ThorOdin | 15.10.2014 09:20 | Hallo, danke schonmal für die großartige Hilfe.
Hier kommen dann mal die LOGs.
mbam.txt: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 14.10.2014
Suchlauf-Zeit: 19:19:28
Logdatei: MW.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.10.13.02
Rootkit Datenbank: v2014.10.11.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Marcel
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 388036
Verstrichene Zeit: 27 Min, 53 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 7
PUP.Optional.SweetPacks.A, HKU\S-1-5-21-1687652912-988993815-1256219632-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{EEE6C360-6118-11DC-9C72-001320C79847}, In Quarantäne, [73c3ae66bfbd261047b2399ed52d7a86],
PUP.Optional.SweetPacks.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{EEE6C360-6118-11DC-9C72-001320C79847}, In Quarantäne, [73c3ae66bfbd261047b2399ed52d7a86],
PUP.Optional.SystemK.A, HKLM\SOFTWARE\WOW6432NODE\SystemK, In Quarantäne, [989e9d77fc80f2441127e33e07fc956b],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\SYSTEMK\General, In Quarantäne, [f1455eb6e29aba7ce4ffc17df40f46ba],
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, In Quarantäne, [c76f8c88740841f57251ff27c53ed32d],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1687652912-988993815-1256219632-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [df570e06205c3bfb2e05083315eea25e],
PUP.Optional.SystemSpeedup, HKU\S-1-5-21-1687652912-988993815-1256219632-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\ssd, In Quarantäne, [dd5994801963f145952d7ea89a6920e0],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 1
PUP.Optional.PriceGong.A, C:\Users\Marcel\AppData\LocalLow\PriceGong, In Quarantäne, [95a142d2f28a64d2c1a9945755adba46],
Dateien: 6
PUP.Optional.RegCleanerPro, C:\Windows\System32\Tasks\ASP, In Quarantäne, [2b0bac68e49883b3c64f36e948bb9e62],
PUP.Optional.SweetPacks.A, C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\yv37y29g.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi, In Quarantäne, [2a0cd93bc4b84de9e116b66cec174ab6],
PUP.Optional.SweetIM.A, C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\yv37y29g.default\searchplugins\sweetim.xml, In Quarantäne, [8fa721f35c20bf77f33964d1f211f907],
PUP.Optional.Iminent.A, C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage, In Quarantäne, [04324bc986f693a3caffda5bb54e8f71],
PUP.Optional.DefaultSearch.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\default-search.xml, In Quarantäne, [57dff71d7a02cd690ad3221cc241a35d],
PUP.Optional.DefaultSearch.A, C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\yv37y29g.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://www.default-search.net/search?sid=476&aid=122&itype=n&ver=12302&tm=322&src=ds&p=");), Ersetzt,[95a161b36f0d1a1ccb889bb610f5e31d]
Physische Sektoren: 0
(No malicious items detected)
(end) AdwCleaner: Code:
# AdwCleaner v4.000 - Bericht erstellt am 15/10/2014 um 09:42:27
# DB v2014-10-15.7
# Aktualisiert 12/10/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Marcel - MARCEL-PC
# Gestartet von : C:\Users\Marcel\Downloads\AdwCleaner_4.000(1).exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Marcel\AppData\Roaming\Common\LuaRT
Ordner Gelöscht : C:\ProgramData\SecTaskMan
Ordner Gelöscht : C:\Users\Marcel\AppData\Roaming\Sixth
Ordner Gelöscht : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\yv37y29g.default\SweetIMToolbarData
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\yv37y29g.default\searchplugins\11-suche.xml
***** [ Tasks ] *****
Task Gelöscht : ASP
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Web-Suche
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\driverscanner
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_install_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_install_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C32F5BF7-6918-4F78-A97A-53CDF7D07C8C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DFEFCDEE-CF1A-4FC8-88AD-129872198372}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{DFEFCDEE-CF1A-4FC8-88AD-129872198372}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Schlüssel Gelöscht : HKCU\Software\Bitberry
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\ImInstaller
Schlüssel Gelöscht : HKCU\Software\Linkey
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Protector
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\ICQ\ICQToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Uniblue
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F2E0D3DD9E5E4B74CA43BCE77815E287
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7
***** [ Browser ] *****
-\\ Internet Explorer v0.0.0.0
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v32.0.3 (x86 de)
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi...\",\"description\":\"California Rock\",\"url\":\"hxxp://feedlive.net/california.asx\"}");
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"false\"}");
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.embeddedsData", "[{\"appId\":\"129675591388832722\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...]
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.meinvz.net%2FDefault\",\"EB_MAIN_FRAME_TITLE\":\"meinVZ%20%7C%20Bist%20Du%20schon%20drin[...]
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"true\"}");
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"false\"}");
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3158970\"}");
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://IncredibarGamesEN.OurToolbar.com//xpi\"}");
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"Incredibar-Games EN\"}");
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
[yv37y29g.default] - Zeile gelöscht : user_pref("CT3158970.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
[yv37y29g.default] - Zeile gelöscht : user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.41.2.1\",\"InstallEventCTime\":1381681847604,\"InstallEvent\":\"True\"}");
[yv37y29g.default] - Zeile gelöscht : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engine=\"hxxp://*google.*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://search.yahoo.com/*\" param=\"[...]
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [17342 octets] - [15/10/2014 09:39:18]
AdwCleaner[S0].txt - [16430 octets] - [15/10/2014 09:42:27]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [16491 octets] ########## JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.14.2014:1)
OS: Windows 7 Home Premium x64
Ran by Marcel on 15.10.2014 at 8:41:19,50
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-1687652912-988993815-1256219632-1002\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ApnStub_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ApnStub_RASDLG
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ApnStub_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\TaskMan_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\TaskMan_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ConduitInstaller_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ConduitInstaller_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_fuer_magix-mp3-maker_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_fuer_magix-mp3-maker_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_fuer_microsoft-project_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_fuer_microsoft-project_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ApnStub_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ApnStub_RASDLG
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ApnStub_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\TaskMan_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\TaskMan_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ConduitInstaller_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\ConduitInstaller_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_magix-mp3-maker_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_magix-mp3-maker_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_microsoft-project_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_fuer_microsoft-project_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\partner"
Successfully deleted: [Folder] "C:\Users\Marcel\AppData\Roaming\asp"
Successfully deleted: [Folder] "C:\Users\Marcel\AppData\Roaming\fbdownloader"
Successfully deleted: [Folder] "C:\Users\Marcel\AppData\Roaming\getrighttogo"
Successfully deleted: [Folder] "C:\Users\Marcel\AppData\Roaming\incredibar"
Successfully deleted: [Folder] "C:\Users\Marcel\AppData\Roaming\ssync"
Successfully deleted: [Folder] "C:\Users\Marcel\AppData\Roaming\systweak"
Successfully deleted: [Folder] "C:\Users\Marcel\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\Marcel\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{09D22829-ED02-49C0-92AB-DF6E6888F345}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{0CF8C633-85E6-46B3-8BD1-D31FCE3E97DC}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{0F79BC35-B954-43D4-9269-7EA4B1C50099}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{19C8AD43-3AFC-420B-B20B-14B69522B7F5}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{1C6BB19D-9BCB-4C90-9718-E49390B5E172}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{1E2C2991-3C29-44FC-BDA6-D7290E152692}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{2013FB68-429A-4708-8B02-9FE6AA6130DA}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{215745BD-CA8E-403B-99B5-EB6261DBC68D}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{2CF03DF3-4E0C-439C-9C18-E351B349B2EA}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{2DC4E62A-856B-4C11-BC47-8D8BB38D8601}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{30462824-CECC-4639-94EF-0DA299C58FA3}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{42185402-8BC0-46BB-B7C1-34AD1F2B84C5}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{548C0284-545E-48A5-9921-9D529377A61E}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{5CA36B87-32F9-4ED3-B819-EC46FD1902F3}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{5ED63A94-AD3D-4097-881F-2A69673C5E58}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{61A66E15-78DC-4902-B420-DF5D0C92FF3D}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{65AB18C0-3AD9-417C-B684-4190CA58A516}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{67B9C2A9-6962-4A0C-9C8D-8718673911EC}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{6807C40F-4B1B-498E-AE38-ECD927F8EFBF}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{6AF768EF-8D60-48F6-B8A3-8AF0C150D412}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{6E63E383-166A-40B0-BFF8-CF1DB8426794}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{745C2A03-A6FF-4B3E-B7A8-02823B0261C6}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{7B8DE106-0E3B-41B6-ACE6-170B2584DE22}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{7DB9D41C-F4A6-46F5-8EBC-C72FEA893781}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{80E45C0F-2349-46CD-8FD7-4082B1FD40FD}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{8841AAF7-E712-407D-85B7-C9BE2B8C1916}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{8B80789D-B802-453C-867B-CA3E83602140}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{8F618D4B-1E75-4588-ABED-BC51D1BD2019}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{A0A23DD3-58CF-4385-A7F1-94608E528D8B}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{A51BCF32-3650-4B69-9D77-7F40CBA063A4}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{A7531B13-61B9-4778-9980-5A78B214C630}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{BE47DC97-4D07-4538-878E-1DC564C0BA5B}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{C171EA56-AEC1-4549-B290-C43656D595BC}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{DC76814A-4AD4-4EA7-B4C3-EF54A2F7F36D}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{E6068C52-6A7C-41BD-8664-6D2D8C4C9D7D}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{E610A49C-1A96-4CB9-B1F7-3B0C04CC63A2}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{F214C794-6588-4711-BF8D-53C76B21284A}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{F3C9C109-D3CB-4B84-981C-25F86756B035}
Successfully deleted: [Empty Folder] C:\Users\Marcel\appdata\local\{F41C418E-2B06-4E92-9A47-B885FC8B1271}
~~~ FireFox
Successfully deleted: [File] C:\Users\Marcel\AppData\Roaming\mozilla\firefox\profiles\yv37y29g.default\user.js
Successfully deleted: [File] C:\Users\Marcel\AppData\Roaming\mozilla\firefox\profiles\yv37y29g.default\invalidprefs.js
Successfully deleted: [File] C:\Users\Marcel\AppData\Roaming\mozilla\firefox\profiles\yv37y29g.default\searchplugins\avira-safesearch.xml
Successfully deleted: [Folder] C:\Users\Marcel\AppData\Roaming\mozilla\firefox\profiles\yv37y29g.default\smartbar
Successfully deleted: [Folder] C:\Users\Marcel\AppData\Roaming\mozilla\firefox\profiles\yv37y29g.default\extensions\software@loadtubes.com
Successfully deleted: [Folder] C:\Users\Marcel\AppData\Roaming\mozilla\firefox\profiles\yv37y29g.default\extensions\toolbar@web.de
Successfully deleted the following from C:\Users\Marcel\AppData\Roaming\mozilla\firefox\profiles\yv37y29g.default\prefs.js
user_pref("CT3158970.1000082.isPlayDisplay", "true");
user_pref("CT3158970.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi...\",\"description\":\"California Rock\",\"url\":\"hxxp://feedlive.net/california.asx\"}");
user_pref("CT3158970.1000234.TWC_TMP_city", "ESSEN");
user_pref("CT3158970.1000234.TWC_TMP_country", "DE");
user_pref("CT3158970.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"false\"}");
user_pref("CT3158970.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3158970.FirstTime", "true");
user_pref("CT3158970.FirstTimeFF3", "true");
user_pref("CT3158970.UserID", "UN27879625876766996");
user_pref("CT3158970.addressBarTakeOverEnabledInHidden", "true");
user_pref("CT3158970.autoDisableScopes", -1);
user_pref("CT3158970.defaultSearch", "false");
user_pref("CT3158970.embeddedsData", "[{\"appId\":\"129675591388832722\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"get
user_pref("CT3158970.enableAlerts", "always");
user_pref("CT3158970.enableSearchFromAddressBar", "false");
user_pref("CT3158970.firstTimeDialogOpened", "true");
user_pref("CT3158970.fixPageNotFoundError", "false");
user_pref("CT3158970.fixPageNotFoundErrorInHidden", "true");
user_pref("CT3158970.fixUrls", true);
user_pref("CT3158970.hxxp___api20_thetrafficstat_net.pid2", "e58605c2-f32c-7b7c-a8be-00c5d9f09062");
user_pref("CT3158970.installId", "ConduitNSISIntegration");
user_pref("CT3158970.installType", "ConduitNSISIntegration");
user_pref("CT3158970.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3158970.isNewTabEnabled", false);
user_pref("CT3158970.isPerformedSmartBarTransition", "true");
user_pref("CT3158970.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
user_pref("CT3158970.navigationAliasesJson", "{\"EB_SEARCH_TERM\":\"\",\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.meinvz.net%2FDefault\",\"EB_MAIN_FRAME_TITLE\":\"meinVZ%20%7C%2
user_pref("CT3158970.openThankYouPage", "false");
user_pref("CT3158970.openUninstallPage", "true");
user_pref("CT3158970.search.searchAppId", "129675591388832722");
user_pref("CT3158970.search.searchCount", "0");
user_pref("CT3158970.searchInNewTabEnabled", "false");
user_pref("CT3158970.searchInNewTabEnabledInHidden", "true");
user_pref("CT3158970.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3158970.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"false\"}");
user_pref("CT3158970.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT3158970.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
user_pref("CT3158970.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3158970\"}");
user_pref("CT3158970.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://IncredibarGamesEN.OurToolbar.com//xpi\"}");
user_pref("CT3158970.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"Incredibar-Games EN\"}");
user_pref("CT3158970.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3158970.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
user_pref("CT3158970.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1351686707427");
user_pref("CT3158970.serviceLayer_services_appsMetadata_lastUpdate", "1351697861482");
user_pref("CT3158970.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1351686708648");
user_pref("CT3158970.serviceLayer_services_login_10.10.27.6_lastUpdate", "1352151635489");
user_pref("CT3158970.serviceLayer_services_optimizer_lastUpdate", "1351697861969");
user_pref("CT3158970.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1351686709527");
user_pref("CT3158970.serviceLayer_services_searchAPI_lastUpdate", "1351686703568");
user_pref("CT3158970.serviceLayer_services_serviceMap_lastUpdate", "1352151634554");
user_pref("CT3158970.serviceLayer_services_toolbarContextMenu_lastUpdate", "1351686708276");
user_pref("CT3158970.serviceLayer_services_toolbarSettings_lastUpdate", "1352151634718");
user_pref("CT3158970.serviceLayer_services_translation_lastUpdate", "1352151634903");
user_pref("CT3158970.settingsINI", true);
user_pref("CT3158970.shouldFirstTimeDialog", "false");
user_pref("CT3158970.smartbar.CTID", "CT3158970");
user_pref("CT3158970.smartbar.Uninstall", "0");
user_pref("CT3158970.smartbar.toolbarName", "Incredibar-Games EN ");
user_pref("CT3158970.startPage", "false");
user_pref("CT3158970.toolbarBornServerTime", "31-10-2012");
user_pref("CT3158970.toolbarCurrentServerTime", "6-11-2012");
user_pref("avira.safe_search.search_was_active", "false");
user_pref("browser.search.defaultenginename", "FBDownloader Search");
user_pref("browser.search.order.1", "default-search.net");
user_pref("browser.search.selectedEngine", "FBDownloader Search");
user_pref("browser.startup.homepage", "hxxps://safesearch.avira.com/");
user_pref("extensions.iminent.admin", false);
user_pref("extensions.iminent.aflt", "orgnl");
user_pref("extensions.iminent.appId", "{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4}");
user_pref("extensions.iminent.autoRvrt", "false");
user_pref("extensions.iminent.dfltLng", "");
user_pref("extensions.iminent.excTlbr", false);
user_pref("extensions.iminent.ffxUnstlRst", false);
user_pref("extensions.iminent.id", "eab25140000000000000000000000000");
user_pref("extensions.iminent.instlDay", "15991");
user_pref("extensions.iminent.instlRef", "");
user_pref("extensions.iminent.newTab", false);
user_pref("extensions.iminent.prdct", "iminent");
user_pref("extensions.iminent.prtnrId", "iminent");
user_pref("extensions.iminent.rvrt", "false");
user_pref("extensions.iminent.smplGrp", "none");
user_pref("extensions.iminent.tlbrId", "base");
user_pref("extensions.iminent.tlbrSrchUrl", "hxxp://start.iminent.com/?ref=toolbarm#q=");
user_pref("extensions.iminent.vrsn", "1.8.25.0");
user_pref("extensions.iminent.vrsnTs", "1.8.25.018:30:24");
user_pref("extensions.iminent.vrsni", "1.8.25.0");
user_pref("extensions.safesearch.MP_DISTINCT_ID", "\"147e5d2e165cc-0c0106675350f18-42504136-0-147e5d2e166d8\"");
user_pref("extensions.safesearch.SAUTH_rndsnr", "\"722e4037461fb109344fd6a300c40346a207fe9e\"");
user_pref("extensions.safesearch.install", "1408310108528");
user_pref("iminent.LayoutId", "28");
user_pref("iminent.version", "7.41.2.1");
user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.41.2.1\",\"InstallEventCTime\":1381681847604,\"InstallEvent\":\"True\"}");
user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
user_pref("sweetim.toolbar.mode.debug", "false");
user_pref("sweetim.toolbar.previous.browser.search.defaulturl", "");
user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engine=\"hxxp://*google.*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://sear
user_pref("sweetim.toolbar.search.history.capacity", "10");
user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", "1");
user_pref("sweetim.toolbar.searchguard.enable", "true");
user_pref("sweetim.toolbar.simapp_id", "{E77C4883-F35F-11E0-A833-00262DC56B4C}");
user_pref("sweetim.toolbar.urls.homepage", "hxxp://home.sweetim.com/?barid={E77C4883-F35F-11E0-A833-00262DC56B4C}");
Emptied folder: C:\Users\Marcel\AppData\Roaming\mozilla\firefox\profiles\yv37y29g.default\minidumps [278 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15.10.2014 at 8:48:27,44
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Und zu guter Letzt, FRST:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-10-2014
Ran by Marcel (administrator) on MARCEL-PC on 15-10-2014 09:57:33
Running from C:\Users\Marcel\Downloads
Loaded Profile: Marcel (Available profiles: Marcel)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.CSSQL08\MSSQL\Binn\sqlservr.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe
(Wistron) C:\Program Files (x86)\Launch Manager\HotkeyApp.exe
(Wistron Corp.) C:\Program Files (x86)\Launch Manager\WButton.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 5\Integrator.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
() C:\Program Files (x86)\1&1 Surf-Stick\AssistantServices.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(X10) C:\Program Files (x86)\Common Files\X10\Common\X10nets.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.CSSQL08\MSSQL\Binn\fdlauncher.exe
(Wistron Corp.) C:\Program Files (x86)\Launch Manager\WisLMSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.CSSQL08\MSSQL\Binn\fdhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11548264 2010-11-03] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2181224 2010-11-03] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2460488 2014-09-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [HotkeyApp] => C:\Program Files (x86)\Launch Manager\HotkeyApp.exe [207400 2010-12-16] (Wistron)
HKLM-x32\...\Run: [Wbutton] => C:\Program Files (x86)\Launch Manager\Wbutton.exe [436264 2010-06-21] (Wistron Corp.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-12-20] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-17] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [165168 2014-09-23] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1687652912-988993815-1256219632-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6482200 2014-09-26] (Piriform Ltd)
HKU\S-1-5-21-1687652912-988993815-1256219632-1002\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-09-29] (Glarysoft Ltd)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [174856 2014-09-14] (NVIDIA Corporation)
AppInit_DLLs: , C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [174856 2014-09-14] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156840 2014-09-14] (NVIDIA Corporation)
BootExecute: autocheck autochk * BootDefrag.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKCU - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKCU - {84F2FA82-405E-4036-B234-BD0F80C959E8} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=foxysecurity
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll (RealDownloader)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\yv37y29g.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1212152.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @real.com/nppl3260;version=17.0.10.8 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=15.0.6.14 -> c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=17.0.10 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.10 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=17.0.10 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.6.14 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.6.14 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=17.0.10.8 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer Cloud)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\yv37y29g.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Avira Browser Safety - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\yv37y29g.default\Extensions\abs@avira.com [2014-10-03]
FF Extension: Popular Website Buddy - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\yv37y29g.default\Extensions\jid1-l6V8exwLVv1lBw@jetpack.xpi [2014-05-14]
FF Extension: Adblock Plus - C:\Users\Marcel\AppData\Roaming\Mozilla\Firefox\Profiles\yv37y29g.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-11-20]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-06-20]
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-06-24]
FF HKLM-x32\...\Firefox\Extensions: [{7ADCCCD0-FDEC-4A18-A329-550A87710223}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
Chrome:
=======
CHR Profile: C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-23]
CHR Extension: (Google Search) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-23]
CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk [2011-05-06]
CHR Extension: (Skype Click to Call) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2012-01-23]
CHR Extension: (Gmail) - C:\Users\Marcel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-23]
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2014-05-13]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-11-29]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-17] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [160560 2014-09-23] (Avira Operations GmbH & Co. KG)
S3 becldr3Service; C:\Program Files (x86)\BCL Technologies\easyConverter SDK 3\Common\becldr.exe [176128 2011-04-19] () [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2014-09-17] (NVIDIA Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MSSQL$CSSQL08; c:\Program Files\Microsoft SQL Server\MSSQL10_50.CSSQL08\MSSQL\Binn\sqlservr.exe [62111072 2011-06-17] (Microsoft Corporation)
R3 MSSQLFDLauncher$CSSQL08; c:\Program Files\Microsoft SQL Server\MSSQL10_50.CSSQL08\MSSQL\Binn\fdlauncher.exe [32096 2010-04-03] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1795912 2014-09-17] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19439944 2014-09-17] (NVIDIA Corporation)
S4 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-05-13] ()
S4 RealPlayer Cloud Service; C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe [1141848 2014-06-24] (RealNetworks, Inc.)
S4 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [23552 2014-05-23] () [File not signed]
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-02-10] () [File not signed]
S4 SQLAgent$CSSQL08; c:\Program Files\Microsoft SQL Server\MSSQL10_50.CSSQL08\MSSQL\Binn\SQLAGENT.EXE [431456 2011-06-17] (Microsoft Corporation)
R2 UI Assistant Service; C:\Program Files (x86)\1&1 Surf-Stick\AssistantServices.exe [253264 2010-09-30] ()
S3 UPnPService; C:\Program Files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [548864 2008-10-21] (Magix AG) [File not signed]
S4 watchmi; C:\Program Files (x86)\watchmi\TvdService.exe [70144 2011-10-07] () [File not signed]
R2 WinDefend; C:\Program Files (x86)\Windows Defender\mpsvc.dll [680960 2012-10-31] (Microsoft Corporation) [File not signed]
R3 WisLMSvc; C:\Program Files (x86)\Launch Manager\WisLMSvc.exe [118560 2009-10-23] (Wistron Corp.)
R2 x10nets; C:\Program Files (x86)\Common Files\X10\Common\X10nets.exe [20480 2009-11-07] (X10) [File not signed]
S2 MsMpSvc; "c:\Program Files\Microsoft Security Client\MsMpEng.exe" [X]
S3 MySQL56; "C:/Program Files/MySQL/MySQL Server 5.6/bin\mysqld" --defaults-file="C:\ProgramData\MySQL\MySQL Server 5.6\my.ini" MySQL56 [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2011-07-04] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-05] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-27] (Avira Operations GmbH & Co. KG)
R0 BootDefragDriver; C:\Windows\System32\drivers\BootDefragDriver.sys [17600 2014-07-18] (Glarysoft Ltd)
R1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20160 2014-10-04] (Glarysoft Ltd)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2011-07-04] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-10-15] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
S3 mod7764; C:\Windows\System32\DRIVERS\mod77-64.sys [909408 2009-08-13] (DiBcom SA)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19272 2014-09-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation)
R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [15896 2009-05-13] (X10 Wireless Technology, Inc.)
S3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [32792 2009-05-13] (X10 Wireless Technology, Inc.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-15 09:44 - 2014-10-15 09:44 - 00000314 _____ () C:\Windows\PFRO.log
2014-10-15 09:39 - 2014-10-15 09:42 - 00000000 ____D () C:\AdwCleaner
2014-10-15 08:55 - 2014-10-15 09:35 - 01976320 _____ () C:\Users\Marcel\Downloads\AdwCleaner_4.000(1).exe
2014-10-15 08:48 - 2014-10-15 08:48 - 00018679 _____ () C:\Users\Marcel\Desktop\JRT.txt
2014-10-15 08:41 - 2014-10-15 08:41 - 00000000 ____D () C:\Windows\ERUNT
2014-10-15 08:23 - 2014-10-15 08:38 - 01705698 _____ (Thisisu) C:\Users\Marcel\Downloads\JRT.exe
2014-10-14 20:08 - 2014-10-14 20:12 - 00003578 _____ () C:\Users\Marcel\Desktop\mbam.txt
2014-10-14 20:00 - 2014-10-15 09:47 - 00000336 _____ () C:\Windows\setupact.log
2014-10-14 20:00 - 2014-10-14 20:00 - 00000000 _____ () C:\Windows\setuperr.log
2014-10-14 17:52 - 2014-10-14 17:52 - 00041031 _____ () C:\Users\Marcel\Downloads\AdwCleaner_4.000.exe
2014-10-13 16:47 - 2014-10-13 16:47 - 09248768 _____ () C:\Users\Marcel\Downloads\BA Biosensortechnik 8.Vorlesung neu.ppt
2014-10-13 16:47 - 2014-10-13 16:47 - 05229568 _____ () C:\Users\Marcel\Downloads\BA Biosensortechnik 6.Vorlesung neu.ppt
2014-10-13 14:36 - 2014-10-13 14:36 - 00003234 _____ () C:\Windows\System32\Tasks\SidebarExecute
2014-10-13 12:31 - 2014-10-13 12:31 - 00034521 _____ () C:\ComboFix.txt
2014-10-13 11:58 - 2014-10-13 12:31 - 00000000 ____D () C:\Qoobox
2014-10-13 11:58 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-10-13 11:58 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-10-13 11:58 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-10-13 11:58 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-10-13 11:58 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-10-13 11:58 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-10-13 11:58 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-10-13 11:58 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-10-13 11:57 - 2014-10-13 12:28 - 00000000 ____D () C:\Windows\erdnt
2014-10-13 11:54 - 2014-10-13 11:54 - 05582915 ____R (Swearware) C:\Users\Marcel\Desktop\ComboFix.exe
2014-10-13 11:19 - 2014-10-13 11:19 - 00011306 _____ () C:\Users\Marcel\Desktop\Maleware.txt
2014-10-12 12:10 - 2014-10-12 12:12 - 00082484 _____ () C:\Users\Marcel\Downloads\Addition.txt
2014-10-12 12:08 - 2014-10-15 09:58 - 00022865 _____ () C:\Users\Marcel\Downloads\FRST.txt
2014-10-12 12:08 - 2014-10-15 09:57 - 00000000 ____D () C:\FRST
2014-10-12 12:08 - 2014-10-12 12:08 - 02109952 _____ (Farbar) C:\Users\Marcel\Downloads\FRST64.exe
2014-10-12 12:03 - 2014-10-15 09:50 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-12 12:03 - 2014-10-12 12:03 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-12 12:03 - 2014-10-12 12:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-12 12:03 - 2014-10-12 12:03 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-12 12:03 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-12 12:03 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-12 12:03 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-12 12:01 - 2014-10-12 12:02 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Marcel\Downloads\mbam-setup-2.0.2.1012(1).exe
2014-10-12 11:36 - 2014-10-12 11:36 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-11 18:52 - 2014-10-12 09:24 - 00025088 _____ () C:\Users\Marcel\Desktop\Solarautarkie.xls
2014-10-11 18:01 - 2014-10-11 18:01 - 00028672 _____ () C:\Users\Marcel\Desktop\Frequenztests.xls
2014-10-11 15:13 - 2014-10-15 09:49 - 00000380 _____ () C:\Windows\Tasks\RNUpgradeHelperLogonPrompt_Marcel.job
2014-10-11 15:13 - 2014-10-13 16:10 - 00000370 _____ () C:\Windows\Tasks\ReclaimerUpdateXML_Marcel.job
2014-10-11 15:13 - 2014-10-13 14:27 - 00000374 _____ () C:\Windows\Tasks\ReclaimerUpdateFiles_Marcel.job
2014-10-11 15:13 - 2014-10-11 15:13 - 00003618 _____ () C:\Windows\System32\Tasks\RNUpgradeHelperResumePrompt_Marcel
2014-10-11 15:13 - 2014-10-11 15:13 - 00002968 _____ () C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Marcel
2014-10-11 15:13 - 2014-10-11 15:13 - 00002964 _____ () C:\Windows\System32\Tasks\ReclaimerUpdateXML_Marcel
2014-10-11 15:13 - 2014-10-11 15:13 - 00002672 _____ () C:\Windows\System32\Tasks\RNUpgradeHelperLogonPrompt_Marcel
2014-10-11 09:56 - 2014-10-11 09:56 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-10-10 19:05 - 2014-10-10 19:06 - 02347384 _____ (ESET) C:\Users\Marcel\Downloads\esetsmartinstaller_deu.exe
2014-10-10 18:58 - 2014-10-10 18:58 - 00985600 _____ () C:\Users\Marcel\Downloads\MicrosoftFixit50123.msi
2014-10-04 17:17 - 2014-10-04 17:17 - 00001070 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-10-04 16:41 - 2014-10-04 16:41 - 17323696 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-10-04 16:21 - 2014-10-04 16:21 - 14515184 _____ () C:\Users\Marcel\Downloads\Glary_Utilities_v5.9.0.16.exe
2014-09-26 19:27 - 2014-09-26 19:27 - 04965896 _____ (Piriform Ltd) C:\Users\Marcel\Downloads\ccsetup418.exe
2014-09-26 17:42 - 2014-09-26 17:42 - 00000000 ____D () C:\Windows\SysWOW64\NV
2014-09-26 17:42 - 2014-09-26 17:42 - 00000000 ____D () C:\Windows\system32\NV
2014-09-26 17:42 - 2014-09-13 22:13 - 00613696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2014-09-26 17:31 - 2014-09-14 01:48 - 31887680 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 24552592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 20922512 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 20589536 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 19954520 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 18106152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 17259664 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 14026304 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 13939272 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 13157696 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-09-26 17:31 - 2014-09-14 01:48 - 11392576 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 11330776 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 04287296 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 04008592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 02838424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 01876296 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434411.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 01539272 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434411.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 00957584 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 00925896 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 00919240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 00894096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 00352016 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 00303600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-09-26 17:31 - 2014-09-14 01:48 - 00032576 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys
2014-09-25 15:22 - 2014-09-02 08:22 - 00001148 _____ () C:\Users\Marcel\Desktop\Zertifizierungsstelle BARiesa.p7b
2014-09-25 15:22 - 2014-09-02 08:22 - 00000977 _____ () C:\Users\Marcel\Desktop\Zertifizierungsstelle BA-License.p7b
2014-09-22 23:05 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-09-22 23:05 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-09-22 23:05 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-09-22 23:05 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-09-22 23:05 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-09-22 23:05 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-09-22 23:05 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-09-22 23:05 - 2013-02-27 07:47 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-09-22 22:50 - 2014-09-04 21:14 - 00038048 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-09-22 22:50 - 2014-09-04 21:14 - 00032416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-09-22 20:51 - 2014-09-22 20:51 - 00002517 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-09-22 20:51 - 2014-09-22 20:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-09-22 19:51 - 2014-09-22 19:51 - 00003156 _____ () C:\Windows\System32\Tasks\{3E132288-3464-4877-8030-6BBC19534E69}
2014-09-22 19:39 - 2014-09-22 19:39 - 00003094 _____ () C:\Windows\System32\Tasks\{044D9CA1-D1E9-40BE-B81E-415FAA2D7E0A}
2014-09-22 19:29 - 2014-09-22 19:29 - 00003094 _____ () C:\Windows\System32\Tasks\{C95A1DD9-7FEA-4D0C-98DA-313729341CC2}
2014-09-22 19:28 - 2014-09-22 19:28 - 00003094 _____ () C:\Windows\System32\Tasks\{B285F283-6178-4F00-B6D9-3A5B3CF6FF5A}
2014-09-22 19:06 - 2014-09-22 19:06 - 00003156 _____ () C:\Windows\System32\Tasks\{B748552C-D57B-4069-95F1-C6349F29783C}
2014-09-22 19:00 - 2014-09-22 19:00 - 00003146 _____ () C:\Windows\System32\Tasks\{45F64A13-7CA0-4E84-B2CE-04812DF233B8}
2014-09-22 18:46 - 2014-09-22 18:46 - 00003156 _____ () C:\Windows\System32\Tasks\{D53FECF9-1117-4C29-99C8-C40376599B86}
2014-09-22 18:34 - 2014-09-22 18:34 - 00003156 _____ () C:\Windows\System32\Tasks\{88695C04-9E78-494E-8380-2FDF312D2885}
2014-09-22 18:29 - 2014-09-22 18:29 - 00003094 _____ () C:\Windows\System32\Tasks\{45E936A0-1E47-45CB-BE7F-91497F8A6BFF}
2014-09-18 07:54 - 2014-09-18 07:54 - 00000165 ____H () C:\Users\Marcel\Desktop\~$Entwicklung eines Teststreifens zum Nachweis von Clenbuterol -.pptx
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-15 09:56 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-15 09:56 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-15 09:52 - 2011-04-11 09:32 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-15 09:48 - 2014-08-11 15:09 - 00000334 _____ () C:\Windows\Tasks\GlaryInitialize 5.job
2014-10-15 09:46 - 2011-06-26 21:09 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-10-15 09:46 - 2011-04-11 09:32 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-15 09:45 - 2011-02-17 14:05 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-10-15 09:45 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-15 09:43 - 2012-01-28 14:53 - 01058310 _____ () C:\Windows\WindowsUpdate.log
2014-10-15 09:42 - 2014-08-09 00:19 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\Common
2014-10-15 09:41 - 2013-01-19 18:23 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-15 09:14 - 2011-12-25 20:29 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\Skype
2014-10-15 06:41 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2014-10-14 20:09 - 2011-02-03 03:28 - 00766306 _____ () C:\Windows\system32\perfh007.dat
2014-10-14 20:09 - 2011-02-03 03:28 - 00175006 _____ () C:\Windows\system32\perfc007.dat
2014-10-14 20:09 - 2009-07-14 07:13 - 01808470 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-14 20:01 - 2014-08-11 15:09 - 00000000 ____D () C:\Program Files (x86)\Glary Utilities 5
2014-10-14 16:45 - 2013-07-07 15:23 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\vlc
2014-10-14 16:26 - 2014-01-17 01:00 - 00003938 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{60C9DE2F-2ABB-493F-8209-2B2EDD2189AA}
2014-10-14 16:14 - 2012-06-06 18:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-13 21:25 - 2014-08-17 23:10 - 00001141 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-10-13 21:25 - 2014-08-17 23:10 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-13 21:25 - 2012-11-01 09:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-10-13 21:25 - 2012-11-01 09:12 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-10-13 21:22 - 2014-06-20 22:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-10-13 19:26 - 2013-03-11 18:29 - 00000000 ____D () C:\Users\Marcel\AppData\Local\Deployment
2014-10-13 19:26 - 2013-03-11 18:29 - 00000000 ____D () C:\Users\Marcel\AppData\Local\Apps\2.0
2014-10-13 12:31 - 2013-04-21 11:53 - 00000000 ____D () C:\Users\.wh..wh.plnk
2014-10-13 12:31 - 2013-04-21 11:53 - 00000000 ____D () C:\Users\.wh..wh.orph
2014-10-13 12:31 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-10-13 12:22 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-10-13 12:19 - 2013-11-22 20:49 - 00003366 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-1687652912-988993815-1256219632-1002
2014-10-13 12:19 - 2013-11-17 11:46 - 00003234 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-1687652912-988993815-1256219632-1002
2014-10-13 12:14 - 2011-04-11 09:37 - 00000000 ____D () C:\Users\Marcel
2014-10-12 12:28 - 2014-02-28 01:43 - 00739328 ___SH () C:\Users\Marcel\Downloads\Thumbs.db
2014-10-11 18:01 - 2014-01-07 18:14 - 00023040 _____ () C:\Users\Marcel\Desktop\Microsoft Excel-Arbeitsblatt (neu).xls
2014-10-11 12:41 - 2012-11-22 01:50 - 00000000 ____D () C:\Users\Marcel\Desktop\Studium
2014-10-09 12:02 - 2012-02-21 14:01 - 00007604 _____ () C:\Users\Marcel\AppData\Local\Resmon.ResmonCfg
2014-10-09 11:13 - 2011-11-21 16:54 - 00000000 ____D () C:\Users\Marcel\Documents\Wichtiges
2014-10-09 08:08 - 2014-08-11 15:09 - 00000000 ____D () C:\Users\Marcel\AppData\Roaming\DiskDefrag
2014-10-04 17:17 - 2013-07-07 15:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-10-04 16:41 - 2013-01-19 18:23 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-10-04 16:41 - 2013-01-19 18:23 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-10-04 16:41 - 2011-12-21 09:35 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-10-04 16:22 - 2014-08-11 15:09 - 00020160 _____ (Glarysoft Ltd) C:\Windows\system32\Drivers\GUBootStartup.sys
2014-10-04 16:22 - 2014-08-11 15:09 - 00002976 _____ () C:\Windows\System32\Tasks\GU5SkipUAC
2014-10-04 16:22 - 2014-08-11 15:09 - 00002634 _____ () C:\Windows\System32\Tasks\GlaryInitialize 5
2014-10-04 16:22 - 2014-08-11 15:09 - 00001096 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
2014-10-04 16:22 - 2014-08-11 15:09 - 00001084 _____ () C:\Users\Public\Desktop\Glary Utilities 5.lnk
2014-10-01 11:43 - 2012-10-30 17:54 - 00000000 ____D () C:\Users\Marcel\Desktop\Privat
2014-09-30 21:28 - 2014-02-26 18:08 - 00696832 ___SH () C:\Users\Marcel\Desktop\Thumbs.db
2014-09-26 19:27 - 2012-10-20 23:16 - 00002774 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-09-26 19:27 - 2011-07-26 18:39 - 00000826 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-09-26 19:27 - 2011-07-26 18:39 - 00000000 ____D () C:\Program Files\CCleaner
2014-09-26 17:42 - 2013-03-09 14:36 - 00000000 ____D () C:\Temp
2014-09-26 17:42 - 2012-10-30 23:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-09-26 17:42 - 2011-02-17 14:05 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-09-25 10:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-23 08:35 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-22 22:53 - 2011-02-17 14:04 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-09-22 20:51 - 2011-12-25 20:29 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-09-22 20:51 - 2011-12-25 20:29 - 00000000 ____D () C:\ProgramData\Skype
2014-09-22 01:07 - 2013-02-15 01:26 - 00002023 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-09-22 01:07 - 2011-02-04 23:32 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-09-18 07:45 - 2013-05-17 19:35 - 00000000 ____D () C:\ProgramData\CambridgeSoft
2014-09-17 08:35 - 2014-02-25 22:52 - 00000952 ___SH () C:\ProgramData\KGyGaAvL.sys
2014-09-17 04:13 - 2014-08-06 18:32 - 01291280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2014-09-17 04:13 - 2014-03-11 17:02 - 02193560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-09-17 04:12 - 2014-08-06 18:32 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-09-17 04:12 - 2014-03-11 17:02 - 02799784 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-09-15 23:28 - 2013-04-03 18:21 - 00000584 _____ () C:\Users\Marcel\Documents\grstyles.stl
2014-09-15 09:06 - 2011-02-03 19:13 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
Some content of TEMP:
====================
C:\Users\Marcel\AppData\Local\Temp\avgnt.exe
C:\Users\Marcel\AppData\Local\Temp\Quarantine.exe
C:\Users\Marcel\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Marcel\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-10-06 00:58
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- --- |