hi,
also:
mbam Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 19.06.2014
Suchlauf-Zeit: 19:13:43
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.19.08
Rootkit Datenbank: v2014.06.02.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Patrick
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 328986
Verstrichene Zeit: 14 Min, 23 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 1
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 1536, Löschen bei Neustart, [e371bebc2e4d3ff7ff33e377e51c748c]
Module: 1
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [96be6515d2a9290d27186d1c649dbc44],
Registrierungsschlüssel: 15
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, In Quarantäne, [e371bebc2e4d3ff7ff33e377e51c748c],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [1d376416c6b537ff9939271ddd259b65],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [1d376416c6b537ff9939271ddd259b65],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [1d376416c6b537ff9939271ddd259b65],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [1d376416c6b537ff9939271ddd259b65],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [1d376416c6b537ff9939271ddd259b65],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [1d376416c6b537ff9939271ddd259b65],
PUP.Optional.SupTab.A, HKU\S-1-5-21-2393365369-527439366-222889412-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [1d376416c6b537ff9939271ddd259b65],
PUP.Optional.SupTab.A, HKU\S-1-5-21-2393365369-527439366-222889412-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [1d376416c6b537ff9939271ddd259b65],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [ff558af0d0ab48eed7e113d59b685ea2],
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\pelmeidfhdlhlbjimpabfcbnnojbboma, In Quarantäne, [9fb52c4e394251e5dc27bdfeed15fa06],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [eb69a7d3a1daec4ac7f1985017ec14ec],
PUP.Optional.MediaPlayer.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Mediaa_Play_AIR_1.4, In Quarantäne, [0153cfab0a71df576f4495107092669a],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2393365369-527439366-222889412-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, In Quarantäne, [3d1780fa6f0c082e660cd71a10f3b050],
PUP.Optional.MediaPlayer.A, HKU\S-1-5-21-2393365369-527439366-222889412-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Mediaa_Play_AIR_1.4, In Quarantäne, [252fe69427548fa7bdf65154c240a15f],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 15
PUP.Optional.Skytech.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SupTab\SEARCH~2.DLL, Gut: (), Schlecht: (C:\PROGRA~2\SupTab\SEARCH~2.DLL),Ersetzt,[ef65f882b3c8053186b99ced738e3ec2]
PUP.Optional.Skytech.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SupTab\SEARCH~1.DLL, Gut: (), Schlecht: (C:\PROGRA~2\SupTab\SEARCH~1.DLL),Ersetzt,[c88c12687902ce682718018823de7d83]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX),Ersetzt,[5afa06747308f54163d9165e60a438c8]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX&q={searchTerms}),Ersetzt,[fd579ae068136cca9a998ee6699b9e62]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX),Ersetzt,[50049dddf98289ad151ca4d063a18d73]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX),Ersetzt,[57fde595c5b667cffc396410917339c7]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[3d171d5d49324beb5a0a4d31de261be5]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX),Ersetzt,[f1636f0be09b54e27dbf95df7e86fb05]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX&q={searchTerms}),Ersetzt,[3a1ab7c38dee67cf6cc7a5cf62a2649c]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX),Ersetzt,[e96bdaa059221a1cc1706c08ac587b85]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX),Ersetzt,[8ec66b0f5b2047efe2538ee624e0c53b]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[62f22c4ed7a43cfa2c387fff10f4ac54]
PUP.Optional.WebsSearches.A, HKU\S-1-5-21-2393365369-527439366-222889412-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX),Ersetzt,[2d27f1891b60261073c3fb79ba4aab55]
PUP.Optional.WebsSearches.A, HKU\S-1-5-21-2393365369-527439366-222889412-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX),Ersetzt,[153f1268c1ba4de9b57d7ef627dd26da]
PUP.Optional.WebsSearches.A, HKU\S-1-5-21-2393365369-527439366-222889412-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1402878576&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX&q={searchTerms}),Ersetzt,[d084e2983645cb6b81b37301bb4916ea]
Ordner: 36
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, Löschen bei Neustart, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\ct2504091, In Quarantäne, [8cc85b1fe6952e0864db6e1f41c16898],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\NativeMessaging\CT2504091, In Quarantäne, [f85cb6c41269ce68d5347d16f40e8080],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\NativeMessaging\CT2504091\nativeMessaging, In Quarantäne, [f85cb6c41269ce68d5347d16f40e8080],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\TestIfExeExist\CT2504091, In Quarantäne, [82d257237308b28476ace8ac47bb57a9],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\TestIfExeExist\CT2504091\nativeMessaging, In Quarantäne, [82d257237308b28476ace8ac47bb57a9],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nnlomafmkpiclmaaekkhpoecnclldmaa, In Quarantäne, [4b0979018af140f60bd6890b7d853cc4],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_nnlomafmkpiclmaaekkhpoecnclldmaa_0, In Quarantäne, [afa54a3089f2fc3a8a58039118ea01ff],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, Löschen bei Neustart, [6aeac3b70c6f6ccaf4c76141f30fbc44],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [6aeac3b70c6f6ccaf4c76141f30fbc44],
PUP.Optional.SearchProtect.A, C:\Users\Patrick\AppData\Local\SearchProtect, In Quarantäne, [da7a8befb4c766d07448ced4f50dfe02],
PUP.Optional.SearchProtect.A, C:\Users\Patrick\AppData\Local\SearchProtect\Logs, In Quarantäne, [da7a8befb4c766d07448ced4f50dfe02],
Dateien: 106
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, Löschen bei Neustart, [e371bebc2e4d3ff7ff33e377e51c748c],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [96be6515d2a9290d27186d1c649dbc44],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, In Quarantäne, [ef65f882b3c8053186b99ced738e3ec2],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, In Quarantäne, [c88c12687902ce682718018823de7d83],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, In Quarantäne, [1d376416c6b537ff9939271ddd259b65],
PUP.Optional.ScramblePacker.A, C:\Users\Patrick\AppData\Local\Temp\media.exe, In Quarantäne, [b3a1ceac91ea6dc92150bfcc28d9e31d],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\spidentifierimpl.exe, In Quarantäne, [c3912258fb8071c5003b25625ca510f0],
PUP.Optional.NewPlayer.A, C:\Users\Patrick\AppData\Local\Temp\newvideoplayersetup.exe, In Quarantäne, [4f05bac0accfc1754cfcfa88cf32da26],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\ct2504091\chLogic.exe, In Quarantäne, [a9ab3347d6a5d462e88178a8f20ff907],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\ct2504091\ctbe.exe, In Quarantäne, [9eb6e7934d2e91a5a6f13ae401ff7090],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\ct2504091\ism.exe, In Quarantäne, [90c407732f4cb77f052d197241c02ad6],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\ct2504091\statisticsStub.exe, In Quarantäne, [8cc8c2b8a9d2ef47b936050541c0d927],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\ct2504091\stub.exe, In Quarantäne, [e470601a86f56ccab17e66c7946c956b],
PUP.Optional.SoftonicTB.A, C:\Users\Patrick\AppData\Local\Temp\cnpy\Softonic_chr_1.8.29.3.exe, In Quarantäne, [68ec68128bf0cc6ad9941f5ce71ab54b],
PUP.Optional.InstallMonetizer, C:\Users\Patrick\Downloads\James.Bond.007.Skyfall.German.AC3.BDRip.XviD CONFiDENT.avi.flv__3038_i148334463_il2650599.exe, In Quarantäne, [2a2a19614b301a1c9e12b27aa061f50b],
PUP.Optional.Softonic.A, C:\Users\Patrick\Downloads\SoftonicDownloader_fuer_freebie-notes.exe, In Quarantäne, [63f1ee8c2a517db901eeb271827fe917],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage, In Quarantäne, [84d04337a6d5cf6721a9f5b8679b6b95],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage-journal, In Quarantäne, [93c16f0bfa815adcb9112c8152b046ba],
PUP.Optional.Superfish.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, In Quarantäne, [43111565a5d6171f988f7935768c3bc5],
PUP.Optional.Superfish.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, In Quarantäne, [fd572654017aea4c41e68b23768cb34d],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.vaccint.com_0.localstorage, In Quarantäne, [203461191c5ff24427597d312bd7ff01],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.vaccint.com_0.localstorage-journal, In Quarantäne, [60f490eaa1da5ed8bcc4c0eeb54db64a],
PUP.Optional.Softonic.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_elchiiiejkobdbblfejjkbphbddgmljf_0.localstorage, In Quarantäne, [da7a99e1ccaf6bcb16da4b664ab8f907],
PUP.Optional.Softonic.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_elchiiiejkobdbblfejjkbphbddgmljf_0.localstorage-journal, In Quarantäne, [1a3a1d5d96e5be784da306ab9072827e],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nnlomafmkpiclmaaekkhpoecnclldmaa_0.localstorage, In Quarantäne, [2f2577038af153e3994fa710fb077c84],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nnlomafmkpiclmaaekkhpoecnclldmaa_0.localstorage-journal, In Quarantäne, [bf953149a0db142228c0783fbc4624dc],
PUP.Optional.QuickStart.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx, In Quarantäne, [a9abdaa03645fe38b26faa0fd23010f0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterfacef32.dll, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\RSHP.exe, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv32.dll, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv64.dll, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WebDataJs, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\arrow.png, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo.png, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo_hover.png, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_logo.png, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo.png, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo2.png, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\0.png, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ie8.js, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, In Quarantäne, [f55f85f5116a092da21315ae2fd3e31d],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\ct2504091\chromeid.txt, In Quarantäne, [8cc85b1fe6952e0864db6e1f41c16898],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\ct2504091\CT2504091.txt, In Quarantäne, [8cc85b1fe6952e0864db6e1f41c16898],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\ct2504091\initdata.json, In Quarantäne, [8cc85b1fe6952e0864db6e1f41c16898],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\ct2504091\manifest.json, In Quarantäne, [8cc85b1fe6952e0864db6e1f41c16898],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\ct2504091\setup.ini.txt, In Quarantäne, [8cc85b1fe6952e0864db6e1f41c16898],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\NativeMessaging\CT2504091\nativeMessaging\nmHostConfig.json, In Quarantäne, [f85cb6c41269ce68d5347d16f40e8080],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\NativeMessaging\CT2504091\nativeMessaging\nmHostManifest.json, In Quarantäne, [f85cb6c41269ce68d5347d16f40e8080],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\NativeMessaging\CT2504091\nativeMessaging\TBMessagingHost.exe, In Quarantäne, [f85cb6c41269ce68d5347d16f40e8080],
PUP.Optional.Conduit.A, C:\Users\Patrick\AppData\Local\Temp\TestIfExeExist\CT2504091\nativeMessaging\TBMessagingHost.exe, In Quarantäne, [82d257237308b28476ace8ac47bb57a9],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nnlomafmkpiclmaaekkhpoecnclldmaa\000016.sst, In Quarantäne, [4b0979018af140f60bd6890b7d853cc4],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nnlomafmkpiclmaaekkhpoecnclldmaa\000020.sst, In Quarantäne, [4b0979018af140f60bd6890b7d853cc4],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nnlomafmkpiclmaaekkhpoecnclldmaa\000029.sst, In Quarantäne, [4b0979018af140f60bd6890b7d853cc4],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nnlomafmkpiclmaaekkhpoecnclldmaa\000032.sst, In Quarantäne, [4b0979018af140f60bd6890b7d853cc4],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nnlomafmkpiclmaaekkhpoecnclldmaa\000035.log, In Quarantäne, [4b0979018af140f60bd6890b7d853cc4],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nnlomafmkpiclmaaekkhpoecnclldmaa\CURRENT, In Quarantäne, [4b0979018af140f60bd6890b7d853cc4],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nnlomafmkpiclmaaekkhpoecnclldmaa\LOCK, In Quarantäne, [4b0979018af140f60bd6890b7d853cc4],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nnlomafmkpiclmaaekkhpoecnclldmaa\LOG, In Quarantäne, [4b0979018af140f60bd6890b7d853cc4],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nnlomafmkpiclmaaekkhpoecnclldmaa\LOG.old, In Quarantäne, [4b0979018af140f60bd6890b7d853cc4],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nnlomafmkpiclmaaekkhpoecnclldmaa\MANIFEST-000034, In Quarantäne, [4b0979018af140f60bd6890b7d853cc4],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_nnlomafmkpiclmaaekkhpoecnclldmaa_0\1, In Quarantäne, [afa54a3089f2fc3a8a58039118ea01ff],
PUP.Optional.CrossRider.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_nnlomafmkpiclmaaekkhpoecnclldmaa_0\2, In Quarantäne, [afa54a3089f2fc3a8a58039118ea01ff],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, In Quarantäne, [6aeac3b70c6f6ccaf4c76141f30fbc44],
PUP.Optional.WebsSearches.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://istart.webssearches.com/?type=hppp&ts=1403161633&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX" ],), Ersetzt,[b69e8ded1b602d095d6a6b405ba99e62]
PUP.Optional.WebsSearches.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://istart.webssearches.com/?type=hppp&ts=1403161633&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX",), Ersetzt,[c78d1c5ebbc086b08741802b53b10df3]
PUP.Optional.WebsSearches.A, C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "search_url": "hxxp://istart.webssearches.com/web/?type=dspp&ts=1403161633&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX&q={searchTerms}",), Ersetzt,[aaaa6c0e2c4f59dd7d4c49623dc709f7]
Physische Sektoren: 0
(No malicious items detected)
(end)
AdwCleaner Code:
# AdwCleaner v3.212 - Bericht erstellt am 19/06/2014 um 20:07:11
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Patrick - PATRICK-HP
# Gestartet von : C:\Users\Patrick\Desktop\adwcleaner_3.212.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Users\Patrick\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Patrick\AppData\Local\NativeMessaging
Ordner Gelöscht : C:\Users\Patrick\AppData\Local\Tbccint
Ordner Gelöscht : C:\Users\Patrick\AppData\Local\Temp\NativeMessaging
Ordner Gelöscht : C:\Users\Patrick\AppData\LocalLow\Softonic
Ordner Gelöscht : C:\Users\Patrick\AppData\Roaming\DownLite
Ordner Gelöscht : C:\Users\Patrick\AppData\Roaming\SeeSimilar02
Ordner Gelöscht : C:\Users\Patrick\AppData\Roaming\SupTab
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.softonic.de_0.localstorage
Datei Gelöscht : C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.softonic.de_0.localstorage-journal
Datei Gelöscht : C:\Windows\System32\Tasks\GoforFilesUpdate
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [seesimilar02@SeeSimilar.com]
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [seesimilar02@SeeSimilar.com]
Schlüssel Gelöscht : HKCU\Software\Classes\pokki
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASMANCS
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{59C0C5BD-2579-433A-BBB8-AFFD59642BAF}
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\GoforFiles
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKLM\Software\GoforFiles
Schlüssel Gelöscht : HKLM\Software\SupDp
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\Uniblue
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Speedchecker Limited
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Google Chrome v35.0.1916.153
[ Datei : C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://www.softonic.de/s/{searchTerms}
Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=dspp&ts=1403161633&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX&q={searchTerms}
Gelöscht [Startup_urls] : hxxp://istart.webssearches.com/?type=hppp&ts=1403161633&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX
Gelöscht [Homepage] : hxxp://istart.webssearches.com/?type=hppp&ts=1403161633&from=tugs&uid=HitachiXHTS547550A9E384_J2110051DXB80BDXB80BX
Gelöscht [Extension] : pelmeidfhdlhlbjimpabfcbnnojbboma
*************************
AdwCleaner[R0].txt - [8907 octets] - [24/08/2013 10:28:50]
AdwCleaner[S0].txt - [3708 octets] - [19/06/2014 20:07:11]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3768 octets] ##########
JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Patrick on 19.06.2014 at 20:11:44.52
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2393365369-527439366-222889412-1001\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B1D17E39-ED8C-4E46-9FBE-40512A6C1181}
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Patrick\appdata\local\{E2FA712C-C776-41DF-A681-9EF8E58B88EB}
Successfully deleted: [Empty Folder] C:\Users\Patrick\appdata\local\{FB4A8325-50B1-4B97-91AD-25AB876B91CE}
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 19.06.2014 at 20:16:39.19
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-06-2014
Ran by Patrick (administrator) on PATRICK-HP on 19-06-2014 20:17:17
Running from C:\Users\Patrick\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(HP) C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe
(HP) C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
( ) C:\Windows\System32\lxbkcoms.exe
( ) C:\Windows\System32\lxdncoms.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AuthenTec Inc.) C:\Program Files (x86)\HP SimplePass\TouchControl.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.7\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
() C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe
(Akamai Technologies, Inc.) C:\Users\Patrick\AppData\Local\Akamai\netsession_win.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dropbox, Inc.) C:\Users\Patrick\AppData\Roaming\Dropbox\bin\Dropbox.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Akamai Technologies, Inc.) C:\Users\Patrick\AppData\Local\Akamai\netsession_win.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
() C:\Program Files (x86)\HP SimplePass\IEWebSiteLogon.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Autodesk, Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\Bluetooth Headset Helper.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)
HKLM\...\Run: [SetDefault] => C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [44880 2011-12-19] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [415680 2012-02-06] (Autodesk, Inc.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1425408 2013-05-29] (IDT, Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291096 2011-12-05] (Intel Corporation)
HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP CoolSense] => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1343904 2012-11-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [ADSK DLMSession] => C:\Program Files (x86)\Common Files\Autodesk Shared\Autodesk Download Manager\DLMSession.exe [1632216 2012-07-23] (Autodesk, Inc.)
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [74752 2012-06-28] (Nullsoft, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Magic Desktop for HP notification] => C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1258504 2013-12-30] (Easybits)
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-06-10] (Hewlett-Packard)
Winlogon\Notify\igfxcui: C:\WINDOWS\SYSTEM32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-2393365369-527439366-222889412-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Patrick\AppData\Local\Akamai\netsession_win.exe [4441920 2012-10-09] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2393365369-527439366-222889412-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-2393365369-527439366-222889412-1001\...\Policies\Explorer: []
HKU\S-1-5-21-2393365369-527439366-222889412-1001\...\MountPoints2: {bac3a611-970d-11e3-9b05-c01885f94df2} - F:\Autorun.exe
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Patrick\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
Startup: C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3070 B611 series.lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 3070 B611 series.lnk -> C:\Program Files\HP\HP Deskjet 3070 B611 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - {20FDEA80-AA0C-4756-9E74-6C994AC7E082} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/5222-111091-7834-3/4?mpre=hxxp://www.ebay.ch/sch/i.html?_nkw={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 195.34.133.21 192.168.1.1
FireFox:
========
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin-x32: @authentec.com/ffwloplugin - C:\Program Files (x86)\HP SimplePass\npffwloplugin.dll ( HP)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @graphisoft.com/GDL Web Plug-in - C:\Program Files (x86)\GRAPHISOFT\GDLWebControl\npGDLMozilla.dll (Graphisoft SE)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.52 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR DefaultSearchKeyword: ecosia.org
CHR DefaultSearchProvider: Ecosia
CHR DefaultSearchURL: hxxp://ecosia.org/search.php?q={searchTerms}&addon=opensearch
CHR DefaultNewTabURL:
CHR Extension: (Google Docs) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-08-24]
CHR Extension: (Google Drive) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-24]
CHR Extension: (YouTube) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-24]
CHR Extension: (Google-Suche) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-24]
CHR Extension: (AdBlock) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-06-16]
CHR Extension: (Google Wallet) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-30]
CHR Extension: (Google Mail) - C:\Users\Patrick\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-24]
CHR HKLM-x32\...\Chrome\Extension: [kanflfepiobnpjbljmngfgegijhdpljm] - C:\Program Files (x86)\HP SimplePass\tschrome.crx [2013-04-01]
==================== Services (Whitelisted) =================
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.)
R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed]
R2 FPLService; C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe [1641768 2013-06-07] (HP)
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-03-12] (WildTangent)
R2 HP DS Service; C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe [13824 2010-10-27] (Hewlett-Packard Company) [File not signed]
R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [145920 2010-10-27] (HP) [File not signed]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed]
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2011-12-16] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2011-12-16] (Intel Corporation)
R2 lxbk_device; C:\Windows\system32\lxbkcoms.exe [565928 2008-02-19] ( )
R2 lxbk_device; C:\Windows\SysWOW64\lxbkcoms.exe [537256 2008-02-19] ( )
R2 lxdn_device; C:\Windows\system32\lxdncoms.exe [1039872 2007-11-28] ( )
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2012-12-01] ()
S3 TrueService; C:\Program Files\Common Files\AuthenTec\TrueService.exe [401856 2013-01-07] (AuthenTec, Inc.)
==================== Drivers (Whitelisted) ====================
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [165688 2013-05-29] (Broadcom Corporation.)
S3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [89640 2011-05-21] (Broadcom Corporation.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [259688 2011-10-27] (Realtek Semiconductor Corp.)
S3 s217bus; C:\Windows\System32\DRIVERS\s217bus.sys [108072 2007-11-02] (MCCI Corporation)
S3 s217mdfl; C:\Windows\System32\DRIVERS\s217mdfl.sys [19496 2007-11-02] (MCCI Corporation)
S3 s217mdm; C:\Windows\System32\DRIVERS\s217mdm.sys [145448 2007-11-02] (MCCI Corporation)
S3 s217nd5; C:\Windows\System32\DRIVERS\s217nd5.sys [33832 2007-11-02] (MCCI Corporation)
S3 s217obex; C:\Windows\System32\DRIVERS\s217obex.sys [124968 2007-11-02] (MCCI Corporation)
S3 s217unic; C:\Windows\System32\DRIVERS\s217unic.sys [138792 2007-11-02] (MCCI)
R3 SmbDrv; C:\Windows\system32\drivers\Smb_driver.sys [20016 2011-10-14] (Synaptics Incorporated)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-19 20:16 - 2014-06-19 20:16 - 00001178 _____ () C:\Users\Patrick\Desktop\JRT.txt
2014-06-19 20:10 - 2014-06-19 20:10 - 01016261 _____ (Thisisu) C:\Users\Patrick\Downloads\JRT (1).exe
2014-06-19 20:10 - 2014-06-19 20:10 - 01016261 _____ (Thisisu) C:\Users\Patrick\Desktop\JRT.exe
2014-06-19 20:05 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-19 20:04 - 2014-06-19 20:04 - 01333465 _____ () C:\Users\Patrick\Desktop\adwcleaner_3.212.exe
2014-06-19 20:03 - 2014-06-19 20:03 - 00031346 _____ () C:\Users\Patrick\Desktop\mbam.txt
2014-06-19 19:50 - 2014-06-19 19:50 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte
2014-06-19 19:45 - 2014-06-19 19:45 - 00724080 _____ () C:\Windows\Minidump\061914-27690-01.dmp
2014-06-19 18:37 - 2014-06-19 18:37 - 00001264 _____ () C:\Users\Patrick\Desktop\Revo Uninstaller.lnk
2014-06-19 18:37 - 2014-06-19 18:37 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-19 18:35 - 2014-06-19 18:36 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Patrick\Desktop\revosetup95.exe
2014-06-19 17:41 - 2014-06-19 17:41 - 00013075 _____ () C:\Users\Patrick\Desktop\Gmer.txt
2014-06-19 16:52 - 2014-06-19 16:52 - 00723888 _____ () C:\Windows\Minidump\061914-28984-01.dmp
2014-06-19 16:09 - 2014-06-19 16:10 - 00724464 _____ () C:\Windows\Minidump\061914-28719-01.dmp
2014-06-19 15:26 - 2014-06-19 15:26 - 00380416 _____ () C:\Users\Patrick\Desktop\Gmer-19357.exe
2014-06-19 15:22 - 2014-06-19 15:24 - 00035585 _____ () C:\Users\Patrick\Desktop\Addition.txt
2014-06-19 15:21 - 2014-06-19 20:17 - 00019606 _____ () C:\Users\Patrick\Desktop\FRST.txt
2014-06-19 15:21 - 2014-06-19 20:17 - 00000000 ____D () C:\FRST
2014-06-19 15:20 - 2014-06-19 15:20 - 02082304 _____ (Farbar) C:\Users\Patrick\Desktop\FRST64.exe
2014-06-19 15:19 - 2014-06-19 15:19 - 00000476 _____ () C:\Users\Patrick\Desktop\defogger_disable.log
2014-06-19 15:19 - 2014-06-19 15:19 - 00000000 _____ () C:\Users\Patrick\defogger_reenable
2014-06-19 15:17 - 2014-06-19 15:17 - 00050477 _____ () C:\Users\Patrick\Desktop\Defogger.exe
2014-06-19 12:32 - 2014-06-19 20:02 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-19 12:31 - 2014-06-19 12:31 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-19 12:31 - 2014-06-19 12:31 - 00001102 _____ () C:\ProgramData\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-19 12:31 - 2014-06-19 12:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-19 12:31 - 2014-06-19 12:31 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-19 12:31 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-19 12:31 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-19 11:31 - 2014-06-19 11:31 - 00000000 _____ () C:\autoexec.bat
2014-06-19 11:30 - 2014-06-19 11:30 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-06-19 11:29 - 2014-06-19 12:29 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-06-19 11:28 - 2014-06-19 11:28 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Patrick\Downloads\SpyHunter-Installer.exe
2014-06-19 11:28 - 2014-06-19 11:28 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Patrick\Downloads\SpyHunter-Installer (1).exe
2014-06-16 14:13 - 2014-06-16 14:13 - 00003138 _____ () C:\Windows\System32\Tasks\{EA557B9B-F151-43CC-97B7-15CDFCC67C29}
2014-06-16 02:34 - 2014-06-16 02:34 - 00000000 ____D () C:\Users\Patrick\AppData\Local\com
2014-06-16 02:33 - 2014-06-16 02:33 - 00003184 _____ () C:\Windows\System32\Tasks\{97BCDE11-FA9A-4338-9756-8DD3BBACC817}
2014-06-16 02:29 - 2014-06-16 14:21 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-06-16 02:28 - 2014-06-16 02:28 - 01245704 _____ () C:\Users\Patrick\Downloads\Setup.exe
2014-06-12 00:03 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-12 00:03 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-12 00:02 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-12 00:02 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-12 00:02 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-12 00:02 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-12 00:02 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-12 00:02 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-12 00:02 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-12 00:02 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-12 00:02 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-12 00:02 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-12 00:01 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-12 00:01 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-12 00:01 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-12 00:01 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-12 00:01 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-12 00:01 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-12 00:01 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-12 00:01 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-12 00:01 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-12 00:01 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-12 00:01 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-12 00:01 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-12 00:01 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-12 00:01 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-12 00:01 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-12 00:01 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-12 00:01 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-12 00:01 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-12 00:01 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 00:01 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-12 00:01 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-12 00:01 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-12 00:01 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-12 00:01 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-12 00:01 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-12 00:01 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-12 00:01 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-12 00:01 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-12 00:01 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-12 00:01 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-12 00:01 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-12 00:01 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-12 00:01 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-12 00:01 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-12 00:01 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-12 00:01 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-12 00:01 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-12 00:01 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-12 00:01 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-12 00:01 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-12 00:01 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-12 00:01 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-12 00:01 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-12 00:01 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-12 00:01 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-12 00:01 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-12 00:01 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-12 00:01 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-12 00:01 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-12 00:01 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-12 00:01 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-12 00:01 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-11 23:59 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-11 23:59 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-23 18:29 - 2014-05-23 18:29 - 00210417 _____ () C:\Users\Patrick\Downloads\e-bilet.zip
==================== One Month Modified Files and Folders =======
2014-06-19 20:17 - 2014-06-19 15:21 - 00019606 _____ () C:\Users\Patrick\Desktop\FRST.txt
2014-06-19 20:17 - 2014-06-19 15:21 - 00000000 ____D () C:\FRST
2014-06-19 20:16 - 2014-06-19 20:16 - 00001178 _____ () C:\Users\Patrick\Desktop\JRT.txt
2014-06-19 20:15 - 2009-07-14 06:45 - 00031472 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-19 20:15 - 2009-07-14 06:45 - 00031472 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-19 20:10 - 2014-06-19 20:10 - 01016261 _____ (Thisisu) C:\Users\Patrick\Downloads\JRT (1).exe
2014-06-19 20:10 - 2014-06-19 20:10 - 01016261 _____ (Thisisu) C:\Users\Patrick\Desktop\JRT.exe
2014-06-19 20:10 - 2014-05-07 08:33 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\DropboxMaster
2014-06-19 20:10 - 2012-11-20 19:55 - 00000000 ___RD () C:\Users\Patrick\Dropbox
2014-06-19 20:10 - 2012-11-20 19:53 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\Dropbox
2014-06-19 20:08 - 2012-11-19 01:00 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-19 20:08 - 2012-09-10 21:35 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\Skype
2014-06-19 20:08 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-19 20:08 - 2009-07-14 06:51 - 00126208 _____ () C:\Windows\setupact.log
2014-06-19 20:07 - 2013-08-24 10:27 - 00000000 ____D () C:\AdwCleaner
2014-06-19 20:07 - 2012-09-04 10:41 - 01411554 _____ () C:\Windows\WindowsUpdate.log
2014-06-19 20:07 - 2010-11-21 05:47 - 00982602 _____ () C:\Windows\PFRO.log
2014-06-19 20:04 - 2014-06-19 20:04 - 01333465 _____ () C:\Users\Patrick\Desktop\adwcleaner_3.212.exe
2014-06-19 20:03 - 2014-06-19 20:03 - 00031346 _____ () C:\Users\Patrick\Desktop\mbam.txt
2014-06-19 20:02 - 2014-06-19 12:32 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-19 19:50 - 2014-06-19 19:50 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth-Geräte
2014-06-19 19:45 - 2014-06-19 19:45 - 00724080 _____ () C:\Windows\Minidump\061914-27690-01.dmp
2014-06-19 19:45 - 2012-10-15 17:57 - 638067174 _____ () C:\Windows\MEMORY.DMP
2014-06-19 19:45 - 2012-10-15 17:57 - 00000000 ____D () C:\Windows\Minidump
2014-06-19 19:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Vss
2014-06-19 19:30 - 2012-11-19 01:00 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-19 19:19 - 2012-03-09 19:23 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-19 18:37 - 2014-06-19 18:37 - 00001264 _____ () C:\Users\Patrick\Desktop\Revo Uninstaller.lnk
2014-06-19 18:37 - 2014-06-19 18:37 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-19 18:36 - 2014-06-19 18:35 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Patrick\Desktop\revosetup95.exe
2014-06-19 18:13 - 2012-11-29 11:48 - 00000000 ____D () C:\Users\Patrick\AppData\Local\Akamai
2014-06-19 17:41 - 2014-06-19 17:41 - 00013075 _____ () C:\Users\Patrick\Desktop\Gmer.txt
2014-06-19 16:52 - 2014-06-19 16:52 - 00723888 _____ () C:\Windows\Minidump\061914-28984-01.dmp
2014-06-19 16:10 - 2014-06-19 16:09 - 00724464 _____ () C:\Windows\Minidump\061914-28719-01.dmp
2014-06-19 15:26 - 2014-06-19 15:26 - 00380416 _____ () C:\Users\Patrick\Desktop\Gmer-19357.exe
2014-06-19 15:24 - 2014-06-19 15:22 - 00035585 _____ () C:\Users\Patrick\Desktop\Addition.txt
2014-06-19 15:20 - 2014-06-19 15:20 - 02082304 _____ (Farbar) C:\Users\Patrick\Desktop\FRST64.exe
2014-06-19 15:19 - 2014-06-19 15:19 - 00000476 _____ () C:\Users\Patrick\Desktop\defogger_disable.log
2014-06-19 15:19 - 2014-06-19 15:19 - 00000000 _____ () C:\Users\Patrick\defogger_reenable
2014-06-19 15:19 - 2012-09-04 10:42 - 00000000 ____D () C:\Users\Patrick
2014-06-19 15:17 - 2014-06-19 15:17 - 00050477 _____ () C:\Users\Patrick\Desktop\Defogger.exe
2014-06-19 14:44 - 2013-05-26 12:15 - 00003946 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{B07BB53A-0FC6-4529-AC67-30E526E52353}
2014-06-19 12:31 - 2014-06-19 12:31 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-19 12:31 - 2014-06-19 12:31 - 00001102 _____ () C:\ProgramData\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-19 12:31 - 2014-06-19 12:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-19 12:31 - 2014-06-19 12:31 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-19 12:31 - 2013-08-24 13:18 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\Malwarebytes
2014-06-19 12:31 - 2013-08-24 13:18 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-19 12:31 - 2013-08-24 13:18 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-06-19 12:29 - 2014-06-19 11:29 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-06-19 11:31 - 2014-06-19 11:31 - 00000000 _____ () C:\autoexec.bat
2014-06-19 11:30 - 2014-06-19 11:30 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-06-19 11:28 - 2014-06-19 11:28 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Patrick\Downloads\SpyHunter-Installer.exe
2014-06-19 11:28 - 2014-06-19 11:28 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Patrick\Downloads\SpyHunter-Installer (1).exe
2014-06-19 09:05 - 2012-09-12 19:44 - 00000340 _____ () C:\Windows\Tasks\HPCeeScheduleForPatrick.job
2014-06-18 13:57 - 2012-09-12 19:44 - 00003198 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForPatrick
2014-06-18 13:57 - 2012-09-05 14:40 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-06-18 13:56 - 2012-12-05 20:03 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-06-17 02:19 - 2013-12-27 14:17 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\Azureus
2014-06-17 01:04 - 2013-06-30 23:24 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\vlc
2014-06-17 00:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-06-16 14:21 - 2014-06-16 02:29 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-06-16 14:13 - 2014-06-16 14:13 - 00003138 _____ () C:\Windows\System32\Tasks\{EA557B9B-F151-43CC-97B7-15CDFCC67C29}
2014-06-16 02:41 - 2013-05-26 12:15 - 00001421 _____ () C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-06-16 02:34 - 2014-06-16 02:34 - 00000000 ____D () C:\Users\Patrick\AppData\Local\com
2014-06-16 02:33 - 2014-06-16 02:33 - 00003184 _____ () C:\Windows\System32\Tasks\{97BCDE11-FA9A-4338-9756-8DD3BBACC817}
2014-06-16 02:28 - 2014-06-16 02:28 - 01245704 _____ () C:\Users\Patrick\Downloads\Setup.exe
2014-06-13 20:36 - 2013-11-07 15:35 - 00000000 ____D () C:\ProgramData\lx_Cats
2014-06-13 20:30 - 2012-03-10 03:35 - 00699666 _____ () C:\Windows\system32\perfh007.dat
2014-06-13 20:30 - 2012-03-10 03:35 - 00149774 _____ () C:\Windows\system32\perfc007.dat
2014-06-13 20:30 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-13 09:20 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-12 03:44 - 2013-07-17 19:56 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-12 03:42 - 2013-01-20 17:47 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-12 03:40 - 2014-05-08 19:07 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-11 20:32 - 2014-04-28 20:33 - 00000000 ____D () C:\Users\Patrick\Documents\Lebenslauf
2014-06-08 11:13 - 2014-06-11 23:59 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-11 23:59 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-03 23:28 - 2014-01-18 16:35 - 00000000 ____D () C:\Users\Patrick\Documents\PS Freebie Notes
2014-05-30 12:21 - 2014-06-12 00:01 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-30 12:02 - 2014-06-12 00:01 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-30 12:02 - 2014-06-12 00:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-30 11:45 - 2014-06-12 00:01 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-30 11:39 - 2014-06-12 00:01 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-30 11:39 - 2014-06-12 00:01 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-30 11:38 - 2014-06-12 00:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-30 11:28 - 2014-06-12 00:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-30 11:27 - 2014-06-12 00:01 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-30 11:24 - 2014-06-12 00:01 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-30 11:21 - 2014-06-12 00:01 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-30 11:21 - 2014-06-12 00:01 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-30 11:20 - 2014-06-12 00:01 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-30 11:18 - 2014-06-12 00:01 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-30 11:11 - 2014-06-12 00:01 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-30 11:08 - 2014-06-12 00:01 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-30 11:06 - 2014-06-12 00:01 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-30 11:02 - 2014-06-12 00:01 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-30 10:55 - 2014-06-12 00:01 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:49 - 2014-06-12 00:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-30 10:46 - 2014-06-12 00:01 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-30 10:44 - 2014-06-12 00:01 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-30 10:44 - 2014-06-12 00:01 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-30 10:43 - 2014-06-12 00:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-30 10:42 - 2014-06-12 00:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-12 00:01 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-30 10:35 - 2014-06-12 00:01 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-30 10:34 - 2014-06-12 00:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-30 10:33 - 2014-06-12 00:01 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-30 10:30 - 2014-06-12 00:01 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-30 10:29 - 2014-06-12 00:01 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-30 10:28 - 2014-06-12 00:01 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-30 10:27 - 2014-06-12 00:01 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-30 10:24 - 2014-06-12 00:01 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-05-30 10:23 - 2014-06-12 00:01 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-30 10:16 - 2014-06-12 00:01 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-30 10:10 - 2014-06-12 00:01 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-12 00:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-30 10:04 - 2014-06-12 00:01 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-30 10:02 - 2014-06-12 00:01 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-30 09:56 - 2014-06-12 00:01 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-30 09:56 - 2014-06-12 00:01 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-30 09:54 - 2014-06-12 00:01 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-30 09:50 - 2014-06-12 00:01 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-12 00:01 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-30 09:43 - 2014-06-12 00:01 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-30 09:40 - 2014-06-12 00:01 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-30 09:30 - 2014-06-12 00:01 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-30 09:21 - 2014-06-12 00:01 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-30 09:15 - 2014-06-12 00:01 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-30 09:13 - 2014-06-12 00:01 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-30 09:13 - 2014-06-12 00:01 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-24 15:58 - 2012-11-28 20:02 - 00003310 _____ () C:\Windows\wininit.ini
2014-05-24 15:58 - 2012-11-20 19:53 - 00000000 ____D () C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-05-23 18:29 - 2014-05-23 18:29 - 00210417 _____ () C:\Users\Patrick\Downloads\e-bilet.zip
Some content of TEMP:
====================
C:\Users\Patrick\AppData\Local\Temp\2040-2082_re-markit.exe
C:\Users\Patrick\AppData\Local\Temp\BackupSetup.exe
C:\Users\Patrick\AppData\Local\Temp\cloud_backup_setup.exe
C:\Users\Patrick\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpcxjf1u.dll
C:\Users\Patrick\AppData\Local\Temp\Extract.exe
C:\Users\Patrick\AppData\Local\Temp\i4jdel0.exe
C:\Users\Patrick\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Patrick\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Patrick\AppData\Local\Temp\lly_webssearches.exe
C:\Users\Patrick\AppData\Local\Temp\Quarantine.exe
C:\Users\Patrick\AppData\Local\Temp\Setup.exe
C:\Users\Patrick\AppData\Local\Temp\SHSetup.exe
C:\Users\Patrick\AppData\Local\Temp\Softonic_chr_1-8-29-3_cn.exe
C:\Users\Patrick\AppData\Local\Temp\SP62991.exe
C:\Users\Patrick\AppData\Local\Temp\SP63224.exe
C:\Users\Patrick\AppData\Local\Temp\SP63801.exe
C:\Users\Patrick\AppData\Local\Temp\sp64126.exe
C:\Users\Patrick\AppData\Local\Temp\speedupmypc.exe
C:\Users\Patrick\AppData\Local\Temp\UninstallHPSA.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-19 13:40
==================== End Of Log ============================ --- --- ---
--- --- ---
Danke,
patrick |