So habe jz alles zusammen: Code:
# AdwCleaner v3.216 - Bericht erstellt am 18/07/2014 um 08:35:30
# Aktualisiert 17/07/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzername : Müller-Gulden - MÜLLERGULDEN
# Gestartet von : C:\Users\Müller-Gulden\Downloads\adwcleaner_3.216.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\SoftwareUpdater
Ordner Gelöscht : C:\ProgramData\AVG Secure Search
Ordner Gelöscht : C:\ProgramData\AVG Security Toolbar
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\DSearchLink
Ordner Gelöscht : C:\Program Files\BonanzaDeals
Ordner Gelöscht : C:\Program Files\Common Files\AVG Secure Search
Ordner Gelöscht : C:\Users\Müller-Gulden\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Müller-Gulden\AppData\Roaming\digitalsite
Datei Gelöscht : C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Datei Gelöscht : C:\Windows\System32\Tasks\DigitalSite
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{35D21B4B-556A-43B8-A3B8-FC15FE22215A}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{35D21B4B-556A-43B8-A3B8-FC15FE22215A}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EC9510D-A439-4950-9399-B6399EDF9EA7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Schlüssel Gelöscht : HKLM\SOFTWARE\530dbdeb56eea42
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\dsiteproducts
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\BrowserSafeGuard
Schlüssel Gelöscht : HKLM\Software\Delta
Schlüssel Gelöscht : HKLM\Software\SupDp
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\supWPM
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17207
-\\ Mozilla Firefox v26.0 (de)
[ Datei : C:\Users\Müller-Gulden\AppData\Roaming\Mozilla\Firefox\Profiles\3l9kdex3.default-1405508231173\prefs.js ]
-\\ Google Chrome v35.0.1916.153
[ Datei : C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=86570016D386C63E&affID=119357&tt=240913_238&tsp=5016
Gelöscht [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1405507719&from=adks&uid=WDCXWD1600BEVS-00RST0_WD-WXH70709240992409&q={searchTerms}
*************************
AdwCleaner[R0].txt - [4975 octets] - [18/07/2014 08:33:54]
AdwCleaner[S0].txt - [4908 octets] - [18/07/2014 08:35:30]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4968 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x86
Ran by Mller-Gulden on 18.07.2014 at 8:41:19,71
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3813648498-136249664-21129230-1000\Software\sweetim
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18.07.2014 at 8:52:15,23
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 18.07.2014
Suchlauf-Zeit: 08:06:05
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.18.02
Rootkit Datenbank: v2014.07.17.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Müller-Gulden
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 287356
Verstrichene Zeit: 9 Min, 46 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.Adpeak.A, C:\Program Files\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt.exe, 1956, Löschen bei Neustart, [f208722ee39812240b7c279722e032ce]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 16
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [dd1d8b15b0cbdf578512eea06e9450b0],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-3813648498-136249664-21129230-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [8773d0d009729c9a82d0ff562ad81fe1],
PUP.Optional.Babylon.A, HKU\S-1-5-21-3813648498-136249664-21129230-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, In Quarantäne, [51a9c3ddb1ca1224fd26fe5740c29868],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [42b828783348b87e8724cf8a28dad12f],
PUP.Optional.Adpeak.A, HKLM\SOFTWARE\AllDaySavings, In Quarantäne, [89719b054239e0563f45bfff18ea35cb],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\BonanzaDealsLive, In Quarantäne, [17e3811f106b9d9926c2fc098183946c],
PUP.Optional.ISearch.A, HKLM\SOFTWARE\omiga-plusSoftware, In Quarantäne, [8f6ba7f9730863d3d51a26ef699b4fb1],
PUP.Optional.WPM.A, HKLM\SOFTWARE\supWindowsMangerProtect, In Quarantäne, [3fbb1090f289c373e61e21fda163e818],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [d228158ba3d884b24f302edb60a4af51],
PUP.Optional.Adpeak.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\AllDaySavingsService, In Quarantäne, [f208722ee39812240b7c279722e032ce],
PUP.Optional.BonanzaDeals.A, HKU\S-1-5-21-3813648498-136249664-21129230-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BonanzaDealsLive, In Quarantäne, [9c5eb2ee4d2e1a1ca0463dc812f224dc],
PUP.Optional.BrowserSafeGuard.A, HKU\S-1-5-21-3813648498-136249664-21129230-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BrowserSafeguardInstalled, In Quarantäne, [55a5623edc9ffe380c35cef662a006fa],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-3813648498-136249664-21129230-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, In Quarantäne, [d2288f1182f9e551fcad5e9fcb3846ba],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3813648498-136249664-21129230-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [32c8e0c05823c076902ea14602008f71],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3813648498-136249664-21129230-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [9268fba50a71a98d448946b79073f907],
PUP.Optional.Qone8, HKU\S-1-5-21-3813648498-136249664-21129230-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [a6544f519edde74ffe8058b102023dc3],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3813648498-136249664-21129230-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0L1N1H2O1S, In Quarantäne, [9268fba50a71a98d448946b79073f907]
Registrierungsdaten: 2
PUP.Optional.ISearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://isearch.omiga-plus.com/?type=hp&ts=1405507421&from=adks&uid=WDCXWD1600BEVS-00RST0_WD-WXH70709240992409, Gut: (www.google.com), Schlecht: (hxxp://isearch.omiga-plus.com/?type=hp&ts=1405507421&from=adks&uid=WDCXWD1600BEVS-00RST0_WD-WXH70709240992409),Ersetzt,[21d9efb14e2d66d07425edae48bcb14f]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[7c7e346cfe7dc5713a0bedb942c2c53b]
Ordner: 40
PUP.Optional.SupTab.A, C:\Program Files\SupTab, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\weather, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\en-US, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\es-419, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\es-ES, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-BE, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-CA, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-CH, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-FR, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-LU, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\it-CH, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\it-IT, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pl, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pt, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pt-BR, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\ru, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\ru-MO, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\tr-TR, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\vi-VI, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\zh-CN, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\zh-TW, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.DigitalSite.A, C:\Users\Müller-Gulden\AppData\Roaming\DigitalSite\UpdateProc, In Quarantäne, [14e6bce4fd7ec175aad546a4b64ced13],
PUP.Optional.BonanzaDeals.A, C:\ProgramData\BonanzaDealsLive, In Quarantäne, [91695b455a21b08612adbbe76e94dd23],
PUP.Optional.BonanzaDeals.A, C:\ProgramData\BonanzaDealsLive\Update, In Quarantäne, [91695b455a21b08612adbbe76e94dd23],
PUP.Optional.BonanzaDeals.A, C:\ProgramData\BonanzaDealsLive\Update\Log, In Quarantäne, [91695b455a21b08612adbbe76e94dd23],
PUP.Optional.BonanzaDeals.A, C:\Users\Müller-Gulden\AppData\Local\BonanzaDealsLive, In Quarantäne, [f208722ede9dd264b808d7cbef1314ec],
PUP.Optional.BonanzaDeals.A, C:\Users\Müller-Gulden\AppData\Local\BonanzaDealsLive\CrashReports, In Quarantäne, [f208722ede9dd264b808d7cbef1314ec],
PUP.Optional.BonanzaDeals.A, C:\Program Files\BonanzaDealsLive, In Quarantäne, [8b6f9709bebd04324181633fcf336f91],
PUP.Optional.BonanzaDeals.A, C:\Program Files\BonanzaDealsLive\CrashReports, In Quarantäne, [8b6f9709bebd04324181633fcf336f91],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, In Quarantäne, [e01a455bbcbf91a54a58ae0956accb35],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [e01a455bbcbf91a54a58ae0956accb35],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, In Quarantäne, [b446fca4b4c7e15556c0308ae51d53ad],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, In Quarantäne, [b446fca4b4c7e15556c0308ae51d53ad],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [b446fca4b4c7e15556c0308ae51d53ad],
PUP.Optional.Adpeak.A, C:\Program Files\AllDaySavings, In Quarantäne, [fefc435d304b1125f5b002bbb151748c],
PUP.Optional.Adpeak.A, C:\Program Files\AllDaySavings\SSL, In Quarantäne, [fefc435d304b1125f5b002bbb151748c],
Dateien: 74
PUP.Optional.Delta.A, C:\ProgramData\DSearchLink\DSearchLink.exe, In Quarantäne, [fcfee9b792e9da5c7f1398cb729257a9],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, In Quarantäne, [e2182d733e3d75c13bd3771a81809d63],
PUP.Optional.BundleInstaller.A, C:\Users\Müller-Gulden\Downloads\ImageEditorSetup.exe, In Quarantäne, [87732080f58652e40ec9fd286c98f808],
PUP.Optional.Boost.A, C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igckfjdcbkimejmjmpmebffdjjjgncfn_0.localstorage, In Quarantäne, [b248f1af46359f97994c5a65cf332cd4],
PUP.Optional.Boost.A, C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igckfjdcbkimejmjmpmebffdjjjgncfn_0.localstorage-journal, In Quarantäne, [ce2c4e526516072f22c3f4cb3fc3b34d],
PUP.Optional.Boost.A, C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage, In Quarantäne, [8a70a9f7ee8d71c57c6a11aefa089967],
PUP.Optional.Boost.A, C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage-journal, In Quarantäne, [de1ce8b82a5180b617cf4c7355ad738d],
PUP.Optional.Boost.A, C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage, In Quarantäne, [d426326ec9b295a17572526d976b2bd5],
PUP.Optional.Boost.A, C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage-journal, In Quarantäne, [d822c8d86516251140a7a31c9d65619f],
PUP.Optional.BrowserSafeGuard.A, C:\Windows\System32\Tasks\BrowserSafeguard, In Quarantäne, [c733970996e563d38f6d536c857dc937],
PUP.Optional.BetterDeals.A, C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage, Löschen bei Neustart, [4bafe9b74e2d0a2cf37b9f2b3bc7966a],
PUP.Optional.BetterDeals.A, C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage-journal, Löschen bei Neustart, [64967f213b4078bedd91b7133ec4b64a],
PUP.Optional.Superfish.A, C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, Löschen bei Neustart, [9268c9d7423960d68425309fc939af51],
PUP.Optional.Superfish.A, C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, In Quarantäne, [7486f5abaecda294baef3f9071912cd4],
PUP.Optional.MindSpark.A, C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_allin1convert.dl.tb.ask.com_0.localstorage, In Quarantäne, [a05a7c24bac15cdafb28d102b54d0bf5],
PUP.Optional.MindSpark.A, C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_allin1convert.dl.tb.ask.com_0.localstorage-journal, In Quarantäne, [01f9c6da0a71ce68ce55fdd61ee4a35d],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\install.data, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\ient.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\uninstall.exe, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\WebDataJs, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\data.html, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\indexIE.html, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\indexIE8.html, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\main.css, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\ver.txt, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\arrow.png, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\default_add_logo.png, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\default_add_logo_hover.png, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\default_logo.png, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\googlelogo.png, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\googlelogo2.png, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\google_trends.png, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\icon128.png, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\icon16.png, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\icon48.png, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\loading.gif, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\logo32.ico, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\img\weather\0.png, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\common.js, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\ga.js, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\ie8.js, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\js.js, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\library.js, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\js\xagainit.js, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\en-US\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\es-419\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\es-ES\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-BE\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-CA\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-CH\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-FR\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\fr-LU\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\it-CH\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\it-IT\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pl\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pt\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\pt-BR\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\ru\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\ru-MO\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\tr-TR\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\vi-VI\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\zh-CN\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.SupTab.A, C:\Program Files\SupTab\web\_locales\zh-TW\messages.json, In Quarantäne, [ad4da5fb0f6c6dc97d0932b26a9817e9],
PUP.Optional.DigitalSite.A, C:\Users\Müller-Gulden\AppData\Roaming\DigitalSite\UpdateProc\config.dat, In Quarantäne, [14e6bce4fd7ec175aad546a4b64ced13],
PUP.Optional.DigitalSite.A, C:\Users\Müller-Gulden\AppData\Roaming\DigitalSite\UpdateProc\prod.dat, In Quarantäne, [14e6bce4fd7ec175aad546a4b64ced13],
PUP.Optional.QuickStart.A, C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage, In Quarantäne, [ac4e4759fe7dc76f24a41705a75dfc04],
PUP.Optional.QuickStart.A, C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage-journal, In Quarantäne, [c337366a91ea74c2d9efc656af557b85],
PUP.Optional.Adpeak.A, C:\Program Files\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt.exe, Löschen bei Neustart, [f208722ee39812240b7c279722e032ce],
PUP.Optional.BonanzaDeals.A, C:\ProgramData\BonanzaDealsLive\Update\Log\BonanzaDealsLive.log, In Quarantäne, [91695b455a21b08612adbbe76e94dd23],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, In Quarantäne, [e01a455bbcbf91a54a58ae0956accb35],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-07-16[12-44-11-653].log, In Quarantäne, [b446fca4b4c7e15556c0308ae51d53ad],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [b446fca4b4c7e15556c0308ae51d53ad],
Physische Sektoren: 0
(No malicious items detected)
(end)
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-07-2014 01
Ran by Müller-Gulden (administrator) on MÜLLERGULDEN on 18-07-2014 08:58:07
Running from C:\Users\Müller-Gulden\Downloads
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe
(Firebird Project) C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgemcx.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Firebird Project) C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Thisisu) C:\Users\Müller-Gulden\Downloads\JRT.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Corporation) C:\Windows\System32\dinotify.exe
(DV Trend Service GmbH) G:\CAP\CAP Client.exe
(Microsoft Corporation) C:\Windows\System32\mstsc.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2014\avgui.exe [5187088 2014-07-10] (AVG Technologies CZ, s.r.o.)
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [280576 2013-05-27] (Microsoft Corporation)
HKU\S-1-5-21-3813648498-136249664-21129230-1000\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [24477056 2014-06-27] (Google)
Startup: C:\Users\Müller-Gulden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll (Google)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE80FA6000752CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
SearchScopes: HKLM - DefaultScope value is missing.
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Müller-Gulden\AppData\Roaming\Mozilla\Firefox\Profiles\3l9kdex3.default-1405508231173
FF Plugin: @soft-xpansion/npsxpdf - C:\Program Files\Common Files\Freemium\np-sxpdf.dll (soft-Xpansion)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\omiga-plus.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM\...\Firefox\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
FF Extension: Free PDF Perfect - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb [2014-02-25]
FF HKLM\...\Thunderbird\Extensions: [{B45418F9-6406-4828-9D1A-35313FB1E2D6}] - C:\ProgramData\Freemium\Free PDF Perfect\Data\fftb
Chrome:
=======
CHR HomePage: https://mysearch.avg.com?cid={D68223C9-8888-477F-8359-F048833FF5F1}&mid=f94076da02eb47d2a6ddd15f95622fcd-d587f15883129c3f5f5f9d699e1d747473be398c&lang=de&ds=AVG&coid=avgtbavg&pr=fr&d=2014-07-17 13:38:52&v=3.1.0.6&pid=wtu&sg=&sap=hp
CHR StartupUrls: "https://mysearch.avg.com?cid={D68223C9-8888-477F-8359-F048833FF5F1}&mid=f94076da02eb47d2a6ddd15f95622fcd-d587f15883129c3f5f5f9d699e1d747473be398c&lang=de&ds=AVG&coid=avgtbavg&pr=fr&d=2014-07-17 13:38:52&v=3.1.0.6&pid=wtu&sg=&sap=hp"
CHR Extension: (Google Docs) - C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-05-16]
CHR Extension: (Google Drive) - C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-16]
CHR Extension: (YouTube) - C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-05-16]
CHR Extension: (Google-Suche) - C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-05-16]
CHR Extension: (Google Wallet) - C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-03]
CHR Extension: (Google Mail) - C:\Users\Müller-Gulden\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-05-16]
========================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3244048 2014-07-10] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [289328 2014-07-10] (AVG Technologies CZ, s.r.o.)
R2 FirebirdGuardianDefaultInstance; C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe [81920 2008-06-13] (Firebird Project) [File not signed]
R3 FirebirdServerDefaultInstance; C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe [2723840 2008-06-13] (Firebird Project) [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 SXDS10; C:\Program Files\Common Files\soft Xpansion\sxds10.exe [234096 2014-02-25] (soft Xpansion)
S2 vToolbarUpdater3.1.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\3.1.0\ToolbarUpdater.exe [X]
==================== Drivers (Whitelisted) ====================
R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [121624 2014-06-30] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [199960 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147736 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [188696 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [241944 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [98584 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27416 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [197400 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-07-17] (AVG Technologies)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-07-18] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation)
R1 netfilter; C:\Windows\System32\drivers\netfilter.sys [31744 2014-07-10] (NetFilterSDK.com) [File not signed]
R0 Si3531; C:\Windows\System32\DRIVERS\Si3531.sys [212520 2009-02-05] (Silicon Image, Inc)
R0 SiFilter; C:\Windows\System32\DRIVERS\SiWinAcc.sys [17064 2009-02-05] (Silicon Image, Inc.)
R0 SiRemFil; C:\Windows\System32\DRIVERS\SiRemFil.sys [12200 2009-02-05] (Silicon Image, Inc.)
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\MLLER-~1\AppData\Local\Temp\catchme.sys [X]
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-18 08:52 - 2014-07-18 08:52 - 00000820 _____ () C:\Users\Müller-Gulden\Desktop\JRT.txt
2014-07-18 08:41 - 2014-07-18 08:41 - 00000000 ____D () C:\Windows\ERUNT
2014-07-18 08:34 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-07-18 08:33 - 2014-07-18 08:35 - 00000000 ____D () C:\AdwCleaner
2014-07-18 08:32 - 2014-07-18 08:32 - 00020400 _____ () C:\Users\Müller-Gulden\Desktop\mbam.txt
2014-07-18 08:05 - 2014-07-18 08:37 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-18 08:04 - 2014-07-18 08:04 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-18 08:04 - 2014-07-18 08:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-18 08:04 - 2014-07-18 08:04 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-18 08:04 - 2014-07-18 08:04 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-18 08:04 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-18 08:04 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-18 08:04 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-18 07:58 - 2014-07-18 07:58 - 01016261 _____ (Thisisu) C:\Users\Müller-Gulden\Downloads\JRT.exe
2014-07-18 07:57 - 2014-07-18 07:58 - 01354223 _____ () C:\Users\Müller-Gulden\Downloads\adwcleaner_3.216.exe
2014-07-18 07:56 - 2014-07-18 07:56 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Müller-Gulden\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-17 14:12 - 2014-07-17 14:12 - 00019195 _____ () C:\ComboFix.txt
2014-07-17 13:46 - 2014-07-17 13:46 - 00013362 _____ () C:\Users\Müller-Gulden\Desktop\ComboFix - Verknüpfung.lnk
2014-07-17 13:44 - 2014-07-17 14:12 - 00000000 ____D () C:\Qoobox
2014-07-17 13:44 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-17 13:44 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-17 13:44 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-17 13:44 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-17 13:44 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-17 13:44 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-17 13:44 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-17 13:44 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-17 13:43 - 2014-07-17 14:11 - 00000000 ____D () C:\Windows\erdnt
2014-07-17 13:42 - 2014-07-17 13:42 - 05222061 ____R (Swearware) C:\Users\Müller-Gulden\Downloads\ComboFix.exe
2014-07-17 13:39 - 2014-07-17 13:39 - 00000000 ____D () C:\Users\Müller-Gulden\AppData\Local\AVG Web TuneUp
2014-07-17 13:38 - 2014-07-17 13:38 - 00000000 ____D () C:\ProgramData\AVG Web TuneUp
2014-07-17 13:38 - 2014-07-17 13:38 - 00000000 ____D () C:\Program Files\AVG Web TuneUp
2014-07-17 13:38 - 2014-07-17 13:37 - 00042784 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys
2014-07-17 12:56 - 2014-07-17 12:56 - 00002733 _____ () C:\Users\Müller-Gulden\Desktop\gmer.txt
2014-07-17 12:41 - 2014-07-17 12:41 - 00380416 _____ () C:\Users\Müller-Gulden\Downloads\Gmer-19357.exe
2014-07-17 12:36 - 2014-07-17 12:36 - 00000488 _____ () C:\Users\Müller-Gulden\Downloads\defogger_disable.log
2014-07-17 12:36 - 2014-07-17 12:36 - 00000000 _____ () C:\Users\Müller-Gulden\defogger_reenable
2014-07-17 12:35 - 2014-07-17 12:35 - 00050477 _____ () C:\Users\Müller-Gulden\Downloads\Defogger.exe
2014-07-17 12:33 - 2014-07-17 12:34 - 01075776 _____ (OR Interactive Ltd) C:\Users\Müller-Gulden\Downloads\IDM2.exe
2014-07-17 12:27 - 2014-07-17 12:30 - 00022319 _____ () C:\Users\Müller-Gulden\Downloads\Addition.txt
2014-07-17 12:25 - 2014-07-18 08:58 - 00011486 _____ () C:\Users\Müller-Gulden\Downloads\FRST.txt
2014-07-17 12:25 - 2014-07-18 08:58 - 00000000 ____D () C:\FRST
2014-07-17 12:24 - 2014-07-17 12:24 - 01077248 _____ (Farbar) C:\Users\Müller-Gulden\Downloads\FRST.exe
2014-07-16 13:07 - 2014-07-16 13:07 - 00000000 ____D () C:\Users\Müller-Gulden\AppData\Roaming\AVG2014
2014-07-16 13:06 - 2014-07-16 13:06 - 00000955 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-07-16 13:06 - 2014-07-16 13:06 - 00000000 ____D () C:\Users\Müller-Gulden\AppData\Roaming\TuneUp Software
2014-07-16 13:06 - 2014-07-16 13:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-07-16 13:05 - 2014-07-16 13:08 - 00000000 ____D () C:\ProgramData\AVG2014
2014-07-16 13:05 - 2014-07-16 13:05 - 00000000 ____D () C:\Program Files\AVG
2014-07-16 13:05 - 2014-07-16 13:05 - 00000000 ____D () C:\$AVG
2014-07-16 13:02 - 2014-07-18 07:12 - 00000000 ____D () C:\ProgramData\MFAData
2014-07-16 13:02 - 2014-07-16 13:11 - 00000000 ____D () C:\Users\Müller-Gulden\AppData\Local\Avg2014
2014-07-16 13:02 - 2014-07-16 13:02 - 04424232 _____ (AVG Technologies) C:\Users\Müller-Gulden\Downloads\avg_avct_stb_all_2014_4116_comppg_24.exe
2014-07-16 13:02 - 2014-07-16 13:02 - 00000000 ____D () C:\Users\Müller-Gulden\AppData\Local\MFAData
2014-07-16 12:45 - 2014-07-18 08:22 - 00000000 ____D () C:\Program Files\A7F8482B-1D99-4EC9-B887-8B130AB7E131
2014-07-16 12:44 - 2014-07-16 13:27 - 00000000 ____D () C:\Program Files\005
2014-07-10 21:40 - 2014-07-10 21:40 - 00031744 _____ (NetFilterSDK.com) C:\Windows\system32\Drivers\netfilter.sys
2014-07-09 15:58 - 2014-07-15 09:53 - 00182003 _____ () C:\Users\Müller-Gulden\Documents\Preisliste 2014.ods
2014-07-09 14:34 - 2014-07-09 14:34 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-07-09 14:34 - 2014-07-09 14:34 - 00000000 ____D () C:\ACCA
2014-07-09 14:28 - 2014-07-09 14:29 - 70104576 _____ (ACCA) C:\Users\Müller-Gulden\Downloads\nw_25322_primusvaenexe.exe
2014-07-09 13:47 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 13:47 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 13:47 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 13:47 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 13:47 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 13:47 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 13:47 - 2014-06-19 01:23 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 13:47 - 2014-06-19 01:16 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 13:47 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 13:47 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 13:47 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 13:47 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 13:47 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 13:46 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 13:46 - 2014-06-19 01:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 13:46 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 13:46 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 13:46 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 13:46 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 13:46 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 13:46 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 13:46 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 13:46 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 13:46 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 13:46 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 13:46 - 2014-06-19 00:52 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 13:46 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 13:46 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 13:46 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 13:46 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 13:46 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 13:46 - 2014-06-18 02:52 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 13:46 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 13:46 - 2014-06-05 16:26 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 13:46 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-08 14:05 - 2014-07-08 14:05 - 00000000 __SHD () C:\Users\Müller-Gulden\AppData\Local\EmieUserList
2014-07-08 14:05 - 2014-07-08 14:05 - 00000000 __SHD () C:\Users\Müller-Gulden\AppData\Local\EmieSiteList
2014-06-30 12:43 - 2014-06-30 12:43 - 00121624 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiskx.sys
==================== One Month Modified Files and Folders =======
2014-07-18 08:59 - 2014-07-17 12:25 - 00011486 _____ () C:\Users\Müller-Gulden\Downloads\FRST.txt
2014-07-18 08:58 - 2014-07-17 12:25 - 00000000 ____D () C:\FRST
2014-07-18 08:52 - 2014-07-18 08:52 - 00000820 _____ () C:\Users\Müller-Gulden\Desktop\JRT.txt
2014-07-18 08:51 - 2013-05-16 09:30 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-18 08:41 - 2014-07-18 08:41 - 00000000 ____D () C:\Windows\ERUNT
2014-07-18 08:38 - 2013-09-18 12:16 - 00000000 ___RD () C:\Users\Müller-Gulden\Google Drive
2014-07-18 08:37 - 2014-07-18 08:05 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-18 08:37 - 2013-05-17 07:29 - 00041614 _____ () C:\Windows\PFRO.log
2014-07-18 08:37 - 2013-05-16 09:30 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-18 08:37 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-18 08:37 - 2009-07-14 06:39 - 00032643 _____ () C:\Windows\setupact.log
2014-07-18 08:36 - 2013-05-16 09:00 - 01586284 _____ () C:\Windows\WindowsUpdate.log
2014-07-18 08:36 - 2009-07-14 06:34 - 00012688 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-18 08:36 - 2009-07-14 06:34 - 00012688 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-18 08:35 - 2014-07-18 08:33 - 00000000 ____D () C:\AdwCleaner
2014-07-18 08:32 - 2014-07-18 08:32 - 00020400 _____ () C:\Users\Müller-Gulden\Desktop\mbam.txt
2014-07-18 08:29 - 2013-05-16 09:30 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-18 08:22 - 2014-07-16 12:45 - 00000000 ____D () C:\Program Files\A7F8482B-1D99-4EC9-B887-8B130AB7E131
2014-07-18 08:04 - 2014-07-18 08:04 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-18 08:04 - 2014-07-18 08:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-18 08:04 - 2014-07-18 08:04 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-18 08:04 - 2014-07-18 08:04 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-18 07:58 - 2014-07-18 07:58 - 01016261 _____ (Thisisu) C:\Users\Müller-Gulden\Downloads\JRT.exe
2014-07-18 07:58 - 2014-07-18 07:57 - 01354223 _____ () C:\Users\Müller-Gulden\Downloads\adwcleaner_3.216.exe
2014-07-18 07:56 - 2014-07-18 07:56 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Müller-Gulden\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-18 07:12 - 2014-07-16 13:02 - 00000000 ____D () C:\ProgramData\MFAData
2014-07-17 14:12 - 2014-07-17 14:12 - 00019195 _____ () C:\ComboFix.txt
2014-07-17 14:12 - 2014-07-17 13:44 - 00000000 ____D () C:\Qoobox
2014-07-17 14:12 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2014-07-17 14:12 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-07-17 14:11 - 2014-07-17 13:43 - 00000000 ____D () C:\Windows\erdnt
2014-07-17 14:07 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2014-07-17 13:46 - 2014-07-17 13:46 - 00013362 _____ () C:\Users\Müller-Gulden\Desktop\ComboFix - Verknüpfung.lnk
2014-07-17 13:42 - 2014-07-17 13:42 - 05222061 ____R (Swearware) C:\Users\Müller-Gulden\Downloads\ComboFix.exe
2014-07-17 13:39 - 2014-07-17 13:39 - 00000000 ____D () C:\Users\Müller-Gulden\AppData\Local\AVG Web TuneUp
2014-07-17 13:38 - 2014-07-17 13:38 - 00000000 ____D () C:\ProgramData\AVG Web TuneUp
2014-07-17 13:38 - 2014-07-17 13:38 - 00000000 ____D () C:\Program Files\AVG Web TuneUp
2014-07-17 13:37 - 2014-07-17 13:38 - 00042784 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys
2014-07-17 12:56 - 2014-07-17 12:56 - 00002733 _____ () C:\Users\Müller-Gulden\Desktop\gmer.txt
2014-07-17 12:41 - 2014-07-17 12:41 - 00380416 _____ () C:\Users\Müller-Gulden\Downloads\Gmer-19357.exe
2014-07-17 12:36 - 2014-07-17 12:36 - 00000488 _____ () C:\Users\Müller-Gulden\Downloads\defogger_disable.log
2014-07-17 12:36 - 2014-07-17 12:36 - 00000000 _____ () C:\Users\Müller-Gulden\defogger_reenable
2014-07-17 12:35 - 2014-07-17 12:35 - 00050477 _____ () C:\Users\Müller-Gulden\Downloads\Defogger.exe
2014-07-17 12:34 - 2014-07-17 12:33 - 01075776 _____ (OR Interactive Ltd) C:\Users\Müller-Gulden\Downloads\IDM2.exe
2014-07-17 12:30 - 2014-07-17 12:27 - 00022319 _____ () C:\Users\Müller-Gulden\Downloads\Addition.txt
2014-07-17 12:24 - 2014-07-17 12:24 - 01077248 _____ (Farbar) C:\Users\Müller-Gulden\Downloads\FRST.exe
2014-07-16 13:39 - 2014-05-08 13:56 - 00000000 ____D () C:\Users\Müller-Gulden\Downloads\club
2014-07-16 13:37 - 2013-09-25 08:27 - 00000000 ____D () C:\Users\Müller-Gulden\Desktop\Prospekte
2014-07-16 13:27 - 2014-07-16 12:44 - 00000000 ____D () C:\Program Files\005
2014-07-16 13:11 - 2014-07-16 13:02 - 00000000 ____D () C:\Users\Müller-Gulden\AppData\Local\Avg2014
2014-07-16 13:08 - 2014-07-16 13:05 - 00000000 ____D () C:\ProgramData\AVG2014
2014-07-16 13:07 - 2014-07-16 13:07 - 00000000 ____D () C:\Users\Müller-Gulden\AppData\Roaming\AVG2014
2014-07-16 13:06 - 2014-07-16 13:06 - 00000955 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-07-16 13:06 - 2014-07-16 13:06 - 00000000 ____D () C:\Users\Müller-Gulden\AppData\Roaming\TuneUp Software
2014-07-16 13:06 - 2014-07-16 13:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-07-16 13:05 - 2014-07-16 13:05 - 00000000 ____D () C:\Program Files\AVG
2014-07-16 13:05 - 2014-07-16 13:05 - 00000000 ____D () C:\$AVG
2014-07-16 13:02 - 2014-07-16 13:02 - 04424232 _____ (AVG Technologies) C:\Users\Müller-Gulden\Downloads\avg_avct_stb_all_2014_4116_comppg_24.exe
2014-07-16 13:02 - 2014-07-16 13:02 - 00000000 ____D () C:\Users\Müller-Gulden\AppData\Local\MFAData
2014-07-16 13:02 - 2013-05-16 09:31 - 00002193 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-16 12:54 - 2013-09-18 12:51 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-07-16 12:54 - 2013-09-18 12:51 - 00001105 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-07-16 12:54 - 2013-05-16 09:28 - 00001409 _____ () C:\Users\Müller-Gulden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-07-15 09:53 - 2014-07-09 15:58 - 00182003 _____ () C:\Users\Müller-Gulden\Documents\Preisliste 2014.ods
2014-07-14 10:28 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-07-10 21:40 - 2014-07-10 21:40 - 00031744 _____ (NetFilterSDK.com) C:\Windows\system32\Drivers\netfilter.sys
2014-07-10 15:53 - 2009-07-14 06:33 - 00293144 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-10 15:52 - 2009-07-14 10:56 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-09 14:34 - 2014-07-09 14:34 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-07-09 14:34 - 2014-07-09 14:34 - 00000000 ____D () C:\ACCA
2014-07-09 14:29 - 2014-07-09 14:28 - 70104576 _____ (ACCA) C:\Users\Müller-Gulden\Downloads\nw_25322_primusvaenexe.exe
2014-07-08 14:05 - 2014-07-08 14:05 - 00000000 __SHD () C:\Users\Müller-Gulden\AppData\Local\EmieUserList
2014-07-08 14:05 - 2014-07-08 14:05 - 00000000 __SHD () C:\Users\Müller-Gulden\AppData\Local\EmieSiteList
2014-07-08 12:31 - 2013-09-18 12:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-06-30 12:43 - 2014-06-30 12:43 - 00121624 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgdiskx.sys
2014-06-20 21:39 - 2014-07-09 13:47 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-06-19 02:16 - 2014-07-09 13:46 - 17276416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-19 01:56 - 2014-07-09 13:47 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-19 01:56 - 2014-07-09 13:46 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-19 01:38 - 2014-07-09 13:46 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-19 01:37 - 2014-07-09 13:46 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-19 01:36 - 2014-07-09 13:47 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-19 01:35 - 2014-07-09 13:46 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-06-19 01:32 - 2014-07-09 13:46 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-19 01:28 - 2014-07-09 13:47 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-19 01:28 - 2014-07-09 13:47 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-19 01:25 - 2014-07-09 13:46 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-19 01:23 - 2014-07-09 13:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-19 01:23 - 2014-07-09 13:47 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-19 01:22 - 2014-07-09 13:46 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-19 01:16 - 2014-07-09 13:47 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-19 01:12 - 2014-07-09 13:47 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-19 01:06 - 2014-07-09 13:47 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-19 01:01 - 2014-07-09 13:46 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-19 00:59 - 2014-07-09 13:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-19 00:58 - 2014-07-09 13:46 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-19 00:52 - 2014-07-09 13:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-19 00:52 - 2014-07-09 13:46 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-19 00:49 - 2014-07-09 13:47 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-19 00:46 - 2014-07-09 13:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-19 00:45 - 2014-07-09 13:46 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-19 00:35 - 2014-07-09 13:46 - 11742208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-19 00:13 - 2014-07-09 13:46 - 01791488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-19 00:09 - 2014-07-09 13:47 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-19 00:07 - 2014-07-09 13:47 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-18 03:51 - 2014-07-09 13:46 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-06-18 02:52 - 2014-07-09 13:46 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
Some content of TEMP:
====================
C:\Users\Müller-Gulden\AppData\Local\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-08 12:57
==================== End Of Log ============================ --- --- --- |