mbam Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 05.09.2014
Suchlauf-Zeit: 03:32:06
Logdatei: qqqqqqqqqqq.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.09.04.12
Rootkit Datenbank: v2014.08.21.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: *****
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 322607
Verstrichene Zeit: 20 Min, 41 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\ExtensionUpdaterService.exe, 3772, Löschen bei Neustart, [872563860e6d3df97cffbc6a956e3ac6]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 97
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [d7d562873f3c4cea26ab05af0101c739],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [d7d562873f3c4cea26ab05af0101c739],
PUP.Optional.VBates, HKLM\SOFTWARE\CLASSES\CLSID\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.VBates, HKLM\SOFTWARE\CLASSES\CLSID\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}\INPROCSERVER32, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.VBates, HKLM\SOFTWARE\CLASSES\TYPELIB\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.VBates, HKLM\SOFTWARE\CLASSES\INTERFACE\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.VBates, HKLM\SOFTWARE\CLASSES\Extension.ExtensionHelperObject.1, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.VBates, HKLM\SOFTWARE\CLASSES\Extension.ExtensionHelperObject, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Extension.ExtensionHelperObject, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.VBates, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Extension.ExtensionHelperObject.1, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.VBates, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, Löschen bei Neustart, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.VBates, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, Löschen bei Neustart, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{1824FF90-C98E-48A6-838F-E3B6572B0C77}, In Quarantäne, [cfdd8465d2a971c5cdfdb4c7bd45a45c],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{DD3A66B9-8A7C-4C3C-8D60-DB225A60D69C}, In Quarantäne, [cfdd8465d2a971c5cdfdb4c7bd45a45c],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{881E49A1-8325-4B19-AE6F-B889A40D073A}, In Quarantäne, [cfdd8465d2a971c5cdfdb4c7bd45a45c],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{881E49A1-8325-4B19-AE6F-B889A40D073A}, In Quarantäne, [cfdd8465d2a971c5cdfdb4c7bd45a45c],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{DD3A66B9-8A7C-4C3C-8D60-DB225A60D69C}, In Quarantäne, [cfdd8465d2a971c5cdfdb4c7bd45a45c],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{1824FF90-C98E-48A6-838F-E3B6572B0C77}, In Quarantäne, [cfdd8465d2a971c5cdfdb4c7bd45a45c],
PUP.Optional.BetterSurf.A, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{1824FF90-C98E-48A6-838F-E3B6572B0C77}, Löschen bei Neustart, [cfdd8465d2a971c5cdfdb4c7bd45a45c],
PUP.Optional.BetterSurf.A, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{1824FF90-C98E-48A6-838F-E3B6572B0C77}, Löschen bei Neustart, [cfdd8465d2a971c5cdfdb4c7bd45a45c],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}, In Quarantäne, [4d5f6188b2c9320407810a7d16ecf50b],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\CLASSES\TYPELIB\{A0EE0278-2986-4E5A-884E-A3BF0357E476}, In Quarantäne, [4d5f6188b2c9320407810a7d16ecf50b],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\CLASSES\INTERFACE\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}, In Quarantäne, [4d5f6188b2c9320407810a7d16ecf50b],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}, In Quarantäne, [4d5f6188b2c9320407810a7d16ecf50b],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A0EE0278-2986-4E5A-884E-A3BF0357E476}, In Quarantäne, [4d5f6188b2c9320407810a7d16ecf50b],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}, In Quarantäne, [4d5f6188b2c9320407810a7d16ecf50b],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\CLASSES\Updater.AmiUpd.1, In Quarantäne, [4d5f6188b2c9320407810a7d16ecf50b],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\CLASSES\Updater.AmiUpd, In Quarantäne, [4d5f6188b2c9320407810a7d16ecf50b],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Updater.AmiUpd, In Quarantäne, [4d5f6188b2c9320407810a7d16ecf50b],
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Updater.AmiUpd.1, In Quarantäne, [4d5f6188b2c9320407810a7d16ecf50b],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}, In Quarantäne, [525a3dac5d1e94a202c912690101b050],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{0113A098-06EA-4776-A011-D75590778F1E}, In Quarantäne, [525a3dac5d1e94a202c912690101b050],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{462862BE-9A5C-49A5-9CBD-A649EAC63645}, In Quarantäne, [525a3dac5d1e94a202c912690101b050],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{462862BE-9A5C-49A5-9CBD-A649EAC63645}, In Quarantäne, [525a3dac5d1e94a202c912690101b050],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{0113A098-06EA-4776-A011-D75590778F1E}, In Quarantäne, [525a3dac5d1e94a202c912690101b050],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}, In Quarantäne, [525a3dac5d1e94a202c912690101b050],
PUP.Optional.BetterSurf.A, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}, Löschen bei Neustart, [525a3dac5d1e94a202c912690101b050],
PUP.Optional.BetterSurf.A, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{6E3C6B04-08FE-43BC-8E50-F90285024DEA}, Löschen bei Neustart, [525a3dac5d1e94a202c912690101b050],
PUP.Optional.LyricsAd, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A8720491-9558-4C0D-9E35-30EED15DFB2B}, In Quarantäne, [e8c49b4e592258dea30ff1c2679b5ca4],
PUP.Optional.LyricsAd, HKLM\SOFTWARE\CLASSES\TYPELIB\{5CCB425E-9B88-48B2-919B-393ACC3A0B2C}, In Quarantäne, [e8c49b4e592258dea30ff1c2679b5ca4],
PUP.Optional.LyricsAd, HKLM\SOFTWARE\CLASSES\INTERFACE\{4BF10C25-CFF7-441A-B4AE-FA5A24E35A2D}, In Quarantäne, [e8c49b4e592258dea30ff1c2679b5ca4],
PUP.Optional.LyricsAd, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4BF10C25-CFF7-441A-B4AE-FA5A24E35A2D}, In Quarantäne, [e8c49b4e592258dea30ff1c2679b5ca4],
PUP.Optional.LyricsAd, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{5CCB425E-9B88-48B2-919B-393ACC3A0B2C}, In Quarantäne, [e8c49b4e592258dea30ff1c2679b5ca4],
PUP.Optional.LyricsAd, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A8720491-9558-4C0D-9E35-30EED15DFB2B}, In Quarantäne, [e8c49b4e592258dea30ff1c2679b5ca4],
PUP.Optional.LyricsAd, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A8720491-9558-4C0D-9E35-30EED15DFB2B}, Löschen bei Neustart, [e8c49b4e592258dea30ff1c2679b5ca4],
PUP.Optional.LyricsAd, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A8720491-9558-4C0D-9E35-30EED15DFB2B}, Löschen bei Neustart, [e8c49b4e592258dea30ff1c2679b5ca4],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{D372567D-67C1-4B29-B3F0-159B52B3E967}, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1AD27395-1659-4DFF-A319-2CFA243861A5}, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1AD27395-1659-4DFF-A319-2CFA243861A5}, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{D372567D-67C1-4B29-B3F0-159B52B3E967}, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\CLASSES\YontooIEClient.Api.1, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\CLASSES\YontooIEClient.Api, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\YontooIEClient.Api, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\YontooIEClient.Api.1, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\CLASSES\YontooIEClient.Layers.1, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\CLASSES\YontooIEClient.Layers, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\YontooIEClient.Layers, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\YontooIEClient.Layers.1, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}, Löschen bei Neustart, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.Yontoo.A, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}, Löschen bei Neustart, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, Löschen bei Neustart, [eebe9b4e4932d363d5bc5922639f7d83],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, In Quarantäne, [eebe02e762195ed8d542773e50b21de3],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, In Quarantäne, [e0cc39b07308db5bbb5d2f863dc50ef2],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}, In Quarantäne, [8b21ac3db6c52c0aa903eaca90728b75],
PUP.Optional.VbatesHelper.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\V-bates Updater, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}_is1, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\Iminent, In Quarantäne, [0e9ed514f3885dd9755933f26a996e92],
PUP.Optional.VbatesHelper.A, HKLM\SOFTWARE\V-bates, In Quarantäne, [d5d7c920304b8babff7e45e1887b11ef],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\Iminent, In Quarantäne, [7a326287eb90e74f3504dc74c93b23dd],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\CLASSES\APPID\YontooIEClient.DLL, In Quarantäne, [b1fbc9205c1f3cfa6d2b976bcd368c74],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\DataMngr, In Quarantäne, [3f6dd514e893979fc24da860f80b827e],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, In Quarantäne, [edbf27c2512a77bfbb13be6728dbe21e],
PUP.Optional.VbatesHelper.A, HKLM\SOFTWARE\WOW6432NODE\V-bates, In Quarantäne, [1795fbee1a61e254f88575b123e00cf4],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Iminent, In Quarantäne, [4c608f5ab2c9a0964aefa2aed23228d8],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\YontooIEClient.DLL, In Quarantäne, [c8e4b4351d5e8fa79efada283dc6619f],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\dedmngkbaffkenlfdcbganndoghblmap, In Quarantäne, [7d2f4e9bbac12f07a42de528ef1408f8],
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\mmifolfpllfdhilecpdpmemhelmanajl, In Quarantäne, [426a3aaf6714ce688f1911f752b1a957],
PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\niapdbllcanepiiimjjndipklodoedlc, In Quarantäne, [b3f938b1d8a365d18e3d1af33ac93bc5],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr, Löschen bei Neustart, [87250fda176476c025ee53e8c63ec23e],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, Löschen bei Neustart, [7537b9301c5f3501868c84b77e8633cd],
PUP.Optional.Babylon.A, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, Löschen bei Neustart, [941801e85d1ecb6b779f013b05ff7090],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Löschen bei Neustart, [8725c821e299d0660fcac55f8d7603fd],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Löschen bei Neustart, [3a72a445a1da999dea4cd9626b99cc34],
PUP.Optional.SuperFish.A, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com, Löschen bei Neustart, [208c836681fa1f173cf1e51cdd26af51],
PUP.Optional.BProtector.A, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, Löschen bei Neustart, [baf29a4f5f1cf83e580ce658e91b51af],
Registrierungswerte: 8
PUP.Optional.VBates, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, C:\Program Files\V-bates\Firefox, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45]
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, C:\Program Files\V-bates\Firefox, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45]
PUP.Optional.VBates, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, In Quarantäne, [3a7209e0e695bc7a69f6d7aa6c965fa1],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, In Quarantäne, [6b418960ed8e4ee8da85b8c953af50b0],
PUP.Optional.VBates, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}_IS1|UninstallString, "C:\Program Files\V-bates\unins000.exe", In Quarantäne, [cbe1ffea67146dc9bf42500d6e9619e7]
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|xz123@ya456.com, C:\Program Files (x86)\BetterSurf\ff, In Quarantäne, [1f8df5f468130a2cbadc877b18ebcb35]
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|ext@bettersurfplus.com, C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff, In Quarantäne, [05a770790675d363a0097a8ef60d867a]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3773635360-3589719687-3993712204-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0L1N1H2O1S, Löschen bei Neustart, [3a72a445a1da999dea4cd9626b99cc34]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 24
PUP.Optional.SoftwareUpdater.A, C:\Users\*****\AppData\Local\SwvUpdater, In Quarantäne, [d7d5cf1ab8c3290d07fb4eaf03ff758b],
PUP.Optional.OffersWizard.A, C:\Program Files (x86)\Common Files\Config, In Quarantäne, [a60699502457ea4c3286877605fd41bf],
PUP.Optional.Yontoo.A, C:\Program Files (x86)\Yontoo, In Quarantäne, [b0fce7020b70bb7b25a5e52837cc7987],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates, Löschen bei Neustart, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\chrome, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\chrome\content, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\chrome\content\libraries, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\chrome\content\resources, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\chrome\locale, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\chrome\locale\en-US, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\chrome\skin, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\defaults, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\defaults\preferences, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\libraries, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\resources, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.Iminent.A, C:\Users\*****\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl, In Quarantäne, [2e7eaa3f2556e94d0cfb3296778b9769],
PUP.Optional.Iminent.A, C:\Program Files (x86)\IminentToolbar, In Quarantäne, [f1bb8168ff7c58de190a8a3ed82a32ce],
PUP.Optional.OpenCandy, C:\Users\*****\AppData\Roaming\OpenCandy, In Quarantäne, [ab01f3f6532888ae7bb155738d7535cb],
PUP.Optional.OpenCandy, C:\Users\*****\AppData\Roaming\OpenCandy\82E0D648DB0E4124BFF0BF23EA630F3F, In Quarantäne, [ab01f3f6532888ae7bb155738d7535cb],
PUP.Optional.OpenCandy, C:\Users\*****\AppData\Roaming\OpenCandy\C58E541E724949A6902064C69351230C, In Quarantäne, [ab01f3f6532888ae7bb155738d7535cb],
PUP.Optional.Iminent.A, C:\Users\*****\AppData\Local\Temp\Iminent, In Quarantäne, [cce02dbc196261d5c481c00806fce818],
PUP.Optional.Webexp, C:\Program Files (x86)\WebexpEnhancedV1, In Quarantäne, [109c49a0fb8044f253c073579c666997],
PUP.Optional.TrustMediaViewer.A, C:\Program Files (x86)\TrustMediaViewerV1, In Quarantäne, [cedee108a9d2db5babdbd50b09f9768a],
Dateien: 100
PUP.Optional.VBates, C:\Program Files\V-bates\Extension64.dll, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.VBates, C:\Program Files\V-bates\Extension32.dll, In Quarantäne, [812bf2f7c1baf640035c008126dcbb45],
PUP.Optional.SoftwareUpdater, C:\Users\*****\AppData\Local\SwvUpdater\Updater.exe, In Quarantäne, [4d5f6188b2c9320407810a7d16ecf50b],
PUP.Optional.Yontoo.A, C:\Program Files (x86)\Yontoo\YontooIEClient.dll, In Quarantäne, [e0cc13d66912b3835138f88418ea629e],
PUP.Optional.GenericExt.A, C:\Users\*****\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl\minibarchrome.exe, In Quarantäne, [119ba1481c5f2214fb6d0d3028d8728e],
PUP.Optional.Conduit.A, C:\Users\*****\AppData\Roaming\OpenCandy\C58E541E724949A6902064C69351230C\SSStub_SearchProtect_p1v0.exe, In Quarantäne, [efbd04e51863e551477188a2b8497d83],
PUP.Optional.OptChrome.A, C:\Program Files (x86)\Yontoo\OptChrome.exe, In Quarantäne, [0ba11fca42397bbbae19839bfa063ac6],
PUP.Optional.Amonetize.A, C:\Users\*****\AppData\Local\Temp\Updater.exe, In Quarantäne, [436924c5accfb97d5ef5be694ab7f40c],
PUP.Optional.SearchProtect.A, C:\Users\*****\AppData\Local\Temp\SPSetup.exe, In Quarantäne, [7a32eefbaccf1d19bedf4c4e07fa41bf],
PUP.Optional.Iminent.A, C:\Users\*****\AppData\Local\Temp\IMsetup.exe, In Quarantäne, [5c506e7bf18a280ea88b153d4eb313ed],
PUP.Optional.SearchProtect.A, C:\Users\*****\AppData\Local\Temp\nsa16E2.exe, In Quarantäne, [802c6e7b1c5fba7c5a313601a0618f71],
PUP.Optional.SearchProtect.A, C:\Users\*****\AppData\Local\Temp\nsb2587.exe, In Quarantäne, [8e1e8e5beb90b08691fa9f98dd245da3],
PUP.Optional.SearchProtect.A, C:\Users\*****\AppData\Local\Temp\nsf1442.exe, In Quarantäne, [08a49c4d4c2f42f4c4c743f4649ded13],
PUP.Optional.SearchProtect.A, C:\Users\*****\AppData\Local\Temp\nsg4867.exe, In Quarantäne, [6c40f2f7b7c4191dcbc0033414ed7a86],
PUP.Optional.SearchProtect.A, C:\Users\*****\AppData\Local\Temp\nskD412.exe, In Quarantäne, [15979059d8a3b87e2e5d1126966b8e72],
PUP.Optional.SearchProtect.A, C:\Users\*****\AppData\Local\Temp\nsl4AA9.exe, In Quarantäne, [01ab3cad5f1c7abcf497340381804bb5],
PUP.Optional.SearchProtect.A, C:\Users\*****\AppData\Local\Temp\nsn115.exe, In Quarantäne, [535926c3bdbee056cfbc2116bf42669a],
PUP.Optional.SearchProtect.A, C:\Users\*****\AppData\Local\Temp\nsq2373.exe, In Quarantäne, [3e6e8b5e502b3afc048739fe0cf5a65a],
PUP.Optional.SearchProtect.A, C:\Users\*****\AppData\Local\Temp\nsuCF20.exe, In Quarantäne, [8d1f1ccde69501356c1ffc3b9071e11f],
PUP.Optional.SearchProtect.A, C:\Users\*****\AppData\Local\Temp\nsuD191.exe, In Quarantäne, [b1fbd81184f7072f5338bb7c917036ca],
PUP.Optional.SearchProtect.A, C:\Users\*****\AppData\Local\Temp\nsv1193.exe, In Quarantäne, [4369f4f582f9cd695437191e47bab24e],
PUP.Optional.SearchProtect.A, C:\Users\*****\AppData\Local\Temp\nsv216F.exe, In Quarantäne, [beee28c193e867cf810ac473e1209a66],
PUP.Optional.SearchProtect.A, C:\Users\*****\AppData\Local\Temp\nsv4605.exe, In Quarantäne, [7438c62395e6053192f939fefa07cc34],
PUP.Optional.Conduit.A, C:\Users\*****\AppData\Local\Temp\utt43D3.tmp.exe, In Quarantäne, [cce03baef4870d29f7c1fa301ae734cc],
PUP.Optional.Conduit.A, C:\Users\*****\AppData\Local\Temp\nsw5ED6.exe, In Quarantäne, [b2fa9b4e413ad85ee195bcd45ca54bb5],
PUP.Optional.Somoto, C:\Users\*****\AppData\Local\Temp\bitool.dll, In Quarantäne, [beee6485f38894a2a82b76d9cc36837d],
PUP.Optional.Bandoo.A, C:\Users\*****\AppData\Local\Temp\SetupDataMngr_Searchqu.exe, In Quarantäne, [6b413eabf08b25110378267ed4305ba5],
PUP.Optional.Iminent, C:\Users\*****\AppData\Local\Temp\Umbrella.exe6ca1d9c5, In Quarantäne, [4468876287f4d75f5d96859006fb09f7],
PUP.Optional.CRX.A, C:\Users\*****\AppData\Local\Temp\bus6FF5\CrxUpdater_d.exe, In Quarantäne, [cce034b53b404fe76975dec9e3212ed2],
PUP.Optional.CRX.A, C:\Users\*****\AppData\Local\Temp\busCF45\CrxUpdater_d.exe, In Quarantäne, [9814ad3ca2d91f176876b3f459ab649c],
PUP.Optional.Delta.A, C:\Users\*****\AppData\Local\Temp\is1070216317\DeltaTB.exe, In Quarantäne, [377540a98cef63d3464cb85d926f2bd5],
PUP.Optional.CRX.A, C:\Users\*****\AppData\Local\Temp\busD3BA\CrxUpdater_d.exe, In Quarantäne, [e4c8f0f90279989ebc221790ae5650b0],
PUP.Optional.CRX.A, C:\Users\*****\AppData\Local\Temp\busDFEB\CrxUpdater_d.exe, In Quarantäne, [7d2f12d7e39855e1c21c71367f85639d],
PUP.Optional.CRX.A, C:\Users\*****\AppData\Local\Temp\bus8746\CrxUpdater_d.exe, In Quarantäne, [9715b5347902979f805e822573913cc4],
PUP.Optional.CRX.A, C:\Users\*****\AppData\Local\Temp\busA37D\CrxUpdater_d.exe, In Quarantäne, [783478711f5cb086726c089f82829c64],
PUP.Optional.CRX.A, C:\Users\*****\AppData\Local\Temp\busA658\CrxUpdater_d.exe, In Quarantäne, [dad2ba2fd0ab72c4bb233a6d7193eb15],
PUP.Optional.CRX.A, C:\Users\*****\AppData\Local\Temp\busAE64\CrxUpdater_d.exe, In Quarantäne, [a507c42598e372c4d40a3572a55f04fc],
PUP.Optional.CRX.A, C:\Users\*****\AppData\Local\Temp\busBF9A\CrxUpdater_d.exe, In Quarantäne, [2a82effa1a6169cdc01e228531d30ff1],
PUP.Optional.BabSolution.A, C:\Users\*****\AppData\Local\Temp\busC13D\BUSolution.dll, In Quarantäne, [bcf0e801087333030d8163b7867b52ae],
PUP.Optional.Conduit.A, C:\Users\*****\AppData\Local\Temp\nslBDDC\SpSetup.exe, In Quarantäne, [f1bb15d4b3c8979f94e851db699831cf],
PUP.Optional.Conduit.A, C:\Users\*****\AppData\Local\Temp\nsp6594\SpSetup.exe, In Quarantäne, [e3c959901c5ffb3bc1bb121aee130af6],
PUP.Optional.Babylon.A, C:\Users\*****\AppData\Local\Temp\AA3232A3-BAB0-7891-BC32-A8D38621D556\Latest\BExternal.dll, In Quarantäne, [4369b5345f1c81b5d24610130df3f50b],
Trojan.RotBrowse, C:\Users\*****\AppData\Local\Temp\AA3232A3-BAB0-7891-BC32-A8D38621D556\Latest\ccp.exe, In Quarantäne, [bfed2ebb8af13cfad6937a57ef15936d],
PUP.Optional.Babylon.A, C:\Users\*****\AppData\Local\Temp\AA3232A3-BAB0-7891-BC32-A8D38621D556\Latest\CrxInstaller.dll, In Quarantäne, [6e3e32b75724eb4b44ff05228b76d729],
PUP.Optional.Delta.A, C:\Users\*****\AppData\Local\Temp\AA3232A3-BAB0-7891-BC32-A8D38621D556\Latest\MyBabylonTB.exe, In Quarantäne, [5c50c821cab13ff7cd93ea9454ad4ab6],
PUP.Optional.Babylon.A, C:\Users\*****\AppData\Local\Temp\AA3232A3-BAB0-7891-BC32-A8D38621D556\Latest\Setup.exe, In Quarantäne, [6a42da0f215a3bfb2e63d84639c7b54b],
PUP.Optional.CRX.A, C:\Users\*****\AppData\Local\Temp\bus1A51\CrxUpdater_d.exe, In Quarantäne, [8f1de0097209e35319c5d9cecd37a759],
PUP.Optional.CRX.A, C:\Users\*****\AppData\Local\Temp\bus253A\CrxUpdater_d.exe, In Quarantäne, [802c44a55526f04637a76f38c83cb749],
PUP.Optional.CRX.A, C:\Users\*****\AppData\Local\Temp\bus27E6\CrxUpdater_d.exe, In Quarantäne, [f8b4c722e4971620b92586214db7718f],
PUP.Optional.CRX.A, C:\Users\*****\AppData\Local\Temp\bus58EB\CrxUpdater_d.exe, In Quarantäne, [2a82b93039423ef80dd1b6f1867e52ae],
PUP.Optional.CRX.A, C:\Users\*****\AppData\Local\Temp\bus6C9A\CrxUpdater_d.exe, In Quarantäne, [367641a80d6ea78fe4fa228543c1837d],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsiC021.exe, In Quarantäne, [6547f4f545367abc1b70d1665da4d42c],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsiE011.exe, In Quarantäne, [644813d67605de589bdb226e679a26da],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsm56E2.exe, In Quarantäne, [d6d6e504c6b5fe384e28642c21e09d63],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsnABD6.exe, In Quarantäne, [83298b5e285346f03a5181b641c09d63],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsp96D8.exe, In Quarantäne, [ffadc128b0cb87aff086e2aece3304fc],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsr7B92.exe, In Quarantäne, [7834a247aecd91a5b0c6c2ceb8493ac6],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nss703C.exe, In Quarantäne, [cddf2fba05760a2c14771d1afd04c53b],
PUP.Optional.Conduit.A, C:\Windows\Temp\nssC7EE.exe, In Quarantäne, [b5f7ebfe2b50fc3a0b6b642c1ae74cb4],
PUP.Optional.Conduit.A, C:\Windows\Temp\nsv73ED.exe, In Quarantäne, [129a70790e6d6ccaa3d3fc948b762bd5],
PUP.Optional.SearchProtect.A, C:\Windows\Temp\nsx686F.exe, In Quarantäne, [fab202e77cff053178136ccb0af70af6],
PUP.Optional.SoftwareUpdater.A, C:\Users\*****\AppData\Local\SwvUpdater\Updater.xml, In Quarantäne, [d7d5cf1ab8c3290d07fb4eaf03ff758b],
PUP.Optional.SoftwareUpdater.A, C:\Users\*****\AppData\Local\SwvUpdater\status.cfg, In Quarantäne, [d7d5cf1ab8c3290d07fb4eaf03ff758b],
PUP.Optional.OffersWizard.A, C:\Program Files (x86)\Common Files\Config\ver.xml, In Quarantäne, [a60699502457ea4c3286877605fd41bf],
PUP.Optional.BrowserProtect.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8t12mosy.default\searchplugins\BrowserProtect.xml, In Quarantäne, [c5e7faef8eeda690861717ea5ba88c74],
PUP.SoftwareUpdater.A, C:\Windows\System32\Tasks\AmiUpdXp, In Quarantäne, [eac2935605768da931da6d9536cd49b7],
PUP.Optional.Yontoo.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8t12mosy.default\extensions\plugin@yontoo.com.xpi, In Quarantäne, [74384a9fc3b8e551cc6c8e7518eb19e7],
PUP.Optional.Trovi.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8t12mosy.default\searchplugins\trovi-search.xml, In Quarantäne, [fcb0a74202790f271dbf4ac28f742dd3],
PUP.Optional.Yontoo.A, C:\Program Files (x86)\Yontoo\YontooLayers.crx, In Quarantäne, [b0fce7020b70bb7b25a5e52837cc7987],
PUP.Optional.Babylon.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8t12mosy.default\searchplugins\babylon.xml, In Quarantäne, [adff4a9fec8ff442b2460514966da15f],
PUP.Optional.BProtector.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8t12mosy.default\bProtector_extensions.sqlite, In Quarantäne, [941846a3f08bf14563a1db3f8083fb05],
PUP.Optional.BProtector.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8t12mosy.default\bprotector_prefs.js, In Quarantäne, [406cc7228af1e3532bda130748bb9070],
PUP.Optional.Delta.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8t12mosy.default\searchplugins\delta.xml, In Quarantäne, [e0cc37b2166525115dce38e212f14ab6],
PUP.Optional.Iminent.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8t12mosy.default\searchplugins\iminent.xml, In Quarantäne, [a20ace1b7209c472cd900a10798a37c9],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\source.crx, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\DGChrome.exe, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\ExtensionUpdaterService.exe, Löschen bei Neustart, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\InstallerHelper.dll, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\NMHClient.exe, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\NMHClient.json, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\PrefHelper.exe, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\unins000.dat, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\unins000.exe, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\chrome.manifest, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\icon.png, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\install.rdf, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\chrome\content\main.js, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\chrome\content\main.xul, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\chrome\content\libraries\DataExchangeScript.js, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\chrome\content\resources\LocalScript.js, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\chrome\locale\en-US\overlay.dtd, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\chrome\skin\overlay.css, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\Firefox\defaults\preferences\defaults.js, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\libraries\DataExchangeScript.js, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Optional.VbatesHelper.A, C:\Program Files\V-bates\resources\LocalScript.js, In Quarantäne, [872563860e6d3df97cffbc6a956e3ac6],
PUP.Software.Updater, C:\Windows\Tasks\AmiUpdXp.job, In Quarantäne, [a507db0ecbb0bf77ce98df4da45f857b],
PUP.Optional.VBates.A, C:\Users\*****\AppData\Local\Temp\v-bates.exe, In Quarantäne, [7d2fe2073645e254d349b6a64fb5d12f],
PUP.Optional.Iminent.A, C:\Users\*****\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl\empty.localstorage, In Quarantäne, [2e7eaa3f2556e94d0cfb3296778b9769],
PUP.Optional.OpenCandy, C:\Users\*****\AppData\Roaming\OpenCandy\82E0D648DB0E4124BFF0BF23EA630F3F\Trial-14.0.1000.89_de-DE_1004733_DE-2.exe, In Quarantäne, [ab01f3f6532888ae7bb155738d7535cb],
PUP.Optional.Iminent.A, C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8t12mosy.default\user.js, Gut: (), Schlecht: (user_pref("extensions.iminent.tlbrSrchUrl", "hxxp://start.iminent.com/?ref=toolbarm#q=");), Ersetzt,[a408dd0c394283b30df851d02cd9d030]
Physische Sektoren: 0
(No malicious items detected)
(end) OTL Code:
OTL logfile created on: 08.09.2014 19:44:43 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\*****\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16521)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
7,89 Gb Total Physical Memory | 5,00 Gb Available Physical Memory | 63,35% Memory free
15,78 Gb Paging File | 12,10 Gb Available in Paging File | 76,68% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279,45 Gb Total Space | 168,74 Gb Free Space | 60,38% Space Free | Partition Type: NTFS
Drive D: | 393,86 Gb Total Space | 136,85 Gb Free Space | 34,74% Space Free | Partition Type: NTFS
Computer Name: *****-PC | User Name: ***** | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\*****\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avrestart.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe (Emsisoft GmbH)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe (BlueStack Systems, Inc.)
PRC - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (BlueStack Systems, Inc.)
PRC - C:\Program Files (x86)\Ensonhaber Alarm\Ensonhaber Alarm.exe ()
PRC - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Microsoft\BingDesktop\BDRuntimeHost.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Microsoft\BingDesktop\BDExtHost.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Microsoft\BingDesktop\BDAppHost.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.)
PRC - C:\Windows\AsScrPro.exe (ASUS)
PRC - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation)
PRC - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
PRC - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS)
PRC - C:\Windows\SysWOW64\ACEngSvr.exe (ASUSTeK)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe ()
PRC - C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
PRC - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ASUS)
========== Modules (No Company Name) ==========
MOD - C:\Users\*****\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
MOD - C:\Program Files (x86)\Ensonhaber Alarm\Ensonhaber Alarm.exe ()
MOD - C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll ()
MOD - C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll ()
MOD - C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (McComponentHostService) -- C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe (McAfee, Inc.)
SRV:64bit: - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:64bit: - (NvStreamSvc) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV:64bit: - (Intel(R) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel(R) Corporation)
SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (WTouchService) -- C:\Program Files\WTouch\WTouchService.exe (Wacom Technology, Corp.)
SRV:64bit: - (TabletServicePen) -- C:\Windows\SysNative\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV - (Avira.OE.ServiceHost) -- C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (a2AntiMalware) -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe (Emsisoft GmbH)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (BstHdUpdaterSvc) -- C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe (BlueStack Systems, Inc.)
SRV - (BstHdLogRotatorSvc) -- C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (BlueStack Systems, Inc.)
SRV - (BstHdAndroidSvc) -- C:\Program Files (x86)\BlueStacks\HD-Service.exe (BlueStack Systems, Inc.)
SRV - (TeamViewer9) -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (NvNetworkService) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation)
SRV - (cphs) -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (BingDesktopUpdate) -- C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe (Microsoft Corp.)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (SearchAnonymizer) -- C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe ()
SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUSTek Computer Inc.)
SRV - (ICCS) -- C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation)
SRV - (ASUS InstantOn) -- C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe (ASUS)
SRV - (ZAtheros Bt&Wlan Coex Agent) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
SRV - (AtherosSvc) -- C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (Atheros Commnucations)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (jhi_service) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation)
SRV - (Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe ()
SRV - (ATKGFNEXSrv) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
SRV - (Fabs) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe (MAGIX®)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (MBAMSwissArmy) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys (Malwarebytes Corporation)
DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (VBoxNetAdp) -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV:64bit: - (MBAMWebAccessControl) -- C:\Windows\SysNative\drivers\mwac.sys (Malwarebytes Corporation)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (nvkflt) -- C:\Windows\SysNative\drivers\nvkflt.sys (NVIDIA Corporation)
DRV:64bit: - (nvpciflt) -- C:\Windows\SysNative\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (dg_ssudbus) -- C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (ssudmdm) -- C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (nvvad_WaveExtensible) -- C:\Windows\SysNative\drivers\nvvad64v.sys (NVIDIA Corporation)
DRV:64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (AsusVBus) -- C:\Windows\SysNative\drivers\AsusVBus.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (AsusVTouch) -- C:\Windows\SysNative\drivers\AsusVTouch.sys (Windows (R) Win 7 DDK provider)
DRV:64bit: - (BtFilter) -- C:\Windows\SysNative\drivers\btfilter.sys (Atheros)
DRV:64bit: - (BTATH_RCP) -- C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
DRV:64bit: - (BTATH_LWFLT) -- C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
DRV:64bit: - (BTATH_HCRP) -- C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
DRV:64bit: - (AthBTPort) -- C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
DRV:64bit: - (BTATH_BUS) -- C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
DRV:64bit: - (btath_avdt) -- C:\Windows\SysNative\drivers\btath_avdt.sys (Atheros)
DRV:64bit: - (BTATH_A2DP) -- C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
DRV:64bit: - (iusb3xhc) -- C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
DRV:64bit: - (iusb3hub) -- C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
DRV:64bit: - (iusb3hcs) -- C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (AiCharger) -- C:\Windows\SysNative\drivers\AiCharger.sys (ASUSTek Computer Inc.)
DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (ETD) -- C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronics Corp.)
DRV:64bit: - (L1C) -- C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (AmUStor) -- C:\Windows\SysNative\drivers\AmUStor.sys (Alcor Micro, Corp.)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (kbfiltr) -- C:\Windows\SysNative\drivers\kbfiltr.sys ( )
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (TPM) -- C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp)
DRV:64bit: - (SiSGbeLH) -- C:\Windows\SysNative\drivers\SiSG664.sys (Silicon Integrated Systems Corp.)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (wacomvhid) -- C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (wacmoumonitor) -- C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV:64bit: - (wacommousefilter) -- C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV:64bit: - (WacomVKHid) -- C:\Windows\SysNative\drivers\WacomVKHid.sys (Wacom Technology)
DRV - (a2acc) -- C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys (Emsisoft GmbH)
DRV - (a2util) -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys (Emsisoft GmbH)
DRV - (BstHdDrv) -- C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys (BlueStack Systems)
DRV - (cleanhlp) -- C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys (Emsisoft GmbH)
DRV - (a2injectiondriver) -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys (Emsisoft GmbH)
DRV - (A2DDA) -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys (Emsisoft GmbH)
DRV - (AiCharger) -- C:\Windows\SysWOW64\drivers\AiCharger.sys (ASUSTek Computer Inc.)
DRV - (ATKWMIACPIIO) -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys (ASUS)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (ASMMAP64) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASUS)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = about:blankROUN
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = about:blankROUN
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {721061fb-eb79-4568-a03c-3ce26d68dae9}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{721061fb-eb79-4568-a03c-3ce26d68dae9}: "URL" = hxxp://de.search.yahoo.com/search/?p={searchTerms}&fr=vc_trans_de_8197&type=dsse
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blankLBA
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 25 0A 1C 6C B0 39 CF 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {B92A71DE-23FC-489F-B537-FE350C74BDF0}
IE - HKCU\..\SearchScopes\{B92A71DE-23FC-489F-B537-FE350C74BDF0}: "URL" = hxxp://de.search.yahoo.com/search?fr=mcafee&type=A011DE885&p={SearchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: ich%40maltegoetz.de:1.5.5
FF - prefs.js..extensions.enabledAddons: nosquint%40urandom.ca:2.1.9
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:31.0
FF - prefs.js..network.proxy.type: 0
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_45: C:\Windows\system32\npdeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.6: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF:64bit: - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\*****\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\dnshelp@dnshelp.com: C:\Users\*****\AppData\Roaming\Helper [2013.02.11 16:02:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: kernel32::GetLongPathNameW(w R8, w .R7, i 1024)i .R6\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: kernel32::GetLongPathNameW(w R8, w .R7, i 1024)i .R6\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Components: kernel32::GetLongPathNameW(w R8, w .R7, i 1024)i .R6\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0.1\extensions\\Plugins: kernel32::GetLongPathNameW(w R8, w .R7, i 1024)i .R6\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0.1\extensions\\Components: kernel32::GetLongPathNameW(w R8, w .R7, i 1024)i .R6\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 25.0.1\extensions\\Plugins: kernel32::GetLongPathNameW(w R8, w .R7, i 1024)i .R6\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 26.0\extensions\\Components: kernel32::GetLongPathNameW(w R8, w .R7, i 1024)i .R6\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 26.0\extensions\\Plugins: kernel32::GetLongPathNameW(w R8, w .R7, i 1024)i .R6\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 31.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014.07.30 22:22:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 31.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014.07.30 22:22:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\msktbird@mcafee.com: C:\Program Files\McAfee\MSK
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\firejump@firejump.net: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8t12mosy.default\extensions\firejump@firejump.net
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\extension@preispilot.com: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\8t12mosy.default\extensions\extension@preispilot.com
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\lrcfan@fansoft.br: C:\Program Files (x86)\LyricsFan\FF\
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{e4f94d1e-2f53-401e-8885-681602c0ddd8}: C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014.04.04 12:36:14 | 000,010,691 | ---- | M] ()
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 31.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014.07.30 22:22:40 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 31.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014.07.30 22:22:41 | 000,000,000 | ---D | M]
[2013.02.09 23:34:03 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Extensions
[2014.09.08 19:36:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\8t12mosy.default\extensions
[2014.09.04 15:05:03 | 000,000,000 | ---D | M] (Avira Browser Safety) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\8t12mosy.default\extensions\abs@avira.com
[2014.09.06 21:53:13 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\8t12mosy.default\extensions\foxyproxy@eric.h.jung
[2013.12.12 13:56:06 | 000,000,000 | ---D | M] (ProxTube - Unblock YouTube) -- C:\Users\*****\AppData\Roaming\mozilla\Firefox\Profiles\8t12mosy.default\extensions\ich@maltegoetz.de
[2013.02.12 01:25:14 | 000,111,107 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\8t12mosy.default\extensions\extension@preispilot.com.xpi
[2013.05.04 01:45:54 | 000,114,250 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\8t12mosy.default\extensions\nosquint@urandom.ca.xpi
[2014.07.23 15:27:10 | 000,967,685 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\8t12mosy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014.08.05 13:51:53 | 000,556,916 | ---- | M] () (No name found) -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\8t12mosy.default\extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi
[2013.02.11 16:02:54 | 000,002,079 | ---- | M] () -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\8t12mosy.default\searchplugins\98941506-d865-4ffd-a8db-da5a32d4be77.xml
[2014.09.08 19:35:45 | 000,000,996 | ---- | M] () -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\8t12mosy.default\searchplugins\avira-safesearch.xml
[2013.02.11 16:11:26 | 000,002,315 | ---- | M] () -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\8t12mosy.default\searchplugins\google-default.xml
[2013.02.11 16:02:37 | 000,001,870 | ---- | M] () -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\8t12mosy.default\searchplugins\{002E3E7B-A688-49FC-8BE9-CCA7EBB47BEC}.xml
[2013.02.11 16:02:37 | 000,002,188 | ---- | M] () -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\8t12mosy.default\searchplugins\{3CED5DB9-007E-40CB-8CBB-4AF88EE949DE}.xml
[2013.02.11 16:02:37 | 000,002,077 | ---- | M] () -- C:\Users\*****\AppData\Roaming\mozilla\firefox\profiles\8t12mosy.default\searchplugins\{76E1CA73-5A2E-4CCC-8400-FC1BCEAA9571}.xml
[2014.07.30 22:22:40 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
[2014.07.30 22:22:46 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (DNS Error Helper) - {9B6B03F1-16CF-4491-BBBB-E872802DD717} - C:\ProgramData\DNSErrorHelper\bho.dll ()
O2 - BHO: (QUICKfind BHO Object) - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\PROGRA~2\IDM\QUICKF~1\PlugIns\IEHelp.dll (IDM)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.)
O4:64bit: - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4:64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Communications)
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Logitech Download Assistant] C:\Windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Ocs_SM] C:\Users\*****\AppData\Roaming\OCS\SM\SearchAnonymizer.exe (OCS)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS)
O4 - HKLM..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" File not found
O4 - HKLM..\Run: [ASUS InstantKey] C:\Program Files (x86)\ASUS\ASUS Instant Key\Ikey_start.exe (ASUS)
O4 - HKLM..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe (ASUS)
O4 - HKLM..\Run: [ASUSPRP] C:\Program Files (x86)\ASUS\APRP\APRP.EXE (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe (ecareme)
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Avira Systray] C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe (Microsoft Corp.)
O4 - HKLM..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe (BlueStack Systems, Inc.)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ASUSTeK Computer Inc.)
O4 - Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Ensonhaber Alarm.lnk = C:\Program Files (x86)\Ensonhaber Alarm\Ensonhaber Alarm.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_45-windows-i586.cab (Java Plug-in 1.6.0_45)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_45-windows-i586.cab (Java Plug-in 1.6.0_45)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_45-windows-i586.cab (Java Plug-in 1.6.0_45)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{01779A16-E73C-4F56-8541-140FBBFE0727}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\System32\Userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (bj.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014.09.08 19:41:10 | 000,042,040 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avnetflt.sys
[2014.09.08 19:39:25 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Avira
[2014.09.08 19:38:37 | 000,130,584 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2014.09.08 19:38:37 | 000,117,712 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2014.09.08 19:38:37 | 000,028,600 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2014.09.08 19:34:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2014.09.08 19:34:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2014.09.08 19:34:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2014.09.08 19:34:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Package Cache
[2014.09.08 18:11:50 | 000,000,000 | ---D | C] -- C:\FRST
[2014.09.08 17:55:19 | 000,000,000 | ---D | C] -- C:\Users\*****\Desktop\workspace
[2014.09.08 15:28:43 | 000,000,000 | ---D | C] -- C:\Users\*****\.android
[2014.09.08 14:40:15 | 000,545,200 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\npdeployJava1.dll
[2014.09.08 14:40:15 | 000,526,768 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\deployJava1.dll
[2014.09.08 14:40:15 | 000,196,528 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaws.exe
[2014.09.08 14:40:15 | 000,172,976 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaw.exe
[2014.09.08 14:40:15 | 000,172,976 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\java.exe
[2014.09.08 14:40:04 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2014.09.08 02:05:28 | 000,000,000 | ---D | C] -- C:\Users\*****\workspace
[2014.09.07 21:39:33 | 000,000,000 | ---D | C] -- C:\20cf004b03143b5f40
[2014.09.06 14:28:40 | 000,000,000 | ---D | C] -- C:\Users\*****\Desktop\eclipse-standard-luna-R-win32-x86_64
[2014.09.05 14:06:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Emsisoft
[2014.09.05 05:30:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
[2014.09.05 05:30:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Emsisoft Anti-Malware
[2014.09.05 03:21:47 | 000,122,584 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014.09.05 03:20:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2014.09.05 03:20:31 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014.09.05 03:20:31 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014.09.05 03:20:31 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014.09.05 03:20:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014.09.05 03:20:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014.08.25 18:52:22 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\Abelssoft
[2014.08.25 18:52:20 | 000,000,000 | ---D | C] -- C:\ProgramData\XDMessagingv4
[2014.08.25 18:52:18 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Local\Abelssoft
[2014.08.25 18:50:37 | 000,000,000 | ---D | C] -- C:\Users\*****\AppData\Roaming\DesktopIconGoodgame
[2 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014.09.08 19:39:32 | 000,042,040 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avnetflt.sys
[2014.09.08 19:34:22 | 000,001,139 | ---- | M] () -- C:\Users\Public\Desktop\Avira.lnk
[2014.09.08 19:25:34 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014.09.08 19:25:29 | 000,009,696 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.09.08 19:25:29 | 000,009,696 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.09.08 19:18:12 | 000,001,124 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014.09.08 19:17:31 | 000,122,584 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014.09.08 19:14:40 | 000,001,120 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014.09.08 19:14:26 | 000,000,387 | ---- | M] () -- C:\Users\*****\AppData\Roaming\sp_data.sys
[2014.09.08 19:14:05 | 000,000,828 | ---- | M] () -- C:\Windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
[2014.09.08 19:12:52 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014.09.08 19:12:41 | 2057,695,231 | -HS- | M] () -- C:\hiberfil.sys
[2014.09.08 17:20:45 | 000,000,000 | ---- | M] () -- C:\Users\*****\defogger_reenable
[2014.09.08 14:40:05 | 000,545,200 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\npdeployJava1.dll
[2014.09.08 14:40:05 | 000,526,768 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\deployJava1.dll
[2014.09.08 14:40:05 | 000,196,528 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaws.exe
[2014.09.08 14:40:05 | 000,172,976 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaw.exe
[2014.09.08 14:40:05 | 000,172,976 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\java.exe
[2014.09.07 23:34:26 | 000,003,477 | ---- | M] () -- C:\Users\*****\Desktop\tiledirt2.png
[2014.09.07 23:34:21 | 000,003,404 | ---- | M] () -- C:\Users\*****\Desktop\tilegrassright.png
[2014.09.07 23:34:17 | 000,003,403 | ---- | M] () -- C:\Users\*****\Desktop\tilegrassleft.png
[2014.09.07 23:34:12 | 000,003,379 | ---- | M] () -- C:\Users\*****\Desktop\tilegrassbot.png
[2014.09.07 23:34:08 | 000,003,383 | ---- | M] () -- C:\Users\*****\Desktop\tiledirt1.png
[2014.09.07 23:01:59 | 000,032,109 | ---- | M] () -- C:\Users\*****\Desktop\background.png
[2014.09.07 23:00:22 | 000,003,208 | ---- | M] () -- C:\Users\*****\Desktop\tileocean.png
[2014.09.07 23:00:17 | 000,003,383 | ---- | M] () -- C:\Users\*****\Desktop\tiledirt.png
[2014.09.07 22:01:19 | 000,011,455 | ---- | M] () -- C:\Users\*****\Desktop\heliboy.png
[2014.09.07 21:59:53 | 000,010,843 | ---- | M] () -- C:\Users\*****\Desktop\heliboy4.png
[2014.09.07 21:59:48 | 000,010,857 | ---- | M] () -- C:\Users\*****\Desktop\heliboy3.png
[2014.09.07 21:59:44 | 000,010,934 | ---- | M] () -- C:\Users\*****\Desktop\heliboy2.png
[2014.09.07 21:59:39 | 000,010,714 | ---- | M] () -- C:\Users\*****\Desktop\heliboy5.png
[2014.09.07 21:58:30 | 000,005,771 | ---- | M] () -- C:\Users\*****\Desktop\character3.png
[2014.09.07 21:58:25 | 000,005,768 | ---- | M] () -- C:\Users\*****\Desktop\character2.png
[2014.09.07 21:33:10 | 095,320,394 | ---- | M] () -- C:\Users\*****\Desktop\COMPONENTS.reg
[2014.09.07 20:56:18 | 000,002,115 | ---- | M] () -- C:\Windows\epplauncher.mif
[2014.09.07 20:29:08 | 007,663,150 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat
[2014.09.07 20:29:08 | 002,762,848 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014.09.07 20:29:08 | 002,385,206 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat
[2014.09.07 20:29:08 | 002,138,748 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014.09.07 20:29:08 | 000,006,488 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014.09.07 20:24:04 | 000,000,306 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2014.09.07 18:04:53 | 000,010,766 | ---- | M] () -- C:\Users\*****\Desktop\jumped.png
[2014.09.07 18:04:35 | 000,007,325 | ---- | M] () -- C:\Users\*****\Desktop\down.png
[2014.09.07 17:39:14 | 000,032,109 | ---- | M] () -- C:\Users\*****\Desktop\background,m5.png
[2014.09.07 12:02:57 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
[2014.09.07 02:30:08 | 000,005,758 | ---- | M] () -- C:\Users\*****\Desktop\character.png
[2014.09.07 00:48:46 | 000,000,155 | ---- | M] () -- C:\Users\*****\.appletviewer
[2014.09.05 05:30:45 | 000,001,097 | ---- | M] () -- C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
[2014.09.05 04:26:19 | 000,001,108 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014.08.25 18:59:12 | 000,365,104 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014.08.15 10:30:05 | 000,130,584 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2014.08.15 10:30:05 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2014.08.15 10:30:04 | 000,117,712 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2014.08.10 15:16:06 | 603,007,920 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014.09.08 19:34:22 | 000,001,139 | ---- | C] () -- C:\Users\Public\Desktop\Avira.lnk
[2014.09.08 17:20:45 | 000,000,000 | ---- | C] () -- C:\Users\*****\defogger_reenable
[2014.09.07 23:34:26 | 000,003,477 | ---- | C] () -- C:\Users\*****\Desktop\tiledirt2.png
[2014.09.07 23:34:21 | 000,003,404 | ---- | C] () -- C:\Users\*****\Desktop\tilegrassright.png
[2014.09.07 23:34:16 | 000,003,403 | ---- | C] () -- C:\Users\*****\Desktop\tilegrassleft.png
[2014.09.07 23:34:12 | 000,003,379 | ---- | C] () -- C:\Users\*****\Desktop\tilegrassbot.png
[2014.09.07 23:34:07 | 000,003,383 | ---- | C] () -- C:\Users\*****\Desktop\tiledirt1.png
[2014.09.07 23:00:22 | 000,003,208 | ---- | C] () -- C:\Users\*****\Desktop\tileocean.png
[2014.09.07 23:00:17 | 000,003,383 | ---- | C] () -- C:\Users\*****\Desktop\tiledirt.png
[2014.09.07 21:59:53 | 000,010,843 | ---- | C] () -- C:\Users\*****\Desktop\heliboy4.png
[2014.09.07 21:59:48 | 000,010,857 | ---- | C] () -- C:\Users\*****\Desktop\heliboy3.png
[2014.09.07 21:59:44 | 000,010,934 | ---- | C] () -- C:\Users\*****\Desktop\heliboy2.png
[2014.09.07 21:59:39 | 000,010,714 | ---- | C] () -- C:\Users\*****\Desktop\heliboy5.png
[2014.09.07 21:58:30 | 000,005,771 | ---- | C] () -- C:\Users\*****\Desktop\character3.png
[2014.09.07 21:58:24 | 000,005,768 | ---- | C] () -- C:\Users\*****\Desktop\character2.png
[2014.09.07 21:33:00 | 095,320,394 | ---- | C] () -- C:\Users\*****\Desktop\COMPONENTS.reg
[2014.09.07 18:20:42 | 000,011,455 | ---- | C] () -- C:\Users\*****\Desktop\heliboy.png
[2014.09.07 18:04:52 | 000,010,766 | ---- | C] () -- C:\Users\*****\Desktop\jumped.png
[2014.09.07 18:04:35 | 000,007,325 | ---- | C] () -- C:\Users\*****\Desktop\down.png
[2014.09.07 17:39:14 | 000,032,109 | ---- | C] () -- C:\Users\*****\Desktop\background.png
[2014.09.07 17:39:14 | 000,032,109 | ---- | C] () -- C:\Users\*****\Desktop\background,m5.png
[2014.09.07 02:30:07 | 000,005,758 | ---- | C] () -- C:\Users\*****\Desktop\character.png
[2014.09.07 00:48:46 | 000,000,155 | ---- | C] () -- C:\Users\*****\.appletviewer
[2014.09.05 05:30:45 | 000,001,097 | ---- | C] () -- C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
[2014.09.05 03:20:38 | 000,001,108 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014.08.25 05:15:01 | 000,002,115 | ---- | C] () -- C:\Windows\epplauncher.mif
[2014.07.26 04:08:33 | 000,012,072 | ---- | C] () -- C:\Windows\SysWow64\drivers\MoborobAssDriver64.sys
[2014.05.07 00:14:31 | 000,299,520 | ---- | C] () -- C:\Windows\SysWow64\igdmd32.dll
[2014.05.07 00:14:31 | 000,182,272 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2014.05.07 00:14:31 | 000,142,848 | ---- | C] () -- C:\Windows\SysWow64\igdail32.dll
[2014.03.12 03:47:27 | 000,535,902 | ---- | C] () -- C:\Users\*****\sonu.VIP
[2014.03.12 03:42:28 | 000,535,386 | ---- | C] () -- C:\Users\*****\uuu.VIP
[2014.03.12 02:13:13 | 000,002,830 | ---- | C] () -- C:\Users\*****\Unbenannt.PNG
[2014.03.08 02:10:08 | 002,323,350 | ---- | C] () -- C:\Users\*****\Standart05.ogg
[2014.03.08 02:10:08 | 000,000,171 | ---- | C] () -- C:\Users\*****\Standart05.cue
[2014.02.28 05:20:16 | 000,000,306 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2014.02.25 08:14:02 | 000,000,000 | ---- | C] () -- C:\Users\*****\java
[2014.02.25 07:50:35 | 000,854,016 | ---- | C] () -- C:\Windows\aapt.exe
[2013.05.31 22:44:20 | 000,000,118 | ---- | C] () -- C:\Users\*****\kvirc4.ini
[2013.02.11 16:02:42 | 000,338,432 | ---- | C] () -- C:\Windows\SysWow64\sqlite36_engine.dll
[2013.02.09 21:49:07 | 000,000,387 | ---- | C] () -- C:\Users\*****\AppData\Roaming\sp_data.sys
[2012.02.24 04:42:37 | 000,131,984 | ---- | C] () -- C:\ProgramData\FullRemove.exe
========== ZeroAccess Check ==========
[2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.07.26 04:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.07.26 03:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 14:19:04 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== Alternate Data Streams ==========
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:D20FFA63
< End of report > |