G:\Windows\system32\ntoskrnl.exe 2015-03-12 09:28 - 2015-02-03 05:34 - 00693176 _____ (Microsoft Corporation) G:\Windows\system32\winload.efi 2015-03-12 09:28 - 2015-02-03 05:34 - 00094656 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\mountmgr.sys 2015-03-12 09:28 - 2015-02-03 05:33 - 00616360 _____ (Microsoft Corporation) G:\Windows\system32\winresume.efi 2015-03-12 09:28 - 2015-02-03 05:31 - 14632960 _____ (Microsoft Corporation) G:\Windows\system32\wmp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 04121600 _____ (Microsoft Corporation) G:\Windows\system32\mf.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 01574400 _____ (Microsoft Corporation) G:\Windows\system32\quartz.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00782848 _____ (Microsoft Corporation) G:\Windows\system32\wmdrmsdk.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00641024 _____ (Microsoft Corporation) G:\Windows\system32\msscp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00503808 _____ (Microsoft Corporation) G:\Windows\system32\srcore.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00500224 _____ (Microsoft Corporation) G:\Windows\system32\AUDIOKSE.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00432128 _____ (Microsoft Corporation) G:\Windows\system32\mfplat.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00371712 _____ (Microsoft Corporation) G:\Windows\system32\qdvd.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00325632 _____ (Microsoft Corporation) G:\Windows\system32\msnetobj.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00229376 _____ (Microsoft Corporation) G:\Windows\system32\wintrust.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00206848 _____ (Microsoft Corporation) G:\Windows\system32\mfps.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00188416 _____ (Microsoft Corporation) G:\Windows\system32\pcasvc.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00063488 _____ (Microsoft Corporation) G:\Windows\system32\setbcdlocale.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00050176 _____ (Microsoft Corporation) G:\Windows\system32\srclient.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00037376 _____ (Microsoft Corporation) G:\Windows\system32\pcadm.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\msmmsp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\spwmp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\msdxm.ocx 2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\dxmasf.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 12625920 _____ (Microsoft Corporation) G:\Windows\system32\wmploc.DLL 2015-03-12 09:28 - 2015-02-03 05:30 - 01480192 _____ (Microsoft Corporation) G:\Windows\system32\crypt32.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 01202176 _____ (Microsoft Corporation) G:\Windows\system32\drmv2clt.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 01069056 _____ (Microsoft Corporation) G:\Windows\system32\cryptui.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00842240 _____ (Microsoft Corporation) G:\Windows\system32\blackbox.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00680960 _____ (Microsoft Corporation) G:\Windows\system32\audiosrv.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00631808 _____ (Microsoft Corporation) G:\Windows\system32\evr.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00497664 _____ (Microsoft Corporation) G:\Windows\system32\drmmgrtn.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00440832 _____ (Microsoft Corporation) G:\Windows\system32\AudioEng.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00296960 _____ (Microsoft Corporation) G:\Windows\system32\rstrui.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00296448 _____ (Microsoft Corporation) G:\Windows\system32\AudioSes.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00284672 _____ (Microsoft Corporation) G:\Windows\system32\EncDump.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00187904 _____ (Microsoft Corporation) G:\Windows\system32\cryptsvc.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00146944 _____ (Microsoft Corporation) G:\Windows\system32\appidpolicyconverter.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00140288 _____ (Microsoft Corporation) G:\Windows\system32\cryptnet.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00126464 _____ (Microsoft Corporation) G:\Windows\system32\audiodg.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00112640 _____ (Microsoft Corporation) G:\Windows\system32\smss.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00082432 _____ (Microsoft Corporation) G:\Windows\system32\cryptsp.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00058880 _____ (Microsoft Corporation) G:\Windows\system32\appidapi.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00055808 _____ (Microsoft Corporation) G:\Windows\system32\rrinstaller.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00043520 _____ (Microsoft Corporation) G:\Windows\system32\csrsrv.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00032256 _____ (Microsoft Corporation) G:\Windows\system32\appidsvc.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00024576 _____ (Microsoft Corporation) G:\Windows\system32\mfpmp.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00017920 _____ (Microsoft Corporation) G:\Windows\system32\appidcertstorecheck.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\pcawrk.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\pcalua.exe 2015-03-12 09:28 - 2015-02-03 05:29 - 00008704 _____ (Microsoft Corporation) G:\Windows\system32\pcaevts.dll 2015-03-12 09:28 - 2015-02-03 05:28 - 00006656 _____ (Microsoft Corporation) G:\Windows\system32\apisetschema.dll 2015-03-12 09:28 - 2015-02-03 05:28 - 00002048 _____ (Microsoft Corporation) G:\Windows\system32\mferror.dll 2015-03-12 09:28 - 2015-02-03 05:19 - 00663552 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\PEAuth.sys 2015-03-12 09:28 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntkrnlpa.exe 2015-03-12 09:28 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntoskrnl.exe 2015-03-12 09:28 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mf.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) G:\Windows\SysWOW64\quartz.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) G:\Windows\SysWOW64\crypt32.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptui.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmv2clt.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\blackbox.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmdrmsdk.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) G:\Windows\SysWOW64\qdvd.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msscp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\evr.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AUDIOKSE.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmmgrtn.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioEng.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfplat.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msnetobj.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioSes.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wintrust.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsvc.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptnet.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfps.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) G:\Windows\SysWOW64\appidapi.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) G:\Windows\SysWOW64\srclient.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\spwmp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msdxm.ocx 2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxmasf.dll 2015-03-12 09:28 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmploc.DLL 2015-03-12 09:28 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\rrinstaller.exe 2015-03-12 09:28 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfpmp.exe 2015-03-12 09:28 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mferror.dll 2015-03-12 09:28 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\apisetschema.dll 2015-03-12 09:28 - 2015-02-03 04:32 - 00061440 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\appid.sys 2015-03-12 09:28 - 2014-11-01 00:24 - 00619056 _____ (Microsoft Corporation) G:\Windows\system32\winload.exe 2015-03-12 09:28 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) G:\Windows\system32\winresume.exe 2015-03-12 09:28 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) G:\Windows\system32\ci.dll 2015-03-12 09:27 - 2015-03-06 07:56 - 00155576 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecpkg.sys 2015-03-12 09:27 - 2015-03-06 07:56 - 00095680 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecdd.sys 2015-03-12 09:27 - 2015-03-06 07:42 - 01461760 _____ (Microsoft Corporation) G:\Windows\system32\lsasrv.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00728064 _____ (Microsoft Corporation) G:\Windows\system32\kerberos.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00341504 _____ (Microsoft Corporation) G:\Windows\system32\schannel.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00314880 _____ (Microsoft Corporation) G:\Windows\system32\msv1_0.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00309760 _____ (Microsoft Corporation) G:\Windows\system32\ncrypt.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00210944 _____ (Microsoft Corporation) G:\Windows\system32\wdigest.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00136192 _____ (Microsoft Corporation) G:\Windows\system32\sspicli.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00086528 _____ (Microsoft Corporation) G:\Windows\system32\TSpkg.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00029184 _____ (Microsoft Corporation) G:\Windows\system32\sspisrv.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00028160 _____ (Microsoft Corporation) G:\Windows\system32\secur32.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00022016 _____ (Microsoft Corporation) G:\Windows\system32\credssp.dll 2015-03-12 09:27 - 2015-03-06 07:41 - 00064000 _____ (Microsoft Corporation) G:\Windows\system32\auditpol.exe 2015-03-12 09:27 - 2015-03-06 07:41 - 00031232 _____ (Microsoft Corporation) G:\Windows\system32\lsass.exe 2015-03-12 09:27 - 2015-03-06 07:39 - 00060416 _____ (Microsoft Corporation) G:\Windows\system32\msobjs.dll 2015-03-12 09:27 - 2015-03-06 07:38 - 00146432 _____ (Microsoft Corporation) G:\Windows\system32\msaudite.dll 2015-03-12 09:27 - 2015-03-06 07:36 - 00686080 _____ (Microsoft Corporation) G:\Windows\system32\adtschema.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) G:\Windows\SysWOW64\kerberos.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msv1_0.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) G:\Windows\SysWOW64\schannel.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ncrypt.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wdigest.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) G:\Windows\SysWOW64\TSpkg.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\secur32.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\credssp.dll 2015-03-12 09:27 - 2015-03-06 07:09 - 00096768 _____ (Microsoft Corporation) G:\Windows\SysWOW64\sspicli.dll 2015-03-12 09:27 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\auditpol.exe 2015-03-12 09:27 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msaudite.dll 2015-03-12 09:27 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msobjs.dll 2015-03-12 09:27 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) G:\Windows\SysWOW64\adtschema.dll 2015-03-12 09:27 - 2015-02-24 05:15 - 00389800 _____ (Microsoft Corporation) G:\Windows\system32\iedkcs32.dll 2015-03-12 09:27 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iedkcs32.dll 2015-03-12 09:27 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.dll 2015-03-12 09:27 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieframe.dll 2015-03-12 09:27 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtmsft.dll 2015-03-12 09:27 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtrans.dll 2015-03-12 09:27 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.dll 2015-03-12 09:27 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) G:\Windows\system32\mshtmled.dll 2015-03-12 09:27 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmled.dll 2015-03-12 09:27 - 2015-02-20 06:41 - 00041984 _____ (Microsoft Corporation) G:\Windows\system32\lpk.dll 2015-03-12 09:27 - 2015-02-20 06:40 - 00100864 _____ (Microsoft Corporation) G:\Windows\system32\fontsub.dll 2015-03-12 09:27 - 2015-02-20 06:40 - 00046080 _____ (Adobe Systems) G:\Windows\system32\atmlib.dll 2015-03-12 09:27 - 2015-02-20 06:40 - 00014336 _____ (Microsoft Corporation) G:\Windows\system32\dciman32.dll 2015-03-12 09:27 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\fontsub.dll 2015-03-12 09:27 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) G:\Windows\SysWOW64\atmlib.dll 2015-03-12 09:27 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dciman32.dll 2015-03-12 09:27 - 2015-02-20 06:12 - 00025600 _____ (Microsoft Corporation) G:\Windows\SysWOW64\lpk.dll 2015-03-12 09:27 - 2015-02-20 05:29 - 00372224 _____ (Adobe Systems Incorporated) G:\Windows\system32\atmfd.dll 2015-03-12 09:27 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\atmfd.dll 2015-03-12 09:27 - 2015-02-20 05:06 - 02724864 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.tlb 2015-03-12 09:27 - 2015-02-20 05:05 - 00004096 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollectorres.dll 2015-03-12 09:27 - 2015-02-20 04:50 - 00066560 _____ (Microsoft Corporation) G:\Windows\system32\iesetup.dll 2015-03-12 09:27 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) G:\Windows\system32\vbscript.dll 2015-03-12 09:27 - 2015-02-20 04:49 - 00048640 _____ (Microsoft Corporation) G:\Windows\system32\ieetwproxystub.dll 2015-03-12 09:27 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) G:\Windows\system32\iertutil.dll 2015-03-12 09:27 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) G:\Windows\system32\MshtmlDac.dll 2015-03-12 09:27 - 2015-02-20 04:41 - 00054784 _____ (Microsoft Corporation) G:\Windows\system32\jsproxy.dll 2015-03-12 09:27 - 2015-02-20 04:40 - 00034304 _____ (Microsoft Corporation) G:\Windows\system32\iernonce.dll 2015-03-12 09:27 - 2015-02-20 04:36 - 00633856 _____ (Microsoft Corporation) G:\Windows\system32\ieui.dll 2015-03-12 09:27 - 2015-02-20 04:35 - 00144384 _____ (Microsoft Corporation) G:\Windows\system32\ieUnatt.exe 2015-03-12 09:27 - 2015-02-20 04:35 - 00114688 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollector.exe 2015-03-12 09:27 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) G:\Windows\system32\jscript9diag.dll 2015-03-12 09:27 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) G:\Windows\system32\jscript9.dll 2015-03-12 09:27 - 2015-02-20 04:26 - 00968704 _____ (Microsoft Corporation) G:\Windows\system32\MsSpellCheckingFacility.exe 2015-03-12 09:27 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.tlb 2015-03-12 09:27 - 2015-02-20 04:22 - 00490496 _____ (Microsoft Corporation) G:\Windows\system32\dxtmsft.dll 2015-03-12 09:27 - 2015-02-20 04:13 - 00077824 _____ (Microsoft Corporation) G:\Windows\system32\JavaScriptCollectionAgent.dll 2015-03-12 09:27 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) G:\Windows\SysWOW64\vbscript.dll 2015-03-12 09:27 - 2015-02-20 04:08 - 00199680 _____ (Microsoft Corporation) G:\Windows\system32\msrating.dll 2015-03-12 09:27 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iesetup.dll 2015-03-12 09:27 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieetwproxystub.dll 2015-03-12 09:27 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) G:\Windows\SysWOW64\MshtmlDac.dll 2015-03-12 09:27 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) G:\Windows\system32\dxtrans.dll 2015-03-12 09:27 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iertutil.dll 2015-03-12 09:27 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jsproxy.dll 2015-03-12 09:27 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iernonce.dll 2015-03-12 09:27 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieui.dll 2015-03-12 09:27 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9diag.dll 2015-03-12 09:27 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieUnatt.exe 2015-03-12 09:27 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) G:\Windows\system32\msfeeds.dll 2015-03-12 09:27 - 2015-02-20 03:49 - 00718848 _____ (Microsoft Corporation) G:\Windows\system32\ie4uinit.exe 2015-03-12 09:27 - 2015-02-20 03:47 - 01359360 _____ (Microsoft Corporation) G:\Windows\system32\mshtmlmedia.dll 2015-03-12 09:27 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) G:\Windows\system32\inetcpl.cpl 2015-03-12 09:27 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) G:\Windows\system32\ieframe.dll 2015-03-12 09:27 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-03-12 09:27 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msrating.dll 2015-03-12 09:27 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9.dll 2015-03-12 09:27 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) G:\Windows\system32\wininet.dll 2015-03-12 09:27 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) G:\Windows\SysWOW64\inetcpl.cpl 2015-03-12 09:27 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msfeeds.dll 2015-03-12 09:27 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmlmedia.dll 2015-03-12 09:27 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) G:\Windows\system32\urlmon.dll 2015-03-12 09:27 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) G:\Windows\system32\ieapfltr.dll 2015-03-12 09:27 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wininet.dll 2015-03-12 09:27 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) G:\Windows\SysWOW64\urlmon.dll 2015-03-12 09:27 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieapfltr.dll 2015-03-12 09:27 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) G:\Windows\SysWOW64\shell32.dll 2015-03-12 09:27 - 2015-02-13 07:22 - 14177280 _____ (Microsoft Corporation) G:\Windows\system32\shell32.dll 2015-03-12 09:27 - 2015-02-03 05:31 - 01424896 _____ (Microsoft Corporation) G:\Windows\system32\WindowsCodecs.dll 2015-03-12 09:27 - 2015-02-03 05:31 - 00215552 _____ (Microsoft Corporation) G:\Windows\system32\ubpm.dll 2015-03-12 09:27 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WindowsCodecs.dll 2015-03-12 09:27 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ubpm.dll 2015-03-12 09:27 - 2015-01-31 05:48 - 03179520 _____ (Microsoft Corporation) G:\Windows\system32\rdpcorets.dll 2015-03-12 09:27 - 2015-01-31 05:48 - 00016384 _____ (Microsoft Corporation) G:\Windows\system32\RdpGroupPolicyExtension.dll 2015-03-12 09:27 - 2015-01-31 01:56 - 00459336 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\cng.sys 2015-03-12 09:27 - 2015-01-31 01:56 - 00243200 _____ (Microsoft Corporation) G:\Windows\system32\rdpudd.dll 2015-03-12 09:27 - 2015-01-17 04:48 - 01067520 _____ (Microsoft Corporation) G:\Windows\system32\msctf.dll 2015-03-12 09:27 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msctf.dll 2015-03-12 09:26 - 2015-02-26 05:25 - 03204096 _____ (Microsoft Corporation) G:\Windows\system32\win32k.sys 2015-03-12 09:26 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) G:\Windows\system32\WMPhoto.dll 2015-03-12 09:26 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WMPhoto.dll 2015-03-10 01:20 - 2015-03-10 01:20 - 00001002 _____ () G:\Users\mse13ssd\Downloads\BAHN_Fahrplan_20150609.ics 2015-03-09 11:16 - 2015-03-09 11:56 - 124202474 _____ () G:\Users\mse13ssd\Downloads\#0325#.rar 2015-03-08 09:43 - 2015-03-08 09:43 - 01230365 _____ () G:\Users\mse13ssd\Downloads\2 (1).wmv 2015-03-08 09:43 - 2015-03-08 09:43 - 01222357 _____ () G:\Users\mse13ssd\Downloads\3.wmv 2015-03-06 16:14 - 2015-03-06 16:51 - 111138743 _____ () G:\Users\mse13ssd\Downloads\julins2014.rar ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-05 18:47 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-05 18:47 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-05 18:45 - 2009-07-14 19:58 - 00700986 _____ () G:\Windows\system32\perfh007.dat 2015-04-05 18:45 - 2009-07-14 19:58 - 00149886 _____ () G:\Windows\system32\perfc007.dat 2015-04-05 18:45 - 2009-07-14 07:13 - 01619284 _____ () G:\Windows\system32\PerfStringBackup.INI 2015-04-05 18:43 - 2014-05-17 10:22 - 01378372 _____ () G:\Windows\WindowsUpdate.log 2015-04-05 18:40 - 2014-07-13 00:21 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Raptr 2015-04-05 18:39 - 2014-05-17 22:03 - 00000000 _____ () G:\Windows\system32\Drivers\lvuvc.hs 2015-04-05 18:39 - 2014-05-17 15:20 - 00033022 _____ () G:\Windows\PFRO.log 2015-04-05 18:39 - 2009-07-14 07:08 - 00000006 ____H () G:\Windows\Tasks\SA.DAT 2015-04-05 18:39 - 2009-07-14 06:51 - 00055579 _____ () G:\Windows\setupact.log 2015-04-05 18:19 - 2015-03-05 14:19 - 00129752 _____ (Malwarebytes Corporation) G:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-04-05 15:10 - 2009-07-14 05:20 - 00000000 __RHD () G:\Users\Default 2015-04-05 15:09 - 2009-07-14 04:34 - 00000215 _____ () G:\Windows\system.ini 2015-04-05 13:19 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\NDF 2015-04-05 13:06 - 2014-05-17 22:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Skype 2015-04-05 12:59 - 2014-05-17 11:54 - 00000000 ____D () G:\Users\mse13ssd 2015-04-05 03:26 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\Web 2015-04-05 02:39 - 2014-05-17 15:57 - 00004182 _____ () G:\Windows\System32\Tasks\avast! Emergency Update 2015-04-04 14:30 - 2014-05-17 20:13 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\TS3Client 2015-04-02 01:34 - 2009-07-14 07:32 - 00000000 ____D () G:\Windows\system32\FxsTmp 2015-03-30 17:36 - 2015-02-28 05:38 - 00000000 ____D () G:\Users\mse13ssd\Desktop\aufgeräumt 2015-03-30 08:10 - 2014-11-01 08:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\25372 2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\DivX 2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX 2015-03-30 04:33 - 2014-08-24 02:00 - 00000000 ____D () G:\ProgramData\DivX 2015-03-30 04:33 - 2014-05-17 15:57 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast 2015-03-30 04:33 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\AppCompat 2015-03-30 04:32 - 2014-08-24 02:01 - 00000000 ____D () G:\Program Files\DivX 2015-03-30 04:32 - 2014-08-24 02:00 - 00000000 ____D () G:\Program Files (x86)\DivX 2015-03-30 04:32 - 2014-06-18 17:31 - 00000000 ____D () G:\Program Files (x86)\Microsoft Office 2015-03-30 04:32 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\registration 2015-03-30 03:27 - 2009-07-14 20:18 - 00000000 ___RD () G:\Users\Public\Recorded TV 2015-03-26 21:20 - 2014-10-12 12:01 - 00000000 ____D () G:\Windows\Minidump 2015-03-26 18:51 - 2014-07-13 00:21 - 00000000 ____D () G:\Program Files (x86)\Raptr 2015-03-26 09:13 - 2014-06-18 17:31 - 00000000 ____D () G:\ProgramData\Microsoft Help 2015-03-22 18:29 - 2014-05-17 12:40 - 00070368 _____ () G:\Users\mse13ssd\AppData\Local\GDIPFONTCACHEV1.DAT 2015-03-22 18:29 - 2009-07-14 06:45 - 00307752 _____ () G:\Windows\system32\FNTCACHE.DAT 2015-03-22 18:25 - 2014-06-18 17:32 - 00000000 ____D () G:\Program Files (x86)\Microsoft Works 2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Google 2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Program Files (x86)\Google 2015-03-15 14:09 - 2014-08-24 13:49 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Adobe 2015-03-15 14:09 - 2014-05-17 15:53 - 00778928 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerApp.exe 2015-03-15 14:09 - 2014-05-17 15:53 - 00142512 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-03-15 05:05 - 2014-06-21 18:28 - 00000000 ____D () G:\Program Files (x86)\Steam 2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Glyph 2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glyph 2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Program Files (x86)\Glyph 2015-03-13 10:32 - 2009-07-14 07:09 - 00000000 ____D () G:\Windows\System32\Tasks\WPD 2015-03-12 12:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\rescache 2015-03-12 09:37 - 2015-02-28 09:01 - 00000000 ___RD () G:\Users\mse13ssd\Virtual Machines 2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\SysWOW64\Dism 2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\Dism 2015-03-12 09:31 - 2014-05-17 20:36 - 00000000 ____D () G:\Windows\system32\MRT 2015-03-12 09:29 - 2014-05-17 20:36 - 122905848 _____ (Microsoft Corporation) G:\Windows\system32\MRT.exe 2015-03-06 13:47 - 2014-10-13 17:23 - 00000000 ___RD () G:\Program Files (x86)\Skype 2015-03-06 13:47 - 2014-05-17 22:15 - 00000000 ____D () G:\ProgramData\Skype ==================== Files in the root of some directories ======= 2014-10-02 16:29 - 2015-02-28 12:40 - 14286848 _____ () G:\Users\mse13ssd\AppData\Roaming\Sandra.mdb 2015-01-23 13:40 - 2015-01-23 13:40 - 0003584 _____ () G:\Users\mse13ssd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-01-01 14:58 - 2015-01-01 14:58 - 0007605 _____ () G:\Users\mse13ssd\AppData\Local\Resmon.ResmonCfg Some content of TEMP: ==================== G:\Users\mse13ssd\AppData\Local\Temp\Quarantine.exe G:\Users\mse13ssd\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) G:\Windows\System32\winlogon.exe => File is digitally signed G:\Windows\System32\wininit.exe => File is digitally signed G:\Windows\SysWOW64\wininit.exe => File is digitally signed G:\Windows\explorer.exe => File is digitally signed G:\Windows\SysWOW64\explorer.exe => File is digitally signed G:\Windows\System32\svchost.exe => File is digitally signed G:\Windows\SysWOW64\svchost.exe => File is digitally signed G:\Windows\System32\services.exe => File is digitally signed G:\Windows\System32\User32.dll => File is digitally signed G:\Windows\SysWOW64\User32.dll => File is digitally signed G:\Windows\System32\userinit.exe => File is digitally signed G:\Windows\SysWOW64\userinit.exe => File is digitally signed G:\Windows\System32\rpcss.dll => File is digitally signed G:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-04-04 00:45 ==================== End Of Log ============================ |
06.04.2015, 11:05 | #6 |
/// the machine /// TB-Ausbilder | Win 7: konnte ShopGlider Deals bis jetzt nicht entfernenESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen |
07.04.2015, 09:40 | #7 |
| Win 7: konnte ShopGlider Deals bis jetzt nicht entfernenCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=9034e1cd59c35d4897ca59e7ac9185aa # engine=23253 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-04-06 10:19:52 # local_time=2015-04-07 12:19:52 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777213 100 95 676013 28023765 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 16002 179988642 0 0 # scanned=590292 # found=129 # cleaned=0 # scan_time=15599 sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe" sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe" sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe" sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe" sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll" sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll" sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe" sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe" sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe" sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe" sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe" sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Temp\ct3297265\ism.exe" sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll" sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll" sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe" sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe" sh=3BF736C24033F3E9302AD9339AB24946B84DBB22 ft=1 fh=16a157c9bf933752 vn="Variante von Win32/Toolbar.SearchSuite.Z evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=A151080AB2A5C8FECCE625974FFE1EEEC7C40637 ft=1 fh=a0dd2ab90579dc22 vn="Variante von Win32/GetNow.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe" sh=8A9C345E13E286F64B09520E8B374BE0F41FF958 ft=1 fh=6add8ca28ee0da1a vn="Win32/AdWare.1ClickDownload.AT Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\Der_knallharte_Prinzipal.exe" sh=B68BF0E698A41B385F988BF936586CBEFAADF1B2 ft=1 fh=8f23a3e3ad9fbfbf vn="Variante von Win32/Toolbar.SearchSuite.J evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\jZipSetup-r113-n-bc.exe" sh=F1157163FF747E652B9F0D5FFF7C122B04E702CA ft=1 fh=13352cc938f5dd09 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe" sh=46100C3A7E115EA5D75C1E413D3735DEF566BC56 ft=1 fh=bc1f79bd33786c53 vn="Win32/Toolbar.Conduit.AE evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\Raidcall_TSV45QFV6.exe" sh=C90DC54D89385CA31BDE44E879E11A498AAEFB8B ft=1 fh=bb5adeb19de8958e vn="Variante von Win32/SoftonicDownloader.F evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe" sh=2DDE7AFBAD3F2903ED3BB46AD82698FD4371270C ft=1 fh=e68f4e0bfda3a157 vn="Variante von Win32/Amonetize.AG evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe" sh=A08B6EC51DDD212A28C63680D05CCAB708CC09A9 ft=1 fh=8b799a2f1c89ab47 vn="Win32/AdWare.1ClickDownload.AT Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe" sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe" sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe" sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe" sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe" sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll" sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll" sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe" sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe" sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe" sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe" sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe" sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe" sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll" sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll" sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe" sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe" sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe" sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe" sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe" sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\ct3297265\ism.exe" sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll" sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll" sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe" sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe" sh=3BF736C24033F3E9302AD9339AB24946B84DBB22 ft=1 fh=16a157c9bf933752 vn="Variante von Win32/Toolbar.SearchSuite.Z evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=A151080AB2A5C8FECCE625974FFE1EEEC7C40637 ft=1 fh=a0dd2ab90579dc22 vn="Variante von Win32/GetNow.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe" sh=8A9C345E13E286F64B09520E8B374BE0F41FF958 ft=1 fh=6add8ca28ee0da1a vn="Win32/AdWare.1ClickDownload.AT Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\Der_knallharte_Prinzipal.exe" sh=B68BF0E698A41B385F988BF936586CBEFAADF1B2 ft=1 fh=8f23a3e3ad9fbfbf vn="Variante von Win32/Toolbar.SearchSuite.J evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\jZipSetup-r113-n-bc.exe" sh=F1157163FF747E652B9F0D5FFF7C122B04E702CA ft=1 fh=13352cc938f5dd09 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe" sh=46100C3A7E115EA5D75C1E413D3735DEF566BC56 ft=1 fh=bc1f79bd33786c53 vn="Win32/Toolbar.Conduit.AE evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\Raidcall_TSV45QFV6.exe" sh=C90DC54D89385CA31BDE44E879E11A498AAEFB8B ft=1 fh=bb5adeb19de8958e vn="Variante von Win32/SoftonicDownloader.F evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe" sh=2DDE7AFBAD3F2903ED3BB46AD82698FD4371270C ft=1 fh=e68f4e0bfda3a157 vn="Variante von Win32/Amonetize.AG evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe" sh=A08B6EC51DDD212A28C63680D05CCAB708CC09A9 ft=1 fh=8b799a2f1c89ab47 vn="Win32/AdWare.1ClickDownload.AT Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe" sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe" sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe" sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe" sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe" sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll" sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll" sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe" sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe" sh=58B5ECA6356C4BE712A4376A3941E693B83E3C3F ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\HDvid-Codec V9.0\51356.crx" sh=00A559F12816F1E9B5C6C6AEDF07D52556898077 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\HDvid-Codec V9.0\51356.xpi" sh=E16893EC0AB084A8DB5F87A5C9A29B0B2846D7F9 ft=1 fh=cca47823c3292533 vn="Variante von Win32/Toolbar.Iminent.C evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\Iminent\inst\Bootstrapper\IminentUninstall.exe" sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe" sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe" sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe" sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\Temp\ct3297265\ism.exe" sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll" sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll" sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe" sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe" sh=3BF736C24033F3E9302AD9339AB24946B84DBB22 ft=1 fh=16a157c9bf933752 vn="Variante von Win32/Toolbar.SearchSuite.Z evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" sh=A151080AB2A5C8FECCE625974FFE1EEEC7C40637 ft=1 fh=a0dd2ab90579dc22 vn="Variante von Win32/GetNow.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe" sh=8A9C345E13E286F64B09520E8B374BE0F41FF958 ft=1 fh=6add8ca28ee0da1a vn="Win32/AdWare.1ClickDownload.AT Anwendung" ac=I fn="C:\Users\mse13\Downloads\Der_knallharte_Prinzipal.exe" sh=B68BF0E698A41B385F988BF936586CBEFAADF1B2 ft=1 fh=8f23a3e3ad9fbfbf vn="Variante von Win32/Toolbar.SearchSuite.J evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Downloads\jZipSetup-r113-n-bc.exe" sh=F1157163FF747E652B9F0D5FFF7C122B04E702CA ft=1 fh=13352cc938f5dd09 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe" sh=46100C3A7E115EA5D75C1E413D3735DEF566BC56 ft=1 fh=bc1f79bd33786c53 vn="Win32/Toolbar.Conduit.AE evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Downloads\Raidcall_TSV45QFV6.exe" sh=C90DC54D89385CA31BDE44E879E11A498AAEFB8B ft=1 fh=bb5adeb19de8958e vn="Variante von Win32/SoftonicDownloader.F evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe" sh=2DDE7AFBAD3F2903ED3BB46AD82698FD4371270C ft=1 fh=e68f4e0bfda3a157 vn="Variante von Win32/Amonetize.AG evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe" sh=A08B6EC51DDD212A28C63680D05CCAB708CC09A9 ft=1 fh=8b799a2f1c89ab47 vn="Win32/AdWare.1ClickDownload.AT Anwendung" ac=I fn="C:\Users\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe" sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe" sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe" sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe" sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe" sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll" sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll" sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe" sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe" sh=31CE21FE36C11E107A6E315EFE1875743809B4CC ft=1 fh=48abcfa6ce4a4014 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="G:\AdwCleaner\Quarantine\G\Users\mse13ssd\AppData\Local\Temp\OCS\ocs_v71b.exe.vir" sh=1153F638CB1AE4E7B26A1472F18D52A8603E6ACF ft=1 fh=53fcb0c52b4f621b vn="Variante von Win32/Amonetize.BY evtl. unerwünschte Anwendung" ac=I fn="G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\File System\002\t\00\00000000" sh=D36B7EB47F1691BF8EAB2EA2805E0D1F1A3791F7 ft=1 fh=88789f35a0bf115b vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="G:\Users\mse13ssd\Downloads\Griffith - CHIP-Installer.exe" sh=7BA0A01D63E1511F6101A736D157C4D1F885EDEB ft=1 fh=1aba12d0f1f8efc7 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="G:\Users\mse13ssd\Downloads\PDFCreator-2_0_0-setup.exe" sh=697DB363C754CB50BB2AB17B95EB2633FAEE993F ft=0 fh=0000000000000000 vn="Win32/Emotet.AD Trojaner" ac=I fn="G:\Users\mse13ssd\Downloads\ZustellnachrichtDHL_bestellung_000029937728.zip" diesmal hat es geklappt: Code:
ATTFilter Results of screen317's Security Check version 0.99.99 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Java 8 Update 31 Java version 32-bit out of Date! Adobe Flash Player 17.0.0.134 Adobe Reader XI Mozilla Firefox (36.0) ````````Process Check: objlist.exe by Laurent```````` AVAST Software Avast AvastSvc.exe AVAST Software Avast avastui.exe `````````````````System Health check````````````````` Total Fragmentation on Drive G: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Ran by mse13ssd (administrator) on MSE13SSD-PC on 07-04-2015 10:36:27 Running from G:\Users\mse13ssd\Desktop Loaded Profiles: mse13ssd (Available profiles: mse13ssd) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) G:\Windows\System32\atiesrxx.exe (Logitech Inc.) G:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (AVAST Software) G:\Program Files\AVAST Software\Avast\AvastSvc.exe (AMD) G:\Windows\System32\atieclxx.exe (Apple Inc.) G:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) G:\Program Files\Bonjour\mDNSResponder.exe (Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe (Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe (Logitech Inc.) G:\Program Files\Logitech Gaming Software\LCore.exe (Microsoft Corporation) G:\Program Files\Windows Sidebar\sidebar.exe (AVAST Software) G:\Program Files\AVAST Software\Avast\avastui.exe () G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Advanced Micro Devices Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (Microsoft Corporation) G:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Launch LCore] => G:\Program Files\Logitech Gaming Software\LCore.exe [10801944 2014-07-28] (Logitech Inc.) HKLM-x32\...\Run: [AvastUI.exe] => G:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software) HKLM-x32\...\Run: [DivXMediaServer] => G:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [StartCCC] => G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Raptr] => G:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-03-25] (Raptr, Inc) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => G:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-3243151774-2580435505-251407729-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-15] (AVAST Software) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-26] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-15] (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-26] (Oracle Corporation) Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - G:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll [2014-10-10] (pdfforge GmbH) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0 FireFox: ======== FF ProfilePath: G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default FF Plugin: @adobe.com/FlashPlayer -> G:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-15] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> G:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-15] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> G:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2012-04-05] () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> G:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-26] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-26] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> G:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.) FF Plugin-x32: Adobe Reader -> G:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Extension: Download videos and MP3s from YouTube - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-11-21] FF Extension: Adblock Plus - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-09] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - G:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - G:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-17] FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension FF Extension: PDF Architect 2 Creator - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2014-12-09] FF HKU\S-1-5-21-3243151774-2580435505-251407729-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff FF Extension: Download videos and MP3s from YouTube - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-11-21] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Profile: G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-09] CHR Extension: (Google Docs) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-09] CHR Extension: (Google Drive) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-09] CHR Extension: (Google Voice Search Hotword (Beta)) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-09] CHR Extension: (YouTube) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-09] CHR Extension: (Google Search) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-09] CHR Extension: (Google Sheets) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-09] CHR Extension: (Google Wallet) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-09] CHR Extension: (Gmail) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-09] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - G:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-15] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; G:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-15] (AVAST Software) S2 PDF Architect 2 Creator; G:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH) S3 SandraAgentSrv; G:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3c\RpcAgentSrv.exe [73712 2014-09-19] (SiSoftware) [File not signed] R2 WinDefend; G:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; G:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 aswHwid; G:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-15] () R2 aswMonFlt; G:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-15] (AVAST Software) R1 aswRdr; G:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-15] (AVAST Software) R0 aswRvrt; G:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-15] () R1 aswSnx; G:\Windows\system32\drivers\aswSnx.sys [1041168 2014-11-21] (AVAST Software) R1 aswSP; G:\Windows\system32\drivers\aswSP.sys [427360 2014-07-15] (AVAST Software) R2 aswStm; G:\Windows\system32\drivers\aswStm.sys [92008 2014-07-15] (AVAST Software) R0 aswVmm; G:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-15] () R3 LGSHidFilt; G:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) S3 catchme; \??\G:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-07 10:36 - 2015-04-07 10:36 - 00012219 _____ () G:\Users\mse13ssd\Desktop\FRST.txt 2015-04-07 10:26 - 2015-04-07 10:26 - 00852607 _____ () G:\Users\mse13ssd\Downloads\SecurityCheck (2).exe 2015-04-07 10:19 - 2015-04-07 10:19 - 00008930 _____ () G:\Users\mse13ssd\Downloads\smime (2).p7s 2015-04-06 19:59 - 2015-04-06 19:59 - 02347384 _____ (ESET) G:\Users\mse13ssd\Downloads\esetsmartinstaller_deu (1).exe 2015-04-06 17:43 - 2015-04-06 17:43 - 00852607 _____ () G:\Users\mse13ssd\Downloads\SecurityCheck (1).exe 2015-04-06 17:41 - 2015-04-06 17:41 - 00852607 _____ () G:\Users\mse13ssd\Downloads\SecurityCheck.exe 2015-04-06 12:27 - 2015-04-06 12:27 - 02347384 _____ (ESET) G:\Users\mse13ssd\Downloads\esetsmartinstaller_deu.exe 2015-04-06 12:27 - 2015-04-06 12:27 - 00000000 ____D () G:\Program Files (x86)\ESET 2015-04-05 19:33 - 2015-04-05 19:33 - 00000207 _____ () G:\Windows\tweaking.com-regbackup-MSE13SSD-PC-Windows-7-Home-Premium-(64-bit).dat 2015-04-05 19:33 - 2015-04-05 19:33 - 00000000 ____D () G:\RegBackup 2015-04-05 18:35 - 2015-04-05 18:35 - 02690981 _____ (Thisisu) G:\Users\mse13ssd\Desktop\JRT.exe 2015-04-05 15:10 - 2015-04-05 15:10 - 00011639 _____ () G:\ComboFix.txt 2015-04-05 15:03 - 2015-04-05 15:10 - 00000000 ____D () G:\Qoobox 2015-04-05 15:03 - 2015-04-05 15:09 - 00000000 ____D () G:\Windows\erdnt 2015-04-05 15:03 - 2011-06-26 08:45 - 00256000 _____ () G:\Windows\PEV.exe 2015-04-05 15:03 - 2010-11-07 19:20 - 00208896 _____ () G:\Windows\MBR.exe 2015-04-05 15:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) G:\Windows\NIRCMD.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) G:\Windows\SWREG.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) G:\Windows\SWSC.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00098816 _____ () G:\Windows\sed.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00080412 _____ () G:\Windows\grep.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00068096 _____ () G:\Windows\zip.exe 2015-04-05 15:01 - 2015-04-05 15:01 - 05617096 ____R (Swearware) G:\Users\mse13ssd\Desktop\ComboFix.exe 2015-04-05 13:10 - 2015-04-05 13:11 - 00380416 _____ () G:\Users\mse13ssd\Downloads\liqvrrec.exe 2015-04-05 13:02 - 2015-04-07 10:36 - 00000000 ____D () G:\FRST 2015-04-05 13:02 - 2015-04-05 13:03 - 00048734 _____ () G:\Users\mse13ssd\Downloads\FRST.txt 2015-04-05 13:02 - 2015-04-05 13:03 - 00024876 _____ () G:\Users\mse13ssd\Downloads\Addition.txt 2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Downloads\FRST64 (1).exe 2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Desktop\FRST64.exe 2015-04-05 12:59 - 2015-04-05 12:59 - 00000478 _____ () G:\Users\mse13ssd\Downloads\defogger_disable.log 2015-04-05 12:59 - 2015-04-05 12:59 - 00000000 _____ () G:\Users\mse13ssd\defogger_reenable 2015-04-05 12:57 - 2015-04-05 12:57 - 00050477 _____ () G:\Users\mse13ssd\Downloads\Defogger.exe 2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (2).exe 2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (1).exe 2015-04-05 03:38 - 2015-04-05 18:38 - 00000000 ____D () G:\AdwCleaner 2015-04-05 03:37 - 2015-04-05 03:38 - 02208768 _____ () G:\Users\mse13ssd\Desktop\adwcleaner_4.200.exe 2015-03-31 05:26 - 2015-03-31 05:26 - 00008930 _____ () G:\Users\mse13ssd\Downloads\smime (1).p7s 2015-03-31 02:41 - 2015-03-31 02:41 - 00000069 _____ () G:\Users\mse13ssd\Desktop\BADLOGIC (German Fandub) - YouTube.url 2015-03-28 00:47 - 2015-03-28 00:47 - 00012288 _____ () G:\Users\mse13ssd\Downloads\Qual-Fraktal.xls 2015-03-27 07:14 - 2015-03-27 07:14 - 00000000 ____D () G:\Users\mse13ssd\Desktop\SciLor's Grooveshark.com Downloader 2015-03-26 21:20 - 2015-03-26 21:20 - 671367548 _____ () G:\Windows\MEMORY.DMP 2015-03-26 21:20 - 2015-03-26 21:20 - 00274624 _____ () G:\Windows\Minidump\032615-29718-01.dmp 2015-03-25 04:31 - 2015-03-25 04:31 - 00002123 _____ () G:\Users\Public\Desktop\CONTRACT J.A.C.K. .lnk 2015-03-25 04:05 - 2015-03-25 04:05 - 00000000 ____D () G:\Program Files (x86)\Sierra 2015-03-25 04:04 - 2015-03-25 04:04 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra 2015-03-25 04:00 - 2003-06-26 10:45 - 00499712 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcp71.dll 2015-03-25 04:00 - 2003-06-26 10:45 - 00348160 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcr71.dll 2015-03-25 04:00 - 2003-03-19 07:20 - 01060864 ____N (Microsoft Corporation) G:\Windows\SysWOW64\mfc71.dll 2015-03-22 18:27 - 2015-03-22 18:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in 2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files\Microsoft Silverlight 2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files (x86)\Microsoft Silverlight 2015-03-21 10:33 - 2015-03-21 10:33 - 13087456 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\Silverlight_x64.exe 2015-03-18 17:29 - 2015-03-18 17:29 - 00002023 _____ () G:\Users\mse13ssd\Desktop\Windows Phone-Desktopanwendung.lnk 2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Phone 2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\Program Files (x86)\Windows Phone 2015-03-18 17:25 - 2015-03-18 17:25 - 06745792 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\WindowsPhone.exe 2015-03-18 17:25 - 2015-03-18 17:25 - 00000000 ____D () G:\ProgramData\Applications 2015-03-16 19:19 - 2015-03-16 19:19 - 00001535 _____ () G:\Users\mse13ssd\Free YouTube to MP3 Converter.lnk 2015-03-15 17:32 - 2015-04-07 10:10 - 00001110 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-15 17:32 - 2015-04-07 04:37 - 00001114 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-03-15 17:32 - 2015-03-15 17:32 - 00004110 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-03-15 17:32 - 2015-03-15 17:32 - 00003858 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-03-15 17:32 - 2015-03-15 17:32 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2015-03-15 17:31 - 2015-03-15 17:31 - 00880208 _____ (Google Inc.) G:\Users\mse13ssd\Downloads\GoogleEarthSetup.exe 2015-03-14 07:06 - 2015-03-14 07:33 - 82044588 _____ () G:\Users\mse13ssd\Downloads\ES-X_DE.rar.crdownload 2015-03-12 09:28 - 2015-02-03 05:34 - 05554104 _____ (Microsoft Corporation) G:\Windows\system32\ntoskrnl.exe 2015-03-12 09:28 - 2015-02-03 05:34 - 00693176 _____ (Microsoft Corporation) G:\Windows\system32\winload.efi 2015-03-12 09:28 - 2015-02-03 05:34 - 00094656 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\mountmgr.sys 2015-03-12 09:28 - 2015-02-03 05:33 - 00616360 _____ (Microsoft Corporation) G:\Windows\system32\winresume.efi 2015-03-12 09:28 - 2015-02-03 05:31 - 14632960 _____ (Microsoft Corporation) G:\Windows\system32\wmp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 04121600 _____ (Microsoft Corporation) G:\Windows\system32\mf.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 01574400 _____ (Microsoft Corporation) G:\Windows\system32\quartz.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00782848 _____ (Microsoft Corporation) G:\Windows\system32\wmdrmsdk.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00641024 _____ (Microsoft Corporation) G:\Windows\system32\msscp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00503808 _____ (Microsoft Corporation) G:\Windows\system32\srcore.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00500224 _____ (Microsoft Corporation) G:\Windows\system32\AUDIOKSE.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00432128 _____ (Microsoft Corporation) G:\Windows\system32\mfplat.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00371712 _____ (Microsoft Corporation) G:\Windows\system32\qdvd.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00325632 _____ (Microsoft Corporation) G:\Windows\system32\msnetobj.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00229376 _____ (Microsoft Corporation) G:\Windows\system32\wintrust.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00206848 _____ (Microsoft Corporation) G:\Windows\system32\mfps.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00188416 _____ (Microsoft Corporation) G:\Windows\system32\pcasvc.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00063488 _____ (Microsoft Corporation) G:\Windows\system32\setbcdlocale.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00050176 _____ (Microsoft Corporation) G:\Windows\system32\srclient.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00037376 _____ (Microsoft Corporation) G:\Windows\system32\pcadm.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\msmmsp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\spwmp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\msdxm.ocx 2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\dxmasf.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 12625920 _____ (Microsoft Corporation) G:\Windows\system32\wmploc.DLL 2015-03-12 09:28 - 2015-02-03 05:30 - 01480192 _____ (Microsoft Corporation) G:\Windows\system32\crypt32.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 01202176 _____ (Microsoft Corporation) G:\Windows\system32\drmv2clt.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 01069056 _____ (Microsoft Corporation) G:\Windows\system32\cryptui.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00842240 _____ (Microsoft Corporation) G:\Windows\system32\blackbox.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00680960 _____ (Microsoft Corporation) G:\Windows\system32\audiosrv.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00631808 _____ (Microsoft Corporation) G:\Windows\system32\evr.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00497664 _____ (Microsoft Corporation) G:\Windows\system32\drmmgrtn.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00440832 _____ (Microsoft Corporation) G:\Windows\system32\AudioEng.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00296960 _____ (Microsoft Corporation) G:\Windows\system32\rstrui.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00296448 _____ (Microsoft Corporation) G:\Windows\system32\AudioSes.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00284672 _____ (Microsoft Corporation) G:\Windows\system32\EncDump.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00187904 _____ (Microsoft Corporation) G:\Windows\system32\cryptsvc.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00146944 _____ (Microsoft Corporation) G:\Windows\system32\appidpolicyconverter.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00140288 _____ (Microsoft Corporation) G:\Windows\system32\cryptnet.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00126464 _____ (Microsoft Corporation) G:\Windows\system32\audiodg.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00112640 _____ (Microsoft Corporation) G:\Windows\system32\smss.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00082432 _____ (Microsoft Corporation) G:\Windows\system32\cryptsp.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00058880 _____ (Microsoft Corporation) G:\Windows\system32\appidapi.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00055808 _____ (Microsoft Corporation) G:\Windows\system32\rrinstaller.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00043520 _____ (Microsoft Corporation) G:\Windows\system32\csrsrv.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00032256 _____ (Microsoft Corporation) G:\Windows\system32\appidsvc.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00024576 _____ (Microsoft Corporation) G:\Windows\system32\mfpmp.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00017920 _____ (Microsoft Corporation) G:\Windows\system32\appidcertstorecheck.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\pcawrk.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\pcalua.exe 2015-03-12 09:28 - 2015-02-03 05:29 - 00008704 _____ (Microsoft Corporation) G:\Windows\system32\pcaevts.dll 2015-03-12 09:28 - 2015-02-03 05:28 - 00006656 _____ (Microsoft Corporation) G:\Windows\system32\apisetschema.dll 2015-03-12 09:28 - 2015-02-03 05:28 - 00002048 _____ (Microsoft Corporation) G:\Windows\system32\mferror.dll 2015-03-12 09:28 - 2015-02-03 05:19 - 00663552 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\PEAuth.sys 2015-03-12 09:28 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntkrnlpa.exe 2015-03-12 09:28 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntoskrnl.exe 2015-03-12 09:28 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mf.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) G:\Windows\SysWOW64\quartz.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) G:\Windows\SysWOW64\crypt32.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptui.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmv2clt.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\blackbox.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmdrmsdk.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) G:\Windows\SysWOW64\qdvd.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msscp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\evr.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AUDIOKSE.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmmgrtn.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioEng.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfplat.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msnetobj.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioSes.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wintrust.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsvc.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptnet.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfps.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) G:\Windows\SysWOW64\appidapi.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) G:\Windows\SysWOW64\srclient.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\spwmp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msdxm.ocx 2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxmasf.dll 2015-03-12 09:28 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmploc.DLL 2015-03-12 09:28 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\rrinstaller.exe 2015-03-12 09:28 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfpmp.exe 2015-03-12 09:28 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mferror.dll 2015-03-12 09:28 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\apisetschema.dll 2015-03-12 09:28 - 2015-02-03 04:32 - 00061440 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\appid.sys 2015-03-12 09:28 - 2014-11-01 00:24 - 00619056 _____ (Microsoft Corporation) G:\Windows\system32\winload.exe 2015-03-12 09:28 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) G:\Windows\system32\winresume.exe 2015-03-12 09:28 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) G:\Windows\system32\ci.dll 2015-03-12 09:27 - 2015-03-06 07:56 - 00155576 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecpkg.sys 2015-03-12 09:27 - 2015-03-06 07:56 - 00095680 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecdd.sys 2015-03-12 09:27 - 2015-03-06 07:42 - 01461760 _____ (Microsoft Corporation) G:\Windows\system32\lsasrv.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00728064 _____ (Microsoft Corporation) G:\Windows\system32\kerberos.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00341504 _____ (Microsoft Corporation) G:\Windows\system32\schannel.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00314880 _____ (Microsoft Corporation) G:\Windows\system32\msv1_0.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00309760 _____ (Microsoft Corporation) G:\Windows\system32\ncrypt.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00210944 _____ (Microsoft Corporation) G:\Windows\system32\wdigest.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00136192 _____ (Microsoft Corporation) G:\Windows\system32\sspicli.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00086528 _____ (Microsoft Corporation) G:\Windows\system32\TSpkg.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00029184 _____ (Microsoft Corporation) G:\Windows\system32\sspisrv.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00028160 _____ (Microsoft Corporation) G:\Windows\system32\secur32.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00022016 _____ (Microsoft Corporation) G:\Windows\system32\credssp.dll 2015-03-12 09:27 - 2015-03-06 07:41 - 00064000 _____ (Microsoft Corporation) G:\Windows\system32\auditpol.exe 2015-03-12 09:27 - 2015-03-06 07:41 - 00031232 _____ (Microsoft Corporation) G:\Windows\system32\lsass.exe 2015-03-12 09:27 - 2015-03-06 07:39 - 00060416 _____ (Microsoft Corporation) G:\Windows\system32\msobjs.dll 2015-03-12 09:27 - 2015-03-06 07:38 - 00146432 _____ (Microsoft Corporation) G:\Windows\system32\msaudite.dll 2015-03-12 09:27 - 2015-03-06 07:36 - 00686080 _____ (Microsoft Corporation) G:\Windows\system32\adtschema.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) G:\Windows\SysWOW64\kerberos.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msv1_0.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) G:\Windows\SysWOW64\schannel.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ncrypt.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wdigest.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) G:\Windows\SysWOW64\TSpkg.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\secur32.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\credssp.dll 2015-03-12 09:27 - 2015-03-06 07:09 - 00096768 _____ (Microsoft Corporation) G:\Windows\SysWOW64\sspicli.dll 2015-03-12 09:27 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\auditpol.exe 2015-03-12 09:27 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msaudite.dll 2015-03-12 09:27 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msobjs.dll 2015-03-12 09:27 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) G:\Windows\SysWOW64\adtschema.dll 2015-03-12 09:27 - 2015-02-24 05:15 - 00389800 _____ (Microsoft Corporation) G:\Windows\system32\iedkcs32.dll 2015-03-12 09:27 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iedkcs32.dll 2015-03-12 09:27 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.dll 2015-03-12 09:27 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieframe.dll 2015-03-12 09:27 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtmsft.dll 2015-03-12 09:27 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtrans.dll 2015-03-12 09:27 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.dll 2015-03-12 09:27 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) G:\Windows\system32\mshtmled.dll 2015-03-12 09:27 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmled.dll 2015-03-12 09:27 - 2015-02-20 06:41 - 00041984 _____ (Microsoft Corporation) G:\Windows\system32\lpk.dll 2015-03-12 09:27 - 2015-02-20 06:40 - 00100864 _____ (Microsoft Corporation) G:\Windows\system32\fontsub.dll 2015-03-12 09:27 - 2015-02-20 06:40 - 00046080 _____ (Adobe Systems) G:\Windows\system32\atmlib.dll 2015-03-12 09:27 - 2015-02-20 06:40 - 00014336 _____ (Microsoft Corporation) G:\Windows\system32\dciman32.dll 2015-03-12 09:27 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\fontsub.dll 2015-03-12 09:27 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) G:\Windows\SysWOW64\atmlib.dll 2015-03-12 09:27 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dciman32.dll 2015-03-12 09:27 - 2015-02-20 06:12 - 00025600 _____ (Microsoft Corporation) G:\Windows\SysWOW64\lpk.dll 2015-03-12 09:27 - 2015-02-20 05:29 - 00372224 _____ (Adobe Systems Incorporated) G:\Windows\system32\atmfd.dll 2015-03-12 09:27 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\atmfd.dll 2015-03-12 09:27 - 2015-02-20 05:06 - 02724864 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.tlb 2015-03-12 09:27 - 2015-02-20 05:05 - 00004096 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollectorres.dll 2015-03-12 09:27 - 2015-02-20 04:50 - 00066560 _____ (Microsoft Corporation) G:\Windows\system32\iesetup.dll 2015-03-12 09:27 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) G:\Windows\system32\vbscript.dll 2015-03-12 09:27 - 2015-02-20 04:49 - 00048640 _____ (Microsoft Corporation) G:\Windows\system32\ieetwproxystub.dll 2015-03-12 09:27 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) G:\Windows\system32\iertutil.dll 2015-03-12 09:27 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) G:\Windows\system32\MshtmlDac.dll 2015-03-12 09:27 - 2015-02-20 04:41 - 00054784 _____ (Microsoft Corporation) G:\Windows\system32\jsproxy.dll 2015-03-12 09:27 - 2015-02-20 04:40 - 00034304 _____ (Microsoft Corporation) G:\Windows\system32\iernonce.dll 2015-03-12 09:27 - 2015-02-20 04:36 - 00633856 _____ (Microsoft Corporation) G:\Windows\system32\ieui.dll 2015-03-12 09:27 - 2015-02-20 04:35 - 00144384 _____ (Microsoft Corporation) G:\Windows\system32\ieUnatt.exe 2015-03-12 09:27 - 2015-02-20 04:35 - 00114688 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollector.exe 2015-03-12 09:27 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) G:\Windows\system32\jscript9diag.dll 2015-03-12 09:27 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) G:\Windows\system32\jscript9.dll 2015-03-12 09:27 - 2015-02-20 04:26 - 00968704 _____ (Microsoft Corporation) G:\Windows\system32\MsSpellCheckingFacility.exe 2015-03-12 09:27 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.tlb 2015-03-12 09:27 - 2015-02-20 04:22 - 00490496 _____ (Microsoft Corporation) G:\Windows\system32\dxtmsft.dll 2015-03-12 09:27 - 2015-02-20 04:13 - 00077824 _____ (Microsoft Corporation) G:\Windows\system32\JavaScriptCollectionAgent.dll 2015-03-12 09:27 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) G:\Windows\SysWOW64\vbscript.dll 2015-03-12 09:27 - 2015-02-20 04:08 - 00199680 _____ (Microsoft Corporation) G:\Windows\system32\msrating.dll 2015-03-12 09:27 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iesetup.dll 2015-03-12 09:27 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieetwproxystub.dll 2015-03-12 09:27 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) G:\Windows\SysWOW64\MshtmlDac.dll 2015-03-12 09:27 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) G:\Windows\system32\dxtrans.dll 2015-03-12 09:27 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iertutil.dll 2015-03-12 09:27 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jsproxy.dll 2015-03-12 09:27 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iernonce.dll 2015-03-12 09:27 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieui.dll 2015-03-12 09:27 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9diag.dll 2015-03-12 09:27 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieUnatt.exe 2015-03-12 09:27 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) G:\Windows\system32\msfeeds.dll 2015-03-12 09:27 - 2015-02-20 03:49 - 00718848 _____ (Microsoft Corporation) G:\Windows\system32\ie4uinit.exe 2015-03-12 09:27 - 2015-02-20 03:47 - 01359360 _____ (Microsoft Corporation) G:\Windows\system32\mshtmlmedia.dll 2015-03-12 09:27 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) G:\Windows\system32\inetcpl.cpl 2015-03-12 09:27 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) G:\Windows\system32\ieframe.dll 2015-03-12 09:27 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-03-12 09:27 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msrating.dll 2015-03-12 09:27 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9.dll 2015-03-12 09:27 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) G:\Windows\system32\wininet.dll 2015-03-12 09:27 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) G:\Windows\SysWOW64\inetcpl.cpl 2015-03-12 09:27 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msfeeds.dll 2015-03-12 09:27 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmlmedia.dll 2015-03-12 09:27 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) G:\Windows\system32\urlmon.dll 2015-03-12 09:27 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) G:\Windows\system32\ieapfltr.dll 2015-03-12 09:27 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wininet.dll 2015-03-12 09:27 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) G:\Windows\SysWOW64\urlmon.dll 2015-03-12 09:27 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieapfltr.dll 2015-03-12 09:27 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) G:\Windows\SysWOW64\shell32.dll 2015-03-12 09:27 - 2015-02-13 07:22 - 14177280 _____ (Microsoft Corporation) G:\Windows\system32\shell32.dll 2015-03-12 09:27 - 2015-02-03 05:31 - 01424896 _____ (Microsoft Corporation) G:\Windows\system32\WindowsCodecs.dll 2015-03-12 09:27 - 2015-02-03 05:31 - 00215552 _____ (Microsoft Corporation) G:\Windows\system32\ubpm.dll 2015-03-12 09:27 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WindowsCodecs.dll 2015-03-12 09:27 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ubpm.dll 2015-03-12 09:27 - 2015-01-31 05:48 - 03179520 _____ (Microsoft Corporation) G:\Windows\system32\rdpcorets.dll 2015-03-12 09:27 - 2015-01-31 05:48 - 00016384 _____ (Microsoft Corporation) G:\Windows\system32\RdpGroupPolicyExtension.dll 2015-03-12 09:27 - 2015-01-31 01:56 - 00459336 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\cng.sys 2015-03-12 09:27 - 2015-01-31 01:56 - 00243200 _____ (Microsoft Corporation) G:\Windows\system32\rdpudd.dll 2015-03-12 09:27 - 2015-01-17 04:48 - 01067520 _____ (Microsoft Corporation) G:\Windows\system32\msctf.dll 2015-03-12 09:27 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msctf.dll 2015-03-12 09:26 - 2015-02-26 05:25 - 03204096 _____ (Microsoft Corporation) G:\Windows\system32\win32k.sys 2015-03-12 09:26 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) G:\Windows\system32\WMPhoto.dll 2015-03-12 09:26 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WMPhoto.dll 2015-03-10 01:20 - 2015-03-10 01:20 - 00001002 _____ () G:\Users\mse13ssd\Downloads\BAHN_Fahrplan_20150609.ics 2015-03-09 11:16 - 2015-03-09 11:56 - 124202474 _____ () G:\Users\mse13ssd\Downloads\#0325#.rar 2015-03-08 09:43 - 2015-03-08 09:43 - 01230365 _____ () G:\Users\mse13ssd\Downloads\2 (1).wmv 2015-03-08 09:43 - 2015-03-08 09:43 - 01222357 _____ () G:\Users\mse13ssd\Downloads\3.wmv ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-07 10:17 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-07 10:17 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-07 10:14 - 2014-05-17 10:22 - 01439466 _____ () G:\Windows\WindowsUpdate.log 2015-04-07 10:14 - 2009-07-14 19:58 - 00700986 _____ () G:\Windows\system32\perfh007.dat 2015-04-07 10:14 - 2009-07-14 19:58 - 00149886 _____ () G:\Windows\system32\perfc007.dat 2015-04-07 10:14 - 2009-07-14 07:13 - 01619284 _____ () G:\Windows\system32\PerfStringBackup.INI 2015-04-07 10:10 - 2014-07-13 00:21 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Raptr 2015-04-07 10:10 - 2014-05-17 22:03 - 00000000 _____ () G:\Windows\system32\Drivers\lvuvc.hs 2015-04-07 10:10 - 2014-05-17 15:57 - 00004182 _____ () G:\Windows\System32\Tasks\avast! Emergency Update 2015-04-07 10:10 - 2009-07-14 07:08 - 00000006 ____H () G:\Windows\Tasks\SA.DAT 2015-04-07 10:10 - 2009-07-14 06:51 - 00055803 _____ () G:\Windows\setupact.log 2015-04-06 21:07 - 2014-05-17 20:13 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\TS3Client 2015-04-06 20:32 - 2014-05-17 22:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Skype 2015-04-06 19:55 - 2014-05-17 15:20 - 00033556 _____ () G:\Windows\PFRO.log 2015-04-05 20:55 - 2014-05-17 12:27 - 00000000 ____D () G:\Program Files (x86)\SRWare Iron 2015-04-05 18:19 - 2015-03-05 14:19 - 00129752 _____ (Malwarebytes Corporation) G:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-04-05 15:10 - 2009-07-14 05:20 - 00000000 __RHD () G:\Users\Default 2015-04-05 15:09 - 2009-07-14 04:34 - 00000215 _____ () G:\Windows\system.ini 2015-04-05 13:19 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\NDF 2015-04-05 12:59 - 2014-05-17 11:54 - 00000000 ____D () G:\Users\mse13ssd 2015-04-05 03:26 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\Web 2015-04-02 01:34 - 2009-07-14 07:32 - 00000000 ____D () G:\Windows\system32\FxsTmp 2015-03-30 17:36 - 2015-02-28 05:38 - 00000000 ____D () G:\Users\mse13ssd\Desktop\aufgeräumt 2015-03-30 08:10 - 2014-11-01 08:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\25372 2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\DivX 2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX 2015-03-30 04:33 - 2014-08-24 02:00 - 00000000 ____D () G:\ProgramData\DivX 2015-03-30 04:33 - 2014-05-17 15:57 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast 2015-03-30 04:33 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\AppCompat 2015-03-30 04:32 - 2014-08-24 02:01 - 00000000 ____D () G:\Program Files\DivX 2015-03-30 04:32 - 2014-08-24 02:00 - 00000000 ____D () G:\Program Files (x86)\DivX 2015-03-30 04:32 - 2014-06-18 17:31 - 00000000 ____D () G:\Program Files (x86)\Microsoft Office 2015-03-30 04:32 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\registration 2015-03-30 03:27 - 2009-07-14 20:18 - 00000000 ___RD () G:\Users\Public\Recorded TV 2015-03-26 21:20 - 2014-10-12 12:01 - 00000000 ____D () G:\Windows\Minidump 2015-03-26 18:51 - 2014-07-13 00:21 - 00000000 ____D () G:\Program Files (x86)\Raptr 2015-03-26 09:13 - 2014-06-18 17:31 - 00000000 ____D () G:\ProgramData\Microsoft Help 2015-03-22 18:29 - 2014-05-17 12:40 - 00070368 _____ () G:\Users\mse13ssd\AppData\Local\GDIPFONTCACHEV1.DAT 2015-03-22 18:29 - 2009-07-14 06:45 - 00307752 _____ () G:\Windows\system32\FNTCACHE.DAT 2015-03-22 18:25 - 2014-06-18 17:32 - 00000000 ____D () G:\Program Files (x86)\Microsoft Works 2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Google 2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Program Files (x86)\Google 2015-03-15 14:09 - 2014-08-24 13:49 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Adobe 2015-03-15 14:09 - 2014-05-17 15:53 - 00778928 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerApp.exe 2015-03-15 14:09 - 2014-05-17 15:53 - 00142512 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-03-15 05:05 - 2014-06-21 18:28 - 00000000 ____D () G:\Program Files (x86)\Steam 2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Glyph 2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glyph 2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Program Files (x86)\Glyph 2015-03-13 10:32 - 2009-07-14 07:09 - 00000000 ____D () G:\Windows\System32\Tasks\WPD 2015-03-12 12:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\rescache 2015-03-12 09:37 - 2015-02-28 09:01 - 00000000 ___RD () G:\Users\mse13ssd\Virtual Machines 2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\SysWOW64\Dism 2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\Dism 2015-03-12 09:31 - 2014-05-17 20:36 - 00000000 ____D () G:\Windows\system32\MRT 2015-03-12 09:29 - 2014-05-17 20:36 - 122905848 _____ (Microsoft Corporation) G:\Windows\system32\MRT.exe ==================== Files in the root of some directories ======= 2014-10-02 16:29 - 2015-02-28 12:40 - 14286848 _____ () G:\Users\mse13ssd\AppData\Roaming\Sandra.mdb 2015-01-23 13:40 - 2015-01-23 13:40 - 0003584 _____ () G:\Users\mse13ssd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-01-01 14:58 - 2015-01-01 14:58 - 0007605 _____ () G:\Users\mse13ssd\AppData\Local\Resmon.ResmonCfg Some content of TEMP: ==================== G:\Users\mse13ssd\AppData\Local\Temp\Quarantine.exe G:\Users\mse13ssd\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) G:\Windows\System32\winlogon.exe => File is digitally signed G:\Windows\System32\wininit.exe => File is digitally signed G:\Windows\SysWOW64\wininit.exe => File is digitally signed G:\Windows\explorer.exe => File is digitally signed G:\Windows\SysWOW64\explorer.exe => File is digitally signed G:\Windows\System32\svchost.exe => File is digitally signed G:\Windows\SysWOW64\svchost.exe => File is digitally signed G:\Windows\System32\services.exe => File is digitally signed G:\Windows\System32\User32.dll => File is digitally signed G:\Windows\SysWOW64\User32.dll => File is digitally signed G:\Windows\System32\userinit.exe => File is digitally signed G:\Windows\SysWOW64\userinit.exe => File is digitally signed G:\Windows\System32\rpcss.dll => File is digitally signed G:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-04-04 00:45 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015 Ran by mse13ssd at 2015-04-07 10:36:50 Running from G:\Users\mse13ssd\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) AGEIA PhysX v7.11.13 (HKLM-x32\...\{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}) (Version: 7.11.13 - AGEIA Technologies, Inc.) Agent Ransack x64 (HKLM\...\{58C0AC50-8FA1-4A95-AEC6-5B2727E5CC6A}) (Version: 7.0.820.1 - Mythicsoft Ltd) AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) Apple Application Support (HKLM-x32\...\{122ADF8C-DDA1-480C-9936-C88F2825B265}) (Version: 2.1.9 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}) (Version: 5.2.0.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Archeage (HKLM-x32\...\Glyph Archeage) (Version: - Trion Worlds, Inc.) ArtMoney SE v7.43 (HKLM-x32\...\ArtMoney SE_is1) (Version: 7.43 - System SoftLab) avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software) Avery Wizard 5.0 (HKLM-x32\...\{FC3B3A5D-7058-4627-9F1E-F95CC38B6054}) (Version: 5.0.5 - Avery) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software) Canon iP7200 series Benutzerregistrierung (HKLM-x32\...\Canon iP7200 series Benutzerregistrierung) (Version: - Canon Inc.) Canon iP7200 series Printer Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP7200_series) (Version: - Canon Inc.) Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - ) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.0.0 - Canon Inc.) CanoScan LiDE 110 Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2414) (Version: - Canon Inc.) ClipboardManager 1.6 (HKLM-x32\...\ClipboardManager_is1) (Version: - ) Contract Jack (HKLM-x32\...\{374CAB30-2F61-4439-9A4A-24D3AEA2960A}) (Version: - ) CPUID CPU-Z 1.70 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) Die Siedler II - Die nächste Generation (HKLM-x32\...\S2TNG) (Version: - ) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.7.0.31 - DivX, LLC) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Free YouTube Download version 3.2.53.128 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.53.128 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.50.1111 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.50.1111 - DVDVideoSoft Ltd.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden GUILD WARS (HKLM-x32\...\Guild Wars) (Version: - ) iTunes (HKLM\...\{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}) (Version: 10.6.3.25 - Apple Inc.) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) Logitech Gaming Software 8.55 (HKLM\...\Logitech Gaming Software) (Version: 8.55.137 - Logitech Inc.) Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Mozilla Firefox 36.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 36.0 (x86 de)) (Version: 36.0 - Mozilla) paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC) Pamela Pro 4.9 (HKLM-x32\...\Pamela) (Version: 4.9 - PamConsult GmbH) PDF Architect 2 Create Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.0 - pdfforge) Raptr (HKLM-x32\...\Raptr) (Version: - ) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) SciLor's grooveshark™.com Downloader 0.4.15 (HKLM-x32\...\{DDEAE484-D5FB-49CB-BD47-9512E8ACCA65}_is1) (Version: 0.4.15 - SciLor) SiSoftware Sandra Lite 2014.SP3c (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2496}_is1) (Version: 20.47.2014.10 - SiSoftware) Skype™ 7.1 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.) SRWare Iron Version SRWare Iron 39.2100.0 (HKLM-x32\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: SRWare Iron 39.2100.0 - SRWare) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden Windows Phone app for desktop (HKLM-x32\...\{19773614-FC22-4ACC-AAA3-E6BDA81ACF92}) (Version: 1.1.2726.0 - Microsoft Corporation) WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 01-04-2015 19:32:07 Windows Update 05-04-2015 15:04:11 ComboFix created restore point ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2015-04-05 15:09 - 00000027 ____A G:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {1FC3D3B2-F254-4B57-9695-FFF62B3AC150} - System32\Tasks\GoogleUpdateTaskMachineCore => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15] (Google Inc.) Task: {34D4B971-AD1B-4F8D-8ED4-6F6BF7ABE60D} - System32\Tasks\avast! Emergency Update => G:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-07-15] (AVAST Software) Task: {BD6EFB7D-29B9-4725-B4CB-C2F47B685F42} - System32\Tasks\Abelssoft\Updater scan => G:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe Task: {DB431844-F8D5-409D-A115-BB442A487B85} - System32\Tasks\GoogleUpdateTaskMachineUA => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15] (Google Inc.) Task: {E57F8AB1-453C-45BC-BF7F-E700E5C6EBA9} - System32\Tasks\Adobe Acrobat Update Task => G:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2014-07-28 20:29 - 2014-07-28 20:29 - 00866584 _____ () G:\Program Files\Logitech Gaming Software\libGLESv2.dll 2014-07-28 20:32 - 2014-07-28 20:32 - 01050904 _____ () G:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2014-07-28 20:29 - 2014-07-28 20:29 - 00059160 _____ () G:\Program Files\Logitech Gaming Software\libEGL.dll 2014-07-28 20:31 - 2014-07-28 20:31 - 00242456 _____ () G:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2014-01-10 07:26 - 2014-01-10 07:26 - 01861968 _____ () G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 2014-07-15 08:28 - 2014-07-15 08:28 - 00301152 _____ () G:\Program Files\AVAST Software\Avast\aswProperty.dll 2015-04-06 19:56 - 2015-04-06 19:56 - 02923520 _____ () G:\Program Files\AVAST Software\Avast\defs\15040601\algo.dll 2015-04-07 10:10 - 2015-04-07 10:10 - 02923520 _____ () G:\Program Files\AVAST Software\Avast\defs\15040700\algo.dll 2012-05-30 20:06 - 2012-05-30 20:06 - 00087912 _____ () G:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2012-05-30 20:06 - 2012-05-30 20:06 - 01242512 _____ () G:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-07-15 08:28 - 2014-07-15 08:28 - 19329904 _____ () G:\Program Files\AVAST Software\Avast\libcef.dll 2014-01-10 07:28 - 2014-01-10 07:28 - 00100688 _____ () G:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2014-05-17 12:27 - 2014-12-05 20:30 - 01359360 _____ () G:\Program Files (x86)\SRWare Iron\libglesv2.dll 2014-05-17 12:27 - 2014-12-05 20:31 - 00212992 _____ () G:\Program Files (x86)\SRWare Iron\libegl.dll 2015-01-08 21:01 - 2014-12-05 20:53 - 09299968 _____ () G:\Program Files (x86)\SRWare Iron\pdf.dll 2014-05-17 12:27 - 2014-12-05 20:32 - 00984576 _____ () G:\Program Files (x86)\SRWare Iron\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: G:\Users\mse13ssd\Downloads\email_5937_20150205205259.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Control Panel\Desktop\\Wallpaper -> G:\Users\mse13ssd\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.0.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: bthserv => 3 MSCONFIG\Services: DPS => 2 MSCONFIG\Services: SensrSvc => 3 MSCONFIG\startupreg: Adobe ARM => "G:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: APSDaemon => "G:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: iTunesHelper => "G:\Program Files (x86)\iTunes\iTunesHelper.exe" ==================== Accounts: ============================= Administrator (S-1-5-21-3243151774-2580435505-251407729-500 - Administrator - Disabled) Gast (S-1-5-21-3243151774-2580435505-251407729-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3243151774-2580435505-251407729-1002 - Limited - Enabled) mse13ssd (S-1-5-21-3243151774-2580435505-251407729-1001 - Administrator - Enabled) => G:\Users\mse13ssd ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/07/2015 10:10:33 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x5cc Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 Error: (04/07/2015 03:22:38 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x514 Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 Error: (04/07/2015 00:47:54 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/06/2015 07:59:18 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/06/2015 07:55:51 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x50c Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 Error: (04/06/2015 05:50:49 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/06/2015 05:44:22 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/06/2015 05:27:33 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. System errors: ============= Error: (04/07/2015 10:10:38 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (04/07/2015 10:10:12 AM) (Source: Ntfs) (EventID: 137) (User: ) Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (04/07/2015 03:22:44 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (04/07/2015 03:22:17 AM) (Source: Ntfs) (EventID: 137) (User: ) Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (04/06/2015 07:55:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (04/06/2015 07:55:30 PM) (Source: Ntfs) (EventID: 137) (User: ) Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (04/06/2015 10:14:00 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz Percentage of memory in use: 14% Total physical RAM: 16384 MB Available physical RAM: 14004.36 MB Total Pagefile: 32766.19 MB Available Pagefile: 30072.39 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.5 GB) (Free:737.58 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:0.01 GB) (Free:0 GB) NTFS Drive f: (Nolf2xp_1) (CDROM) (Total:0.64 GB) (Free:0 GB) CDFS Drive g: (SSD) (Fixed) (Total:119.24 GB) (Free:25.03 GB) NTFS Drive m: (SAMSUNG) (Fixed) (Total:1396.92 GB) (Free:834.32 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: 7E008421) Partition 1: (Active) - (Size=119.2 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 1CA61CA5) Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=7 MB) - (Type=07 NTFS) ======================================================== Disk: 6 (Size: 1397.3 GB) (Disk ID: 5C9C6FA9) Partition 1: (Not Active) - (Size=1397.3 GB) - (Type=0C) ==================== End Of Log ============================ Und keine Probleme mehr! Vielen lieben Dank! LG, Hendrik Sander |
07.04.2015, 17:37 | #8 |
/// the machine /// TB-Ausbilder | Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen Java updaten. Revo Uninstaller - Download - Filepony damit Chrome deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.google.com/chrome/answer/3296214?hl=de Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe C:\Documents and Settings\mse13\AppData\Local\Temp\ct3297265\ism.exe C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Documents and Settings\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe C:\Documents and Settings\mse13\Downloads\Der_knallharte_Prinzipal.exe C:\Documents and Settings\mse13\Downloads\jZipSetup-r113-n-bc.exe C:\Documents and Settings\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe C:\Documents and Settings\mse13\Downloads\Raidcall_TSV45QFV6.exe C:\Documents and Settings\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe C:\Documents and Settings\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe C:\Documents and Settings\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\ct3297265\ism.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Dokumente und Einstellungen\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe C:\Dokumente und Einstellungen\mse13\Downloads\Der_knallharte_Prinzipal.exe C:\Dokumente und Einstellungen\mse13\Downloads\jZipSetup-r113-n-bc.exe C:\Dokumente und Einstellungen\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe C:\Dokumente und Einstellungen\mse13\Downloads\Raidcall_TSV45QFV6.exe C:\Dokumente und Einstellungen\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe C:\Dokumente und Einstellungen\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe C:\Dokumente und Einstellungen\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe C:\Program Files (x86)\HDvid-Codec V9.0\51356.crx C:\Program Files (x86)\HDvid-Codec V9.0\51356.xpi C:\Program Files (x86)\Iminent\inst\Bootstrapper\IminentUninstall.exe C:\Users\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe C:\Users\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe C:\Users\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe C:\Users\mse13\AppData\Local\Temp\ct3297265\ism.exe C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Users\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe C:\Users\mse13\Downloads\Der_knallharte_Prinzipal.exe C:\Users\mse13\Downloads\jZipSetup-r113-n-bc.exe C:\Users\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe C:\Users\mse13\Downloads\Raidcall_TSV45QFV6.exe C:\Users\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe C:\Users\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe C:\Users\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe C:\Users\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe G:\AdwCleaner\Quarantine\G\Users\mse13ssd\AppData\Local\Temp\OCS\ocs_v71b.exe.vir G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\File System\002\t\00\00000000 G:\Users\mse13ssd\Downloads\Griffith - CHIP-Installer.exe G:\Users\mse13ssd\Downloads\PDFCreator-2_0_0-setup.exe G:\Users\mse13ssd\Downloads\ZustellnachrichtDHL_bestellung_000029937728.zip Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0 Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.04.2015, 09:39 | #9 |
| Win 7: konnte ShopGlider Deals bis jetzt nicht entfernenCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015 Ran by mse13ssd at 2015-04-08 08:10:14 Run:1 Running from G:\Users\mse13ssd\Desktop Loaded Profiles: mse13ssd (Available profiles: mse13ssd) Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe C:\Documents and Settings\mse13\AppData\Local\Temp\ct3297265\ism.exe C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Documents and Settings\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe C:\Documents and Settings\mse13\Downloads\Der_knallharte_Prinzipal.exe C:\Documents and Settings\mse13\Downloads\jZipSetup-r113-n-bc.exe C:\Documents and Settings\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe C:\Documents and Settings\mse13\Downloads\Raidcall_TSV45QFV6.exe C:\Documents and Settings\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe C:\Documents and Settings\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe C:\Documents and Settings\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\ct3297265\ism.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Dokumente und Einstellungen\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe C:\Dokumente und Einstellungen\mse13\Downloads\Der_knallharte_Prinzipal.exe C:\Dokumente und Einstellungen\mse13\Downloads\jZipSetup-r113-n-bc.exe C:\Dokumente und Einstellungen\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe C:\Dokumente und Einstellungen\mse13\Downloads\Raidcall_TSV45QFV6.exe C:\Dokumente und Einstellungen\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe C:\Dokumente und Einstellungen\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe C:\Dokumente und Einstellungen\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe C:\Program Files (x86)\HDvid-Codec V9.0\51356.crx C:\Program Files (x86)\HDvid-Codec V9.0\51356.xpi C:\Program Files (x86)\Iminent\inst\Bootstrapper\IminentUninstall.exe C:\Users\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe C:\Users\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe C:\Users\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe C:\Users\mse13\AppData\Local\Temp\ct3297265\ism.exe C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe C:\Users\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe C:\Users\mse13\Downloads\Der_knallharte_Prinzipal.exe C:\Users\mse13\Downloads\jZipSetup-r113-n-bc.exe C:\Users\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe C:\Users\mse13\Downloads\Raidcall_TSV45QFV6.exe C:\Users\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe C:\Users\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe C:\Users\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe C:\Users\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe G:\AdwCleaner\Quarantine\G\Users\mse13ssd\AppData\Local\Temp\OCS\ocs_v71b.exe.vir G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\File System\002\t\00\00000000 G:\Users\mse13ssd\Downloads\Griffith - CHIP-Installer.exe G:\Users\mse13ssd\Downloads\PDFCreator-2_0_0-setup.exe G:\Users\mse13ssd\Downloads\ZustellnachrichtDHL_bestellung_000029937728.zip Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0 Emptytemp: ***************** C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe => Moved successfully. C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe => Moved successfully. C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe => Moved successfully. C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe => Moved successfully. C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll => Moved successfully. C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll => Moved successfully. C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe => Moved successfully. C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe => Moved successfully. "C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe" => File/Directory not found. "C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe" => File/Directory not found. "C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe" => File/Directory not found. "C:\Documents and Settings\mse13\AppData\Local\Temp\ct3297265\ism.exe" => File/Directory not found. "C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll" => File/Directory not found. "C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll" => File/Directory not found. "C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe" => File/Directory not found. "C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe" => File/Directory not found. C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe => Moved successfully. C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi => Moved successfully. Could not move "C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot. C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi => Moved successfully. Could not move "C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot. C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi => Moved successfully. Could not move "C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot. C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi => Moved successfully. C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Moved successfully. Could not move "C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => Scheduled to move on reboot. Could not move "C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot. C:\Documents and Settings\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe => Moved successfully. C:\Documents and Settings\mse13\Downloads\Der_knallharte_Prinzipal.exe => Moved successfully. C:\Documents and Settings\mse13\Downloads\jZipSetup-r113-n-bc.exe => Moved successfully. C:\Documents and Settings\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe => Moved successfully. C:\Documents and Settings\mse13\Downloads\Raidcall_TSV45QFV6.exe => Moved successfully. C:\Documents and Settings\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe => Moved successfully. C:\Documents and Settings\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe => Moved successfully. C:\Documents and Settings\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe => Moved successfully. "C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe" => File/Directory not found. "C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe" => File/Directory not found. "C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe" => File/Directory not found. "C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe" => File/Directory not found. "C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll" => File/Directory not found. "C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll" => File/Directory not found. "C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe" => File/Directory not found. "C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\ct3297265\ism.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found. Could not move "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot. "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found. Could not move "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot. "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found. Could not move "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot. "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => File/Directory not found. Could not move "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => Scheduled to move on reboot. Could not move "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot. "C:\Dokumente und Einstellungen\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Downloads\Der_knallharte_Prinzipal.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Downloads\jZipSetup-r113-n-bc.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Downloads\Raidcall_TSV45QFV6.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe" => File/Directory not found. "C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe" => File/Directory not found. C:\Program Files (x86)\HDvid-Codec V9.0\51356.crx => Moved successfully. C:\Program Files (x86)\HDvid-Codec V9.0\51356.xpi => Moved successfully. C:\Program Files (x86)\Iminent\inst\Bootstrapper\IminentUninstall.exe => Moved successfully. "C:\Users\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe" => File/Directory not found. "C:\Users\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe" => File/Directory not found. "C:\Users\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe" => File/Directory not found. "C:\Users\mse13\AppData\Local\Temp\ct3297265\ism.exe" => File/Directory not found. "C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll" => File/Directory not found. "C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll" => File/Directory not found. "C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe" => File/Directory not found. "C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe" => File/Directory not found. "C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe" => File/Directory not found. "C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found. C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Moved successfully. "C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found. C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Moved successfully. "C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found. C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Moved successfully. "C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found. "C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => File/Directory not found. C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi => Moved successfully. C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Moved successfully. "C:\Users\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe" => File/Directory not found. "C:\Users\mse13\Downloads\Der_knallharte_Prinzipal.exe" => File/Directory not found. "C:\Users\mse13\Downloads\jZipSetup-r113-n-bc.exe" => File/Directory not found. "C:\Users\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe" => File/Directory not found. "C:\Users\mse13\Downloads\Raidcall_TSV45QFV6.exe" => File/Directory not found. "C:\Users\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe" => File/Directory not found. "C:\Users\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe" => File/Directory not found. "C:\Users\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe" => File/Directory not found. "C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe" => File/Directory not found. "C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe" => File/Directory not found. "C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe" => File/Directory not found. "C:\Users\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe" => File/Directory not found. "C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll" => File/Directory not found. "C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll" => File/Directory not found. "C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe" => File/Directory not found. "C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe" => File/Directory not found. G:\AdwCleaner\Quarantine\G\Users\mse13ssd\AppData\Local\Temp\OCS\ocs_v71b.exe.vir => Moved successfully. "G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\File System\002\t\00\00000000" => File/Directory not found. G:\Users\mse13ssd\Downloads\Griffith - CHIP-Installer.exe => Moved successfully. G:\Users\mse13ssd\Downloads\PDFCreator-2_0_0-setup.exe => Moved successfully. G:\Users\mse13ssd\Downloads\ZustellnachrichtDHL_bestellung_000029937728.zip => Moved successfully. HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer => value deleted successfully. EmptyTemp: => Removed 647.4 MB temporary data. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-04-08 08:12:55)<= C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully. C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully. C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully. C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi => Is moved successfully. C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully. C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully. C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully. C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully. C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi => Is moved successfully. C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully. ==== End of Fixlog 08:12:56 ==== FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Ran by mse13ssd (administrator) on MSE13SSD-PC on 08-04-2015 10:35:24 Running from G:\Users\mse13ssd\Desktop Loaded Profiles: mse13ssd (Available profiles: mse13ssd) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) G:\Windows\System32\atiesrxx.exe (Logitech Inc.) G:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (AVAST Software) G:\Program Files\AVAST Software\Avast\AvastSvc.exe (AMD) G:\Windows\System32\atieclxx.exe (Apple Inc.) G:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) G:\Program Files\Bonjour\mDNSResponder.exe (Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe (Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe (Logitech Inc.) G:\Program Files\Logitech Gaming Software\LCore.exe (Microsoft Corporation) G:\Program Files\Windows Sidebar\sidebar.exe (AVAST Software) G:\Program Files\AVAST Software\Avast\avastui.exe () G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Advanced Micro Devices Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe (Microsoft Corporation) G:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Launch LCore] => G:\Program Files\Logitech Gaming Software\LCore.exe [10801944 2014-07-28] (Logitech Inc.) HKLM-x32\...\Run: [AvastUI.exe] => G:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software) HKLM-x32\...\Run: [DivXMediaServer] => G:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC) HKLM-x32\...\Run: [DivXUpdate] => G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM-x32\...\Run: [StartCCC] => G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Raptr] => G:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-03-25] (Raptr, Inc) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => G:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-3243151774-2580435505-251407729-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-15] (AVAST Software) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-04-08] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-15] (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-04-08] (Oracle Corporation) Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - G:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll [2014-10-10] (pdfforge GmbH) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0 FireFox: ======== FF ProfilePath: G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default FF Plugin: @adobe.com/FlashPlayer -> G:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-15] () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> G:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-15] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> G:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2012-04-05] () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> G:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> G:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-04-08] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> G:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-04-08] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> G:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.) FF Plugin-x32: Adobe Reader -> G:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.) FF Extension: Download videos and MP3s from YouTube - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-11-21] FF Extension: Adblock Plus - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-09] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - G:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - G:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-17] FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension FF Extension: PDF Architect 2 Creator - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2014-12-09] FF HKU\S-1-5-21-3243151774-2580435505-251407729-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff FF Extension: Download videos and MP3s from YouTube - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-11-21] Chrome: ======= Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION CHR Profile: G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-09] CHR Extension: (Google Docs) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-09] CHR Extension: (Google Drive) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-09] CHR Extension: (Google Voice Search Hotword (Beta)) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-09] CHR Extension: (YouTube) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-09] CHR Extension: (Google Search) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-09] CHR Extension: (Google Sheets) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-09] CHR Extension: (Google Wallet) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-09] CHR Extension: (Gmail) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-09] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - G:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-15] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; G:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-15] (AVAST Software) S2 PDF Architect 2 Creator; G:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH) S3 SandraAgentSrv; G:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3c\RpcAgentSrv.exe [73712 2014-09-19] (SiSoftware) [File not signed] R2 WinDefend; G:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; G:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 aswHwid; G:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-15] () R2 aswMonFlt; G:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-15] (AVAST Software) R1 aswRdr; G:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-15] (AVAST Software) R0 aswRvrt; G:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-15] () R1 aswSnx; G:\Windows\system32\drivers\aswSnx.sys [1041168 2014-11-21] (AVAST Software) R1 aswSP; G:\Windows\system32\drivers\aswSP.sys [427360 2014-07-15] (AVAST Software) R2 aswStm; G:\Windows\system32\drivers\aswStm.sys [92008 2014-07-15] (AVAST Software) R0 aswVmm; G:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-15] () R3 LGSHidFilt; G:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) S3 catchme; \??\G:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-08 10:35 - 2015-04-08 10:35 - 00012107 _____ () G:\Users\mse13ssd\Desktop\FRST.txt 2015-04-08 07:54 - 2015-04-08 07:54 - 00001019 _____ () G:\Users\Public\Desktop\SRWare Iron.lnk 2015-04-08 07:54 - 2015-04-08 07:54 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\SRWare Iron 2015-04-08 07:54 - 2015-04-08 07:54 - 00000000 ____D () G:\Program Files (x86)\SRWare Iron 2015-04-08 07:51 - 2015-04-08 07:51 - 44832392 _____ (SRWare ) G:\Users\mse13ssd\Downloads\srware_iron(2).exe 2015-04-08 07:49 - 2015-04-08 07:49 - 44827361 _____ (SRWare ) G:\Users\mse13ssd\Downloads\srware_iron(1).exe 2015-04-08 06:14 - 2015-04-08 06:14 - 00001267 _____ () G:\Users\mse13ssd\Desktop\Revo Uninstaller.lnk 2015-04-08 06:12 - 2015-04-08 06:12 - 02623656 _____ (VS Revo Group Ltd.) G:\Users\mse13ssd\Downloads\revosetup95.exe 2015-04-07 10:44 - 2015-04-07 10:44 - 00000000 ___SD () G:\Windows\SysWOW64\GWX 2015-04-07 10:44 - 2015-04-07 10:44 - 00000000 ___SD () G:\Windows\system32\GWX 2015-04-07 10:26 - 2015-04-07 10:26 - 00852607 _____ () G:\Users\mse13ssd\Downloads\SecurityCheck (2).exe 2015-04-07 10:19 - 2015-04-07 10:19 - 00008930 _____ () G:\Users\mse13ssd\Downloads\smime (2).p7s 2015-04-06 19:59 - 2015-04-06 19:59 - 02347384 _____ (ESET) G:\Users\mse13ssd\Downloads\esetsmartinstaller_deu (1).exe 2015-04-06 17:43 - 2015-04-06 17:43 - 00852607 _____ () G:\Users\mse13ssd\Downloads\SecurityCheck (1).exe 2015-04-06 17:41 - 2015-04-06 17:41 - 00852607 _____ () G:\Users\mse13ssd\Downloads\SecurityCheck.exe 2015-04-06 12:27 - 2015-04-06 12:27 - 02347384 _____ (ESET) G:\Users\mse13ssd\Downloads\esetsmartinstaller_deu.exe 2015-04-06 12:27 - 2015-04-06 12:27 - 00000000 ____D () G:\Program Files (x86)\ESET 2015-04-05 19:33 - 2015-04-05 19:33 - 00000207 _____ () G:\Windows\tweaking.com-regbackup-MSE13SSD-PC-Windows-7-Home-Premium-(64-bit).dat 2015-04-05 19:33 - 2015-04-05 19:33 - 00000000 ____D () G:\RegBackup 2015-04-05 18:35 - 2015-04-05 18:35 - 02690981 _____ (Thisisu) G:\Users\mse13ssd\Desktop\JRT.exe 2015-04-05 15:10 - 2015-04-05 15:10 - 00011639 _____ () G:\ComboFix.txt 2015-04-05 15:03 - 2015-04-05 15:10 - 00000000 ____D () G:\Qoobox 2015-04-05 15:03 - 2015-04-05 15:09 - 00000000 ____D () G:\Windows\erdnt 2015-04-05 15:03 - 2011-06-26 08:45 - 00256000 _____ () G:\Windows\PEV.exe 2015-04-05 15:03 - 2010-11-07 19:20 - 00208896 _____ () G:\Windows\MBR.exe 2015-04-05 15:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) G:\Windows\NIRCMD.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) G:\Windows\SWREG.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) G:\Windows\SWSC.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00098816 _____ () G:\Windows\sed.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00080412 _____ () G:\Windows\grep.exe 2015-04-05 15:03 - 2000-08-31 02:00 - 00068096 _____ () G:\Windows\zip.exe 2015-04-05 15:01 - 2015-04-05 15:01 - 05617096 ____R (Swearware) G:\Users\mse13ssd\Desktop\ComboFix.exe 2015-04-05 13:10 - 2015-04-05 13:11 - 00380416 _____ () G:\Users\mse13ssd\Downloads\liqvrrec.exe 2015-04-05 13:02 - 2015-04-08 10:35 - 00000000 ____D () G:\FRST 2015-04-05 13:02 - 2015-04-05 13:03 - 00048734 _____ () G:\Users\mse13ssd\Downloads\FRST.txt 2015-04-05 13:02 - 2015-04-05 13:03 - 00024876 _____ () G:\Users\mse13ssd\Downloads\Addition.txt 2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Downloads\FRST64 (1).exe 2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Desktop\FRST64.exe 2015-04-05 12:59 - 2015-04-05 12:59 - 00000478 _____ () G:\Users\mse13ssd\Downloads\defogger_disable.log 2015-04-05 12:59 - 2015-04-05 12:59 - 00000000 _____ () G:\Users\mse13ssd\defogger_reenable 2015-04-05 12:57 - 2015-04-05 12:57 - 00050477 _____ () G:\Users\mse13ssd\Downloads\Defogger.exe 2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (2).exe 2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (1).exe 2015-04-05 03:38 - 2015-04-05 18:38 - 00000000 ____D () G:\AdwCleaner 2015-04-05 03:37 - 2015-04-05 03:38 - 02208768 _____ () G:\Users\mse13ssd\Desktop\adwcleaner_4.200.exe 2015-03-31 05:26 - 2015-03-31 05:26 - 00008930 _____ () G:\Users\mse13ssd\Downloads\smime (1).p7s 2015-03-28 00:47 - 2015-03-28 00:47 - 00012288 _____ () G:\Users\mse13ssd\Downloads\Qual-Fraktal.xls 2015-03-27 07:14 - 2015-03-27 07:14 - 00000000 ____D () G:\Users\mse13ssd\Desktop\SciLor's Grooveshark.com Downloader 2015-03-26 21:20 - 2015-03-26 21:20 - 671367548 _____ () G:\Windows\MEMORY.DMP 2015-03-26 21:20 - 2015-03-26 21:20 - 00274624 _____ () G:\Windows\Minidump\032615-29718-01.dmp 2015-03-25 04:31 - 2015-03-25 04:31 - 00002123 _____ () G:\Users\Public\Desktop\CONTRACT J.A.C.K. .lnk 2015-03-25 04:05 - 2015-03-25 04:05 - 00000000 ____D () G:\Program Files (x86)\Sierra 2015-03-25 04:04 - 2015-03-25 04:04 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra 2015-03-25 04:00 - 2003-06-26 10:45 - 00499712 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcp71.dll 2015-03-25 04:00 - 2003-06-26 10:45 - 00348160 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcr71.dll 2015-03-25 04:00 - 2003-03-19 07:20 - 01060864 ____N (Microsoft Corporation) G:\Windows\SysWOW64\mfc71.dll 2015-03-22 18:27 - 2015-03-22 18:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in 2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files\Microsoft Silverlight 2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files (x86)\Microsoft Silverlight 2015-03-21 10:33 - 2015-03-21 10:33 - 13087456 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\Silverlight_x64.exe 2015-03-18 17:29 - 2015-03-18 17:29 - 00002023 _____ () G:\Users\mse13ssd\Desktop\Windows Phone-Desktopanwendung.lnk 2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Phone 2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\Program Files (x86)\Windows Phone 2015-03-18 17:25 - 2015-03-18 17:25 - 06745792 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\WindowsPhone.exe 2015-03-18 17:25 - 2015-03-18 17:25 - 00000000 ____D () G:\ProgramData\Applications 2015-03-16 19:19 - 2015-03-16 19:19 - 00001535 _____ () G:\Users\mse13ssd\Free YouTube to MP3 Converter.lnk 2015-03-15 17:32 - 2015-04-08 09:37 - 00001114 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-03-15 17:32 - 2015-04-08 08:12 - 00001110 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-03-15 17:32 - 2015-03-15 17:32 - 00004110 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-03-15 17:32 - 2015-03-15 17:32 - 00003858 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-03-15 17:32 - 2015-03-15 17:32 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2015-03-15 17:31 - 2015-03-15 17:31 - 00880208 _____ (Google Inc.) G:\Users\mse13ssd\Downloads\GoogleEarthSetup.exe 2015-03-14 07:06 - 2015-03-14 07:33 - 82044588 _____ () G:\Users\mse13ssd\Downloads\ES-X_DE.rar.crdownload 2015-03-12 09:28 - 2015-02-03 05:34 - 05554104 _____ (Microsoft Corporation) G:\Windows\system32\ntoskrnl.exe 2015-03-12 09:28 - 2015-02-03 05:34 - 00693176 _____ (Microsoft Corporation) G:\Windows\system32\winload.efi 2015-03-12 09:28 - 2015-02-03 05:34 - 00094656 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\mountmgr.sys 2015-03-12 09:28 - 2015-02-03 05:33 - 00616360 _____ (Microsoft Corporation) G:\Windows\system32\winresume.efi 2015-03-12 09:28 - 2015-02-03 05:31 - 14632960 _____ (Microsoft Corporation) G:\Windows\system32\wmp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 04121600 _____ (Microsoft Corporation) G:\Windows\system32\mf.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 01574400 _____ (Microsoft Corporation) G:\Windows\system32\quartz.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00782848 _____ (Microsoft Corporation) G:\Windows\system32\wmdrmsdk.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00641024 _____ (Microsoft Corporation) G:\Windows\system32\msscp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00503808 _____ (Microsoft Corporation) G:\Windows\system32\srcore.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00500224 _____ (Microsoft Corporation) G:\Windows\system32\AUDIOKSE.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00432128 _____ (Microsoft Corporation) G:\Windows\system32\mfplat.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00371712 _____ (Microsoft Corporation) G:\Windows\system32\qdvd.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00325632 _____ (Microsoft Corporation) G:\Windows\system32\msnetobj.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00229376 _____ (Microsoft Corporation) G:\Windows\system32\wintrust.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00206848 _____ (Microsoft Corporation) G:\Windows\system32\mfps.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00188416 _____ (Microsoft Corporation) G:\Windows\system32\pcasvc.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00063488 _____ (Microsoft Corporation) G:\Windows\system32\setbcdlocale.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00050176 _____ (Microsoft Corporation) G:\Windows\system32\srclient.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00037376 _____ (Microsoft Corporation) G:\Windows\system32\pcadm.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\msmmsp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\spwmp.dll 2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\msdxm.ocx 2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\dxmasf.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 12625920 _____ (Microsoft Corporation) G:\Windows\system32\wmploc.DLL 2015-03-12 09:28 - 2015-02-03 05:30 - 01480192 _____ (Microsoft Corporation) G:\Windows\system32\crypt32.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 01202176 _____ (Microsoft Corporation) G:\Windows\system32\drmv2clt.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 01069056 _____ (Microsoft Corporation) G:\Windows\system32\cryptui.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00842240 _____ (Microsoft Corporation) G:\Windows\system32\blackbox.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00680960 _____ (Microsoft Corporation) G:\Windows\system32\audiosrv.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00631808 _____ (Microsoft Corporation) G:\Windows\system32\evr.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00497664 _____ (Microsoft Corporation) G:\Windows\system32\drmmgrtn.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00440832 _____ (Microsoft Corporation) G:\Windows\system32\AudioEng.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00296960 _____ (Microsoft Corporation) G:\Windows\system32\rstrui.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00296448 _____ (Microsoft Corporation) G:\Windows\system32\AudioSes.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00284672 _____ (Microsoft Corporation) G:\Windows\system32\EncDump.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00187904 _____ (Microsoft Corporation) G:\Windows\system32\cryptsvc.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00146944 _____ (Microsoft Corporation) G:\Windows\system32\appidpolicyconverter.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00140288 _____ (Microsoft Corporation) G:\Windows\system32\cryptnet.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00126464 _____ (Microsoft Corporation) G:\Windows\system32\audiodg.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00112640 _____ (Microsoft Corporation) G:\Windows\system32\smss.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00082432 _____ (Microsoft Corporation) G:\Windows\system32\cryptsp.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00058880 _____ (Microsoft Corporation) G:\Windows\system32\appidapi.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00055808 _____ (Microsoft Corporation) G:\Windows\system32\rrinstaller.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00043520 _____ (Microsoft Corporation) G:\Windows\system32\csrsrv.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00032256 _____ (Microsoft Corporation) G:\Windows\system32\appidsvc.dll 2015-03-12 09:28 - 2015-02-03 05:30 - 00024576 _____ (Microsoft Corporation) G:\Windows\system32\mfpmp.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00017920 _____ (Microsoft Corporation) G:\Windows\system32\appidcertstorecheck.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\pcawrk.exe 2015-03-12 09:28 - 2015-02-03 05:30 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\pcalua.exe 2015-03-12 09:28 - 2015-02-03 05:29 - 00008704 _____ (Microsoft Corporation) G:\Windows\system32\pcaevts.dll 2015-03-12 09:28 - 2015-02-03 05:28 - 00006656 _____ (Microsoft Corporation) G:\Windows\system32\apisetschema.dll 2015-03-12 09:28 - 2015-02-03 05:28 - 00002048 _____ (Microsoft Corporation) G:\Windows\system32\mferror.dll 2015-03-12 09:28 - 2015-02-03 05:19 - 00663552 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\PEAuth.sys 2015-03-12 09:28 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntkrnlpa.exe 2015-03-12 09:28 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntoskrnl.exe 2015-03-12 09:28 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mf.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) G:\Windows\SysWOW64\quartz.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) G:\Windows\SysWOW64\crypt32.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptui.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmv2clt.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\blackbox.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmdrmsdk.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) G:\Windows\SysWOW64\qdvd.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msscp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\evr.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AUDIOKSE.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmmgrtn.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioEng.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfplat.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msnetobj.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioSes.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wintrust.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsvc.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptnet.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfps.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) G:\Windows\SysWOW64\appidapi.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) G:\Windows\SysWOW64\srclient.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\spwmp.dll 2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msdxm.ocx 2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxmasf.dll 2015-03-12 09:28 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmploc.DLL 2015-03-12 09:28 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\rrinstaller.exe 2015-03-12 09:28 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfpmp.exe 2015-03-12 09:28 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mferror.dll 2015-03-12 09:28 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\apisetschema.dll 2015-03-12 09:28 - 2015-02-03 04:32 - 00061440 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\appid.sys 2015-03-12 09:28 - 2014-11-01 00:24 - 00619056 _____ (Microsoft Corporation) G:\Windows\system32\winload.exe 2015-03-12 09:28 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) G:\Windows\system32\winresume.exe 2015-03-12 09:28 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) G:\Windows\system32\ci.dll 2015-03-12 09:27 - 2015-03-06 07:56 - 00155576 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecpkg.sys 2015-03-12 09:27 - 2015-03-06 07:56 - 00095680 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecdd.sys 2015-03-12 09:27 - 2015-03-06 07:42 - 01461760 _____ (Microsoft Corporation) G:\Windows\system32\lsasrv.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00728064 _____ (Microsoft Corporation) G:\Windows\system32\kerberos.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00341504 _____ (Microsoft Corporation) G:\Windows\system32\schannel.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00314880 _____ (Microsoft Corporation) G:\Windows\system32\msv1_0.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00309760 _____ (Microsoft Corporation) G:\Windows\system32\ncrypt.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00210944 _____ (Microsoft Corporation) G:\Windows\system32\wdigest.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00136192 _____ (Microsoft Corporation) G:\Windows\system32\sspicli.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00086528 _____ (Microsoft Corporation) G:\Windows\system32\TSpkg.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00029184 _____ (Microsoft Corporation) G:\Windows\system32\sspisrv.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00028160 _____ (Microsoft Corporation) G:\Windows\system32\secur32.dll 2015-03-12 09:27 - 2015-03-06 07:42 - 00022016 _____ (Microsoft Corporation) G:\Windows\system32\credssp.dll 2015-03-12 09:27 - 2015-03-06 07:41 - 00064000 _____ (Microsoft Corporation) G:\Windows\system32\auditpol.exe 2015-03-12 09:27 - 2015-03-06 07:41 - 00031232 _____ (Microsoft Corporation) G:\Windows\system32\lsass.exe 2015-03-12 09:27 - 2015-03-06 07:39 - 00060416 _____ (Microsoft Corporation) G:\Windows\system32\msobjs.dll 2015-03-12 09:27 - 2015-03-06 07:38 - 00146432 _____ (Microsoft Corporation) G:\Windows\system32\msaudite.dll 2015-03-12 09:27 - 2015-03-06 07:36 - 00686080 _____ (Microsoft Corporation) G:\Windows\system32\adtschema.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) G:\Windows\SysWOW64\kerberos.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msv1_0.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) G:\Windows\SysWOW64\schannel.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ncrypt.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wdigest.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) G:\Windows\SysWOW64\TSpkg.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\secur32.dll 2015-03-12 09:27 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\credssp.dll 2015-03-12 09:27 - 2015-03-06 07:09 - 00096768 _____ (Microsoft Corporation) G:\Windows\SysWOW64\sspicli.dll 2015-03-12 09:27 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\auditpol.exe 2015-03-12 09:27 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msaudite.dll 2015-03-12 09:27 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msobjs.dll 2015-03-12 09:27 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) G:\Windows\SysWOW64\adtschema.dll 2015-03-12 09:27 - 2015-02-24 05:15 - 00389800 _____ (Microsoft Corporation) G:\Windows\system32\iedkcs32.dll 2015-03-12 09:27 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iedkcs32.dll 2015-03-12 09:27 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.dll 2015-03-12 09:27 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieframe.dll 2015-03-12 09:27 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtmsft.dll 2015-03-12 09:27 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtrans.dll 2015-03-12 09:27 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.dll 2015-03-12 09:27 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) G:\Windows\system32\mshtmled.dll 2015-03-12 09:27 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmled.dll 2015-03-12 09:27 - 2015-02-20 06:41 - 00041984 _____ (Microsoft Corporation) G:\Windows\system32\lpk.dll 2015-03-12 09:27 - 2015-02-20 06:40 - 00100864 _____ (Microsoft Corporation) G:\Windows\system32\fontsub.dll 2015-03-12 09:27 - 2015-02-20 06:40 - 00046080 _____ (Adobe Systems) G:\Windows\system32\atmlib.dll 2015-03-12 09:27 - 2015-02-20 06:40 - 00014336 _____ (Microsoft Corporation) G:\Windows\system32\dciman32.dll 2015-03-12 09:27 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\fontsub.dll 2015-03-12 09:27 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) G:\Windows\SysWOW64\atmlib.dll 2015-03-12 09:27 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dciman32.dll 2015-03-12 09:27 - 2015-02-20 06:12 - 00025600 _____ (Microsoft Corporation) G:\Windows\SysWOW64\lpk.dll 2015-03-12 09:27 - 2015-02-20 05:29 - 00372224 _____ (Adobe Systems Incorporated) G:\Windows\system32\atmfd.dll 2015-03-12 09:27 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\atmfd.dll 2015-03-12 09:27 - 2015-02-20 05:06 - 02724864 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.tlb 2015-03-12 09:27 - 2015-02-20 05:05 - 00004096 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollectorres.dll 2015-03-12 09:27 - 2015-02-20 04:50 - 00066560 _____ (Microsoft Corporation) G:\Windows\system32\iesetup.dll 2015-03-12 09:27 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) G:\Windows\system32\vbscript.dll 2015-03-12 09:27 - 2015-02-20 04:49 - 00048640 _____ (Microsoft Corporation) G:\Windows\system32\ieetwproxystub.dll 2015-03-12 09:27 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) G:\Windows\system32\iertutil.dll 2015-03-12 09:27 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) G:\Windows\system32\MshtmlDac.dll 2015-03-12 09:27 - 2015-02-20 04:41 - 00054784 _____ (Microsoft Corporation) G:\Windows\system32\jsproxy.dll 2015-03-12 09:27 - 2015-02-20 04:40 - 00034304 _____ (Microsoft Corporation) G:\Windows\system32\iernonce.dll 2015-03-12 09:27 - 2015-02-20 04:36 - 00633856 _____ (Microsoft Corporation) G:\Windows\system32\ieui.dll 2015-03-12 09:27 - 2015-02-20 04:35 - 00144384 _____ (Microsoft Corporation) G:\Windows\system32\ieUnatt.exe 2015-03-12 09:27 - 2015-02-20 04:35 - 00114688 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollector.exe 2015-03-12 09:27 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) G:\Windows\system32\jscript9diag.dll 2015-03-12 09:27 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) G:\Windows\system32\jscript9.dll 2015-03-12 09:27 - 2015-02-20 04:26 - 00968704 _____ (Microsoft Corporation) G:\Windows\system32\MsSpellCheckingFacility.exe 2015-03-12 09:27 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.tlb 2015-03-12 09:27 - 2015-02-20 04:22 - 00490496 _____ (Microsoft Corporation) G:\Windows\system32\dxtmsft.dll 2015-03-12 09:27 - 2015-02-20 04:13 - 00077824 _____ (Microsoft Corporation) G:\Windows\system32\JavaScriptCollectionAgent.dll 2015-03-12 09:27 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) G:\Windows\SysWOW64\vbscript.dll 2015-03-12 09:27 - 2015-02-20 04:08 - 00199680 _____ (Microsoft Corporation) G:\Windows\system32\msrating.dll 2015-03-12 09:27 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iesetup.dll 2015-03-12 09:27 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieetwproxystub.dll 2015-03-12 09:27 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) G:\Windows\SysWOW64\MshtmlDac.dll 2015-03-12 09:27 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) G:\Windows\system32\dxtrans.dll 2015-03-12 09:27 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iertutil.dll 2015-03-12 09:27 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jsproxy.dll 2015-03-12 09:27 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iernonce.dll 2015-03-12 09:27 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieui.dll 2015-03-12 09:27 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9diag.dll 2015-03-12 09:27 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieUnatt.exe 2015-03-12 09:27 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) G:\Windows\system32\msfeeds.dll 2015-03-12 09:27 - 2015-02-20 03:49 - 00718848 _____ (Microsoft Corporation) G:\Windows\system32\ie4uinit.exe 2015-03-12 09:27 - 2015-02-20 03:47 - 01359360 _____ (Microsoft Corporation) G:\Windows\system32\mshtmlmedia.dll 2015-03-12 09:27 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) G:\Windows\system32\inetcpl.cpl 2015-03-12 09:27 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) G:\Windows\system32\ieframe.dll 2015-03-12 09:27 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-03-12 09:27 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msrating.dll 2015-03-12 09:27 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9.dll 2015-03-12 09:27 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) G:\Windows\system32\wininet.dll 2015-03-12 09:27 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) G:\Windows\SysWOW64\inetcpl.cpl 2015-03-12 09:27 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msfeeds.dll 2015-03-12 09:27 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmlmedia.dll 2015-03-12 09:27 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) G:\Windows\system32\urlmon.dll 2015-03-12 09:27 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) G:\Windows\system32\ieapfltr.dll 2015-03-12 09:27 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wininet.dll 2015-03-12 09:27 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) G:\Windows\SysWOW64\urlmon.dll 2015-03-12 09:27 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieapfltr.dll 2015-03-12 09:27 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) G:\Windows\SysWOW64\shell32.dll 2015-03-12 09:27 - 2015-02-13 07:22 - 14177280 _____ (Microsoft Corporation) G:\Windows\system32\shell32.dll 2015-03-12 09:27 - 2015-02-03 05:31 - 01424896 _____ (Microsoft Corporation) G:\Windows\system32\WindowsCodecs.dll 2015-03-12 09:27 - 2015-02-03 05:31 - 00215552 _____ (Microsoft Corporation) G:\Windows\system32\ubpm.dll 2015-03-12 09:27 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WindowsCodecs.dll 2015-03-12 09:27 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ubpm.dll 2015-03-12 09:27 - 2015-01-31 05:48 - 03179520 _____ (Microsoft Corporation) G:\Windows\system32\rdpcorets.dll 2015-03-12 09:27 - 2015-01-31 05:48 - 00016384 _____ (Microsoft Corporation) G:\Windows\system32\RdpGroupPolicyExtension.dll 2015-03-12 09:27 - 2015-01-31 01:56 - 00459336 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\cng.sys 2015-03-12 09:27 - 2015-01-31 01:56 - 00243200 _____ (Microsoft Corporation) G:\Windows\system32\rdpudd.dll 2015-03-12 09:27 - 2015-01-17 04:48 - 01067520 _____ (Microsoft Corporation) G:\Windows\system32\msctf.dll 2015-03-12 09:27 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msctf.dll 2015-03-12 09:26 - 2015-02-26 05:25 - 03204096 _____ (Microsoft Corporation) G:\Windows\system32\win32k.sys 2015-03-12 09:26 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) G:\Windows\system32\WMPhoto.dll 2015-03-12 09:26 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WMPhoto.dll 2015-03-10 01:20 - 2015-03-10 01:20 - 00001002 _____ () G:\Users\mse13ssd\Downloads\BAHN_Fahrplan_20150609.ics 2015-03-09 11:16 - 2015-03-09 11:56 - 124202474 _____ () G:\Users\mse13ssd\Downloads\#0325#.rar ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-08 10:13 - 2014-05-17 10:22 - 01484543 _____ () G:\Windows\WindowsUpdate.log 2015-04-08 08:19 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-08 08:19 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-08 08:16 - 2009-07-14 19:58 - 00700986 _____ () G:\Windows\system32\perfh007.dat 2015-04-08 08:16 - 2009-07-14 19:58 - 00149886 _____ () G:\Windows\system32\perfc007.dat 2015-04-08 08:16 - 2009-07-14 07:13 - 01619284 _____ () G:\Windows\system32\PerfStringBackup.INI 2015-04-08 08:13 - 2014-07-13 00:21 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Raptr 2015-04-08 08:12 - 2014-05-17 22:03 - 00000000 _____ () G:\Windows\system32\Drivers\lvuvc.hs 2015-04-08 08:12 - 2014-05-17 15:20 - 00034368 _____ () G:\Windows\PFRO.log 2015-04-08 08:12 - 2009-07-14 07:08 - 00000006 ____H () G:\Windows\Tasks\SA.DAT 2015-04-08 08:12 - 2009-07-14 06:51 - 00055859 _____ () G:\Windows\setupact.log 2015-04-08 06:14 - 2014-05-17 12:42 - 00000000 ____D () G:\Program Files (x86)\VS Revo Group 2015-04-08 05:43 - 2014-05-17 22:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Skype 2015-04-08 00:59 - 2014-10-01 13:55 - 00098216 _____ (Oracle Corporation) G:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2015-04-08 00:59 - 2014-10-01 13:55 - 00000000 ____D () G:\Program Files (x86)\Java 2015-04-07 22:29 - 2014-05-17 20:13 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\TS3Client 2015-04-07 10:10 - 2014-05-17 15:57 - 00004182 _____ () G:\Windows\System32\Tasks\avast! Emergency Update 2015-04-05 18:19 - 2015-03-05 14:19 - 00129752 _____ (Malwarebytes Corporation) G:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-04-05 15:10 - 2009-07-14 05:20 - 00000000 __RHD () G:\Users\Default 2015-04-05 15:09 - 2009-07-14 04:34 - 00000215 _____ () G:\Windows\system.ini 2015-04-05 13:19 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\NDF 2015-04-05 12:59 - 2014-05-17 11:54 - 00000000 ____D () G:\Users\mse13ssd 2015-04-05 03:26 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\Web 2015-04-02 01:34 - 2009-07-14 07:32 - 00000000 ____D () G:\Windows\system32\FxsTmp 2015-03-30 17:36 - 2015-02-28 05:38 - 00000000 ____D () G:\Users\mse13ssd\Desktop\aufgeräumt 2015-03-30 08:10 - 2014-11-01 08:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\25372 2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\DivX 2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX 2015-03-30 04:33 - 2014-08-24 02:00 - 00000000 ____D () G:\ProgramData\DivX 2015-03-30 04:33 - 2014-05-17 15:57 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast 2015-03-30 04:33 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\AppCompat 2015-03-30 04:32 - 2014-08-24 02:01 - 00000000 ____D () G:\Program Files\DivX 2015-03-30 04:32 - 2014-08-24 02:00 - 00000000 ____D () G:\Program Files (x86)\DivX 2015-03-30 04:32 - 2014-06-18 17:31 - 00000000 ____D () G:\Program Files (x86)\Microsoft Office 2015-03-30 04:32 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\registration 2015-03-30 03:27 - 2009-07-14 20:18 - 00000000 ___RD () G:\Users\Public\Recorded TV 2015-03-26 21:20 - 2014-10-12 12:01 - 00000000 ____D () G:\Windows\Minidump 2015-03-26 18:51 - 2014-07-13 00:21 - 00000000 ____D () G:\Program Files (x86)\Raptr 2015-03-26 09:13 - 2014-06-18 17:31 - 00000000 ____D () G:\ProgramData\Microsoft Help 2015-03-22 18:29 - 2014-05-17 12:40 - 00070368 _____ () G:\Users\mse13ssd\AppData\Local\GDIPFONTCACHEV1.DAT 2015-03-22 18:29 - 2009-07-14 06:45 - 00307752 _____ () G:\Windows\system32\FNTCACHE.DAT 2015-03-22 18:25 - 2014-06-18 17:32 - 00000000 ____D () G:\Program Files (x86)\Microsoft Works 2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Google 2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Program Files (x86)\Google 2015-03-15 14:09 - 2014-08-24 13:49 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Adobe 2015-03-15 14:09 - 2014-05-17 15:53 - 00778928 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerApp.exe 2015-03-15 14:09 - 2014-05-17 15:53 - 00142512 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-03-15 05:05 - 2014-06-21 18:28 - 00000000 ____D () G:\Program Files (x86)\Steam 2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Glyph 2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glyph 2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Program Files (x86)\Glyph 2015-03-13 10:32 - 2009-07-14 07:09 - 00000000 ____D () G:\Windows\System32\Tasks\WPD 2015-03-12 12:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\rescache 2015-03-12 09:37 - 2015-02-28 09:01 - 00000000 ___RD () G:\Users\mse13ssd\Virtual Machines 2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\SysWOW64\Dism 2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\Dism 2015-03-12 09:31 - 2014-05-17 20:36 - 00000000 ____D () G:\Windows\system32\MRT 2015-03-12 09:29 - 2014-05-17 20:36 - 122905848 _____ (Microsoft Corporation) G:\Windows\system32\MRT.exe ==================== Files in the root of some directories ======= 2014-10-02 16:29 - 2015-02-28 12:40 - 14286848 _____ () G:\Users\mse13ssd\AppData\Roaming\Sandra.mdb 2015-01-23 13:40 - 2015-01-23 13:40 - 0003584 _____ () G:\Users\mse13ssd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-01-01 14:58 - 2015-01-01 14:58 - 0007605 _____ () G:\Users\mse13ssd\AppData\Local\Resmon.ResmonCfg ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) G:\Windows\System32\winlogon.exe => File is digitally signed G:\Windows\System32\wininit.exe => File is digitally signed G:\Windows\SysWOW64\wininit.exe => File is digitally signed G:\Windows\explorer.exe => File is digitally signed G:\Windows\SysWOW64\explorer.exe => File is digitally signed G:\Windows\System32\svchost.exe => File is digitally signed G:\Windows\SysWOW64\svchost.exe => File is digitally signed G:\Windows\System32\services.exe => File is digitally signed G:\Windows\System32\User32.dll => File is digitally signed G:\Windows\SysWOW64\User32.dll => File is digitally signed G:\Windows\System32\userinit.exe => File is digitally signed G:\Windows\SysWOW64\userinit.exe => File is digitally signed G:\Windows\System32\rpcss.dll => File is digitally signed G:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-04-04 00:45 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015 Ran by mse13ssd at 2015-04-08 10:35:59 Running from G:\Users\mse13ssd\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) AGEIA PhysX v7.11.13 (HKLM-x32\...\{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}) (Version: 7.11.13 - AGEIA Technologies, Inc.) Agent Ransack x64 (HKLM\...\{58C0AC50-8FA1-4A95-AEC6-5B2727E5CC6A}) (Version: 7.0.820.1 - Mythicsoft Ltd) AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) Apple Application Support (HKLM-x32\...\{122ADF8C-DDA1-480C-9936-C88F2825B265}) (Version: 2.1.9 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}) (Version: 5.2.0.6 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Archeage (HKLM-x32\...\Glyph Archeage) (Version: - Trion Worlds, Inc.) ArtMoney SE v7.43 (HKLM-x32\...\ArtMoney SE_is1) (Version: 7.43 - System SoftLab) avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software) Avery Wizard 5.0 (HKLM-x32\...\{FC3B3A5D-7058-4627-9F1E-F95CC38B6054}) (Version: 5.0.5 - Avery) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version: - Gearbox Software) Canon iP7200 series Benutzerregistrierung (HKLM-x32\...\Canon iP7200 series Benutzerregistrierung) (Version: - Canon Inc.) Canon iP7200 series Printer Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP7200_series) (Version: - Canon Inc.) Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - ) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.0.0 - Canon Inc.) CanoScan LiDE 110 Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2414) (Version: - Canon Inc.) ClipboardManager 1.6 (HKLM-x32\...\ClipboardManager_is1) (Version: - ) Contract Jack (HKLM-x32\...\{374CAB30-2F61-4439-9A4A-24D3AEA2960A}) (Version: - ) CPUID CPU-Z 1.70 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) Die Siedler II - Die nächste Generation (HKLM-x32\...\S2TNG) (Version: - ) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.7.0.31 - DivX, LLC) ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - ) Free YouTube Download version 3.2.53.128 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.53.128 - DVDVideoSoft Ltd.) Free YouTube to MP3 Converter version 3.12.50.1111 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.50.1111 - DVDVideoSoft Ltd.) Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden GUILD WARS (HKLM-x32\...\Guild Wars) (Version: - ) iTunes (HKLM\...\{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}) (Version: 10.6.3.25 - Apple Inc.) Java 8 Update 40 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation) Logitech Gaming Software 8.55 (HKLM\...\Logitech Gaming Software) (Version: 8.55.137 - Logitech Inc.) Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Mozilla Firefox 36.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 36.0 (x86 de)) (Version: 36.0 - Mozilla) paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC) Pamela Pro 4.9 (HKLM-x32\...\Pamela) (Version: 4.9 - PamConsult GmbH) PDF Architect 2 Create Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.0 - pdfforge) Raptr (HKLM-x32\...\Raptr) (Version: - ) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) SciLor's grooveshark™.com Downloader 0.4.15 (HKLM-x32\...\{DDEAE484-D5FB-49CB-BD47-9512E8ACCA65}_is1) (Version: 0.4.15 - SciLor) SiSoftware Sandra Lite 2014.SP3c (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2496}_is1) (Version: 20.47.2014.10 - SiSoftware) Skype™ 7.1 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.) SRWare Iron Version SRWare Iron 41.2200.0 (HKLM-x32\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: SRWare Iron 41.2200.0 - SRWare) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden Windows Phone app for desktop (HKLM-x32\...\{19773614-FC22-4ACC-AAA3-E6BDA81ACF92}) (Version: 1.1.2726.0 - Microsoft Corporation) WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 01-04-2015 19:32:07 Windows Update 05-04-2015 15:04:11 ComboFix created restore point 07-04-2015 10:44:02 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2015-04-05 15:09 - 00000027 ____A G:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {1FC3D3B2-F254-4B57-9695-FFF62B3AC150} - System32\Tasks\GoogleUpdateTaskMachineCore => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15] (Google Inc.) Task: {34D4B971-AD1B-4F8D-8ED4-6F6BF7ABE60D} - System32\Tasks\avast! Emergency Update => G:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-07-15] (AVAST Software) Task: {4FEEE84D-7E59-4CDF-B74D-B91A75A59971} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => G:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation) Task: {97825458-5F0E-4103-805A-204524B8F97C} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => G:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {BD6EFB7D-29B9-4725-B4CB-C2F47B685F42} - System32\Tasks\Abelssoft\Updater scan => G:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe Task: {D34A6BF5-32B4-4467-9D46-CA4D3DED9394} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => G:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {DB431844-F8D5-409D-A115-BB442A487B85} - System32\Tasks\GoogleUpdateTaskMachineUA => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15] (Google Inc.) Task: {E57F8AB1-453C-45BC-BF7F-E700E5C6EBA9} - System32\Tasks\Adobe Acrobat Update Task => G:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {F818CCEB-3516-47E4-BCF8-6CBFB192089F} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => G:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2014-07-28 20:29 - 2014-07-28 20:29 - 00866584 _____ () G:\Program Files\Logitech Gaming Software\libGLESv2.dll 2014-07-28 20:32 - 2014-07-28 20:32 - 01050904 _____ () G:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2014-07-28 20:29 - 2014-07-28 20:29 - 00059160 _____ () G:\Program Files\Logitech Gaming Software\libEGL.dll 2014-07-28 20:31 - 2014-07-28 20:31 - 00242456 _____ () G:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2014-01-10 07:26 - 2014-01-10 07:26 - 01861968 _____ () G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 2014-07-15 08:28 - 2014-07-15 08:28 - 00301152 _____ () G:\Program Files\AVAST Software\Avast\aswProperty.dll 2015-04-07 22:11 - 2015-04-07 22:11 - 02924544 _____ () G:\Program Files\AVAST Software\Avast\defs\15040701\algo.dll 2012-05-30 20:06 - 2012-05-30 20:06 - 00087912 _____ () G:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2012-05-30 20:06 - 2012-05-30 20:06 - 01242512 _____ () G:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-07-15 08:28 - 2014-07-15 08:28 - 19329904 _____ () G:\Program Files\AVAST Software\Avast\libcef.dll 2014-01-10 07:28 - 2014-01-10 07:28 - 00100688 _____ () G:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2015-04-08 07:54 - 2015-03-04 10:54 - 01482240 _____ () G:\Program Files (x86)\SRWare Iron\libglesv2.dll 2015-04-08 07:54 - 2015-03-04 10:54 - 00073728 _____ () G:\Program Files (x86)\SRWare Iron\libegl.dll 2015-04-08 07:54 - 2015-03-08 11:12 - 09579008 _____ () G:\Program Files (x86)\SRWare Iron\pdf.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: G:\Users\mse13ssd\Downloads\email_5937_20150205205259.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Control Panel\Desktop\\Wallpaper -> G:\Users\mse13ssd\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.0.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: bthserv => 3 MSCONFIG\Services: DPS => 2 MSCONFIG\Services: SensrSvc => 3 MSCONFIG\startupreg: Adobe ARM => "G:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: APSDaemon => "G:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: iTunesHelper => "G:\Program Files (x86)\iTunes\iTunesHelper.exe" ==================== Accounts: ============================= Administrator (S-1-5-21-3243151774-2580435505-251407729-500 - Administrator - Disabled) Gast (S-1-5-21-3243151774-2580435505-251407729-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3243151774-2580435505-251407729-1002 - Limited - Enabled) mse13ssd (S-1-5-21-3243151774-2580435505-251407729-1001 - Administrator - Enabled) => G:\Users\mse13ssd ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/08/2015 08:12:35 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x6a0 Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 Error: (04/08/2015 06:14:44 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: chrome.exe, Version: 39.0.2171.65, Zeitstempel: 0x5482f276 Name des fehlerhaften Moduls: chrome.dll, Version: 39.0.2171.65, Zeitstempel: 0x5482f23e Ausnahmecode: 0xc0000005 Fehleroffset: 0x00043bcd ID des fehlerhaften Prozesses: 0x128c Startzeit der fehlerhaften Anwendung: 0xchrome.exe0 Pfad der fehlerhaften Anwendung: chrome.exe1 Pfad des fehlerhaften Moduls: chrome.exe2 Berichtskennung: chrome.exe3 Error: (04/08/2015 06:13:30 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/08/2015 06:13:30 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/08/2015 02:14:25 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/07/2015 10:10:33 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x5cc Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 Error: (04/07/2015 03:22:38 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x514 Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 Error: (04/07/2015 00:47:54 AM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/06/2015 07:59:18 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/06/2015 07:55:51 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e Ausnahmecode: 0x40000015 Fehleroffset: 0x000a327c ID des fehlerhaften Prozesses: 0x50c Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0 Pfad der fehlerhaften Anwendung: creator-ws.exe1 Pfad des fehlerhaften Moduls: creator-ws.exe2 Berichtskennung: creator-ws.exe3 System errors: ============= Error: (04/08/2015 08:12:39 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (04/08/2015 08:12:13 AM) (Source: Ntfs) (EventID: 137) (User: ) Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (04/07/2015 10:10:38 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (04/07/2015 10:10:12 AM) (Source: Ntfs) (EventID: 137) (User: ) Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (04/07/2015 03:22:44 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (04/07/2015 03:22:17 AM) (Source: Ntfs) (EventID: 137) (User: ) Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (04/06/2015 07:55:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (04/06/2015 07:55:30 PM) (Source: Ntfs) (EventID: 137) (User: ) Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten. Error: (04/06/2015 10:14:00 AM) (Source: DCOM) (EventID: 10010) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz Percentage of memory in use: 13% Total physical RAM: 16384 MB Available physical RAM: 14208.54 MB Total Pagefile: 32766.19 MB Available Pagefile: 30427.84 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.5 GB) (Free:736.3 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: () (Fixed) (Total:0.01 GB) (Free:0 GB) NTFS Drive f: (Nolf2xp_1) (CDROM) (Total:0.64 GB) (Free:0 GB) CDFS Drive g: (SSD) (Fixed) (Total:119.24 GB) (Free:25.43 GB) NTFS Drive m: (SAMSUNG) (Fixed) (Total:1396.92 GB) (Free:834.32 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: 7E008421) Partition 1: (Active) - (Size=119.2 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 1CA61CA5) Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=7 MB) - (Type=07 NTFS) ======================================================== Disk: 6 (Size: 1397.3 GB) (Disk ID: 5C9C6FA9) Partition 1: (Not Active) - (Size=1397.3 GB) - (Type=0C) ==================== End Of Log ============================ |
08.04.2015, 17:42 | #10 |
/// the machine /// TB-Ausbilder | Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.04.2015, 17:48 | #11 |
| Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen Nein, kann keine feststellen. Vielen Dank dafür! LG, MSE XIII |
09.04.2015, 08:15 | #12 |
/// the machine /// TB-Ausbilder | Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen Cleanup: (Die Reihenfolge ist hier entscheidend) Falls Defogger verwendet wurde: Erneut starten und auf Re-enable klicken. Falls Combofix verwendet wurde: Combofix deinstallieren .
Alle Logs gepostet? Dann lade Dir bitte DelFix herunter.
Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst. Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen. Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...und/oder das Forum mit einer kleinen Spende unterstützen. Absicherung: Beim Betriebsystem Windows die automatischen Updates aktivieren. Auch die sicherheitsrelevante Software sollte immer nur in der aktuellsten Version vorliegen: Browser Java Flash-Player PDF-Reader Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren. Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen. Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig. Verwende ein Antivirusprogramm mit Echtzeitscanner und stets aktueller Signaturendatenbank. Meine Empfehlung: Emsisoft Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und ESET scannen. Optional: NoScript verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen. Malwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen. Lade Software von einem sauberen Portal wie . Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen. Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwarecleaner . Abschließend noch ein paar grundsätzliche Bemerkungen: Ändere regelmäßig Deine wichtigen Online-Passwörter und erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems. Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen |
agent, alter, alternative, anderen, angeblich, anleitung, autostart, avast, beiträge, bestimmte, bestimmten, code, cpu-z, deaktivieren, direkt, entfernen, fehler, folge, folgende, gelöscht, installer, launch, nachfrage, nichts, revo uninstaller, versucht, win, zeichen |