Hallo schrauber,
die Suche im revo uninstaller brachte kein Ergebnis. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 16.05.2014
Suchlauf-Zeit: 18:06:30
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.05.16.10
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: drudenfuss
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 269753
Verstrichene Zeit: 29 Min, 13 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 34
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110511291116}, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{11111111-1111-1111-1111-110511291116}, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440544294416}, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550555295516}, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660566296616}, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550555295516}, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660566296616}, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440544294416}, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0052916.BHO.1, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110511291116}, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110511291116}, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0052916.BHO, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0052916.BHO, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0052916.BHO.1, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-1407684291-1401557966-2466634541-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{11111111-1111-1111-1111-110511291116}, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-1407684291-1401557966-2466634541-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110511291116}, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{22222222-2222-2222-2222-220522292216}, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0052916.Sandbox.1, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0052916.Sandbox, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0052916.Sandbox, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0052916.Sandbox.1, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220522292216}, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110511291116}\INPROCSERVER32, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\19979, In Quarantäne, [2ded133fc4b7dd591ddac2cc748e817f],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\PSHD-9.9, In Quarantäne, [74a65bf799e252e4459e493a99691ce4],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\19979, In Quarantäne, [95857bd70774ed49d225315d39c938c8],
PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PSHD-9.9, In Quarantäne, [43d7044ebbc0c571a041117203ff48b8],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1407684291-1401557966-2466634541-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, In Quarantäne, [ee2c70e2304b1c1ad649873ff70c18e8],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-1407684291-1401557966-2466634541-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PSHD-9.9, In Quarantäne, [5fbbe66c94e74cea1bc684ff837fa35d],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1407684291-1401557966-2466634541-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\19979, In Quarantäne, [f129b1a14b303cfa9f59523c30d239c7],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-1407684291-1401557966-2466634541-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\PlusVHD, In Quarantäne, [e33771e17605072fbfe14648f30f15eb],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-1407684291-1401557966-2466634541-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT, In Quarantäne, [9387005257244aec45913b5f867c57a9],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\DD041521-E3A6-D7E6-3973-C6D4568E8EC7, In Quarantäne, [ba608dc5dc9fc4729d9ff08869999a66],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PSHD-9.9, In Quarantäne, [e03ac290bac182b43eb28bf3df231be5],
Registrierungswerte: 1
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-1407684291-1401557966-2466634541-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT|Install, 1, In Quarantäne, [9387005257244aec45913b5f867c57a9]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 4
PUP.Optional.OpenCandy, C:\Users\drudenfuss\AppData\Roaming\OpenCandy, In Quarantäne, [f525f260423921153b6b4a26c939669a],
PUP.Optional.OpenCandy, C:\Users\drudenfuss\AppData\Roaming\OpenCandy\CA131D44E9A54E2CA891D62DC23F1274, In Quarantäne, [f525f260423921153b6b4a26c939669a],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\BlockAndSurf-soft, In Quarantäne, [ba608dc5dc9fc4729d9ff08869999a66],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9, In Quarantäne, [e03ac290bac182b43eb28bf3df231be5],
Dateien: 37
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bho64.dll, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bho.dll, In Quarantäne, [1cfee66c3e3dff374c62f1880ef39a66],
PUP.Optional.Breitschopp, C:\Users\drudenfuss\Downloads\winzip(2).exe, In Quarantäne, [a07a381aa2d91125883ae15731d3d030],
PUP.Optional.Breitschopp, C:\Users\drudenfuss\Downloads\freizeitkarte-deutschland-nord.exe, In Quarantäne, [f22854fe384357dfc3ffdf5960a443bd],
PUP.Optional.Breitschopp, C:\Users\drudenfuss\Downloads\freizeitkarte-deutschland-sued.exe, In Quarantäne, [9882242edd9e1323695963d5f70d56aa],
PUP.Optional.BlockAndSurf.A, C:\Windows\Tasks\BlockAndSurf Update.job, In Quarantäne, [0e0c84ce7efd2313c34ac5be0101e31d],
PUP.Optional.CrossRider.A, C:\Windows\Tasks\05998167-6439-4088-b69d-d8e5bf3b2640-1.job, In Quarantäne, [1406aea478031620ccab90fded15d32d],
PUP.Optional.CrossRider.A, C:\Windows\Tasks\05998167-6439-4088-b69d-d8e5bf3b2640-2.job, In Quarantäne, [60ba1f33403b0f27ccab395416ecee12],
PUP.Optional.CrossRider.A, C:\Windows\Tasks\05998167-6439-4088-b69d-d8e5bf3b2640-3.job, In Quarantäne, [93876fe36516bb7ba6d1523b9f6318e8],
PUP.Optional.CrossRider.A, C:\Windows\Tasks\05998167-6439-4088-b69d-d8e5bf3b2640-4.job, In Quarantäne, [d04ae66cb7c4d46215625c3111f14db3],
PUP.Optional.CrossRider.A, C:\Windows\Tasks\05998167-6439-4088-b69d-d8e5bf3b2640-5.job, In Quarantäne, [e139f35f0774be78ee896e1fce3435cb],
PUP.Optional.OpenCandy, C:\Users\drudenfuss\AppData\Roaming\OpenCandy\CA131D44E9A54E2CA891D62DC23F1274\TuneUpUtilities2014_de-DE.exe, In Quarantäne, [f525f260423921153b6b4a26c939669a],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\BlockAndSurf-soft\161.crx, In Quarantäne, [ba608dc5dc9fc4729d9ff08869999a66],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\BlockAndSurf-soft\161.dat, In Quarantäne, [ba608dc5dc9fc4729d9ff08869999a66],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\BlockAndSurf-soft\161.xpi, In Quarantäne, [ba608dc5dc9fc4729d9ff08869999a66],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\BlockAndSurf-soft\a.db, In Quarantäne, [ba608dc5dc9fc4729d9ff08869999a66],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\BlockAndSurf-soft\b.db, In Quarantäne, [ba608dc5dc9fc4729d9ff08869999a66],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\BlockAndSurf-soft\BlockAndSurfPQO.exe, In Quarantäne, [ba608dc5dc9fc4729d9ff08869999a66],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\BlockAndSurf-soft\BlockAndSurfPQO161.bin, In Quarantäne, [ba608dc5dc9fc4729d9ff08869999a66],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\BlockAndSurf-soft\BlockAndSurfPQO161.dll, In Quarantäne, [ba608dc5dc9fc4729d9ff08869999a66],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\BlockAndSurf-soft\BlockNSurf.exe, In Quarantäne, [ba608dc5dc9fc4729d9ff08869999a66],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\BlockAndSurf-soft\Sqlite3.dll, In Quarantäne, [ba608dc5dc9fc4729d9ff08869999a66],
PUP.Optional.BlockAndSurf.A, C:\Program Files (x86)\BlockAndSurf-soft\Uninstall.exe, In Quarantäne, [ba608dc5dc9fc4729d9ff08869999a66],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\05998167-6439-4088-b69d-d8e5bf3b2640-2.exe, In Quarantäne, [e03ac290bac182b43eb28bf3df231be5],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\05998167-6439-4088-b69d-d8e5bf3b2640-3.exe, In Quarantäne, [e03ac290bac182b43eb28bf3df231be5],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\05998167-6439-4088-b69d-d8e5bf3b2640-4.exe, In Quarantäne, [e03ac290bac182b43eb28bf3df231be5],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\05998167-6439-4088-b69d-d8e5bf3b2640-5.exe, In Quarantäne, [e03ac290bac182b43eb28bf3df231be5],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\360-52916.crx, In Quarantäne, [e03ac290bac182b43eb28bf3df231be5],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\52916.crx, In Quarantäne, [e03ac290bac182b43eb28bf3df231be5],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\52916.xpi, In Quarantäne, [e03ac290bac182b43eb28bf3df231be5],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\background.html, In Quarantäne, [e03ac290bac182b43eb28bf3df231be5],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-bg.exe, In Quarantäne, [e03ac290bac182b43eb28bf3df231be5],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9-codedownloader.exe, In Quarantäne, [e03ac290bac182b43eb28bf3df231be5],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\PSHD-9.9.ico, In Quarantäne, [e03ac290bac182b43eb28bf3df231be5],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\Uninstall.exe, In Quarantäne, [e03ac290bac182b43eb28bf3df231be5],
PUP.Optional.PlusHD.A, C:\Program Files (x86)\PSHD-9.9\utils.exe, In Quarantäne, [e03ac290bac182b43eb28bf3df231be5],
PUP.Optional.CrossRider.A, C:\Users\drudenfuss\AppData\Roaming\Mozilla\Firefox\Profiles\l2c7ah0z.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "145ccfb36f9bc5ec4cfe492498d4492e");), Ersetzt,[64b6272b205b3cfa619278fec341ca36]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.208 - Bericht erstellt am 16/05/2014 um 18:20:32
# Aktualisiert 11/05/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : drudenfuss - MEINE
# Gestartet von : C:\Users\drudenfuss\Downloads\adwcleaner_3.208.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : bupService
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\SparPilotAddon
Datei Gelöscht : C:\Users\drudenfuss\AppData\Roaming\Mozilla\Firefox\Profiles\l2c7ah0z.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0B65B5CE-1CB5-4ECD-B369-2A02F614E6A5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{10E0BF94-AB2A-4FC0-86F6-AA117ABFA54C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{130DDF47-335B-4A3B-809C-6A27561D247C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{521E3668-62B3-49E2-B5C2-B82B6D2DDBEF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{676E475C-3B97-492B-9541-B853D1DF05F9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{819342BD-C4A5-425A-B7C7-A4CB08EF846A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9DA4B4BB-5C18-4AAB-803B-6BBBB0A2AAC0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A17F8466-5402-4A46-9635-AB3DB292A88C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A3F2D37F-8025-4DED-BE8F-9477FD9F11EC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D912D2DF-4651-4DF6-8752-5C0E338038C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DA076F67-EBC4-434C-9044-C9FB413CE566}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F343045E-E20A-46E1-82D8-9962C43EFC9E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{553318DA-D010-469E-84B1-496563CAE1BF}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\powerpack
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\blockAndSurf
Schlüssel Gelöscht : HKLM\Software\installedbrowserextensions
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\installedbrowserextensions
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
-\\ Mozilla Firefox v29.0 (de)
[ Datei : C:\Users\drudenfuss\AppData\Roaming\Mozilla\Firefox\Profiles\l2c7ah0z.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "145ccfb36f9bc5ec4cfe492498d4492e");
*************************
AdwCleaner[R0].txt - [28750 octets] - [14/11/2013 06:55:26]
AdwCleaner[R1].txt - [5119 octets] - [16/05/2014 18:19:33]
AdwCleaner[S0].txt - [27436 octets] - [14/11/2013 06:58:39]
AdwCleaner[S1].txt - [4731 octets] - [16/05/2014 18:20:32]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [4791 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by drudenfuss on 16.05.2014 at 18:35:17,83
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Myfree Codec
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Myfree Codec
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\LCTaskAssistant12_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\LCTaskAssistant12_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\LCTaskAssistant12_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\LCTaskAssistant12_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{00FA2264-0590-
4E4A-A105-09D1D1B032F8}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Program Files (x86)\myfree codec"
~~~ FireFox
Emptied folder: C:\Users\drudenfuss\AppData\Roaming\mozilla\firefox\profiles\l2c7ah0z.default\minidumps [12 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.05.2014 at 18:51:36,22
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-05-2014
Ran by drudenfuss (administrator) on MEINE on 16-05-2014 19:04:27
Running from C:\Users\drudenfuss\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\System Control Manager\MSIService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.5.0.28\ccsvchst.exe
(ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM) C:\Windows\System32\PrintCtrl.exe
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Crawler.com) C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(ActMask Co.,Ltd - hxxp://www.all2pdf.com) C:\Windows\System32\PrintDisp.exe
(Crawler.com) C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft) C:\Program Files (x86)\AntiBrowserSpy\AntiBrowserSpyBrowserMaske.exe
(TomTom) C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe
(Dropbox, Inc.) C:\Users\drudenfuss\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Crawler.com) C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 4\Integrator.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.5.0.28\ccsvchst.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [PrintDisp] => C:\windows\system32\PrintDisp.exe [828416 2011-08-08] (ActMask Co.,Ltd - hxxp://www.all2pdf.com)
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com)
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-01-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [MGSysCtrl] => C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe [2408448 2010-02-05] (Micro-Star International Co., Ltd.)
HKLM-x32\...\Run: [NortonOnlineBackupReminder] => C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NOBuActivation.exe [3272040 2009-12-09] (Symantec Corporation)
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\Run: [BrowserMask] => C:\PROGRAM FILES (X86)\ANTIBROWSERSPY\ANTIBROWSERSPYBROWSERMASKE.EXE [101328 2012-08-14] (Microsoft)
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\Run: [MyDriveConnect.exe] => C:\Program Files (x86)\MyDrive Connect\MyDriveConnect.exe [473496 2013-11-29] (TomTom)
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 4\StartupManager.exe [37152 2014-04-14] (Glarysoft Ltd)
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\MountPoints2: E - E:\start.exe
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\MountPoints2: {067e0b3e-aeb7-11df-aa96-406186b191b8} - F:\AutoRun.exe
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\MountPoints2: {067e0b6f-aeb7-11df-aa96-406186b191b8} - F:\AutoRun.exe
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\MountPoints2: {188d83f6-a160-11df-98f1-406186b191b8} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\MountPoints2: {188d83ff-a160-11df-98f1-406186b191b8} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\MountPoints2: {254d1f1c-dfd6-11e1-9afd-406186b191b8} - F:\AutoRun.exe
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\MountPoints2: {254d1f1f-dfd6-11e1-9afd-406186b191b8} - F:\AutoRun.exe
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\MountPoints2: {87339100-dc1a-11e2-b17d-406186b191b8} - F:\AutoRun.exe
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\MountPoints2: {87339107-dc1a-11e2-b17d-406186b191b8} - F:\AutoRun.exe
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\MountPoints2: {8ec385ae-e17f-11e1-b3ad-406186b191b8} - F:\AutoRun.exe
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\MountPoints2: {8ec385bd-e17f-11e1-b3ad-406186b191b8} - F:\AutoRun.exe
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\MountPoints2: {ed39562b-f681-11df-ac52-406186b191b8} - F:\AutoRun.exe
HKU\S-1-5-21-1407684291-1401557966-2466634541-1000\...\MountPoints2: {ed39562e-f681-11df-ac52-406186b191b8} - F:\AutoRun.exe
IFEO\hpwucli.exe: [Debugger] "C:\PROGRAM FILES (X86)\TUNEUP UTILITIES 2014\TUAutoReactivator64.EXE"
Startup: C:\Users\drudenfuss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\drudenfuss\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.geocaching.com
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch
SearchScopes: HKCU - 314E5DDC384B46038FAC92D4E3C83E2B URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=protegere
SearchScopes: HKCU - {1CE535F8-5D17-47B3-BE3F-BA1B4C3B9353} URL = hxxp://www.otto.de.anonymize-me.de/?to=6F74746F2E6465&st={searchTerms}&clid=4511e8a3-f6aa-48a0-ad5b-4146985bc807&pid=freewarede&mode=bounce&k=0
SearchScopes: HKCU - {4DD9BCFF-1F75-4E1F-9991-A116A1039BE9} URL =
SearchScopes: HKCU - {4E4BC4E2-C540-43F3-A49C-AE5CB465219D} URL = hxxp://www.amazon.de.anonymize-me.de/?to=616D617A6F6E2E6465&st={searchTerms}&clid=4511e8a3-f6aa-48a0-ad5b-4146985bc807&pid=freewarede&mode=bounce&k=0
SearchScopes: HKCU - {7CE364CF-D945-4008-99FE-D8CCD6104FB8} URL = hxxp://www.myvideo.de.anonymize-me.de/?to=6D79766964656F2E6465&st={searchTerms}&clid=4511e8a3-f6aa-48a0-ad5b-4146985bc807&pid=freewarede&mode=bounce&k=0
SearchScopes: HKCU - {8489FC1C-EB2E-4FAB-933E-C4A599C71522} URL = hxxp://de.wikipedia.org.anonymize-me.de/?to=64652E77696B6970656469612E6F7267&st={searchTerms}&clid=4511e8a3-f6aa-48a0-ad5b-4146985bc807&pid=freewarede&mode=bounce&k=0
SearchScopes: HKCU - {AA015869-A4B7-4550-9BC6-49B542629BEF} URL = hxxp://www.pricerunner.de.anonymize-me.de/?to=707269636572756E6E65722E6465&st={searchTerms}&clid=4511e8a3-f6aa-48a0-ad5b-4146985bc807&pid=freewarede&mode=bounce&k=0
SearchScopes: HKCU - {c1d89ae7-449d-4929-b24b-fded04adbe06} URL = hxxp://isearch.glarysoft.com/?q={searchTerms}&src=iesearch
SearchScopes: HKCU - {ECAF159E-8367-4AB6-9FE6-300EE3CFE393} URL = hxxp://search.ebay.de.anonymize-me.de/?to=656261792E6465&st={searchTerms}&clid=4511e8a3-f6aa-48a0-ad5b-4146985bc807&pid=freewarede&mode=bounce&k=0
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.5.0.28\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.5.0.28\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.5.0.28\coIEPlg.dll (Symantec Corporation)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{3159D203-761A-4EE6-AE35-862A69E3373A}: [NameServer]8.8.8.8,8.8.4.4
FireFox:
========
FF ProfilePath: C:\Users\drudenfuss\AppData\Roaming\Mozilla\Firefox\Profiles\l2c7ah0z.default
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.geocaching.com/
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @garmin.com/GpsControl - C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.)
FF Plugin-x32: @garmin.com/GpsControl - C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Users\drudenfuss\AppData\Roaming\Mozilla\Firefox\Profiles\l2c7ah0z.default\searchplugins\familyone.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Garmin Communicator - C:\Users\drudenfuss\AppData\Roaming\Mozilla\Firefox\Profiles\l2c7ah0z.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2014-03-19]
FF Extension: Adblock Plus - C:\Users\drudenfuss\AppData\Roaming\Mozilla\Firefox\Profiles\l2c7ah0z.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-05-12]
FF Extension: Greasemonkey - C:\Users\drudenfuss\AppData\Roaming\Mozilla\Firefox\Profiles\l2c7ah0z.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2012-08-24]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\coFFPlgn\ []
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\IPSFF [2013-10-10]
FF HKCU\...\Firefox\Extensions: [{B268766A-11BD-62B9-AF54-26C96C8D7214}] - C:\Program Files (x86)\BlockAndSurf-soft\161.xpi
==================== Services (Whitelisted) =================
S4 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 N360; C:\Program Files (x86)\Norton 360 Premier Edition\Engine\20.5.0.28\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
R2 ST2012_Svc; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [1149104 2013-04-03] (Crawler.com)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2140984 2014-04-15] (TuneUp Software)
==================== Drivers (Whitelisted) ====================
R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20140409.001\BHDrvx64.sys [1525976 2014-03-19] (Symantec Corporation)
S0 BootDefragDriver; C:\Windows\SysWOW64\drivers\BootDefragDriver.sys [16640 2013-04-24] (<Glarysoft Ltd>)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1405000.01C\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-11-21] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2013-12-23] (Symantec Corporation)
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20140515.001\IDSvia64.sys [525016 2014-03-26] (Symantec Corporation)
R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20140516.002\ENG64.SYS [126040 2014-05-08] (Symantec Corporation)
R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\VirusDefs\20140516.002\EX64.SYS [2099288 2014-05-08] (Symantec Corporation)
S3 smserial; C:\Windows\System32\DRIVERS\SmSerl64.sys [1227776 2009-06-10] (Motorola Inc.)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [818424 2011-07-21] (Duplex Secure Ltd.)
R2 sp_rsdrv2; C:\Windows\System32\DRIVERS\stflt.sys [51496 2014-05-12] (Windows (R) Win 7 DDK provider)
R1 SRTSP; C:\Windows\System32\Drivers\N360x64\1405000.01C\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1405000.01C\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1405000.01C\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1405000.01C\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation)
R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-06-20] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1405000.01C\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1405000.01C\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2014-03-26] (TuneUp Software)
R1 {e63d9559-e4c3-499e-867a-a3c9d0a21400}w64; C:\Windows\System32\drivers\{e63d9559-e4c3-499e-867a-a3c9d0a21400}w64.sys [61120 2014-04-24] (StdLib)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 hwusbfake; system32\DRIVERS\ewusbfake.sys [X]
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-16 19:04 - 2014-05-16 19:04 - 00020573 _____ () C:\Users\drudenfuss\Downloads\FRST.txt
2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 ____D () C:\Users\drudenfuss\Downloads\FRST-OlderVersion
2014-05-16 18:51 - 2014-05-16 18:51 - 00001611 _____ () C:\Users\drudenfuss\Desktop\JRT.txt
2014-05-16 18:35 - 2014-05-16 18:35 - 00000000 ____D () C:\windows\ERUNT
2014-05-16 18:34 - 2014-05-16 18:34 - 01016261 _____ (Thisisu) C:\Users\drudenfuss\Downloads\JRT.exe
2014-05-16 18:17 - 2014-05-16 18:18 - 01325827 _____ () C:\Users\drudenfuss\Downloads\adwcleaner_3.208.exe
2014-05-16 17:25 - 2014-05-16 17:25 - 00001238 _____ () C:\Users\drudenfuss\Desktop\Revo Uninstaller.lnk
2014-05-16 17:24 - 2014-05-16 17:24 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\drudenfuss\Downloads\revosetup95.exe
2014-05-15 13:34 - 2014-05-15 13:34 - 00380416 _____ () C:\Users\drudenfuss\Downloads\Gmer-19357.exe
2014-05-15 13:17 - 2014-05-16 19:04 - 00000000 ____D () C:\FRST
2014-05-15 13:16 - 2014-05-16 19:04 - 02067456 _____ (Farbar) C:\Users\drudenfuss\Downloads\FRST64.exe
2014-05-15 13:14 - 2014-05-15 13:14 - 00000020 _____ () C:\Users\drudenfuss\defogger_reenable
2014-05-15 13:13 - 2014-05-15 13:13 - 00050477 _____ () C:\Users\drudenfuss\Downloads\Defogger.exe
2014-05-15 12:35 - 2014-05-16 18:13 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-15 12:35 - 2014-05-15 12:35 - 00001076 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-15 12:35 - 2014-05-15 12:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-15 12:35 - 2014-05-15 12:35 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-15 12:35 - 2014-05-15 12:35 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-15 12:35 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-05-15 12:35 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-05-15 12:35 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-05-15 12:30 - 2014-05-15 12:32 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\drudenfuss\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-15 07:55 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-05-15 07:55 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-05-15 07:55 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-05-15 07:55 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-05-15 07:55 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-05-15 07:55 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-05-15 07:31 - 2014-05-15 07:31 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-05-15 07:31 - 2014-05-15 07:31 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-05-15 06:56 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-05-15 06:56 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-05-15 06:56 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2014-05-15 06:56 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2014-05-15 06:48 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2014-05-15 06:48 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2014-05-15 06:48 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2014-05-15 06:48 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2014-05-15 06:48 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2014-05-15 06:48 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2014-05-15 06:48 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2014-05-15 06:48 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2014-05-15 06:48 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2014-05-15 06:48 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2014-05-15 06:48 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2014-05-15 06:48 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\windows\system32\objsel.dll
2014-05-15 06:48 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2014-05-15 06:48 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2014-05-15 06:48 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2014-05-15 06:48 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2014-05-15 06:48 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-05-15 06:48 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\wincredprovider.dll
2014-05-15 06:48 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2014-05-15 06:48 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\windows\system32\cngprovider.dll
2014-05-15 06:48 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\adprovider.dll
2014-05-15 06:48 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\capiprovider.dll
2014-05-15 06:48 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\windows\system32\dpapiprovider.dll
2014-05-15 06:48 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\dimsroam.dll
2014-05-15 06:48 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-05-15 06:48 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2014-05-15 06:48 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2014-05-15 06:48 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2014-05-15 06:48 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\windows\SysWOW64\objsel.dll
2014-05-15 06:48 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2014-05-15 06:48 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2014-05-15 06:48 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2014-05-15 06:48 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-05-15 06:48 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\cngprovider.dll
2014-05-15 06:48 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\windows\SysWOW64\adprovider.dll
2014-05-15 06:48 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\windows\SysWOW64\capiprovider.dll
2014-05-15 06:48 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dpapiprovider.dll
2014-05-15 06:48 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\windows\SysWOW64\dimsroam.dll
2014-05-15 06:48 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wincredprovider.dll
2014-05-15 06:48 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-05-15 06:48 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2014-05-14 20:21 - 2014-05-14 20:21 - 00006429 _____ () C:\Users\drudenfuss\Downloads\GC54DKK.gpx
2014-05-14 19:47 - 2014-05-14 19:47 - 00021274 _____ () C:\Users\drudenfuss\Downloads\GC4WPCJ.gpx
2014-05-14 19:46 - 2014-05-14 19:46 - 00017332 _____ () C:\Users\drudenfuss\Downloads\GC50331.gpx
2014-05-14 19:43 - 2014-05-14 19:44 - 00017747 _____ () C:\Users\drudenfuss\Downloads\GC50N4F.gpx
2014-05-14 19:42 - 2014-05-14 19:42 - 00012550 _____ () C:\Users\drudenfuss\Downloads\GC52BNN.gpx
2014-05-12 23:16 - 2014-05-16 17:20 - 00000000 ____D () C:\ProgramData\Spyware Terminator
2014-05-12 23:16 - 2014-05-12 23:16 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\windows\system32\Drivers\stflt.sys
2014-05-12 23:16 - 2014-05-12 23:16 - 00001012 _____ () C:\Users\Public\Desktop\Spyware Terminator 2012.lnk
2014-05-12 23:16 - 2014-05-12 23:16 - 00000000 ____D () C:\Users\drudenfuss\AppData\Roaming\Spyware Terminator
2014-05-12 23:16 - 2014-05-12 23:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Terminator 2012
2014-05-12 23:16 - 2014-05-12 23:16 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator
2014-05-12 23:14 - 2014-05-12 23:15 - 05049344 _____ (Crawler.com ) C:\Users\drudenfuss\Downloads\SpywareTerminatorSetup_3.0.0.82.exe
2014-05-12 23:14 - 2014-05-12 23:14 - 00000000 ____D () C:\windows\System32\Tasks\Norton 360
2014-05-12 23:05 - 2014-05-12 23:05 - 00003238 _____ () C:\windows\System32\Tasks\Norton WSC Integration
2014-05-12 21:52 - 2014-05-12 22:33 - 00001993 _____ () C:\Users\drudenfuss\Desktop\Avira PC Cleaner.lnk
2014-05-12 20:24 - 2014-05-12 20:24 - 00000000 _____ () C:\autoexec.bat
2014-05-12 20:23 - 2014-05-12 20:23 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-05-12 20:22 - 2014-05-12 22:51 - 00000000 ____D () C:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-05-09 20:55 - 2014-05-09 20:55 - 00001133 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-09 20:55 - 2014-05-09 20:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-09 15:28 - 2014-05-09 15:28 - 00002770 _____ () C:\windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013
2014-05-08 11:52 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-05-08 11:52 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-05-07 20:37 - 2014-05-07 20:37 - 00003694 _____ () C:\windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2014-05-07 20:25 - 2014-05-07 20:25 - 00002183 _____ () C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2014-05-07 20:25 - 2014-04-15 15:59 - 00040760 _____ (TuneUp Software) C:\windows\system32\TURegOpt.exe
2014-05-07 20:25 - 2014-04-15 15:59 - 00029496 _____ (TuneUp Software) C:\windows\system32\authuitu.dll
2014-05-07 20:25 - 2014-04-15 15:59 - 00025400 _____ (TuneUp Software) C:\windows\SysWOW64\authuitu.dll
2014-05-07 20:24 - 2014-05-07 20:24 - 00002175 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2014.lnk
2014-05-07 20:24 - 2014-05-07 20:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2014
2014-05-07 20:09 - 2014-05-07 20:16 - 27883432 _____ (TuneUp Software) C:\Users\drudenfuss\Downloads\TuneUpUtilities2014_de-DE.exe
2014-05-07 19:44 - 2013-10-02 04:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2014-05-07 19:44 - 2013-10-02 04:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-05-07 19:44 - 2013-10-02 04:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-05-07 19:44 - 2013-10-02 03:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2014-05-07 19:44 - 2013-10-02 03:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2014-05-07 19:44 - 2013-10-02 03:29 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2014-05-07 19:44 - 2013-10-02 03:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2014-05-07 19:44 - 2013-10-02 02:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2014-05-07 19:44 - 2013-10-02 02:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2014-05-07 19:44 - 2013-10-02 02:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2014-05-07 19:44 - 2013-10-02 02:08 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2014-05-07 19:44 - 2013-10-02 02:01 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2014-05-07 19:44 - 2013-10-02 01:58 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2014-05-07 19:44 - 2013-10-02 01:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2014-05-07 19:44 - 2013-10-02 01:08 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2014-05-07 19:44 - 2013-10-02 00:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2014-05-07 19:42 - 2012-08-23 16:13 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2014-05-07 19:42 - 2012-08-23 16:10 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2014-05-07 19:42 - 2012-08-23 15:24 - 00015360 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2014-05-07 19:42 - 2012-08-23 13:12 - 00192000 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpendp_winip.dll
2014-05-07 19:42 - 2012-08-23 12:51 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2014-05-07 19:42 - 2012-08-23 11:51 - 03174912 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2014-05-07 19:38 - 2013-09-25 04:23 - 01030144 _____ (Microsoft Corporation) C:\windows\system32\TSWorkspace.dll
2014-05-07 19:38 - 2013-09-25 03:57 - 00792576 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSWorkspace.dll
2014-05-07 19:38 - 2012-05-04 13:00 - 00366592 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2014-05-07 19:38 - 2012-05-04 11:59 - 00514560 _____ (Microsoft Corporation) C:\windows\SysWOW64\qdvd.dll
2014-05-07 15:33 - 2014-05-12 18:49 - 00000000 ____D () C:\Users\drudenfuss\Desktop\Offene Rechnung
2014-05-07 12:08 - 2014-05-08 10:58 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-05-07 07:04 - 2014-05-07 07:04 - 00000000 ____D () C:\Users\drudenfuss\AppData\Local\Avg2014
2014-05-07 06:59 - 2014-05-16 18:22 - 00001120 _____ () C:\windows\setupact.log
2014-05-07 06:59 - 2014-05-07 06:59 - 00000000 _____ () C:\windows\setuperr.log
2014-05-07 06:58 - 2014-05-16 18:21 - 00029780 _____ () C:\windows\PFRO.log
2014-05-07 06:50 - 2014-05-07 06:50 - 00000000 ____D () C:\Users\drudenfuss\AppData\Local\TuneUp Software
2014-05-07 06:49 - 2014-05-07 20:25 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2014
2014-05-07 06:48 - 2014-05-07 20:34 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-05-07 06:39 - 2014-05-07 06:48 - 29024616 _____ (Mozilla) C:\Users\drudenfuss\Downloads\Mozilla_Firefox_v29.0.exe
2014-05-07 05:54 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-05-07 05:53 - 2014-05-15 12:07 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-05-06 20:40 - 2014-04-24 12:23 - 00061120 _____ (StdLib) C:\windows\system32\Drivers\{e63d9559-e4c3-499e-867a-a3c9d0a21400}w64.sys
2014-05-06 17:54 - 2014-05-06 19:55 - 223210162 _____ () C:\Users\drudenfuss\Downloads\Install_Freizeitkarte_DEU_de.zip.part
2014-05-06 17:53 - 2014-05-07 05:51 - 144752095 _____ () C:\Users\drudenfuss\Downloads\Freizeitkarte_DEU_de.gmap.zip.part
2014-05-06 17:53 - 2014-05-07 00:01 - 540157832 _____ () C:\Users\drudenfuss\Downloads\DEU_de_gmapsupp.img.zip.part
2014-05-06 17:53 - 2014-05-06 19:36 - 88856979 _____ () C:\Users\drudenfuss\Downloads\Freizeitkarte_DEU_de.Images.zip.part
2014-05-06 17:25 - 2014-05-06 17:25 - 00000000 ____D () C:\ProgramData\Caphyon
2014-05-06 17:25 - 2014-05-06 17:25 - 00000000 ____D () C:\Program Files (x86)\PatchBeam
2014-05-06 17:24 - 2014-05-06 17:25 - 00001928 _____ () C:\Users\Public\Desktop\PowerArchiver.lnk
2014-05-06 17:24 - 2014-05-06 17:25 - 00000000 ____D () C:\Program Files (x86)\PowerArchiver
2014-05-06 17:24 - 2014-05-06 17:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerArchiver
2014-05-06 17:11 - 2014-05-06 17:16 - 18983808 _____ () C:\Users\drudenfuss\Downloads\powarc1405042int.exe
2014-05-06 15:56 - 2014-05-06 17:30 - 00000000 ____D () C:\Users\drudenfuss\OSM-Karten
2014-05-05 17:54 - 2014-05-05 17:54 - 00000000 ____D () C:\Users\drudenfuss\AppData\Local\WinZip
2014-05-05 17:53 - 2014-05-05 17:53 - 00002207 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk
2014-05-05 17:53 - 2014-05-05 17:53 - 00000000 ____D () C:\ProgramData\WinZip
2014-05-05 17:53 - 2014-05-05 17:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2014-05-05 17:53 - 2014-05-05 17:53 - 00000000 ____D () C:\Program Files (x86)\WinZip
2014-05-05 17:28 - 2014-05-05 17:34 - 43543552 _____ () C:\Users\drudenfuss\Downloads\wz180gev-32.msi
2014-05-05 16:41 - 2014-05-05 16:41 - 00000000 ____D () C:\Users\drudenfuss\AppData\Roaming\dlg
2014-05-04 18:32 - 2014-05-04 18:33 - 04809728 _____ () C:\Users\drudenfuss\Downloads\RCH65SpoilerDownloader_133.msi
2014-04-28 22:39 - 2014-04-28 22:39 - 00000000 __SHD () C:\Users\drudenfuss\AppData\Local\EmieUserList
2014-04-28 22:39 - 2014-04-28 22:39 - 00000000 __SHD () C:\Users\drudenfuss\AppData\Local\EmieSiteList
2014-04-28 22:10 - 2014-04-28 22:10 - 00001435 _____ () C:\Users\drudenfuss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-28 22:05 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\windows\system32\IEUDINIT.EXE
2014-04-28 22:03 - 2014-04-28 22:04 - 00000000 ___HD () C:\windows\msdownld.tmp
2014-04-28 21:57 - 2014-04-28 21:57 - 13551104 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 11745792 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 05784064 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 04254720 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 02767360 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 02260480 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 02178048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 02043904 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-04-28 21:57 - 2014-04-28 21:57 - 01967104 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-04-28 21:57 - 2014-04-28 21:57 - 01789440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 01400832 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 01228800 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 01143808 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00628736 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat
2014-04-28 21:57 - 2014-04-28 21:57 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat
2014-04-28 21:57 - 2014-04-28 21:57 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00586240 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00524288 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00453120 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2014-04-28 21:57 - 2014-04-28 21:57 - 00367616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2014-04-28 21:57 - 2014-04-28 21:57 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00263376 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00244224 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00238288 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2014-04-28 21:57 - 2014-04-28 21:57 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2014-04-28 21:57 - 2014-04-28 21:57 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-04-28 18:35 - 2014-04-28 18:57 - 65446536 _____ (Microsoft Corporation) C:\Users\drudenfuss\Downloads\EIE11_DE-DE_WOL_WIN764.EXE
2014-04-22 19:21 - 2014-05-13 19:55 - 00000000 ____D () C:\Users\drudenfuss\Downloads\PQ's
2014-04-19 19:01 - 2014-04-19 22:03 - 00000000 ____D () C:\Users\drudenfuss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RCH65 Spoiler Downloader
2014-04-19 19:01 - 2014-04-19 19:01 - 00003067 _____ () C:\Users\drudenfuss\Desktop\RCH65 Spoiler Downloader.lnk
2014-04-19 19:01 - 2014-04-19 19:01 - 00000000 ____D () C:\Program Files (x86)\RCH65 Spoiler Downloader
==================== One Month Modified Files and Folders =======
2014-05-16 19:04 - 2014-05-16 19:04 - 00020573 _____ () C:\Users\drudenfuss\Downloads\FRST.txt
2014-05-16 19:04 - 2014-05-16 19:04 - 00000000 ____D () C:\Users\drudenfuss\Downloads\FRST-OlderVersion
2014-05-16 19:04 - 2014-05-15 13:17 - 00000000 ____D () C:\FRST
2014-05-16 19:04 - 2014-05-15 13:16 - 02067456 _____ (Farbar) C:\Users\drudenfuss\Downloads\FRST64.exe
2014-05-16 18:58 - 2011-10-06 06:15 - 00003938 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{05D35448-9BE1-4F2C-98EF-959F068928DE}
2014-05-16 18:57 - 2011-12-26 18:41 - 01649782 _____ () C:\windows\SysWOW64\PerfStringBackup.INI
2014-05-16 18:57 - 2010-04-23 20:32 - 00703204 _____ () C:\windows\system32\perfh007.dat
2014-05-16 18:57 - 2010-04-23 20:32 - 00150830 _____ () C:\windows\system32\perfc007.dat
2014-05-16 18:51 - 2014-05-16 18:51 - 00001611 _____ () C:\Users\drudenfuss\Desktop\JRT.txt
2014-05-16 18:35 - 2014-05-16 18:35 - 00000000 ____D () C:\windows\ERUNT
2014-05-16 18:34 - 2014-05-16 18:34 - 01016261 _____ (Thisisu) C:\Users\drudenfuss\Downloads\JRT.exe
2014-05-16 18:32 - 2009-07-14 06:45 - 00025840 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-16 18:32 - 2009-07-14 06:45 - 00025840 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-16 18:29 - 2012-02-04 23:09 - 01163253 _____ () C:\windows\WindowsUpdate.log
2014-05-16 18:28 - 2014-03-12 15:25 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-05-16 18:27 - 2011-12-30 17:10 - 00000000 ____D () C:\Users\drudenfuss\AppData\Roaming\Dropbox
2014-05-16 18:26 - 2011-12-30 17:15 - 00000000 ___RD () C:\Users\drudenfuss\Dropbox
2014-05-16 18:23 - 2013-11-21 00:18 - 00000344 _____ () C:\windows\Tasks\GlaryInitialize 4.job
2014-05-16 18:23 - 2013-11-21 00:18 - 00000000 ____D () C:\Program Files (x86)\Glary Utilities 4
2014-05-16 18:22 - 2014-05-07 06:59 - 00001120 _____ () C:\windows\setupact.log
2014-05-16 18:22 - 2012-03-13 09:55 - 00000432 _____ () C:\windows\system32\Drivers\etc\hosts.ics
2014-05-16 18:22 - 2010-08-01 23:33 - 00065536 _____ () C:\windows\system32\Ikeext.etl
2014-05-16 18:22 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-05-16 18:21 - 2014-05-07 06:58 - 00029780 _____ () C:\windows\PFRO.log
2014-05-16 18:20 - 2013-11-14 06:52 - 00000000 ____D () C:\AdwCleaner
2014-05-16 18:18 - 2014-05-16 18:17 - 01325827 _____ () C:\Users\drudenfuss\Downloads\adwcleaner_3.208.exe
2014-05-16 18:13 - 2014-05-15 12:35 - 00119512 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-16 18:08 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\SchCache
2014-05-16 17:25 - 2014-05-16 17:25 - 00001238 _____ () C:\Users\drudenfuss\Desktop\Revo Uninstaller.lnk
2014-05-16 17:25 - 2012-11-18 20:53 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-16 17:24 - 2014-05-16 17:24 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\drudenfuss\Downloads\revosetup95.exe
2014-05-16 17:20 - 2014-05-12 23:16 - 00000000 ____D () C:\ProgramData\Spyware Terminator
2014-05-16 09:46 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\tracing
2014-05-15 14:16 - 2013-02-28 16:08 - 00000000 ____D () C:\Users\drudenfuss\Eigene Dokumente
2014-05-15 13:34 - 2014-05-15 13:34 - 00380416 _____ () C:\Users\drudenfuss\Downloads\Gmer-19357.exe
2014-05-15 13:14 - 2014-05-15 13:14 - 00000020 _____ () C:\Users\drudenfuss\defogger_reenable
2014-05-15 13:14 - 2010-07-30 11:06 - 00000000 ____D () C:\Users\drudenfuss
2014-05-15 13:13 - 2014-05-15 13:13 - 00050477 _____ () C:\Users\drudenfuss\Downloads\Defogger.exe
2014-05-15 12:35 - 2014-05-15 12:35 - 00001076 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-15 12:35 - 2014-05-15 12:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-15 12:35 - 2014-05-15 12:35 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-15 12:35 - 2014-05-15 12:35 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-15 12:32 - 2014-05-15 12:30 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\drudenfuss\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-15 12:13 - 2010-07-30 11:20 - 00000000 ___RD () C:\Users\drudenfuss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 12:13 - 2010-07-30 11:20 - 00000000 ___RD () C:\Users\drudenfuss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 12:07 - 2014-05-07 05:53 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-05-15 07:55 - 2010-04-23 23:11 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-15 07:53 - 2013-07-27 00:12 - 00000000 ____D () C:\windows\system32\MRT
2014-05-15 07:44 - 2010-09-13 16:39 - 93223848 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-05-15 07:31 - 2014-05-15 07:31 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2014-05-15 07:31 - 2014-05-15 07:31 - 00000000 ____D () C:\Users\Default User\AppData\Local\Microsoft Help
2014-05-14 20:21 - 2014-05-14 20:21 - 00006429 _____ () C:\Users\drudenfuss\Downloads\GC54DKK.gpx
2014-05-14 19:47 - 2014-05-14 19:47 - 00021274 _____ () C:\Users\drudenfuss\Downloads\GC4WPCJ.gpx
2014-05-14 19:46 - 2014-05-14 19:46 - 00017332 _____ () C:\Users\drudenfuss\Downloads\GC50331.gpx
2014-05-14 19:44 - 2014-05-14 19:43 - 00017747 _____ () C:\Users\drudenfuss\Downloads\GC50N4F.gpx
2014-05-14 19:42 - 2014-05-14 19:42 - 00012550 _____ () C:\Users\drudenfuss\Downloads\GC52BNN.gpx
2014-05-13 21:50 - 2010-08-06 18:07 - 00000000 ____D () C:\Users\drudenfuss\AppData\Local\Google
2014-05-13 21:50 - 2010-08-06 18:07 - 00000000 ____D () C:\Program Files (x86)\Google
2014-05-13 21:47 - 2010-08-29 18:09 - 00000000 ____D () C:\Program Files (x86)\SpoilerSync
2014-05-13 21:44 - 2010-07-30 11:25 - 00000000 ____D () C:\Users\drudenfuss\AppData\Local\Adobe
2014-05-13 20:32 - 2014-03-12 15:25 - 00692400 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-05-13 20:32 - 2014-03-12 15:25 - 00070832 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-13 20:32 - 2014-03-12 15:25 - 00003822 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-05-13 20:08 - 2010-09-16 20:07 - 00000000 ____D () C:\Users\drudenfuss\AppData\Local\CrashDumps
2014-05-13 19:55 - 2014-04-22 19:21 - 00000000 ____D () C:\Users\drudenfuss\Downloads\PQ's
2014-05-13 19:42 - 2011-06-23 15:12 - 00003776 _____ () C:\windows\System32\Tasks\HP-Online-Aktualisierungsprogramm
2014-05-13 05:55 - 2013-09-09 19:37 - 00000000 ____D () C:\Program Files (x86)\Secunia
2014-05-13 05:53 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-12 23:16 - 2014-05-12 23:16 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\windows\system32\Drivers\stflt.sys
2014-05-12 23:16 - 2014-05-12 23:16 - 00001012 _____ () C:\Users\Public\Desktop\Spyware Terminator 2012.lnk
2014-05-12 23:16 - 2014-05-12 23:16 - 00000000 ____D () C:\Users\drudenfuss\AppData\Roaming\Spyware Terminator
2014-05-12 23:16 - 2014-05-12 23:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Terminator 2012
2014-05-12 23:16 - 2014-05-12 23:16 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator
2014-05-12 23:15 - 2014-05-12 23:14 - 05049344 _____ (Crawler.com ) C:\Users\drudenfuss\Downloads\SpywareTerminatorSetup_3.0.0.82.exe
2014-05-12 23:14 - 2014-05-12 23:14 - 00000000 ____D () C:\windows\System32\Tasks\Norton 360
2014-05-12 23:06 - 2010-11-17 14:55 - 00000000 ____D () C:\windows\system32\Drivers\N360x64
2014-05-12 23:05 - 2014-05-12 23:05 - 00003238 _____ () C:\windows\System32\Tasks\Norton WSC Integration
2014-05-12 23:04 - 2012-11-02 08:15 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 Premier Edition
2014-05-12 22:51 - 2014-05-12 20:22 - 00000000 ____D () C:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-05-12 22:33 - 2014-05-12 21:52 - 00001993 _____ () C:\Users\drudenfuss\Desktop\Avira PC Cleaner.lnk
2014-05-12 20:24 - 2014-05-12 20:24 - 00000000 _____ () C:\autoexec.bat
2014-05-12 20:23 - 2014-05-12 20:23 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-05-12 18:49 - 2014-05-07 15:33 - 00000000 ____D () C:\Users\drudenfuss\Desktop\Offene Rechnung
2014-05-11 08:06 - 2014-03-29 21:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-09 20:55 - 2014-05-09 20:55 - 00001133 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-05-09 20:55 - 2014-05-09 20:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-09 15:28 - 2014-05-09 15:28 - 00002770 _____ () C:\windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013
2014-05-09 08:14 - 2014-05-15 06:56 - 00477184 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-05-09 08:11 - 2014-05-15 06:56 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-05-08 11:25 - 2011-12-30 17:11 - 00000000 ____D () C:\Users\drudenfuss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-08 11:04 - 2009-07-14 04:34 - 00000601 _____ () C:\windows\win.ini
2014-05-08 10:58 - 2014-05-07 12:08 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-05-07 20:37 - 2014-05-07 20:37 - 00003694 _____ () C:\windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2014-05-07 20:34 - 2014-05-07 06:48 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-05-07 20:34 - 2012-03-12 15:03 - 00000000 ____D () C:\Users\drudenfuss\AppData\Local\Downloaded Installations
2014-05-07 20:34 - 2011-06-14 11:21 - 00000000 ____D () C:\Users\drudenfuss\AppData\Roaming\HpUpdate
2014-05-07 20:34 - 2011-02-20 18:03 - 00000000 __SHD () C:\ProgramData\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2014-05-07 20:27 - 2011-02-20 18:03 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-05-07 20:25 - 2014-05-07 20:25 - 00002183 _____ () C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2014-05-07 20:25 - 2014-05-07 06:49 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2014
2014-05-07 20:24 - 2014-05-07 20:24 - 00002175 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2014.lnk
2014-05-07 20:24 - 2014-05-07 20:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2014
2014-05-07 20:16 - 2014-05-07 20:09 - 27883432 _____ (TuneUp Software) C:\Users\drudenfuss\Downloads\TuneUpUtilities2014_de-DE.exe
2014-05-07 19:50 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-05-07 19:46 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-05-07 17:05 - 2009-07-14 07:13 - 01629434 _____ () C:\windows\system32\PerfStringBackup.INI
2014-05-07 12:08 - 2009-07-14 05:20 - 00000000 ___HD () C:\windows\system32\GroupPolicy
2014-05-07 12:08 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\SysWOW64\GroupPolicy
2014-05-07 07:04 - 2014-05-07 07:04 - 00000000 ____D () C:\Users\drudenfuss\AppData\Local\Avg2014
2014-05-07 06:59 - 2014-05-07 06:59 - 00000000 _____ () C:\windows\setuperr.log
2014-05-07 06:52 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-05-07 06:52 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Sidebar
2014-05-07 06:50 - 2014-05-07 06:50 - 00000000 ____D () C:\Users\drudenfuss\AppData\Local\TuneUp Software
2014-05-07 06:50 - 2011-02-20 18:04 - 00000000 ____D () C:\Users\drudenfuss\AppData\Roaming\TuneUp Software
2014-05-07 06:48 - 2014-05-07 06:39 - 29024616 _____ (Mozilla) C:\Users\drudenfuss\Downloads\Mozilla_Firefox_v29.0.exe
2014-05-07 06:44 - 2014-01-16 13:10 - 00002976 _____ () C:\windows\System32\Tasks\GU4SkipUAC
2014-05-07 06:44 - 2013-11-21 00:18 - 00002644 _____ () C:\windows\System32\Tasks\GlaryInitialize 4
2014-05-07 06:44 - 2013-11-21 00:18 - 00001066 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 4.lnk
2014-05-07 06:42 - 2013-09-09 20:03 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP
2014-05-07 06:42 - 2013-03-25 17:53 - 00001923 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk
2014-05-07 06:42 - 2013-03-25 17:53 - 00001873 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2014-05-07 06:35 - 2013-08-12 20:31 - 00000000 ____D () C:\Users\drudenfuss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup-Disabled
2014-05-07 06:35 - 2010-02-03 15:52 - 00000000 ____D () C:\windows\Panther
2014-05-07 06:24 - 2013-02-03 19:20 - 00000000 ____D () C:\Program Files (x86)\Elaborate Bytes
2014-05-07 05:51 - 2014-05-06 17:53 - 144752095 _____ () C:\Users\drudenfuss\Downloads\Freizeitkarte_DEU_de.gmap.zip.part
2014-05-07 00:01 - 2014-05-06 17:53 - 540157832 _____ () C:\Users\drudenfuss\Downloads\DEU_de_gmapsupp.img.zip.part
2014-05-06 19:55 - 2014-05-06 17:54 - 223210162 _____ () C:\Users\drudenfuss\Downloads\Install_Freizeitkarte_DEU_de.zip.part
2014-05-06 19:36 - 2014-05-06 17:53 - 88856979 _____ () C:\Users\drudenfuss\Downloads\Freizeitkarte_DEU_de.Images.zip.part
2014-05-06 17:30 - 2014-05-06 15:56 - 00000000 ____D () C:\Users\drudenfuss\OSM-Karten
2014-05-06 17:25 - 2014-05-06 17:25 - 00000000 ____D () C:\ProgramData\Caphyon
2014-05-06 17:25 - 2014-05-06 17:25 - 00000000 ____D () C:\Program Files (x86)\PatchBeam
2014-05-06 17:25 - 2014-05-06 17:24 - 00001928 _____ () C:\Users\Public\Desktop\PowerArchiver.lnk
2014-05-06 17:25 - 2014-05-06 17:24 - 00000000 ____D () C:\Program Files (x86)\PowerArchiver
2014-05-06 17:24 - 2014-05-06 17:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerArchiver
2014-05-06 17:16 - 2014-05-06 17:11 - 18983808 _____ () C:\Users\drudenfuss\Downloads\powarc1405042int.exe
2014-05-06 16:50 - 2013-07-20 18:11 - 00131072 ___SH () C:\Users\drudenfuss\Downloads\Thumbs.db
2014-05-06 06:40 - 2014-05-15 07:55 - 23544320 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-05-06 06:17 - 2014-05-15 07:55 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-05-06 05:25 - 2014-05-15 07:55 - 17382912 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-05-06 05:07 - 2014-05-15 07:55 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-05-06 05:00 - 2014-05-15 07:55 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-05-06 04:10 - 2014-05-15 07:55 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-05-05 17:54 - 2014-05-05 17:54 - 00000000 ____D () C:\Users\drudenfuss\AppData\Local\WinZip
2014-05-05 17:53 - 2014-05-05 17:53 - 00002207 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk
2014-05-05 17:53 - 2014-05-05 17:53 - 00000000 ____D () C:\ProgramData\WinZip
2014-05-05 17:53 - 2014-05-05 17:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2014-05-05 17:53 - 2014-05-05 17:53 - 00000000 ____D () C:\Program Files (x86)\WinZip
2014-05-05 17:34 - 2014-05-05 17:28 - 43543552 _____ () C:\Users\drudenfuss\Downloads\wz180gev-32.msi
2014-05-05 16:48 - 2014-02-26 14:44 - 00000000 ____D () C:\Users\drudenfuss\AppData\Roaming\Audacity
2014-05-05 16:46 - 2013-10-31 09:52 - 00000000 ____D () C:\Program Files (x86)\CEWE
2014-05-05 16:41 - 2014-05-05 16:41 - 00000000 ____D () C:\Users\drudenfuss\AppData\Roaming\dlg
2014-05-04 22:14 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\rescache
2014-05-04 18:33 - 2014-05-04 18:32 - 04809728 _____ () C:\Users\drudenfuss\Downloads\RCH65SpoilerDownloader_133.msi
2014-05-02 20:31 - 2011-01-26 20:50 - 00000000 ____D () C:\ProgramData\Sonic
2014-04-29 20:37 - 2010-07-30 11:13 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-04-28 22:39 - 2014-04-28 22:39 - 00000000 __SHD () C:\Users\drudenfuss\AppData\Local\EmieUserList
2014-04-28 22:39 - 2014-04-28 22:39 - 00000000 __SHD () C:\Users\drudenfuss\AppData\Local\EmieSiteList
2014-04-28 22:10 - 2014-04-28 22:10 - 00001435 _____ () C:\Users\drudenfuss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-28 22:04 - 2014-04-28 22:03 - 00000000 ___HD () C:\windows\msdownld.tmp
2014-04-28 21:57 - 2014-04-28 21:57 - 13551104 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 11745792 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 05784064 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 04254720 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 02767360 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 02260480 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 02178048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 02043904 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-04-28 21:57 - 2014-04-28 21:57 - 01967104 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-04-28 21:57 - 2014-04-28 21:57 - 01789440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 01400832 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 01228800 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 01143808 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00942592 _____ (Microsoft Corporation) C:\windows\system32\jsIntl.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00846336 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00752640 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00704512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00645120 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsIntl.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00628736 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00616104 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dat
2014-04-28 21:57 - 2014-04-28 21:57 - 00616104 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dat
2014-04-28 21:57 - 2014-04-28 21:57 - 00610304 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00592896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00586240 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00548352 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00524288 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00455168 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00453120 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00413696 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2014-04-28 21:57 - 2014-04-28 21:57 - 00367616 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2014-04-28 21:57 - 2014-04-28 21:57 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00263376 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\msls31.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00244224 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00238288 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\url.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00235008 _____ (Microsoft Corporation) C:\windows\system32\elshyph.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00233472 _____ (Microsoft Corporation) C:\windows\SysWOW64\url.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00208384 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00194048 _____ (Microsoft Corporation) C:\windows\SysWOW64\elshyph.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00182272 _____ (Microsoft Corporation) C:\windows\SysWOW64\msls31.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00167424 _____ (Microsoft Corporation) C:\windows\system32\iexpress.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00151552 _____ (Microsoft Corporation) C:\windows\SysWOW64\iexpress.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00147968 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00143872 _____ (Microsoft Corporation) C:\windows\system32\wextract.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00139264 _____ (Microsoft Corporation) C:\windows\SysWOW64\wextract.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00131072 _____ (Microsoft Corporation) C:\windows\system32\IEAdvpack.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00127488 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00116736 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\IEAdvpack.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00105984 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00090112 _____ (Microsoft Corporation) C:\windows\system32\SetIEInstalledDate.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\icardie.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2014-04-28 21:57 - 2014-04-28 21:57 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\SetIEInstalledDate.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\RegisterIEPKEYs.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00069120 _____ (Microsoft Corporation) C:\windows\SysWOW64\icardie.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2014-04-28 21:57 - 2014-04-28 21:57 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\pngfilt.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00056832 _____ (Microsoft Corporation) C:\windows\SysWOW64\pngfilt.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\msfeedsbs.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00048640 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmler.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\mshtmler.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00048128 _____ (Microsoft Corporation) C:\windows\system32\imgutil.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedsbs.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00038400 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\imgutil.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00032256 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00030208 _____ (Microsoft Corporation) C:\windows\system32\licmgr10.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00024576 _____ (Microsoft Corporation) C:\windows\SysWOW64\licmgr10.dll
2014-04-28 21:57 - 2014-04-28 21:57 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\mshta.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00013312 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshta.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\msfeedssync.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00012800 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeedssync.exe
2014-04-28 21:57 - 2014-04-28 21:57 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-04-28 18:57 - 2014-04-28 18:35 - 65446536 _____ (Microsoft Corporation) C:\Users\drudenfuss\Downloads\EIE11_DE-DE_WOL_WIN764.EXE
2014-04-24 12:23 - 2014-05-06 20:40 - 00061120 _____ (StdLib) C:\windows\system32\Drivers\{e63d9559-e4c3-499e-867a-a3c9d0a21400}w64.sys
2014-04-19 22:03 - 2014-04-19 19:01 - 00000000 ____D () C:\Users\drudenfuss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RCH65 Spoiler Downloader
2014-04-19 19:01 - 2014-04-19 19:01 - 00003067 _____ () C:\Users\drudenfuss\Desktop\RCH65 Spoiler Downloader.lnk
2014-04-19 19:01 - 2014-04-19 19:01 - 00000000 ____D () C:\Program Files (x86)\RCH65 Spoiler Downloader
Some content of TEMP:
====================
C:\Users\drudenfuss\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgx7vt9.dll
C:\Users\drudenfuss\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe
[2014-05-15 06:48] - [2014-03-04 11:43] - 0455168 ____A (Microsoft Corporation) 88AB9B72B4BF3963A0DE0820B4B0B06C
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-04 22:06
==================== End Of Log ============================ --- --- ---
gruß Heli Eb |