Friedrich290 | 19.05.2015 17:11 | Hallo,
1: MBAM HTML-Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 19.05.2015
Suchlauf-Zeit: 16:27:30
Logdatei: MB 1.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.05.19.03
Rootkit Datenbank: v2015.05.16.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Daniel
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 407006
Verstrichene Zeit: 27 Min, 27 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 46
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{0B23278C-F04F-4E8D-A4E0-3ED65D6CADAC}, In Quarantäne, [cab5880d2b5f42f4b72f1a5648bd8b75],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{67428E28-7B13-4298-A767-14E87A80B93B}, In Quarantäne, [2b54fa9ba7e354e2dd08fb758b7a04fc],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E3DD5DB5-E7F9-4B46-91FD-572705C45A45}, In Quarantäne, [26591382b0da9e98549396dabe470df3],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EB2268EB-6D29-4703-9AD5-42F79ACD492C}, In Quarantäne, [3a45187d37534ee8ebfc1c54ad586799],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FFE033AE-CA5D-4D00-93B6-EF267AF8E9B7}, In Quarantäne, [1966d9bc3753a29425c0a8c8c045ba46],
PUP.Optional.Dregol.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [156a653099f180b6a61a4e1be124d42c],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E3DD5DB5-E7F9-4B46-91FD-572705C45A45}, In Quarantäne, [324d682d5337d16527c02947867f728e],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EB2268EB-6D29-4703-9AD5-42F79ACD492C}, In Quarantäne, [d9a61481365478bec126d49cc243649c],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FFE033AE-CA5D-4D00-93B6-EF267AF8E9B7}, In Quarantäne, [5f20e9ac06841d1903e28de349bc53ad],
PUP.Optional.Crossbrowse.A, HKU\S-1-5-21-223822767-1807346583-171944255-1001\SOFTWARE\CrossBrowser, In Quarantäne, [d0af484d6c1e4fe7f34aeaf10cf79967],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{0B23278C-F04F-4E8D-A4E0-3ED65D6CADAC}, In Quarantäne, [56292e677f0b82b4f9eaee82b352b947],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1537DF48-1670-41C1-89E0-64563DC0D9B4}, In Quarantäne, [d7a82f668a005fd7a53efb7533d28779],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{191B8998-5785-4B94-8CC8-2CD51ECF2DB6}, In Quarantäne, [2b54bdd8fa90ee482eb5df914abb01ff],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2915F330-C8AC-4A99-83F6-165C26DF64CE}, In Quarantäne, [354a7d1808822a0c5193dc946a9b57a9],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3A6C116B-B7E5-4915-8426-C560D0279F17}, In Quarantäne, [027d6233464457df09da610fb055d030],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4269028E-568F-4817-AB14-486871288038}, In Quarantäne, [2659dabb67239d99a143185840c59b65],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{49D04A3B-1449-4509-AB41-7E1F111816DF}, In Quarantäne, [bec1a3f27b0f1422f5ee3f318085dc24],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4A216DBF-88BC-4000-A2FF-27E4977EC6EC}, In Quarantäne, [bbc41580503a61d5657ef37d40c5d927],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{53A54BA8-6CC0-4AAD-B39A-E4E5D6AB3716}, In Quarantäne, [027d4055602ad5610adab7b9d72e5ea2],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{57EB1AC0-820C-4EFA-B2A3-68CBE2464D75}, In Quarantäne, [7609f5a0f09a8aac3fa5b5bb867fe61a],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5A0DD69F-277F-4136-A34E-BE5E3A7938F9}, In Quarantäne, [750adabb137757df21c25f118481c739],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5B67D75F-BC6A-4A70-B462-AC7DD5C69046}, In Quarantäne, [c9b68e07c6c459dd766e640ca065966a],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{67428E28-7B13-4298-A767-14E87A80B93B}, In Quarantäne, [a6d9dabbb5d566d042a0185813f21ee2],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68317F56-9E00-4286-A482-60CB1F92A553}, In Quarantäne, [fa850f861a701323dd0757190cf96f91],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7640CCC9-3099-447B-A666-36864367ED78}, In Quarantäne, [5d22b6dffd8d2016b034d19f20e56f91],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{774344BC-53BF-4C38-8458-5D41D5779E7D}, In Quarantäne, [d2adc5d0bcce51e5786cd29e867f8b75],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7E6B3DA6-CE95-4873-B2AD-8F4838F2F33C}, In Quarantäne, [a2ddbbda2c5ed85e598afd73bc491ae6],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{84613B00-6AAE-4228-BD26-B270C7A3C9DB}, In Quarantäne, [c0bf8e07147651e5a241a8c8e32222de],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{85DF9591-4175-4D4C-A330-E9BC9D10D3CB}, In Quarantäne, [3847d5c03d4d3afc746f195738cdaf51],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9218CF0C-CE9C-4A1B-9021-DBA6EC408766}, In Quarantäne, [85fa0f865f2b45f1a043ef81838239c7],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{99EFA113-99FB-4AA1-ABEE-A38E867FEFD8}, In Quarantäne, [ceb12372058593a3885c75fbd72e4eb2],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9BD8899D-57D6-4211-93C7-50EC623DE8FC}, In Quarantäne, [aed165304446c67000e43f318b7a728e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A20CA807-70D6-4542-8358-1BF27C1323DD}, In Quarantäne, [2a5595006e1c300631b3145c23e2cc34],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A96E171A-CC1C-4A23-9EA1-28D6D6391FAA}, In Quarantäne, [2f506b2a36541f17fce7eb854cb903fd],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B24D5919-6719-42C1-B1D1-B46DD880DDC9}, In Quarantäne, [a7d8bbdaf298d75fe3000b65fa0b36ca],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CED94FA4-9202-473E-B23E-78A6B1E42F3C}, In Quarantäne, [93ec70258dfd5adc6e751b551fe622de],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D4EAECEB-64F2-46F5-B97E-E317DA942D27}, In Quarantäne, [58274451aedc43f3984b066a3fc67789],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D709A9FB-831C-4F4F-8FD6-55F4BDCEE2A8}, In Quarantäne, [d1ae02934347f73fa143ed8363a202fe],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E3DD5DB5-E7F9-4B46-91FD-572705C45A45}, In Quarantäne, [2956badb4b3fd4624a9a145ce52042be],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E7EA9BE5-284E-4590-8F8C-DC1BFE3F3654}, In Quarantäne, [a8d70d8829613006a53e145ccf36f50b],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EB2268EB-6D29-4703-9AD5-42F79ACD492C}, In Quarantäne, [d8a70491632750e6459f0d63e322af51],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EDD0611F-7E6A-493C-9184-6CF4B3E6CEEB}, In Quarantäne, [09769cf92961d066855f78f83acb40c0],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F291F329-3FE6-4E37-AA38-4EB2EFE8ED19}, In Quarantäne, [8df20c8998f2c27419ca87e994712ad6],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F493A178-DCE8-46CD-8674-BE57D4AD1E6E}, In Quarantäne, [e49b9df8c9c14cea9a49a0d038cdf907],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FFE033AE-CA5D-4D00-93B6-EF267AF8E9B7}, In Quarantäne, [5f209cf9f39781b5dc06b3bda85de41c],
PUP.Optional.Dregol.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [384795008a0026107e4196d3c540718f],
Registrierungswerte: 54
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{0b23278c-f04f-4e8d-a4e0-3ed65d6cadac}|AppName, TheHDvid-Codec V10-buttonutil.exe, In Quarantäne, [cab5880d2b5f42f4b72f1a5648bd8b75]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{67428e28-7b13-4298-a767-14e87a80b93b}|AppName, TheHDvid-Codec V10-bg.exe, In Quarantäne, [2b54fa9ba7e354e2dd08fb758b7a04fc]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{e3dd5db5-e7f9-4b46-91fd-572705c45a45}|AppName, CinemaP-1.9cV02.01-codedownloader.exe, In Quarantäne, [26591382b0da9e98549396dabe470df3]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{eb2268eb-6d29-4703-9ad5-42f79acd492c}|AppName, TheHDvid-Codec V10-codedownloader.exe, In Quarantäne, [3a45187d37534ee8ebfc1c54ad586799]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ffe033ae-ca5d-4d00-93b6-ef267af8e9b7}|AppName, CinemaP-1.9cV02.01-bg.exe, In Quarantäne, [1966d9bc3753a29425c0a8c8c045ba46]
PUP.Optional.Dregol.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, hxxp://www.dregol.com/results.php?f=4&q={searchTerms}&a=drg_ggbg_15_15&cd=2XzuyEtN2Y1L1Qzu0Fzz0AzyyCtA0EyByCtByD0CyC0C0BzztN0D0Tzu0StCtCzyyEtN1L2XzutAtFzytFzztFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0DyB0EyEzytAyCtGyE0D0EyBtGyDtAyD0EtG0EtD0DyEtGtCyC0FtAzzyE0C0DtB0ByE0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0F0AtCtA0FyD0FtG0ByBtC0EtGyEyDtByCtG0B0EzyyBtG0B0DyBzytB0E0C0CtBzzzzzy2QtN0A0LzuyE&cr=1691039868&ir=, In Quarantäne, [156a653099f180b6a61a4e1be124d42c]
PUP.Optional.Dregol.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback, hxxp://www.dregol.com/results.php?f=4&q={searchTerms}&a=drg_ggbg_15_15&cd=2XzuyEtN2Y1L1Qzu0Fzz0AzyyCtA0EyByCtByD0CyC0C0BzztN0D0Tzu0StCtCzyyEtN1L2XzutAtFzytFzztFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0DyB0EyEzytAyCtGyE0D0EyBtGyDtAyD0EtG0EtD0DyEtGtCyC0FtAzzyE0C0DtB0ByE0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0F0AtCtA0FyD0FtG0ByBtC0EtGyEyDtByCtG0B0EzyyBtG0B0DyBzytB0E0C0CtBzzzzzy2QtN0A0LzuyE&cr=1691039868&ir=, In Quarantäne, [453a5e37d9b1c86e744c5019ad5856aa]
PUP.Optional.Dregol.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|FaviconPath, C:\Users\Daniel\AppData\LocalLow\Microsoft\Internet Explorer\Services\Run_Dregol.ico, In Quarantäne, [5e218e07a5e5df573c84c0a99d68a65a]
PUP.Optional.Dregol.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, Dregol, In Quarantäne, [cab51d78ddad4cea7e420f5acf368e72]
PUP.Optional.Dregol.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|DisplayName, Dregol, In Quarantäne, [7c036f26e0aaf343e8d8f77204016898]
PUP.Optional.Dregol.C, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\Run_Dregol\\, In Quarantäne, [e09fb3e2a5e5b185f4e2bd1bd92ab848]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{e3dd5db5-e7f9-4b46-91fd-572705c45a45}|AppName, CinemaP-1.9cV02.01-codedownloader.exe, In Quarantäne, [324d682d5337d16527c02947867f728e]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{eb2268eb-6d29-4703-9ad5-42f79acd492c}|AppName, TheHDvid-Codec V10-codedownloader.exe, In Quarantäne, [d9a61481365478bec126d49cc243649c]
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ffe033ae-ca5d-4d00-93b6-ef267af8e9b7}|AppName, CinemaP-1.9cV02.01-bg.exe, In Quarantäne, [5f20e9ac06841d1903e28de349bc53ad]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{0b23278c-f04f-4e8d-a4e0-3ed65d6cadac}|AppName, TheHDvid-Codec V10-buttonutil.exe, In Quarantäne, [56292e677f0b82b4f9eaee82b352b947]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1537DF48-1670-41C1-89E0-64563DC0D9B4}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-buttonutil.exe, In Quarantäne, [d7a82f668a005fd7a53efb7533d28779]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{191B8998-5785-4B94-8CC8-2CD51ECF2DB6}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-buttonutil.exe, In Quarantäne, [2b54bdd8fa90ee482eb5df914abb01ff]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2915F330-C8AC-4A99-83F6-165C26DF64CE}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-codedownloader.exe, In Quarantäne, [354a7d1808822a0c5193dc946a9b57a9]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3A6C116B-B7E5-4915-8426-C560D0279F17}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-buttonutil.exe, In Quarantäne, [027d6233464457df09da610fb055d030]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4269028E-568F-4817-AB14-486871288038}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-codedownloader.exe, In Quarantäne, [2659dabb67239d99a143185840c59b65]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{49D04A3B-1449-4509-AB41-7E1F111816DF}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-buttonutil.exe, In Quarantäne, [bec1a3f27b0f1422f5ee3f318085dc24]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4A216DBF-88BC-4000-A2FF-27E4977EC6EC}|AppName, d187d13c-eb9d-4d47-bf31-4a5c3088774b-2.exe-buttonutil.exe, In Quarantäne, [bbc41580503a61d5657ef37d40c5d927]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{53A54BA8-6CC0-4AAD-B39A-E4E5D6AB3716}|AppName, d187d13c-eb9d-4d47-bf31-4a5c3088774b-2.exe-codedownloader.exe, In Quarantäne, [027d4055602ad5610adab7b9d72e5ea2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{57EB1AC0-820C-4EFA-B2A3-68CBE2464D75}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-codedownloader.exe, In Quarantäne, [7609f5a0f09a8aac3fa5b5bb867fe61a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5A0DD69F-277F-4136-A34E-BE5E3A7938F9}|AppName, d187d13c-eb9d-4d47-bf31-4a5c3088774b-2.exe-buttonutil.exe, In Quarantäne, [750adabb137757df21c25f118481c739]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5B67D75F-BC6A-4A70-B462-AC7DD5C69046}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-codedownloader.exe, In Quarantäne, [c9b68e07c6c459dd766e640ca065966a]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{67428e28-7b13-4298-a767-14e87a80b93b}|AppName, TheHDvid-Codec V10-bg.exe, In Quarantäne, [a6d9dabbb5d566d042a0185813f21ee2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68317F56-9E00-4286-A482-60CB1F92A553}|AppName, d187d13c-eb9d-4d47-bf31-4a5c3088774b-2.exe-codedownloader.exe, In Quarantäne, [fa850f861a701323dd0757190cf96f91]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7640CCC9-3099-447B-A666-36864367ED78}|AppName, d187d13c-eb9d-4d47-bf31-4a5c3088774b-2.exe-codedownloader.exe, In Quarantäne, [5d22b6dffd8d2016b034d19f20e56f91]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{774344BC-53BF-4C38-8458-5D41D5779E7D}|AppName, d187d13c-eb9d-4d47-bf31-4a5c3088774b-2.exe-codedownloader.exe, In Quarantäne, [d2adc5d0bcce51e5786cd29e867f8b75]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7E6B3DA6-CE95-4873-B2AD-8F4838F2F33C}|AppName, d187d13c-eb9d-4d47-bf31-4a5c3088774b-2.exe-buttonutil.exe, In Quarantäne, [a2ddbbda2c5ed85e598afd73bc491ae6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{84613B00-6AAE-4228-BD26-B270C7A3C9DB}|AppName, d187d13c-eb9d-4d47-bf31-4a5c3088774b-2.exe-buttonutil.exe, In Quarantäne, [c0bf8e07147651e5a241a8c8e32222de]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{85DF9591-4175-4D4C-A330-E9BC9D10D3CB}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-buttonutil.exe, In Quarantäne, [3847d5c03d4d3afc746f195738cdaf51]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9218CF0C-CE9C-4A1B-9021-DBA6EC408766}|AppName, d187d13c-eb9d-4d47-bf31-4a5c3088774b-2.exe-buttonutil.exe, In Quarantäne, [85fa0f865f2b45f1a043ef81838239c7]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{99EFA113-99FB-4AA1-ABEE-A38E867FEFD8}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-codedownloader.exe, In Quarantäne, [ceb12372058593a3885c75fbd72e4eb2]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9BD8899D-57D6-4211-93C7-50EC623DE8FC}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-codedownloader.exe, In Quarantäne, [aed165304446c67000e43f318b7a728e]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A20CA807-70D6-4542-8358-1BF27C1323DD}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-codedownloader.exe, In Quarantäne, [2a5595006e1c300631b3145c23e2cc34]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A96E171A-CC1C-4A23-9EA1-28D6D6391FAA}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-buttonutil.exe, In Quarantäne, [2f506b2a36541f17fce7eb854cb903fd]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B24D5919-6719-42C1-B1D1-B46DD880DDC9}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-buttonutil.exe, In Quarantäne, [a7d8bbdaf298d75fe3000b65fa0b36ca]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CED94FA4-9202-473E-B23E-78A6B1E42F3C}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-buttonutil.exe, In Quarantäne, [93ec70258dfd5adc6e751b551fe622de]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D4EAECEB-64F2-46F5-B97E-E317DA942D27}|AppName, d187d13c-eb9d-4d47-bf31-4a5c3088774b-2.exe-buttonutil.exe, In Quarantäne, [58274451aedc43f3984b066a3fc67789]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D709A9FB-831C-4F4F-8FD6-55F4BDCEE2A8}|AppName, d187d13c-eb9d-4d47-bf31-4a5c3088774b-2.exe-codedownloader.exe, In Quarantäne, [d1ae02934347f73fa143ed8363a202fe]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{e3dd5db5-e7f9-4b46-91fd-572705c45a45}|AppName, CinemaP-1.9cV02.01-codedownloader.exe, In Quarantäne, [2956badb4b3fd4624a9a145ce52042be]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E7EA9BE5-284E-4590-8F8C-DC1BFE3F3654}|AppName, d187d13c-eb9d-4d47-bf31-4a5c3088774b-2.exe-buttonutil.exe, In Quarantäne, [a8d70d8829613006a53e145ccf36f50b]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{eb2268eb-6d29-4703-9ad5-42f79acd492c}|AppName, TheHDvid-Codec V10-codedownloader.exe, In Quarantäne, [d8a70491632750e6459f0d63e322af51]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EDD0611F-7E6A-493C-9184-6CF4B3E6CEEB}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-codedownloader.exe, In Quarantäne, [09769cf92961d066855f78f83acb40c0]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F291F329-3FE6-4E37-AA38-4EB2EFE8ED19}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-buttonutil.exe, In Quarantäne, [8df20c8998f2c27419ca87e994712ad6]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F493A178-DCE8-46CD-8674-BE57D4AD1E6E}|AppName, b40dd6cd-32c8-47b3-8b1a-f50c2f0f4068-2.exe-buttonutil.exe, In Quarantäne, [e49b9df8c9c14cea9a49a0d038cdf907]
PUP.Optional.CrossRider.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ffe033ae-ca5d-4d00-93b6-ef267af8e9b7}|AppName, CinemaP-1.9cV02.01-bg.exe, In Quarantäne, [5f209cf9f39781b5dc06b3bda85de41c]
PUP.Optional.Dregol.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, hxxp://www.dregol.com/results.php?f=4&q={searchTerms}&a=drg_ggbg_15_15&cd=2XzuyEtN2Y1L1Qzu0Fzz0AzyyCtA0EyByCtByD0CyC0C0BzztN0D0Tzu0StCtCzyyEtN1L2XzutAtFzytFzztFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0DyB0EyEzytAyCtGyE0D0EyBtGyDtAyD0EtG0EtD0DyEtGtCyC0FtAzzyE0C0DtB0ByE0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0F0AtCtA0FyD0FtG0ByBtC0EtGyEyDtByCtG0B0EzyyBtG0B0DyBzytB0E0C0CtBzzzzzy2QtN0A0LzuyE&cr=1691039868&ir=, In Quarantäne, [384795008a0026107e4196d3c540718f]
PUP.Optional.Dregol.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback, hxxp://www.dregol.com/results.php?f=4&q={searchTerms}&a=drg_ggbg_15_15&cd=2XzuyEtN2Y1L1Qzu0Fzz0AzyyCtA0EyByCtByD0CyC0C0BzztN0D0Tzu0StCtCzyyEtN1L2XzutAtFzytFzztFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0DyB0EyEzytAyCtGyE0D0EyBtGyDtAyD0EtG0EtD0DyEtGtCyC0FtAzzyE0C0DtB0ByE0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0F0AtCtA0FyD0FtG0ByBtC0EtGyEyDtByCtG0B0EzyyBtG0B0DyBzytB0E0C0CtBzzzzzy2QtN0A0LzuyE&cr=1691039868&ir=, In Quarantäne, [641bcec735551620a11ecc9daa5b768a]
PUP.Optional.Dregol.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|FaviconPath, C:\Users\Daniel\AppData\LocalLow\Microsoft\Internet Explorer\Services\Run_Dregol.ico, In Quarantäne, [502f6035c8c25cda0db2e683d4317a86]
PUP.Optional.Dregol.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, Dregol, In Quarantäne, [c0bf3d58c3c7fd398a357eebb84df808]
PUP.Optional.Dregol.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|DisplayName, Dregol, In Quarantäne, [5827811494f61125dee1c5a4bf466b95]
Registrierungsdaten: 1
PUP.Optional.Dregol.A, HKU\S-1-5-21-223822767-1807346583-171944255-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.dregol.com/?f=1&a=drg_ggbg_15_15&cd=2XzuyEtN2Y1L1Qzu0Fzz0AzyyCtA0EyByCtByD0CyC0C0BzztN0D0Tzu0StCtCzyyEtN1L2XzutAtFzytFzztFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0DyB0EyEzytAyCtGyE0D0EyBtGyDtAyD0EtG0EtD0DyEtGtCyC0FtAzzyE0C0DtB0ByE0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0F0AtCtA0FyD0FtG0ByBtC0EtGyEyDtByCtG0B0EzyyBtG0B0DyBzytB0E0C0CtBzzzzzy2QtN0A0LzuyE&cr=1691039868&ir=, Gut: (www.google.com), Schlecht: (hxxp://www.dregol.com/?f=1&a=drg_ggbg_15_15&cd=2XzuyEtN2Y1L1Qzu0Fzz0AzyyCtA0EyByCtByD0CyC0C0BzztN0D0Tzu0StCtCzyyEtN1L2XzutAtFzytFzztFtBtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyE0DyB0EyEzytAyCtGyE0D0EyBtGyDtAyD0EtG0EtD0DyEtGtCyC0FtAzzyE0C0DtB0ByE0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0F0AtCtA0FyD0FtG0ByBtC0EtGyEyDtByCtG0B0EzyyBtG0B0DyBzytB0E0C0CtBzzzzzy2QtN0A0LzuyE&cr=1691039868&ir=),Ersetzt,[453a7f162d5dd95d3c7a21f450b6fe02]
Ordner: 3
PUP.Optional.UniSales.A, C:\Program Files (x86)\Unisales, In Quarantäne, [d6a973224a40181efe355180f211d12f],
PUP.Optional.Dregol.A, C:\Users\Daniel\AppData\Roaming\Run_dregol, In Quarantäne, [eb94dcb9e2a8072f9e14508363a016ea],
PUP.Optional.Dregol.A, C:\Users\Daniel\AppData\Roaming\Run_dregol\UpdateProc, In Quarantäne, [eb94dcb9e2a8072f9e14508363a016ea],
Dateien: 10
PUP.Optional.Mindspark, C:\Users\Daniel\Downloads\InternetSpeedTrackerSetup2.5.15.8.pd^BBQ^xdm181^YYA^de.downspeedtest.exe, In Quarantäne, [ceb19ef74446cf677c6974905bab9f61],
PUP.Optional.Dregol.C, C:\Users\Daniel\AppData\LocalLow\Microsoft\Internet Explorer\Services\Run_Dregol.ico, In Quarantäne, [8ef14e47a1e9fe38715b09cf53b0fb05],
PUP.Optional.Dregol.A, C:\Windows\System32\Tasks\Run_dregol, In Quarantäne, [6817583d7d0d3105f9c7d20bd3307888],
PUP.Optional.Dregol.A, C:\Windows\Tasks\Run_dregol.job, In Quarantäne, [6a152f66bad0dd59f3ce3f9ee51efd03],
PUP.Optional.Dregol.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\8f6jup2q.default\searchplugins\dregol.xml, In Quarantäne, [4a351e77abdf4aec685a02db28db9f61],
PUP.Optional.HDNotifier.A, C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\8f6jup2q.default\extensions\{0e84d0b4-5388-4a04-a2bf-1043c386a4dc}.xpi, In Quarantäne, [dfa0b4e14b3f6ec8678ef97818ed06fa],
PUP.Optional.UniSales.A, C:\Program Files (x86)\Unisales\JBGgrV4x87VoTw.dat, In Quarantäne, [d6a973224a40181efe355180f211d12f],
PUP.Optional.UniSales.A, C:\Program Files (x86)\Unisales\JBGgrV4x87VoTw.tlb, In Quarantäne, [d6a973224a40181efe355180f211d12f],
PUP.Optional.Dregol.A, C:\Users\Daniel\AppData\Roaming\Run_dregol\UpdateProc\config.dat, In Quarantäne, [eb94dcb9e2a8072f9e14508363a016ea],
PUP.Optional.Dregol.A, C:\Users\Daniel\AppData\Roaming\Run_dregol\UpdateProc\info.dat, In Quarantäne, [eb94dcb9e2a8072f9e14508363a016ea],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) ADW:
AdwCleaner Logfile: Code:
# AdwCleaner v4.204 - Bericht erstellt 19/05/2015 um 17:49:46
# Aktualisiert 12/05/2015 von Xplode
# Datenbank : 2015-05-12.2 [Server]
# Betriebssystem : Windows 8.1 (x64)
# Benutzername : Daniel - 1906DANIEL
# Gestarted von : C:\Users\Daniel\Downloads\AdwCleaner_4.204.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\supermegabest
Ordner Gelöscht : C:\Program Files (x86)\unisAlEEs
Ordner Gelöscht : C:\Program Files (x86)\uonaisaeles
Ordner Gelöscht : C:\Program Files (x86)\YouettubeAAdBillocke
Ordner Gelöscht : C:\Windows\SysWOW64\config\systemprofile\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\pokki
Ordner Gelöscht : C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\8f6jup2q.default\Extensions\yasearch@yandex.ru
Ordner Gelöscht : C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\8f6jup2q.default\Extensions\vb@yandex.ru
Ordner Gelöscht : C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcdeaofcapijfmeopimkgcepdpbdepnb
Ordner Gelöscht : C:\Users\Daniel\AppData\Roaming\Opera Software\Opera Stable\Extensions\aonedlchkbicmhepimiahfalheedjgbh
Datei Gelöscht : C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [jid1-n5ARdBzHkUEdAA@jetpack]
Wert Gelöscht : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [jid1-n5ARdBzHkUEdAA@jetpack]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\aonedlchkbicmhepimiahfalheedjgbh
Schlüssel Gelöscht : HKLM\SOFTWARE\a5cafea9-581a-a155-bbed-37a765c285d3
Schlüssel Gelöscht : HKLM\SOFTWARE\d2942acc-2821-4fbd-8484-eb07a8c3ce09
Schlüssel Gelöscht : HKLM\SOFTWARE\e96055be-6a8b-4f6f-8d35-36c272e291db
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{1D37BD00-E9FD-40D1-80E7-1795E510ECAA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\SOFTWARE\SPPDCOM
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v38.0.1 (x86 de)
[8f6jup2q.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.vb@yandex.ru.alienAddonRecords", "{\"chrome://unitedtb/content/newtab/newtab-page.xhtml\":10}");
[8f6jup2q.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.vb@yandex.ru.browser.alien.newtab.url", "chrome://unitedtb/content/newtab/newtab-page.xhtml");
[8f6jup2q.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.vb@yandex.ru.description", "Keep all your favorite sites in one place with Visual Bookmarks. Simply click on the one of the mini webpages to visit a site. You can customize the n[...]
-\\ Google Chrome v
-\\ Chromium v
-\\ Opera v0.0.0.0
[C:\Users\Daniel\AppData\Roaming\Opera Software\Opera Stable\Preferences] - Gelöscht [Extension] : aonedlchkbicmhepimiahfalheedjgbh
*************************
AdwCleaner[R0].txt - [14014 Bytes] - [08/01/2015 13:56:14]
AdwCleaner[R1].txt - [917 Bytes] - [08/01/2015 15:41:06]
AdwCleaner[R2].txt - [3508 Bytes] - [19/05/2015 17:47:30]
AdwCleaner[S0].txt - [13922 Bytes] - [08/01/2015 13:57:27]
AdwCleaner[S1].txt - [977 Bytes] - [08/01/2015 15:42:44]
AdwCleaner[S2].txt - [3405 Bytes] - [19/05/2015 17:49:46]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [3464 Bytes] ########## --- --- ---
JRT: HTML-Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.7.4 (05.19.2015:1)
OS: Windows 8.1 x64
Ran by Daniel on 19.05.2015 at 17:57:07,87
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
Successfully deleted: [Task] C:\Windows\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-223822767-1807346583-171944255-1002
Successfully deleted: [Task] C:\Windows\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-223822767-1807346583-171944255-500
Successfully deleted: [Task] C:\Windows\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-3530894810-3726368839-2921617375-500
Successfully deleted: [Task] C:\Windows\system32\tasks\Optimize Start Menu Cache Files-S-1-5-21-729939966-155158532-1426229192-500
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] C:\Program Files (x86)\OptuOn
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 19.05.2015 at 17:58:46,94
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Frst folgt
und hier die FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-05-2015 02
Ran by Daniel (administrator) on 1906DANIEL on 19-05-2015 18:09:44
Running from C:\Users\Daniel\Desktop\Bereinigung
Loaded Profiles: Daniel (Available profiles: UpdatusUser & Daniel)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(TODO: <Company name>) C:\Program Files\Acer\User Experience Improvement Program\Plugin\AppMonitor\AppMonitorPlugIn.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20856_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672304 2014-03-18] (Realtek Semiconductor)
HKLM-x32\...\Run: [BacKGround Agent] => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [66304 2015-05-06] (Acer Incorporated)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [843480 2014-10-08] (BlueStack Systems, Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [728312 2015-05-07] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [129272 2015-03-16] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [abDocsDllLoader] => C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe [92928 2015-05-06] ()
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [134784 2014-02-25] (Atheros Communications)
HKU\S-1-5-21-223822767-1807346583-171944255-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [2888384 2015-05-15] (Valve Corporation)
HKU\S-1-5-21-223822767-1807346583-171944255-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8204056 2015-04-23] (Piriform Ltd)
HKU\S-1-5-21-223822767-1807346583-171944255-1002\...\MountPoints2: {5aa5bc4b-ac8b-11e4-8279-f8a963e7625c} - "E:\AutoRun.exe"
HKU\S-1-5-21-223822767-1807346583-171944255-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [133632 2014-10-29] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ ACloudSynced] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-223822767-1807346583-171944255-1002 -> {0F4290CD-0C1F-43D0-AD78-654E5ADC2694} URL =
SearchScopes: HKU\S-1-5-21-223822767-1807346583-171944255-1002 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-03-10] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2015-04-09] (Oracle Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-04-14] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2015-04-09] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-02-16] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-16] (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\8f6jup2q.default
FF NewTab: yafd:tabs
FF SelectedSearchEngine: Google
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-14] ()
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-04-09] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2015-04-09] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-05-14] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-05-14] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-12-10] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-10] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-16] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-16] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-01-15] (Microsoft Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2014-12-24] ()
FF Extension: OptuOn - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\8f6jup2q.default\Extensions\4@ckIbAWyX.com [2014-12-26]
FF Extension: Avira Browser Safety - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\8f6jup2q.default\Extensions\abs@avira.com [2015-05-06]
FF Extension: {2b5f4e51-080e-409c-8353-01cc79790137} - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\8f6jup2q.default\Extensions\{2b5f4e51-080e-409c-8353-01cc79790137}.xpi [2015-01-01]
Chrome:
=======
CHR Profile: C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbacbcfdfaapbcnlnbmciiaakomhkbkb [2015-01-06]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ocbnpbkmjpgbdcgiflkgkpnkinifpgpj] - C:\Users\Daniel\ChromeExtensions\ocbnpbkmjpgbdcgiflkgkpnkinifpgpj\amazon-icon-2.crx [2015-03-11]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [827640 2015-05-07] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [434424 2015-05-07] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [434424 2015-05-07] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1185584 2015-05-07] (Avira Operations GmbH & Co. KG)
S2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [319104 2014-02-25] (Windows (R) Win 7 DDK provider) [File not signed]
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [201008 2015-03-16] (Avira Operations GmbH & Co. KG)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [409304 2014-10-08] (BlueStack Systems, Inc.)
S2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [388824 2014-10-08] (BlueStack Systems, Inc.)
S2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [782040 2014-10-08] (BlueStack Systems, Inc.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
S2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2839296 2015-05-06] (Acer Incorporated)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2736824 2015-04-07] (Microsoft Corporation)
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1429504 2015-03-05] (Microsoft Corporation)
S3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573032 2014-06-12] (Acer Incorporated)
S2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-18] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-10] (Intel Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [466664 2014-06-10] (Acer Incorporate)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S2 Mobile Broadband HL Service; C:\ProgramData\MobileBrServ\mbbservice.exe [239184 2014-02-15] ()
S3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [458984 2014-06-26] (Acer Incorporate)
S2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-24] ()
S3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [449768 2014-06-26] (Acer Incorporate)
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [234240 2014-07-15] (acer)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 A2DDA; C:\EEK\bin\a2ddax64.sys [26176 2015-05-17] (Emsisoft GmbH)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3888640 2014-02-14] (Qualcomm Atheros Communications, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [152744 2015-05-07] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132120 2015-05-07] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-11-24] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [43576 2015-03-04] (Avira Operations GmbH & Co. KG)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [122072 2014-10-08] (BlueStack Systems)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2014-02-25] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
S3 cleanhlp; C:\EEK\bin\cleanhlp64.sys [57024 2015-05-17] (Emsisoft GmbH)
R3 iaLPSS_I2C; C:\Windows\System32\drivers\iaLPSS_I2C.sys [99320 2013-10-03] (Intel Corporation)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-19] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [466136 2014-01-14] (Realsil Semiconductor Corporation)
R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [42224 2014-02-19] (Synaptics Incorporated)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-19 18:05 - 2015-05-19 18:05 - 00030350 _____ () C:\Users\Daniel\Desktop\MB 1.txt
2015-05-19 17:58 - 2015-05-19 17:59 - 00001187 _____ () C:\Users\Daniel\Desktop\JRT.txt
2015-05-19 17:57 - 2015-05-19 17:57 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-1906DANIEL-Windows-8.1-(64-bit).dat
2015-05-19 17:57 - 2015-05-19 17:57 - 00000000 ____D () C:\RegBackup
2015-05-19 17:55 - 2015-05-19 17:55 - 02720196 _____ (Thisisu) C:\Users\Daniel\Downloads\JRT.exe
2015-05-19 17:46 - 2015-05-19 17:46 - 02209792 _____ () C:\Users\Daniel\Downloads\AdwCleaner_4.204.exe
2015-05-19 17:46 - 2015-05-19 17:46 - 00030350 _____ () C:\MB 2.txt
2015-05-19 17:45 - 2015-05-19 17:45 - 00000844 _____ () C:\MB 1.txt
2015-05-19 17:43 - 2015-05-19 17:49 - 00000000 ____D () C:\Users\TEMP
2015-05-19 17:40 - 2015-05-19 17:51 - 00004264 _____ () C:\Windows\PFRO.log
2015-05-19 17:40 - 2015-05-19 17:51 - 00000232 _____ () C:\Windows\setupact.log
2015-05-19 17:40 - 2015-05-19 17:40 - 00000000 _____ () C:\Windows\setuperr.log
2015-05-19 16:26 - 2015-05-19 16:26 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Daniel\Downloads\mbam-setup-2.1.6.1022.exe
2015-05-18 22:01 - 2015-05-18 22:01 - 05623645 _____ (Swearware) C:\Users\Daniel\Downloads\ComboFix(1).exe
2015-05-18 21:51 - 2015-05-18 21:51 - 05623645 _____ (Swearware) C:\Users\Daniel\Downloads\ComboFix.exe
2015-05-18 12:43 - 2015-05-18 13:05 - 1456501248 _____ () C:\Users\Daniel\Desktop\EuroTruckSimulator2_1_17_1_patch.exe
2015-05-18 11:01 - 2015-05-18 11:03 - 00048799 _____ () C:\Users\Daniel\Downloads\Addition.txt
2015-05-18 10:59 - 2015-05-18 11:03 - 00043486 _____ () C:\Users\Daniel\Downloads\FRST.txt
2015-05-18 10:58 - 2015-05-18 10:58 - 02107392 _____ (Farbar) C:\Users\Daniel\Downloads\FRST64.exe
2015-05-17 18:24 - 2015-05-17 18:24 - 00000898 _____ () C:\EamClean.log
2015-05-17 15:31 - 2015-05-17 15:31 - 00000759 _____ () C:\Users\Daniel\Desktop\Start Emsisoft Emergency Kit.lnk
2015-05-17 15:30 - 2015-05-17 18:30 - 00000000 ____D () C:\EEK
2015-05-17 15:28 - 2015-05-17 15:30 - 154414048 _____ () C:\Users\Daniel\Downloads\EmsisoftEmergencyKit.exe
2015-05-16 21:51 - 2015-05-16 21:51 - 00325440 _____ () C:\Users\Daniel\Downloads\BullGuardDownloader_uksem60.exe
2015-05-16 18:29 - 2015-05-16 18:29 - 00000000 _____ () C:\autoexec.bat
2015-05-16 18:27 - 2015-05-16 18:27 - 03109248 _____ (Enigma Software Group USA, LLC.) C:\Users\Daniel\Downloads\SpyHunter-Installer.exe
2015-05-16 18:19 - 2015-05-16 18:19 - 00001163 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-05-16 18:19 - 2015-05-16 18:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-16 18:19 - 2015-05-16 18:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-05-15 15:47 - 2015-04-24 23:32 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-05-15 15:47 - 2015-04-10 02:34 - 02256896 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-05-15 15:47 - 2015-04-10 02:11 - 01943040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-05-15 15:47 - 2015-04-03 02:35 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\PhotoMetadataHandler.dll
2015-05-15 15:47 - 2015-04-03 02:14 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhotoMetadataHandler.dll
2015-05-15 15:47 - 2015-04-02 00:22 - 02985984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2015-05-15 15:47 - 2015-04-02 00:20 - 04417536 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2015-05-15 15:47 - 2015-04-01 05:45 - 01491456 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll
2015-05-15 15:47 - 2015-04-01 04:31 - 01207296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbghelp.dll
2015-05-15 15:47 - 2015-03-20 03:56 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ahcache.sys
2015-05-15 15:47 - 2015-03-17 19:26 - 00467776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2015-05-15 15:47 - 2015-03-13 06:03 - 00239424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2015-05-15 15:47 - 2015-03-13 06:03 - 00154432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2015-05-15 15:47 - 2015-03-13 04:02 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2015-05-15 15:47 - 2015-03-13 03:11 - 02162176 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2015-05-15 15:47 - 2015-03-13 02:39 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRH.dll
2015-05-15 15:47 - 2015-03-13 02:29 - 00410017 _____ () C:\Windows\system32\ApnDatabase.xml
2015-05-15 15:47 - 2015-03-11 03:49 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-15 15:47 - 2015-03-11 03:09 - 00021504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdbinst.exe
2015-05-15 15:47 - 2015-03-09 04:02 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthhfenum.sys
2015-05-15 15:47 - 2015-03-06 05:08 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-05-15 15:47 - 2015-03-06 04:47 - 01696256 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2015-05-15 15:47 - 2015-03-06 04:43 - 01969664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll
2015-05-15 15:47 - 2015-03-05 01:09 - 01429504 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-05-15 15:47 - 2015-03-04 03:32 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Input.Inking.dll
2015-05-15 15:47 - 2015-03-04 03:12 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll
2015-05-15 15:47 - 2015-02-18 01:19 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll
2015-05-15 15:47 - 2015-01-30 02:53 - 02819584 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers.dll
2015-05-15 15:47 - 2014-11-14 08:58 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsDatabase.dll
2015-05-13 20:49 - 2015-05-13 20:49 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-05-13 20:49 - 2015-05-13 20:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-05-13 20:49 - 2015-05-13 20:49 - 00000000 ____D () C:\Program Files\WinRAR
2015-05-13 20:48 - 2015-05-13 20:48 - 02058768 _____ () C:\Users\Daniel\Desktop\winrar-x64-521d.exe
2015-05-13 20:43 - 2015-05-16 18:19 - 00001077 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-05-13 19:54 - 2015-05-16 10:31 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\Yandex
2015-05-13 19:54 - 2015-05-13 19:54 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Chromium
2015-05-13 19:53 - 2015-05-13 20:16 - 00000000 ____D () C:\Program Files (x86)\Hamster Soft
2015-05-13 19:53 - 2015-05-13 19:55 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\HamsterSoft
2015-05-13 15:59 - 2015-05-13 15:59 - 09358488 _____ () C:\Users\Daniel\Downloads\Sphax PureBDCraft 64x MC14.zip
2015-05-13 13:18 - 2015-05-13 13:18 - 00002001 _____ () C:\Users\Public\Desktop\abMedia.lnk
2015-05-13 13:15 - 2015-05-13 13:15 - 00002005 _____ () C:\Users\Public\Desktop\abPhoto.lnk
2015-05-13 13:09 - 2015-04-30 22:35 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 13:09 - 2015-04-30 22:35 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-13 13:03 - 2015-05-01 01:05 - 00429568 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-13 13:03 - 2015-05-01 00:48 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-05-13 13:03 - 2015-04-21 19:14 - 24971776 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-13 13:03 - 2015-04-14 00:48 - 04180480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-13 13:03 - 2015-04-10 03:00 - 01996800 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-13 13:03 - 2015-04-10 02:50 - 01387008 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-13 13:03 - 2015-04-10 02:26 - 01560576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-05-13 13:03 - 2015-04-09 00:55 - 00410128 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-13 13:02 - 2015-04-21 18:50 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-13 13:02 - 2015-04-21 18:50 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-13 13:02 - 2015-04-21 18:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-13 13:02 - 2015-04-21 18:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-13 13:02 - 2015-04-21 18:35 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-13 13:02 - 2015-04-21 18:31 - 06025728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-13 13:02 - 2015-04-21 18:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-05-13 13:02 - 2015-04-21 18:13 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-05-13 13:02 - 2015-04-21 18:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-05-13 13:02 - 2015-04-21 18:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-05-13 13:02 - 2015-04-21 18:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-13 13:02 - 2015-04-21 18:07 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-05-13 13:02 - 2015-04-21 18:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-13 13:02 - 2015-04-21 18:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-05-13 13:02 - 2015-04-21 17:59 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-05-13 13:02 - 2015-04-21 17:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-05-13 13:02 - 2015-04-21 17:52 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-05-13 13:02 - 2015-04-21 17:49 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-13 13:02 - 2015-04-21 17:49 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-13 13:02 - 2015-04-21 17:49 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-13 13:02 - 2015-04-21 17:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-13 13:02 - 2015-04-21 17:40 - 14401536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-13 13:02 - 2015-04-21 17:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-05-13 13:02 - 2015-04-21 17:37 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-05-13 13:02 - 2015-04-21 17:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-05-13 13:02 - 2015-04-21 17:32 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-05-13 13:02 - 2015-04-21 17:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-05-13 13:02 - 2015-04-21 17:28 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-05-13 13:02 - 2015-04-21 17:27 - 02352128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-13 13:02 - 2015-04-21 17:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-05-13 13:02 - 2015-04-21 17:26 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-05-13 13:02 - 2015-04-21 17:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-05-13 13:02 - 2015-04-21 17:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-05-13 13:02 - 2015-04-21 17:15 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-13 13:02 - 2015-04-21 17:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-13 13:02 - 2015-04-21 17:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-05-13 13:02 - 2015-04-21 16:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-05-13 13:02 - 2015-04-21 16:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-05-13 13:02 - 2015-03-30 07:47 - 00561928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-05-13 13:02 - 2015-03-27 05:27 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-13 13:02 - 2015-03-27 04:50 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2015-05-13 13:02 - 2015-03-27 04:48 - 01441792 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-12 11:55 - 2015-05-12 11:55 - 00003334 _____ () C:\Windows\System32\Tasks\AcerCloud
2015-05-12 11:54 - 2015-05-12 11:55 - 00002030 _____ () C:\Users\Public\Desktop\Acer Portal.lnk
2015-05-12 11:53 - 2015-05-12 11:53 - 00001969 _____ () C:\Users\Public\Desktop\abDocs.lnk
2015-05-10 18:53 - 2015-05-17 19:49 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\.minecraft
2015-05-10 18:52 - 2015-05-10 18:52 - 00000000 ____D () C:\Users\Daniel\Downloads\Neuer Ordner
2015-05-07 11:33 - 2015-05-07 11:34 - 00192736 _____ () C:\Users\Daniel\Downloads\FRITZ.Box Fon WLAN 7360 124.06.20_07.05.15_1133(1).export
2015-05-07 11:33 - 2015-05-07 11:33 - 00192736 _____ () C:\Users\Daniel\Downloads\FRITZ.Box Fon WLAN 7360 124.06.20_07.05.15_1133.export
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-19 18:09 - 2015-01-08 14:01 - 00000000 ____D () C:\Users\Daniel\Desktop\Bereinigung
2015-05-19 18:09 - 2015-01-07 20:41 - 00000000 ____D () C:\FRST
2015-05-19 18:07 - 2014-12-25 21:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-19 18:05 - 2015-01-06 11:23 - 01387374 _____ () C:\Windows\WindowsUpdate.log
2015-05-19 18:04 - 2015-01-08 14:05 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-19 18:02 - 2014-12-24 20:27 - 00000000 ____D () C:\Users\Daniel\OneDrive
2015-05-19 18:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2015-05-19 17:53 - 2014-12-25 00:49 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-05-19 17:51 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-19 17:50 - 2015-01-08 13:56 - 00000000 ____D () C:\AdwCleaner
2015-05-19 17:47 - 2014-12-24 20:38 - 00003942 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{61AB47E5-AB5A-4D8B-89BB-14B1822A6C56}
2015-05-19 16:26 - 2015-01-08 14:05 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-19 16:26 - 2015-01-08 14:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-19 16:26 - 2015-01-08 14:05 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-05-19 16:05 - 2014-12-27 21:25 - 00000000 ____D () C:\Users\Daniel\Documents\Euro Truck Simulator 2
2015-05-19 16:03 - 2015-01-12 17:23 - 00223232 ___SH () C:\Users\Daniel\Desktop\Thumbs.db
2015-05-19 11:08 - 2014-08-31 01:14 - 00765582 _____ () C:\Windows\system32\perfh007.dat
2015-05-19 11:08 - 2014-08-31 01:14 - 00159366 _____ () C:\Windows\system32\perfc007.dat
2015-05-19 11:08 - 2014-03-18 12:03 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-19 09:57 - 2015-01-15 17:17 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2015-05-18 22:06 - 2014-12-24 20:28 - 00000000 ____D () C:\Users\Daniel\AppData\Local\CrashDumps
2015-05-18 22:06 - 2014-12-24 20:10 - 00000000 ____D () C:\Users\Daniel
2015-05-18 13:07 - 2014-12-27 21:22 - 00000000 ____D () C:\Program Files (x86)\Euro Truck Simulator 2
2015-05-17 18:24 - 2013-08-22 16:44 - 00495952 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-17 18:23 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-05-16 22:10 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp
2015-05-16 22:09 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ImmersiveControlPanel
2015-05-16 15:27 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache
2015-05-15 16:51 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-05-13 20:11 - 2015-02-15 21:53 - 00000000 ____D () C:\Program Files (x86)\WinRAR
2015-05-13 19:57 - 2015-01-02 14:59 - 00000000 ____D () C:\Users\Daniel\Desktop\.minecraft
2015-05-13 13:18 - 2014-07-25 23:21 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2015-05-13 13:18 - 2014-07-25 23:20 - 00000000 ____D () C:\Program Files (x86)\Acer
2015-05-13 13:16 - 2014-12-24 20:26 - 00000000 ____D () C:\Users\Daniel\AppData\Local\clear.fi
2015-05-13 13:09 - 2013-08-22 15:36 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-05-13 13:07 - 2014-03-18 11:45 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-12 19:00 - 2014-12-24 20:13 - 00000000 ____D () C:\Users\Daniel\AppData\Local\AOP SDK
2015-05-12 11:52 - 2014-07-25 23:57 - 00000000 ___HD () C:\OEM
2015-05-09 21:23 - 2014-12-24 20:11 - 00000000 ____D () C:\Users\Daniel\AppData\Local\Packages
2015-05-09 10:40 - 2015-04-15 14:41 - 00000000 ____D () C:\Windows\Minidump
2015-05-07 11:49 - 2014-12-24 21:29 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-07 11:46 - 2014-12-24 21:29 - 128913832 ____N (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-05-07 09:39 - 2015-01-06 23:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-05-07 09:38 - 2015-01-06 23:52 - 00152744 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-05-07 09:38 - 2015-01-06 23:52 - 00132120 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-05-06 15:32 - 2015-01-02 15:25 - 00000000 ____D () C:\Users\Daniel\Desktop\minecraft Test
2015-05-06 15:31 - 2015-04-09 15:09 - 06596606 _____ () C:\Users\Daniel\Downloads\FTB_Launcher.jar
2015-05-06 15:31 - 2015-01-02 16:05 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\ftblauncher
2015-05-06 15:31 - 2015-01-02 16:05 - 00000000 ____D () C:\Users\Daniel\AppData\Local\ftblauncher
2015-05-06 14:46 - 2014-12-25 01:48 - 00000838 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-05-06 14:46 - 2014-12-25 01:48 - 00000000 ____D () C:\Program Files\CCleaner
2015-05-05 19:59 - 2014-12-24 22:40 - 00792568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-05-05 19:59 - 2014-12-24 22:40 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-29 17:43 - 2014-07-25 23:22 - 00000000 ____D () C:\ProgramData\CyberLink
2015-04-25 19:48 - 2015-01-30 16:29 - 00000000 ____D () C:\Users\Daniel\AppData\Roaming\.technic
2015-04-25 19:48 - 2015-01-30 16:28 - 04697768 _____ () C:\Users\Daniel\Desktop\TechnicLauncher.exe
2015-04-19 14:30 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppCompat
==================== Files in the root of some directories =======
2014-08-30 16:11 - 2014-08-30 16:11 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some content of TEMP:
====================
C:\Users\Daniel\AppData\Local\Temp\avgnt.exe
C:\Users\Daniel\AppData\Local\Temp\Quarantine.exe
C:\Users\Daniel\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-05 18:29
==================== End Of Log ============================ --- --- ---
--- --- --- |