Hallo und frohe Weihnachten!
Hier das Anwendungsprotokoll von MBAM Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 26.12.2014
Suchlauf-Zeit: 16:01:45
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2014.12.26.07
Rootkit Datenbank: v2014.12.23.02
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Wilhelm
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 498317
Verstrichene Zeit: 26 Min, 48 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1512, Löschen bei Neustart, [5a15a6c1bfbd50e67fd84e73897808f8]
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 17
PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, In Quarantäne, [5a15a6c1bfbd50e67fd84e73897808f8],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [49260562601c1125db44746a16ecc33d],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [49260562601c1125db44746a16ecc33d],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [3936b4b36913f93d8ab9358b51b3c739],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [3a358add7dff11252c6f9b3913f1af51],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, In Quarantäne, [f17e2f389ce0270fdc762171c93a15eb],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, In Quarantäne, [2946184f4d2f1224f1b7a7d048bbb050],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [db940166423a30061b28c4fc06fe619f],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, In Quarantäne, [f7781c4b89f35cda8c0b37a0778d58a8],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, In Quarantäne, [75fa93d4a2da4cead4c414c3d034ce32],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, In Quarantäne, [90df590e314bc76f7915e77d1ae910f0],
PUP.Optional.ICinema.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\I - Cinema-nv, In Quarantäne, [59166601f686ce68980e74fddb28af51],
PUP.Optional.ICinema.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\I - Cinema, In Quarantäne, [4a25a0c7512b10266045432ee023de22],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2955863073-899098632-722755702-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\BlockAndSurf, In Quarantäne, [353a184ff28add59c8c99bd9e91ab050],
PUP.Optional.MultiIE.A, HKU\S-1-5-21-2955863073-899098632-722755702-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\DynConIE, In Quarantäne, [3639ec7bdd9f9a9c95707d55c341df21],
PUP.Optional.Qone8, HKU\S-1-5-21-2955863073-899098632-722755702-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [bcb3de89186482b41f232b957a8ab54b],
PUP.Optional.FastStart.A, HKU\S-1-5-21-2955863073-899098632-722755702-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS, In Quarantäne, [fe71cb9c5d1f7abcec902b413ec5f808],
Registrierungswerte: 3
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, In Quarantäne, [2946184f4d2f1224f1b7a7d048bbb050]
PUP.Optional.FastStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com, In Quarantäne, [274883e4106cb383981da42f1de7fa06]
PUP.Optional.FastStart.A, HKU\S-1-5-21-2955863073-899098632-722755702-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, In Quarantäne, [fe71cb9c5d1f7abcec902b413ec5f808]
Registrierungsdaten: 8
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1418585457&from=cvs&uid=WDCXWD3200BPVT-24JJ5T0_WD-WXC1C12V9918V9918, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418585457&from=cvs&uid=WDCXWD3200BPVT-24JJ5T0_WD-WXC1C12V9918V9918),Ersetzt,[b6b9d097205c95a1bd77f083e91c3dc3]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[a1ce87e0daa257df193cfa8318ed8e72]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1418585457&from=cvs&uid=WDCXWD3200BPVT-24JJ5T0_WD-WXC1C12V9918V9918&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1418585457&from=cvs&uid=WDCXWD3200BPVT-24JJ5T0_WD-WXC1C12V9918V9918&q={searchTerms}),Ersetzt,[214e3334d4a84aec4de5a4cf29dc2cd4]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1418585457&from=cvs&uid=WDCXWD3200BPVT-24JJ5T0_WD-WXC1C12V9918V9918, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418585457&from=cvs&uid=WDCXWD3200BPVT-24JJ5T0_WD-WXC1C12V9918V9918),Ersetzt,[4c2394d35c20c76f240c87ec36cf1ee2]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1418585457&from=cvs&uid=WDCXWD3200BPVT-24JJ5T0_WD-WXC1C12V9918V9918, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418585457&from=cvs&uid=WDCXWD3200BPVT-24JJ5T0_WD-WXC1C12V9918V9918),Ersetzt,[83ec4522f3890a2c93a1cfa4897cf20e]
PUP.Optional.WebSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1418585457&from=cvs&uid=WDCXWD3200BPVT-24JJ5T0_WD-WXC1C12V9918V9918&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1418585457&from=cvs&uid=WDCXWD3200BPVT-24JJ5T0_WD-WXC1C12V9918V9918&q={searchTerms}),Ersetzt,[204f6cfbbebe7abc054a4639d332bc44]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[6a050067a7d584b2e2735924a85dab55]
PUP.Optional.WebsSearches.A, HKU\S-1-5-21-2955863073-899098632-722755702-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1418585457&from=cvs&uid=WDCXWD3200BPVT-24JJ5T0_WD-WXC1C12V9918V9918, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1418585457&from=cvs&uid=WDCXWD3200BPVT-24JJ5T0_WD-WXC1C12V9918V9918),Ersetzt,[fc73293ea3d9bd794ce9ec87fe07ba46]
Ordner: 36
PUP.Optional.PicColor.A, C:\ProgramData\PicColorData, In Quarantäne, [e887a2c5a0dc78be38a47de2f80b659b],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\include, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\include\tools, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\js\lib, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\js\module, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\js\pack, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\en, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\en-US, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\es, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\es-419, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\fr, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\fr-BE, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\fr-CA, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\fr-CH, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\fr-LU, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\it, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\it-CH, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\pl, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\pt-BR, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\ru, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\ru-MO, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\tr, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\vi, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\zh-CN, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\zh-TW, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\skin, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\defaults, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\defaults\preferences, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\modules, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Löschen bei Neustart, [caa53433d5a710262ff741fd758e7e82],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [caa53433d5a710262ff741fd758e7e82],
Dateien: 78
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Löschen bei Neustart, [5a15a6c1bfbd50e67fd84e73897808f8],
PUP.Optional.HDQuality.A, C:\Users\Wilhelm\AppData\Roaming\PEHLZF.exe, In Quarantäne, [c0af5413c0bc59ddef19eee2bb46ed13],
PUP.Optional.HDQuality.A, C:\Users\Wilhelm\AppData\Roaming\WNOTDII.exe, In Quarantäne, [1857bdaafb81a78f50b8626ec839718f],
PUP.Optional.OpenCandy, C:\Users\Wilhelm\Downloads\DTLite4454-0314.exe, In Quarantäne, [f679fa6d7ffd7fb7364682215aabed13],
PUP.Optional.DownloadGuide, C:\Users\Wilhelm\Downloads\download-adblock-chrome (1).exe, In Quarantäne, [90df13548cf00531f1470eeaef12d030],
PUP.Optional.DownloadGuide, C:\Users\Wilhelm\Downloads\download-adblock-chrome.exe, In Quarantäne, [0867303706760d296bcda355bf42768a],
PUP.Optional.PicColor.A, C:\ProgramData\PicColorData\Config.bin.bus, In Quarantäne, [e887a2c5a0dc78be38a47de2f80b659b],
PUP.Optional.PicColor.A, C:\ProgramData\PicColorData\Config.bin, In Quarantäne, [e887a2c5a0dc78be38a47de2f80b659b],
PUP.Optional.WebSearchs.A, C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_istart.webssearches.com_0.localstorage, In Quarantäne, [f8778fd892eae3531e492c4ba95a7a86],
PUP.Optional.WebSearchs.A, C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_istart.webssearches.com_0.localstorage-journal, In Quarantäne, [b1be7cebdba153e36106db9cd72ce61a],
PUP.Optional.SelectNGo.A, C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage, In Quarantäne, [eb8481e6a3d96dc9a705c1c26c97649c],
PUP.Optional.SelectNGo.A, C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage-journal, In Quarantäne, [91def86f324a8bab911b5e25db28d12f],
PUP.Optional.WebsSearches.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\webssearches.xml, In Quarantäne, [c5aa9fc883f9c96da0b431618e759b65],
PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMedia.ini, In Quarantäne, [c2ad8bdc225a80b6c4539446b450c33d],
PUP.Optional.ColorMedia.A, C:\Windows\System32\ColorMediaOff.ini, In Quarantäne, [1e517cebfe7e2d093ade5f7b3dc7db25],
PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMediaOff.ini, In Quarantäne, [37382740fa82a88ec8506c6e05ff25db],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome.manifest, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\install.rdf, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\index.html, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\quick_start.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\quick_start.xul, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\include\speed_dial.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\include\tools\about_blank_hook.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\include\tools\misc.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\include\tools\popup_image_helper.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\include\tools\urlrequestor.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\js\js.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\js\lib\doT.min.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\js\lib\jquery-2.1.0.min.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\js\lib\jquery.autocomplete.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\js\module\hotSearch.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\js\module\mostgrid.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\js\module\search.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\js\module\stat.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\js\pack\common.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\js\pack\ga.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\content\js\pack\xagainit.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\en\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\en-US\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\es\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\es-419\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\fr\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\fr-BE\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\fr-CA\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\fr-CH\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\fr-LU\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\it\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\it-CH\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\pl\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\pt-BR\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\ru\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\ru-MO\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\tr\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\vi\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\zh-CN\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\locale\zh-TW\locale.properties, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\skin\default_logo.png, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\skin\googlelogo.png, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\skin\google_trends.png, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\skin\icon.png, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\skin\loading.gif, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\skin\logo.png, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\skin\newtab.ico, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\skin\simple.css, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\chrome\skin\style.css, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\defaults\preferences\fvd.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\defaults\preferences\preferences.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\modules\addonmanager.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\modules\aes.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\modules\config.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\modules\dialogs.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\modules\last_tab.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\modules\misc.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\modules\properties.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\modules\remoterequest.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\modules\restoreprefs.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.FastStart.A, C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\extensions\faststartff@gmail.com\modules\settings.js, In Quarantäne, [5a154d1a4537b97d549857e55ca7e917],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [caa53433d5a710262ff741fd758e7e82],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Hier die Logdatei vom Adwcleaner Code:
# AdwCleaner v4.106 - Bericht erstellt am 26/12/2014 um 17:00:29
# Aktualisiert 21/12/2014 von Xplode
# Database : 2014-12-21.4 [Live]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Wilhelm - WILHELM-PC
# Gestartet von : C:\Users\Wilhelm\Downloads\AdwCleaner_4.106.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : globalUpdatem
Dienst Gelöscht : vToolbarUpdater18.1.9
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\AVG Secure Search
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\PurpleRain
Ordner Gelöscht : C:\Program Files (x86)\AVG Secure Search
Ordner Gelöscht : C:\Program Files (x86)\AVG Security Toolbar
Ordner Gelöscht : C:\Program Files (x86)\Common Files\AVG Secure Search
Ordner Gelöscht : C:\Users\Wilhelm\AppData\Local\AVG Secure Search
Ordner Gelöscht : C:\Users\Wilhelm\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Wilhelm\AppData\LocalLow\AVG Secure Search
Ordner Gelöscht : C:\Users\Wilhelm\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\Wilhelm\Documents\Optimizer Pro
Ordner Gelöscht : C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Datei Gelöscht : C:\Users\Wilhelm\Desktop\Continue Live Installation.lnk
Datei Gelöscht : C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\user.js
Datei Gelöscht : C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage-journal
***** [ Tasks ] *****
Task Gelöscht : LaunchSignup
Task Gelöscht : Run_Bobby_Browser
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] ***** und Junkware Removal Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 7 Home Premium x64
Ran by Wilhelm on 26.12.2014 at 17:09:04,80
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Wilhelm\appdata\local\{0DCEB829-DA43-44EB-8CE7-C09227A31874}
Successfully deleted: [Empty Folder] C:\Users\Wilhelm\appdata\local\{314344E7-67FC-40B9-8243-BADD95A0842F}
Successfully deleted: [Empty Folder] C:\Users\Wilhelm\appdata\local\{3ECC254A-CF59-4A53-A5FB-8D37D1BF7F49}
Successfully deleted: [Empty Folder] C:\Users\Wilhelm\appdata\local\{54773F7E-BF16-4A2F-AB5D-90658B8DDBA3}
Successfully deleted: [Empty Folder] C:\Users\Wilhelm\appdata\local\{5672F370-3677-4FA2-91A6-1894CE1419FD}
Successfully deleted: [Empty Folder] C:\Users\Wilhelm\appdata\local\{6E1F388D-47BD-46E0-962F-FD67181A2FBF}
Successfully deleted: [Empty Folder] C:\Users\Wilhelm\appdata\local\{7B72FA56-3671-49A3-9748-BC087A81C63F}
Successfully deleted: [Empty Folder] C:\Users\Wilhelm\appdata\local\{AAB7FF2C-7113-41A9-9828-51E62094A5D4}
Successfully deleted: [Empty Folder] C:\Users\Wilhelm\appdata\local\{D46CC2FE-FB54-4017-AF4F-D15C77625CA9}
Successfully deleted: [Empty Folder] C:\Users\Wilhelm\appdata\local\{EC087281-0A5F-4955-94EB-D30461A17AA1}
Successfully deleted: [Empty Folder] C:\Users\Wilhelm\appdata\local\{F216C47D-584F-4518-B15F-198EDADCC88C}
~~~ FireFox
Emptied folder: C:\Users\Wilhelm\AppData\Roaming\mozilla\firefox\profiles\wuyinxuy.default\minidumps [7 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26.12.2014 at 17:13:48,07
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-12-2014
Ran by Wilhelm (administrator) on WILHELM-PC on 26-12-2014 17:23:08
Running from C:\Users\Wilhelm\Downloads
Loaded Profile: Wilhelm (Available profiles: Wilhelm)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Egis Technology Inc. ) C:\Program Files (x86)\EgisTec Port Locker\Egishlpsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GbR) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510d series\Bin\ScanToPCActivationApp.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Egis Technology Inc. ) C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11772520 2011-01-04] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2588968 2011-02-14] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9768352 2012-04-13] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5940128 2012-04-13] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [206176 2012-04-13] (Lenovo)
HKLM-x32\...\Run: [PLTSR] => C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe [364400 2010-10-22] (Egis Technology Inc. )
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [87336 2010-02-03] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3667472 2014-12-18] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2955863073-899098632-722755702-1001\...\Run: [HP Photosmart 5510d series (NET)] => C:\Program Files\HP\HP Photosmart 5510d series\Bin\ScanToPCActivationApp.exe [2676584 2011-08-16] (Hewlett-Packard Co.)
HKU\S-1-5-21-2955863073-899098632-722755702-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
Startup: C:\Users\Wilhelm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Wilhelm\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Wilhelm\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Wilhelm\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Wilhelm\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Wilhelm\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Wilhelm\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Wilhelm\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll (Dropbox, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-2955863073-899098632-722755702-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:59089;https=127.0.0.1:59089
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2955863073-899098632-722755702-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2955863073-899098632-722755702-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: PDF Architect Helper -> {3A2D5EBA-F86D-4BD3-A177-019765996711} -> C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default
FF NewTab: google.de
FF Homepage: google.de
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Adblock Plus - C:\Users\Wilhelm\AppData\Roaming\Mozilla\Firefox\Profiles\wuyinxuy.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-09-18]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2012-12-13]
Chrome:
=======
CHR HomePage: Default -> hxxp://istart.webssearches.com/?type=hp&ts=1418585457&from=cvs&uid=WDCXWD3200BPVT-24JJ5T0_WD-WXC1C12V9918V9918
CHR StartupUrls: Default -> "hxxp://googl.de/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-23]
CHR Extension: (Google Docs) - C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-05-10]
CHR Extension: (Google Drive) - C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-10]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-04]
CHR Extension: (YouTube) - C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-05-10]
CHR Extension: (Adblock Plus) - C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-05-12]
CHR Extension: (Google-Suche) - C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-05-10]
CHR Extension: (Google Tabellen) - C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-23]
CHR Extension: (mimhmidgldhoghjoehfigallmmndjkef) - C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Extensions\mimhmidgldhoghjoehfigallmmndjkef [2014-12-21]
CHR Extension: (Google Wallet) - C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Google Mail) - C:\Users\Wilhelm\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-05-10]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3432976 2014-12-18] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [298080 2014-12-18] (AVG Technologies CZ, s.r.o.)
R2 EgisTec Service Help; C:\Program Files (x86)\EgisTec Port Locker\Egishlpsvc.exe [327024 2010-10-22] (Egis Technology Inc. )
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1522312 2012-11-22] (pdfforge GbR)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [905864 2012-11-22] (pdfforge GbR)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [260888 2014-12-08] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [203544 2014-11-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [313624 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [124184 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [274200 2014-10-10] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [50976 2014-08-07] (AVG Technologies)
S3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-26] (Malwarebytes Corporation)
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8200552 2010-12-15] (Realtek Semiconductor Corp.)
U3 BcmSqlStartupSvc; No ImagePath
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
U2 CLKMSVC10_3A60B698; No ImagePath
U2 CLKMSVC10_C3B3B687; No ImagePath
U2 DriverService; No ImagePath
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
U2 IAStorDataMgrSvc; No ImagePath
U2 iATAgentService; No ImagePath
U2 idealife Update Service; No ImagePath
U3 IGRS; No ImagePath
U2 IviRegMgr; No ImagePath
U2 nvUpdatusService; No ImagePath
U2 Oasis2Service; No ImagePath
U2 PCCarerService; No ImagePath
U2 ReadyComm.DirectRouter; No ImagePath
U2 RichVideo; No ImagePath
U2 RtLedService; No ImagePath
U2 SeaPort; No ImagePath
U2 SoftwareService; No ImagePath
U3 SQLWriter; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-26 17:23 - 2014-12-26 17:23 - 00000000 ____D () C:\Users\Wilhelm\Downloads\FRST-OlderVersion
2014-12-26 17:13 - 2014-12-26 17:14 - 00001950 _____ () C:\Users\Wilhelm\Desktop\JRT.txt
2014-12-26 17:09 - 2014-12-26 17:09 - 00000000 ____D () C:\windows\ERUNT
2014-12-26 17:08 - 2014-12-26 17:08 - 01707646 _____ (Thisisu) C:\Users\Wilhelm\Downloads\JRT.exe
2014-12-26 17:03 - 2014-12-26 17:03 - 00016342 _____ () C:\Users\Wilhelm\Desktop\AdwCleaner[S0].txt
2014-12-26 16:55 - 2014-12-26 17:00 - 00000000 ____D () C:\AdwCleaner
2014-12-26 16:54 - 2014-12-26 16:54 - 02173952 _____ () C:\Users\Wilhelm\Downloads\AdwCleaner_4.106.exe
2014-12-26 16:52 - 2014-12-26 16:52 - 00030886 _____ () C:\Users\Wilhelm\Desktop\mbam.txt
2014-12-23 09:53 - 2014-12-23 10:24 - 00000000 ____D () C:\Qoobox
2014-12-23 09:53 - 2014-12-23 10:22 - 00000000 ____D () C:\windows\erdnt
2014-12-23 09:53 - 2011-06-26 07:45 - 00256000 _____ () C:\windows\PEV.exe
2014-12-23 09:53 - 2010-11-07 18:20 - 00208896 _____ () C:\windows\MBR.exe
2014-12-23 09:53 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2014-12-23 09:53 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2014-12-23 09:53 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2014-12-23 09:53 - 2000-08-31 01:00 - 00098816 _____ () C:\windows\sed.exe
2014-12-23 09:53 - 2000-08-31 01:00 - 00080412 _____ () C:\windows\grep.exe
2014-12-23 09:53 - 2000-08-31 01:00 - 00068096 _____ () C:\windows\zip.exe
2014-12-23 09:49 - 2014-12-23 09:50 - 05601641 ____R (Swearware) C:\Users\Wilhelm\Desktop\ComboFix.exe
2014-12-23 00:11 - 2014-12-23 00:11 - 00000959 _____ () C:\Users\Wilhelm\Downloads\avg-erkennungen.txt
2014-12-23 00:01 - 2014-12-23 00:01 - 00006598 _____ () C:\Users\Wilhelm\Downloads\gmer.txt
2014-12-22 23:46 - 2014-12-22 23:47 - 00380416 _____ () C:\Users\Wilhelm\Downloads\Gmer-19357.exe
2014-12-22 23:44 - 2014-12-22 23:44 - 00034206 _____ () C:\Users\Wilhelm\Downloads\Addition.txt
2014-12-22 23:43 - 2014-12-26 17:23 - 00018537 _____ () C:\Users\Wilhelm\Downloads\FRST.txt
2014-12-22 23:43 - 2014-12-26 17:23 - 00000000 ____D () C:\FRST
2014-12-22 23:41 - 2014-12-26 17:23 - 02122752 _____ (Farbar) C:\Users\Wilhelm\Downloads\FRST64.exe
2014-12-22 23:40 - 2014-12-22 23:40 - 00000476 _____ () C:\Users\Wilhelm\Downloads\defogger_disable.log
2014-12-22 23:40 - 2014-12-22 23:40 - 00000000 _____ () C:\Users\Wilhelm\defogger_reenable
2014-12-22 23:37 - 2014-12-22 23:38 - 00050477 _____ () C:\Users\Wilhelm\Downloads\Defogger.exe
2014-12-22 23:00 - 2014-12-26 16:50 - 00129752 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-22 23:00 - 2014-12-22 23:00 - 00001062 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-22 23:00 - 2014-12-22 23:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-22 23:00 - 2014-12-22 23:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-22 23:00 - 2014-12-22 23:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-22 23:00 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-12-22 23:00 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-12-22 23:00 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-12-22 22:58 - 2014-12-22 22:58 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Wilhelm\Downloads\mbam-setup-2.0.4.1028.exe
2014-12-22 22:55 - 2014-12-22 22:55 - 00002748 _____ () C:\Users\Wilhelm\Desktop\schädlinge.csv
2014-12-22 20:27 - 2014-12-22 20:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-21 12:01 - 2014-12-22 22:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak
2014-12-20 14:47 - 2014-12-20 14:47 - 00000941 _____ () C:\Users\Public\Desktop\AVG 2015.lnk
2014-12-20 14:27 - 2014-12-20 14:35 - 159747880 _____ (AVG Technologies) C:\Users\Wilhelm\Downloads\avg_free_x86_all_2015_5645a8758.exe
2014-12-20 14:23 - 2014-12-20 14:23 - 00002152 _____ () C:\Users\Wilhelm\Desktop\chrome.lnk
2014-12-18 07:39 - 2014-12-18 07:39 - 00000000 ____D () C:\Users\Wilhelm\Desktop\Sansibar
2014-12-18 07:39 - 2014-12-18 07:39 - 00000000 ____D () C:\Users\Wilhelm\Desktop\privat
2014-12-18 07:39 - 2014-12-18 07:39 - 00000000 ____D () C:\Users\Wilhelm\Desktop\Dar es Salaam
2014-12-18 07:06 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-12-18 07:06 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-12-17 17:36 - 2014-12-17 17:36 - 00002225 _____ () C:\windows\patsearch.bin
2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_webinstrNewH_01009.Wdf
2014-12-14 20:34 - 2014-12-14 20:34 - 00000000 ____D () C:\Users\Wilhelm\AppData\Roaming\dlg
2014-12-14 20:32 - 2014-12-14 20:32 - 00000000 ____D () C:\windows\System32\Tasks\PurpleRain
2014-12-14 20:31 - 2014-12-14 10:53 - 00378640 _____ (CartCrunch Israel Ltd.) C:\windows\system32\ColorMedia64.dll
2014-12-14 20:31 - 2014-12-14 10:53 - 00332568 _____ (CartCrunch Israel Ltd.) C:\windows\SysWOW64\ColorMedia.dll
2014-12-13 08:22 - 2014-12-13 08:22 - 00003096 _____ () C:\windows\System32\Tasks\{D075EB54-7F73-425D-8537-55DFB5FFDC44}
2014-12-10 22:39 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2014-12-10 22:39 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2014-12-10 22:39 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2014-12-10 22:39 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2014-12-10 22:39 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2014-12-10 22:39 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2014-12-10 22:39 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2014-12-10 22:39 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2014-12-10 22:39 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2014-12-10 22:39 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2014-12-10 21:38 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-12-10 21:38 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-12-10 21:38 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-12-10 21:38 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-12-10 21:38 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-12-10 21:38 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-12-10 21:38 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-12-10 21:38 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-12-10 21:38 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-12-10 21:38 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-12-10 21:38 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-12-10 21:38 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-12-10 21:38 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-12-10 21:38 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-12-10 21:38 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-12-10 21:38 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-12-10 21:38 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-12-10 21:38 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-12-10 21:38 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-12-10 21:38 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-12-10 21:38 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 21:38 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-12-10 21:38 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-12-10 21:38 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-12-10 21:38 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-12-10 21:38 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-12-10 21:38 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-12-10 21:38 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-12-10 21:38 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-12-10 21:38 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-12-10 21:38 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-12-10 21:38 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-12-10 21:38 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-12-10 21:38 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-12-10 21:38 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-12-10 21:38 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-12-10 21:38 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-12-10 21:38 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-12-10 21:38 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-12-10 21:38 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-10 21:38 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-12-10 21:38 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-12-10 21:38 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-12-10 21:38 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-12-10 21:38 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-12-10 21:38 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-12-10 21:38 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-12-10 21:38 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-12-10 21:38 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-12-10 21:38 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-12-10 21:38 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-12-10 21:38 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-12-10 21:38 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-12-10 21:38 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-12-10 18:06 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2014-12-10 18:06 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2014-12-10 18:06 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2014-12-10 18:06 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2014-12-10 18:06 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2014-12-10 18:01 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\windows\system32\charmap.exe
2014-12-10 18:01 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\windows\SysWOW64\charmap.exe
2014-12-10 18:01 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll
2014-12-10 18:01 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll
2014-12-10 18:01 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll
2014-12-10 18:01 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll
2014-12-10 18:01 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe
2014-12-10 18:01 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmSvc.dll
2014-12-10 18:01 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-10 18:01 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmWmiPl.dll
2014-12-10 18:01 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmAuto.dll
2014-12-10 18:01 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManHTTPConfig.exe
2014-12-08 21:24 - 2014-12-08 21:24 - 00260888 _____ (AVG Technologies CZ, s.r.o.) C:\windows\system32\Drivers\avgidsdrivera.sys
2014-12-06 08:05 - 2014-12-18 19:09 - 00000000 ____D () C:\Users\TEMP.Wilhelm-PC.001
2014-12-06 08:05 - 2014-12-06 20:17 - 00000000 ___RD () C:\Users\TEMP.Wilhelm-PC.001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-12-06 08:05 - 2014-12-06 20:17 - 00000000 ___RD () C:\Users\TEMP.Wilhelm-PC.001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-06 08:05 - 2014-12-06 20:17 - 00000000 ____D () C:\Users\TEMP.Wilhelm-PC.001\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2014-12-06 08:05 - 2012-10-13 11:01 - 00000000 ____D () C:\Users\TEMP.Wilhelm-PC.001\AppData\Roaming\TuneUp Software
2014-12-06 08:05 - 2012-06-09 18:08 - 00000000 ____D () C:\Users\TEMP.Wilhelm-PC.001\AppData\Local\Microsoft Help
2014-12-06 08:05 - 2010-12-19 06:31 - 00000189 _____ () C:\Users\TEMP.Wilhelm-PC.001\Desktop\Lenovo Telephony Start Now.url
2014-12-01 21:29 - 2014-12-01 21:29 - 00000000 ____D () C:\Users\Wilhelm\AppData\Roaming\AVG2015
2014-12-01 21:24 - 2014-12-20 14:46 - 00000000 ____D () C:\ProgramData\AVG2015
2014-12-01 21:18 - 2014-12-20 15:12 - 00000000 ____D () C:\Users\Wilhelm\AppData\Local\Avg2015
2014-11-30 09:21 - 2014-11-30 09:21 - 00000941 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-26 17:11 - 2012-07-01 16:47 - 00000000 ____D () C:\Users\Wilhelm\AppData\Roaming\Skype
2014-12-26 17:10 - 2009-07-14 05:45 - 00021280 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-26 17:10 - 2009-07-14 05:45 - 00021280 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-26 17:08 - 2012-04-14 05:43 - 00699682 _____ () C:\windows\system32\perfh007.dat
2014-12-26 17:08 - 2012-04-14 05:43 - 00149790 _____ () C:\windows\system32\perfc007.dat
2014-12-26 17:08 - 2009-07-14 06:13 - 01620684 _____ () C:\windows\system32\PerfStringBackup.INI
2014-12-26 17:03 - 2012-04-13 22:44 - 00210218 _____ () C:\windows\system32\fastboot.set
2014-12-26 17:03 - 2012-04-13 22:40 - 00001106 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-26 17:02 - 2010-11-21 04:47 - 00265428 _____ () C:\windows\PFRO.log
2014-12-26 17:02 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-12-26 17:02 - 2009-07-14 05:51 - 00158805 _____ () C:\windows\setupact.log
2014-12-26 17:01 - 2012-04-13 21:50 - 01226442 _____ () C:\windows\WindowsUpdate.log
2014-12-26 16:51 - 2012-04-13 22:40 - 00001110 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-26 16:38 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\Web
2014-12-26 16:32 - 2012-08-08 21:18 - 00000000 ____D () C:\ProgramData\MFAData
2014-12-26 11:00 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\NDF
2014-12-23 10:24 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-12-23 10:15 - 2009-07-14 03:34 - 00000215 _____ () C:\windows\system.ini
2014-12-23 10:13 - 2009-07-14 03:34 - 74448896 _____ () C:\windows\system32\config\software.bak
2014-12-23 10:13 - 2009-07-14 03:34 - 24379392 _____ () C:\windows\system32\config\system.bak
2014-12-23 10:13 - 2009-07-14 03:34 - 00524288 _____ () C:\windows\system32\config\default.bak
2014-12-23 10:13 - 2009-07-14 03:34 - 00262144 _____ () C:\windows\system32\config\security.bak
2014-12-23 10:13 - 2009-07-14 03:34 - 00262144 _____ () C:\windows\system32\config\sam.bak
2014-12-23 00:03 - 2013-06-09 21:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-22 23:47 - 2013-04-22 18:11 - 00000000 ____D () C:\Users\Wilhelm\AppData\Roaming\vlc
2014-12-22 23:40 - 2012-06-08 23:46 - 00000000 ____D () C:\Users\Wilhelm
2014-12-22 23:26 - 2013-09-03 19:52 - 00000000 ____D () C:\Users\Wilhelm\AppData\Roaming\dvdcss
2014-12-21 21:09 - 2013-12-28 11:15 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-12-20 15:02 - 2012-08-08 21:19 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-12-20 14:50 - 2014-03-31 17:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-12-20 14:50 - 2012-08-08 21:20 - 00000000 ____D () C:\$AVG
2014-12-20 14:10 - 2012-06-09 11:14 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-12-19 10:42 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-12-18 19:10 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2014-12-18 19:09 - 2014-11-24 21:22 - 00000000 ____D () C:\Users\TEMP.Wilhelm-PC.000
2014-12-14 20:59 - 2013-06-09 21:16 - 00001159 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-12-14 20:59 - 2013-06-09 21:16 - 00001147 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-12-14 20:59 - 2012-06-08 23:50 - 00001421 _____ () C:\Users\Wilhelm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-12-14 12:14 - 2014-11-21 20:34 - 00000000 ____D () C:\Users\Wilhelm\AppData\Local\Windows Live
2014-12-11 10:01 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-12-10 22:49 - 2012-06-09 00:09 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-10 22:47 - 2013-08-15 06:40 - 00000000 ____D () C:\windows\system32\MRT
2014-12-10 22:41 - 2012-10-31 22:05 - 112710672 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-12-06 20:17 - 2012-06-08 23:46 - 00000000 ____D () C:\Users\Wilhelm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2014-12-06 20:17 - 2012-04-13 22:29 - 00000000 ____D () C:\ProgramData\Port Locker
2014-12-06 20:17 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\registration
Some content of TEMP:
====================
C:\Users\Wilhelm\AppData\Local\Temp\Quarantine.exe
C:\Users\Wilhelm\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-18 19:02
==================== End Of Log ============================ --- --- ---
Vielen Dank und noch einen schönen 2. Weihnachtstag! |