Hallo,
die Logs folgen. Vielen Dank.
mbam: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 10.11.2014
Scan Time: 21:03:20
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.11.10.08
Rootkit Database: v2014.11.10.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Mänz
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 482583
Time Elapsed: 22 min, 56 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 59
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, Quarantined, [f9270b2f7a02b77f6714509c758d52ae],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, Quarantined, [f9270b2f7a02b77f6714509c758d52ae],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}, Quarantined, [d24e80ba1369989e64620cad7290c23e],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}, Quarantined, [9a86a4966d0f66d0bac11ecda16125db],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, Quarantined, [fe2235058cf047ef73075a9158aa7c84],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}, Quarantined, [fe2235058cf047ef73075a9158aa7c84],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\escort.escortIEPane.1, Quarantined, [fe2235058cf047ef73075a9158aa7c84],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\escort.escortIEPane, Quarantined, [fe2235058cf047ef73075a9158aa7c84],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\escort.escortIEPane, Quarantined, [fe2235058cf047ef73075a9158aa7c84],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\escort.escortIEPane.1, Quarantined, [fe2235058cf047ef73075a9158aa7c84],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}, Quarantined, [fe2235058cf047ef73075a9158aa7c84],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{4599D05A-D545-4069-BB42-5895B4EAE05B}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1231839B-064E-4788-B865-465A1B5266FD}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2DAC2231-CC35-482B-97C5-CED1D4185080}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{57C91446-8D81-4156-A70E-624551442DE9}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{97DD820D-2E20-40AD-B01E-6730B2FCE630}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B177446D-54A4-4869-BABC-8566110B4BE0}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F05B12E1-ADE8-4485-B45B-898748B53C37}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1231839B-064E-4788-B865-465A1B5266FD}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2DAC2231-CC35-482B-97C5-CED1D4185080}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{57C91446-8D81-4156-A70E-624551442DE9}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{97DD820D-2E20-40AD-B01E-6730B2FCE630}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B177446D-54A4-4869-BABC-8566110B4BE0}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F05B12E1-ADE8-4485-B45B-898748B53C37}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{4599D05A-D545-4069-BB42-5895B4EAE05B}, Quarantined, [021e56e4fd7f6acc9bdf89632cd633cd],
PUP.Optional.Babylon.A, HKU\S-1-5-21-2436741097-1297008016-2183685444-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, Quarantined, [f22e51e9403cf6401df25b586d95c53b],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}, Quarantined, [34ecfe3cb7c564d274fbf4f8e9198878],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035382.Sandbox, Quarantined, [4cd40d2df587dc5a93af2c16e02324dc],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0035382.Sandbox.1, Quarantined, [37e94af0fe7e30066ad82f13f40f956b],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\DataMngr, Quarantined, [80a0d5650379989efc9a242aa75ce020],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035382.Sandbox, Quarantined, [b769d565740895a12e142b17887be41c],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0035382.Sandbox.1, Quarantined, [f0306fcbadcf7abc5ce649f910f37c84],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\DELTA\DELTA\Instl, Quarantined, [af710f2bee8e56e03342a1e5e61ed42c],
PUP.Optional.Hosts.A, HKLM\SOFTWARE\WOW6432NODE\HOSTS\INSTALLER, Quarantined, [00200d2da5d7f73f34c096d1937017e9],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-2436741097-1297008016-2183685444-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, Quarantined, [aa76c07a5c20a3933d01176a31d3e11f],
PUP.Optional.Hosts, HKU\S-1-5-21-2436741097-1297008016-2183685444-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HOSTS, Quarantined, [ab759aa00b7152e4d537241b57ac7c84],
PUP.Optional.Delta.A, HKU\S-1-5-21-2436741097-1297008016-2183685444-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DELTA\DELTA, Quarantined, [af711921413bea4ce1ffea953dc71de3],
PUP.Optional.Delta.A, HKU\S-1-5-21-2436741097-1297008016-2183685444-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DELTA\DELTA\IESTRG, Quarantined, [f12f9aa0bac2280e0a27cfb9a262be42],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2436741097-1297008016-2183685444-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Alex, Quarantined, [61bfc872fe7ea69082c762065ca702fe],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}, Quarantined, [dd43231707754de918de7f805ba7a25e],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\delta.deltaappCore.1, Quarantined, [dd43231707754de918de7f805ba7a25e],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\delta.deltaappCore, Quarantined, [dd43231707754de918de7f805ba7a25e],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\delta.deltaappCore, Quarantined, [dd43231707754de918de7f805ba7a25e],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\delta.deltaappCore.1, Quarantined, [dd43231707754de918de7f805ba7a25e],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}, Quarantined, [dd43231707754de918de7f805ba7a25e],
Registry Values: 7
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{82E1477C-B154-48D3-9891-33D83C26BCD3}, Delta Toolbar, Quarantined, [9a86a4966d0f66d0bac11ecda16125db]
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{82E1477C-B154-48D3-9891-33D83C26BCD3}, Quarantined, [30f0cb6f8defc17581faab404eb43dc3],
PUP.Optional.Hosts.A, HKLM\SOFTWARE\WOW6432NODE\HOSTS\INSTALLER|BundledIe, 1, Quarantined, [00200d2da5d7f73f34c096d1937017e9]
PUP.Optional.Hosts, HKU\S-1-5-21-2436741097-1297008016-2183685444-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HOSTS|BhoRunningVersion, 153, Quarantined, [ab759aa00b7152e4d537241b57ac7c84]
PUP.Optional.Delta.A, HKU\S-1-5-21-2436741097-1297008016-2183685444-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DELTA\DELTA|tlbrSrchUrl, Quarantined, [af711921413bea4ce1ffea953dc71de3],
PUP.Optional.Delta.A, HKU\S-1-5-21-2436741097-1297008016-2183685444-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DELTA\DELTA|lastB, hxxp://www.delta-search.com/?babsrc=HP_ss&mntrId=D0EF801F0293B4F8&affID=121562&tsp=4930, Quarantined, [7da39aa07dffb185a38f7e0a26de946c]
PUP.Optional.Delta.A, HKU\S-1-5-21-2436741097-1297008016-2183685444-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DELTA\DELTA\IESTRG|tlbrsrchurl, Quarantined, [f12f9aa0bac2280e0a27cfb9a262be42],
Registry Data: 0
(No malicious items detected)
Folders: 10
PUP.Optional.Hosts.A, C:\Program Files (x86)\hosts, Quarantined, [bf6178c22f4dd85e2b1fc0a81be89868],
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\BabSolution\Shared, Quarantined, [b66aec4eef8df244a896eeb19173a957],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5, Quarantined, [dd43231707754de918de7f805ba7a25e],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5\bh, Quarantined, [dd43231707754de918de7f805ba7a25e],
PUP.Optional.OpenCandy, C:\Users\Mänz\AppData\Roaming\OpenCandy, Quarantined, [e33d1a209ede82b41016ff01b94a847c],
PUP.Optional.OpenCandy, C:\Users\Mänz\AppData\Roaming\OpenCandy\144DB8668BD24C92B2048ABB9078595D, Quarantined, [e33d1a209ede82b41016ff01b94a847c],
PUP.Optional.OpenCandy, C:\Users\Mänz\AppData\Roaming\OpenCandy\44B87735F45141B3B5D7599B1161B0D9, Quarantined, [e33d1a209ede82b41016ff01b94a847c],
PUP.Optional.OnlySearch, C:\Users\Mänz\AppData\Local\onlysearch, Quarantined, [bb65c8725329e65087c07da7cb38fc04],
PUP.Optional.OnlySearch, C:\Users\Mänz\AppData\Local\onlysearch\onlysearch, Quarantined, [bb65c8725329e65087c07da7cb38fc04],
PUP.Optional.OnlySearch, C:\Users\Mänz\AppData\Local\onlysearch\onlysearch\1.3.12.9, Quarantined, [bb65c8725329e65087c07da7cb38fc04],
Files: 54
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5\deltaTlbr.dll, Quarantined, [9a86a4966d0f66d0bac11ecda16125db],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5\bh\delta.dll, Quarantined, [fe2235058cf047ef73075a9158aa7c84],
PUP.Optional.Babylon.A, C:\Users\Mänz\AppData\Roaming\OpenCandy\144DB8668BD24C92B2048ABB9078595D\DeltaTB.exe, Quarantined, [829e98a26517c472d9ca45d9bd445fa1],
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\OpenCandy\44B87735F45141B3B5D7599B1161B0D9\DeltaTB.exe, Quarantined, [c45c3901d0ac43f38c8f43dda45d22de],
PUP.Optional.Hosts.A, C:\Program Files (x86)\hosts\hosts-buttonutil.exe, Quarantined, [e43c7bbf96e6280e6ab33b339e63cd33],
PUP.Optional.Hosts.A, C:\Program Files (x86)\hosts\hosts-buttonutil64.exe, Quarantined, [1a06af8b81fbae88f32a90ded42d5ba5],
PUP.Optional.CrossRider, C:\Program Files (x86)\hosts\hosts-helper.exe, Quarantined, [ea3659e15824fe38b1b394ad51b0af51],
Trojan.InstallMonetizer, C:\Users\Mänz\Downloads\LOIC, Quarantined, [bc640a302f4d89ad77c374bdd92809f7],
PUP.Optional.OpenCandy.A, C:\Users\Mänz\Downloads\KATEELIFE_-_Mega_Collection_(60_Videos)_-_Part_1_of_2(1).exe, Quarantined, [aa76a793225a45f155409ba711efc43c],
PUP.Optional.OpenCandy.A, C:\Users\Mänz\Downloads\KATEELIFE_-_Mega_Collection_(60_Videos)_-_Part_1_of_2.exe, Quarantined, [4bd5bf7b81fbec4ad3c2261c3ac63ac6],
Spyware.Passwords.ED, C:\Windows\Installer\{9C8021C9-1A11-4BBC-AB2E-54790826D74C}\api-ms-win-system-actxprxy-l1-1-0.dll, Quarantined, [b967a1993b41bb7b3a5cddf5956c35cb],
PUP.Optional.Babylon.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\searchplugins\babylon.xml, Quarantined, [2af65cde5428f0465e03db859b68e020],
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\searchplugins\delta.xml, Quarantined, [829e95a580fc80b6573d74ecc340a55b],
PUP.Optional.Hosts.A, C:\Program Files (x86)\hosts\background.html, Quarantined, [bf6178c22f4dd85e2b1fc0a81be89868],
PUP.Optional.Hosts.A, C:\Program Files (x86)\hosts\hosts-buttonutil.dll, Quarantined, [bf6178c22f4dd85e2b1fc0a81be89868],
PUP.Optional.Hosts.A, C:\Program Files (x86)\hosts\hosts-buttonutil64.dll, Quarantined, [bf6178c22f4dd85e2b1fc0a81be89868],
PUP.Optional.Hosts.A, C:\Program Files (x86)\hosts\hosts.ico, Quarantined, [bf6178c22f4dd85e2b1fc0a81be89868],
PUP.Optional.Hosts.A, C:\Program Files (x86)\hosts\Installer.log, Quarantined, [bf6178c22f4dd85e2b1fc0a81be89868],
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\BabSolution\Shared\Delta.ico, Quarantined, [b66aec4eef8df244a896eeb19173a957],
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\BabSolution\Shared\BabMaint.exe, Quarantined, [b66aec4eef8df244a896eeb19173a957],
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\BabSolution\Shared\chu.js, Quarantined, [b66aec4eef8df244a896eeb19173a957],
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\BabSolution\Shared\GUninstaller.exe, Quarantined, [b66aec4eef8df244a896eeb19173a957],
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\BabSolution\Shared\SetupParams.ini, Quarantined, [b66aec4eef8df244a896eeb19173a957],
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\BabSolution\Shared\sqlite3.dll, Quarantined, [b66aec4eef8df244a896eeb19173a957],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5\deltaApp.dll, Quarantined, [dd43231707754de918de7f805ba7a25e],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5\deltaEng.dll, Quarantined, [dd43231707754de918de7f805ba7a25e],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5\deltasrv.exe, Quarantined, [dd43231707754de918de7f805ba7a25e],
PUP.Optional.Delta.A, C:\Program Files (x86)\Delta\delta\1.8.21.5\uninstall.exe, Quarantined, [dd43231707754de918de7f805ba7a25e],
PUP.Optional.OpenCandy, C:\Users\Mänz\AppData\Roaming\OpenCandy\44B87735F45141B3B5D7599B1161B0D9\5472.ico, Quarantined, [e33d1a209ede82b41016ff01b94a847c],
PUP.Optional.OpenCandy, C:\Users\Mänz\AppData\Roaming\OpenCandy\44B87735F45141B3B5D7599B1161B0D9\EBB77268-338F-4C6A-8590-AD88FED26F4A, Quarantined, [e33d1a209ede82b41016ff01b94a847c],
PUP.Optional.OpenCandy, C:\Users\Mänz\AppData\Roaming\OpenCandy\44B87735F45141B3B5D7599B1161B0D9\OCBrowserHelper_1.0.6.125.exe, Quarantined, [e33d1a209ede82b41016ff01b94a847c],
PUP.Optional.CrossRider.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossrider.bic", "140ef10e953d820751ae6266a3a5fb5d");), Replaced,[3be599a1a7d559dd8d288eea55b05fa1]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (user_pref("extensions.delta.admin", false);), Replaced,[829efa404b313ff707c45523da2bc43c]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (ferences
/* Do not edit this file.
*
*), Replaced,[b56b3604ceae8da9f6d5de9a2adb9967]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (rences
/* Do not edit this file.
*
* If you make changes to this file w), Replaced,[2af656e4057767cffccf91e7a362d030]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (e.
*
* If you make changes to this file whil), Replaced,[be6208329fddb482ac1ffe7a72935aa6]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (ces
/* Do not edit this file.
*
* If ), Replaced,[ae72a793d4a854e25b70bcbc37ceee12]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (erences
/* Do not edit this file.
*
* ), Replaced,[0f1180baa1db31058843d5a36e974eb2]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (rences
/* Do not edit this file.
*
* If y), Replaced,[88980238a4d8092d19b2e8907a8bdf21]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (ces
/* Do not edit this file.
*
* If you make changes to this ), Replaced,[ff2143f7304c59dde7e4ed8b1fe6748c]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: ( this file.
*
* If you make changes to this ), Replaced,[9e821d1daad2e94d408bd2a617eed828]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (ces
/* Do not edit this file.
*
* If yo), Replaced,[58c847f38fed51e59d2eea8e798cfd03]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (ences
/* Do not edit this file.
*
* I), Replaced,[e7399c9e89f3b185577403759d68ac54]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (rences
/* Do not edit this file.
*
* If ), Replaced,[8e920b2f522a7fb7ecdfde9ae1244eb2]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (nces
/* Do not edit this file.
*
* If), Replaced,[7fa10139295343f36d5ec0b8b550b54b]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (erences
/* Do not edit this file.
*
* I), Replaced,[6ab6f545304c47ef448781f72dd8f808]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (ences
/* Do not edit this file.
*
* If), Replaced,[6cb456e45c2058de93381068d2332dd3]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (rences
/* Do not edit this file.
*
* If), Replaced,[4dd33dfd7b01b97d01ca3d3bcf363fc1]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (ences
/* Do not edit this file.
*
* If y), Replaced,[2bf5b486bdbfe74f933894e40203f010]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (nces
/* Do not edit this file.
*
* If you make ch), Replaced,[7ba5af8b1468d5618f3c275139ccff01]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (* Do not edit this file.
*
* If you make cha), Replaced,[b7695bdf81fb61d504c7c9af6f96c63a]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (ces
/* Do not edit this file.
*
* If), Replaced,[e04057e3d8a44bebf2d92e4a63a216ea]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (ferences
/* Do not edit this file.
*
* If you make changes ), Replaced,[52ce4feb5b21b284e1ea33454db8b64a]
PUP.Optional.Delta.A, C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\prefs.js, Good: (), Bad: (dit this file.
*
* If you make changes to), Replaced,[50d0bc7ef785cb6b0cbff7817095a65a]
Physical Sectors: 0
(No malicious items detected)
(end) adwcleaner Code:
# AdwCleaner v4.101 - Bericht erstellt am 10/11/2014 um 21:44:34
# Aktualisiert 09/11/2014 von Xplode
# Database : 2014-11-10.2 [Live]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Mänz - HOME
# Gestartet von : C:\Users\Mänz\Downloads\AdwCleaner_4.101.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\Program Files (x86)\Delta
Ordner Gelöscht : C:\Users\Administrator\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\Mänz\AppData\LocalLow\Delta
Ordner Gelöscht : C:\Users\Mänz\AppData\Roaming\BabSolution
Ordner Gelöscht : C:\Users\Mänz\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Mänz\AppData\Roaming\DownLite
Datei Gelöscht : C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\searchplugins\BrowserDefender.xml
Datei Gelöscht : C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\user.js
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKCU\Software\Classes\keepmysearch
Schlüssel Gelöscht : HKLM\SOFTWARE\f68b8fe16ded48
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220322532282}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{1EA4DBF0-3C3B-11CF-810C-00AA00389B71}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Delta
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17344
-\\ Mozilla Firefox v33.1 (x86 de)
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.crossrider.bic", "140ef10e953d820751ae6266a3a5fb5d");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.admin", false);
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.dfltLng", "de");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.excTlbr", false);
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true);
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.id", "d0efea19000000000000801f0293b4f8");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.instlDay", "15887");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.newTab", false);
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.prdct", "delta");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.rvrt", "false");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.21.5");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.21.50:25:47");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.21.5");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta_i.babExt", "");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=121562&tsp=4930");
[et9w0fsv.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss");
-\\ Google Chrome v38.0.2125.111
-\\ Chromium v
*************************
AdwCleaner[R0].txt - [5578 octets] - [10/11/2014 21:42:26]
AdwCleaner[S0].txt - [5548 octets] - [10/11/2014 21:44:34]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5608 octets] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.7 (11.08.2014:1)
OS: Windows 7 Home Premium x64
Ran by M„nz on 10.11.2014 at 21:49:34,90
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311531182}
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\M„nz\AppData\Roaming\mozilla\firefox\profiles\et9w0fsv.default\minidumps [427 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 10.11.2014 at 21:52:02,94
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ frst
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-11-2014 01
Ran by Mänz (administrator) on HOME on 10-11-2014 21:55:06
Running from C:\Users\Mänz\Downloads
Loaded Profile: Mänz (Available profiles: Mänz & Administrator)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Hi-Rez Studios) D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Users\Mänz\AppData\Local\Amazon Music\Amazon Music Helper.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Realtek) C:\Program Files (x86)\Edimax\PCIe Wireless LAN\RtlService.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\Edimax\PCIe Wireless LAN\RtWLan.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
(Flux Software LLC) C:\Users\Mänz\AppData\Local\FluxSoftware\Flux\flux.exe
() C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(Logitech(c)) C:\Program Files (x86)\Logitech\G930\G930.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Razer USA Ltd) C:\Program Files (x86)\Razer\BlackWidow\BlackWidowTray.exe
(Logitech Inc.) D:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
(Apple Inc.) D:\Program Files (x86)\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\GUI\GDSC.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AvkBap64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2463552 2014-10-04] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [GDFirewallTray] => C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe [1756792 2014-05-20] (G Data Software AG)
HKLM-x32\...\Run: [Logitech G930] => C:\Program Files (x86)\Logitech\G930\G930.exe [1516888 2011-03-23] (Logitech(c))
HKLM-x32\...\Run: [Razer Blackwidow Driver] => C:\Program Files (x86)\Razer\BlackWidow\BlackwidowTray.exe [883088 2011-03-08] (Razer USA Ltd)
HKLM-x32\...\Run: [LWS] => D:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.)
HKLM-x32\...\Run: [iTunesHelper] => D:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3835728 2014-11-03] (LogMeIn Inc.)
HKU\S-1-5-21-2436741097-1297008016-2183685444-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1938624 2014-10-21] (Valve Corporation)
HKU\S-1-5-21-2436741097-1297008016-2183685444-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [468192 2014-09-01] (Sony)
HKU\S-1-5-21-2436741097-1297008016-2183685444-1001\...\Run: [f.lux] => C:\Users\Mänz\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-2436741097-1297008016-2183685444-1001\...\Run: [Amazon Music] => C:\Users\Mänz\AppData\Local\Amazon Music\Amazon Music Helper.exe [3356480 2014-07-22] ()
Startup: C:\Users\Mänz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
Startup: C:\Users\Mänz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2436741097-1297008016-2183685444-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 10 C:\Windows\SysWOW64\PrxerNsp.dll [56424] ()
Winsock: Catalog5-x64 10 %SystemRoot%\system32\PrxerNsp.dll [57448] ()
FireFox:
========
FF ProfilePath: C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fnew.songza.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*'))%20%7B%20return%20'PROXY%20us11.sq.proxmate.me%3A8000%3B%20PROXY%20us09.sq.proxmate.me%3A8000%3B%20PROXY%20us01.sq.proxmate.me%3A8000%3B%20PROXY%20us05.sq.proxmate.me%3A8000%3B%20PROXY%20us04.sq.proxmate.me%3A8000%3B%20PROXY%20us10.sq.proxmate.me%3A8000%3B%20PROXY%20us03.sq.proxmate.me%3A8000%3B%20PROXY%20us07.sq.proxmate.me%3A8000%3B%20PROXY%20us06.sq.proxmate.me%3A8000%3B%20PROXY%20us08.sq.proxmate.me%3A8000%3B%20PROXY%20us02.sq.proxmate.me%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2436741097-1297008016-2183685444-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Mänz\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2436741097-1297008016-2183685444-1001: sony.com/MediaGoDetector -> C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll (Sony Network Entertainment International LLC)
FF Plugin HKU\S-1-5-21-2436741097-1297008016-2183685444-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\ddg.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxMate - Proxy on steroids! - C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-05-01]
FF Extension: Reddit Enhancement Suite - C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\Extensions\jid1-xUfzOsOFlzSOXg@jetpack.xpi [2014-06-27]
FF Extension: Updated Ad Blocker for Firefox 11+ - C:\Users\Mänz\AppData\Roaming\Mozilla\Firefox\Profiles\et9w0fsv.default\Extensions\{4DC70064-89E2-4a55-8FC6-E8CDEAE3618C}.xpi [2013-06-27]
Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll No File
CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File
CHR Plugin: (Unity Player) - C:\Users\Mänz\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Profile: C:\Users\Mänz\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Mänz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-09-28]
CHR Extension: (Google Drive) - C:\Users\Mänz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-09-28]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Mänz\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-12]
CHR Extension: (YouTube) - C:\Users\Mänz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-09-28]
CHR Extension: (Adblock Plus) - C:\Users\Mänz\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-02-21]
CHR Extension: (Google-Suche) - C:\Users\Mänz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-09-28]
CHR Extension: (ProxMate) - C:\Users\Mänz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifalmiidchkjjmkkbkoaibpmoeichmki [2014-08-22]
CHR Extension: (Google Wallet) - C:\Users\Mänz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-28]
CHR Extension: (Google Mail) - C:\Users\Mänz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-09-28]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2250360 2014-07-30] (G Data Software AG)
R2 AVKService; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe [914552 2013-12-19] (G Data Software AG)
R2 AVKWCtl; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlX64.exe [2683760 2014-05-20] (G Data Software AG)
S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2013-12-22] (BitRaider, LLC)
R3 GDFwSvc; C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe [3228136 2014-08-21] (G Data Software AG)
R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [700536 2014-05-20] (G Data Software AG)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-10-04] (NVIDIA Corporation)
R2 HiPatchService; D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-08-22] (Hi-Rez Studios) [File not signed]
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2014-10-21] (LogMeIn, Inc.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-10-04] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-10-04] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2013-07-16] ()
R2 RealtekSE; C:\Program Files (x86)\Edimax\PCIe Wireless LAN\RtlService.exe [36864 2010-04-16] (Realtek) [File not signed]
S2 USBDLM; C:\Program Files\USBDLM\USBDLM.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [55808 2014-09-25] (G Data Software AG)
R1 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt64.sys [20992 2014-09-25] (G Data Software AG)
R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [142336 2014-09-25] (G Data Software AG)
R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [64000 2014-09-25] (G Data Software AG)
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64512 2014-09-25] (G Data Software AG)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2014-05-15] (G Data Software)
R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [61440 2014-09-25] (G Data Software AG)
S3 LADF_BakerCOnly; C:\Windows\System32\DRIVERS\ladfBakerCamd64.sys [410184 2011-03-18] (Logitech)
S3 LADF_BakerROnly; C:\Windows\System32\DRIVERS\ladfBakerRamd64.sys [335688 2011-03-18] (Logitech)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-10-04] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation)
R3 RzSynapse; C:\Windows\System32\DRIVERS\RzSynapse.sys [115200 2010-10-15] (Razer USA Ltd)
S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X]
S3 catchme; \??\C:\combomeister\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-10 21:55 - 2014-11-10 21:55 - 00000000 ____D () C:\Users\Mänz\Downloads\FRST-OlderVersion
2014-11-10 21:52 - 2014-11-10 21:52 - 00001169 _____ () C:\Users\Mänz\Desktop\JRT.txt
2014-11-10 21:49 - 2014-11-10 21:49 - 01706808 _____ (Thisisu) C:\Users\Mänz\Downloads\JRT.exe
2014-11-10 21:49 - 2014-11-10 21:49 - 00000000 ____D () C:\Windows\ERUNT
2014-11-10 21:40 - 2014-11-10 21:44 - 00000000 ____D () C:\AdwCleaner
2014-11-10 21:40 - 2014-11-10 21:40 - 02140160 _____ () C:\Users\Mänz\Downloads\AdwCleaner_4.101.exe
2014-11-10 21:29 - 2014-11-10 21:29 - 00021983 _____ () C:\Users\Mänz\Desktop\mbam.txt
2014-11-10 21:02 - 2014-11-10 21:02 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-10 21:02 - 2014-11-10 21:02 - 00001112 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-10 21:02 - 2014-11-10 21:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-10 21:02 - 2014-11-10 21:02 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-10 21:02 - 2014-11-10 21:02 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-10 21:02 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-10 21:02 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-10 21:02 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-10 21:01 - 2014-11-10 21:01 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Mänz\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-10 16:14 - 2014-11-10 16:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-06 13:25 - 2014-11-06 13:25 - 00022240 _____ () C:\ComboFix.txt
2014-11-06 13:06 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-11-06 13:06 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-11-06 13:06 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-11-06 13:06 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-11-06 13:06 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-11-06 13:06 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-11-06 13:06 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-11-06 13:06 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-11-06 13:04 - 2014-11-06 13:26 - 00000000 ____D () C:\Qoobox
2014-11-06 13:03 - 2014-11-06 13:25 - 00000000 ____D () C:\Windows\erdnt
2014-11-06 13:03 - 2014-11-06 13:03 - 05591672 ____R (Swearware) C:\Users\Mänz\Desktop\combomeister.exe
2014-11-06 12:54 - 2014-11-06 12:54 - 05591672 _____ (Swearware) C:\Users\Mänz\Downloads\ComboFix.exe
2014-11-06 12:47 - 2014-11-06 12:47 - 00000916 _____ () C:\Users\Mänz\Desktop\Revo Uninstaller.lnk
2014-11-06 12:46 - 2014-11-06 12:46 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Mänz\Downloads\revosetup95.exe
2014-11-05 20:07 - 2014-11-10 21:55 - 00021584 _____ () C:\Users\Mänz\Downloads\FRST.txt
2014-11-05 20:07 - 2014-11-10 21:55 - 00000000 ____D () C:\FRST
2014-11-05 20:07 - 2014-11-05 20:08 - 00034761 _____ () C:\Users\Mänz\Downloads\Addition.txt
2014-11-05 20:06 - 2014-11-10 21:55 - 02116096 _____ (Farbar) C:\Users\Mänz\Downloads\FRST64.exe
2014-11-05 19:41 - 2014-11-05 19:41 - 02077392 _____ (Microsoft Corporation) C:\Users\Mänz\Downloads\IE11-Windows6.1.exe
2014-11-05 19:29 - 2014-11-05 19:29 - 00001503 _____ () C:\Users\Public\Desktop\League of Legends.lnk
2014-11-05 19:29 - 2014-11-05 19:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2014-11-05 19:28 - 2014-11-05 19:29 - 30668968 _____ (Riot Games) C:\Users\Mänz\Downloads\LeagueofLegends_EUW_Installer_9_15_2014(2).exe
2014-11-05 18:54 - 2014-11-05 18:54 - 30668968 _____ (Riot Games) C:\Users\Mänz\Downloads\LeagueofLegends_EUW_Installer_9_15_2014(1).exe
2014-11-05 15:55 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2014-11-05 15:55 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2014-11-05 15:55 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2014-11-05 15:54 - 2014-11-05 19:29 - 00000000 ____D () C:\Users\Mänz\AppData\Roaming\Riot Games
2014-11-05 15:53 - 2014-11-05 15:53 - 30668968 _____ (Riot Games) C:\Users\Mänz\Downloads\LeagueofLegends_EUW_Installer_9_15_2014.exe
2014-11-04 16:56 - 2014-11-04 16:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-11-04 16:56 - 2014-11-04 16:56 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-11-02 03:45 - 2014-11-02 03:45 - 00000210 _____ () C:\Users\Mänz\Desktop\beste idee.txt
2014-10-30 17:47 - 2014-10-30 17:48 - 01125200 _____ () C:\Users\Mänz\Downloads\Tor Vidalia Bridge Bundle - CHIP-Installer.exe
2014-10-29 22:31 - 2014-10-31 11:31 - 00000000 ____D () C:\ProgramData\HuceQpok
2014-10-22 20:10 - 2014-10-04 07:42 - 01291280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2014-10-22 20:10 - 2014-10-04 07:41 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-10-22 20:10 - 2014-09-04 20:14 - 00038048 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-10-22 20:10 - 2014-09-04 20:14 - 00032416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-10-16 13:55 - 2014-10-16 13:55 - 00752533 _____ () C:\Users\Mänz\Downloads\Textredaktion_neu.pptx
2014-10-16 13:46 - 2014-10-10 03:05 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-16 13:46 - 2014-10-10 03:05 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-16 13:46 - 2014-10-10 03:00 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-16 13:46 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-16 13:46 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-10-16 13:46 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-16 13:46 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-16 13:46 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-10-16 13:46 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-10-16 13:46 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-10-16 13:46 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-10-16 13:46 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-10-16 13:46 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-16 13:46 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-16 13:46 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-16 13:46 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-16 13:46 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-10-16 13:46 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-16 13:46 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-16 13:46 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-16 13:46 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-16 13:46 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-16 13:46 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-16 13:46 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-16 13:46 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-16 13:46 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-16 13:46 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-16 13:46 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-10-16 13:46 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-16 13:46 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-16 13:46 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-16 13:46 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-10-16 13:46 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-16 13:46 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-16 13:46 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-10-16 13:46 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-16 13:46 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-10-16 13:46 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-10-16 13:46 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-16 13:46 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-10-16 13:46 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-16 13:46 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-10-16 13:46 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-10-16 13:46 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-10-16 13:46 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-10-16 13:46 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-10-16 13:46 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-10-16 13:46 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-16 13:46 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-16 13:46 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-16 13:46 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-16 13:46 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-16 13:46 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-10-16 13:46 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-10-16 13:46 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-10-16 13:46 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-16 13:46 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-10-16 13:46 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-16 13:46 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-10-16 13:46 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-10-16 13:46 - 2014-09-18 03:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-16 13:46 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-10-16 13:46 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-16 13:46 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-10-16 13:46 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-16 13:46 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-10-16 13:46 - 2014-07-17 03:07 - 03722240 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-16 13:46 - 2014-07-17 03:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-10-16 13:46 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-16 13:46 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-16 13:46 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-16 13:46 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-16 13:46 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-16 13:46 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-16 13:46 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-10-16 13:46 - 2014-07-17 02:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-10-16 13:46 - 2014-07-17 02:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-10-16 13:46 - 2014-07-17 02:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-10-16 13:46 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-10-16 13:46 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-10-16 13:46 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-16 13:46 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-16 13:46 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-16 13:46 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-10-16 13:46 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-10-16 13:46 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-16 13:46 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-10-16 13:46 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-15 12:04 - 2014-10-15 12:04 - 00000000 ____D () C:\Users\Mänz\Desktop\Neuer Ordner
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-10 21:55 - 2013-12-09 02:53 - 00000000 ____D () C:\Users\Mänz\AppData\Local\Battle.net
2014-11-10 21:53 - 2009-07-14 05:45 - 00028720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-10 21:53 - 2009-07-14 05:45 - 00028720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-10 21:47 - 2014-08-01 21:06 - 00000000 ____D () C:\Users\Mänz\AppData\Local\Deployment
2014-11-10 21:46 - 2013-08-10 21:40 - 00000000 ____D () C:\Users\Mänz\AppData\Local\LogMeIn Hamachi
2014-11-10 21:46 - 2013-03-26 10:16 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-11-10 21:45 - 2014-08-28 14:52 - 00016679 _____ () C:\Windows\setupact.log
2014-11-10 21:45 - 2013-09-28 12:33 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-10 21:45 - 2013-04-02 13:26 - 00223838 _____ () C:\Windows\PFRO.log
2014-11-10 21:45 - 2013-04-01 17:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-10 21:45 - 2013-03-25 17:16 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-11-10 21:45 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-10 21:44 - 2013-03-25 16:47 - 01182258 _____ () C:\Windows\WindowsUpdate.log
2014-11-10 21:29 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\TAPI
2014-11-10 21:26 - 2013-09-28 12:33 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-10 21:04 - 2013-04-01 17:35 - 00000000 ____D () C:\Users\Mänz\AppData\Roaming\Skype
2014-11-10 21:00 - 2013-05-28 16:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-10 16:11 - 2014-09-08 15:44 - 00000000 ____D () C:\Users\Mänz\AppData\Roaming\Spotify
2014-11-09 13:34 - 2011-04-12 08:43 - 00699416 _____ () C:\Windows\system32\perfh007.dat
2014-11-09 13:34 - 2011-04-12 08:43 - 00149556 _____ () C:\Windows\system32\perfc007.dat
2014-11-09 13:34 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-08 21:15 - 2014-09-08 15:44 - 00000000 ____D () C:\Users\Mänz\AppData\Local\Spotify
2014-11-06 15:37 - 2013-05-21 20:57 - 00000000 ____D () C:\Users\Mänz\AppData\Roaming\TS3Client
2014-11-06 13:26 - 2014-08-01 21:06 - 00000000 ____D () C:\Users\Mänz\AppData\Local\Apps\2.0
2014-11-06 13:26 - 2013-04-27 16:56 - 00000000 ____D () C:\Users\M�nz
2014-11-06 13:26 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-11-06 13:20 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-11-05 19:41 - 2013-12-03 10:11 - 00011536 _____ () C:\Windows\IE11_main.log
2014-11-05 18:53 - 2014-07-12 06:49 - 00000000 ____D () C:\Users\Mänz\AppData\Local\CrashDumps
2014-11-05 15:47 - 2013-03-25 17:06 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-11-01 17:01 - 2013-04-02 15:05 - 00000000 ____D () C:\Users\Mänz\Desktop\Hntrgrnd
2014-10-28 21:27 - 2013-09-28 12:33 - 00002181 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-10-28 15:35 - 2013-08-06 01:40 - 00000000 ____D () C:\Users\Mänz\AppData\Roaming\.minecraft
2014-10-28 06:34 - 2010-11-21 04:27 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-22 20:11 - 2014-04-22 17:29 - 00000000 ____D () C:\Users\Mänz\AppData\Local\NVIDIA Corporation
2014-10-22 20:10 - 2013-03-25 17:12 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-10-20 18:10 - 2014-09-12 16:28 - 00000000 ____D () C:\Windows\rescache
2014-10-20 15:21 - 2013-09-28 12:33 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-20 15:21 - 2013-09-28 12:33 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-19 19:54 - 2014-10-09 20:00 - 00014081 _____ () C:\Users\Mänz\Desktop\Vorlesungsverzeichnis.ods
2014-10-17 12:43 - 2009-07-14 05:45 - 00297232 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-17 03:49 - 2014-05-07 02:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-17 02:04 - 2013-07-19 00:09 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-17 02:00 - 2013-03-25 17:56 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-15 13:17 - 2014-03-19 01:46 - 00000000 ____D () C:\Users\Mänz\Desktop\awwwww
2014-10-15 12:05 - 2013-09-28 16:30 - 00000000 ____D () C:\Users\Mänz\Desktop\Uni
2014-10-14 17:15 - 2014-08-17 00:22 - 00003246 _____ () C:\Windows\System32\Tasks\SidebarExecute
2014-10-11 17:37 - 2013-08-02 16:12 - 00289086 _____ () C:\Windows\DPINST.LOG
2014-10-11 17:36 - 2014-09-19 17:24 - 00002032 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2014-10-11 17:36 - 2014-04-19 09:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
Some content of TEMP:
====================
C:\Users\Mänz\AppData\Local\Temp\Quarantine.exe
C:\Users\Mänz\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Mänz\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-05 16:54
==================== End Of Log ============================ --- --- --- |