NeedHelp08 | 06.05.2014 14:43 | Hallo...
Hier sind die Logs in der von dir gewünschten Reihenfolge.
Dankeschön Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 06.05.2014
Suchlauf-Zeit: 14:18:20
Logdatei: protokoll.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.05.06.04
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Cena
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 300963
Verstrichene Zeit: 23 Min, 46 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 60
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\CLSID\{E6062A33-016E-4BDA-A6F1-890D989F8656}, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\CLSID\{CACBAC2D-FDC3-4608-A289-6F281F471B83}, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CACBAC2D-FDC3-4608-A289-6F281F471B83}, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\TYPELIB\{73BB74C6-8886-4245-BCDA-448137D75D42}, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{73BB74C6-8886-4245-BCDA-448137D75D42}, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\HD Streamer.Tool.1, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\HD Streamer.Tool, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\HD Streamer.Tool, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\HD Streamer.Tool.1, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E6062A33-016E-4BDA-A6F1-890D989F8656}, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\HD Streamer.ScriptHostObject.1, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\HD Streamer.ScriptHostObject, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\HD Streamer.ScriptHostObject, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E6062A33-016E-4BDA-A6F1-890D989F8656}, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E6062A33-016E-4BDA-A6F1-890D989F8656}, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\HD Streamer.ScriptHostObject.1, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\CLSID\{E6062A33-016E-4BDA-A6F1-890D989F8656}\INPROCSERVER32, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3868E0C2-3E75-445F-B748-C97BB82300AC}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\TYPELIB\{6D697641-4C65-49F0-8CED-FE8180B5E37E}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{6D697641-4C65-49F0-8CED-FE8180B5E37E}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\HD Streamer.Navbar.1, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\HD Streamer.Navbar, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\HD Streamer.Navbar, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\HD Streamer.Navbar.1, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\CLSID\{3868E0C2-3E75-445F-B748-C97BB82300AC}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\TYPELIB\{E7ABCD91-74F6-45AD-968B-A45EB265072C}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{045F91B3-695F-423A-98C7-8DE3C47AA020}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{A1440EC3-F0FA-407A-B811-DE6668C06D29}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{C815E3DA-0823-49B0-9270-D1771D58B317}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{E4A994B0-5550-4680-A4C6-B9470B888069}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\INTERFACE\{F9EB11AB-9384-4736-9B33-993940F88895}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{045F91B3-695F-423A-98C7-8DE3C47AA020}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A1440EC3-F0FA-407A-B811-DE6668C06D29}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C815E3DA-0823-49B0-9270-D1771D58B317}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E4A994B0-5550-4680-A4C6-B9470B888069}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F9EB11AB-9384-4736-9B33-993940F88895}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E7ABCD91-74F6-45AD-968B-A45EB265072C}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\CLASSES\TYPELIB\{5375FB9F-DF09-444B-9DC0-C6ED079C2577}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{5375FB9F-DF09-444B-9DC0-C6ED079C2577}, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\HD Streamer, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 5
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\skin, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
Dateien: 54
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\ScriptHost64.dll, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\ScriptHost.dll, In Quarantäne, [728e37c9e41c8d73de3cef32659d956b],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\background.html, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\ButtonSite.dll, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\ButtonSite64.dll, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\128.png, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\16.ico, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\16.png, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\18.png, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\32.ico, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\32.png, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\48.png, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\AddonsFramework.Typelib.dll, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\AddonsFramework.Typelib64.dll, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\BackgroundHost.exe, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\BackgroundHost64.exe, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\bg.js, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\config.xml, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\content.js, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\jquery-1.9.1.min.js, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\json2.min.js, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\options.htm, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\settings.html, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\settings.js, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\settings_128.png, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\uninstall.exe, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\updater.js, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer, C:\Program Files (x86)\HD Streamer\updaterWrapper.js, In Quarantäne, [b0500df32cd40ef28a7a375454ae59a7],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome.manifest, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\icon.png, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\install.rdf, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\128.png, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\16.ico, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\16.png, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\18.png, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\32.ico, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\32.png, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\48.png, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\background.html, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\bg.js, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\button.xml, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\config.js, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\content.js, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\framework.js, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\framework.png, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\framework.xul, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\jquery-1.9.1.min.js, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\options.xul, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\settings.html, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\settings.js, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\settings.json, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\settings_128.png, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\content\subscriptloader.js, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
PUP.Optional.HDStreamer.A, C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\extensions\hd_streamer@iMedia\chrome\skin\framework.css, In Quarantäne, [cb354cb4758b659b1ceab7b851b1d828],
Physische Sektoren: 0
(No malicious items detected)
(end) AdwCleaner Logfile: Code:
# AdwCleaner v3.207 - Bericht erstellt am 06/05/2014 um 14:29:57
# Aktualisiert 05/05/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Cena - CENA-PC
# Gestartet von : C:\Users\Cena\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : EnablerService
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\Addon Enabler
Ordner Gelöscht : C:\Program Files (x86)\HD Streamer
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\AddonsFramework.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ButtonSite.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHost.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{19975B78-1907-4DD6-A437-4C48120F46A4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{562B9316-C08A-444A-9482-62080DD851AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{562B9317-C08A-444A-9482-62080DD851AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E6062A33-016E-4BDA-A6F1-890D989F8656}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F9EB11AB-9384-4736-9B33-993940F88895}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6062A33-016E-4BDA-A6F1-890D989F8656}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{E6062A33-016E-4BDA-A6F1-890D989F8656}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BBBE01ED-0F1E-44DB-88C1-5CC1AEE3B462}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F9EB11AB-9384-4736-9B33-993940F88895}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6062A33-016E-4BDA-A6F1-890D989F8656}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HD Streamer
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\HD Streamer
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16545
-\\ Mozilla Firefox v29.0 (de)
[ Datei : C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\prefs.js ]
*************************
AdwCleaner[R0].txt - [5011 octets] - [06/05/2014 14:26:40]
AdwCleaner[S0].txt - [4860 octets] - [06/05/2014 14:29:57]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4920 octets] ########## --- --- ---
[/CODE] Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Cena on 06.05.2014 at 14:33:53,59
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Cena\AppData\Roaming\mozilla\firefox\profiles\l96ctmzd.default-1381765439836\minidumps [6 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06.05.2014 at 14:53:19,97
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und die FRST.txt
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-05-2014
Ran by Cena (administrator) on CENA-PC on 06-05-2014 14:54:44
Running from C:\Users\Cena\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Foxit Corporation) C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\System32\PrintCtrl.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Thisisu) C:\Users\Cena\Downloads\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191312 2012-08-07] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2816336 2012-05-09] (ELAN Microelectronics Corp.)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [438784 2010-12-17] ()
HKLM\...\Run: [PrintDisp] => C:\Windows\system32\PrintDisp.exe [826368 2011-02-19] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-07-03] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3873704 2014-04-28] (AVAST Software)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [174296 2014-02-08] (NVIDIA Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [174296 2014-02-08] (NVIDIA Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [174296 2014-02-08] (NVIDIA Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [174296 2014-02-08] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [148528 2014-02-08] (NVIDIA Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB53A02624DD5CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Samsung BHO Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836
FF Homepage: about:home
FF NetworkProxy: "backup.ftp", "64.34.14.28"
FF NetworkProxy: "backup.ftp_port", 7808
FF NetworkProxy: "backup.socks", "64.34.14.28"
FF NetworkProxy: "backup.socks_port", 7808
FF NetworkProxy: "backup.ssl", "64.34.14.28"
FF NetworkProxy: "backup.ssl_port", 7808
FF NetworkProxy: "ftp", "68.71.76.242"
FF NetworkProxy: "ftp_port", 8082
FF NetworkProxy: "http", "68.71.76.242"
FF NetworkProxy: "http_port", 8082
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "68.71.76.242"
FF NetworkProxy: "socks_port", 8082
FF NetworkProxy: "ssl", "68.71.76.242"
FF NetworkProxy: "ssl_port", 8082
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.4 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: HD Streamer - C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\Extensions\hd_streamer@iMedia [2014-05-06]
FF Extension: ProxTube - Unblock YouTube - C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\Extensions\ich@maltegoetz.de [2013-12-19]
FF Extension: EPUBReader - C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F} [2013-12-03]
FF Extension: WOT - C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-26]
FF Extension: DownloadHelper - C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-26]
FF Extension: Check4Change - C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\Extensions\check4change-owner@mozdev.org.xpi [2014-03-03]
FF Extension: Adblock Plus - C:\Users\Cena\AppData\Roaming\Mozilla\Firefox\Profiles\l96ctmzd.default-1381765439836\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-22]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-12-08]
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-28] (AVAST Software)
R2 ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [79664 2012-03-30] (Diskeeper Corporation)
R2 FoxitCloudUpdateService; C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [239680 2014-02-19] (Foxit Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-12-08] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-12-08] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-05-08] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation)
S3 Samsung UPD Service2; C:\Windows\System32\SUPDSvc2.exe [165456 2011-12-02] (Samsung Electronics)
R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] ()
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3385584 2013-05-08] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31920 2013-06-02] (Wondershare)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-04-28] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-28] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-04-28] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-28] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-04-28] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-04-28] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-04-28] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-04-28] ()
R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23344 2012-03-30] (Diskeeper Corporation)
R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [95024 2012-03-30] (Diskeeper Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-06 14:54 - 2014-05-06 14:54 - 00000000 ____D () C:\Users\Cena\Downloads\FRST-OlderVersion
2014-05-06 14:53 - 2014-05-06 14:53 - 00000768 _____ () C:\Users\Cena\Desktop\JRT.txt
2014-05-06 14:32 - 2014-05-06 14:32 - 01016261 _____ (Thisisu) C:\Users\Cena\Downloads\JRT.exe
2014-05-06 14:26 - 2014-05-06 14:30 - 00000000 ____D () C:\AdwCleaner
2014-05-06 14:25 - 2014-05-06 14:25 - 01316991 _____ () C:\Users\Cena\Downloads\adwcleaner.exe
2014-05-06 14:23 - 2014-05-06 14:23 - 00020452 _____ () C:\Users\Cena\Downloads\mbam.txt
2014-05-06 14:19 - 2014-05-06 14:30 - 00019560 _____ () C:\Windows\PFRO.log
2014-05-05 23:23 - 2014-05-05 23:25 - 00000000 ____D () C:\Users\Cena\Desktop\musik
2014-05-05 12:54 - 2014-04-29 13:39 - 17849344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-05 12:54 - 2014-04-29 13:15 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-05 12:54 - 2014-04-29 12:28 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-05 12:54 - 2014-04-29 12:07 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-05 11:51 - 2014-05-05 11:51 - 00001268 _____ () C:\Users\Public\Desktop\Nero Burning ROM.lnk
2014-05-05 11:50 - 2014-05-05 11:50 - 00000000 ____D () C:\Program Files (x86)\Nero
2014-05-05 11:08 - 2014-05-05 11:08 - 00000000 ____D () C:\Users\Cena\AppData\Roaming\30593
2014-05-05 11:00 - 2014-05-05 11:11 - 00000000 ____D () C:\Users\Cena\Documents\DVDFab9
2014-05-04 18:59 - 2014-05-04 18:59 - 00029105 _____ () C:\Users\Cena\Downloads\Addition.txt
2014-05-04 18:58 - 2014-05-06 14:54 - 00016313 _____ () C:\Users\Cena\Downloads\FRST.txt
2014-05-04 18:58 - 2014-05-06 14:54 - 00000000 ____D () C:\FRST
2014-05-04 18:57 - 2014-05-06 14:54 - 02063872 _____ (Farbar) C:\Users\Cena\Downloads\FRST64.exe
2014-05-04 11:07 - 2014-05-04 11:07 - 00000000 ____D () C:\Users\Cena\Desktop\Matthias_Reim-Die_Leichtigkeit_Des_Seins-2CD-DE-2014-VOiCE
2014-05-03 21:28 - 2014-05-06 14:30 - 00001299 _____ () C:\Windows\setupact.log
2014-05-03 21:28 - 2014-05-03 21:28 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-03 19:36 - 2014-05-03 19:36 - 08761447 _____ () C:\Users\Cena\Downloads\01 They Dont Love You No More (feat..m4a
2014-05-03 19:28 - 2014-05-03 19:28 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-05-03 19:28 - 2014-05-03 19:28 - 00000000 ____D () C:\Users\Cena\AppData\Local\Skype
2014-05-03 19:28 - 2014-05-03 19:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-05-03 19:26 - 2014-05-03 19:26 - 00000877 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-05-03 19:20 - 2014-05-03 19:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-03 19:18 - 2014-05-03 19:18 - 00001942 _____ () C:\DelFix.txt
2014-05-03 18:26 - 2014-05-06 14:22 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-03 18:26 - 2014-05-03 18:26 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-03 18:26 - 2014-05-03 18:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-03 18:26 - 2014-05-03 18:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-03 18:26 - 2014-05-03 18:26 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-03 18:26 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-03 18:26 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-03 18:26 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-03 17:26 - 2014-05-03 19:18 - 00000000 ____D () C:\Windows\ERUNT
2014-04-29 09:23 - 2014-04-29 09:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2014-04-28 10:17 - 2014-04-28 10:17 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-04-28 10:17 - 2014-04-28 10:17 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-04-28 10:17 - 2014-04-28 10:17 - 00001972 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-04-26 19:31 - 2014-04-26 19:31 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-26 19:31 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-26 19:31 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-26 18:17 - 2014-04-26 18:17 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01009.Wdf
2014-04-23 12:44 - 2014-04-23 12:44 - 00000000 ____D () C:\Users\Cena\dwhelper
2014-04-18 20:51 - 2014-04-18 20:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ggsemc_01009.Wdf
2014-04-18 20:51 - 2014-04-18 20:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ggflt_01009.Wdf
2014-04-18 20:46 - 2014-04-18 21:03 - 00000000 ____D () C:\Users\Cena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sony Mobile
2014-04-18 20:46 - 2014-04-18 21:03 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile
2014-04-18 20:46 - 2014-04-18 20:46 - 00027760 _____ (Sony Ericsson Mobile Communications) C:\Windows\system32\Drivers\ggsemc.sys
2014-04-18 20:46 - 2014-04-18 20:46 - 00014448 _____ (Sony Ericsson Mobile Communications) C:\Windows\system32\Drivers\ggflt.sys
2014-04-18 09:06 - 2014-03-08 06:06 - 10926592 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-18 09:06 - 2014-03-08 05:49 - 02334720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-18 09:06 - 2014-03-08 05:41 - 01347072 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-18 09:06 - 2014-03-08 05:40 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-18 09:06 - 2014-03-08 05:39 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-18 09:06 - 2014-03-08 05:38 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-04-18 09:06 - 2014-03-08 05:37 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-18 09:06 - 2014-03-08 05:34 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-04-18 09:06 - 2014-03-08 05:34 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-18 09:06 - 2014-03-08 05:33 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-18 09:06 - 2014-03-08 05:32 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-18 09:06 - 2014-03-08 05:32 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-18 09:06 - 2014-03-08 05:30 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-04-18 09:06 - 2014-03-08 05:24 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-18 09:06 - 2014-03-08 01:20 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-18 09:06 - 2014-03-08 01:12 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-18 09:06 - 2014-03-08 01:03 - 01105408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-18 09:06 - 2014-03-08 01:02 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-18 09:06 - 2014-03-08 01:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-18 09:06 - 2014-03-08 01:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-04-18 09:06 - 2014-03-08 00:59 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-18 09:06 - 2014-03-08 00:57 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-04-18 09:06 - 2014-03-08 00:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-18 09:06 - 2014-03-08 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-18 09:06 - 2014-03-08 00:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-18 09:06 - 2014-03-08 00:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-18 09:06 - 2014-03-08 00:52 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-04-18 09:06 - 2014-03-08 00:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-18 09:03 - 2014-04-18 09:03 - 00004224 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-18 09:03 - 2014-04-18 09:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-18 09:03 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-18 09:03 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-18 09:03 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-18 09:03 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-17 17:01 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-17 17:01 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-17 17:01 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-17 17:01 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-17 17:01 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-17 17:01 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-17 17:01 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-17 17:01 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-17 17:01 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-17 17:01 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-17 17:01 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-17 17:01 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-17 17:01 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-17 17:01 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-17 17:01 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-17 17:01 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-17 17:01 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
==================== One Month Modified Files and Folders =======
2014-05-06 14:54 - 2014-05-06 14:54 - 00000000 ____D () C:\Users\Cena\Downloads\FRST-OlderVersion
2014-05-06 14:54 - 2014-05-04 18:58 - 00016313 _____ () C:\Users\Cena\Downloads\FRST.txt
2014-05-06 14:54 - 2014-05-04 18:58 - 00000000 ____D () C:\FRST
2014-05-06 14:54 - 2014-05-04 18:57 - 02063872 _____ (Farbar) C:\Users\Cena\Downloads\FRST64.exe
2014-05-06 14:54 - 2012-12-08 16:13 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-06 14:53 - 2014-05-06 14:53 - 00000768 _____ () C:\Users\Cena\Desktop\JRT.txt
2014-05-06 14:38 - 2009-07-14 06:45 - 00031088 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-06 14:38 - 2009-07-14 06:45 - 00031088 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-06 14:35 - 2011-04-12 09:43 - 00699682 _____ () C:\Windows\system32\perfh007.dat
2014-05-06 14:35 - 2011-04-12 09:43 - 00149790 _____ () C:\Windows\system32\perfc007.dat
2014-05-06 14:35 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-06 14:32 - 2014-05-06 14:32 - 01016261 _____ (Thisisu) C:\Users\Cena\Downloads\JRT.exe
2014-05-06 14:30 - 2014-05-06 14:26 - 00000000 ____D () C:\AdwCleaner
2014-05-06 14:30 - 2014-05-06 14:19 - 00019560 _____ () C:\Windows\PFRO.log
2014-05-06 14:30 - 2014-05-03 21:28 - 00001299 _____ () C:\Windows\setupact.log
2014-05-06 14:30 - 2012-12-08 09:55 - 01436382 _____ () C:\Windows\WindowsUpdate.log
2014-05-06 14:30 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-06 14:25 - 2014-05-06 14:25 - 01316991 _____ () C:\Users\Cena\Downloads\adwcleaner.exe
2014-05-06 14:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-05-06 14:23 - 2014-05-06 14:23 - 00020452 _____ () C:\Users\Cena\Downloads\mbam.txt
2014-05-06 14:22 - 2014-05-03 18:26 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-06 14:19 - 2011-04-12 09:55 - 00000000 ____D () C:\Windows\CSC
2014-05-06 08:55 - 2013-01-08 12:33 - 00000099 _____ () C:\Users\Public\LMDebug.log
2014-05-05 23:25 - 2014-05-05 23:23 - 00000000 ____D () C:\Users\Cena\Desktop\musik
2014-05-05 23:21 - 2012-12-08 16:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-05 12:54 - 2014-03-28 10:08 - 00000000 ____D () C:\Users\Cena\AppData\Local\JDownloader 2.0
2014-05-05 11:51 - 2014-05-05 11:51 - 00001268 _____ () C:\Users\Public\Desktop\Nero Burning ROM.lnk
2014-05-05 11:51 - 2013-02-26 15:10 - 00000000 ____D () C:\Users\Cena\AppData\Roaming\Nero
2014-05-05 11:50 - 2014-05-05 11:50 - 00000000 ____D () C:\Program Files (x86)\Nero
2014-05-05 11:13 - 2012-12-29 20:20 - 00000000 ____D () C:\Users\Cena\AppData\Roaming\FileZilla
2014-05-05 11:11 - 2014-05-05 11:00 - 00000000 ____D () C:\Users\Cena\Documents\DVDFab9
2014-05-05 11:08 - 2014-05-05 11:08 - 00000000 ____D () C:\Users\Cena\AppData\Roaming\30593
2014-05-05 11:00 - 2013-10-23 19:21 - 00000000 ____D () C:\Users\Cena\AppData\Roaming\vlc
2014-05-04 18:59 - 2014-05-04 18:59 - 00029105 _____ () C:\Users\Cena\Downloads\Addition.txt
2014-05-04 11:07 - 2014-05-04 11:07 - 00000000 ____D () C:\Users\Cena\Desktop\Matthias_Reim-Die_Leichtigkeit_Des_Seins-2CD-DE-2014-VOiCE
2014-05-03 21:28 - 2014-05-03 21:28 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-03 19:36 - 2014-05-03 19:36 - 08761447 _____ () C:\Users\Cena\Downloads\01 They Dont Love You No More (feat..m4a
2014-05-03 19:30 - 2014-01-13 11:00 - 00000000 ____D () C:\Users\Cena\Downloads\fitness
2014-05-03 19:30 - 2013-03-06 14:09 - 00000000 ____D () C:\Users\Cena\AppData\Roaming\Notepad++
2014-05-03 19:29 - 2013-04-28 17:25 - 00000000 ____D () C:\Users\Cena\AppData\Roaming\Skype
2014-05-03 19:28 - 2014-05-03 19:28 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-05-03 19:28 - 2014-05-03 19:28 - 00000000 ____D () C:\Users\Cena\AppData\Local\Skype
2014-05-03 19:28 - 2014-05-03 19:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-05-03 19:28 - 2013-04-28 17:25 - 00000000 ____D () C:\ProgramData\Skype
2014-05-03 19:28 - 2012-12-19 12:09 - 00000000 ____D () C:\ProgramData\Sonos,_Inc
2014-05-03 19:27 - 2013-03-18 18:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp
2014-05-03 19:27 - 2013-03-18 18:21 - 00000000 ____D () C:\Program Files (x86)\Winamp
2014-05-03 19:26 - 2014-05-03 19:26 - 00000877 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-05-03 19:23 - 2012-12-08 15:33 - 00002770 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-05-03 19:22 - 2012-12-08 15:33 - 00000000 ____D () C:\Program Files\CCleaner
2014-05-03 19:20 - 2014-05-03 19:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-03 19:18 - 2014-05-03 19:18 - 00001942 _____ () C:\DelFix.txt
2014-05-03 19:18 - 2014-05-03 17:26 - 00000000 ____D () C:\Windows\ERUNT
2014-05-03 18:57 - 2012-12-21 13:52 - 00000000 ____D () C:\Users\Cena\.gimp-2.8
2014-05-03 18:26 - 2014-05-03 18:26 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-03 18:26 - 2014-05-03 18:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-03 18:26 - 2014-05-03 18:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-03 18:26 - 2014-05-03 18:26 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-03 18:04 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-04-29 15:00 - 2012-12-18 21:53 - 00000000 ____D () C:\Users\Cena\AppData\Roaming\Mp3tag
2014-04-29 13:39 - 2014-05-05 12:54 - 17849344 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 13:15 - 2014-05-05 12:54 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 12:28 - 2014-05-05 12:54 - 12347392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 12:07 - 2014-05-05 12:54 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-29 09:55 - 2012-12-08 16:13 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-29 09:54 - 2012-12-08 16:13 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-29 09:54 - 2012-12-08 16:13 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-29 09:23 - 2014-04-29 09:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2014-04-29 09:23 - 2012-12-18 21:51 - 00000000 ____D () C:\Program Files (x86)\Mp3tag
2014-04-28 15:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-28 10:17 - 2014-04-28 10:17 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-04-28 10:17 - 2014-04-28 10:17 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-04-28 10:17 - 2014-04-28 10:17 - 00001972 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-04-28 10:17 - 2013-12-27 10:08 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-04-28 10:17 - 2013-03-05 17:30 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-04-28 10:17 - 2013-03-05 17:30 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-04-28 10:17 - 2012-12-08 15:31 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-04-28 10:17 - 2012-12-08 15:31 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-04-28 10:17 - 2012-12-08 15:31 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-04-28 10:17 - 2012-12-08 15:31 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-04-28 10:17 - 2012-12-08 15:31 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-04-28 10:17 - 2012-12-08 15:31 - 00003924 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-04-26 19:31 - 2014-04-26 19:31 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-26 18:17 - 2014-04-26 18:17 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01009.Wdf
2014-04-25 13:58 - 2013-10-14 17:55 - 00000000 ____D () C:\Program Files (x86)\FileZilla FTP Client
2014-04-25 13:58 - 2013-05-14 10:45 - 00002006 _____ () C:\Users\Public\Desktop\FileZilla Client.lnk
2014-04-25 13:58 - 2013-05-14 10:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2014-04-24 17:07 - 2013-03-18 18:21 - 00000000 ____D () C:\Users\Cena\AppData\Roaming\Winamp
2014-04-23 17:24 - 2012-12-19 12:10 - 00001953 _____ () C:\Users\Public\Desktop\Sonos.lnk
2014-04-23 17:24 - 2012-12-19 12:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sonos
2014-04-23 17:24 - 2012-12-19 12:10 - 00000000 ____D () C:\Program Files (x86)\Sonos
2014-04-23 17:24 - 2012-12-19 12:09 - 00000000 ____D () C:\Users\Cena\AppData\Local\Downloaded Installations
2014-04-23 12:44 - 2014-04-23 12:44 - 00000000 ____D () C:\Users\Cena\dwhelper
2014-04-23 12:44 - 2012-12-08 09:55 - 00000000 ____D () C:\Users\Cena
2014-04-18 21:49 - 2014-03-29 08:53 - 00000000 ____D () C:\Users\Cena\Desktop\858HDJES
2014-04-18 21:31 - 2013-11-14 17:41 - 00000000 ____D () C:\Users\Cena\AppData\Local\Adobe
2014-04-18 21:03 - 2014-04-18 20:46 - 00000000 ____D () C:\Users\Cena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sony Mobile
2014-04-18 21:03 - 2014-04-18 20:46 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile
2014-04-18 20:58 - 2012-12-08 16:05 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-18 20:51 - 2014-04-18 20:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ggsemc_01009.Wdf
2014-04-18 20:51 - 2014-04-18 20:51 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ggflt_01009.Wdf
2014-04-18 20:46 - 2014-04-18 20:46 - 00027760 _____ (Sony Ericsson Mobile Communications) C:\Windows\system32\Drivers\ggsemc.sys
2014-04-18 20:46 - 2014-04-18 20:46 - 00014448 _____ (Sony Ericsson Mobile Communications) C:\Windows\system32\Drivers\ggflt.sys
2014-04-18 09:11 - 2013-08-15 18:05 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-18 09:08 - 2012-12-16 19:24 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-18 09:05 - 2013-10-19 20:16 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-18 09:03 - 2014-04-18 09:03 - 00004224 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-18 09:03 - 2014-04-18 09:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-18 09:03 - 2014-03-28 10:33 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-17 16:53 - 2012-12-08 17:46 - 00000830 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2014-04-17 16:53 - 2012-12-08 17:46 - 00000828 _____ () C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-04-14 20:13 - 2014-04-18 09:03 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-14 20:05 - 2014-04-18 09:03 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-14 20:05 - 2014-04-18 09:03 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-14 20:04 - 2014-04-18 09:03 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-14 04:24 - 2014-04-26 19:31 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-14 04:19 - 2014-04-26 19:31 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
Some content of TEMP:
====================
C:\Users\Cena\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\Cena\AppData\Local\Temp\Quarantine.exe
C:\Users\Cena\AppData\Local\Temp\xmlUpdater.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-29 10:03
==================== End Of Log ============================ --- --- ---
--- --- --- |