Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Lässtige werbung trotz addblock (https://www.trojaner-board.de/162190-laesstige-werbung-trotz-addblock.html)

reisser 27.12.2014 15:05

Lässtige werbung trotz addblock
 
Hi zusammen :)

Seid Gestern habe ich in google chrome andauernd einblendende werbung die ich nicht weg bekomme die stört sowas von!!!
benutze win 7 64 bit
brauche Dringend Hilfe

MFG Adrian





FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-12-2014
Ran by Reisser (administrator) on REISSER-PC on 27-12-2014 15:01:45
Running from C:\Users\Reisser\Downloads
Loaded Profile: Reisser (Available profiles: Reisser)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Englisch (USA)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(CartCrunch Israel Ltd.) C:\ProgramData\SecurityUtility\ColorMedia.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\rcore.exe
() C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files (x86)\QuickTime\qttask.exe
() C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Time Lapse Solutions) C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe
(Abengine) C:\Program Files (x86)\Flwsrf\abengine.exe
() C:\Program Files (x86)\Flwsrf\ijs.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Cinema HDV27.12) C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6.exe
(globalUpdate) C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2463552 2014-10-04] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [282624 2007-04-27] (Apple Inc.)
HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] ()
HKLM-x32\...\Run: [gmsd_de_44] => [X]
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Run: [LiveSupport] => "C:\Program Files (x86)\LiveSupport\LiveSupport.exe" /noshow /log
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Run: [SwvUpdtr] => C:\Users\Reisser\AppData\Local\24567\Updater.exe [773632 2014-12-27] ()
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Run: [PCSpeedUp] => C:\Program Files (x86)\PC Speed Up\PCSUNotifier.exe [342472 2014-12-10] ()
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: G - G:\StorioSetup.exe
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {2e971c8e-719e-11e4-b18f-bc5ff45b0bd1} - F:\SNC715MusicPlayer.exe
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {432e0770-7651-11e4-a244-806e6f6e6963} - F:\VTech_toy_Setup.exe
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {9dac61e2-89ed-11e4-b4c2-bc5ff45b0bd1} - G:\StorioSetup.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:50863;https=127.0.0.1:50863
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = omiga-plus
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419615594&from=tugs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = omiga-plus
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419615594&from=tugs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Start Page = Tikotin
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Tikotin
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe omiga-plus
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419615594&from=tugs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419615594&from=tugs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope value is missing.
SearchScopes: HKLM-x32 -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.searchoholic.info/?l=1&q={searchTerms}&pid=1091&r=2014/12/22&hid=8793653231034268742&lg=EN&cc=DE&unqvl=72
SearchScopes: HKU\S-1-5-21-1744345613-2801571155-2633355246-1000 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M967FE9C1-A9A5-43A2-8659-C914B636C4B4&SearchSource=58&CUI=&UM=8&UP=SP7CE64842-07CE-4A5F-8347-E1F6816C072C&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-1744345613-2801571155-2633355246-1000 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M967FE9C1-A9A5-43A2-8659-C914B636C4B4&SearchSource=58&CUI=&UM=8&UP=SP7CE64842-07CE-4A5F-8347-E1F6816C072C&q={searchTerms}&SSPV=
SearchScopes: HKU\S-1-5-21-1744345613-2801571155-2633355246-1000 -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.searchoholic.info/?l=1&q={searchTerms}&pid=1091&r=2014/12/22&hid=8793653231034268742&lg=EN&cc=DE&unqvl=72
BHO: CinemaHd For Pro 2.4cV27.12 -> {11111111-1111-1111-1111-110611571181} -> C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\CinemaHd For Pro 2.4cV27.12-bho64.dll (Cinema HDV27.12)
BHO-x32: CinemaHd For Pro 2.4cV27.12 -> {11111111-1111-1111-1111-110611571181} -> C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\CinemaHd For Pro 2.4cV27.12-bho.dll (Cinema HDV27.12)
BHO-x32: No Name -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} ->  No File
Winsock: Catalog9 01 C:\Windows\SysWOW64\abengine.dll [324592] (Abengine)
Winsock: Catalog9 02 C:\Windows\SysWOW64\abengine.dll [324592] (Abengine)
Winsock: Catalog9 03 C:\Windows\SysWOW64\abengine.dll [324592] (Abengine)
Winsock: Catalog9 04 C:\Windows\SysWOW64\abengine.dll [324592] (Abengine)
Winsock: Catalog9 16 C:\Windows\SysWOW64\abengine.dll [324592] (Abengine)
Winsock: Catalog9-x64 01 C:\Windows\system32\abengine64.dll [370880] (Abengine)
Winsock: Catalog9-x64 02 C:\Windows\system32\abengine64.dll [370880] (Abengine)
Winsock: Catalog9-x64 03 C:\Windows\system32\abengine64.dll [370880] (Abengine)
Winsock: Catalog9-x64 04 C:\Windows\system32\abengine64.dll [370880] (Abengine)
Winsock: Catalog9-x64 05 C:\Windows\system32\ColorMedia64.dll [378640] (CartCrunch Israel Ltd.)
Winsock: Catalog9-x64 06 C:\Windows\system32\ColorMedia64.dll [378640] (CartCrunch Israel Ltd.)
Winsock: Catalog9-x64 07 C:\Windows\system32\ColorMedia64.dll [378640] (CartCrunch Israel Ltd.)
Winsock: Catalog9-x64 08 C:\Windows\system32\ColorMedia64.dll [378640] (CartCrunch Israel Ltd.)
Winsock: Catalog9-x64 20 C:\Windows\system32\ColorMedia64.dll [378640] (CartCrunch Israel Ltd.)
Winsock: Catalog9-x64 21 C:\Windows\system32\abengine64.dll [370880] (Abengine)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (globalUpdate)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default ->
CHR StartupUrls: Default -> ""
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-26]
CHR Extension: (Google Docs) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-26]
CHR Extension: (Google Drive) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-26]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-26]
CHR Extension: (YouTube) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-26]
CHR Extension: (Google Search) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-26]
CHR Extension: (Google Sheets) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-26]
CHR Extension: (Google Wallet) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-26]
CHR Extension: (Gmail) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-26]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 abengine; C:\Program Files (x86)\Flwsrf\abengine.exe [1348168 2014-12-05] (Abengine) [File not signed]
R2 ColorMedia; C:\ProgramData\SecurityUtility\ColorMedia.exe [1398576 2014-12-14] (CartCrunch Israel Ltd.)
R2 dZPlDQFMAyN; C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe [2726776 2014-12-27] (Time Lapse Solutions)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-10-04] (NVIDIA Corporation)
S2 globalUpdate; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-12-27] (globalUpdate) [File not signed]
S3 globalUpdatem; C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [68608 2014-12-27] (globalUpdate) [File not signed]
R2 InjectorService; C:\Program Files (x86)\Flwsrf\ijs.exe [164352 2014-11-29] () [File not signed]
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-10-04] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-10-04] (NVIDIA Corporation)
R2 rcores; C:\Windows\rcore.exe [4963840 2014-12-25] () [File not signed]
R2 SecurityUtility Service; C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe [537248 2014-12-25] ()
S2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe -service [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-10-04] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-27 15:01 - 2014-12-27 15:02 - 00016117 _____ () C:\Users\Reisser\Downloads\FRST.txt
2014-12-27 15:01 - 2014-12-27 15:01 - 02122752 _____ (Farbar) C:\Users\Reisser\Downloads\FRST64.exe
2014-12-27 15:01 - 2014-12-27 15:01 - 00000000 ____D () C:\FRST
2014-12-27 14:59 - 2014-12-27 14:59 - 00001137 _____ () C:\Users\Reisser\Desktop\Continue File Opener Installation.lnk
2014-12-27 14:48 - 2014-12-27 14:48 - 00797824 _____ ( ) C:\Users\Reisser\Downloads\FileOpenerSetup.exe
2014-12-27 14:29 - 2014-12-27 14:40 - 00000000 ____D () C:\Program Files (x86)\PC Speed Up
2014-12-27 14:29 - 2014-12-27 14:29 - 00003952 _____ () C:\Windows\System32\Tasks\amiupdaterExi
2014-12-27 14:29 - 2014-12-27 14:29 - 00003748 _____ () C:\Windows\System32\Tasks\amiupdaterExd
2014-12-27 14:29 - 2014-12-27 14:29 - 00002724 _____ () C:\Windows\System32\Tasks\PC SpeedUp Service Deactivator
2014-12-27 14:29 - 2014-12-27 14:29 - 00000344 _____ () C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
2014-12-27 14:29 - 2014-12-27 14:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Speed Up
2014-12-27 14:23 - 2014-12-27 14:23 - 00008564 _____ () C:\Windows\System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-7
2014-12-27 14:23 - 2014-12-27 14:23 - 00008562 _____ () C:\Windows\System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6
2014-12-27 14:23 - 2014-12-27 14:23 - 00006524 _____ () C:\Windows\System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-1
2014-12-27 14:23 - 2014-12-27 14:23 - 00005534 _____ () C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-7.job
2014-12-27 14:23 - 2014-12-27 14:23 - 00005534 _____ () C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6.job
2014-12-27 14:23 - 2014-12-27 14:23 - 00005492 _____ () C:\Windows\System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5
2014-12-27 14:23 - 2014-12-27 14:23 - 00005156 _____ () C:\Windows\System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-2
2014-12-27 14:23 - 2014-12-27 14:23 - 00003494 _____ () C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-1.job
2014-12-27 14:23 - 2014-12-27 14:23 - 00002462 _____ () C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5_user.job
2014-12-27 14:23 - 2014-12-27 14:23 - 00002462 _____ () C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5.job
2014-12-27 14:23 - 2014-12-27 14:23 - 00002126 _____ () C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-2.job
2014-12-27 14:23 - 2014-12-27 14:23 - 00000000 ____D () C:\Program Files (x86)\2f4249ae-2ea2-4d9e-8f18-8c64e6461106
2014-12-27 14:22 - 2014-12-27 14:23 - 00004376 _____ () C:\Windows\System32\Tasks\KWWB
2014-12-27 14:22 - 2014-12-27 14:23 - 00001342 _____ () C:\Windows\Tasks\KWWB.job
2014-12-27 14:22 - 2014-12-27 14:23 - 00000000 ____D () C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12
2014-12-27 14:22 - 2014-12-27 14:22 - 02055144 _____ (Cinema HDV27.12) C:\Users\Reisser\AppData\Roaming\KWWB.exe
2014-12-27 14:22 - 2014-12-27 14:22 - 00007540 _____ () C:\Windows\System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-3
2014-12-27 14:22 - 2014-12-27 14:22 - 00004510 _____ () C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-3.job
2014-12-27 14:22 - 2014-12-27 14:22 - 00000000 ____D () C:\Program Files (x86)\globalUpdate
2014-12-27 12:15 - 2014-12-27 12:15 - 00000000 ____D () C:\Users\Reisser\AppData\Local\24567
2014-12-27 11:53 - 2014-12-27 11:53 - 00004640 _____ () C:\Windows\SysWOW64\abengine.ini
2014-12-27 11:53 - 2014-12-27 11:53 - 00003090 _____ () C:\Windows\System32\Tasks\upfs7235
2014-12-27 11:53 - 2014-12-27 11:53 - 00002544 _____ () C:\Windows\SysWOW64\abengineOff.ini
2014-12-27 11:53 - 2014-12-27 11:53 - 00002544 _____ () C:\Windows\system32\abengineOff.ini
2014-12-27 11:53 - 2014-12-27 11:53 - 00000002 _____ () C:\END
2014-12-27 11:53 - 2014-12-27 11:53 - 00000000 ____D () C:\Program Files (x86)\Flwsrf
2014-12-27 11:53 - 2014-12-05 00:09 - 00370880 _____ (Abengine) C:\Windows\system32\abengine64.dll
2014-12-27 11:53 - 2014-12-05 00:09 - 00324592 _____ (Abengine) C:\Windows\SysWOW64\abengine.dll
2014-12-27 11:52 - 2014-12-27 14:51 - 00000000 ____D () C:\Users\Reisser\AppData\Local\ZombieInvasion
2014-12-27 11:52 - 2014-12-27 11:52 - 00000000 ____D () C:\ProgramData\ZombieInvasion
2014-12-27 11:52 - 2014-12-27 11:52 - 00000000 ____D () C:\ProgramData\qMuLXOMiMf
2014-12-26 20:54 - 2014-12-26 21:03 - 00000000 ____D () C:\Users\Reisser\Desktop\weihnachten 14
2014-12-26 20:45 - 2014-12-26 08:06 - 00008977 _____ () C:\Users\Reisser\Downloads\rla-dtvpmt1.ts.nfo
2014-12-26 20:45 - 2014-12-25 23:20 - 745466933 _____ () C:\Users\Reisser\Downloads\die tribute von Panem.mkv
2014-12-26 20:45 - 2014-12-23 12:02 - 00000220 _____ () C:\Users\Reisser\Downloads\Goldesel.to - Die Seite fuer Direkt-Downloads aller Art.url
2014-12-26 20:45 - 2014-12-23 12:02 - 00000116 _____ () C:\Users\Reisser\Downloads\goldesel.to - quality source for more than 15 years .txt
2014-12-26 20:35 - 2014-12-26 20:42 - 208666624 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part1.rar
2014-12-26 20:34 - 2014-12-26 20:42 - 208666624 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part3.rar
2014-12-26 20:34 - 2014-12-26 20:41 - 208666624 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part2.rar
2014-12-26 20:34 - 2014-12-26 20:38 - 126903232 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part4.rar
2014-12-26 19:28 - 2014-12-26 19:30 - 00002196 _____ () C:\Users\Reisser\Desktop\chrome.lnk
2014-12-26 19:18 - 2014-12-26 19:18 - 00003160 _____ () C:\Windows\System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B}
2014-12-26 19:12 - 2014-12-26 19:12 - 00003156 _____ () C:\Windows\System32\Tasks\Run_Bobby_Browser
2014-12-26 19:08 - 2014-12-26 19:08 - 00000000 ____D () C:\Program Files (x86)\predm
2014-12-26 19:06 - 2014-12-26 19:06 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\dlg
2014-12-26 19:05 - 2014-12-26 19:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-12-26 19:04 - 2014-12-27 11:44 - 00005240 _____ () C:\Windows\SysWOW64\ColorMedia.ini
2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\SysWOW64\ColorMediaOff.ini
2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\system32\ColorMediaOff.ini
2014-12-26 19:04 - 2014-12-26 19:04 - 00000000 ____D () C:\ProgramData\SecurityUtilityData
2014-12-26 19:04 - 2014-12-26 19:04 - 00000000 ____D () C:\ProgramData\SecurityUtility
2014-12-26 19:04 - 2014-12-26 19:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-12-26 19:04 - 2014-12-14 10:53 - 00378640 _____ (CartCrunch Israel Ltd.) C:\Windows\system32\ColorMedia64.dll
2014-12-26 19:04 - 2014-12-14 10:53 - 00332568 _____ (CartCrunch Israel Ltd.) C:\Windows\SysWOW64\ColorMedia.dll
2014-12-26 19:00 - 2014-12-26 19:00 - 00596368 _____ () C:\Users\Reisser\Downloads\download-adblock-chrome.exe
2014-12-26 18:53 - 2014-12-26 18:57 - 00019405 _____ () C:\Users\Reisser\Downloads\software_removal_tool.log
2014-12-26 18:42 - 2014-12-27 14:29 - 00000000 ___HD () C:\Users\Public\Temp
2014-12-26 18:41 - 2014-12-26 18:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-12-26 18:40 - 2014-12-27 14:45 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-26 18:40 - 2014-12-27 14:27 - 00000966 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2014-12-26 18:40 - 2014-12-27 14:27 - 00000962 _____ () C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2014-12-26 18:40 - 2014-12-27 14:22 - 00003964 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
2014-12-26 18:40 - 2014-12-27 14:22 - 00003710 _____ () C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
2014-12-26 18:40 - 2014-12-27 11:44 - 00001694 _____ () C:\Windows\Tasks\PTJGYIFC.job
2014-12-26 18:40 - 2014-12-27 11:44 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-26 18:40 - 2014-12-26 18:55 - 00001925 _____ () C:\Windows\patsearch.bin
2014-12-26 18:40 - 2014-12-26 18:55 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-12-26 18:40 - 2014-12-26 18:40 - 01966056 _____ (HQ-VideoV26.12) C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe
2014-12-26 18:40 - 2014-12-26 18:40 - 00004728 _____ () C:\Windows\System32\Tasks\PTJGYIFC
2014-12-26 18:40 - 2014-12-26 18:40 - 00003896 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-12-26 18:40 - 2014-12-26 18:40 - 00003644 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-12-26 18:40 - 2014-12-26 18:40 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrNewH_01009.Wdf
2014-12-26 18:40 - 2014-12-26 18:40 - 00000000 ____D () C:\Users\Reisser\AppData\Local\globalUpdate
2014-12-26 18:40 - 2014-12-25 12:44 - 04963840 _____ () C:\Windows\rcore.exe
2014-12-26 18:39 - 2014-12-26 19:18 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\omiga-plus
2014-12-26 18:39 - 2014-12-26 18:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip
2014-12-26 18:35 - 2014-12-26 18:35 - 00000000 ___DC () C:\Users\Reisser\AppData\Local\MigWiz
2014-12-26 07:16 - 2014-12-26 07:16 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2014-12-25 18:43 - 2014-12-25 20:53 - 1995124610 _____ () C:\Users\Reisser\Downloads\Orphan.Das.Waisenkind.German.AC3.HDRip.XViD-FuN.avi
2014-12-25 16:59 - 2014-12-25 17:00 - 00000000 ____D () C:\Users\Reisser\Downloads\34020109
2014-12-25 14:19 - 2014-12-23 09:12 - 00000000 ____D () C:\Users\Reisser\Downloads\Ice_Age_Sid_Und_Seine_Freunde-Cool_Und_Locker-2014-NoGroup
2014-12-24 17:15 - 2014-12-24 17:15 - 00000000 ____D () C:\Program Files (x86)\Ripple Emulator
2014-12-24 17:14 - 2014-12-24 17:14 - 00000000 ____D () C:\ProgramData\3980744520298899654
2014-12-24 17:14 - 2014-12-24 17:14 - 00000000 ____D () C:\Program Files (x86)\BuyyNsaave
2014-12-24 17:13 - 2014-12-24 17:13 - 00000000 ____D () C:\ProgramData\migbhnamcclanachieldofcbpebkajke
2014-12-23 23:14 - 2014-11-04 16:50 - 878567444 _____ () C:\Users\Reisser\Downloads\The Purge 2.mkv
2014-12-22 21:43 - 2014-12-22 21:43 - 00000000 ____D () C:\Users\Reisser\Downloads\G0neGrl.ld.HD.de
2014-12-22 17:40 - 2014-12-22 17:40 - 00000000 ____D () C:\ProgramData\3872871776
2014-12-22 17:31 - 2014-12-22 17:31 - 00000000 ____D () C:\Users\Reisser\Documents\Optimizer Pro
2014-12-22 16:27 - 2014-12-22 16:28 - 00000000 ____D () C:\Users\Reisser\AppData\Local\DownloadManager
2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\VTech
2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTech
2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\Program Files (x86)\VTech
2014-12-19 17:14 - 2014-12-19 17:14 - 00000000 _____ () C:\Users\Reisser\AppData\Local\{E9C16533-9CB5-45BF-A1F9-47B28A73E05D}
2014-12-18 15:33 - 2014-12-18 17:29 - 00000000 ____D () C:\Users\Reisser\Downloads\Hörbücher
2014-12-18 13:21 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-18 13:21 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-17 17:42 - 2014-12-17 17:42 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\NVIDIA
2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Mindscape
2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mindscape
2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mindscape
2014-12-17 17:39 - 2014-12-17 17:39 - 00000000 ____D () C:\Program Files (x86)\Mindscape
2014-12-17 17:36 - 2014-12-17 17:36 - 00054156 ____H () C:\Windows\QTFont.qfn
2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-12-17 17:32 - 2014-12-17 17:35 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-12-12 23:05 - 2014-12-12 23:05 - 00159200 ____T () C:\Users\Reisser\AppData\Roaming\CrashRpt1402.dll
2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\Users\Reisser\AppData\Local\CrashRpt
2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIW Pro Trial
2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\Program Files (x86)\SIW Pro Trial
2014-12-12 03:19 - 2014-12-12 03:19 - 00000000 ____D () C:\Windows\system32\appraiser
2014-12-12 03:01 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-12 03:01 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-12 03:01 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-12-12 03:01 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-12-12 03:01 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-12-12 03:01 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-12-12 03:01 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-12-12 03:01 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-12-12 03:01 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-12-12 03:01 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2014-12-11 04:56 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-12-11 04:56 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2014-12-11 04:55 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-11 04:55 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-11 04:55 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-11 04:55 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-11 04:55 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-11 04:55 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-11 04:55 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-11 04:55 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-11 04:55 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-11 04:55 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-11 04:55 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-11 04:55 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-11 04:55 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-11 04:55 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-11 04:55 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-11 04:55 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-11 04:55 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-11 04:55 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-11 04:55 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-11 04:55 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-11 04:55 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-11 04:55 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-11 04:55 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-11 04:55 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-11 04:55 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-11 04:55 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-11 04:55 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-11 04:55 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-11 04:55 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-11 04:55 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-11 04:55 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-11 04:55 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-11 04:55 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-11 04:55 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-11 04:55 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-11 04:55 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-11 04:55 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-11 04:55 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-11 04:55 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-11 04:55 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-11 04:55 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-11 04:55 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-11 04:55 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-11 04:55 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-11 04:55 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-11 04:55 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-11 04:55 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-11 04:55 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-11 04:55 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-11 04:55 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-11 04:55 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-11 04:55 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-11 04:55 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-11 04:55 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-11 04:55 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-11 04:55 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-11 04:55 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-11 04:54 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-11 04:54 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-11 04:54 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-11 04:54 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-11 04:54 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-11 04:54 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-11 04:54 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-11 04:54 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-11 04:54 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-11 04:54 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-11 04:54 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-11 04:54 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-11 04:54 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-11 04:54 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-12-11 00:26 - 2014-12-11 00:26 - 01413208 _____ () C:\Windows\Minidump\121114-20248-01.dmp
2014-12-05 12:01 - 2014-12-27 11:40 - 00012288 _____ () C:\Users\Reisser\Desktop\Stundenzettelfür Feru - Dezember14 -.xls
2014-12-04 13:29 - 2014-12-13 15:32 - 00000062 _____ () C:\Users\Reisser\Desktop\Neues Textdokument.txt
2014-12-04 12:53 - 2014-12-25 14:20 - 00000000 ____D () C:\Users\Reisser\Downloads\Musik
2014-12-04 12:52 - 2014-12-09 19:08 - 00000000 ____D () C:\Users\Reisser\Downloads\Kinder Filme
2014-11-28 13:23 - 2014-12-11 00:26 - 564424988 _____ () C:\Windows\MEMORY.DMP
2014-11-28 13:23 - 2014-12-11 00:26 - 00000000 ____D () C:\Windows\Minidump
2014-11-27 19:28 - 2014-12-22 18:10 - 00000000 ____D () C:\Users\Reisser\Desktop\Wallpapers
2014-11-27 18:51 - 2014-11-27 18:51 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-11-27 18:20 - 2014-11-27 18:21 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Nero
2014-11-27 18:20 - 2014-11-27 18:20 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\OpenCandy
2014-11-27 18:15 - 2014-11-27 18:50 - 00000000 ____D () C:\ProgramData\Nero
2014-11-27 18:14 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2014-11-27 18:14 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2014-11-27 18:13 - 2014-11-27 18:13 - 00000000 ____D () C:\ProgramData\Package Cache
2014-11-27 17:58 - 2014-11-27 18:17 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\DeepBurner
2014-11-27 17:57 - 2014-11-27 17:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DeepBurner
2014-11-27 17:57 - 2014-11-27 17:57 - 00000000 ____D () C:\Program Files (x86)\Astonsoft
2014-11-27 17:21 - 2014-11-27 17:21 - 00000000 ____D () C:\Users\Reisser\Documents\Ashampoo Burning Studio FREE
2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Ashampoo
2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\Users\Reisser\AppData\Local\ashampoo
2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\Program Files (x86)\Ashampoo

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-27 14:23 - 2014-11-08 15:29 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-12-27 13:25 - 2014-11-08 14:39 - 01971342 _____ () C:\Windows\WindowsUpdate.log
2014-12-27 11:52 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-27 11:52 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-27 11:51 - 2014-11-08 16:15 - 00697256 _____ () C:\Windows\system32\perfh007.dat
2014-12-27 11:51 - 2014-11-08 16:15 - 00149224 _____ () C:\Windows\system32\perfc007.dat
2014-12-27 11:51 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-27 11:44 - 2014-11-08 14:52 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-12-27 11:44 - 2010-11-21 04:47 - 00037796 _____ () C:\Windows\PFRO.log
2014-12-27 11:44 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-27 11:44 - 2009-07-14 05:51 - 00041347 _____ () C:\Windows\setupact.log
2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Users\Reisser\AppData\Local\Google
2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Program Files (x86)\Google
2014-12-26 18:39 - 2014-11-08 14:42 - 00001649 _____ () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-12-25 12:22 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-22 18:10 - 2014-11-10 17:53 - 00000000 ____D () C:\Users\Reisser\Downloads\Filme
2014-12-17 17:42 - 2014-11-08 14:42 - 00000000 ____D () C:\Users\Reisser\AppData\Local\VirtualStore
2014-12-12 05:23 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-12-12 03:19 - 2014-11-08 19:04 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-12-12 03:04 - 2014-11-08 19:30 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-12 03:02 - 2014-11-08 19:30 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-11 00:29 - 2014-11-16 15:02 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-12-05 11:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-01 06:58 - 2014-11-20 17:29 - 00012288 _____ () C:\Users\Reisser\Desktop\Stundenzettelfür Feru - November 14 - Kopie.xls
2014-11-27 18:20 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Cursors

Some content of TEMP:
====================
C:\Users\Reisser\AppData\Local\Temp\089C73368233.exe
C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.dll
C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.exe
C:\Users\Reisser\AppData\Local\Temp\EFDF6877-8E55-A3B8-0364-69652FE51F4F.exe
C:\Users\Reisser\AppData\Local\Temp\ICReinstall_FileOpenerSetup.exe
C:\Users\Reisser\AppData\Local\Temp\Launcher__10272.exe
C:\Users\Reisser\AppData\Local\Temp\Launcher__9848.exe
C:\Users\Reisser\AppData\Local\Temp\Launcher__9999.exe
C:\Users\Reisser\AppData\Local\Temp\LiveSupport_setup.exe
C:\Users\Reisser\AppData\Local\Temp\ms.exe
C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Reisser\AppData\Local\Temp\nvStInst.exe
C:\Users\Reisser\AppData\Local\Temp\optprosetup.exe
C:\Users\Reisser\AppData\Local\Temp\setup_384.exe
C:\Users\Reisser\AppData\Local\Temp\SpOrder.dll
C:\Users\Reisser\AppData\Local\Temp\Storio2_DE_ger_Setup_pid_1588.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-12-15 17:20

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---

--- --- ---

FRST Additions Logfile:
Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-12-2014
Ran by Reisser at 2014-12-27 15:02:47
Running from C:\Users\Reisser\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Abenteuer Pferderücken Demo (HKLM-x32\...\Abenteuer Pferderücken Demo) (Version:  - )
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Ashampoo Burning Studio FREE v.1.14.5 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.12.0 - Asmedia Technology)
CinemaHd For Pro 2.4cV27.12 (HKLM-x32\...\CinemaHd For Pro 2.4cV27.12) (Version: 1.35.12.18 - Cinema HDV27.12)
Flwsrf (HKLM-x32\...\Flwsrf) (Version: 3.0.0.2 - Flwsrf) <==== ATTENTION!
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.65 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
K-Lite Codec Pack 10.8.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.8.0 - )
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
mkv2vob (HKLM-x32\...\{21AE04E8-EBF6-40DB-9AA9-B7A80C5D057D}) (Version: 2.4.9 - 3r1c)
NVIDIA 3D Vision Controller Driver 344.46 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 344.46 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 344.60 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.3 - NVIDIA Corporation)
NVIDIA Graphics Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.60 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.32.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
omiga-plus uninstall (HKLM-x32\...\omiga-plus uninstall) (Version:  - omiga-plus) <==== ATTENTION
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
PC Speed Up (HKLM\...\PCSU-SL_is1) (Version: 3.8.3.0 - Speedchecker Limited) <==== ATTENTION
QuickTime (HKLM-x32\...\{08094E03-AFE4-4853-9D31-6D0743DF5328}) (Version: 7.1.6.200 - Apple Computer, Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.)
SecurityUtility (HKLM-x32\...\SecurityUtility) (Version: 1.0.0.992 - )
SHIELD Streaming (Version: 3.1.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.13.56 - NVIDIA Corporation) Hidden
SIW Pro Edition (Trial Version) (HKLM-x32\...\{3B9704C8-1286-4a17-9EA8-F63004FC74A1}_is1) (Version: 2014.10.16 - Topala Software Solutions)
Software Version Updater (HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}) (Version: 1.1.4.2 - ) <==== ATTENTION
VTech Download Agent Library (x32 Version: 1.00.0000 - VTech) Hidden
VTech Download Manager (HKLM-x32\...\VTechDownloadManager) (Version:  - VTech)
WinRAR 5.10 Beta 4 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH)
Zombie Invasion (HKLM-x32\...\ZombieInvasion) (Version: 2.7.50 - Time Lapse Solutions)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

22-12-2014 17:38:19 Removed Apple Software Update
25-12-2014 17:07:37 Windows Update
26-12-2014 18:53:33 Software Removal Tool

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {058D4BF1-586D-49C2-8015-438E97637BB8} - System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5 => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION
Task: {07C4EDDE-20D1-4BFF-8659-B50E309D06FA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.)
Task: {32E4AC8B-D955-4847-BF7D-215EA9001513} - System32\Tasks\PTJGYIFC => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe [2014-12-26] (HQ-VideoV26.12) <==== ATTENTION
Task: {375D32C7-2DF3-4769-A2C8-2CC4A1A2038A} - System32\Tasks\globalUpdateUpdateTaskMachineUA => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-12-27] (globalUpdate) <==== ATTENTION
Task: {4D0C693A-EBE8-4241-B781-4B9F04671106} - System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-3 => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-3.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION
Task: {4DCB2EBB-48CF-46E4-B971-2C82DC29C90D} - System32\Tasks\PC SpeedUp Service Deactivator => C:\Program Files (x86)\PC Speed Up\PCSUSD.exe [2014-12-10] () <==== ATTENTION
Task: {7C46BBB5-8422-47C1-A9C2-3BB2C3C41657} - System32\Tasks\upfs7235 => C:\Program Files (x86)\Flwsrf\upfs7235.exe [2014-12-05] ()
Task: {7D3768C6-C09E-49D4-BDF0-3A2B8040FDB0} - System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-7 => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-7.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION
Task: {850FC5E5-AE51-4C51-95E1-FF3768705CCA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.)
Task: {8B1C00F0-602F-40B2-9557-43584EC56145} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2014-10-06] ()
Task: {93F395D4-4E96-4489-8C49-75F00D051B22} - System32\Tasks\globalUpdateUpdateTaskMachineCore => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-12-27] (globalUpdate) <==== ATTENTION
Task: {95357790-1215-4EC2-8985-08746970D29D} - System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-1 => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\CinemaHd For Pro 2.4cV27.12-codedownloader.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION
Task: {D5ACE67C-2D56-4D85-AAEF-15701D01ECB4} - System32\Tasks\Run_Bobby_Browser => C:\Users\Reisser\AppData\Local\BoBrowser\Application\bobrowser.exe <==== ATTENTION
Task: {DCFAB0D7-340E-42C6-A8C1-45EF755A38FD} - System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-2 => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-2.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION
Task: {E1B12AA3-8587-49F7-8FD4-24A42FBB9ED3} - System32\Tasks\KWWB => C:\Users\Reisser\AppData\Roaming\KWWB.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION
Task: {E4E2559A-16D1-4F31-B32E-7D55DC599C1A} - System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5_user => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION
Task: {E7D7C2C6-68D3-4C46-9826-F912206163EA} - System32\Tasks\amiupdaterExd => cmd.exe /c start /min bitsadmin /transfer amijob /download /priority high hxxp://d17xr4aw9ok0me.cloudfront.net/Updater.exe "C:\Users\Reisser\AppData\Local\Temp\amiupdater1440.exe"
Task: {F125BC51-2941-4F4A-B676-B6C8A5B0E166} - System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B} => pcalua.exe -a C:\Users\Reisser\AppData\Roaming\omiga-plus\UninstallManager.exe -c  -ptid=tugs
Task: {F1E05127-80E4-400F-8C60-436999246896} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {F7148153-DE7E-454F-9759-3E651C5CF7A7} - System32\Tasks\amiupdaterExi => C:\Users\Reisser\AppData\Local\Temp\amiupdater1440.exe <==== ATTENTION
Task: {FC55D932-5FAC-4A5D-8814-F6F2264ED660} - System32\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6 => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION
Task: C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-1.job => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\CinemaHd For Pro 2.4cV27.12-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-2.job => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-2.exe <==== ATTENTION
Task: C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-3.job => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-3.exe <==== ATTENTION
Task: C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5.job => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5_user.job => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5.exe <==== ATTENTION
Task: C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6.job => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6.exe <==== ATTENTION
Task: C:\Windows\Tasks\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-7.job => C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-7.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job => C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\KWWB.job => C:\Users\Reisser\AppData\Roaming\KWWB.exe <==== ATTENTION
Task: C:\Windows\Tasks\PC SpeedUp Service Deactivator.job => C:\Program Files (x86)\PC Speed Up\PCSUSD.exe <==== ATTENTION
Task: C:\Windows\Tasks\PTJGYIFC.job => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2014-11-08 14:51 - 2014-10-30 03:10 - 00117064 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-12-26 18:40 - 2014-12-25 12:44 - 04963840 _____ () C:\Windows\rcore.exe
2014-12-26 19:04 - 2014-12-25 19:14 - 00537248 _____ () C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe
2014-10-13 02:49 - 2014-06-20 07:42 - 00401280 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
2014-11-29 13:26 - 2014-11-29 13:26 - 00164352 _____ () C:\Program Files (x86)\Flwsrf\ijs.exe
2014-10-13 02:49 - 2014-03-04 12:20 - 00117760 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QtSolutions_SOAP-2.7.dll
2014-10-13 02:49 - 2014-04-22 03:14 - 00065536 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QHttpServer.dll
2014-10-13 02:49 - 2014-05-06 06:39 - 00861184 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\platforms\qwindows.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00021504 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qgif.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00020992 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qico.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00204800 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qjpeg.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00218112 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qmng.dll
2014-10-13 02:49 - 2014-05-06 06:58 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qsvg.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00015360 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtga.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00307712 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtiff.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00014848 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qwbmp.dll
2014-10-13 02:49 - 2014-05-06 07:31 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\sensors\qtsensors_dummy.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00036352 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qgenericbearer.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00038912 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qnativewifibearer.dll
2014-12-27 14:23 - 2014-12-27 14:23 - 00182760 _____ () C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12\eee4bccf-2d1a-41af-827c-69d1b17a9cc6.dll
2014-12-26 18:41 - 2014-11-14 22:15 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\libglesv2.dll
2014-12-26 18:41 - 2014-11-14 22:15 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\libegl.dll
2014-12-26 18:41 - 2014-11-14 22:15 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\ffmpegsumo.dll
2014-12-26 18:41 - 2014-11-14 22:15 - 14910280 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\PepperFlash\pepflashplayer.dll
2014-12-26 18:41 - 2014-11-14 22:15 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\pdf.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\abengine => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ColorMedia => ""="service"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


========================= Accounts: ==========================

Administrator (S-1-5-21-1744345613-2801571155-2633355246-500 - Administrator - Disabled)
Guest (S-1-5-21-1744345613-2801571155-2633355246-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1744345613-2801571155-2633355246-1002 - Limited - Enabled)
Reisser (S-1-5-21-1744345613-2801571155-2633355246-1000 - Administrator - Enabled) => C:\Users\Reisser

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (12/27/2014 02:23:02 PM) (Source: MsiInstaller) (EventID: 11309) (User: Reisser-PC)
Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt.  System error 3.  Verify that the file exists and that you can access it.

Error: (12/27/2014 00:23:19 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm chrome.exe, Version 39.0.2171.65 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1fc0

Startzeit: 01d021c34c497746

Endzeit: 16

Anwendungspfad: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

Berichts-ID: bc3b44d9-8dba-11e4-8bfc-bc5ff45b0bd1

Error: (12/27/2014 11:46:14 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/26/2014 08:45:52 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5792.  Message ID: [0x2509].

Error: (12/26/2014 07:27:09 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (12/26/2014 07:27:09 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (12/26/2014 07:27:06 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (12/26/2014 07:27:06 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (12/26/2014 07:27:04 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (12/26/2014 07:27:04 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".


System errors:
=============
Error: (12/27/2014 11:46:58 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "globalUpdate Update Service (globalUpdate)" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (12/27/2014 11:44:45 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "IePlugin Services" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (12/27/2014 11:44:26 AM) (Source: Ntfs) (EventID: 137) (User: )
Description: Auf dem Volume "\\?\Volume{2dd34089-674c-11e4-af0b-806e6f6e6963}" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (12/27/2014 11:44:26 AM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (12/26/2014 08:15:43 PM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (12/26/2014 08:15:41 PM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (12/26/2014 08:15:40 PM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (12/26/2014 08:15:39 PM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (12/26/2014 08:15:37 PM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (12/26/2014 08:15:36 PM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.


Microsoft Office Sessions:
=========================
Error: (12/27/2014 02:23:02 PM) (Source: MsiInstaller) (EventID: 11309) (User: Reisser-PC)
Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt.  System error 3.  Verify that the file exists and that you can access it.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (12/27/2014 00:23:19 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: chrome.exe39.0.2171.651fc001d021c34c49774616C:\Program Files (x86)\Google\Chrome\Application\chrome.exebc3b44d9-8dba-11e4-8bfc-bc5ff45b0bd1

Error: (12/27/2014 11:46:14 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/26/2014 08:45:52 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5792.  Message ID: [0x2509].

Error: (12/26/2014 07:27:09 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl

Error: (12/26/2014 07:27:09 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl

Error: (12/26/2014 07:27:06 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl

Error: (12/26/2014 07:27:06 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl

Error: (12/26/2014 07:27:04 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl

Error: (12/26/2014 07:27:04 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl


==================== Memory info ===========================

Processor: AMD FX(tm)-6100 Six-Core Processor
Percentage of memory in use: 31%
Total physical RAM: 8171.53 MB
Available physical RAM: 5558.59 MB
Total Pagefile: 16341.24 MB
Available Pagefile: 13317.54 MB
Total Virtual: 8192 MB
Available Virtual: 8191.77 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:172.79 GB) (Free:69.58 GB) NTFS
Drive d: () (Fixed) (Total:292.97 GB) (Free:27.66 GB) NTFS
Drive e: (Filme 2 St) (Fixed) (Total:465.61 GB) (Free:189.89 GB) NTFS
Drive f: (GSP1RMCULXFRER_EN_DVD) (CDROM) (Total:3.09 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: FFB8F33B)
Partition 1: (Not Active) - (Size=172.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=293 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 3280EB00)
Partition 1: (Active) - (Size=126 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.6 GB) - (Type=07 NTFS)

==================== End Of Log ============================

--- --- ---

cosinus 27.12.2014 15:34

Hi und :hallo:

Adware/Junkware/Toolbars entfernen

(alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!)

1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.




3. Schritt: Frisches Log mit FRST

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


reisser 27.12.2014 16:10

adw cleaner
 
AdwCleaner Logfile:
Code:

# AdwCleaner v4.106 - Report created 27/12/2014 at 15:50:26
# Updated 21/12/2014 by Xplode
# Database : 2014-12-21.4 [Live]
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : Reisser - REISSER-PC
# Running from : C:\Users\Reisser\Downloads\AdwCleaner_4.106.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
[#] Service Deleted : IePluginServices
Service Deleted : rcores
Service Deleted : ColorMedia
Service Deleted : InjectorService
Service Deleted : abengine

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\IePluginServices
Folder Deleted : C:\ProgramData\ZombieInvasion
Folder Deleted : C:\ProgramData\3980744520298899654
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pc speed up
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip
[!] Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\pc speed up
Folder Deleted : C:\Program Files (x86)\predm
Folder Deleted : C:\Program Files (x86)\CinemaHd For Pro 2.4cV27.12
Folder Deleted : C:\Users\Reisser\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Reisser\AppData\Local\Microsoft\Silverlight\OutOfBrowser\Speedchecker.PCSpeedUp
Folder Deleted : C:\Users\Reisser\AppData\Local\CrashRpt
Folder Deleted : C:\Users\Reisser\AppData\Local\DownloadManager
Folder Deleted : C:\Users\Reisser\AppData\Local\ZombieInvasion
Folder Deleted : C:\Users\Reisser\AppData\Roaming\omiga-plus
Folder Deleted : C:\Users\Reisser\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\Reisser\Documents\Optimizer Pro
File Deleted : C:\END
File Deleted : C:\Windows\rcore.exe
File Deleted : C:\Users\Reisser\AppData\Roaming\LiveSupport.exe_log.txt
File Deleted : C:\Users\Reisser\AppData\Roaming\regsvr32.exe_log.txt
File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_inst.shoppingate.info_0.localstorage
File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_inst.shoppingate.info_0.localstorage-journal
File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage
File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage-journal
File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage
File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal
File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage
File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal

***** [ Scheduled Tasks ] *****

Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : PC SpeedUp Service Deactivator
Task Deleted : Run_Bobby_Browser
Task Deleted : f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-1
Task Deleted : f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-2
Task Deleted : f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-3
Task Deleted : f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5
Task Deleted : f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-5_user
Task Deleted : f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-6
Task Deleted : f55115b9-ed36-45eb-8fb1-d52dd6dddd1e-7

***** [ Shortcuts ] *****

Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Shortcut Disinfected : C:\Users\Reisser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\Reisser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk

***** [ Registry ] *****

Key Deleted : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [livesupport]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [pcspeedup]
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\Classes\BuyNsave.BuyNsave
Key Deleted : HKLM\SOFTWARE\Classes\BuyNsave.BuyNsave.9
Key Deleted : HKLM\SOFTWARE\Classes\.
Key Deleted : HKLM\SOFTWARE\Classes\..9
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1f80c42e-d3a4-491a-8c2c-1c587df69b2e}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9c183513-92d9-43dd-81e0-9f30a36ca67f}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611571181}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622572281}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655575581}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666576681}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644574481}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571181}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1f80c42e-d3a4-491a-8c2c-1c587df69b2e}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9c183513-92d9-43dd-81e0-9f30a36ca67f}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5e62c5b3-db2c-46c6-88ae-9b102ba6421e}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f434484f-cbc8-45f2-9444-0b82be85500f}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{1f80c42e-d3a4-491a-8c2c-1c587df69b2e}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{9c183513-92d9-43dd-81e0-9f30a36ca67f}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611571181}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622572281}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3AE76A17-C344-4A83-81CE-65EFEE41E42D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4C0A69B0-CE97-42B7-86FC-08280C99C74D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E9EB4D5-C929-4005-AC62-1856B1DA5A24}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{8FAF962C-3EDE-405E-B1D0-62B8235C6044}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C1F5E799-B218-4C32-B189-3C389BA140BB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F60C9408-3110-4C98-A139-ABE1EE1111DD}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655575581}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666576681}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611571181}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5e62c5b3-db2c-46c6-88ae-9b102ba6421e}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f434484f-cbc8-45f2-9444-0b82be85500f}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\InetStat
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\OCS
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\Speedchecker Limited
Key Deleted : HKCU\Software\TutoTag
Key Deleted : HKCU\Software\StormWatchApp
Key Deleted : HKCU\Software\BoBrowser
Key Deleted : HKCU\Software\Wnkey
Key Deleted : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\DynConIE
Key Deleted : HKCU\Software\AppDataLow\Software\CinemaHd For Pro 2.4cV27.12
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\SOFTWARE\FlowSurf
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\omiga-plusSoftware
Key Deleted : HKLM\SOFTWARE\Speedchecker Limited
Key Deleted : HKLM\SOFTWARE\Tutorials
Key Deleted : HKLM\SOFTWARE\Clara
Key Deleted : HKLM\SOFTWARE\GAMESDESKTOP
Key Deleted : HKLM\SOFTWARE\CinemaHd For Pro 2.4cV27.12
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\omiga-plus uninstall
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{842C4394-47F7-60DE-480B-C09116B63559}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CinemaHd For Pro 2.4cV27.12
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : [x64] HKLM\SOFTWARE\Speedchecker Limited
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCSU-SL_is1
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\websearch.searchoholic.info

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17496

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Google Chrome v39.0.2171.65

[C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419615594&from=tugs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms}
[C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419615594&from=tugs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms}
[C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://websearch.searchoholic.info/?l=1&q={searchTerms}&pid=1091&r=2014/12/22&hid=8793653231034268742&lg=EN&cc=DE&unqvl=72
[C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3331398&octid=EB_ORIGINAL_CTID&ISID=M6911AFB1-B655-464C-8E34-5E1CC33D8BD5&SearchSource=58&CUI=&UM=6&UP=SPFCE036FE-6C01-4AD8-BCF5-2AF6403F7C7C&q={searchTerms}&SSPV=
[C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3331398&octid=EB_ORIGINAL_CTID&ISID=M6911AFB1-B655-464C-8E34-5E1CC33D8BD5&SearchSource=58&CUI=&UM=6&UP=SPFCE036FE-6C01-4AD8-BCF5-2AF6403F7C7C&q={searchTerms}&SSPV=
[C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M967FE9C1-A9A5-43A2-8659-C914B636C4B4&SearchSource=58&CUI=&UM=8&UP=SP7CE64842-07CE-4A5F-8347-E1F6816C072C&q={searchTerms}&SSPV=
[C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3322197&octid=EB_ORIGINAL_CTID&ISID=M967FE9C1-A9A5-43A2-8659-C914B636C4B4&SearchSource=58&CUI=&UM=8&UP=SP7CE64842-07CE-4A5F-8347-E1F6816C072C&q={searchTerms}&SSPV=

*************************

AdwCleaner[R0].txt - [20752 octets] - [27/12/2014 15:47:37]
AdwCleaner[S0].txt - [19862 octets] - [27/12/2014 15:50:26]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [19923 octets] ##########

--- --- ---

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 7 Ultimate x64
Ran by Reisser on 27.12.2014 at 15:56:14,99
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611171162}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611171162}



~~~ Files

Successfully deleted: [File] "C:\Users\Reisser\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Reisser\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage-journal"



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.12.2014 at 15:58:41,48
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

#
FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-12-2014
Ran by Reisser (administrator) on REISSER-PC on 27-12-2014 16:06:01
Running from C:\Users\Reisser\Downloads
Loaded Profile: Reisser (Available profiles: Reisser)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Englisch (USA)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe
(Time Lapse Solutions) C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Apple Inc.) C:\Program Files (x86)\QuickTime\qttask.exe
() C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2463552 2014-10-04] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [282624 2007-04-27] (Apple Inc.)
HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] ()
HKLM-x32\...\Run: [gmsd_de_44] => [X]
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Run: [SwvUpdtr] => C:\Users\Reisser\AppData\Local\24567\Updater.exe [773632 2014-12-27] ()
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: G - G:\StorioSetup.exe
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {2e971c8e-719e-11e4-b18f-bc5ff45b0bd1} - F:\SNC715MusicPlayer.exe
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {432e0770-7651-11e4-a244-806e6f6e6963} - F:\VTech_toy_Setup.exe
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {9dac61e2-89ed-11e4-b4c2-bc5ff45b0bd1} - G:\StorioSetup.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:50863;https=127.0.0.1:50863
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default ->
CHR StartupUrls: Default -> ""
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-26]
CHR Extension: (Google Docs) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-26]
CHR Extension: (Google Drive) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-26]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-26]
CHR Extension: (YouTube) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-26]
CHR Extension: (Google Search) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-26]
CHR Extension: (Google Sheets) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-26]
CHR Extension: (Google Wallet) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-26]
CHR Extension: (Gmail) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-26]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 dZPlDQFMAyN; C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe [2726776 2014-12-27] (Time Lapse Solutions)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-10-04] (NVIDIA Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-10-04] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-10-04] (NVIDIA Corporation)
R2 SecurityUtility Service; C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe [537248 2014-12-25] ()

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-10-04] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-27 15:58 - 2014-12-27 15:58 - 00001474 _____ () C:\Users\Reisser\Desktop\JRT.txt
2014-12-27 15:56 - 2014-12-27 15:56 - 00000000 ____D () C:\Windows\ERUNT
2014-12-27 15:53 - 2014-12-27 15:53 - 00000000 ____D () C:\Users\Reisser\AppData\Local\ZombieInvasion
2014-12-27 15:46 - 2014-12-27 15:50 - 00000000 ____D () C:\AdwCleaner
2014-12-27 15:46 - 2014-12-27 15:46 - 02173952 _____ () C:\Users\Reisser\Downloads\AdwCleaner_4.106.exe
2014-12-27 15:46 - 2014-12-27 15:46 - 01707646 _____ (Thisisu) C:\Users\Reisser\Downloads\JRT.exe
2014-12-27 15:02 - 2014-12-27 15:03 - 00027876 _____ () C:\Users\Reisser\Downloads\Addition.txt
2014-12-27 15:01 - 2014-12-27 16:06 - 00010546 _____ () C:\Users\Reisser\Downloads\FRST.txt
2014-12-27 15:01 - 2014-12-27 16:06 - 00000000 ____D () C:\FRST
2014-12-27 15:01 - 2014-12-27 15:01 - 02122752 _____ (Farbar) C:\Users\Reisser\Downloads\FRST64.exe
2014-12-27 14:59 - 2014-12-27 14:59 - 00001137 _____ () C:\Users\Reisser\Desktop\Continue File Opener Installation.lnk
2014-12-27 14:48 - 2014-12-27 14:48 - 00797824 _____ ( ) C:\Users\Reisser\Downloads\FileOpenerSetup.exe
2014-12-27 14:23 - 2014-12-27 14:23 - 00000000 ____D () C:\Program Files (x86)\2f4249ae-2ea2-4d9e-8f18-8c64e6461106
2014-12-27 14:22 - 2014-12-27 15:52 - 00001342 _____ () C:\Windows\Tasks\KWWB.job
2014-12-27 14:22 - 2014-12-27 14:23 - 00004376 _____ () C:\Windows\System32\Tasks\KWWB
2014-12-27 14:22 - 2014-12-27 14:22 - 02055144 _____ (Cinema HDV27.12) C:\Users\Reisser\AppData\Roaming\KWWB.exe
2014-12-27 12:15 - 2014-12-27 12:15 - 00000000 ____D () C:\Users\Reisser\AppData\Local\24567
2014-12-27 11:53 - 2014-12-27 15:52 - 00000000 ____D () C:\Program Files (x86)\Flwsrf
2014-12-27 11:53 - 2014-12-27 11:53 - 00004640 _____ () C:\Windows\SysWOW64\abengine.ini
2014-12-27 11:53 - 2014-12-27 11:53 - 00003090 _____ () C:\Windows\System32\Tasks\upfs7235
2014-12-27 11:53 - 2014-12-27 11:53 - 00002544 _____ () C:\Windows\SysWOW64\abengineOff.ini
2014-12-27 11:53 - 2014-12-27 11:53 - 00002544 _____ () C:\Windows\system32\abengineOff.ini
2014-12-27 11:53 - 2014-12-05 00:09 - 00370880 _____ (Abengine) C:\Windows\system32\abengine64.dll
2014-12-27 11:53 - 2014-12-05 00:09 - 00324592 _____ (Abengine) C:\Windows\SysWOW64\abengine.dll
2014-12-27 11:52 - 2014-12-27 11:52 - 00000000 ____D () C:\ProgramData\qMuLXOMiMf
2014-12-26 20:54 - 2014-12-26 21:03 - 00000000 ____D () C:\Users\Reisser\Desktop\weihnachten 14
2014-12-26 20:45 - 2014-12-26 08:06 - 00008977 _____ () C:\Users\Reisser\Downloads\rla-dtvpmt1.ts.nfo
2014-12-26 20:45 - 2014-12-25 23:20 - 745466933 _____ () C:\Users\Reisser\Downloads\die tribute von Panem.mkv
2014-12-26 20:45 - 2014-12-23 12:02 - 00000220 _____ () C:\Users\Reisser\Downloads\Goldesel.to - Die Seite fuer Direkt-Downloads aller Art.url
2014-12-26 20:45 - 2014-12-23 12:02 - 00000116 _____ () C:\Users\Reisser\Downloads\goldesel.to - quality source for more than 15 years .txt
2014-12-26 20:35 - 2014-12-26 20:42 - 208666624 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part1.rar
2014-12-26 20:34 - 2014-12-26 20:42 - 208666624 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part3.rar
2014-12-26 20:34 - 2014-12-26 20:41 - 208666624 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part2.rar
2014-12-26 20:34 - 2014-12-26 20:38 - 126903232 _____ () C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part4.rar
2014-12-26 19:28 - 2014-12-26 19:30 - 00002196 _____ () C:\Users\Reisser\Desktop\chrome.lnk
2014-12-26 19:18 - 2014-12-26 19:18 - 00003160 _____ () C:\Windows\System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B}
2014-12-26 19:06 - 2014-12-26 19:06 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\dlg
2014-12-26 19:05 - 2014-12-26 19:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-12-26 19:04 - 2014-12-27 11:44 - 00005240 _____ () C:\Windows\SysWOW64\ColorMedia.ini
2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\SysWOW64\ColorMediaOff.ini
2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\system32\ColorMediaOff.ini
2014-12-26 19:04 - 2014-12-26 19:04 - 00000000 ____D () C:\ProgramData\SecurityUtilityData
2014-12-26 19:04 - 2014-12-26 19:04 - 00000000 ____D () C:\ProgramData\SecurityUtility
2014-12-26 19:04 - 2014-12-26 19:04 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-12-26 19:04 - 2014-12-14 10:53 - 00378640 _____ (CartCrunch Israel Ltd.) C:\Windows\system32\ColorMedia64.dll
2014-12-26 19:04 - 2014-12-14 10:53 - 00332568 _____ (CartCrunch Israel Ltd.) C:\Windows\SysWOW64\ColorMedia.dll
2014-12-26 19:00 - 2014-12-26 19:00 - 00596368 _____ () C:\Users\Reisser\Downloads\download-adblock-chrome.exe
2014-12-26 18:53 - 2014-12-26 18:57 - 00019405 _____ () C:\Users\Reisser\Downloads\software_removal_tool.log
2014-12-26 18:42 - 2014-12-27 14:29 - 00000000 ___HD () C:\Users\Public\Temp
2014-12-26 18:41 - 2014-12-27 15:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-12-26 18:40 - 2014-12-27 15:52 - 00001694 _____ () C:\Windows\Tasks\PTJGYIFC.job
2014-12-26 18:40 - 2014-12-27 15:52 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-26 18:40 - 2014-12-27 15:45 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-26 18:40 - 2014-12-26 18:55 - 00001925 _____ () C:\Windows\patsearch.bin
2014-12-26 18:40 - 2014-12-26 18:40 - 01966056 _____ (HQ-VideoV26.12) C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe
2014-12-26 18:40 - 2014-12-26 18:40 - 00004728 _____ () C:\Windows\System32\Tasks\PTJGYIFC
2014-12-26 18:40 - 2014-12-26 18:40 - 00003896 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-12-26 18:40 - 2014-12-26 18:40 - 00003644 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-12-26 18:40 - 2014-12-26 18:40 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrNewH_01009.Wdf
2014-12-26 18:35 - 2014-12-26 18:35 - 00000000 ___DC () C:\Users\Reisser\AppData\Local\MigWiz
2014-12-26 07:16 - 2014-12-26 07:16 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2014-12-25 18:43 - 2014-12-25 20:53 - 1995124610 _____ () C:\Users\Reisser\Downloads\Orphan.Das.Waisenkind.German.AC3.HDRip.XViD-FuN.avi
2014-12-25 16:59 - 2014-12-25 17:00 - 00000000 ____D () C:\Users\Reisser\Downloads\34020109
2014-12-25 14:19 - 2014-12-23 09:12 - 00000000 ____D () C:\Users\Reisser\Downloads\Ice_Age_Sid_Und_Seine_Freunde-Cool_Und_Locker-2014-NoGroup
2014-12-24 17:15 - 2014-12-24 17:15 - 00000000 ____D () C:\Program Files (x86)\Ripple Emulator
2014-12-24 17:14 - 2014-12-24 17:14 - 00000000 ____D () C:\Program Files (x86)\BuyyNsaave
2014-12-24 17:13 - 2014-12-24 17:13 - 00000000 ____D () C:\ProgramData\migbhnamcclanachieldofcbpebkajke
2014-12-23 23:14 - 2014-11-04 16:50 - 878567444 _____ () C:\Users\Reisser\Downloads\The Purge 2.mkv
2014-12-22 21:43 - 2014-12-22 21:43 - 00000000 ____D () C:\Users\Reisser\Downloads\G0neGrl.ld.HD.de
2014-12-22 17:40 - 2014-12-22 17:40 - 00000000 ____D () C:\ProgramData\3872871776
2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\VTech
2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTech
2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\Program Files (x86)\VTech
2014-12-19 17:14 - 2014-12-19 17:14 - 00000000 _____ () C:\Users\Reisser\AppData\Local\{E9C16533-9CB5-45BF-A1F9-47B28A73E05D}
2014-12-18 15:33 - 2014-12-18 17:29 - 00000000 ____D () C:\Users\Reisser\Downloads\Hörbücher
2014-12-18 13:21 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-18 13:21 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-17 17:42 - 2014-12-17 17:42 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\NVIDIA
2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Mindscape
2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mindscape
2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mindscape
2014-12-17 17:39 - 2014-12-17 17:39 - 00000000 ____D () C:\Program Files (x86)\Mindscape
2014-12-17 17:36 - 2014-12-17 17:36 - 00054156 ____H () C:\Windows\QTFont.qfn
2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-12-17 17:32 - 2014-12-17 17:35 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-12-12 23:05 - 2014-12-12 23:05 - 00159200 ____T () C:\Users\Reisser\AppData\Roaming\CrashRpt1402.dll
2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIW Pro Trial
2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\Program Files (x86)\SIW Pro Trial
2014-12-12 03:19 - 2014-12-12 03:19 - 00000000 ____D () C:\Windows\system32\appraiser
2014-12-12 03:01 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-12 03:01 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-12 03:01 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-12-12 03:01 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-12-12 03:01 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-12-12 03:01 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-12-12 03:01 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-12-12 03:01 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-12-12 03:01 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-12-12 03:01 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2014-12-11 04:56 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-12-11 04:56 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2014-12-11 04:55 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-11 04:55 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-11 04:55 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-11 04:55 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-11 04:55 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-11 04:55 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-11 04:55 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-11 04:55 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-11 04:55 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-11 04:55 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-11 04:55 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-11 04:55 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-11 04:55 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-11 04:55 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-11 04:55 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-11 04:55 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-11 04:55 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-11 04:55 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-11 04:55 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-11 04:55 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-11 04:55 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-11 04:55 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-11 04:55 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-11 04:55 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-11 04:55 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-11 04:55 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-11 04:55 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-11 04:55 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-11 04:55 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-11 04:55 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-11 04:55 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-11 04:55 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-11 04:55 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-11 04:55 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-11 04:55 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-11 04:55 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-11 04:55 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-11 04:55 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-11 04:55 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-11 04:55 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-11 04:55 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-11 04:55 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-11 04:55 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-11 04:55 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-11 04:55 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-11 04:55 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-11 04:55 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-11 04:55 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-11 04:55 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-11 04:55 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-11 04:55 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-11 04:55 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-11 04:55 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-11 04:55 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-11 04:55 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-11 04:55 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-11 04:55 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-11 04:54 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-11 04:54 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-11 04:54 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-11 04:54 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-11 04:54 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-11 04:54 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-11 04:54 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-11 04:54 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-11 04:54 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-11 04:54 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-11 04:54 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-11 04:54 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-11 04:54 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-11 04:54 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-12-11 00:26 - 2014-12-11 00:26 - 01413208 _____ () C:\Windows\Minidump\121114-20248-01.dmp
2014-12-05 12:01 - 2014-12-27 11:40 - 00012288 _____ () C:\Users\Reisser\Desktop\Stundenzettelfür Feru - Dezember14 -.xls
2014-12-04 13:29 - 2014-12-13 15:32 - 00000062 _____ () C:\Users\Reisser\Desktop\Neues Textdokument.txt
2014-12-04 12:53 - 2014-12-25 14:20 - 00000000 ____D () C:\Users\Reisser\Downloads\Musik
2014-12-04 12:52 - 2014-12-09 19:08 - 00000000 ____D () C:\Users\Reisser\Downloads\Kinder Filme
2014-11-28 13:23 - 2014-12-11 00:26 - 564424988 _____ () C:\Windows\MEMORY.DMP
2014-11-28 13:23 - 2014-12-11 00:26 - 00000000 ____D () C:\Windows\Minidump
2014-11-27 19:28 - 2014-12-22 18:10 - 00000000 ____D () C:\Users\Reisser\Desktop\Wallpapers
2014-11-27 18:51 - 2014-11-27 18:51 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-11-27 18:20 - 2014-11-27 18:21 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Nero
2014-11-27 18:15 - 2014-11-27 18:50 - 00000000 ____D () C:\ProgramData\Nero
2014-11-27 18:14 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2014-11-27 18:14 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2014-11-27 18:13 - 2014-11-27 18:13 - 00000000 ____D () C:\ProgramData\Package Cache
2014-11-27 17:58 - 2014-11-27 18:17 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\DeepBurner
2014-11-27 17:57 - 2014-11-27 17:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DeepBurner
2014-11-27 17:57 - 2014-11-27 17:57 - 00000000 ____D () C:\Program Files (x86)\Astonsoft
2014-11-27 17:21 - 2014-11-27 17:21 - 00000000 ____D () C:\Users\Reisser\Documents\Ashampoo Burning Studio FREE
2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Ashampoo
2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\Users\Reisser\AppData\Local\ashampoo
2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-11-27 17:18 - 2014-11-27 17:18 - 00000000 ____D () C:\Program Files (x86)\Ashampoo

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-27 15:59 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-27 15:59 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-27 15:58 - 2014-11-08 16:15 - 00697256 _____ () C:\Windows\system32\perfh007.dat
2014-12-27 15:58 - 2014-11-08 16:15 - 00149224 _____ () C:\Windows\system32\perfc007.dat
2014-12-27 15:58 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-27 15:55 - 2014-11-08 14:39 - 01982971 _____ () C:\Windows\WindowsUpdate.log
2014-12-27 15:51 - 2014-11-08 14:52 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-12-27 15:51 - 2010-11-21 04:47 - 00038116 _____ () C:\Windows\PFRO.log
2014-12-27 15:51 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-27 15:51 - 2009-07-14 05:51 - 00041515 _____ () C:\Windows\setupact.log
2014-12-27 15:50 - 2014-11-08 14:42 - 00000993 _____ () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-12-27 14:23 - 2014-11-08 15:29 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Users\Reisser\AppData\Local\Google
2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Program Files (x86)\Google
2014-12-25 12:22 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-22 18:10 - 2014-11-10 17:53 - 00000000 ____D () C:\Users\Reisser\Downloads\Filme
2014-12-17 17:42 - 2014-11-08 14:42 - 00000000 ____D () C:\Users\Reisser\AppData\Local\VirtualStore
2014-12-12 05:23 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-12-12 03:19 - 2014-11-08 19:04 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-12-12 03:04 - 2014-11-08 19:30 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-12 03:02 - 2014-11-08 19:30 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-11 00:29 - 2014-11-16 15:02 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-12-05 11:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-01 06:58 - 2014-11-20 17:29 - 00012288 _____ () C:\Users\Reisser\Desktop\Stundenzettelfür Feru - November 14 - Kopie.xls
2014-11-27 18:20 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Cursors

Some content of TEMP:
====================
C:\Users\Reisser\AppData\Local\Temp\089C73368233.exe
C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.dll
C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.exe
C:\Users\Reisser\AppData\Local\Temp\EFDF6877-8E55-A3B8-0364-69652FE51F4F.exe
C:\Users\Reisser\AppData\Local\Temp\ICReinstall_FileOpenerSetup.exe
C:\Users\Reisser\AppData\Local\Temp\Launcher__10272.exe
C:\Users\Reisser\AppData\Local\Temp\Launcher__9848.exe
C:\Users\Reisser\AppData\Local\Temp\Launcher__9999.exe
C:\Users\Reisser\AppData\Local\Temp\LiveSupport_setup.exe
C:\Users\Reisser\AppData\Local\Temp\ms.exe
C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Reisser\AppData\Local\Temp\nvStInst.exe
C:\Users\Reisser\AppData\Local\Temp\optprosetup.exe
C:\Users\Reisser\AppData\Local\Temp\Quarantine.exe
C:\Users\Reisser\AppData\Local\Temp\setup_384.exe
C:\Users\Reisser\AppData\Local\Temp\SpOrder.dll
C:\Users\Reisser\AppData\Local\Temp\sqlite3.dll
C:\Users\Reisser\AppData\Local\Temp\Storio2_DE_ger_Setup_pid_1588.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-12-15 17:20

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---

ist das alles so richtig?

cosinus 27.12.2014 17:09

Bitte auch ne neue Addition.txt erstellen, dazu FRST starten und einen Haken setzen bei Addition.txt, dann auf Scan klicken.

http://saved.im/mtg0mjy4yjlu/2014-04...ryscantool.png

reisser 28.12.2014 12:23

FRST Additions Logfile:
Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-12-2014
Ran by Reisser at 2014-12-28 12:20:59
Running from C:\Users\Reisser\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Abenteuer Pferderücken Demo (HKLM-x32\...\Abenteuer Pferderücken Demo) (Version:  - )
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Ashampoo Burning Studio FREE v.1.14.5 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.12.0 - Asmedia Technology)
Flwsrf (HKLM-x32\...\Flwsrf) (Version: 3.0.0.2 - Flwsrf) <==== ATTENTION!
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.65 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
K-Lite Codec Pack 10.8.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.8.0 - )
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
mkv2vob (HKLM-x32\...\{21AE04E8-EBF6-40DB-9AA9-B7A80C5D057D}) (Version: 2.4.9 - 3r1c)
NVIDIA 3D Vision Controller Driver 344.46 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 344.46 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 344.60 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.3 - NVIDIA Corporation)
NVIDIA Graphics Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.60 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.32.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
QuickTime (HKLM-x32\...\{08094E03-AFE4-4853-9D31-6D0743DF5328}) (Version: 7.1.6.200 - Apple Computer, Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.)
SecurityUtility (HKLM-x32\...\SecurityUtility) (Version: 1.0.0.992 - )
SHIELD Streaming (Version: 3.1.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.13.56 - NVIDIA Corporation) Hidden
SIW Pro Edition (Trial Version) (HKLM-x32\...\{3B9704C8-1286-4a17-9EA8-F63004FC74A1}_is1) (Version: 2014.10.16 - Topala Software Solutions)
VTech Download Agent Library (x32 Version: 1.00.0000 - VTech) Hidden
VTech Download Manager (HKLM-x32\...\VTechDownloadManager) (Version:  - VTech)
WinRAR 5.10 Beta 4 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH)
Zombie Invasion (HKLM-x32\...\ZombieInvasion) (Version: 2.7.50 - Time Lapse Solutions)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

22-12-2014 17:38:19 Removed Apple Software Update
25-12-2014 17:07:37 Windows Update
26-12-2014 18:53:33 Software Removal Tool
28-12-2014 03:00:23 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {07C4EDDE-20D1-4BFF-8659-B50E309D06FA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.)
Task: {32E4AC8B-D955-4847-BF7D-215EA9001513} - System32\Tasks\PTJGYIFC => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe [2014-12-26] (HQ-VideoV26.12) <==== ATTENTION
Task: {7C46BBB5-8422-47C1-A9C2-3BB2C3C41657} - System32\Tasks\upfs7235 => C:\Program Files (x86)\Flwsrf\upfs7235.exe [2014-12-05] ()
Task: {850FC5E5-AE51-4C51-95E1-FF3768705CCA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.)
Task: {8B1C00F0-602F-40B2-9557-43584EC56145} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2014-10-06] ()
Task: {E1B12AA3-8587-49F7-8FD4-24A42FBB9ED3} - System32\Tasks\KWWB => C:\Users\Reisser\AppData\Roaming\KWWB.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION
Task: {F125BC51-2941-4F4A-B676-B6C8A5B0E166} - System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B} => pcalua.exe -a C:\Users\Reisser\AppData\Roaming\omiga-plus\UninstallManager.exe -c  -ptid=tugs
Task: {F1E05127-80E4-400F-8C60-436999246896} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\KWWB.job => C:\Users\Reisser\AppData\Roaming\KWWB.exe <==== ATTENTION
Task: C:\Windows\Tasks\PTJGYIFC.job => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2014-11-08 14:51 - 2014-10-30 03:10 - 00117064 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-12-26 19:04 - 2014-12-25 19:14 - 00537248 _____ () C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe
2014-10-13 02:49 - 2014-06-20 07:42 - 00401280 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
2014-10-13 02:49 - 2014-03-04 12:20 - 00117760 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QtSolutions_SOAP-2.7.dll
2014-10-13 02:49 - 2014-04-22 03:14 - 00065536 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QHttpServer.dll
2014-10-13 02:49 - 2014-05-06 06:39 - 00861184 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\platforms\qwindows.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00021504 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qgif.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00020992 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qico.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00204800 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qjpeg.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00218112 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qmng.dll
2014-10-13 02:49 - 2014-05-06 06:58 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qsvg.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00015360 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtga.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00307712 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtiff.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00014848 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qwbmp.dll
2014-10-13 02:49 - 2014-05-06 07:31 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\sensors\qtsensors_dummy.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00036352 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qgenericbearer.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00038912 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qnativewifibearer.dll
2014-12-26 18:41 - 2014-11-14 22:15 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\libglesv2.dll
2014-12-26 18:41 - 2014-11-14 22:15 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\libegl.dll
2014-12-26 18:41 - 2014-11-14 22:15 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\pdf.dll
2014-12-26 18:41 - 2014-11-14 22:15 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\ffmpegsumo.dll
2014-12-26 18:41 - 2014-11-14 22:15 - 14910280 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.65\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\abengine => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ColorMedia => ""="service"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


========================= Accounts: ==========================

Administrator (S-1-5-21-1744345613-2801571155-2633355246-500 - Administrator - Disabled)
Guest (S-1-5-21-1744345613-2801571155-2633355246-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1744345613-2801571155-2633355246-1002 - Limited - Enabled)
Reisser (S-1-5-21-1744345613-2801571155-2633355246-1000 - Administrator - Enabled) => C:\Users\Reisser

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================

System errors:
=============
Error: (12/28/2014 00:10:09 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT AUTHORITY60 ein Fehler festgestellt.

        Neue Signaturversion:

        Vorherige Signaturversion: 1.191.939.0

        Aktualisierungsquelle: %NT AUTHORITY59

        Aktualisierungsphase: 4.6.0305.00

        Quellpfad: 4.6.0305.01

        Signaturtyp: %NT AUTHORITY602

        Aktualisierungstyp: %NT AUTHORITY604

        Benutzer: NT AUTHORITY\SYSTEM

        Aktuelle Modulversion: %NT AUTHORITY605

        Vorherige Modulversion: %NT AUTHORITY606

        Fehlercode: %NT AUTHORITY607

        Fehlerbeschreibung: %NT AUTHORITY608

Error: (12/28/2014 10:44:05 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT AUTHORITY60 ein Fehler festgestellt.

        Neue Signaturversion:

        Vorherige Signaturversion: 1.191.939.0

        Aktualisierungsquelle: %NT AUTHORITY59

        Aktualisierungsphase: 4.6.0305.00

        Quellpfad: 4.6.0305.01

        Signaturtyp: %NT AUTHORITY602

        Aktualisierungstyp: %NT AUTHORITY604

        Benutzer: NT AUTHORITY\SYSTEM

        Aktuelle Modulversion: %NT AUTHORITY605

        Vorherige Modulversion: %NT AUTHORITY606

        Fehlercode: %NT AUTHORITY607

        Fehlerbeschreibung: %NT AUTHORITY608

Error: (12/28/2014 03:00:23 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT AUTHORITY60 ein Fehler festgestellt.

        Neue Signaturversion:

        Vorherige Signaturversion: 1.191.939.0

        Aktualisierungsquelle: %NT AUTHORITY59

        Aktualisierungsphase: 4.6.0305.00

        Quellpfad: 4.6.0305.01

        Signaturtyp: %NT AUTHORITY602

        Aktualisierungstyp: %NT AUTHORITY604

        Benutzer: NT AUTHORITY\SYSTEM

        Aktuelle Modulversion: %NT AUTHORITY605

        Vorherige Modulversion: %NT AUTHORITY606

        Fehlercode: %NT AUTHORITY607

        Fehlerbeschreibung: %NT AUTHORITY608

Error: (12/28/2014 00:53:41 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT AUTHORITY60 ein Fehler festgestellt.

        Neue Signaturversion:

        Vorherige Signaturversion: 1.191.939.0

        Aktualisierungsquelle: %NT AUTHORITY59

        Aktualisierungsphase: 4.6.0305.00

        Quellpfad: 4.6.0305.01

        Signaturtyp: %NT AUTHORITY602

        Aktualisierungstyp: %NT AUTHORITY604

        Benutzer: NT AUTHORITY\SYSTEM

        Aktuelle Modulversion: %NT AUTHORITY605

        Vorherige Modulversion: %NT AUTHORITY606

        Fehlercode: %NT AUTHORITY607

        Fehlerbeschreibung: %NT AUTHORITY608

Error: (12/27/2014 08:44:29 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT AUTHORITY60 ein Fehler festgestellt.

        Neue Signaturversion:

        Vorherige Signaturversion: 1.191.939.0

        Aktualisierungsquelle: %NT AUTHORITY59

        Aktualisierungsphase: 4.6.0305.00

        Quellpfad: 4.6.0305.01

        Signaturtyp: %NT AUTHORITY602

        Aktualisierungstyp: %NT AUTHORITY604

        Benutzer: NT AUTHORITY\SYSTEM

        Aktuelle Modulversion: %NT AUTHORITY605

        Vorherige Modulversion: %NT AUTHORITY606

        Fehlercode: %NT AUTHORITY607

        Fehlerbeschreibung: %NT AUTHORITY608

Error: (12/27/2014 08:34:34 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}


Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Processor: AMD FX(tm)-6100 Six-Core Processor
Percentage of memory in use: 26%
Total physical RAM: 8171.53 MB
Available physical RAM: 5989.85 MB
Total Pagefile: 16641.24 MB
Available Pagefile: 13664.34 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:172.79 GB) (Free:68.8 GB) NTFS
Drive d: () (Fixed) (Total:292.97 GB) (Free:27.66 GB) NTFS
Drive e: (Filme 2 St) (Fixed) (Total:465.61 GB) (Free:189.89 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: FFB8F33B)
Partition 1: (Not Active) - (Size=172.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=293 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 3280EB00)
Partition 1: (Active) - (Size=126 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.6 GB) - (Type=07 NTFS)

==================== End Of Log ============================

--- --- ---

cosinus 28.12.2014 23:44

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKLM-x32\...\Run: [gmsd_de_44] => [X]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:50863;https=127.0.0.1:50863
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
R2 dZPlDQFMAyN; C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe [2726776 2014-12-27] (Time Lapse Solutions)
Task: {32E4AC8B-D955-4847-BF7D-215EA9001513} - System32\Tasks\PTJGYIFC => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe [2014-12-26] (HQ-VideoV26.12) <==== ATTENTION
Task: {7C46BBB5-8422-47C1-A9C2-3BB2C3C41657} - System32\Tasks\upfs7235 => C:\Program Files (x86)\Flwsrf\upfs7235.exe [2014-12-05] ()
Task: {E1B12AA3-8587-49F7-8FD4-24A42FBB9ED3} - System32\Tasks\KWWB => C:\Users\Reisser\AppData\Roaming\KWWB.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION
Task: {F125BC51-2941-4F4A-B676-B6C8A5B0E166} - System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B} => pcalua.exe -a C:\Users\Reisser\AppData\Roaming\omiga-plus\UninstallManager.exe -c  -ptid=tugs
Task: C:\Windows\Tasks\KWWB.job => C:\Users\Reisser\AppData\Roaming\KWWB.exe <==== ATTENTION
Task: C:\Windows\Tasks\PTJGYIFC.job => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe <==== ATTENTION
C:\Users\Reisser\AppData\Roaming\omiga-plus
C:\Users\Reisser\AppData\Local\Temp\089C73368233.exe
C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.dll
C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.exe
C:\Users\Reisser\AppData\Local\Temp\EFDF6877-8E55-A3B8-0364-69652FE51F4F.exe
C:\Users\Reisser\AppData\Local\Temp\ICReinstall_FileOpenerSetup.exe
C:\Users\Reisser\AppData\Local\Temp\Launcher__10272.exe
C:\Users\Reisser\AppData\Local\Temp\Launcher__9848.exe
C:\Users\Reisser\AppData\Local\Temp\Launcher__9999.exe
C:\Users\Reisser\AppData\Local\Temp\LiveSupport_setup.exe
C:\Users\Reisser\AppData\Local\Temp\ms.exe
C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Reisser\AppData\Local\Temp\nvStInst.exe
C:\Users\Reisser\AppData\Local\Temp\optprosetup.exe
C:\Users\Reisser\AppData\Local\Temp\Quarantine.exe
C:\Users\Reisser\AppData\Local\Temp\setup_384.exe
C:\Users\Reisser\AppData\Local\Temp\SpOrder.dll
C:\Users\Reisser\AppData\Local\Temp\sqlite3.dll
C:\Users\Reisser\AppData\Local\Temp\Storio2_DE_ger_Setup_pid_1588.exe
C:\Users\Reisser\Desktop\Continue File Opener Installation.lnk
C:\Users\Reisser\Downloads\FileOpenerSetup.exe
C:\Program Files (x86)\2f4249ae-2ea2-4d9e-8f18-8c64e6461106
C:\Windows\Tasks\KWWB.job
C:\Windows\System32\Tasks\KWWB
C:\Users\Reisser\AppData\Roaming\KWWB.exe
C:\Program Files (x86)\Flwsrf
C:\Windows\SysWOW64\abengine.ini
C:\Windows\System32\Tasks\upfs7235
C:\Windows\SysWOW64\abengineOff.ini
C:\Windows\system32\abengineOff.ini
C:\Windows\system32\abengine64.dll
C:\Windows\SysWOW64\abengine.dll
C:\ProgramData\qMuLXOMiMf
C:\Users\Reisser\Downloads\rla-dtvpmt1.ts.nfo
C:\Users\Reisser\Downloads\Goldesel.to - Die Seite fuer Direkt-Downloads aller Art.url
C:\Users\Reisser\Downloads\goldesel.to - quality source for more than 15 years .txt
C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part1.rar
C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part3.rar
C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part2.rar
C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part4.rar
C:\Windows\System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B}
C:\Users\Reisser\Downloads\Orphan.Das.Waisenkind.German.AC3.HDRip.XViD-FuN.avi
C:\Users\Reisser\AppData\Roaming\dlg
C:\ProgramData\SecurityUtilityData
C:\ProgramData\SecurityUtility
C:\Windows\Tasks\PTJGYIFC.job
C:\Windows\patsearch.bin
C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe
C:\Windows\System32\Tasks\PTJGYIFC
C:\Users\Reisser\Downloads\34020109
C:\Program Files (x86)\BuyyNsaave
C:\ProgramData\migbhnamcclanachieldofcbpebkajke
C:\Users\Reisser\Downloads\The Purge 2.mkv
C:\Users\Reisser\Downloads\G0neGrl.ld.HD.de
C:\ProgramData\3872871776
C:\ProgramData\SecurityUtility
C:\ProgramData\qMuLXOMiMf
C:\Users\Reisser\AppData\Local\24567
EmptyTemp:
Hosts:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


reisser 29.12.2014 10:56

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-12-2014
Ran by Reisser at 2014-12-29 08:15:52 Run:1
Running from C:\Users\Reisser\Downloads\FRST-OlderVersion
Loaded Profile: Reisser (Available profiles: Reisser)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
HKLM-x32\...\Run: [gmsd_de_44] => [X]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:50863;https=127.0.0.1:50863
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
R2 dZPlDQFMAyN; C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe [2726776 2014-12-27] (Time Lapse Solutions)
Task: {32E4AC8B-D955-4847-BF7D-215EA9001513} - System32\Tasks\PTJGYIFC => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe [2014-12-26] (HQ-VideoV26.12) <==== ATTENTION
Task: {7C46BBB5-8422-47C1-A9C2-3BB2C3C41657} - System32\Tasks\upfs7235 => C:\Program Files (x86)\Flwsrf\upfs7235.exe [2014-12-05] ()
Task: {E1B12AA3-8587-49F7-8FD4-24A42FBB9ED3} - System32\Tasks\KWWB => C:\Users\Reisser\AppData\Roaming\KWWB.exe [2014-12-27] (Cinema HDV27.12) <==== ATTENTION
Task: {F125BC51-2941-4F4A-B676-B6C8A5B0E166} - System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B} => pcalua.exe -a C:\Users\Reisser\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=tugs
Task: C:\Windows\Tasks\KWWB.job => C:\Users\Reisser\AppData\Roaming\KWWB.exe <==== ATTENTION
Task: C:\Windows\Tasks\PTJGYIFC.job => C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe <==== ATTENTION
C:\Users\Reisser\AppData\Roaming\omiga-plus
C:\Users\Reisser\AppData\Local\Temp\089C73368233.exe
C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.dll
C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.exe
C:\Users\Reisser\AppData\Local\Temp\EFDF6877-8E55-A3B8-0364-69652FE51F4F.exe
C:\Users\Reisser\AppData\Local\Temp\ICReinstall_FileOpenerSetup.exe
C:\Users\Reisser\AppData\Local\Temp\Launcher__10272.exe
C:\Users\Reisser\AppData\Local\Temp\Launcher__9848.exe
C:\Users\Reisser\AppData\Local\Temp\Launcher__9999.exe
C:\Users\Reisser\AppData\Local\Temp\LiveSupport_setup.exe
C:\Users\Reisser\AppData\Local\Temp\ms.exe
C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\Reisser\AppData\Local\Temp\nvStInst.exe
C:\Users\Reisser\AppData\Local\Temp\optprosetup.exe
C:\Users\Reisser\AppData\Local\Temp\Quarantine.exe
C:\Users\Reisser\AppData\Local\Temp\setup_384.exe
C:\Users\Reisser\AppData\Local\Temp\SpOrder.dll
C:\Users\Reisser\AppData\Local\Temp\sqlite3.dll
C:\Users\Reisser\AppData\Local\Temp\Storio2_DE_ger_Setup_pid_1588.exe
C:\Users\Reisser\Desktop\Continue File Opener Installation.lnk
C:\Users\Reisser\Downloads\FileOpenerSetup.exe
C:\Program Files (x86)\2f4249ae-2ea2-4d9e-8f18-8c64e6461106
C:\Windows\Tasks\KWWB.job
C:\Windows\System32\Tasks\KWWB
C:\Users\Reisser\AppData\Roaming\KWWB.exe
C:\Program Files (x86)\Flwsrf
C:\Windows\SysWOW64\abengine.ini
C:\Windows\System32\Tasks\upfs7235
C:\Windows\SysWOW64\abengineOff.ini
C:\Windows\system32\abengineOff.ini
C:\Windows\system32\abengine64.dll
C:\Windows\SysWOW64\abengine.dll
C:\ProgramData\qMuLXOMiMf
C:\Users\Reisser\Downloads\rla-dtvpmt1.ts.nfo
C:\Users\Reisser\Downloads\Goldesel.to - Die Seite fuer Direkt-Downloads aller Art.url
C:\Users\Reisser\Downloads\goldesel.to - quality source for more than 15 years .txt
C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part1.rar
C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part3.rar
C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part2.rar
C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part4.rar
C:\Windows\System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B}
C:\Users\Reisser\Downloads\Orphan.Das.Waisenkind.German.AC3.HDRip.XViD-FuN.avi
C:\Users\Reisser\AppData\Roaming\dlg
C:\ProgramData\SecurityUtilityData
C:\ProgramData\SecurityUtility
C:\Windows\Tasks\PTJGYIFC.job
C:\Windows\patsearch.bin
C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe
C:\Windows\System32\Tasks\PTJGYIFC
C:\Users\Reisser\Downloads\34020109
C:\Program Files (x86)\BuyyNsaave
C:\ProgramData\migbhnamcclanachieldofcbpebkajke
C:\Users\Reisser\Downloads\The Purge 2.mkv
C:\Users\Reisser\Downloads\G0neGrl.ld.HD.de
C:\ProgramData\3872871776
C:\ProgramData\SecurityUtility
C:\ProgramData\qMuLXOMiMf
C:\Users\Reisser\AppData\Local\24567
EmptyTemp:
Hosts:
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\gmsd_de_44 => value deleted successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
dZPlDQFMAyN => Unable to stop service
dZPlDQFMAyN => Service deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{32E4AC8B-D955-4847-BF7D-215EA9001513}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{32E4AC8B-D955-4847-BF7D-215EA9001513}" => Key deleted successfully.
C:\Windows\System32\Tasks\PTJGYIFC => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PTJGYIFC" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7C46BBB5-8422-47C1-A9C2-3BB2C3C41657}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7C46BBB5-8422-47C1-A9C2-3BB2C3C41657}" => Key deleted successfully.
C:\Windows\System32\Tasks\upfs7235 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\upfs7235" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E1B12AA3-8587-49F7-8FD4-24A42FBB9ED3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E1B12AA3-8587-49F7-8FD4-24A42FBB9ED3}" => Key deleted successfully.
C:\Windows\System32\Tasks\KWWB => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\KWWB" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F125BC51-2941-4F4A-B676-B6C8A5B0E166}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F125BC51-2941-4F4A-B676-B6C8A5B0E166}" => Key deleted successfully.
C:\Windows\System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FAE8AC9F-4635-4533-905E-1266F8CF043B}" => Key deleted successfully.
C:\Windows\Tasks\KWWB.job => Moved successfully.
C:\Windows\Tasks\PTJGYIFC.job => Moved successfully.
"C:\Users\Reisser\AppData\Roaming\omiga-plus" => File/Directory not found.
C:\Users\Reisser\AppData\Local\Temp\089C73368233.exe => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.dll => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\D3065033-A7E9-A772-2B8A-BEFA7C6AFE24.exe => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\EFDF6877-8E55-A3B8-0364-69652FE51F4F.exe => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\ICReinstall_FileOpenerSetup.exe => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\Launcher__10272.exe => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\Launcher__9848.exe => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\Launcher__9999.exe => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\LiveSupport_setup.exe => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\ms.exe => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI.dll => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\nvSCPAPI64.dll => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\nvStInst.exe => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\optprosetup.exe => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\setup_384.exe => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\SpOrder.dll => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\sqlite3.dll => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\Storio2_DE_ger_Setup_pid_1588.exe => Moved successfully.
C:\Users\Reisser\Desktop\Continue File Opener Installation.lnk => Moved successfully.
C:\Users\Reisser\Downloads\FileOpenerSetup.exe => Moved successfully.
C:\Program Files (x86)\2f4249ae-2ea2-4d9e-8f18-8c64e6461106 => Moved successfully.
"C:\Windows\Tasks\KWWB.job" => File/Directory not found.
"C:\Windows\System32\Tasks\KWWB" => File/Directory not found.
C:\Users\Reisser\AppData\Roaming\KWWB.exe => Moved successfully.
C:\Program Files (x86)\Flwsrf => Moved successfully.
C:\Windows\SysWOW64\abengine.ini => Moved successfully.
"C:\Windows\System32\Tasks\upfs7235" => File/Directory not found.
C:\Windows\SysWOW64\abengineOff.ini => Moved successfully.
C:\Windows\system32\abengineOff.ini => Moved successfully.
C:\Windows\system32\abengine64.dll => Moved successfully.
C:\Windows\SysWOW64\abengine.dll => Moved successfully.

"C:\ProgramData\qMuLXOMiMf" directory move:

Could not move "C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.dat" => Scheduled to move on reboot.
C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe => Moved successfully.
C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.exe.config => Moved successfully.
Could not move "C:\ProgramData\qMuLXOMiMf\info.dat" => Scheduled to move on reboot.
Could not move "C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe" => Scheduled to move on reboot.
Could not move "C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe.config" => Scheduled to move on reboot.
Could not move "C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe" => Scheduled to move on reboot.
Could not move "C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe.config" => Scheduled to move on reboot.
Could not move "C:\ProgramData\qMuLXOMiMf\dat\fvbqzObVHb.dll" => Scheduled to move on reboot.
Could not move "C:\ProgramData\qMuLXOMiMf\dat\WQSxEJcIi.dll" => Scheduled to move on reboot.
Could not move "C:\ProgramData\qMuLXOMiMf" directory. => Scheduled to move on reboot.

C:\Users\Reisser\Downloads\rla-dtvpmt1.ts.nfo => Moved successfully.
C:\Users\Reisser\Downloads\Goldesel.to - Die Seite fuer Direkt-Downloads aller Art.url => Moved successfully.
"C:\Users\Reisser\Downloads\goldesel.to - quality source for more than 15 years .txt" => File/Directory not found.
C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part1.rar => Moved successfully.
C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part3.rar => Moved successfully.
C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part2.rar => Moved successfully.
C:\Users\Reisser\Downloads\DTVP.Mockingjay.Teil1-RELiABLE.part4.rar => Moved successfully.
"C:\Windows\System32\Tasks\{FAE8AC9F-4635-4533-905E-1266F8CF043B}" => File/Directory not found.
C:\Users\Reisser\Downloads\Orphan.Das.Waisenkind.German.AC3.HDRip.XViD-FuN.avi => Moved successfully.
C:\Users\Reisser\AppData\Roaming\dlg => Moved successfully.
C:\ProgramData\SecurityUtilityData => Moved successfully.
C:\ProgramData\SecurityUtility => Moved successfully.
"C:\Windows\Tasks\PTJGYIFC.job" => File/Directory not found.
C:\Windows\patsearch.bin => Moved successfully.
C:\Users\Reisser\AppData\Roaming\PTJGYIFC.exe => Moved successfully.
"C:\Windows\System32\Tasks\PTJGYIFC" => File/Directory not found.
C:\Users\Reisser\Downloads\34020109 => Moved successfully.
C:\Program Files (x86)\BuyyNsaave => Moved successfully.
C:\ProgramData\migbhnamcclanachieldofcbpebkajke => Moved successfully.
C:\Users\Reisser\Downloads\The Purge 2.mkv => Moved successfully.
C:\Users\Reisser\Downloads\G0neGrl.ld.HD.de => Moved successfully.
C:\ProgramData\3872871776 => Moved successfully.
"C:\ProgramData\SecurityUtility" => File/Directory not found.

"C:\ProgramData\qMuLXOMiMf" directory move:

Could not move "C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.dat" => Scheduled to move on reboot.
Could not move "C:\ProgramData\qMuLXOMiMf\info.dat" => Scheduled to move on reboot.
Could not move "C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe" => Scheduled to move on reboot.
Could not move "C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe.config" => Scheduled to move on reboot.
Could not move "C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe" => Scheduled to move on reboot.
Could not move "C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe.config" => Scheduled to move on reboot.
Could not move "C:\ProgramData\qMuLXOMiMf\dat\fvbqzObVHb.dll" => Scheduled to move on reboot.
Could not move "C:\ProgramData\qMuLXOMiMf\dat\WQSxEJcIi.dll" => Scheduled to move on reboot.
Could not move "C:\ProgramData\qMuLXOMiMf" directory. => Scheduled to move on reboot.

C:\Users\Reisser\AppData\Local\24567 => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 14.2 GB temporary data.

=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-12-29 08:17:48)<=

C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.dat => Is moved successfully.
C:\ProgramData\qMuLXOMiMf\info.dat => Is moved successfully.
C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe => Is moved successfully.
C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe.config => Is moved successfully.
C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe => Is moved successfully.
C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe.config => Is moved successfully.
C:\ProgramData\qMuLXOMiMf\dat\fvbqzObVHb.dll => Is moved successfully.
C:\ProgramData\qMuLXOMiMf\dat\WQSxEJcIi.dll => Is moved successfully.
C:\ProgramData\qMuLXOMiMf => Is moved successfully.
C:\ProgramData\qMuLXOMiMf\dZPlDQFMAyN.dat => Is moved successfully.
C:\ProgramData\qMuLXOMiMf\info.dat => Is moved successfully.
C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe => Is moved successfully.
C:\ProgramData\qMuLXOMiMf\dat\CPbbcyH.exe.config => Is moved successfully.
C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe => Is moved successfully.
C:\ProgramData\qMuLXOMiMf\dat\FUalhq.exe.config => Is moved successfully.
C:\ProgramData\qMuLXOMiMf\dat\fvbqzObVHb.dll => Is moved successfully.
C:\ProgramData\qMuLXOMiMf\dat\WQSxEJcIi.dll => Is moved successfully.
C:\ProgramData\qMuLXOMiMf => Is moved successfully.

==== End of Fixlog 08:17:48 ====

scheint als wenn alles ok ist kommt bis jetzt nichtzs mehr nerviges!!!
;) vielen dank für die Kompetente Hilfe :)

schnell und echt super geholfen

MFG Adrian !TOP!

cosinus 29.12.2014 18:29

Dann zeig mal frische FRST Logs. Haken setzen bei addition.txt dann auf Scan klicken

http://saved.im/mtg0mjy4yjlu/2014-04...ryscantool.png

reisser 30.12.2014 09:18

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-12-2014
Ran by Reisser (administrator) on REISSER-PC on 30-12-2014 09:15:19
Running from C:\Users\Reisser\Downloads
Loaded Profile: Reisser (Available profiles: Reisser)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Englisch (USA)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe
(Fuyu LIMITED) C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Program Files (x86)\SupTab\HpUI.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Program Files (x86)\SupTab\Loader64.exe
() C:\Program Files (x86)\SupTab\Loader32.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files (x86)\QuickTime\qttask.exe
() C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(VTech) C:\Program Files (x86)\VTech\DownloadManager\System\DownloadManager.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2463552 2014-10-04] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [282624 2007-04-27] (Apple Inc.)
HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] ()
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Run: [SwvUpdtr] => C:\Users\Reisser\AppData\Local\24567\Updater.exe /reg
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: G - G:\StorioSetup.exe
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {2e971c8e-719e-11e4-b18f-bc5ff45b0bd1} - F:\SNC715MusicPlayer.exe
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {9dac61e2-89ed-11e4-b4c2-bc5ff45b0bd1} - G:\StorioSetup.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:51111;https=127.0.0.1:51111
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = webssearches
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = webssearches
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1419800064&from=cvs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = webssearches
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = webssearches
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1419800064&from=cvs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Start Page = webssearches
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = webssearches
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe webssearches
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1419800064&from=cvs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1419800064&from=cvs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1744345613-2801571155-2633355246-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1419800064&from=cvs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1744345613-2801571155-2633355246-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1419800064&from=cvs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975&q={searchTerms}
BHO-x32: IETabPage Class -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> C:\Program Files (x86)\SupTab\SupTab.dll (Thinknice Co. Limited)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default -> https://www.google.de/?gws_rd=ssl
CHR StartupUrls: Default -> "hxxp://istart.webssearches.com/?type=hp&ts=1419800064&from=cvs&uid=WDCXWD5000AAKS-00YGA0_WD-WCAS8059997599975"
CHR DefaultSearchKeyword: Default -> webssearches
CHR DefaultSuggestURL: Default ->
CHR Profile: C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-26]
CHR Extension: (Google Docs) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-26]
CHR Extension: (Google Drive) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-26]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-26]
CHR Extension: (YouTube) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-26]
CHR Extension: (Google Search) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-26]
CHR Extension: (Google Sheets) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-26]
CHR Extension: (Google Wallet) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-26]
CHR Extension: (Gmail) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-26]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-10-04] (NVIDIA Corporation)
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [715656 2014-12-28] (Cherished Technololgy LIMITED)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-10-04] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-10-04] (NVIDIA Corporation)
R2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe [485888 2014-12-28] (Fuyu LIMITED) [File not signed]
S2 SecurityUtility Service; C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe -p "Covus" -c "Covus_Coupons" -s "CCC8" -i "851594" -g "" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-10-04] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-30 09:13 - 2014-12-30 09:13 - 00023089 _____ () C:\Users\Reisser\Downloads\Addition.txt
2014-12-30 09:12 - 2014-12-30 09:15 - 00012865 _____ () C:\Users\Reisser\Downloads\FRST.txt
2014-12-30 08:57 - 2014-12-30 08:57 - 00000000 ____D () C:\Users\Reisser\AppData\Local\DownloadManager
2014-12-29 16:01 - 2014-12-26 16:15 - 1030449942 _____ () C:\Users\Reisser\Downloads\pso-pinguine-webrip.mkv
2014-12-29 16:01 - 2014-12-26 16:15 - 01435648 _____ () C:\Users\Reisser\Downloads\remove_this
2014-12-29 16:01 - 2014-12-26 16:15 - 00022191 _____ () C:\Users\Reisser\Downloads\pso-pinguine-webrip.nfo
2014-12-29 16:01 - 2014-12-26 16:15 - 00000220 _____ () C:\Users\Reisser\Downloads\Goldesel.to - Die Seite fuer Direkt-Downloads aller Art.url
2014-12-29 16:01 - 2014-12-26 16:15 - 00000116 _____ () C:\Users\Reisser\Downloads\goldesel.to - quality source for more than 15 years .txt
2014-12-29 15:50 - 2014-12-29 16:00 - 199972800 _____ () C:\Users\Reisser\Downloads\Die.Pinguine.aus.Madagascar-PsO.part1.rar
2014-12-29 15:50 - 2014-12-29 15:59 - 199972800 _____ () C:\Users\Reisser\Downloads\Die.Pinguine.aus.Madagascar-PsO.part5.rar
2014-12-29 15:50 - 2014-12-29 15:59 - 199972800 _____ () C:\Users\Reisser\Downloads\Die.Pinguine.aus.Madagascar-PsO.part3.rar
2014-12-29 15:50 - 2014-12-29 15:59 - 199972800 _____ () C:\Users\Reisser\Downloads\Die.Pinguine.aus.Madagascar-PsO.part2.rar
2014-12-29 15:50 - 2014-12-29 15:58 - 199972800 _____ () C:\Users\Reisser\Downloads\Die.Pinguine.aus.Madagascar-PsO.part4.rar
2014-12-29 15:50 - 2014-12-29 15:52 - 42332050 _____ () C:\Users\Reisser\Downloads\Die.Pinguine.aus.Madagascar-PsO.part6.rar
2014-12-29 09:09 - 2014-12-29 09:09 - 00000000 ____D () C:\ProgramData\1078601655
2014-12-29 08:14 - 2014-12-29 08:16 - 00000000 ____D () C:\Users\Reisser\Downloads\FRST-OlderVersion
2014-12-29 08:11 - 2014-12-29 08:11 - 00000000 ____D () C:\ProgramData\Browser
2014-12-29 08:06 - 2014-12-29 08:07 - 00000002 _____ () C:\END
2014-12-28 22:00 - 2014-12-28 22:00 - 00000000 ____D () C:\Users\Reisser\Documents\Optimizer Pro
2014-12-28 21:57 - 2014-12-28 21:57 - 00001188 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk
2014-12-28 21:57 - 2014-12-28 21:57 - 00001176 _____ () C:\Users\Public\Desktop\paint.net.lnk
2014-12-28 21:57 - 2014-12-28 21:57 - 00000000 ____D () C:\Program Files\paint.net
2014-12-28 21:56 - 2014-12-28 21:59 - 00000000 ____D () C:\Users\Reisser\AppData\Local\paint.net
2014-12-28 21:54 - 2014-12-28 21:54 - 00000000 ____D () C:\ProgramData\WindowsMangerProtect
2014-12-28 21:54 - 2014-12-28 21:54 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-12-28 21:54 - 2014-12-28 21:54 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-12-28 21:45 - 2014-12-28 21:45 - 00000854 _____ () C:\Users\Reisser\AppData\Local\recently-used.xbel
2014-12-28 21:45 - 2014-12-28 21:45 - 00000000 ____D () C:\Users\Reisser\.thumbnails
2014-12-28 21:43 - 2014-12-28 21:49 - 00000000 ____D () C:\Users\Reisser\.gimp-2.8
2014-12-28 21:43 - 2014-12-28 21:43 - 00000000 ____D () C:\Users\Reisser\AppData\Local\gegl-0.2
2014-12-28 03:01 - 2014-12-28 03:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-12-28 03:01 - 2014-12-28 03:01 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-12-28 03:01 - 2014-12-28 03:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-12-27 15:58 - 2014-12-27 15:58 - 00001474 _____ () C:\Users\Reisser\Desktop\JRT.txt
2014-12-27 15:56 - 2014-12-27 15:56 - 00000000 ____D () C:\Windows\ERUNT
2014-12-27 15:53 - 2014-12-29 08:07 - 00000000 ____D () C:\Users\Reisser\AppData\Local\ZombieInvasion
2014-12-27 15:46 - 2014-12-27 15:50 - 00000000 ____D () C:\AdwCleaner
2014-12-27 15:46 - 2014-12-27 15:46 - 01707646 _____ (Thisisu) C:\Users\Reisser\Downloads\JRT.exe
2014-12-27 15:01 - 2014-12-30 09:15 - 00000000 ____D () C:\FRST
2014-12-27 15:01 - 2014-12-29 08:14 - 02123264 _____ (Farbar) C:\Users\Reisser\Downloads\FRST64.exe
2014-12-26 20:54 - 2014-12-26 21:03 - 00000000 ____D () C:\Users\Reisser\Desktop\weihnachten 14
2014-12-26 19:28 - 2014-12-28 21:54 - 00002416 _____ () C:\Users\Reisser\Desktop\chrome.lnk
2014-12-26 19:04 - 2014-12-27 11:44 - 00005240 _____ () C:\Windows\SysWOW64\ColorMedia.ini
2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\SysWOW64\ColorMediaOff.ini
2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\system32\ColorMediaOff.ini
2014-12-26 19:04 - 2014-12-14 10:53 - 00378640 _____ (CartCrunch Israel Ltd.) C:\Windows\system32\ColorMedia64.dll
2014-12-26 19:04 - 2014-12-14 10:53 - 00332568 _____ (CartCrunch Israel Ltd.) C:\Windows\SysWOW64\ColorMedia.dll
2014-12-26 18:42 - 2014-12-27 14:29 - 00000000 ___HD () C:\Users\Public\Temp
2014-12-26 18:41 - 2014-12-27 15:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-12-26 18:40 - 2014-12-30 08:30 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-26 18:40 - 2014-12-29 08:18 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-12-26 18:40 - 2014-12-29 08:18 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-12-26 18:40 - 2014-12-29 08:18 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-26 18:40 - 2014-12-26 18:40 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrNewH_01009.Wdf
2014-12-26 18:35 - 2014-12-26 18:35 - 00000000 ___DC () C:\Users\Reisser\AppData\Local\MigWiz
2014-12-26 07:16 - 2014-12-26 07:16 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2014-12-24 17:15 - 2014-12-24 17:15 - 00000000 ____D () C:\Program Files (x86)\Ripple Emulator
2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\VTech
2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTech
2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\Program Files (x86)\VTech
2014-12-19 17:14 - 2014-12-19 17:14 - 00000000 _____ () C:\Users\Reisser\AppData\Local\{E9C16533-9CB5-45BF-A1F9-47B28A73E05D}
2014-12-18 15:33 - 2014-12-18 17:29 - 00000000 ____D () C:\Users\Reisser\Downloads\Hörbücher
2014-12-18 13:21 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-18 13:21 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-17 17:42 - 2014-12-17 17:42 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\NVIDIA
2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Mindscape
2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mindscape
2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mindscape
2014-12-17 17:39 - 2014-12-17 17:39 - 00000000 ____D () C:\Program Files (x86)\Mindscape
2014-12-17 17:36 - 2014-12-17 17:36 - 00054156 ____H () C:\Windows\QTFont.qfn
2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-12-17 17:32 - 2014-12-17 17:35 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-12-12 23:05 - 2014-12-12 23:05 - 00159200 ____T () C:\Users\Reisser\AppData\Roaming\CrashRpt1402.dll
2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIW Pro Trial
2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\Program Files (x86)\SIW Pro Trial
2014-12-12 03:19 - 2014-12-12 03:19 - 00000000 ____D () C:\Windows\system32\appraiser
2014-12-12 03:01 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-12 03:01 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-12 03:01 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-12-12 03:01 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-12-12 03:01 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-12-12 03:01 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-12-12 03:01 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-12-12 03:01 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-12-12 03:01 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-12-12 03:01 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2014-12-11 04:56 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-12-11 04:56 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2014-12-11 04:55 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-11 04:55 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-11 04:55 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-11 04:55 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-11 04:55 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-11 04:55 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-11 04:55 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-11 04:55 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-11 04:55 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-11 04:55 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-11 04:55 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-11 04:55 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-11 04:55 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-11 04:55 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-11 04:55 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-11 04:55 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-11 04:55 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-11 04:55 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-11 04:55 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-11 04:55 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-11 04:55 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-11 04:55 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-11 04:55 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-11 04:55 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-11 04:55 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-11 04:55 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-11 04:55 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-11 04:55 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-11 04:55 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-11 04:55 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-11 04:55 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-11 04:55 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-11 04:55 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-11 04:55 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-11 04:55 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-11 04:55 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-11 04:55 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-11 04:55 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-11 04:55 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-11 04:55 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-11 04:55 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-11 04:55 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-11 04:55 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-11 04:55 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-11 04:55 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-11 04:55 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-11 04:55 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-11 04:55 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-11 04:55 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-11 04:55 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-11 04:55 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-11 04:55 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-11 04:55 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-11 04:55 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-11 04:55 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-11 04:55 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-11 04:55 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-11 04:54 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-11 04:54 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-11 04:54 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-11 04:54 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-11 04:54 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-11 04:54 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-11 04:54 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-11 04:54 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-11 04:54 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-11 04:54 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-11 04:54 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-11 04:54 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-11 04:54 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-11 04:54 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-12-11 00:26 - 2014-12-11 00:26 - 01413208 _____ () C:\Windows\Minidump\121114-20248-01.dmp
2014-12-05 12:01 - 2014-12-27 11:40 - 00012288 _____ () C:\Users\Reisser\Desktop\Stundenzettelfür Feru - Dezember14 -.xls
2014-12-04 13:29 - 2014-12-13 15:32 - 00000062 _____ () C:\Users\Reisser\Desktop\Neues Textdokument.txt
2014-12-04 12:53 - 2014-12-29 14:39 - 00000000 ____D () C:\Users\Reisser\Downloads\Musik
2014-12-04 12:52 - 2014-12-29 14:55 - 00000000 ____D () C:\Users\Reisser\Downloads\Kinder Filme

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-30 08:42 - 2014-11-08 14:39 - 01502338 _____ () C:\Windows\WindowsUpdate.log
2014-12-29 14:50 - 2014-11-10 17:53 - 00000000 ____D () C:\Users\Reisser\Downloads\Filme
2014-12-29 14:40 - 2014-11-27 19:28 - 00000000 ____D () C:\Users\Reisser\Desktop\Wallpapers
2014-12-29 09:48 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-29 09:48 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-29 08:24 - 2014-11-08 16:15 - 00697256 _____ () C:\Windows\system32\perfh007.dat
2014-12-29 08:24 - 2014-11-08 16:15 - 00149224 _____ () C:\Windows\system32\perfc007.dat
2014-12-29 08:24 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-29 08:17 - 2014-11-08 14:52 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-12-29 08:17 - 2010-11-21 04:47 - 00042446 _____ () C:\Windows\PFRO.log
2014-12-29 08:17 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-29 08:17 - 2009-07-14 05:51 - 00042019 _____ () C:\Windows\setupact.log
2014-12-28 21:54 - 2014-11-08 14:42 - 00001213 _____ () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-12-28 21:45 - 2014-11-08 14:42 - 00000000 ____D () C:\Users\Reisser
2014-12-27 14:23 - 2014-11-08 15:29 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Users\Reisser\AppData\Local\Google
2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Program Files (x86)\Google
2014-12-25 12:22 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-17 17:42 - 2014-11-08 14:42 - 00000000 ____D () C:\Users\Reisser\AppData\Local\VirtualStore
2014-12-12 05:23 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-12-12 03:19 - 2014-11-08 19:04 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-12-12 03:04 - 2014-11-08 19:30 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-12 03:02 - 2014-11-08 19:30 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-11 00:29 - 2014-11-16 15:02 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-12-11 00:26 - 2014-11-28 13:23 - 564424988 _____ () C:\Windows\MEMORY.DMP
2014-12-11 00:26 - 2014-11-28 13:23 - 00000000 ____D () C:\Windows\Minidump
2014-12-05 11:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-01 06:58 - 2014-11-20 17:29 - 00012288 _____ () C:\Users\Reisser\Desktop\Stundenzettelfür Feru - November 14 - Kopie.xls

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-12-15 17:20

==================== End Of Log ============================

--- --- ---

--- --- ---


FRST Additions Logfile:
Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-12-2014
Ran by Reisser at 2014-12-30 09:15:38
Running from C:\Users\Reisser\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Abenteuer Pferderücken Demo (HKLM-x32\...\Abenteuer Pferderücken Demo) (Version:  - )
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Ashampoo Burning Studio FREE v.1.14.5 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.12.0 - Asmedia Technology)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
K-Lite Codec Pack 10.8.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.8.0 - )
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
mkv2vob (HKLM-x32\...\{21AE04E8-EBF6-40DB-9AA9-B7A80C5D057D}) (Version: 2.4.9 - 3r1c)
NVIDIA 3D Vision Controller Driver 344.46 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 344.46 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 344.60 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.3 - NVIDIA Corporation)
NVIDIA Graphics Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.60 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.32.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
paint.net (HKLM\...\{F509C1F4-0029-49F9-B145-A4C4E8DF481A}) (Version: 4.0.3 - dotPDN LLC)
QuickTime (HKLM-x32\...\{08094E03-AFE4-4853-9D31-6D0743DF5328}) (Version: 7.1.6.200 - Apple Computer, Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.)
SecurityUtility (HKLM-x32\...\SecurityUtility) (Version: 1.0.0.992 - )
SHIELD Streaming (Version: 3.1.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.13.56 - NVIDIA Corporation) Hidden
SIW Pro Edition (Trial Version) (HKLM-x32\...\{3B9704C8-1286-4a17-9EA8-F63004FC74A1}_is1) (Version: 2014.10.16 - Topala Software Solutions)
VTech Download Agent Library (x32 Version: 1.00.0000 - VTech) Hidden
VTech Download Manager (HKLM-x32\...\VTechDownloadManager) (Version:  - VTech)
webssearches uninstall (HKLM-x32\...\webssearches uninstall) (Version:  - webssearches) <==== ATTENTION
WinRAR 5.10 Beta 4 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

22-12-2014 17:38:19 Removed Apple Software Update
25-12-2014 17:07:37 Windows Update
26-12-2014 18:53:33 Software Removal Tool
28-12-2014 03:00:23 Windows Update
28-12-2014 21:56:42 paint.net v4.0.3

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2014-12-29 08:16 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {07C4EDDE-20D1-4BFF-8659-B50E309D06FA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.)
Task: {850FC5E5-AE51-4C51-95E1-FF3768705CCA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.)
Task: {8B1C00F0-602F-40B2-9557-43584EC56145} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2014-10-06] ()
Task: {F1E05127-80E4-400F-8C60-436999246896} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2014-11-08 14:51 - 2014-10-30 03:10 - 00117064 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-08-21 12:33 - 2014-12-28 21:54 - 00106376 _____ () C:\Program Files (x86)\SupTab\WindowsSupportDll64.dll
2014-08-21 12:32 - 2014-12-28 21:54 - 00733576 _____ () C:\Program Files (x86)\SupTab\HpUI.exe
2014-07-16 10:55 - 2014-07-16 10:55 - 00073216 _____ () C:\Program Files (x86)\SupTab\Loader64.exe
2014-07-16 11:16 - 2014-07-16 11:16 - 00064000 _____ () C:\Program Files (x86)\SupTab\Loader32.exe
2014-10-13 02:49 - 2014-06-20 07:42 - 00401280 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
2014-08-21 12:33 - 2014-12-28 21:54 - 00023944 _____ () C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll
2014-10-13 02:49 - 2014-03-04 12:20 - 00117760 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QtSolutions_SOAP-2.7.dll
2014-10-13 02:49 - 2014-04-22 03:14 - 00065536 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QHttpServer.dll
2014-10-13 02:49 - 2014-05-06 06:39 - 00861184 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\platforms\qwindows.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00021504 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qgif.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00020992 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qico.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00204800 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qjpeg.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00218112 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qmng.dll
2014-10-13 02:49 - 2014-05-06 06:58 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qsvg.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00015360 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtga.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00307712 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtiff.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00014848 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qwbmp.dll
2014-10-13 02:49 - 2014-05-06 07:31 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\sensors\qtsensors_dummy.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00036352 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qgenericbearer.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00038912 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qnativewifibearer.dll
2014-12-29 08:25 - 2014-12-06 02:50 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libglesv2.dll
2014-12-29 08:25 - 2014-12-06 02:50 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libegl.dll
2014-12-29 08:25 - 2014-12-06 02:50 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dll
2014-12-29 08:25 - 2014-12-06 02:50 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ffmpegsumo.dll
2014-10-13 02:49 - 2014-05-02 09:44 - 00032256 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QHttpMessageClient.dll
2014-11-05 03:13 - 2014-07-03 04:18 - 00031616 _____ () C:\Program Files (x86)\VTech\DownloadManager\Applications\InnoTab_DE_ger\InnoTabFSLibrary.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\abengine => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ColorMedia => ""="service"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


========================= Accounts: ==========================

Administrator (S-1-5-21-1744345613-2801571155-2633355246-500 - Administrator - Disabled)
Guest (S-1-5-21-1744345613-2801571155-2633355246-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1744345613-2801571155-2633355246-1002 - Limited - Enabled)
Reisser (S-1-5-21-1744345613-2801571155-2633355246-1000 - Administrator - Enabled) => C:\Users\Reisser

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (12/29/2014 04:03:10 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5168.  Message ID: [0x2509].

Error: (12/29/2014 04:01:52 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5368.  Message ID: [0x2509].

Error: (12/29/2014 02:55:40 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 2472.  Message ID: [0x2509].

Error: (12/29/2014 02:52:42 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 4420.  Message ID: [0x2509].

Error: (12/29/2014 02:49:46 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 3344.  Message ID: [0x2509].

Error: (12/29/2014 02:47:17 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 3964.  Message ID: [0x2509].

Error: (12/29/2014 02:44:55 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 4676.  Message ID: [0x2509].

Error: (12/29/2014 02:39:09 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 4988.  Message ID: [0x2509].

Error: (12/29/2014 09:08:40 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (12/29/2014 09:08:40 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".


System errors:
=============
Error: (12/29/2014 11:50:01 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT AUTHORITY60 ein Fehler festgestellt.

        Neue Signaturversion:

        Vorherige Signaturversion: 1.191.1047.0

        Aktualisierungsquelle: %NT AUTHORITY59

        Aktualisierungsphase: 4.6.0305.00

        Quellpfad: 4.6.0305.01

        Signaturtyp: %NT AUTHORITY602

        Aktualisierungstyp: %NT AUTHORITY604

        Benutzer: NT AUTHORITY\SYSTEM

        Aktuelle Modulversion: %NT AUTHORITY605

        Vorherige Modulversion: %NT AUTHORITY606

        Fehlercode: %NT AUTHORITY607

        Fehlerbeschreibung: %NT AUTHORITY608

Error: (12/29/2014 10:29:13 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Beim Aktualisieren der Signaturen wurde von %NT AUTHORITY60 ein Fehler festgestellt.

        Neue Signaturversion:

        Vorherige Signaturversion: 1.191.1047.0

        Aktualisierungsquelle: %NT AUTHORITY59

        Aktualisierungsphase: 4.6.0305.00

        Quellpfad: 4.6.0305.01

        Signaturtyp: %NT AUTHORITY602

        Aktualisierungstyp: %NT AUTHORITY604

        Benutzer: NT AUTHORITY\SYSTEM

        Aktuelle Modulversion: %NT AUTHORITY605

        Vorherige Modulversion: %NT AUTHORITY606

        Fehlercode: %NT AUTHORITY607

        Fehlerbeschreibung: %NT AUTHORITY608

Error: (12/29/2014 08:17:39 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "SecurityUtility Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2

Error: (12/29/2014 08:17:09 AM) (Source: Ntfs) (EventID: 137) (User: )
Description: Auf dem Volume "\\?\Volume{2dd34089-674c-11e4-af0b-806e6f6e6963}" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (12/29/2014 08:17:09 AM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (12/29/2014 08:15:52 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Optimizer Pro Crash Monitor" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (12/29/2014 08:05:08 AM) (Source: Ntfs) (EventID: 137) (User: )
Description: Auf dem Volume "\\?\Volume{2dd34089-674c-11e4-af0b-806e6f6e6963}" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (12/29/2014 08:05:07 AM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (12/28/2014 09:34:13 PM) (Source: Ntfs) (EventID: 137) (User: )
Description: Auf dem Volume "\\?\Volume{2dd34089-674c-11e4-af0b-806e6f6e6963}" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (12/28/2014 09:34:13 PM) (Source: Disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.


Microsoft Office Sessions:
=========================
Error: (12/29/2014 04:03:10 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5168.  Message ID: [0x2509].

Error: (12/29/2014 04:01:52 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5368.  Message ID: [0x2509].

Error: (12/29/2014 02:55:40 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 2472.  Message ID: [0x2509].

Error: (12/29/2014 02:52:42 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 4420.  Message ID: [0x2509].

Error: (12/29/2014 02:49:46 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 3344.  Message ID: [0x2509].

Error: (12/29/2014 02:47:17 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 3964.  Message ID: [0x2509].

Error: (12/29/2014 02:44:55 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 4676.  Message ID: [0x2509].

Error: (12/29/2014 02:39:09 PM) (Source: .NET Runtime) (EventID: 1022) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 4988.  Message ID: [0x2509].

Error: (12/29/2014 09:08:40 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl

Error: (12/29/2014 09:08:40 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.6195"C:\Windows\SysWOW64\DivXControlPanelApplet.cpl


==================== Memory info ===========================

Processor: AMD FX(tm)-6100 Six-Core Processor
Percentage of memory in use: 21%
Total physical RAM: 8171.53 MB
Available physical RAM: 6376.85 MB
Total Pagefile: 16641.24 MB
Available Pagefile: 13706.23 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:172.79 GB) (Free:103.17 GB) NTFS
Drive d: () (Fixed) (Total:292.97 GB) (Free:58.35 GB) NTFS
Drive e: (Filme 2 St) (Fixed) (Total:465.61 GB) (Free:129.15 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: FFB8F33B)
Partition 1: (Not Active) - (Size=172.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=293 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 3280EB00)
Partition 1: (Active) - (Size=126 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.6 GB) - (Type=07 NTFS)

==================== End Of Log ============================

--- --- ---

cosinus 30.12.2014 09:24

Das ist ja immer noch Adware ....:balla:....bitte nochmal das volle Programm!! :kloppen:

Adware/Junkware/Toolbars entfernen

(alte Versionen von adwCleaner und falls vorhanden JRT vorher löschen, danach neu runterladen auf den Desktop!)

1. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).




2. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.




3. Schritt: Frisches Log mit FRST

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


reisser 05.01.2015 09:54

AdwCleaner Logfile:
Code:

# AdwCleaner v4.106 - Report created 05/01/2015 at 09:33:08
# Updated 21/12/2014 by Xplode
# Database : 2015-01-03.1 [Live]
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : Reisser - REISSER-PC
# Running from : C:\Users\Reisser\Desktop\AdwCleaner_4.106 - Kopie.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.trovi.com_0.localstorage
File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.trovi.com_0.localstorage-journal
File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage
File Deleted : C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17496


-\\ Google Chrome v39.0.2171.95


*************************

AdwCleaner[R0].txt - [20752 octets] - [27/12/2014 15:47:37]
AdwCleaner[R1].txt - [18811 octets] - [05/01/2015 09:22:06]
AdwCleaner[R2].txt - [1568 octets] - [05/01/2015 09:31:43]
AdwCleaner[S0].txt - [20132 octets] - [27/12/2014 15:50:26]
AdwCleaner[S1].txt - [18194 octets] - [05/01/2015 09:23:21]
AdwCleaner[S2].txt - [1497 octets] - [05/01/2015 09:33:08]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1557 octets] ##########

--- --- ---


mnhg~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Ultimate x64
Ran by Reisser on 05.01.2015 at 9:36:32,08
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files

Successfully deleted: [File] "C:\Users\Reisser\appdata\local\google\chrome\user data\default\local storage\http_www.trovi.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Reisser\appdata\local\google\chrome\user data\default\local storage\http_www.trovi.com_0.localstorage-journal"



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05.01.2015 at 9:38:49,77
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


FRST Logfile:

FRST Logfile:

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2015
Ran by Reisser (administrator) on REISSER-PC on 05-01-2015 09:45:09
Running from C:\Users\Reisser\Desktop
Loaded Profile: Reisser (Available profiles: Reisser)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Englisch (USA)
Internet Explorer Version 11 (Default browser: Bobrowser)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files (x86)\QuickTime\qttask.exe
() C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2463552 2014-10-04] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [282624 2007-04-27] (Apple Inc.)
HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] ()
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Run: [SwvUpdtr] => C:\Users\Reisser\AppData\Local\24567\Updater.exe /reg
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: G - G:\StorioSetup.exe
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {2e971c8e-719e-11e4-b18f-bc5ff45b0bd1} - F:\SNC715MusicPlayer.exe
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\MountPoints2: {9dac61e2-89ed-11e4-b4c2-bc5ff45b0bd1} - G:\StorioSetup.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:51111;https=127.0.0.1:51111
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = Google
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Firefox\Extensions: [{75229658-C485-8921-6792-5A8E5A8C26B4}] - C:\Program Files (x86)\ver3BetterMarkIt\185.xpi

Chrome:
=======
CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3331316&octid=EB_ORIGINAL_CTID&ISID=M1D1612CD-E697-484A-B9DE-850FA4C8F09D&SearchSource=55&CUI=&UM=8&UP=SP0225E5DB-2AB9-423E-9B34-14F8D9DC2719&SSPV=
CHR StartupUrls: Default -> "hxxp://www.trovi.com/?gd=&ctid=CT3331316&octid=EB_ORIGINAL_CTID&ISID=M1D1612CD-E697-484A-B9DE-850FA4C8F09D&SearchSource=55&CUI=&UM=8&UP=SP0225E5DB-2AB9-423E-9B34-14F8D9DC2719&SSPV="
CHR DefaultSearchKeyword: Default -> trovi.search
CHR DefaultNewTabURL: Default -> https://www.trovi.com/?gd=&ctid=CT3331316&octid=EB_ORIGINAL_CTID&ISID=M1D1612CD-E697-484A-B9DE-850FA4C8F09D&SearchSource=69&CUI=&SSPV=&lay=5&p=cnts&UM=8&UP=SP0225E5DB-2AB9-423E-9B34-14F8D9DC2719&SAT=CNTS
CHR DefaultSuggestURL: Default -> hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms}
CHR Profile: C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-26]
CHR Extension: (Google Docs) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-26]
CHR Extension: (Google Drive) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-26]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-26]
CHR Extension: (YouTube) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-26]
CHR Extension: (Google Search) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-26]
CHR Extension: (Google Sheets) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-26]
CHR Extension: (Google Wallet) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-26]
CHR Extension: (Gmail) - C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-26]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-10-04] (NVIDIA Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-10-04] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-10-04] (NVIDIA Corporation)
S2 SecurityUtility Service; C:\ProgramData\SecurityUtility\SecurityUtilitySrv.exe -p "Covus" -c "Covus_Coupons" -s "CCC8" -i "851594" -g "" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-10-04] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation)
R2 webinstrNHK; C:\Windows\system32\Drivers\webinstrNHK.sys [56432 2015-01-04] (Corsica)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-05 09:45 - 2015-01-05 09:45 - 00010775 _____ () C:\Users\Reisser\Desktop\FRST.txt
2015-01-05 09:44 - 2015-01-05 09:44 - 02123776 _____ (Farbar) C:\Users\Reisser\Desktop\FRST64.exe
2015-01-05 09:38 - 2015-01-05 09:38 - 00000919 _____ () C:\Users\Reisser\Desktop\JRT.txt
2015-01-05 09:35 - 2015-01-05 09:35 - 00001637 _____ () C:\Users\Reisser\Desktop\AdwCleaner[S2].txt
2015-01-05 09:28 - 2015-01-05 09:18 - 02173952 _____ () C:\Users\Reisser\Desktop\AdwCleaner_4.106 - Kopie.exe
2015-01-05 09:28 - 2015-01-05 09:17 - 01707939 _____ (Thisisu) C:\Users\Reisser\Desktop\JRT - Kopie.exe
2015-01-04 19:22 - 2015-01-04 19:22 - 00002351 _____ () C:\Windows\patsearch.bin
2015-01-04 19:22 - 2015-01-04 19:21 - 00056432 _____ (Corsica) C:\Windows\system32\Drivers\webinstrNHK.sys
2015-01-04 19:20 - 2015-01-05 09:35 - 00001342 _____ () C:\Windows\Tasks\PESM.job
2015-01-04 19:20 - 2015-01-04 19:21 - 00004376 _____ () C:\Windows\System32\Tasks\PESM
2015-01-04 19:20 - 2015-01-04 19:21 - 00000000 ____D () C:\Program Files (x86)\c37590b6-b104-45a2-80cb-69d810a404ed
2015-01-04 19:20 - 2015-01-04 19:20 - 01965032 _____ (home) C:\Users\Reisser\AppData\Roaming\PESM.exe
2015-01-03 13:00 - 2015-01-01 23:33 - 1068301169 _____ () C:\Users\Reisser\Downloads\Fury-Herz aus Stahl.mkv
2015-01-03 12:10 - 2015-01-02 01:12 - 844664404 _____ () C:\Users\Reisser\Downloads\Nachts im Museum 3.mkv
2014-12-31 18:09 - 2014-12-31 18:09 - 00000000 ____D () C:\Program Files (x86)\Belkin
2014-12-31 18:08 - 2014-12-31 18:08 - 00000000 ____D () C:\Windows\{4626E3EA-85B3-464E-B296-F3F5488D8B08}
2014-12-29 09:09 - 2014-12-29 09:09 - 00000000 ____D () C:\ProgramData\1078601655
2014-12-28 21:57 - 2014-12-28 21:57 - 00001188 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk
2014-12-28 21:57 - 2014-12-28 21:57 - 00000000 ____D () C:\Program Files\paint.net
2014-12-28 21:56 - 2014-12-28 21:59 - 00000000 ____D () C:\Users\Reisser\AppData\Local\paint.net
2014-12-28 21:45 - 2014-12-28 21:45 - 00000854 _____ () C:\Users\Reisser\AppData\Local\recently-used.xbel
2014-12-28 21:45 - 2014-12-28 21:45 - 00000000 ____D () C:\Users\Reisser\.thumbnails
2014-12-28 21:43 - 2014-12-28 21:49 - 00000000 ____D () C:\Users\Reisser\.gimp-2.8
2014-12-28 21:43 - 2014-12-28 21:43 - 00000000 ____D () C:\Users\Reisser\AppData\Local\gegl-0.2
2014-12-28 03:01 - 2014-12-28 03:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-12-28 03:01 - 2014-12-28 03:01 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-12-28 03:01 - 2014-12-28 03:01 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-12-27 15:56 - 2014-12-27 15:56 - 00000000 ____D () C:\Windows\ERUNT
2014-12-27 15:46 - 2015-01-05 09:33 - 00000000 ____D () C:\AdwCleaner
2014-12-27 15:01 - 2015-01-05 09:45 - 00000000 ____D () C:\FRST
2014-12-26 20:54 - 2014-12-26 21:03 - 00000000 ____D () C:\Users\Reisser\Desktop\weihnachten 14
2014-12-26 19:04 - 2014-12-27 11:44 - 00005240 _____ () C:\Windows\SysWOW64\ColorMedia.ini
2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\SysWOW64\ColorMediaOff.ini
2014-12-26 19:04 - 2014-12-27 11:44 - 00002840 _____ () C:\Windows\system32\ColorMediaOff.ini
2014-12-26 19:04 - 2014-12-14 10:53 - 00378640 _____ (CartCrunch Israel Ltd.) C:\Windows\system32\ColorMedia64.dll
2014-12-26 19:04 - 2014-12-14 10:53 - 00332568 _____ (CartCrunch Israel Ltd.) C:\Windows\SysWOW64\ColorMedia.dll
2014-12-26 18:42 - 2014-12-27 14:29 - 00000000 ___HD () C:\Users\Public\Temp
2014-12-26 18:41 - 2015-01-05 09:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-12-26 18:40 - 2015-01-05 09:35 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-26 18:40 - 2014-12-29 08:18 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-12-26 18:40 - 2014-12-29 08:18 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-12-26 18:40 - 2014-12-29 08:18 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-26 18:40 - 2014-12-26 18:40 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_webinstrNewH_01009.Wdf
2014-12-26 18:35 - 2014-12-26 18:35 - 00000000 ___DC () C:\Users\Reisser\AppData\Local\MigWiz
2014-12-26 07:16 - 2014-12-26 07:16 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2014-12-24 17:15 - 2014-12-24 17:15 - 00000000 ____D () C:\Program Files (x86)\Ripple Emulator
2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\VTech
2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTech
2014-12-22 16:27 - 2014-12-22 16:27 - 00000000 ____D () C:\Program Files (x86)\VTech
2014-12-19 17:14 - 2014-12-19 17:14 - 00000000 _____ () C:\Users\Reisser\AppData\Local\{E9C16533-9CB5-45BF-A1F9-47B28A73E05D}
2014-12-18 15:33 - 2014-12-18 17:29 - 00000000 ____D () C:\Users\Reisser\Downloads\Hörbücher
2014-12-18 13:21 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-18 13:21 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-17 17:42 - 2014-12-17 17:42 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\NVIDIA
2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Mindscape
2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mindscape
2014-12-17 17:41 - 2014-12-17 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mindscape
2014-12-17 17:39 - 2014-12-17 17:39 - 00000000 ____D () C:\Program Files (x86)\Mindscape
2014-12-17 17:36 - 2014-12-17 17:36 - 00054156 ____H () C:\Windows\QTFont.qfn
2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-12-17 17:36 - 2014-12-17 17:36 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-12-17 17:32 - 2014-12-17 17:35 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-12-12 23:05 - 2014-12-12 23:05 - 00159200 ____T () C:\Users\Reisser\AppData\Roaming\CrashRpt1402.dll
2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIW Pro Trial
2014-12-12 23:05 - 2014-12-12 23:05 - 00000000 ____D () C:\Program Files (x86)\SIW Pro Trial
2014-12-12 03:19 - 2014-12-12 03:19 - 00000000 ____D () C:\Windows\system32\appraiser
2014-12-12 03:01 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-12 03:01 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-12 03:01 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-12-12 03:01 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-12-12 03:01 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-12-12 03:01 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-12-12 03:01 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-12-12 03:01 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-12-12 03:01 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-12-12 03:01 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-12-11 04:56 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2014-12-11 04:56 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-12-11 04:56 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2014-12-11 04:55 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-11 04:55 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-11 04:55 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-11 04:55 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-11 04:55 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-11 04:55 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-11 04:55 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-11 04:55 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-11 04:55 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-11 04:55 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-11 04:55 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-11 04:55 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-11 04:55 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-11 04:55 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-11 04:55 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-11 04:55 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-11 04:55 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-11 04:55 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-11 04:55 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-11 04:55 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-11 04:55 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-11 04:55 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-11 04:55 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-11 04:55 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-11 04:55 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-11 04:55 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-11 04:55 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-11 04:55 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-11 04:55 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-11 04:55 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-11 04:55 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-11 04:55 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-11 04:55 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-11 04:55 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-11 04:55 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-11 04:55 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-11 04:55 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-11 04:55 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-11 04:55 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-11 04:55 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-11 04:55 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-11 04:55 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-11 04:55 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-11 04:55 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-11 04:55 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-11 04:55 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-11 04:55 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-11 04:55 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-11 04:55 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-11 04:55 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-11 04:55 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-11 04:55 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-11 04:55 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-11 04:55 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-11 04:55 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-11 04:55 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-11 04:55 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-11 04:54 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-11 04:54 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-11 04:54 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-11 04:54 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-11 04:54 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-11 04:54 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-11 04:54 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-11 04:54 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-11 04:54 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-11 04:54 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-11 04:54 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-11 04:54 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-11 04:54 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-11 04:54 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-12-11 00:26 - 2014-12-11 00:26 - 01413208 _____ () C:\Windows\Minidump\121114-20248-01.dmp

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-05 09:42 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-05 09:42 - 2009-07-14 05:45 - 00026944 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-05 09:40 - 2014-11-08 16:15 - 00697256 _____ () C:\Windows\system32\perfh007.dat
2015-01-05 09:40 - 2014-11-08 16:15 - 00149224 _____ () C:\Windows\system32\perfc007.dat
2015-01-05 09:40 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-05 09:38 - 2014-11-08 14:39 - 01842146 _____ () C:\Windows\WindowsUpdate.log
2015-01-05 09:34 - 2014-11-08 14:52 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-01-05 09:34 - 2010-11-21 04:47 - 00047230 _____ () C:\Windows\PFRO.log
2015-01-05 09:34 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-05 09:34 - 2009-07-14 05:51 - 00043525 _____ () C:\Windows\setupact.log
2015-01-05 09:23 - 2014-11-08 14:42 - 00000993 _____ () C:\Users\Reisser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-04 19:21 - 2014-11-08 15:29 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2015-01-03 12:13 - 2014-12-04 12:53 - 00000000 ____D () C:\Users\Reisser\Downloads\Musik
2015-01-03 12:10 - 2014-12-04 12:52 - 00000000 ____D () C:\Users\Reisser\Downloads\Kinder Filme
2014-12-31 18:29 - 2014-11-10 17:53 - 00000000 ____D () C:\Users\Reisser\Downloads\Filme
2014-12-31 18:14 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-31 18:09 - 2014-11-08 14:44 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-12-29 14:40 - 2014-11-27 19:28 - 00000000 ____D () C:\Users\Reisser\Desktop\Wallpapers
2014-12-28 21:45 - 2014-11-08 14:42 - 00000000 ____D () C:\Users\Reisser
2014-12-27 11:40 - 2014-12-05 12:01 - 00012288 _____ () C:\Users\Reisser\Desktop\Stundenzettelfür Feru - Dezember14 -.xls
2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Users\Reisser\AppData\Local\Google
2014-12-26 18:41 - 2014-11-08 15:03 - 00000000 ____D () C:\Program Files (x86)\Google
2014-12-25 12:22 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-17 17:42 - 2014-11-08 14:42 - 00000000 ____D () C:\Users\Reisser\AppData\Local\VirtualStore
2014-12-13 15:32 - 2014-12-04 13:29 - 00000062 _____ () C:\Users\Reisser\Desktop\Neues Textdokument.txt
2014-12-12 05:23 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-12-12 03:19 - 2014-11-08 19:04 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-12 03:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-12-12 03:04 - 2014-11-08 19:30 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-12 03:02 - 2014-11-08 19:30 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-11 00:29 - 2014-11-16 15:02 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-12-11 00:26 - 2014-11-28 13:23 - 564424988 _____ () C:\Windows\MEMORY.DMP
2014-12-11 00:26 - 2014-11-28 13:23 - 00000000 ____D () C:\Windows\Minidump

Some content of TEMP:
====================
C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.dll
C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.exe
C:\Users\Reisser\AppData\Local\Temp\ED0B3C23-8BE8-3EB3-1490-A4C4FFFA8DA2.exe
C:\Users\Reisser\AppData\Local\Temp\nse838F.exe
C:\Users\Reisser\AppData\Local\Temp\Quarantine.exe
C:\Users\Reisser\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-04 14:49

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---

--- --- ---

--- --- ---

FRST Additions Logfile:
Code:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-01-2015
Ran by Reisser at 2015-01-05 09:46:06
Running from C:\Users\Reisser\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Disabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Disabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Abenteuer Pferderücken Demo (HKLM-x32\...\Abenteuer Pferderücken Demo) (Version:  - )
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Ashampoo Burning Studio FREE v.1.14.5 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.14.5 - Ashampoo GmbH & Co. KG)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.12.0 - Asmedia Technology)
Belkin F7D1101 Basic Wireless USB Adapter (HKLM-x32\...\InstallShield_{AFD89880-C544-4777-B645-FBF6D3391B11}) (Version: 1.0.0.4 - Belkin)
Belkin F7D1101 Basic Wireless USB Adapter (x32 Version: 1.0.0.4 - Belkin) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
K-Lite Codec Pack 10.8.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.8.0 - )
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
mkv2vob (HKLM-x32\...\{21AE04E8-EBF6-40DB-9AA9-B7A80C5D057D}) (Version: 2.4.9 - 3r1c)
NVIDIA 3D Vision Controller Driver 344.46 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 344.46 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 344.60 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.3 - NVIDIA Corporation)
NVIDIA Graphics Driver 344.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.60 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.32.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation)
paint.net (HKLM\...\{F509C1F4-0029-49F9-B145-A4C4E8DF481A}) (Version: 4.0.3 - dotPDN LLC)
QuickTime (HKLM-x32\...\{08094E03-AFE4-4853-9D31-6D0743DF5328}) (Version: 7.1.6.200 - Apple Computer, Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.44.421.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.)
SecurityUtility (HKLM-x32\...\SecurityUtility) (Version: 1.0.0.992 - )
SHIELD Streaming (Version: 3.1.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.13.56 - NVIDIA Corporation) Hidden
SIW Pro Edition (Trial Version) (HKLM-x32\...\{3B9704C8-1286-4a17-9EA8-F63004FC74A1}_is1) (Version: 2014.10.16 - Topala Software Solutions)
VTech Download Agent Library (x32 Version: 1.00.0000 - VTech) Hidden
VTech Download Manager (HKLM-x32\...\VTechDownloadManager) (Version:  - VTech)
WinRAR 5.10 Beta 4 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.10.4 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

31-12-2014 18:09:18 Installiert Belkin F7D1101 Basic Wireless USB Adapter
31-12-2014 18:24:58 Windows Update
04-01-2015 15:00:32 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2014-12-29 08:16 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {07C4EDDE-20D1-4BFF-8659-B50E309D06FA} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.)
Task: {850FC5E5-AE51-4C51-95E1-FF3768705CCA} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-26] (Google Inc.)
Task: {8B1C00F0-602F-40B2-9557-43584EC56145} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2014-10-06] ()
Task: {C2A4DBCF-85DB-4AF7-9667-235505B79D5D} - System32\Tasks\PESM => C:\Users\Reisser\AppData\Roaming\PESM.exe [2015-01-04] (home) <==== ATTENTION
Task: {F1E05127-80E4-400F-8C60-436999246896} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\PESM.job => C:\Users\Reisser\AppData\Roaming\PESM.exe <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2014-11-08 14:51 - 2014-10-30 03:10 - 00117064 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-10-13 02:49 - 2014-06-20 07:42 - 00401280 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
2014-10-13 02:49 - 2014-03-04 12:20 - 00117760 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QtSolutions_SOAP-2.7.dll
2014-10-13 02:49 - 2014-04-22 03:14 - 00065536 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\QHttpServer.dll
2014-10-13 02:49 - 2014-05-06 06:39 - 00861184 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\platforms\qwindows.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00021504 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qgif.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00020992 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qico.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00204800 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qjpeg.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00218112 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qmng.dll
2014-10-13 02:49 - 2014-05-06 06:58 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qsvg.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00015360 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtga.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00307712 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qtiff.dll
2014-10-13 02:49 - 2014-05-06 11:44 - 00014848 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\imageformats\qwbmp.dll
2014-10-13 02:49 - 2014-05-06 07:31 - 00015872 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\sensors\qtsensors_dummy.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00036352 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qgenericbearer.dll
2014-10-13 02:49 - 2014-05-06 06:38 - 00038912 _____ () C:\Program Files (x86)\VTech\DownloadManager\System\plugins\bearer\qnativewifibearer.dll
2014-12-29 08:25 - 2014-12-06 02:50 - 01077064 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libglesv2.dll
2014-12-29 08:25 - 2014-12-06 02:50 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\libegl.dll
2014-12-29 08:25 - 2014-12-06 02:50 - 09009480 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dll
2014-12-29 08:25 - 2014-12-06 02:50 - 01677128 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ffmpegsumo.dll
2014-12-29 08:25 - 2014-12-06 02:50 - 14913352 _____ () C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\abengine => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ColorMedia => ""="service"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


========================= Accounts: ==========================

Administrator (S-1-5-21-1744345613-2801571155-2633355246-500 - Administrator - Disabled)
Guest (S-1-5-21-1744345613-2801571155-2633355246-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1744345613-2801571155-2633355246-1002 - Limited - Enabled)
Reisser (S-1-5-21-1744345613-2801571155-2633355246-1000 - Administrator - Enabled) => C:\Users\Reisser

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================

System errors:
=============

Microsoft Office Sessions:
=========================

==================== Memory info ===========================

Processor: AMD FX(tm)-6100 Six-Core Processor
Percentage of memory in use: 35%
Total physical RAM: 8171.53 MB
Available physical RAM: 5273.06 MB
Total Pagefile: 16641.24 MB
Available Pagefile: 13501.4 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:172.79 GB) (Free:103.26 GB) NTFS
Drive d: () (Fixed) (Total:292.97 GB) (Free:54.41 GB) NTFS
Drive e: (Filme 2 St) (Fixed) (Total:465.61 GB) (Free:136.17 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: FFB8F33B)
Partition 1: (Not Active) - (Size=172.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=293 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 3280EB00)
Partition 1: (Active) - (Size=126 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.6 GB) - (Type=07 NTFS)

==================== End Of Log ============================


#~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Ultimate x64
Ran by Reisser on 05.01.2015 at 9:36:32,08
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files

Successfully deleted: [File] "C:\Users\Reisser\appdata\local\google\chrome\user data\default\local storage\http_www.trovi.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Reisser\appdata\local\google\chrome\user data\default\local storage\http_www.trovi.com_0.localstorage-journal"



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05.01.2015 at 9:38:49,77
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

cosinus 05.01.2015 10:09

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:51111;https=127.0.0.1:51111
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Firefox\Extensions: [{75229658-C485-8921-6792-5A8E5A8C26B4}] - C:\Program Files (x86)\ver3BetterMarkIt\185.xpi
CHR DefaultSuggestURL: Default -> http://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms}
Task: {C2A4DBCF-85DB-4AF7-9667-235505B79D5D} - System32\Tasks\PESM => C:\Users\Reisser\AppData\Roaming\PESM.exe [2015-01-04] (home) <==== ATTENTION
Task: C:\Windows\Tasks\PESM.job => C:\Users\Reisser\AppData\Roaming\PESM.exe <==== ATTENTION
C:\Windows\Tasks\PESM.job
C:\Windows\System32\Tasks\PESM
C:\Program Files (x86)\c37590b6-b104-45a2-80cb-69d810a404ed
C:\Users\Reisser\AppData\Roaming\PESM.exe
C:\Windows\{4626E3EA-85B3-464E-B296-F3F5488D8B08}
C:\ProgramData\1078601655
C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.dll
C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.exe
C:\Users\Reisser\AppData\Local\Temp\ED0B3C23-8BE8-3EB3-1490-A4C4FFFA8DA2.exe
C:\Users\Reisser\AppData\Local\Temp\nse838F.exe
C:\Program Files (x86)\ver3BetterMarkIt
EmptyTemp:
Hosts:


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


reisser 05.01.2015 13:24

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-01-2015
Ran by Reisser at 2015-01-05 13:14:57 Run:2
Running from C:\Users\Reisser\Desktop
Loaded Profile: Reisser (Available profiles: Reisser)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:51111;https=127.0.0.1:51111
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\...\Firefox\Extensions: [{75229658-C485-8921-6792-5A8E5A8C26B4}] - C:\Program Files (x86)\ver3BetterMarkIt\185.xpi
CHR DefaultSuggestURL: Default -> hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms}
Task: {C2A4DBCF-85DB-4AF7-9667-235505B79D5D} - System32\Tasks\PESM => C:\Users\Reisser\AppData\Roaming\PESM.exe [2015-01-04] (home) <==== ATTENTION
Task: C:\Windows\Tasks\PESM.job => C:\Users\Reisser\AppData\Roaming\PESM.exe <==== ATTENTION
C:\Windows\Tasks\PESM.job
C:\Windows\System32\Tasks\PESM
C:\Program Files (x86)\c37590b6-b104-45a2-80cb-69d810a404ed
C:\Users\Reisser\AppData\Roaming\PESM.exe
C:\Windows\{4626E3EA-85B3-464E-B296-F3F5488D8B08}
C:\ProgramData\1078601655
C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.dll
C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.exe
C:\Users\Reisser\AppData\Local\Temp\ED0B3C23-8BE8-3EB3-1490-A4C4FFFA8DA2.exe
C:\Users\Reisser\AppData\Local\Temp\nse838F.exe
C:\Program Files (x86)\ver3BetterMarkIt
EmptyTemp:
Hosts:

*****************

HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-21-1744345613-2801571155-2633355246-1000\Software\Mozilla\Firefox\Extensions\\{75229658-C485-8921-6792-5A8E5A8C26B4} => value deleted successfully.
Chrome DefaultSuggestURL deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C2A4DBCF-85DB-4AF7-9667-235505B79D5D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2A4DBCF-85DB-4AF7-9667-235505B79D5D}" => Key deleted successfully.
C:\Windows\System32\Tasks\PESM => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PESM" => Key deleted successfully.
C:\Windows\Tasks\PESM.job => Moved successfully.
"C:\Windows\Tasks\PESM.job" => File/Directory not found.
"C:\Windows\System32\Tasks\PESM" => File/Directory not found.
C:\Program Files (x86)\c37590b6-b104-45a2-80cb-69d810a404ed => Moved successfully.
C:\Users\Reisser\AppData\Roaming\PESM.exe => Moved successfully.
C:\Windows\{4626E3EA-85B3-464E-B296-F3F5488D8B08} => Moved successfully.
C:\ProgramData\1078601655 => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.dll => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\A76AB81D-707A-5889-895E-EED6F2E97078.exe => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\ED0B3C23-8BE8-3EB3-1490-A4C4FFFA8DA2.exe => Moved successfully.
C:\Users\Reisser\AppData\Local\Temp\nse838F.exe => Moved successfully.
"C:\Program Files (x86)\ver3BetterMarkIt" => File/Directory not found.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 545.4 MB temporary data.


The system needed a reboot.

==== End of Fixlog 13:15:06 ====

cosinus 05.01.2015 13:26

Okay, dann Kontrollscans mit MBAM und ESET bitte:

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


reisser 05.01.2015 15:12

Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlauf Datum: 05.01.2015
Suchlauf-Zeit: 13:52:38
Logdatei: mbam.txt
Administrator: Ja

Version: 2.00.4.1028
Malware Datenbank: v2015.01.05.05
Rootkit Datenbank: v2014.12.30.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Reisser

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 315176
Verstrichene Zeit: 7 Min, 28 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(Keine schädliche Elemente erkannt)

Module: 0
(Keine schädliche Elemente erkannt)

Registrierungsschlüssel: 9
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, In Quarantäne, [696014dfa4e559ddc860835f788c56aa],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, In Quarantäne, [92374fa48ffa092d4ed9f0f22ed6f50b],
PUP.Optional.CinemaHDPro.A, HKLM\SOFTWARE\WOW6432NODE\CinemaHd For Pro 2.4cV27.12-nv, In Quarantäne, [dfea777c92f73ef89a9467ff966d7e82],
PUP.Optional.HDVid.A, HKLM\SOFTWARE\WOW6432NODE\TheHDvid-Codec V10-nv, In Quarantäne, [dbee747fdfaae5512be530500cf73ec2],
PUP.Optional.HDVid.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\TheHDvid-Codec V10-nv, In Quarantäne, [efda91620d7c82b4f9181f61ed16f907],
PUP.Optional.CrossRider.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQPro-Video 1.6V26.12, In Quarantäne, [ffca26cd395054e2c0eb87e517ec8878],
PUP.Optional.HDVid.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\TheHDvid-Codec V10, In Quarantäne, [4980f7fc9bee8ea8070b1769f3107e82],
PUP.Optional.CinemaHDPro.A, HKU\S-1-5-21-1744345613-2801571155-2633355246-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CinemaHd For Pro 2.4cV27.12-nv, In Quarantäne, [9d2c965d3752e15575baa1c520e3cf31],
PUP.Optional.HDVid.A, HKU\S-1-5-21-1744345613-2801571155-2633355246-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\TheHDvid-Codec V10-nv, In Quarantäne, [785137bcd4b5b97d60b1453bde25827e],

Registrierungswerte: 0
(Keine schädliche Elemente erkannt)

Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)

Ordner: 0
(Keine schädliche Elemente erkannt)

Dateien: 13
PUP.Optional.Nova.A, C:\Program Files (x86)\AGEIA Technologies\382b2585-51fa-44d5-80fa-5d6425b8899f.dll, In Quarantäne, [4782b0436722191d479638c8b34f6c94],
PUP.Optional.Nova.A, C:\Program Files (x86)\AGEIA Technologies\9c1d7823-4df5-447b-9440-3f94dbcc7595.dll, In Quarantäne, [7b4e886b5633b77fc41920e01ce6ce32],
PUP.Optional.SearchProtect.A, C:\Windows\AppPatch\AppPatch64\VCLdr64.dll, In Quarantäne, [80492ac9800979bd033fe5c852af827e],
PUP.Optional.SearchProtect.A, C:\Windows\AppPatch\nbin\VC32Loader.dll, In Quarantäne, [2d9c6d86444588aee35f139a9a679868],
PUP.Optional.WebInstrNew.A, C:\Windows\System32\drivers\Msft_Kernel_webinstrNewH_01009.Wdf, In Quarantäne, [3e8b995a7c0d6bcb45d65f05010201ff],
PUP.Optional.Trovi.A, C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.trovi.com_0.localstorage, Löschen bei Neustart, [8f3aca29e5a463d348e4820d19ea6898],
PUP.Optional.Trovi.A, C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.trovi.com_0.localstorage-journal, Löschen bei Neustart, [2b9e24cff198e45248e4830c06fd04fc],
PUP.Optional.SearchProtect, C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, In Quarantäne, [19b0f2015c2dc37353d8538fc44023dd],
PUP.Optional.ReMarkable.A, C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage, Löschen bei Neustart, [1faa23d02a5f2c0ad63bfae9e024ee12],
PUP.Optional.ReMarkable.A, C:\Users\Reisser\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal, Löschen bei Neustart, [8643d122810880b6ba5712d158ac52ae],
PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMedia.ini, In Quarantäne, [1dac9f54f792e0561568816218ec9d63],
PUP.Optional.ColorMedia.A, C:\Windows\System32\ColorMediaOff.ini, In Quarantäne, [2a9f22d1addc3600d1ad25bed43037c9],
PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMediaOff.ini, In Quarantäne, [a623f5fed6b30e28c6b85c87c0447f81],

Physische Sektoren: 0
(Keine schädliche Elemente erkannt)


(end)


Alle Zeitangaben in WEZ +1. Es ist jetzt 04:28 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19