holger-s2 | 25.01.2015 13:17 | Hallo,
super, vielen Dank für die schnelle Antwort.
Bitte kurze Info, was weiter zu tun ist/
wenn etwas fehlt oder
"alles ok" wenn mein Problem beseitigt ist.
Hier die geforderten Dateien: mbam Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 25.01.2015
Suchlauf-Zeit: 12:24:44
Logdatei: mbam1.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.01.25.06
Rootkit Datenbank: v2015.01.14.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7
CPU: x64
Dateisystem: NTFS
Benutzer: AZi-PC
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 315520
Verstrichene Zeit: 9 Min, 11 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 20
PUP.Optional.PicColor.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B8D1E62C-5D04-4AB0-A09E-688FF75743EF}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1B0071C9-831E-43DD-9EFE-722D8AEB9E2E}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5217E897-1728-4B11-BC9D-5405AD551BEF}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{6073385E-A128-4464-9DFD-C7CF0F39A492}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{81E47395-D310-4064-B963-844C4088AB76}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{83E41C3D-190A-4052-A046-269722F3B4FD}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A62D52D9-1E41-4772-A794-71B9B92AA014}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D1C116A0-DC17-4257-9190-033AE10F90B9}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{ED5B55CA-994B-42B9-93B6-1FD306925967}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FB7F9DF6-2A66-444F-BA5D-2F221F1B1AC8}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1B0071C9-831E-43DD-9EFE-722D8AEB9E2E}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5217E897-1728-4B11-BC9D-5405AD551BEF}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6073385E-A128-4464-9DFD-C7CF0F39A492}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{81E47395-D310-4064-B963-844C4088AB76}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{83E41C3D-190A-4052-A046-269722F3B4FD}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A62D52D9-1E41-4772-A794-71B9B92AA014}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D1C116A0-DC17-4257-9190-033AE10F90B9}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{ED5B55CA-994B-42B9-93B6-1FD306925967}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FB7F9DF6-2A66-444F-BA5D-2F221F1B1AC8}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{B8D1E62C-5D04-4AB0-A09E-688FF75743EF}, In Quarantäne, [6f2bb04ba5e4a294b1891d4b22e113ed],
Registrierungswerte: 0
(Keine schädliche Elemente erkannt)
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 1
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
Dateien: 19
PUP.Optional.XTab.A, C:\Users\AZi-PC\AppData\Local\Temp\~dlFC9C\~dljyb\tmp\XTab_v4.0.exe, In Quarantäne, [05959b603356f83e248cb55259a92ad6],
PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMedia.ini, In Quarantäne, [cfcb25d621685bdbb1498972669e9d63],
PUP.Optional.ColorMedia.A, C:\Windows\System32\ColorMediaOff.ini, In Quarantäne, [4a50ca31a0e938fe73882ad1689c03fd],
PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMediaOff.ini, In Quarantäne, [ecae40bb0b7e1f17d32851aa29db30d0],
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\ColorMedia.tlb, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\ColorMediaCrt.dll, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\freebl3.dll, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\libnspr4.dll, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\libplc4.dll, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\libplds4.dll, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\nss3.dll, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\nssckbi.dll, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\nssdbm3.dll, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\nssutil3.dll, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\RfndNSIS.dll, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\smime3.dll, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\softokn3.dll, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\sqlite3.dll, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
PUP.Optional.PicColor.A, C:\ProgramData\PicColor Utility\ssl3.dll, Löschen bei Neustart, [6f2bb04ba5e4a294b1891d4b22e113ed],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) adwcleaner(s4) Code:
# AdwCleaner v4.109 - Bericht erstellt am 25/01/2015 um 12:56:35
# Aktualisiert 24/01/2015 von Xplode
# Database : 2015-01-24.4 [Live]
# Betriebssystem : Windows 7 Ultimate (64 bits)
# Benutzername : AZi-PC - AZI-PC
# Gestartet von : C:\Users\AZi-PC\Downloads\Safety\adwcleaner_4.109.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : ColorMedia
[#] Dienst Gelöscht : cmwf
[#] Dienst Gelöscht : cmwr
***** [ Dateien / Ordner ] *****
Datei Gelöscht : C:\Windows\System32\drivers\cmwr.sys
Datei Gelöscht : C:\Windows\System32\drivers\cmwf.sys
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v8.0.7600.16385
-\\ Google Chrome v40.0.2214.91
[C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=dspp&ts=1422125000&from=cvs&uid=395049983_266162_54A4CF31&q={searchTerms}
[C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=dspp&ts=1422125000&from=cvs&uid=395049983_266162_54A4CF31&q={searchTerms}
[C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.iminent.com/?appId=402A8546-4CC4-45CD-A31E-F0B5DE4435C2&ref=toolbox&q={searchTerms}
[C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=dspp&ts=1422125000&from=cvs&uid=395049983_266162_54A4CF31&q={searchTerms}
[C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=dspp&ts=1422125000&from=cvs&uid=395049983_266162_54A4CF31&q={searchTerms}
[C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://isearch.babylon.com/?q={searchTerms}&affID=120519&babsrc=SP_ss_bayi&mntrId=F0DF0015AF079DFA
[C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://isearch.babylon.com/?q={searchTerms}&affID=120519&babsrc=SP_ss_bayi&mntrId=F0DF0015AF079DFA
[C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://isearch.babylon.com/?q={searchTerms}&affID=120519&babsrc=SP_ss_bayi&mntrId=F0DF0015AF079DFA
*************************
AdwCleaner[R0].txt - [9102 octets] - [24/01/2015 21:14:10]
AdwCleaner[R1].txt - [2813 octets] - [24/01/2015 22:09:24]
AdwCleaner[R2].txt - [1237 octets] - [24/01/2015 22:16:52]
AdwCleaner[R3].txt - [3022 octets] - [24/01/2015 22:56:45]
AdwCleaner[R4].txt - [3112 octets] - [25/01/2015 10:29:13]
AdwCleaner[R5].txt - [1537 octets] - [25/01/2015 10:33:52]
AdwCleaner[R6].txt - [1597 octets] - [25/01/2015 11:02:24]
AdwCleaner[R7].txt - [3308 octets] - [25/01/2015 12:54:07]
AdwCleaner[S0].txt - [9213 octets] - [24/01/2015 21:17:32]
AdwCleaner[S1].txt - [2890 octets] - [24/01/2015 22:14:05]
AdwCleaner[S2].txt - [465 octets] - [24/01/2015 22:20:21]
AdwCleaner[S3].txt - [3189 octets] - [25/01/2015 10:31:42]
AdwCleaner[S4].txt - [3241 octets] - [25/01/2015 12:56:35]
########## EOF - C:\AdwCleaner\AdwCleaner[S4].txt - [3301 octets] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Ultimate x64
Ran by AZi-PC on 25.01.2015 at 13:01:22,18
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25.01.2015 at 13:06:02,07
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01
Ran by AZi-PC (administrator) on AZI-PC on 25-01-2015 13:10:13
Running from C:\Users\AZi-PC\Desktop
Loaded Profiles: AZi-PC (Available profiles: AZi-PC)
Platform: Windows 7 Ultimate (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(EIZO Corporation) C:\Program Files (x86)\EIZO\ScreenSlicer\ESCSlicer.exe
(EIZO Corporation) C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD\Lcdctrl.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(ATI Technologies Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2015-01-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [124208 2014-10-22] (Avira Operations GmbH & Co. KG)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\EIZO ScreenSlicer.lnk
ShortcutTarget: EIZO ScreenSlicer.lnk -> C:\Windows\Installer\{292A177D-723F-4537-9985-BC8BFCD8B63D}\NewShortcut1_ECE901F38F8D425291BF1815F96683B4.exe (Macrovision Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScreenManager Pro for LCD Ver3.3.3.lnk
ShortcutTarget: ScreenManager Pro for LCD Ver3.3.3.lnk -> C:\Program Files (x86)\EIZO\ScreenManager Pro for LCD\Lcdctrl.exe (EIZO Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:49436;https=127.0.0.1:49436;
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\S-1-5-21-3672898365-1647074900-201637474-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Winsock: Catalog9 01 C:\Windows\SysWOW64\ColorMedia.dll [324776] (CartCrunch Israel Ltd.)
Winsock: Catalog9 02 C:\Windows\SysWOW64\ColorMedia.dll [324776] (CartCrunch Israel Ltd.)
Winsock: Catalog9 03 C:\Windows\SysWOW64\ColorMedia.dll [324776] (CartCrunch Israel Ltd.)
Winsock: Catalog9 04 C:\Windows\SysWOW64\ColorMedia.dll [324776] (CartCrunch Israel Ltd.)
Winsock: Catalog9 15 C:\Windows\SysWOW64\ColorMedia.dll [324776] (CartCrunch Israel Ltd.)
Winsock: Catalog9-x64 01 C:\Windows\system32\ColorMedia64.dll [370688] (CartCrunch Israel Ltd.)
Winsock: Catalog9-x64 02 C:\Windows\system32\ColorMedia64.dll [370688] (CartCrunch Israel Ltd.)
Winsock: Catalog9-x64 03 C:\Windows\system32\ColorMedia64.dll [370688] (CartCrunch Israel Ltd.)
Winsock: Catalog9-x64 04 C:\Windows\system32\ColorMedia64.dll [370688] (CartCrunch Israel Ltd.)
Winsock: Catalog9-x64 15 C:\Windows\system32\ColorMedia64.dll [370688] (CartCrunch Israel Ltd.)
Tcpip\..\Interfaces\{3FCFEC49-E79E-42E3-9AE6-CFF4F098A30B}: [NameServer] 192.168.0.1
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
Chrome:
=======
CHR HomePage: Default ->
CHR StartupUrls: Default -> "https://www.google.de/", "hxxp://istart.webssearches.com/?type=hppp&ts=1401179454&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1401342874&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1401392681&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1401470905&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1401534646&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1401613039&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1401814348&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1401981463&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1402251016&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1402332086&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1402681885&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1402772176&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1402851446&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1402913513&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1402990213&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1403171129&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1403182900&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1403194663&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hppp&ts=1403361600&from=tugs&uid=395049983_266162_F0DFA897", "hxxp://istart.webssearches.com/?type=hp&ts=1422124986&from=cvs&uid=395049983_266162_54A4CF31", "hxxp://istart.webssearches.com/?type=hppp&ts=1422125000&from=cvs&uid=395049983_266162_54A4CF31"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-24]
CHR Extension: (Google Docs) - C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-24]
CHR Extension: (Google Drive) - C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-24]
CHR Extension: (YouTube) - C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-24]
CHR Extension: (Google-Suche) - C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-24]
CHR Extension: (Google Tabellen) - C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-24]
CHR Extension: (Avira Browserschutz) - C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-01-24]
CHR Extension: (Bookmark Manager) - C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-01-24]
CHR Extension: (Google Wallet) - C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-24]
CHR Extension: (Google Mail) - C:\Users\AZi-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-24]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2015-01-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2015-01-24] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [164656 2014-10-22] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
S2 ColorMedia; C:\ProgramData\PicColor Utility\ColorMedia.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2015-01-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2015-01-24] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 cmwf; C:\Windows\system32\Drivers\cmwf.sys [33952 2015-01-07] () [File not signed]
R1 cmwr; C:\Windows\system32\Drivers\cmwr.sys [45216 2015-01-07] () [File not signed]
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-25] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-25 13:06 - 2015-01-25 13:06 - 00000622 _____ () C:\Users\AZi-PC\Desktop\JRT1.txt
2015-01-25 13:06 - 2015-01-25 13:06 - 00000622 _____ () C:\Users\AZi-PC\Desktop\JRT.txt
2015-01-25 13:01 - 2015-01-25 13:01 - 00000000 ____D () C:\Windows\ERUNT
2015-01-25 12:59 - 2015-01-25 12:59 - 00003381 _____ () C:\Users\AZi-PC\Desktop\AdwCleaner[S4].txt
2015-01-25 12:52 - 2015-01-25 12:52 - 00006766 _____ () C:\Users\AZi-PC\Desktop\mbam1.txt
2015-01-25 12:46 - 2015-01-25 12:46 - 00006765 _____ () C:\Users\AZi-PC\Desktop\mbam.txt
2015-01-25 12:24 - 2015-01-25 13:09 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-25 12:23 - 2015-01-25 12:23 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-25 12:23 - 2015-01-25 12:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-25 12:23 - 2015-01-25 12:23 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-25 12:23 - 2015-01-25 12:23 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-25 12:23 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-25 12:23 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-25 12:23 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-01-25 12:22 - 2015-01-25 12:22 - 00000000 ____D () C:\Users\AZi-PC\Downloads\Safety
2015-01-25 12:22 - 2015-01-25 12:22 - 00000000 ____D () C:\Users\AZi-PC\Downloads\Grafik
2015-01-25 12:22 - 2015-01-25 12:21 - 01707939 _____ (Thisisu) C:\Users\AZi-PC\Desktop\JRT.exe
2015-01-25 12:21 - 2015-01-25 12:21 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\AZi-PC\Desktop\mbam-setup-2.0.4.1028.exe
2015-01-25 10:49 - 2015-01-25 10:49 - 00018284 _____ () C:\Users\AZi-PC\Desktop\Addition.txt
2015-01-25 10:48 - 2015-01-25 13:10 - 00012603 _____ () C:\Users\AZi-PC\Desktop\FRST.txt
2015-01-25 10:48 - 2015-01-25 13:10 - 00000000 ____D () C:\FRST
2015-01-25 10:42 - 2015-01-25 10:42 - 02129920 _____ (Farbar) C:\Users\AZi-PC\Desktop\FRST64.exe
2015-01-24 22:35 - 2015-01-24 22:39 - 00000000 ____D () C:\Users\AZi-PC\Documents\Tipard Studio
2015-01-24 22:35 - 2015-01-24 22:35 - 00001429 _____ () C:\Users\Public\Desktop\Tipard TS Converter.lnk
2015-01-24 22:35 - 2015-01-24 22:35 - 00000000 ____D () C:\Users\AZi-PC\AppData\Local\Tipard Studio
2015-01-24 22:35 - 2015-01-24 22:35 - 00000000 ____D () C:\ProgramData\Tipard Studio
2015-01-24 22:35 - 2015-01-24 22:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tipard
2015-01-24 22:35 - 2015-01-24 22:35 - 00000000 ____D () C:\Program Files (x86)\Tipard Studio
2015-01-24 22:34 - 2015-01-24 22:34 - 24154712 _____ (Tipard Studio ) C:\Users\AZi-PC\Downloads\ts71-converter.exe
2015-01-24 22:21 - 2015-01-24 22:21 - 00000000 ____D () C:\Users\AZi-PC\AppData\Local\Microsoft Games
2015-01-24 21:14 - 2015-01-25 12:56 - 00000000 ____D () C:\AdwCleaner
2015-01-24 20:58 - 2015-01-24 20:58 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-01-24 20:57 - 2015-01-24 20:54 - 00043064 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-01-24 20:49 - 2015-01-24 20:49 - 00003150 _____ () C:\Windows\System32\Tasks\{655729CA-F8E3-4BD9-A398-D24CC2E3B7DB}
2015-01-24 20:40 - 2015-01-24 20:40 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-01-24 20:40 - 2015-01-24 20:40 - 00000000 ____D () C:\Windows\system32\appraiser
2015-01-24 20:39 - 2015-01-24 20:39 - 00000000 ____D () C:\Users\AZi-PC\AppData\Roaming\EIZO
2015-01-24 20:39 - 2015-01-24 20:39 - 00000000 ____D () C:\Users\AZi-PC\AppData\Local\Downloaded Installations
2015-01-24 20:39 - 2015-01-24 20:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EIZO
2015-01-24 20:34 - 2015-01-24 20:39 - 00000000 ____D () C:\Program Files (x86)\EIZO
2015-01-24 20:34 - 2015-01-24 20:34 - 00000000 ____D () C:\Users\AZi-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EIZO
2015-01-24 20:31 - 2015-01-24 20:35 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-24 20:30 - 2014-12-04 03:32 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-01-24 20:30 - 2014-12-04 03:32 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-01-24 20:30 - 2014-12-04 03:32 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-01-24 20:30 - 2014-12-04 03:31 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-01-24 20:30 - 2014-12-04 03:31 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-01-24 20:30 - 2014-12-04 03:31 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-01-24 20:30 - 2014-12-04 03:26 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-01-24 20:30 - 2014-12-02 00:21 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-01-24 20:30 - 2011-04-09 07:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-01-24 20:30 - 2011-04-09 07:45 - 05509504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-24 20:30 - 2011-04-09 07:13 - 03957632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-24 20:30 - 2011-04-09 07:13 - 03901824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-24 20:30 - 2011-04-09 06:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2015-01-24 20:29 - 2014-09-15 01:44 - 03195392 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-01-24 20:29 - 2009-10-24 05:28 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2015-01-24 20:29 - 2009-10-24 05:27 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2015-01-24 20:26 - 2012-06-02 23:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-01-24 20:26 - 2012-06-02 23:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-01-24 20:26 - 2012-06-02 23:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-01-24 20:26 - 2012-06-02 23:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-01-24 20:26 - 2012-06-02 23:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-01-24 20:26 - 2012-06-02 23:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-01-24 20:26 - 2012-06-02 23:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-01-24 20:26 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-01-24 20:26 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-01-24 20:24 - 2015-01-24 20:24 - 00000000 ____D () C:\Users\AZi-PC\AppData\Roaming\ATI
2015-01-24 20:24 - 2015-01-24 20:24 - 00000000 ____D () C:\Users\AZi-PC\AppData\Local\ATI
2015-01-24 20:24 - 2015-01-24 20:24 - 00000000 ____D () C:\ProgramData\ATI
2015-01-24 20:22 - 2015-01-24 20:22 - 00000000 _____ () C:\Windows\ativpsrm.bin
2015-01-24 20:21 - 2015-01-24 20:21 - 00000000 ____D () C:\ProgramData\AMD
2015-01-24 20:20 - 2015-01-24 20:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-01-24 20:20 - 2015-01-24 20:20 - 00000000 ____D () C:\Program Files (x86)\AMD AVT
2015-01-24 20:19 - 2015-01-24 20:19 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2015-01-24 20:19 - 2015-01-24 20:19 - 00000000 ____D () C:\Program Files (x86)\AMD
2015-01-24 20:18 - 2015-01-24 20:18 - 01558224 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-01-24 20:17 - 2009-11-25 11:47 - 01942856 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2015-01-24 20:17 - 2009-11-25 11:47 - 01130824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2015-01-24 20:17 - 2009-11-25 11:47 - 00444752 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll
2015-01-24 20:17 - 2009-11-25 11:47 - 00320352 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe
2015-01-24 20:17 - 2009-11-25 11:47 - 00297808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscoree.dll
2015-01-24 20:17 - 2009-11-25 11:47 - 00295264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHost.exe
2015-01-24 20:17 - 2009-11-25 11:47 - 00109912 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll
2015-01-24 20:17 - 2009-11-25 11:47 - 00099176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHostProxy.dll
2015-01-24 20:17 - 2009-11-25 11:47 - 00049472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netfxperf.dll
2015-01-24 20:17 - 2009-11-25 11:47 - 00048960 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll
2015-01-24 20:16 - 2015-01-24 20:58 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-24 20:15 - 2015-01-24 20:20 - 00000000 ____D () C:\Program Files\AMD
2015-01-24 20:13 - 2015-01-24 20:13 - 00000000 ____D () C:\AMD
2015-01-24 19:53 - 2015-01-24 19:53 - 00000000 ____D () C:\Users\AZi-PC\AppData\Roaming\Avira
2015-01-24 19:52 - 2015-01-24 20:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-01-24 19:52 - 2015-01-24 19:52 - 00002066 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2015-01-24 19:51 - 2015-01-24 20:58 - 00000000 ____D () C:\ProgramData\Avira
2015-01-24 19:51 - 2015-01-24 20:58 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-01-24 19:51 - 2015-01-24 20:54 - 00131608 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-01-24 19:51 - 2015-01-24 20:54 - 00119272 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-01-24 19:51 - 2015-01-24 19:51 - 00000000 ____D () C:\Users\AZi-PC\AppData\Roaming\dlg
2015-01-24 19:51 - 2013-12-18 09:32 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-01-24 19:44 - 2015-01-07 21:07 - 00045216 _____ () C:\Windows\system32\Drivers\cmwr.sys
2015-01-24 19:44 - 2015-01-07 21:07 - 00033952 _____ () C:\Windows\system32\Drivers\cmwf.sys
2015-01-24 19:44 - 2015-01-07 20:54 - 00370688 _____ (CartCrunch Israel Ltd.) C:\Windows\system32\ColorMedia64.dll
2015-01-24 19:44 - 2015-01-07 20:54 - 00324776 _____ (CartCrunch Israel Ltd.) C:\Windows\SysWOW64\ColorMedia.dll
2015-01-24 19:37 - 2015-01-25 12:57 - 00131632 _____ () C:\Windows\PFRO.log
2015-01-24 19:34 - 2015-01-24 21:17 - 00001023 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-24 19:34 - 2015-01-24 21:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-01-24 19:32 - 2015-01-25 13:09 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-24 19:32 - 2015-01-25 12:37 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-24 19:32 - 2015-01-24 19:34 - 00000000 ____D () C:\Users\AZi-PC\AppData\Local\Google
2015-01-24 19:32 - 2015-01-24 19:34 - 00000000 ____D () C:\Users\AZi-PC\AppData\Local\Deployment
2015-01-24 19:32 - 2015-01-24 19:34 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-24 19:32 - 2015-01-24 19:32 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-01-24 19:32 - 2015-01-24 19:32 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-01-24 19:32 - 2015-01-24 19:32 - 00000000 ____D () C:\Users\AZi-PC\AppData\Local\Apps\2.0
2015-01-24 19:28 - 2015-01-24 19:28 - 00000010 _____ () C:\Users\AZi-PC\Desktop\Kennwort Heimnetzgruppe.txt
2015-01-24 19:21 - 2015-01-24 19:21 - 00057560 _____ () C:\Users\AZi-PC\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-24 19:11 - 2015-01-24 21:17 - 00000919 _____ () C:\Users\AZi-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-01-24 19:11 - 2015-01-24 21:17 - 00000851 _____ () C:\Users\AZi-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2015-01-24 19:11 - 2015-01-24 19:11 - 00000000 ____D () C:\Users\AZi-PC\AppData\Local\VirtualStore
2015-01-24 19:10 - 2015-01-24 19:11 - 00000000 ____D () C:\Users\AZi-PC
2015-01-24 19:10 - 2015-01-24 19:10 - 00000020 ___SH () C:\Users\AZi-PC\ntuser.ini
2015-01-24 19:10 - 2015-01-24 19:10 - 00000000 _SHDL () C:\Users\AZi-PC\Vorlagen
2015-01-24 19:10 - 2015-01-24 19:10 - 00000000 _SHDL () C:\Users\AZi-PC\Startmenü
2015-01-24 19:10 - 2015-01-24 19:10 - 00000000 _SHDL () C:\Users\AZi-PC\Netzwerkumgebung
2015-01-24 19:10 - 2015-01-24 19:10 - 00000000 _SHDL () C:\Users\AZi-PC\Lokale Einstellungen
2015-01-24 19:10 - 2015-01-24 19:10 - 00000000 _SHDL () C:\Users\AZi-PC\Eigene Dateien
2015-01-24 19:10 - 2015-01-24 19:10 - 00000000 _SHDL () C:\Users\AZi-PC\Druckumgebung
2015-01-24 19:10 - 2015-01-24 19:10 - 00000000 _SHDL () C:\Users\AZi-PC\Documents\Eigene Musik
2015-01-24 19:10 - 2015-01-24 19:10 - 00000000 _SHDL () C:\Users\AZi-PC\Documents\Eigene Bilder
2015-01-24 19:10 - 2015-01-24 19:10 - 00000000 _SHDL () C:\Users\AZi-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-01-24 19:10 - 2015-01-24 19:10 - 00000000 _SHDL () C:\Users\AZi-PC\AppData\Local\Verlauf
2015-01-24 19:10 - 2015-01-24 19:10 - 00000000 _SHDL () C:\Users\AZi-PC\AppData\Local\Anwendungsdaten
2015-01-24 19:10 - 2015-01-24 19:10 - 00000000 _SHDL () C:\Users\AZi-PC\Anwendungsdaten
2015-01-24 19:10 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\AZi-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-01-24 19:10 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\AZi-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default\Startmenü
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Programme
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\ProgramData\Startmenü
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\ProgramData\Favoriten
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\ProgramData\Dokumente
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 _SHDL () C:\Dokumente und Einstellungen
2015-01-24 19:08 - 2015-01-24 19:08 - 00000000 __SHD () C:\Recovery
2015-01-24 19:07 - 2015-01-25 13:06 - 00383449 _____ () C:\Windows\WindowsUpdate.log
2015-01-24 19:02 - 2015-01-24 19:02 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2015-01-24 19:02 - 2015-01-24 19:02 - 00000000 ____D () C:\Windows\CSC
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-25 13:07 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-25 13:07 - 2009-07-14 05:51 - 00025722 _____ () C:\Windows\setupact.log
2015-01-25 13:04 - 2009-07-14 18:58 - 00698688 _____ () C:\Windows\system32\perfh007.dat
2015-01-25 13:04 - 2009-07-14 18:58 - 00148828 _____ () C:\Windows\system32\perfc007.dat
2015-01-25 13:04 - 2009-07-14 06:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-25 13:03 - 2009-07-14 05:45 - 00014192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-25 13:03 - 2009-07-14 05:45 - 00014192 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-25 12:48 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\Performance
2015-01-24 20:41 - 2009-07-14 05:45 - 00265696 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-24 20:40 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2015-01-24 20:16 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\restore
2015-01-24 19:27 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2015-01-24 19:15 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-01-24 19:08 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2015-01-24 19:08 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Windows NT
2015-01-24 19:06 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2015-01-24 19:03 - 2009-10-14 07:04 - 00000000 ____D () C:\Windows\Panther
2015-01-24 19:03 - 2009-10-14 06:06 - 00003540 _____ () C:\Windows\TSSysprep.log
2015-01-24 19:03 - 2009-07-14 05:46 - 00002790 _____ () C:\Windows\DtcInstall.log
2015-01-24 19:01 - 2009-07-14 06:38 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2015-01-24 19:01 - 2009-07-14 06:32 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
2014-12-31 13:12 - 2009-10-14 06:12 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\AZi-PC\AppData\Local\Temp\avgnt.exe
C:\Users\AZi-PC\AppData\Local\Temp\Quarantine.exe
C:\Users\AZi-PC\AppData\Local\Temp\SpOrder.dll
C:\Users\AZi-PC\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2009-10-14 06:05
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Viele Grüße,
Holger |