Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 18.05.2014
Suchlauf-Zeit: 15:01:46
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.05.18.03
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: mochenmo1
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 253688
Verstrichene Zeit: 6 Min, 14 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 4
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 1432, Löschen bei Neustart, [3ba09ab885f6fd39c93e2432af528d73]
PUP.Optional.WpManager, C:\ProgramData\WPM\wprotectmanager.exe, 1564, Löschen bei Neustart, [17c43f13d6a53501a5bebea20cf5b64a]
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\updatewebget.exe, 1844, Löschen bei Neustart, [8d4e163c29523600e1e48ceb2bd6ca36]
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\bin\utilwebget.exe, 2108, Löschen bei Neustart, [a437aea4ef8cb18518ad85f28f72817f]
Module: 4
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, Löschen bei Neustart, [2fac5bf7b7c44aecf259d85d41bffe02],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, Löschen bei Neustart, [2fac5bf7b7c44aecf259d85d41bffe02],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\webgetBHO.dll, Löschen bei Neustart, [fdde2c265c1ff046388cc6b159a860a0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [4b90fe541b60ab8b3cca8119f0120ff1],
Registrierungsschlüssel: 28
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, In Quarantäne, [3ba09ab885f6fd39c93e2432af528d73],
PUP.Optional.WpManager, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Wpm, In Quarantäne, [17c43f13d6a53501a5bebea20cf5b64a],
PUP.Optional.WpManager, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WPM, In Quarantäne, [17c43f13d6a53501a5bebea20cf5b64a],
PUP.Optional.Webget.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update webget, In Quarantäne, [8d4e163c29523600e1e48ceb2bd6ca36],
PUP.Optional.Webget.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util webget, In Quarantäne, [a437aea4ef8cb18518ad85f28f72817f],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [2fac5bf7b7c44aecf259d85d41bffe02],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [2fac5bf7b7c44aecf259d85d41bffe02],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [2fac5bf7b7c44aecf259d85d41bffe02],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [2fac5bf7b7c44aecf259d85d41bffe02],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [2fac5bf7b7c44aecf259d85d41bffe02],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [2fac5bf7b7c44aecf259d85d41bffe02],
PUP.Optional.SupTab.A, HKU\S-1-5-21-2435969490-785047729-4073554876-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Löschen bei Neustart, [2fac5bf7b7c44aecf259d85d41bffe02],
PUP.Optional.SupTab.A, HKU\S-1-5-21-2435969490-785047729-4073554876-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Löschen bei Neustart, [2fac5bf7b7c44aecf259d85d41bffe02],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [2fac5bf7b7c44aecf259d85d41bffe02],
PUP.Optional.Webget.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{0A4AA078-E14F-4459-901A-D5F6ACB22DD6}, In Quarantäne, [fdde2c265c1ff046388cc6b159a860a0],
PUP.Optional.Webget.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F88A773B-C7D6-4097-AD99-144D59C291E1}, In Quarantäne, [fdde2c265c1ff046388cc6b159a860a0],
PUP.Optional.Webget.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F88A773B-C7D6-4097-AD99-144D59C291E1}, In Quarantäne, [fdde2c265c1ff046388cc6b159a860a0],
PUP.Optional.Webget.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{0A4AA078-E14F-4459-901A-D5F6ACB22DD6}, In Quarantäne, [fdde2c265c1ff046388cc6b159a860a0],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [4497054de4972f070bbb1648fc068779],
PUP.Optional.Webget.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\webget, In Quarantäne, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [a338b1a15f1c9e983fd5b50aed168977],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [9843430fd9a241f5ee1db31558ab10f0],
PUP.Optional.Webget.A, HKLM\SOFTWARE\WOW6432NODE\webget, In Quarantäne, [db002d25d9a26ccaa4ebf98e5fa3ec14],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [23b8c9897a015dd9b65e8a35b84b60a0],
PUP.Optional.Webget.A, HKU\S-1-5-21-2435969490-785047729-4073554876-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\webget, Löschen bei Neustart, [8358b79b84f7e4520a84d4b3ff03b24e],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2435969490-785047729-4073554876-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Löschen bei Neustart, [b328cf839cdf92a460e4b3eaab57fd03],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2435969490-785047729-4073554876-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Löschen bei Neustart, [37a473df4338092de06f51624ab9b64a],
PUP.Optional.Qone8, HKU\S-1-5-21-2435969490-785047729-4073554876-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Löschen bei Neustart, [6774341e8dee64d2040f605f669d06fa],
Registrierungswerte: 4
Spyware.Zbot.VXGen, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN|36467805, C:\PROGRA~3\msriv.exe, In Quarantäne, [578492c01f5c6dc9a293f376de23b34d]
Spyware.Zbot.VXGen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN|36467805, C:\PROGRA~3\msriv.exe, In Quarantäne, [578492c01f5c6dc9a293f376de23b34d]
PUP.Optional.WpManager.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WPM|ImagePath, C:\ProgramData\WPM\wprotectmanager.exe -service, In Quarantäne, [8a51064c0e6da88eaf42fec529dadb25]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2435969490-785047729-4073554876-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0V1D1S1R1D0V1O, Löschen bei Neustart, [37a473df4338092de06f51624ab9b64a]
Registrierungsdaten: 11
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SupTab\SEARCH~1.DLL, Gut: (), Schlecht: (C:\PROGRA~2\SupTab\SEARCH~1.DLL),Ersetzt,[4b90fe541b60ab8b3cca8119f0120ff1]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SupTab\SEARCH~2.DLL, Gut: (), Schlecht: (C:\PROGRA~2\SupTab\SEARCH~2.DLL),Ersetzt,[4b90fe541b60ab8b3cca8119f0120ff1]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1400298711&from=cor&uid=INTELXSSDSA2BW120G3A_CVPR1261026R120LGN&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1400298711&from=cor&uid=INTELXSSDSA2BW120G3A_CVPR1261026R120LGN&q={searchTerms}),Ersetzt,[bc1f71e12952bc7a1f2981cc30d4db25]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.sweet-page.com/?type=hp&ts=1400298711&from=cor&uid=INTELXSSDSA2BW120G3A_CVPR1261026R120LGN, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1400298711&from=cor&uid=INTELXSSDSA2BW120G3A_CVPR1261026R120LGN),Ersetzt,[21ba71e1651687af4007de6ff3111ee2]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.sweet-page.com/?type=hp&ts=1400298711&from=cor&uid=INTELXSSDSA2BW120G3A_CVPR1261026R120LGN, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1400298711&from=cor&uid=INTELXSSDSA2BW120G3A_CVPR1261026R120LGN),Ersetzt,[a23955fdaecde155440575d8e420ee12]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[4e8d71e1f88380b639a16ce00bf906fa]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1400298711&from=cor&uid=INTELXSSDSA2BW120G3A_CVPR1261026R120LGN&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1400298711&from=cor&uid=INTELXSSDSA2BW120G3A_CVPR1261026R120LGN&q={searchTerms}),Ersetzt,[796268ea9eddae8891b7bd9008fc55ab]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.sweet-page.com/?type=hp&ts=1400298711&from=cor&uid=INTELXSSDSA2BW120G3A_CVPR1261026R120LGN, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1400298711&from=cor&uid=INTELXSSDSA2BW120G3A_CVPR1261026R120LGN),Ersetzt,[b7249eb486f5fc3a4700c885996b0000]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.sweet-page.com/?type=hp&ts=1400298711&from=cor&uid=INTELXSSDSA2BW120G3A_CVPR1261026R120LGN, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1400298711&from=cor&uid=INTELXSSDSA2BW120G3A_CVPR1261026R120LGN),Ersetzt,[2ab15ff386f59a9c3910bd90ba4a718f]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[db00aba73a419c9af6e487c5de267987]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-2435969490-785047729-4073554876-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.sweet-page.com/?type=hp&ts=1400298711&from=cor&uid=INTELXSSDSA2BW120G3A_CVPR1261026R120LGN, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1400298711&from=cor&uid=INTELXSSDSA2BW120G3A_CVPR1261026R120LGN),Löschen bei Neustart,[e1fadb77403b33035ce7a2abf80c5fa1]
Ordner: 28
PUP.Optional.Webget.A, C:\Program Files (x86)\webget, Löschen bei Neustart, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\bin, Löschen bei Neustart, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\bin\plugins, In Quarantäne, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, Löschen bei Neustart, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
Dateien: 82
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, Löschen bei Neustart, [3ba09ab885f6fd39c93e2432af528d73],
PUP.Optional.WpManager, C:\ProgramData\WPM\wprotectmanager.exe, Löschen bei Neustart, [17c43f13d6a53501a5bebea20cf5b64a],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\updatewebget.exe, Löschen bei Neustart, [8d4e163c29523600e1e48ceb2bd6ca36],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\bin\utilwebget.exe, Löschen bei Neustart, [a437aea4ef8cb18518ad85f28f72817f],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, Löschen bei Neustart, [2fac5bf7b7c44aecf259d85d41bffe02],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\webgetBHO.dll, In Quarantäne, [fdde2c265c1ff046388cc6b159a860a0],
Spyware.Zbot.VXGen, C:\ProgramData\msriv.exe, In Quarantäne, [578492c01f5c6dc9a293f376de23b34d],
Trojan.FakeMS.ED, C:\Users\mochenmo1\AppData\Local\Temp\dlbc.dll, In Quarantäne, [03d8a2b05823c274916be496cb36c13f],
PUP.Optional.SkyTech.A, C:\Users\mochenmo1\AppData\Local\Temp\99185186\99185186.zipDir\alilog.dll, In Quarantäne, [7e5d3c1699e2b97de82d49e9817f4ab6],
PUP.Optional.IePluginService.A, C:\Users\mochenmo1\AppData\Local\Temp\99185186\99185186.zipDir\tmp\SupTab_Setup302.exe, In Quarantäne, [5586034fe3980432c740fb5ba65b4db3],
PUP.Optional.WpManager, C:\Users\mochenmo1\AppData\Local\Temp\99185186\99185186.zipDir\tmp\wpm_v18.8.0.304.exe, In Quarantäne, [eeeda5ade2990135224198c8c938649c],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\webget.ico, In Quarantäne, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\7za.exe, In Quarantäne, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\updatewebget.InstallState, In Quarantäne, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\webgetUninstall.exe, In Quarantäne, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\bin\utilwebget.InstallState, In Quarantäne, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\bin\webget.PurBrowse64.exe, In Quarantäne, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\bin\webget.PurBrowseG.zip, In Quarantäne, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\bin\plugins\webget.Bromon.dll, In Quarantäne, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\bin\plugins\webget.BrowserAdapterS.dll, In Quarantäne, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\bin\plugins\webget.CompatibilityChecker.dll, In Quarantäne, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\bin\plugins\webget.FFUpdate.dll, In Quarantäne, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\bin\plugins\webget.IEUpdate.dll, In Quarantäne, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.Webget.A, C:\Program Files (x86)\webget\bin\plugins\webget.PurBrowseG.dll, In Quarantäne, [5685ed65abd083b3a9e42c5bff03b947],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterfacef32.dll, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\RSHP.exe, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv32.dll, Löschen bei Neustart, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv64.dll, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WebDataJs, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\arrow.png, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo.png, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo_hover.png, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_logo.png, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo.png, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo2.png, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\0.png, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ie8.js, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, In Quarantäne, [4b90fe541b60ab8b3cca8119f0120ff1],
Trojan.Dropper, C:\Users\mochenmo1\update.exe, In Quarantäne, [ca11d47ea2d948eeb200ef0c0df5916f],
Physische Sektoren: 0
(No malicious items detected)
(end)
AdwCleaner Logfile:
Code:
# AdwCleaner v3.208 - Bericht erstellt am 18/05/2014 um 15:13:56
# Aktualisiert 11/05/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : mochenmo1 - MOCHENMO1-PC
# Gestartet von : C:\Users\mochenmo1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QLA6PCEM\adwcleaner_3.208.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\ParetoLogic
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\Program Files (x86)\driver-soft
Ordner Gelöscht : C:\Users\mochenmo1\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\MOCHEN~1\AppData\Local\Temp\webget
Ordner Gelöscht : C:\Users\mochenmo1\AppData\Roaming\DriverCure
Ordner Gelöscht : C:\Users\mochenmo1\AppData\Roaming\ParetoLogic
Ordner Gelöscht : C:\Users\mochenmo1\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\mochenmo1\AppData\Roaming\sweet-page
Ordner Gelöscht : C:\Users\mochenmo1\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\mochenmo1\Documents\Mobogenie
Datei Gelöscht : C:\Users\mochenmo1\Uninstall.exe
Datei Gelöscht : C:\Windows\Tasks\paretologic registration3.job
Datei Gelöscht : C:\Windows\System32\Tasks\paretologic registration3
Datei Gelöscht : C:\Windows\Tasks\paretologic update version3.job
Datei Gelöscht : C:\Windows\System32\Tasks\paretologic update version3
Datei Gelöscht : C:\Windows\Tasks\PC Health Advisor Defrag.job
Datei Gelöscht : C:\Windows\System32\Tasks\PC Health Advisor Defrag
Datei Gelöscht : C:\Windows\Tasks\PC Health Advisor.job
Datei Gelöscht : C:\Windows\System32\Tasks\PC Health Advisor
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Mobogenie_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Mobogenie_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\systweakasp_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\systweakasp_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wpm_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wpm_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKLM\SOFTWARE\14919ea49a8f3b4aa3cf1058d9a64cec
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_curse-client_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_for_curse-client_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_prism-video-converter_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_prism-video-converter_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{059EACC2-1ABE-49E8-928D-DC8BD355B7A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gelöscht : HKCU\Software\Ciuvo
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\ParetoLogic
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\Driver-Soft
Schlüssel Gelöscht : HKLM\Software\dt soft\daemon tools toolbar
Schlüssel Gelöscht : HKLM\Software\ParetoLogic
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\ParetoLogic
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16421
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
*************************
AdwCleaner[R0].txt - [5394 octets] - [18/05/2014 15:13:02]
AdwCleaner[S0].txt - [4823 octets] - [18/05/2014 15:13:56]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4883 octets] ##########
--- --- ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by mochenmo1 on 18.05.2014 at 15:24:46,85
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\driver genius
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\drivergenius"
Successfully deleted: [Folder] "C:\ProgramData\ustechsupport"
Successfully deleted: [Folder] "C:\Users\mochenmo1\AppData\Roaming\ustechsupport"
Successfully deleted: [Folder] "C:\Program Files (x86)\ustechsupport"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18.05.2014 at 15:28:44,78
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-05-2014
Ran by mochenmo1 (administrator) on MOCHENMO1-PC on 18-05-2014 15:30:59
Running from C:\Users\mochenmo1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F0VDOL6S
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(DT Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Sidebar\sidebar.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(RealNetworks, Inc.) C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDCtrl] => C:\Program Files\elantech\etdctrl.exe [2588968 2010-11-12] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => c:\program files\realtek\audio\hda\ravcpl64.exe [12673128 2011-08-16] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => c:\program files\realtek\audio\hda\ravbg64.exe [2277480 2011-08-16] (Realtek Semiconductor)
HKLM\...\Run: [Power Management] => c:\program files\acer\acer epower management\epowertray.exe [1831016 2011-08-02] (Acer Incorporated)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "c:\program files\intel\turboboost\runtbgadgetonce.vbs"
HKLM\...\Run: [AtherosBtStack] => c:\program files (x86)\bluetooth suite\btvstack.exe [976032 2011-09-16] (Atheros Communications)
HKLM\...\Run: [AthBtTray] => c:\program files (x86)\bluetooth suite\athbttray.exe [799904 2011-09-16] (Atheros Commnucations)
HKLM-x32\...\Run: [BackupManagerTray] => c:\program files (x86)\nti\acer backup manager\backupmanagertray.exe [297280 2011-04-24] (NTI Corporation)
HKLM-x32\...\Run: [OOTag] => c:\program files (x86)\acer\oobeoffer\ootag.exe [13856 2010-02-23] (Microsoft)
HKLM-x32\...\Run: [StartCCC] => c:\program files (x86)\ati technologies\ati.ace\core-static\clistart.exe [336384 2011-02-08] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [LManager] => c:\program files (x86)\launch manager\lmanager.exe [1103440 2011-07-01] (Dritek System Inc.)
HKLM-x32\...\Run: [NUSB3MON] => c:\program files (x86)\renesas electronics\usb 3.0 host controller driver\application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295512 2013-09-03] (RealNetworks, Inc.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => c:\dolby pcee4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-05-16] (Avira Operations GmbH & Co. KG)
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 0
HKLM\...\Policies\Explorer: [HideSCAHealth] 0
HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid}
HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-2435969490-785047729-4073554876-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd)
HKU\S-1-5-21-2435969490-785047729-4073554876-1000\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\Overwolf.exe -silent
HKU\S-1-5-21-2435969490-785047729-4073554876-1000\...\Run: [UZmedia Update] => regsvr32.exe
HKU\S-1-5-21-2435969490-785047729-4073554876-1000\...\Policies\Explorer: [TaskbarNoNotification] 0
HKU\S-1-5-21-2435969490-785047729-4073554876-1000\...\Policies\Explorer: [HideSCAHealth] 0
HKU\S-1-5-21-2435969490-785047729-4073554876-1000\...\MountPoints2: {1232592b-8fba-11e1-95c9-e4d53d088c7c} - G:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-2435969490-785047729-4073554876-1000\...\MountPoints2: {4701b1ef-9c7b-11e2-8905-e4d53d088c7c} - G:\.\Setup.exe AUTORUN=1
HKU\S-1-5-21-2435969490-785047729-4073554876-1000\...\MountPoints2: {88a6e618-80e9-11e1-9204-e4d53d088c7c} - F:\setup.exe
HKU\S-1-5-21-2435969490-785047729-4073554876-1000\...\MountPoints2: {b6f3effd-758d-11e1-960b-e4d53d088c7c} - "F:\WD SmartWare.exe" autoplay=true
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-flv
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Avira Savings Advisor BHO - {A18A516C-AA41-46A9-92DB-60208917E442} - C:\Program Files (x86)\avira\Internet Explorer\avira32.dll ()
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.448 - C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 - C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @videolan.org/vlc,version=2.0.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-05-16] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-05-16] (Avira Operations GmbH & Co. KG)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-24] (NTI Corporation)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-05-16] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-05-16] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-05-16] (Avira Operations GmbH & Co. KG)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2012-04-07] ()
U5 UnlockerDriver5; C:\Program Files (x86)\TC UP\PLUGINS\Media\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] ()
R1 VD_FileDisk; C:\Windows\System32\Drivers\VD_FileDisk.sys [30312 2011-01-26] (CaptainFlint Software)
R1 {9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw64; C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw64.sys [61112 2014-05-16] (StdLib)
U3 a3h2opvh; C:\Windows\System32\Drivers\a3h2opvh.sys [0 ] (Microsoft Corporation)
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbfake; system32\DRIVERS\ewusbfake.sys [X]
S3 USBMULCD; system32\drivers\CM10664.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-18 15:28 - 2014-05-18 15:28 - 00001032 _____ () C:\Users\mochenmo1\Desktop\JRT.txt
2014-05-18 15:24 - 2014-05-18 15:24 - 00000000 ____D () C:\Windows\ERUNT
2014-05-18 15:15 - 2014-05-18 15:15 - 00004971 _____ () C:\Users\mochenmo1\Desktop\AdwCleaner[S0].txt
2014-05-18 15:12 - 2014-05-18 15:22 - 00000000 ____D () C:\AdwCleaner
2014-05-18 15:11 - 2014-05-18 15:11 - 00025573 _____ () C:\Users\mochenmo1\Desktop\mbam.txt.txt
2014-05-18 14:54 - 2014-05-18 15:10 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-18 14:54 - 2014-05-18 14:54 - 00001066 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-18 14:54 - 2014-05-18 14:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-18 14:54 - 2014-05-18 14:54 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-18 14:54 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-18 14:54 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-18 14:54 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-18 14:50 - 2014-05-18 14:50 - 00003408 _____ () C:\Windows\System32\Tasks\aviraSWU
2014-05-18 14:50 - 2014-05-18 14:50 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Avira
2014-05-18 14:49 - 2014-05-18 14:50 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-05-18 14:49 - 2014-05-18 14:49 - 00001958 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-05-18 14:49 - 2014-05-18 14:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-05-18 14:49 - 2014-05-18 14:49 - 00000000 ____D () C:\ProgramData\Avira
2014-05-18 14:49 - 2014-05-16 23:52 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-05-18 14:49 - 2014-05-16 23:52 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-05-18 14:49 - 2014-05-16 23:52 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-05-17 14:48 - 2014-05-18 15:30 - 00000000 ____D () C:\FRST
2014-05-17 08:03 - 2014-05-17 08:03 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\TrojanHunter
2014-05-17 07:22 - 2014-05-16 18:34 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw64.sys
2014-05-17 06:47 - 2014-05-18 14:48 - 00000000 ____D () C:\Program Files (x86)\TrojanHunter 5.5
2014-05-17 06:47 - 2014-05-17 06:47 - 00059392 ____R () C:\Windows\SysWOW64\streamhlp.dll
2014-05-17 05:54 - 2014-05-17 05:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-05-17 05:52 - 2014-05-17 05:52 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-05-17 05:51 - 2014-05-17 05:51 - 00669799 _____ () C:\Users\mochenmo1\Downloads\voxware_audio.zip
2014-05-16 22:29 - 2014-05-16 22:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Combined Community Codec Pack
2014-05-16 22:29 - 2014-05-16 22:29 - 00000000 ____D () C:\Program Files (x86)\Combined Community Codec Pack
2014-05-16 01:33 - 2014-05-16 01:38 - 00000000 ____D () C:\Program Files (x86)\Total Video Converter
2014-05-16 01:31 - 2014-05-16 01:31 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GSpot
2014-05-16 01:31 - 2014-05-16 01:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GSpot
2014-05-16 01:31 - 2014-05-16 01:31 - 00000000 ____D () C:\Program Files (x86)\GSpot
2014-05-16 01:30 - 2014-05-16 01:30 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Win7codecs
2014-05-16 01:30 - 2014-05-16 01:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Win7codecs
2014-05-16 01:30 - 2014-05-16 01:30 - 00000000 ____D () C:\Program Files (x86)\Win7codecs
2014-05-16 01:28 - 2014-05-16 01:28 - 00008629 _____ () C:\Windows\LDPINST.LOG
2014-05-16 00:35 - 2014-05-18 09:44 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\vlc
2014-05-16 00:35 - 2014-05-17 05:54 - 00001030 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-05-16 00:32 - 2014-05-16 01:17 - 00000000 ____D () C:\Users\mochenmo1\soundbackends
2014-05-16 00:32 - 2014-05-16 01:17 - 00000000 ____D () C:\Users\mochenmo1\sound
2014-05-16 00:32 - 2014-05-16 01:17 - 00000000 ____D () C:\Users\mochenmo1\plugins
2014-05-16 00:32 - 2014-05-16 01:17 - 00000000 ____D () C:\Users\mochenmo1\platforms
2014-05-16 00:32 - 2014-05-16 01:17 - 00000000 ____D () C:\Users\mochenmo1\imageformats
2014-05-16 00:32 - 2014-05-16 01:17 - 00000000 ____D () C:\Users\mochenmo1\accessible
2014-05-16 00:32 - 2014-05-16 00:32 - 00000000 ____D () C:\Users\mochenmo1\translations
2014-05-16 00:32 - 2014-05-16 00:32 - 00000000 ____D () C:\Users\mochenmo1\styles
2014-05-16 00:32 - 2014-05-16 00:32 - 00000000 ____D () C:\Users\mochenmo1\news
2014-05-16 00:32 - 2014-05-16 00:32 - 00000000 ____D () C:\Users\mochenmo1\gfx
2014-05-16 00:29 - 2014-05-16 01:21 - 00000000 ____D () C:\Users\mochenmo1\AppData\Local\Overwolf
2014-05-16 00:29 - 2014-05-16 01:17 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-05-16 00:29 - 2014-05-16 01:17 - 00000000 ____D () C:\Users\mochenmo1\AppData\Local\TeamSpeak 3 Client
2014-05-16 00:29 - 2014-05-16 00:32 - 00000798 _____ () C:\Users\mochenmo1\Desktop\TeamSpeak 3 Client.lnk
2014-05-16 00:29 - 2014-05-16 00:29 - 01301028 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win64-1394624943-2014-05-16 00_29_42.913393.dmp
2014-05-16 00:25 - 2014-05-16 00:25 - 01293740 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win64-1394624943-2014-05-16 00_25_21.003342.dmp
2014-05-15 23:30 - 2009-03-24 12:52 - 00155984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.ocx
2014-05-15 23:05 - 2014-05-15 23:05 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-05-15 23:05 - 2014-05-15 23:05 - 00001983 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-05-15 23:04 - 2014-05-16 01:16 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-05-15 22:34 - 2014-05-15 22:34 - 01171946 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 22_34_22.992244.dmp
2014-05-15 22:23 - 2014-05-15 22:23 - 00001228 _____ () C:\Users\mochenmo1\Desktop\Revo Uninstaller.lnk
2014-05-15 22:23 - 2014-05-15 22:23 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-15 21:49 - 2014-05-15 21:49 - 00000000 ____D () C:\backup
2014-05-15 21:44 - 2014-05-18 15:22 - 00126644 _____ () C:\Windows\PFRO.log
2014-05-15 21:44 - 2014-05-18 15:22 - 00001232 _____ () C:\Windows\setupact.log
2014-05-15 21:44 - 2014-05-15 21:44 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-15 21:09 - 2014-05-15 21:09 - 17352880 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-05-15 21:00 - 2014-05-15 21:00 - 01170722 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 21_00_16.075060.dmp
2014-05-15 20:52 - 2014-05-15 21:07 - 00000991 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-05-15 20:52 - 2014-05-15 20:52 - 00002780 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-05-15 20:52 - 2014-05-15 20:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-05-15 20:52 - 2014-05-15 20:52 - 00000000 ____D () C:\Program Files\CCleaner
2014-05-15 20:48 - 2014-05-15 20:48 - 00003170 _____ () C:\Windows\System32\Tasks\{0DE29827-F5F2-483D-8333-7C424F679B3D}
2014-05-15 20:41 - 2014-05-15 20:41 - 01194692 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_41_01.371074.dmp
2014-05-15 20:40 - 2014-05-15 20:40 - 01306049 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win64-1394624943-2014-05-15 20_40_30.614315.dmp
2014-05-15 20:40 - 2014-05-15 20:40 - 01295455 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win64-1394624943-2014-05-15 20_40_34.385530.dmp
2014-05-15 20:40 - 2014-05-15 20:40 - 01294943 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win64-1394624943-2014-05-15 20_40_36.714664.dmp
2014-05-15 20:40 - 2014-05-15 20:40 - 01195948 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_40_39.795840.dmp
2014-05-15 20:39 - 2014-05-15 20:39 - 01296113 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win64-1394624943-2014-05-15 20_39_44.959703.dmp
2014-05-15 20:32 - 2014-05-15 20:32 - 01170722 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_32_33.183978.dmp
2014-05-15 20:28 - 2014-05-15 20:28 - 01170722 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_28_41.318444.dmp
2014-05-15 20:25 - 2014-05-15 20:25 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_25_32.635991.dmp
2014-05-15 20:25 - 2014-05-15 20:25 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_25_26.306629.dmp
2014-05-15 20:25 - 2014-05-15 20:25 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_25_07.048527.dmp
2014-05-15 20:24 - 2014-05-15 20:24 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_24_48.781482.dmp
2014-05-15 20:24 - 2014-05-15 20:24 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_24_46.346343.dmp
2014-05-15 20:24 - 2014-05-15 20:24 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_24_42.550126.dmp
2014-05-15 20:24 - 2014-05-15 20:24 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_24_38.440891.dmp
2014-05-15 20:24 - 2014-05-15 20:24 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_24_36.935805.dmp
2014-05-15 20:24 - 2014-05-15 20:24 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_24_28.041296.dmp
2014-05-15 20:20 - 2014-05-15 20:20 - 01166445 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_20_40.076257.dmp
2014-05-15 01:51 - 2014-05-15 01:51 - 00008802 _____ () C:\Users\Public\DECRYPT_INSTRUCTION.HTML
2014-05-15 01:51 - 2014-05-15 01:51 - 00008802 _____ () C:\Users\mochenmo1\Documents\DECRYPT_INSTRUCTION.HTML
2014-05-15 01:51 - 2014-05-15 01:51 - 00004742 _____ () C:\Users\Public\DECRYPT_INSTRUCTION.TXT
2014-05-15 01:51 - 2014-05-15 01:51 - 00004742 _____ () C:\Users\mochenmo1\Documents\DECRYPT_INSTRUCTION.TXT
2014-05-15 01:51 - 2014-05-15 01:51 - 00000280 _____ () C:\Users\Public\DECRYPT_INSTRUCTION.URL
2014-05-15 01:51 - 2014-05-15 01:51 - 00000280 _____ () C:\Users\mochenmo1\Documents\DECRYPT_INSTRUCTION.URL
2014-05-15 01:50 - 2014-05-15 01:50 - 00008802 _____ () C:\Users\mochenmo1\AppData\Local\DECRYPT_INSTRUCTION.HTML
2014-05-15 01:50 - 2014-05-15 01:50 - 00008802 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.HTML
2014-05-15 01:50 - 2014-05-15 01:50 - 00004742 _____ () C:\Users\mochenmo1\AppData\Local\DECRYPT_INSTRUCTION.TXT
2014-05-15 01:50 - 2014-05-15 01:50 - 00004742 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.TXT
2014-05-15 01:50 - 2014-05-15 01:50 - 00000280 _____ () C:\Users\mochenmo1\AppData\Local\DECRYPT_INSTRUCTION.URL
2014-05-15 01:50 - 2014-05-15 01:50 - 00000280 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.URL
2014-05-15 01:48 - 2014-05-15 20:26 - 00000000 ___HD () C:\2ce2165
2014-05-14 00:17 - 2014-05-14 00:17 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Astuma
2014-05-13 19:38 - 2014-05-13 19:38 - 00204280 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-13 19_38_36.980195.dmp
2014-05-13 19:38 - 2014-05-13 19:38 - 00203536 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-13 19_38_36.981195.dmp
2014-05-11 22:19 - 2014-05-15 20:30 - 00000000 ____D () C:\Program Files (x86)\ROCCAT
2014-05-09 00:23 - 2014-05-09 00:23 - 00000000 ____D () C:\Users\mochenmo1\Documents\Screen Recording Suite
2014-05-09 00:22 - 2014-05-15 20:30 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Apowersoft
2014-05-09 00:22 - 2014-05-15 20:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apowersoft
2014-05-09 00:22 - 2014-05-15 20:30 - 00000000 ____D () C:\Program Files (x86)\Apowersoft
2014-05-02 00:30 - 2014-05-02 00:31 - 00000000 ____D () C:\Windows\system32\config\RCCBakup
2014-05-02 00:25 - 2014-05-02 00:25 - 00000000 ____D () C:\Users\mochenmo1\AppData\Local\cache
2014-05-02 00:25 - 2014-05-02 00:25 - 00000000 ____D () C:\Users\mochenmo1\.android
2014-05-02 00:13 - 2014-05-02 00:13 - 00000000 ____D () C:\Users\Public\Documents\DriverGenius
2014-05-02 00:10 - 2014-05-15 20:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Genius Professional Edition
2014-05-01 23:55 - 2014-05-18 15:06 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-01 23:55 - 2014-05-15 01:50 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Malwarebytes
2014-04-26 00:57 - 2014-05-15 20:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-04-26 00:57 - 2014-05-15 20:42 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-04-26 00:57 - 2014-05-15 20:42 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-04-26 00:06 - 2014-05-16 02:43 - 00000000 ____D () C:\Users\mochenmo1\AppData\Local\UZmedia
2014-04-26 00:04 - 2014-05-15 20:42 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-04-20 16:44 - 2014-05-15 21:43 - 00000000 ____D () C:\ProgramData\2992199F9A
==================== One Month Modified Files and Folders =======
2014-05-18 15:30 - 2014-05-17 14:48 - 00000000 ____D () C:\FRST
2014-05-18 15:30 - 2009-07-14 06:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-18 15:30 - 2009-07-14 06:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-18 15:29 - 2012-04-07 22:00 - 00000000 ____D () C:\Users\mochenmo1\AppData\Local\CrashDumps
2014-05-18 15:28 - 2014-05-18 15:28 - 00001032 _____ () C:\Users\mochenmo1\Desktop\JRT.txt
2014-05-18 15:28 - 2011-10-31 06:19 - 00654166 _____ () C:\Windows\system32\perfh007.dat
2014-05-18 15:28 - 2011-10-31 06:19 - 00130006 _____ () C:\Windows\system32\perfc007.dat
2014-05-18 15:28 - 2009-07-14 07:13 - 01498506 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-18 15:24 - 2014-05-18 15:24 - 00000000 ____D () C:\Windows\ERUNT
2014-05-18 15:23 - 2013-08-30 04:17 - 00003356 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2435969490-785047729-4073554876-1000
2014-05-18 15:23 - 2013-08-08 19:21 - 00003230 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2435969490-785047729-4073554876-1000
2014-05-18 15:22 - 2014-05-18 15:12 - 00000000 ____D () C:\AdwCleaner
2014-05-18 15:22 - 2014-05-15 21:44 - 00126644 _____ () C:\Windows\PFRO.log
2014-05-18 15:22 - 2014-05-15 21:44 - 00001232 _____ () C:\Windows\setupact.log
2014-05-18 15:22 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-18 15:15 - 2014-05-18 15:15 - 00004971 _____ () C:\Users\mochenmo1\Desktop\AdwCleaner[S0].txt
2014-05-18 15:14 - 2012-03-24 10:34 - 00000000 ____D () C:\Users\mochenmo1
2014-05-18 15:11 - 2014-05-18 15:11 - 00025573 _____ () C:\Users\mochenmo1\Desktop\mbam.txt.txt
2014-05-18 15:10 - 2014-05-18 14:54 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-18 15:06 - 2014-05-01 23:55 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-18 15:06 - 2012-08-28 12:34 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-18 15:02 - 2014-05-17 05:52 - 00000000 ____D () C:\ProgramData\IePluginServices
2014-05-18 15:02 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Speech
2014-05-18 14:54 - 2014-05-18 14:54 - 00001066 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-18 14:54 - 2014-05-18 14:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-18 14:54 - 2014-05-18 14:54 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-18 14:50 - 2014-05-18 14:50 - 00003408 _____ () C:\Windows\System32\Tasks\aviraSWU
2014-05-18 14:50 - 2014-05-18 14:50 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Avira
2014-05-18 14:50 - 2014-05-18 14:49 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-05-18 14:49 - 2014-05-18 14:49 - 00001958 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-05-18 14:49 - 2014-05-18 14:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-05-18 14:49 - 2014-05-18 14:49 - 00000000 ____D () C:\ProgramData\Avira
2014-05-18 14:48 - 2014-05-17 06:47 - 00000000 ____D () C:\Program Files (x86)\TrojanHunter 5.5
2014-05-18 09:53 - 2012-09-18 00:07 - 00000000 ____D () C:\Program Files (x86)\NCH Software
2014-05-18 09:52 - 2011-10-30 21:48 - 00000000 ____D () C:\ProgramData\CyberLink
2014-05-18 09:52 - 2011-08-12 09:23 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-05-18 09:44 - 2014-05-16 00:35 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\vlc
2014-05-17 14:46 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-05-17 08:03 - 2014-05-17 08:03 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\TrojanHunter
2014-05-17 06:58 - 2011-10-30 21:26 - 01610618 _____ () C:\Windows\WindowsUpdate.log
2014-05-17 06:47 - 2014-05-17 06:47 - 00059392 ____R () C:\Windows\SysWOW64\streamhlp.dll
2014-05-17 05:54 - 2014-05-17 05:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-05-17 05:54 - 2014-05-16 00:35 - 00001030 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-05-17 05:51 - 2014-05-17 05:51 - 00669799 _____ () C:\Users\mochenmo1\Downloads\voxware_audio.zip
2014-05-16 23:52 - 2014-05-18 14:49 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-05-16 23:52 - 2014-05-18 14:49 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-05-16 23:52 - 2014-05-18 14:49 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-05-16 22:29 - 2014-05-16 22:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Combined Community Codec Pack
2014-05-16 22:29 - 2014-05-16 22:29 - 00000000 ____D () C:\Program Files (x86)\Combined Community Codec Pack
2014-05-16 22:29 - 2013-07-20 22:57 - 00000000 ____D () C:\Program Files (x86)\Google
2014-05-16 22:17 - 2013-09-23 23:58 - 00003378 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2435969490-785047729-4073554876-1000
2014-05-16 22:17 - 2013-09-23 23:58 - 00003252 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2435969490-785047729-4073554876-1000
2014-05-16 18:34 - 2014-05-17 07:22 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gw64.sys
2014-05-16 06:24 - 2012-04-25 11:56 - 00000000 ____D () C:\Users\mochenmo1\AppData\Local\QuickPar
2014-05-16 02:43 - 2014-04-26 00:06 - 00000000 ____D () C:\Users\mochenmo1\AppData\Local\UZmedia
2014-05-16 01:50 - 2013-06-20 02:30 - 00003398 _____ () C:\Windows\System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-2435969490-785047729-4073554876-1000
2014-05-16 01:42 - 2012-09-18 00:07 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-05-16 01:38 - 2014-05-16 01:33 - 00000000 ____D () C:\Program Files (x86)\Total Video Converter
2014-05-16 01:37 - 2012-03-24 10:34 - 00060360 _____ () C:\Users\mochenmo1\AppData\Local\GDIPFONTCACHEV1.DAT
2014-05-16 01:36 - 2009-07-14 06:45 - 00283136 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-05-16 01:31 - 2014-05-16 01:31 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GSpot
2014-05-16 01:31 - 2014-05-16 01:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GSpot
2014-05-16 01:31 - 2014-05-16 01:31 - 00000000 ____D () C:\Program Files (x86)\GSpot
2014-05-16 01:30 - 2014-05-16 01:30 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Win7codecs
2014-05-16 01:30 - 2014-05-16 01:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Win7codecs
2014-05-16 01:30 - 2014-05-16 01:30 - 00000000 ____D () C:\Program Files (x86)\Win7codecs
2014-05-16 01:30 - 2012-04-01 19:47 - 00000000 ____D () C:\ProgramData\Win7codecs
2014-05-16 01:28 - 2014-05-16 01:28 - 00008629 _____ () C:\Windows\LDPINST.LOG
2014-05-16 01:28 - 2012-04-01 19:42 - 00000000 ____D () C:\ProgramData\LogiShrd
2014-05-16 01:28 - 2012-04-01 19:42 - 00000000 ____D () C:\Program Files\Common Files\Logishrd
2014-05-16 01:21 - 2014-05-16 00:29 - 00000000 ____D () C:\Users\mochenmo1\AppData\Local\Overwolf
2014-05-16 01:17 - 2014-05-16 00:32 - 00000000 ____D () C:\Users\mochenmo1\soundbackends
2014-05-16 01:17 - 2014-05-16 00:32 - 00000000 ____D () C:\Users\mochenmo1\sound
2014-05-16 01:17 - 2014-05-16 00:32 - 00000000 ____D () C:\Users\mochenmo1\plugins
2014-05-16 01:17 - 2014-05-16 00:32 - 00000000 ____D () C:\Users\mochenmo1\platforms
2014-05-16 01:17 - 2014-05-16 00:32 - 00000000 ____D () C:\Users\mochenmo1\imageformats
2014-05-16 01:17 - 2014-05-16 00:32 - 00000000 ____D () C:\Users\mochenmo1\accessible
2014-05-16 01:17 - 2014-05-16 00:29 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-05-16 01:17 - 2014-05-16 00:29 - 00000000 ____D () C:\Users\mochenmo1\AppData\Local\TeamSpeak 3 Client
2014-05-16 01:17 - 2013-08-09 23:23 - 00000000 ____D () C:\Program Files (x86)\TC UP
2014-05-16 01:17 - 2012-06-08 23:57 - 00000000 ____D () C:\ProgramData\Real
2014-05-16 01:17 - 2011-10-30 21:43 - 00000000 ____D () C:\ProgramData\Atheros
2014-05-16 01:17 - 2011-08-12 10:02 - 00000000 ____D () C:\ProgramData\BackupManager
2014-05-16 01:17 - 2011-08-12 10:00 - 00000000 ____D () C:\ProgramData\Adobe
2014-05-16 01:17 - 2011-08-12 09:59 - 00000000 ____D () C:\ProgramData\oem
2014-05-16 01:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-05-16 01:16 - 2014-05-15 23:04 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-05-16 01:16 - 2012-04-01 19:45 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-05-16 00:32 - 2014-05-16 00:32 - 00000000 ____D () C:\Users\mochenmo1\translations
2014-05-16 00:32 - 2014-05-16 00:32 - 00000000 ____D () C:\Users\mochenmo1\styles
2014-05-16 00:32 - 2014-05-16 00:32 - 00000000 ____D () C:\Users\mochenmo1\news
2014-05-16 00:32 - 2014-05-16 00:32 - 00000000 ____D () C:\Users\mochenmo1\gfx
2014-05-16 00:32 - 2014-05-16 00:29 - 00000798 _____ () C:\Users\mochenmo1\Desktop\TeamSpeak 3 Client.lnk
2014-05-16 00:29 - 2014-05-16 00:29 - 01301028 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win64-1394624943-2014-05-16 00_29_42.913393.dmp
2014-05-16 00:25 - 2014-05-16 00:25 - 01293740 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win64-1394624943-2014-05-16 00_25_21.003342.dmp
2014-05-15 23:45 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-15 23:05 - 2014-05-15 23:05 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-05-15 23:05 - 2014-05-15 23:05 - 00001983 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-05-15 22:55 - 2012-08-31 16:35 - 00000000 ____D () C:\Users\mochenmo1\AppData\Local\Adobe
2014-05-15 22:42 - 2012-04-30 23:21 - 00000000 ____D () C:\Users\mochenmo1\AppData\Local\Deployment
2014-05-15 22:34 - 2014-05-15 22:34 - 01171946 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 22_34_22.992244.dmp
2014-05-15 22:23 - 2014-05-15 22:23 - 00001228 _____ () C:\Users\mochenmo1\Desktop\Revo Uninstaller.lnk
2014-05-15 22:23 - 2014-05-15 22:23 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-15 21:49 - 2014-05-15 21:49 - 00000000 ____D () C:\backup
2014-05-15 21:44 - 2014-05-15 21:44 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-15 21:43 - 2014-04-20 16:44 - 00000000 ____D () C:\ProgramData\2992199F9A
2014-05-15 21:09 - 2014-05-15 21:09 - 17352880 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-05-15 21:09 - 2012-08-28 12:34 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-15 21:09 - 2012-05-18 21:01 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-15 21:09 - 2011-08-12 10:01 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-15 21:07 - 2014-05-15 20:52 - 00000991 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-05-15 21:00 - 2014-05-15 21:00 - 01170722 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 21_00_16.075060.dmp
2014-05-15 20:56 - 2012-09-29 01:53 - 00000000 ____D () C:\Windows\Minidump
2014-05-15 20:56 - 2012-04-25 00:56 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Media Player Classic
2014-05-15 20:56 - 2012-04-07 21:39 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\DAEMON Tools Lite
2014-05-15 20:56 - 2007-07-12 03:49 - 00000000 ____D () C:\Windows\Panther
2014-05-15 20:52 - 2014-05-15 20:52 - 00002780 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-05-15 20:52 - 2014-05-15 20:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-05-15 20:52 - 2014-05-15 20:52 - 00000000 ____D () C:\Program Files\CCleaner
2014-05-15 20:48 - 2014-05-15 20:48 - 00003170 _____ () C:\Windows\System32\Tasks\{0DE29827-F5F2-483D-8333-7C424F679B3D}
2014-05-15 20:45 - 2014-04-09 22:30 - 00000000 ____D () C:\Program Files (x86)\NirSoft
2014-05-15 20:43 - 2014-05-02 00:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Genius Professional Edition
2014-05-15 20:42 - 2014-04-26 00:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-05-15 20:42 - 2014-04-26 00:57 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-05-15 20:42 - 2014-04-26 00:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-05-15 20:42 - 2014-04-26 00:04 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-05-15 20:42 - 2013-09-03 19:22 - 00000000 ____D () C:\ProgramData\RealNetworks
2014-05-15 20:42 - 2013-03-30 12:20 - 00000000 ____D () C:\Program Files (x86)\Guild Wars 2
2014-05-15 20:42 - 2012-05-26 13:08 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Real
2014-05-15 20:42 - 2012-05-18 21:01 - 00000000 ____D () C:\Windows\system32\Macromed
2014-05-15 20:42 - 2012-03-26 21:27 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Skype
2014-05-15 20:42 - 2011-08-12 10:01 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-05-15 20:42 - 2011-08-12 10:00 - 00000000 ___HD () C:\OEM
2014-05-15 20:42 - 2011-08-12 09:45 - 00000000 ____D () C:\ProgramData\Acer
2014-05-15 20:42 - 2011-08-12 09:43 - 00000000 ____D () C:\ProgramData\Skype
2014-05-15 20:42 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat
2014-05-15 20:41 - 2014-05-15 20:41 - 01194692 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_41_01.371074.dmp
2014-05-15 20:40 - 2014-05-15 20:40 - 01306049 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win64-1394624943-2014-05-15 20_40_30.614315.dmp
2014-05-15 20:40 - 2014-05-15 20:40 - 01295455 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win64-1394624943-2014-05-15 20_40_34.385530.dmp
2014-05-15 20:40 - 2014-05-15 20:40 - 01294943 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win64-1394624943-2014-05-15 20_40_36.714664.dmp
2014-05-15 20:40 - 2014-05-15 20:40 - 01195948 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_40_39.795840.dmp
2014-05-15 20:39 - 2014-05-15 20:39 - 01296113 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win64-1394624943-2014-05-15 20_39_44.959703.dmp
2014-05-15 20:32 - 2014-05-15 20:32 - 01170722 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_32_33.183978.dmp
2014-05-15 20:30 - 2014-05-11 22:19 - 00000000 ____D () C:\Program Files (x86)\ROCCAT
2014-05-15 20:30 - 2014-05-09 00:22 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Apowersoft
2014-05-15 20:30 - 2014-05-09 00:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apowersoft
2014-05-15 20:30 - 2014-05-09 00:22 - 00000000 ____D () C:\Program Files (x86)\Apowersoft
2014-05-15 20:30 - 2014-03-08 21:20 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-05-15 20:30 - 2013-05-01 18:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Any Video Converter
2014-05-15 20:28 - 2014-05-15 20:28 - 01170722 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_28_41.318444.dmp
2014-05-15 20:26 - 2014-05-15 01:48 - 00000000 ___HD () C:\2ce2165
2014-05-15 20:26 - 2013-04-06 23:05 - 00000000 ____D () C:\Program Files (x86)\TechSmith
2014-05-15 20:25 - 2014-05-15 20:25 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_25_32.635991.dmp
2014-05-15 20:25 - 2014-05-15 20:25 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_25_26.306629.dmp
2014-05-15 20:25 - 2014-05-15 20:25 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_25_07.048527.dmp
2014-05-15 20:24 - 2014-05-15 20:24 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_24_48.781482.dmp
2014-05-15 20:24 - 2014-05-15 20:24 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_24_46.346343.dmp
2014-05-15 20:24 - 2014-05-15 20:24 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_24_42.550126.dmp
2014-05-15 20:24 - 2014-05-15 20:24 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_24_38.440891.dmp
2014-05-15 20:24 - 2014-05-15 20:24 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_24_36.935805.dmp
2014-05-15 20:24 - 2014-05-15 20:24 - 01163707 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_24_28.041296.dmp
2014-05-15 20:20 - 2014-05-15 20:20 - 01166445 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-15 20_20_40.076257.dmp
2014-05-15 01:51 - 2014-05-15 01:51 - 00008802 _____ () C:\Users\Public\DECRYPT_INSTRUCTION.HTML
2014-05-15 01:51 - 2014-05-15 01:51 - 00008802 _____ () C:\Users\mochenmo1\Documents\DECRYPT_INSTRUCTION.HTML
2014-05-15 01:51 - 2014-05-15 01:51 - 00004742 _____ () C:\Users\Public\DECRYPT_INSTRUCTION.TXT
2014-05-15 01:51 - 2014-05-15 01:51 - 00004742 _____ () C:\Users\mochenmo1\Documents\DECRYPT_INSTRUCTION.TXT
2014-05-15 01:51 - 2014-05-15 01:51 - 00000280 _____ () C:\Users\Public\DECRYPT_INSTRUCTION.URL
2014-05-15 01:51 - 2014-05-15 01:51 - 00000280 _____ () C:\Users\mochenmo1\Documents\DECRYPT_INSTRUCTION.URL
2014-05-15 01:51 - 2013-07-02 20:18 - 00000000 ____D () C:\Users\mochenmo1\Documents\Any Video Converter
2014-05-15 01:51 - 2012-04-25 01:02 - 00000000 ____D () C:\Users\mochenmo1\Documents\CyberLink
2014-05-15 01:50 - 2014-05-15 01:50 - 00008802 _____ () C:\Users\mochenmo1\AppData\Local\DECRYPT_INSTRUCTION.HTML
2014-05-15 01:50 - 2014-05-15 01:50 - 00008802 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.HTML
2014-05-15 01:50 - 2014-05-15 01:50 - 00004742 _____ () C:\Users\mochenmo1\AppData\Local\DECRYPT_INSTRUCTION.TXT
2014-05-15 01:50 - 2014-05-15 01:50 - 00004742 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.TXT
2014-05-15 01:50 - 2014-05-15 01:50 - 00000280 _____ () C:\Users\mochenmo1\AppData\Local\DECRYPT_INSTRUCTION.URL
2014-05-15 01:50 - 2014-05-15 01:50 - 00000280 _____ () C:\ProgramData\DECRYPT_INSTRUCTION.URL
2014-05-15 01:50 - 2014-05-01 23:55 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Malwarebytes
2014-05-15 01:50 - 2013-05-01 18:21 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Any Video Converter
2014-05-15 01:50 - 2012-04-26 18:10 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\InternetEverywhere
2014-05-15 01:50 - 2012-03-24 10:56 - 00000000 ____D () C:\Users\mochenmo1\AppData\Local\Western Digital
2014-05-15 01:49 - 2011-10-30 21:25 - 00000000 ____D () C:\book
2014-05-15 01:49 - 2011-08-12 10:09 - 00008728 __RSH () C:\BOOTSECT.BAK
2014-05-14 00:17 - 2014-05-14 00:17 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Astuma
2014-05-13 19:38 - 2014-05-13 19:38 - 00204280 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-13 19_38_36.980195.dmp
2014-05-13 19:38 - 2014-05-13 19:38 - 00203536 _____ () C:\Users\mochenmo1\Documents\ts3_clientui-win32-1378715177-2014-05-13 19_38_36.981195.dmp
2014-05-12 00:10 - 2009-07-14 04:34 - 54525952 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-05-12 00:10 - 2009-07-14 04:34 - 16777216 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-05-12 00:10 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-05-09 00:23 - 2014-05-09 00:23 - 00000000 ____D () C:\Users\mochenmo1\Documents\Screen Recording Suite
2014-05-08 20:06 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-05-02 00:31 - 2014-05-02 00:30 - 00000000 ____D () C:\Windows\system32\config\RCCBakup
2014-05-02 00:25 - 2014-05-02 00:25 - 00000000 ____D () C:\Users\mochenmo1\AppData\Local\cache
2014-05-02 00:25 - 2014-05-02 00:25 - 00000000 ____D () C:\Users\mochenmo1\.android
2014-05-02 00:13 - 2014-05-02 00:13 - 00000000 ____D () C:\Users\Public\Documents\DriverGenius
2014-05-02 00:07 - 2013-05-01 18:21 - 00000000 ____D () C:\Program Files (x86)\Any Video Converter
2014-05-01 16:19 - 2009-07-14 07:38 - 00067584 ____S () C:\Windows\bootstat(32).dat
2014-04-30 11:07 - 2013-09-17 19:21 - 00000000 ____D () C:\Users\mochenmo1\AppData\Roaming\Guild Wars 2
2014-04-20 16:57 - 2010-11-21 09:16 - 00000000 ___RD () C:\Users\Public\Recorded TV
Files to move or delete:
====================
C:\Users\mochenmo1\createfileassoc.exe
C:\Users\mochenmo1\error_report.exe
C:\Users\mochenmo1\libeay32.dll
C:\Users\mochenmo1\msvcp110.dll
C:\Users\mochenmo1\msvcr110.dll
C:\Users\mochenmo1\OverwolfTeamSpeakInstaller.exe
C:\Users\mochenmo1\package_inst.exe
C:\Users\mochenmo1\Qt5Core.dll
C:\Users\mochenmo1\Qt5Gui.dll
C:\Users\mochenmo1\Qt5Network.dll
C:\Users\mochenmo1\Qt5Sql.dll
C:\Users\mochenmo1\Qt5Widgets.dll
C:\Users\mochenmo1\quazip.dll
C:\Users\mochenmo1\ssleay32.dll
C:\Users\mochenmo1\ts3client_win64.exe
Some content of TEMP:
====================
C:\Users\mochenmo1\AppData\Local\Temp\9t6h.difxapi.dll
C:\Users\mochenmo1\AppData\Local\Temp\AskSLib.dll
C:\Users\mochenmo1\AppData\Local\Temp\avgnt.exe
C:\Users\mochenmo1\AppData\Local\Temp\del.dll
C:\Users\mochenmo1\AppData\Local\Temp\Difx64.exe
C:\Users\mochenmo1\AppData\Local\Temp\ffmpeg17.exe
C:\Users\mochenmo1\AppData\Local\Temp\Quarantine.exe
C:\Users\mochenmo1\AppData\Local\Temp\vlc-2.1.3-win32.exe
C:\Users\mochenmo1\AppData\Local\Temp\W2NTSo.difxapi.dll
C:\Users\mochenmo1\AppData\Local\Temp\zuYJ.Difx64.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-14 02:30
==================== End Of Log ============================
--- --- ---
oh je, eine ganze menge mist drauf:(