Hier sämtliche Scans:
Malwarebytes Anti-Malware: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 29.08.2014
Suchlauf-Zeit: 21:25:15
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.08.29.05
Rootkit Datenbank: v2014.08.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: ***
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 404429
Verstrichene Zeit: 8 Min, 45 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1896, Löschen bei Neustart, [4118f7d51566fe38a5779d1288796a96]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 16
PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, In Quarantäne, [4118f7d51566fe38a5779d1288796a96],
PUP.Optional.WindowsProtectManger.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WindowsMangerProtect, In Quarantäne, [4118f7d51566fe38a5779d1288796a96],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [2039d5f7abd090a66530fe7cca38956b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [2039d5f7abd090a66530fe7cca38956b],
PUP.Optional.SupTab.A, HKU\S-1-5-21-461601121-2454032722-3572995621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [2039d5f7abd090a66530fe7cca38956b],
PUP.Optional.SupTab.A, HKU\S-1-5-21-461601121-2454032722-3572995621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [2039d5f7abd090a66530fe7cca38956b],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [0752626ab2c93bfbfef4c578f70d6898],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [045525a73744b28498d4fe540103ce32],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, In Quarantäne, [4514745890ebbe7835d78f5dc63c2cd4],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, In Quarantäne, [1f3a5c706e0de65088f441ceaa595ea2],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [8acf5f6dd1aac3730ce6a499679dce32],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP, In Quarantäne, [aeabb319e9921422983fba3137cb24dc],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, In Quarantäne, [2237309cafccbb7b75967c70c240ae52],
PUP.Optional.WebSearches.A, HKU\S-1-5-21-461601121-2454032722-3572995621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SupHpUISoft, In Quarantäne, [d089ae1e611a1224c1082fbe857df907],
PUP.Optional.Qone8, HKU\S-1-5-21-461601121-2454032722-3572995621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [bb9eac20601bd95d4fa2d26ba06444bc],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\webssearches uninstall, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
Registrierungswerte: 4
PUP.Optional.FastStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com, In Quarantäne, [99c085477dfe5dd98103b39e838116ea]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\SupTab, In Quarantäne, [aeabb319e9921422983fba3137cb24dc]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, irs, In Quarantäne, [2237309cafccbb7b75967c70c240ae52]
PUP.Optional.FastStart.A, HKU\S-1-5-21-461601121-2454032722-3572995621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, In Quarantäne, [3b1e408c85f6b383c0cc43b4659d20e0]
Registrierungsdaten: 8
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "D:\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1409168539&from=irs&uid=ST9750420AS_5WS2DTNAXXXX5WS2DTNA, Gut: (firefox.exe), Schlecht: ("D:\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1409168539&from=irs&uid=ST9750420AS_5WS2DTNAXXXX5WS2DTNA),Ersetzt,[5ffa18b4710af0462b7aeeecc53fa858]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1409168539&from=irs&uid=ST9750420AS_5WS2DTNAXXXX5WS2DTNA, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1409168539&from=irs&uid=ST9750420AS_5WS2DTNAXXXX5WS2DTNA),Ersetzt,[fb5e7a52215ab185f6a9c6142ada50b0]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[62f7f4d8dba044f2dcf07d675ea6b34d]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "D:\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1409168539&from=irs&uid=ST9750420AS_5WS2DTNAXXXX5WS2DTNA, Gut: (firefox.exe), Schlecht: ("D:\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1409168539&from=irs&uid=ST9750420AS_5WS2DTNAXXXX5WS2DTNA),Ersetzt,[c099e9e32457ed49d7ce8e4cfd0735cb]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1409168539&from=irs&uid=ST9750420AS_5WS2DTNAXXXX5WS2DTNA&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1409168539&from=irs&uid=ST9750420AS_5WS2DTNAXXXX5WS2DTNA&q={searchTerms}),Ersetzt,[c990fdcf0576c274633a00da13f1c33d]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1409168539&from=irs&uid=ST9750420AS_5WS2DTNAXXXX5WS2DTNA, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1409168539&from=irs&uid=ST9750420AS_5WS2DTNAXXXX5WS2DTNA),Ersetzt,[6ced369642393ef8a3f87c5e8e76e61a]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1409168539&from=irs&uid=ST9750420AS_5WS2DTNAXXXX5WS2DTNA, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1409168539&from=irs&uid=ST9750420AS_5WS2DTNAXXXX5WS2DTNA),Ersetzt,[75e4ece03a4176c0cdd2ba20a85c26da]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[a2b7c507afcce84e5f6d8e563ec6837d]
Ordner: 65
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\code, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\include, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\include\tools, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\js\lib, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\js\module, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\js\pack, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\en, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\en-US, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\es, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\es-419, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\fr, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\fr-BE, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\fr-CA, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\fr-CH, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\fr-LU, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\it, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\it-CH, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\pl, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\pt-BR, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\ru, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\ru-MO, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\tr, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\vi, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\zh-CN, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\zh-TW, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\skin, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\defaults, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\defaults\preferences, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\modules, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Löschen bei Neustart, [085156767605b68017ffb5260af8c13f],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, In Quarantäne, [085156767605b68017ffb5260af8c13f],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [085156767605b68017ffb5260af8c13f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
Dateien: 155
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Löschen bei Neustart, [4118f7d51566fe38a5779d1288796a96],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, In Quarantäne, [2039d5f7abd090a66530fe7cca38956b],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\242.json, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\MessageBox.xml, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\un.ini, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\uninstallDlg2.xml, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\UninstallManager.exe, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\bg.png, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\bg1.png, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\bk_shadow.png, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\button.png, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\button1.png, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\checkbox.png, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\checkbox_select.png, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\checked.png, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\close.png, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\loading_bg.png, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\loading_light.png, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\min.png, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\scrollbar.bmp, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\Thumbs.db, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\unchecked.png, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\code\code1.jpg, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\code\code2.jpg, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\code\code3.jpg, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\code\code4.jpg, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\code\code5.jpg, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\code\code6.jpg, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.WebsSearches.A, C:\Users\***\AppData\Roaming\webssearches\images\code\Thumbs.db, In Quarantäne, [1742cc00e7943afc3850b6138f73bb45],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome.manifest, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\install.rdf, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\index.html, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\quick_start.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\quick_start.xul, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\include\speed_dial.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\include\tools\about_blank_hook.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\include\tools\misc.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\include\tools\popup_image_helper.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\include\tools\urlrequestor.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\js\js.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\js\lib\doT.min.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\js\lib\jquery-2.1.0.min.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\js\lib\jquery.autocomplete.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\js\module\hotSearch.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\js\module\mostgrid.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\js\module\search.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\js\module\stat.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\js\pack\common.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\js\pack\ga.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\content\js\pack\xagainit.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\en\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\en-US\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\es\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\es-419\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\fr\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\fr-BE\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\fr-CA\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\fr-CH\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\fr-LU\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\it\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\it-CH\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\pl\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\pt-BR\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\ru\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\ru-MO\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\tr\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\vi\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\zh-CN\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\locale\zh-TW\locale.properties, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\skin\default_logo.png, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\skin\googlelogo.png, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\skin\google_trends.png, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\skin\icon.png, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\skin\loading.gif, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\skin\logo.png, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\skin\newtab.ico, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\skin\simple.css, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\chrome\skin\style.css, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\defaults\preferences\fvd.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\defaults\preferences\preferences.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\modules\addonmanager.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\modules\aes.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\modules\config.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\modules\dialogs.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\modules\last_tab.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\modules\misc.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\modules\properties.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\modules\remoterequest.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\modules\restoreprefs.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.FastStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\extensions\faststartff@gmail.com\modules\settings.js, In Quarantäne, [ea6f87452d4ec86ebe17fbdebc467a86],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-08-27[21-42-45-683].log, In Quarantäne, [085156767605b68017ffb5260af8c13f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\HpUI.exe, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\Loader32.exe, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\Loader64.exe, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\RSHP.exe, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupIePluginServiceUpdate.exe, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll64.dll, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\bk_shadow.png, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\btn.png, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\close.png, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml.bak, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\ck_box.png, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\ck_check.png, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\radio_bk.png, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\image\radio_check.png, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit-ie8.js, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit2.0.js, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, In Quarantäne, [85d403c93d3ecd695ada23bed52df20e],
PUP.Optional.QuickStart.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");), Ersetzt,[6aefc9039ae1f04652f7987d10f5af51]
Physische Sektoren: 0
(No malicious items detected)
(end) AdwCleaner: Code:
# AdwCleaner v3.308 - Bericht erstellt am 29/08/2014 um 21:47:44
# Aktualisiert 20/08/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : *** - BLACK-STEALTH
# Gestartet von : C:\Users\***\Desktop\adwcleaner_3.308.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\NeeXtuCouep
Ordner Gelöscht : C:\Program Files (x86)\GetPrivate
Ordner Gelöscht : C:\Program Files (x86)\NeeXtuCouep
Ordner Gelöscht : C:\Users\***\AppData\Roaming\GetPrivate
Ordner Gelöscht : C:\Users\***\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\cknebhggccemgcnbidipinkifmmegdel
Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\cknebhggccemgcnbidipinkifmmegdel
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Programme\Internet Explorer (64-bit).lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Programme\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Programme\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Programme\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\***\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\***\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17239
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v31.0 (x86 de)
[ Datei : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\prefs.js ]
Zeile gelöscht : user_pref("extensions.quick_start.enable_search1", false);
Zeile gelöscht : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [5359 octets] - [26/05/2014 19:45:30]
AdwCleaner[R1].txt - [4391 octets] - [29/08/2014 21:44:57]
AdwCleaner[S0].txt - [5262 octets] - [26/05/2014 19:46:47]
AdwCleaner[S1].txt - [3391 octets] - [29/08/2014 21:47:44]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [3451 octets] ########## JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Professional x64
Ran by Sven on 29.08.2014 at 22:02:13,95
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.08.2014 at 22:05:14,90
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-08-2014
Ran by *** (administrator) on BLACK-STEALTH on 29-08-2014 22:12:42
Running from C:\Users\***\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(AVAST Software) D:\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files (x86)\AAVUpdateManager\aavus.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(CyberLink) D:\PowerDVD13\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe
(CyberLink) D:\PowerDVD13\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe
(DVBLogic) D:\DVBLogic\DVBLink2\DVBLinkServer.exe
(Hauppauge Computer Works) D:\WinTV\TVServer\HauppaugeTVServer.exe
(ASUS) C:\Program Files\P4G\BatteryLife.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Nero AG) D:\Nero 8\Nero BackItUp\NBService.exe
(Prolific Technology Inc.) C:\Windows\SysWOW64\IoctlSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
() D:\1&1 Surf-Stick\AssistantServices.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Apple Inc.) D:\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) D:\Apple\Internet Services\ApplePhotoStreams.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Windows (R) Win 7 DDK provider) C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
(Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe
(AVAST Software) D:\Avast\avastui.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(Apple Inc.) D:\iTunes\iTunesHelper.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Apple Inc.) D:\Apple\Internet Services\APSDaemon.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2392360 2010-10-08] (Synaptics Incorporated)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [THXCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64
HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [92968 2010-10-08] (Synaptics Incorporated)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8292120 2013-11-14] (Logitech Inc.)
HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [403688 2012-06-28] (Acronis)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11075176 2010-07-22] (Realtek Semiconductor)
HKLM-x32\...\Run: [FLxHCIm] => C:\Program Files\Fresco Logic Inc\Fresco Logic USB3.0 Host Controller\host\FLxHCIm.exe [40448 2011-01-21] (Windows (R) Win 7 DDK provider)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-23] ()
HKLM-x32\...\Run: [THX TruStudio NB Settings] => C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [907776 2011-01-28] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [5993216 2012-06-28] (Acronis)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [AcronisTimounterMonitor] => C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe [1173712 2012-06-28] (Acronis)
HKLM-x32\...\Run: [AvastUI.exe] => D:\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2014-06-16] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4513792 2014-05-22] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrHelp] => C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe [2009088 2013-01-18] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => D:\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
HKU\S-1-5-21-461601121-2454032722-3572995621-1000\...\Run: [iCloudServices] => D:\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-461601121-2454032722-3572995621-1000\...\Run: [ApplePhotoStreams] => D:\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-461601121-2454032722-3572995621-1005\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-461601121-2454032722-3572995621-1005\...\Run: [iCloudServices] => D:\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-461601121-2454032722-3572995621-1005\...\Run: [ApplePhotoStreams] => D:\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-461601121-2454032722-3572995621-1005\...\MountPoints2: {7885fa50-2fc3-11e1-af67-806e6f6e6963} - I:\InstAll.exe
HKU\S-1-5-21-461601121-2454032722-3572995621-1005\...\MountPoints2: {8225242e-384b-11e1-b1f7-74f06dbf1989} - K:\Setup\rsrc\Autorun.exe
HKU\S-1-5-21-461601121-2454032722-3572995621-1005\...\MountPoints2: {877fa340-2fe9-11e1-8ae5-806e6f6e6963} - J:\Autoplay.exe -auto
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => D:\Avast\ashShA64.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.tt-lan.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xC179616C8CD8CD01
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> D:\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> D:\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724
FF Homepage: hxxp://flyspray.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll ()
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> D:\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=11.20.2 -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.20.2 -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> D:\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> D:\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> D:\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> D:\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> D:\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Extension: YouTube Unblocker - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\Extensions\youtubeunblocker@unblocker.yt [2014-05-20]
FF Extension: Ghostery - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\Extensions\firefox@ghostery.com.xpi [2014-06-02]
FF Extension: CookieCuller - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\Extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}.xpi [2014-06-02]
FF Extension: DownThemAll! - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8k2w2jkw.default-1400622986724\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2014-05-20]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - D:\Avast\WebRep\FF
FF Extension: avast! Online Security - D:\Avast\WebRep\FF [2011-12-26]
FF HKCU\...\Firefox\Extensions: [jid1-VZC3jSUSB1KxYw@jetpack] - C:\Users\***\AppData\Roaming\Steam\jid1-VZC3jSUSB1KxYw@jetpack
FF Extension: skype_addon - C:\Users\***\AppData\Roaming\Steam\jid1-VZC3jSUSB1KxYw@jetpack [2012-02-18]
FF StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR Profile: C:\Users\***\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\caghfdecfohghebhagkkijpkomohkmfm [2014-05-18]
CHR Extension: (No Name) - C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\llhdpmoidjebhjmdgeobfkeipaegeaak [2014-05-18]
CHR HKCU\...\Chrome\Extension: [bofpgnmdjnpjpegclhggphjeladaklnf] - C:\Users\***\AppData\Roaming\Steam\bofpgnmdjnpjpegclhggphjeladaklnf.crx [2012-02-02]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - D:\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-13]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AAV UpdateService; C:\Program Files (x86)\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 avast! Antivirus; D:\Avast\AvastSvc.exe [50344 2014-07-13] (AVAST Software)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112 2013-09-25] (Brother Industries, Ltd.) [File not signed]
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2011-12-26] (Creative Labs) [File not signed]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2011-12-26] (Creative Labs) [File not signed]
R2 CyberLink PowerDVD 13 Media Server Monitor Service; D:\PowerDVD13\PowerDVD13\Kernel\DMS\CLMSMonitorServicePDVD13.exe [77576 2013-03-20] (CyberLink)
R2 CyberLink PowerDVD 13 Media Server Service; D:\PowerDVD13\PowerDVD13\Kernel\DMS\CLMSServerPDVD13.exe [323336 2013-03-20] (CyberLink)
R2 DVBLinkServer2; D:\DVBLogic\DVBLink2\DVBLinkServer.exe [1991680 2010-10-21] (DVBLogic) [File not signed]
R2 HauppaugeTVServer; D:\WinTV\TVServer\HauppaugeTVServer.exe [570368 2011-10-27] (Hauppauge Computer Works) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 Nero BackItUp Scheduler 3; D:\Nero 8\Nero BackItUp\NBService.exe [877864 2008-12-02] (Nero AG)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [537896 2008-12-12] (Nero AG)
R2 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [File not signed]
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2013-09-19] ()
R2 UI Assistant Service; D:\1&1 Surf-Stick\AssistantServices.exe [253264 2010-12-08] ()
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-13] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-13] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-13] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-13] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-07-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-13] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-13] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-13] ()
S3 CdaC15BA; C:\Windows\SysWOW64\drivers\CDAC15BA.SYS [8864 2012-12-22] () [File not signed]
S3 CYDTV_SRV; C:\Windows\System32\drivers\cydtv.sys [576480 2010-07-13] ( )
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [279616 2012-01-06] (DT Soft Ltd)
R3 dvblinkcap; C:\Windows\System32\DRIVERS\dvblinkcap.sys [18608 2010-07-19] (DVBLink)
R3 dvblinkcap2; C:\Windows\System32\DRIVERS\dvblinkcap2.sys [18608 2010-07-19] (DVBLink)
R3 dvblinkcap3; C:\Windows\System32\DRIVERS\dvblinkcap3.sys [18608 2010-07-19] (DVBLink)
R3 dvblinkcap4; C:\Windows\System32\DRIVERS\dvblinkcap4.sys [18608 2010-07-19] (DVBLink)
R3 dvblinktun; C:\Windows\System32\DRIVERS\dvblinktun.sys [20784 2010-07-19] (DVBLink)
R3 dvblinktun2; C:\Windows\System32\DRIVERS\dvblinktun2.sys [20784 2010-07-19] (DVBLink)
R3 dvblinktun3; C:\Windows\System32\DRIVERS\dvblinktun3.sys [20784 2010-07-19] (DVBLink)
R3 dvblinktun4; C:\Windows\System32\DRIVERS\dvblinktun4.sys [20784 2010-07-19] (DVBLink)
R3 FLxHCIh; C:\Windows\System32\DRIVERS\FLxHCIh.sys [50176 2011-01-21] (Fresco Logic)
S3 hcw17bda; C:\Windows\System32\drivers\hcw17bda.sys [67456 2010-01-27] (Hauppauge Computer Works, Inc.)
S4 ithsgt; C:\Windows\SysWOW64\DRIVERS\ithsgt.sys [162432 2012-08-16] () [File not signed]
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S2 lilsgt; C:\Windows\System32\DRIVERS\lilsgt.sys [21504 2012-08-16] () [File not signed]
S2 lilsgt; C:\Windows\SysWOW64\DRIVERS\lilsgt.sys [12032 2012-08-16] () [File not signed]
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-29] (Malwarebytes Corporation)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-08-10] (Corel Corporation)
R3 ROCKEYNT; C:\Windows\System32\DRIVERS\Rockey4.sys [31784 2012-03-29] (Feitian Technologies Co., Ltd.)
S3 Rockey_USB; C:\Windows\System32\DRIVERS\Rockey4USB.sys [22696 2012-03-29] (Feitian Technologies Co., Ltd.)
S3 SaiH5F0D; C:\Windows\System32\DRIVERS\SaiH5F0D.sys [171144 2007-05-01] (Saitek)
S3 SaiU5F0D; C:\Windows\System32\DRIVERS\SaiU5F0D.sys [34304 2007-05-01] (Saitek)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [530488 2011-12-26] () [File not signed]
S3 TTUSB2BDA_NTAMD64; C:\Windows\System32\DRIVERS\ttusb2bda_amd64.sys [737312 2008-12-16] (TechnoTrend GmbH)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-16] ()
R2 {09F57980-3432-4AFC-957D-27AC45FAE1F5}; D:\PowerDVD13\PowerDVD13\Common\NavFilter\000.fcl [130320 2013-03-19] (CyberLink Corp.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cleanhlp; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-29 22:12 - 2014-08-29 22:12 - 00000000 ____D () C:\Users\***\Desktop\FRST-OlderVersion
2014-08-29 22:05 - 2014-08-29 22:05 - 00000647 _____ () C:\Users\***\Desktop\JRT.txt
2014-08-29 21:53 - 2014-08-29 21:53 - 00003528 _____ () C:\Users\***\Desktop\AdwCleaner[S1].txt
2014-08-29 21:42 - 2014-08-29 21:44 - 00045457 _____ () C:\Users\***\Desktop\mbam.txt
2014-08-29 21:23 - 2014-08-29 21:41 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-29 21:23 - 2014-08-29 21:23 - 00001076 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-29 21:23 - 2014-08-29 21:23 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-29 21:23 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-29 21:23 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-29 21:23 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-29 21:20 - 2014-04-06 08:36 - 01016261 _____ (Thisisu) C:\Users\***\Desktop\JRT.exe
2014-08-29 21:19 - 2014-08-29 21:19 - 01364531 _____ () C:\Users\***\Desktop\adwcleaner_3.308.exe
2014-08-28 21:42 - 2014-08-29 21:42 - 00070144 _____ () C:\Windows\SysWOW64\tasks.dll
2014-08-28 19:24 - 2014-08-28 19:24 - 00075409 _____ () C:\Users\***\Desktop\ComboFix.txt
2014-08-28 19:19 - 2014-08-28 19:19 - 00075489 _____ () C:\ComboFix.txt
2014-08-28 18:02 - 2014-08-28 19:19 - 00000000 ____D () C:\ComboFix
2014-08-28 18:00 - 2014-08-28 06:15 - 05574834 ____R (Swearware) C:\Users\***\Desktop\ComboFix.exe
2014-08-27 22:28 - 2014-08-27 22:28 - 00003185 _____ () C:\Users\***\Desktop\Gmer.rar
2014-08-27 22:16 - 2014-08-27 22:16 - 00028975 _____ () C:\Users\***\Desktop\Gmer.txt
2014-08-27 21:54 - 2014-08-29 22:12 - 00022885 _____ () C:\Users\***\Desktop\FRST.txt
2014-08-27 21:54 - 2014-08-29 22:12 - 00000000 ____D () C:\FRST
2014-08-27 21:54 - 2014-08-27 22:04 - 00049612 _____ () C:\Users\***\Desktop\Addition.txt
2014-08-27 21:51 - 2014-08-27 21:51 - 00380416 _____ () C:\Users\***\Desktop\ghjp30nj.exe
2014-08-27 21:50 - 2014-08-29 22:12 - 02103808 _____ (Farbar) C:\Users\***\Desktop\FRST64.exe
2014-08-27 21:42 - 2014-08-27 21:42 - 00003264 _____ () C:\Windows\System32\Tasks\GPUP
2014-08-27 20:59 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-27 20:59 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-27 20:59 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-26 23:33 - 2014-08-26 23:33 - 00319912 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-26 23:33 - 2014-08-26 23:33 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-26 23:33 - 2014-08-26 23:33 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-26 23:33 - 2014-08-26 23:33 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-08-26 23:33 - 2014-08-26 23:33 - 00000000 ____D () C:\Program Files\Java
2014-08-24 17:37 - 2014-08-24 17:37 - 00000000 ____D () C:\Users\***\AppData\Local\Sony Online Entertainment
2014-08-22 18:57 - 2014-08-22 18:58 - 00000000 ____D () C:\Users\***\AppData\Roaming\Kalypso Media
2014-08-22 18:54 - 2014-08-22 18:54 - 00001533 _____ () C:\Users\Public\Desktop\DUNGEONS Game of the Year edition.lnk
2014-08-22 18:22 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-22 18:22 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-22 18:22 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-22 18:22 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-22 18:22 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-22 18:22 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-22 18:22 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-08-22 18:22 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-22 18:22 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-22 18:22 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-22 18:22 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-22 18:22 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-22 18:22 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-22 18:22 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-08-21 15:37 - 2014-08-21 15:37 - 00002477 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-08-21 15:37 - 2014-08-21 15:37 - 00000000 ____D () C:\Users\***\AppData\Local\Skype
2014-08-21 15:02 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-21 15:02 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-21 15:02 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-21 15:02 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-21 15:02 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-21 15:02 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-21 15:02 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-21 15:02 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-21 15:01 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-21 15:01 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-21 15:01 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-21 15:01 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-21 15:01 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-21 15:01 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-21 15:01 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-21 15:01 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-21 15:01 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-21 15:01 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-21 15:01 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-21 15:01 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-21 15:01 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-21 15:01 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-21 15:01 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-21 15:01 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-21 15:01 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-21 15:01 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-21 15:01 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-21 15:01 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-21 15:01 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-21 15:01 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-21 15:01 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-21 15:01 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-21 15:01 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-21 15:01 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-21 15:01 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-21 15:01 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-21 15:01 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-21 15:01 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-21 15:01 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-21 15:01 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-21 15:01 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-21 15:01 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-21 15:01 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-21 15:01 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-21 15:01 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-21 15:01 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-21 15:01 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-21 15:01 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-21 15:01 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-21 15:01 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-21 15:01 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-21 15:01 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-21 15:01 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-21 15:01 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-21 15:01 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-21 15:01 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-21 15:01 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-21 15:01 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-21 15:01 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-21 15:01 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-21 15:01 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-21 15:01 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-21 15:01 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-21 15:01 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-21 15:01 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-21 15:01 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-21 15:01 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-21 15:01 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-21 15:01 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-21 15:01 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-21 15:01 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-21 15:01 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-21 15:01 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-21 15:00 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-21 15:00 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-21 15:00 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-21 15:00 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-21 15:00 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-21 10:36 - 2014-08-21 10:36 - 00000000 ____D () C:\Program Files\iTunes
2014-08-21 10:36 - 2014-08-21 10:36 - 00000000 ____D () C:\Program Files\iPod
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-29 22:13 - 2014-08-27 21:54 - 00022885 _____ () C:\Users\***\Desktop\FRST.txt
2014-08-29 22:12 - 2014-08-29 22:12 - 00000000 ____D () C:\Users\***\Desktop\FRST-OlderVersion
2014-08-29 22:12 - 2014-08-27 21:54 - 00000000 ____D () C:\FRST
2014-08-29 22:12 - 2014-08-27 21:50 - 02103808 _____ (Farbar) C:\Users\***\Desktop\FRST64.exe
2014-08-29 22:07 - 2014-05-24 20:11 - 00007205 _____ () C:\Windows\setupact.log
2014-08-29 22:07 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-29 22:06 - 2011-12-26 15:25 - 01857003 _____ () C:\Windows\WindowsUpdate.log
2014-08-29 22:06 - 2009-07-14 06:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-29 22:06 - 2009-07-14 06:45 - 00021872 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-29 22:05 - 2014-08-29 22:05 - 00000647 _____ () C:\Users\***\Desktop\JRT.txt
2014-08-29 21:53 - 2014-08-29 21:53 - 00003528 _____ () C:\Users\***\Desktop\AdwCleaner[S1].txt
2014-08-29 21:52 - 2012-07-09 17:33 - 00004124 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-08-29 21:49 - 2014-05-24 20:57 - 00115574 _____ () C:\Windows\PFRO.log
2014-08-29 21:47 - 2014-05-26 19:45 - 00000000 ____D () C:\AdwCleaner
2014-08-29 21:47 - 2013-11-12 21:44 - 00000967 _____ () C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-29 21:47 - 2012-05-05 17:43 - 00000000 ___RD () C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Programme
2014-08-29 21:44 - 2014-08-29 21:42 - 00045457 _____ () C:\Users\***\Desktop\mbam.txt
2014-08-29 21:42 - 2014-08-28 21:42 - 00070144 _____ () C:\Windows\SysWOW64\tasks.dll
2014-08-29 21:41 - 2014-08-29 21:23 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-29 21:36 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Branding
2014-08-29 21:25 - 2014-06-29 00:05 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-29 21:23 - 2014-08-29 21:23 - 00001076 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-29 21:23 - 2014-08-29 21:23 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-29 21:19 - 2014-08-29 21:19 - 01364531 _____ () C:\Users\***\Desktop\adwcleaner_3.308.exe
2014-08-28 19:24 - 2014-08-28 19:24 - 00075409 _____ () C:\Users\***\Desktop\ComboFix.txt
2014-08-28 19:24 - 2011-12-26 15:38 - 00000000 ____D () C:\Users\***
2014-08-28 19:19 - 2014-08-28 19:19 - 00075489 _____ () C:\ComboFix.txt
2014-08-28 19:19 - 2014-08-28 18:02 - 00000000 ____D () C:\ComboFix
2014-08-28 19:19 - 2014-05-24 20:26 - 00000000 ____D () C:\Qoobox
2014-08-28 19:17 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-08-28 18:52 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-08-28 18:14 - 2009-07-14 04:34 - 86245376 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-08-28 18:14 - 2009-07-14 04:34 - 26476544 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-08-28 18:14 - 2009-07-14 04:34 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-08-28 18:14 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-08-28 18:14 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-08-28 18:13 - 2014-05-24 20:26 - 00000000 ____D () C:\Windows\erdnt
2014-08-28 18:01 - 2011-04-12 09:43 - 00699682 _____ () C:\Windows\system32\perfh007.dat
2014-08-28 18:01 - 2011-04-12 09:43 - 00149790 _____ () C:\Windows\system32\perfc007.dat
2014-08-28 18:01 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-28 06:15 - 2014-08-28 18:00 - 05574834 ____R (Swearware) C:\Users\***\Desktop\ComboFix.exe
2014-08-27 22:28 - 2014-08-27 22:28 - 00003185 _____ () C:\Users\***\Desktop\Gmer.rar
2014-08-27 22:16 - 2014-08-27 22:16 - 00028975 _____ () C:\Users\***\Desktop\Gmer.txt
2014-08-27 22:04 - 2014-08-27 21:54 - 00049612 _____ () C:\Users\***\Desktop\Addition.txt
2014-08-27 21:51 - 2014-08-27 21:51 - 00380416 _____ () C:\Users\***\Desktop\ghjp30nj.exe
2014-08-27 21:42 - 2014-08-27 21:42 - 00003264 _____ () C:\Windows\System32\Tasks\GPUP
2014-08-27 21:37 - 2013-10-13 02:50 - 00000000 ____D () C:\Users\***\AppData\Local\Battle.net
2014-08-27 21:04 - 2009-07-14 06:45 - 05109560 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-27 18:37 - 2013-08-18 15:49 - 00000000 ____D () C:\Users\***\AppData\Local\20924801-609E-4B66-8071-BE0F0DC8EEC4.aplzod
2014-08-27 18:20 - 2014-03-22 19:43 - 00007891 _____ () C:\Windows\BRRBCOM.INI
2014-08-26 23:33 - 2014-08-26 23:33 - 00319912 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-26 23:33 - 2014-08-26 23:33 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-26 23:33 - 2014-08-26 23:33 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-26 23:33 - 2014-08-26 23:33 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-08-26 23:33 - 2014-08-26 23:33 - 00000000 ____D () C:\Program Files\Java
2014-08-26 23:31 - 2014-07-17 21:01 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-08-26 23:31 - 2014-06-29 01:16 - 00000000 ____D () C:\Program Files (x86)\Java
2014-08-24 17:37 - 2014-08-24 17:37 - 00000000 ____D () C:\Users\***\AppData\Local\Sony Online Entertainment
2014-08-23 04:07 - 2014-08-27 20:59 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 03:45 - 2014-08-27 20:59 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:59 - 2014-08-27 20:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 18:58 - 2014-08-22 18:57 - 00000000 ____D () C:\Users\***\AppData\Roaming\Kalypso Media
2014-08-22 18:54 - 2014-08-22 18:54 - 00001533 _____ () C:\Users\Public\Desktop\DUNGEONS Game of the Year edition.lnk
2014-08-21 16:28 - 2014-03-22 20:22 - 00000000 ____D () C:\Users\***\AppData\Roaming\ControlCenter4
2014-08-21 16:10 - 2011-12-26 19:20 - 00000000 ____D () C:\Users\***\AppData\Roaming\Skype
2014-08-21 15:37 - 2014-08-21 15:37 - 00002477 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-08-21 15:37 - 2014-08-21 15:37 - 00000000 ____D () C:\Users\***\AppData\Local\Skype
2014-08-21 15:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-21 15:07 - 2013-07-10 18:04 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-21 15:05 - 2011-12-26 15:56 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-21 10:36 - 2014-08-21 10:36 - 00000000 ____D () C:\Program Files\iTunes
2014-08-21 10:36 - 2014-08-21 10:36 - 00000000 ____D () C:\Program Files\iPod
2014-08-21 10:31 - 2014-06-29 00:05 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-21 10:31 - 2012-04-01 10:29 - 00699568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-21 10:31 - 2011-12-26 16:55 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-05 09:20 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-04 19:15 - 2011-12-26 19:26 - 00000000 ____D () C:\Users\***\AppData\Roaming\FileZilla
2014-08-03 21:16 - 2012-05-10 22:57 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-08-03 21:16 - 2012-05-10 22:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-08-01 01:41 - 2014-08-21 15:01 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-01 01:16 - 2014-08-21 15:01 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
Some content of TEMP:
====================
C:\Users\***\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-27 20:18
==================== End Of Log ============================ --- --- --- |