Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 04.06.2014
Suchlauf-Zeit: 15:10:22
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.04.05
Rootkit Datenbank: v2014.06.02.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: geiche
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 333334
Verstrichene Zeit: 7 Min, 50 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 14
PUP.Optional.SaveSense.A, HKU\S-1-5-21-2917435617-3823699889-1472500709-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{71e129ff-6c2a-4984-818c-7e2c998b8d99}, Löschen bei Neustart, [f5802c4846352a0c8ea461d7d82a60a0],
PUP.Optional.SpeedTest.A, HKU\S-1-5-21-2917435617-3823699889-1472500709-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{0A44F337-EFC8-44BC-891F-4A2FA57995D9}, Löschen bei Neustart, [2253e391285362d447b4b97d08fa12ee],
PUP.Optional.BestToolbars, HKU\S-1-5-21-2917435617-3823699889-1472500709-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{2977C29A-6723-4436-90BB-F7C5FDEF88A1}, Löschen bei Neustart, [a4d1b6be93e876c04c5c85eb847ef60a],
PUP.Optional.BestToolbars, HKU\S-1-5-21-2917435617-3823699889-1472500709-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{2977C29A-6723-4436-90BB-F7C5FDEF88A1}, Löschen bei Neustart, [a4d1b6be93e876c04c5c85eb847ef60a],
PUP.Optional.MediaView.A, HKLM\SOFTWARE\MediaViewV1alpha1699, In Quarantäne, [a1d46e060d6ef34399a6347905fd0bf5],
PUP.Optional.MediaView.A, HKLM\SOFTWARE\MediaViewV1alpha5797, In Quarantäne, [6c09443093e88aac7bc4327b62a001ff],
PUP.Optional.SpeedTest.A, HKLM\SOFTWARE\CLASSES\Speed Test (4354).BackgroundHostObject, In Quarantäne, [21544b29d6a5dd59cd2e189d877b3ec2],
PUP.Optional.SpeedTest.A, HKLM\SOFTWARE\CLASSES\Speed Test (4354).BackgroundHostObject.1, In Quarantäne, [2e4734408af1c4726b90575e8d75c937],
PUP.Optional.Feven.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Feven 1.5, Löschen bei Neustart, [e78ecba966155fd747631f91c33f35cb],
PUP.Optional.Feven.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\freeven, Löschen bei Neustart, [245186ee007b57df83f489225da5d42c],
PUP.Optional.Feven.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Freeven pro 1.2, Löschen bei Neustart, [2d484f250378bb7b5d9aedaa82806b95],
PUP.Optional.MediaEnhance.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\media enhance, Löschen bei Neustart, [35407bf992e944f216a45d43ce346898],
PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-1.3, Löschen bei Neustart, [8aebec8834476bcb1551961226dc12ee],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2917435617-3823699889-1472500709-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Löschen bei Neustart, [3b3a3a3af586a98d68666e71986b22de],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 6
PUP.Optional.Snapdo, HKU\S-1-5-21-2917435617-3823699889-1472500709-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=Tuguu&co=DE&userid=99c3ef05-9edb-44e5-fd92-b5bb599b4209&searchtype=ds&q={searchTerms}&installDate=14/11/2013, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=Tuguu&co=DE&userid=99c3ef05-9edb-44e5-fd92-b5bb599b4209&searchtype=ds&q={searchTerms}&installDate=14/11/2013),Löschen bei Neustart,[92e3ef858eed0234b8b82147ba4a7888]
PUP.Optional.Snapdo, HKU\S-1-5-21-2917435617-3823699889-1472500709-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=Tuguu&co=DE&userid=99c3ef05-9edb-44e5-fd92-b5bb599b4209&searchtype=ds&q={searchTerms}&installDate=14/11/2013, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=Tuguu&co=DE&userid=99c3ef05-9edb-44e5-fd92-b5bb599b4209&searchtype=ds&q={searchTerms}&installDate=14/11/2013),Löschen bei Neustart,[04713f352f4c0b2b036eee7a30d43bc5]
PUP.Optional.Snapdo, HKU\S-1-5-21-2917435617-3823699889-1472500709-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=Tuguu&co=DE&userid=99c3ef05-9edb-44e5-fd92-b5bb599b4209&searchtype=hp&installDate=14/11/2013, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=Tuguu&co=DE&userid=99c3ef05-9edb-44e5-fd92-b5bb599b4209&searchtype=hp&installDate=14/11/2013),Löschen bei Neustart,[5d18472d2d4eae880f630d5b58ac718f]
PUP.Optional.Snapdo, HKU\S-1-5-21-2917435617-3823699889-1472500709-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=Tuguu&co=DE&userid=99c3ef05-9edb-44e5-fd92-b5bb599b4209&searchtype=ds&q={searchTerms}&installDate=14/11/2013, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=Tuguu&co=DE&userid=99c3ef05-9edb-44e5-fd92-b5bb599b4209&searchtype=ds&q={searchTerms}&installDate=14/11/2013),Löschen bei Neustart,[7ef713616516989e660d07618f750bf5]
PUP.Optional.Snapdo, HKU\S-1-5-21-2917435617-3823699889-1472500709-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=Tuguu&co=DE&userid=99c3ef05-9edb-44e5-fd92-b5bb599b4209&searchtype=ds&q={searchTerms}&installDate=14/11/2013, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=Tuguu&co=DE&userid=99c3ef05-9edb-44e5-fd92-b5bb599b4209&searchtype=ds&q={searchTerms}&installDate=14/11/2013),Löschen bei Neustart,[d99c7ff5f88387af95df3d2b60a401ff]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2917435617-3823699889-1472500709-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=Tuguu&co=DE&userid=99c3ef05-9edb-44e5-fd92-b5bb599b4209&searchtype=ds&q={searchTerms}&installDate=14/11/2013, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=Tuguu&dpid=Tuguu&co=DE&userid=99c3ef05-9edb-44e5-fd92-b5bb599b4209&searchtype=ds&q={searchTerms}&installDate=14/11/2013),Löschen bei Neustart,[3a3b3d375427b482868638275da7629e]
Ordner: 25
PUP.Optional.FreeGames.A, C:\Users\geiche\AppData\Roaming\freegames4357, In Quarantäne, [d3a2b0c4b8c3af87ab634f347a8814ec],
PUP.Optional.SpeedTest.A, C:\Users\geiche\AppData\Roaming\speedtest4350, In Quarantäne, [f77efa7a1f5c9d99c8494a39a2605ba5],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\Main, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\Main\bin, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\Main\Logs, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\Main\rep, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\SearchProtect, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\SearchProtect\bin, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\SearchProtect\Logs, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\SearchProtect\rep, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\bin, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\bubble, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\libs, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\protection, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\settings, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\uninstall, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\rep, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_dmgpbjjcdccinnndjdgmegndbmhbgglb_0, In Quarantäne, [4c29e39198e31a1c95d6ed9bc33f7c84],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dmgpbjjcdccinnndjdgmegndbmhbgglb, In Quarantäne, [a6cf34402556270f5c1bc2c6ef13ff01],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhlmghjmomaoodfgjeikphfdljhpcpkl, In Quarantäne, [3441acc8ec8f1c1ae6209eec986a01ff],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_hhlmghjmomaoodfgjeikphfdljhpcpkl_0, In Quarantäne, [e194650fdba08ea858af5931738f7090],
Dateien: 103
PUP.Optional.InstallBrain.A, C:\Users\geiche\AppData\Local\Temp\Сodec Performer804128.exe, In Quarantäne, [88ed5420fa819e98e2ccb98a5ea333cd],
PUP.Optional.InstallBrain.A, C:\Users\geiche\Downloads\CodecPerformerSetup.exe, In Quarantäne, [88ed4232c9b2bd79e2cc91b28c75aa56],
PUP.Optional.Domalq, C:\Users\geiche\Downloads\Java7.exe, In Quarantäne, [aec752220873a98dcc68f2397b8558a8],
PUP.Optional.Outbrowse, C:\Users\geiche\Downloads\Malwarebytes.exe, In Quarantäne, [2c4951234239063083e9dea148b97888],
PUP.Optional.BundleInstaller.A, C:\Users\geiche\Downloads\VideoPerformerSetup_v6e2769.exe, In Quarantäne, [0a6bbeb60477aa8c1a8044f3e51f9e62],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hhlmghjmomaoodfgjeikphfdljhpcpkl_0.localstorage, In Quarantäne, [70050173f9826dc94cd8446113efe41c],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hhlmghjmomaoodfgjeikphfdljhpcpkl_0.localstorage-journal, In Quarantäne, [41343044fe7dc373c4603b6a9c66ba46],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dmgpbjjcdccinnndjdgmegndbmhbgglb_0.localstorage, In Quarantäne, [076eed87700b1c1ae0ba3e6944be38c8],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dmgpbjjcdccinnndjdgmegndbmhbgglb_0.localstorage-journal, In Quarantäne, [caab8ee6cdae4ee8aaf0e3c48b7732ce],
PUP.Optional.FreeGames.A, C:\Users\geiche\AppData\Roaming\freegames4357\freegames4357.crx, In Quarantäne, [d3a2b0c4b8c3af87ab634f347a8814ec],
PUP.Optional.FreeGames.A, C:\Users\geiche\AppData\Roaming\freegames4357\freegames4357DeskTopIcon.ico, In Quarantäne, [d3a2b0c4b8c3af87ab634f347a8814ec],
PUP.Optional.FreeGames.A, C:\Users\geiche\AppData\Roaming\freegames4357\install_helper.exe, In Quarantäne, [d3a2b0c4b8c3af87ab634f347a8814ec],
PUP.Optional.SpeedTest.A, C:\Users\geiche\AppData\Roaming\speedtest4350\DeskTopIcon.ico, In Quarantäne, [f77efa7a1f5c9d99c8494a39a2605ba5],
PUP.Optional.SpeedTest.A, C:\Users\geiche\AppData\Roaming\speedtest4350\install_helper.exe, In Quarantäne, [f77efa7a1f5c9d99c8494a39a2605ba5],
PUP.Optional.SpeedTest.A, C:\Users\geiche\AppData\Roaming\speedtest4350\speedtest4350.crx, In Quarantäne, [f77efa7a1f5c9d99c8494a39a2605ba5],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\EULA.txt, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\Main\bin\CltMngSvc.exe, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\Main\bin\SPTool.dll, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\Main\bin\SPtool.dll_1387965383656, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\Main\bin\SPtool.dll_1389595566291, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\Main\bin\uninstall.exe, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\Main\rep\SystemRepository.dat, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\SearchProtect\bin\cltmng.exe, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\SearchProtect\bin\SPTool64.exe, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\SearchProtect\bin\SPVC32.dll, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\SearchProtect\bin\SPVC32Loader.dll, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\SearchProtect\bin\SPVC64.dll, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\SearchProtect\bin\SPVC64Loader.dll, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\bin\cltmngui.exe, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\settings.html, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\style.css, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\bubble\bubble.css, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\bubble\bubble.html, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\bubble\bubble.js, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\bubble\defaults.js, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\Apply-default.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\Apply-onclick.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\Apply-Rollover.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\bg-with-logo.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\bg.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\bgNotif.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\bgSettings.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\bgUninstall.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\btnBlue.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\btnClose.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\btnSilver.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\checkbox.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\checkbox_checked.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\checkbox_def.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\close-win-def.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\close-win-over-click.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\gray-bg.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\hez-def.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\hez-selected.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\hez.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\icon-win.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\info-icon.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\menu-rollover.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\menu-selected.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\radio-button-def.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\radio-button-selected.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\radio-button.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\radio-button2.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\Settings-icon.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\text-field.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\v.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\Images\x.png, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\libs\defaults.js, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\libs\dialogUtils.js, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\libs\jquery.1.7.1.min.js, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\libs\json2.min.js, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\libs\main.js, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\libs\SPDialogAPI.js, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\protection\defaults.js, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\protection\protection.css, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\protection\protection.html, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\protection\protection.js, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\settings\defaults.js, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\settings\settings.css, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\settings\settings.html, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\settings\settings.js, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\uninstall\defaults.js, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\uninstall\uninstall.css, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\uninstall\uninstall.html, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.SearchProtect.A, C:\Program Files\SearchProtect3506262\UI\dialogs\uninstall\uninstall.js, In Quarantäne, [afc67ef67605e94dda7bb1d6c93921df],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_dmgpbjjcdccinnndjdgmegndbmhbgglb_0\19, In Quarantäne, [4c29e39198e31a1c95d6ed9bc33f7c84],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dmgpbjjcdccinnndjdgmegndbmhbgglb\000102.ldb, In Quarantäne, [a6cf34402556270f5c1bc2c6ef13ff01],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dmgpbjjcdccinnndjdgmegndbmhbgglb\000105.log, In Quarantäne, [a6cf34402556270f5c1bc2c6ef13ff01],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dmgpbjjcdccinnndjdgmegndbmhbgglb\CURRENT, In Quarantäne, [a6cf34402556270f5c1bc2c6ef13ff01],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dmgpbjjcdccinnndjdgmegndbmhbgglb\LOCK, In Quarantäne, [a6cf34402556270f5c1bc2c6ef13ff01],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dmgpbjjcdccinnndjdgmegndbmhbgglb\LOG, In Quarantäne, [a6cf34402556270f5c1bc2c6ef13ff01],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dmgpbjjcdccinnndjdgmegndbmhbgglb\LOG.old, In Quarantäne, [a6cf34402556270f5c1bc2c6ef13ff01],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dmgpbjjcdccinnndjdgmegndbmhbgglb\MANIFEST-000103, In Quarantäne, [a6cf34402556270f5c1bc2c6ef13ff01],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhlmghjmomaoodfgjeikphfdljhpcpkl\002348.ldb, In Quarantäne, [3441acc8ec8f1c1ae6209eec986a01ff],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhlmghjmomaoodfgjeikphfdljhpcpkl\002362.ldb, In Quarantäne, [3441acc8ec8f1c1ae6209eec986a01ff],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhlmghjmomaoodfgjeikphfdljhpcpkl\002365.ldb, In Quarantäne, [3441acc8ec8f1c1ae6209eec986a01ff],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhlmghjmomaoodfgjeikphfdljhpcpkl\002366.log, In Quarantäne, [3441acc8ec8f1c1ae6209eec986a01ff],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhlmghjmomaoodfgjeikphfdljhpcpkl\CURRENT, In Quarantäne, [3441acc8ec8f1c1ae6209eec986a01ff],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhlmghjmomaoodfgjeikphfdljhpcpkl\LOCK, In Quarantäne, [3441acc8ec8f1c1ae6209eec986a01ff],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhlmghjmomaoodfgjeikphfdljhpcpkl\LOG, In Quarantäne, [3441acc8ec8f1c1ae6209eec986a01ff],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhlmghjmomaoodfgjeikphfdljhpcpkl\LOG.old, In Quarantäne, [3441acc8ec8f1c1ae6209eec986a01ff],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhlmghjmomaoodfgjeikphfdljhpcpkl\MANIFEST-002364, In Quarantäne, [3441acc8ec8f1c1ae6209eec986a01ff],
PUP.Optional.CrossRider.A, C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_hhlmghjmomaoodfgjeikphfdljhpcpkl_0\1, In Quarantäne, [e194650fdba08ea858af5931738f7090],
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=19ab1fd83fc6c941a57d20f56dabcc73
# engine=18552
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-06-04 01:50:07
# local_time=2014-06-04 03:50:07 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 33869 153520998 0 0
# scanned=11323
# found=37
# cleaned=0
# scan_time=472
sh=EA91A7B4AB2DE640BBDAE944E5F91E6C479DCDDF ft=1 fh=9996c0ea4bfd5a76 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\avira_free_antivirus_de.exe"
sh=71435DDB11E00D0243380C4902324853FE4ECE8F ft=1 fh=12b0cd2dde452d65 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ApnIC[1].0"
sh=E44D062204C9698F5C95651F2E424D37A31F5B15 ft=0 fh=0000000000000000 vn="Variante von Win32/Bundled.Toolbar.Ask.F potenziell unsichere Anwendung" ac=I fn="C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AskToolbarInstaller-AVIRA-V7[1].7z"
sh=567F7670AC05037B3D666088C2B25036098F2AA7 ft=0 fh=0000000000000000 vn="Variante von Win32/Bundled.Toolbar.Ask.F potenziell unsichere Anwendung" ac=I fn="C:\$WINDOWS.~Q\DATA\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AskToolbarInstaller-AVIRA-V7[2].7z"
sh=709DDDA530C3B99D0D3A168A13C659E6E33B5E6F ft=1 fh=347b57a574be47ba vn="Variante von Win32/Toolbar.Montiera.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\buenosearch LTD\buenosearch\1.8.28.7\buenosearchApp.dll.vir"
sh=103D4108A2DB9D2A9807AFE325277819FE9C8210 ft=1 fh=9ba40ad0f3418667 vn="möglicherweise Variante von Win32/Toolbar.Montiera.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\buenosearch LTD\buenosearch\1.8.28.7\buenosearchEng.dll.vir"
sh=7161DEDF77F089EC9F18D938578539604E3D19BA ft=1 fh=51e69ad137bde36c vn="Variante von Win32/Toolbar.Montiera.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\buenosearch LTD\buenosearch\1.8.28.7\buenosearchsrv.exe.vir"
sh=0C507C8C521AD1F2DC2DDA05455A4C067DDDA0D6 ft=1 fh=d7b118d85c3c98f0 vn="Variante von Win32/Toolbar.Montiera.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\buenosearch LTD\buenosearch\1.8.28.7\buenosearchTlbr.dll.vir"
sh=D4E496762425903D89311B727FCEC3B4DF7153E7 ft=1 fh=4d575f89f4e859f5 vn="Win32/Toolbar.Montiera.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\buenosearch LTD\buenosearch\1.8.28.7\uninstall.exe.vir"
sh=19C476FABB1B7C06079DF1E7A023EE556A0D8BAF ft=1 fh=53f848299ef89fdb vn="Variante von Win32/Toolbar.Escort.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\buenosearch LTD\buenosearch\1.8.28.7\bh\buenosearch.dll.vir"
sh=934580F56C6D22F48EB975648C3DB6485870938E ft=1 fh=1dee43825ec78b5e vn="Variante von Win32/Amonetize.X evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MediaViewV1\MediaViewV1alpha1699\uninstall.exe.vir"
sh=8E412C3173F26AA13DE956CD7F214E3867DC6D6B ft=1 fh=d116909f5ec78b5e vn="Variante von Win32/Amonetize.X evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\MediaViewV1\MediaViewV1alpha5797\uninstall.exe.vir"
sh=6BB87322CC04A1DE85408C4B3BECB03356230BE3 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Plus-HD-1.3\31257.crx.vir"
sh=D329A6E239ACD37CDE0407F88BC1F98386447CD6 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\Plus-HD-1.3\31257.xpi.vir"
sh=FABF99D84DAE1B16B0BDBA7003ACA991AE40DB47 ft=1 fh=2aca0aed277d57d6 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\SaveSenseLive\Update\SaveSenseLive.exe.vir"
sh=10903598F769E2AC5F1E2372E90F6722A3A860B7 ft=1 fh=89560075533c3d40 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll.vir"
sh=88482528CE4F67A1004B50BA93282CEACCEDE534 ft=1 fh=e40b702402e604d5 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\SaveSenseLive\Update\1.3.23.0\psmachine.dll.vir"
sh=FABF99D84DAE1B16B0BDBA7003ACA991AE40DB47 ft=1 fh=2aca0aed277d57d6 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\SaveSenseLive\Update\1.3.23.0\SaveSenseLive.exe.vir"
sh=70D49B9ABA391E6976DAB5C4BEA63733459B3F1C ft=1 fh=0b76a05977e7722a vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveBroker.exe.vir"
sh=FABF99D84DAE1B16B0BDBA7003ACA991AE40DB47 ft=1 fh=2aca0aed277d57d6 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHandler.exe.vir"
sh=F09B9B9B1D16D1539D23CC6ACDE0DC7BC983DF59 ft=1 fh=2dbadf99ca2df2d7 vn="Win32/SaveSense.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveOnDemand.exe.vir"
sh=189FC4DEFBF3AF52775F7A922789A0CA6A8FF6F8 ft=1 fh=4ed2a41f68ba7620 vn="Variante von Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\SupTab\SupTab.dll.vir"
sh=95D8C7F2851240F836D46EBD0DCB0BBAE3C9C3C8 ft=1 fh=c39b2415a29978f2 vn="Variante von Win32/ELEX.AD evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\IePluginService\PluginService.exe.vir"
sh=A57A0DBBB1F4509E15617380DE4A0D02B2751622 ft=1 fh=c71c001135f763b4 vn="Variante von Win32/ELEX.AE evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\WPM\wprotectmanager.exe.vir"
sh=7747A4AF95D60CB0E9636E483BBED8D1E94A3BCD ft=1 fh=d5b93855013f06e6 vn="Variante von Win32/Conduit.SearchProtect.N evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\geiche\AppData\Local\Conduit\Chrome\CT3317491\CHUninstaller.exe.vir"
sh=8E6A6992A3C7FEC4000FA1A4D764DD597109E0B5 ft=1 fh=c71c0011cd00713e vn="Win32/NextLive.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\geiche\AppData\Local\genienext\nengine.dll.vir"
sh=8CE29B8AB884C4365F82A7A8AFB62B296781C051 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb\1.26.28_0\extensionData\plugins\91.js.vir"
sh=723D315206A52C4CE6BE51080EAE93F13ACDBD86 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhlmghjmomaoodfgjeikphfdljhpcpkl\1.26.196_0\extensionData\plugins\194_retargeting_bi_m.js.js.vir"
sh=8F399BFA81BF493FF5FE7D4CD69A7C44E8EF1A6A ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhlmghjmomaoodfgjeikphfdljhpcpkl\1.26.196_0\extensionData\plugins\195_icm_convertmedia_m.js.vir"
sh=A7920DCAE31CAB7E2BAA6D10C4B2C540F5D87CF0 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhlmghjmomaoodfgjeikphfdljhpcpkl\1.26.196_0\extensionData\plugins\208_gam_manager.js.vir"
sh=0F33FFF12F6552F1790D3825DBB1B7A0D359EA56 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhlmghjmomaoodfgjeikphfdljhpcpkl\1.26.196_0\extensionData\plugins\217_similar_products_m.js.vir"
sh=932A0B84A1EE5590D4311A71FEE071A08166963C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhlmghjmomaoodfgjeikphfdljhpcpkl\1.26.196_0\extensionData\plugins\221_icm_downloads_m.js.vir"
sh=DC790DFB6D4E0C15D927A3B20EFC147F44D4F5E7 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhlmghjmomaoodfgjeikphfdljhpcpkl\1.26.196_0\extensionData\plugins\91_monetizationLoader.js.js.vir"
sh=82375A6153BE4F1F134E2E0A6077B67597E7F382 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhlmghjmomaoodfgjeikphfdljhpcpkl\1.26.196_0\extensionData\plugins\93_superfish_no_coupons_m.js.vir"
sh=1DA36F2CEBBB8BACCE6B13E4438FEEBCD11B284C ft=1 fh=72b5baba16092778 vn="Win32/Conduit.SearchProtect evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\kejlhopdgiicmagejpikgcinmicololf\10.31.0.526_0\APISupport\APISupport.dll.vir"
sh=119B91098847A205621FA7388C8B4A2FC134F0EB ft=1 fh=a4ebcb24189af321 vn="Variante von Win32/Toolbar.Conduit.AH evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\kejlhopdgiicmagejpikgcinmicololf\10.31.0.526_0\nativeMessaging\TBMessagingHost.exe.vir"
sh=8E6270F9DA8ECE45F03149274B3DBD370FF2F404 ft=1 fh=141990a027dc0992 vn="Variante von Win32/Conduit.SearchProtect.N evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\kejlhopdgiicmagejpikgcinmicololf\10.31.0.526_0\plugins\ChromeApiPlugin.dll.vir"
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:02-06-2014
Ran by geiche (administrator) on GEICHE-PC on 04-06-2014 16:00:18
Running from C:\Users\geiche\Downloads
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(ArcSoft, Inc.) C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe
(Adobe Systems) C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Nalpeiron Ltd.) C:\Windows\System32\nlssrv32.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
() C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe
(Avira) C:\Program Files\Avira\AviraSpeedup\avira_system_speedup.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.24.7\GoogleCrashHandler.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files\QuickTime\QTTask.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
(Samsung) C:\Program Files\Samsung\Kies\Kies.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\RPDS\Bin\rpsystray.exe
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
(MAGIX AG) C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Renesas Electronics Corporation) C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(RealNetworks, Inc.) C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe
(CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe
(cyberlink) C:\Program Files\CyberLink\Shared files\brs.exe
(CyberLink) C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe [5388904 2010-10-05] (Realtek Semiconductor)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-27] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [NWEReboot] => [X]
HKLM\...\Run: [TkBellExe] => c:\program files\real\realplayer\Update\realsched.exe [296520 2014-04-30] (RealNetworks, Inc.)
HKLM\...\Run: [LGODDFU] => blrun
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311616 2014-04-23] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-2917435617-3823699889-1472500709-1000\...\Run: [AviraSpeedup] => C:\Program Files\Avira\AviraSpeedup\avira_system_speedup.exe [5036600 2014-02-25] (Avira)
HKU\S-1-5-21-2917435617-3823699889-1472500709-1000\...\Run: [LightScribe Control Panel] => C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2741616 2011-03-04] (Hewlett-Packard Company)
HKU\S-1-5-21-2917435617-3823699889-1472500709-1000\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [22415552 2014-04-25] (Google)
HKU\S-1-5-21-2917435617-3823699889-1472500709-1000\...\Run: [Google Update] => C:\Users\geiche\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-09-12] (Google Inc.)
HKU\S-1-5-21-2917435617-3823699889-1472500709-1000\...\Run: [swg] => C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-08-30] (Google Inc.)
HKU\S-1-5-21-2917435617-3823699889-1472500709-1000\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [1564992 2014-04-23] (Samsung)
HKU\S-1-5-21-2917435617-3823699889-1472500709-1001\...\RunOnce: [WAB Migrate] - C:\Program Files\Windows Mail\wab.exe [516096 2010-11-20] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk
ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files\Real\RealPlayer\RPDS\Bin\rpsystray.exe (RealNetworks, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9420946AEBA4CE01
HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.msn.com/1me10IE11DEDE/MCM_WCP
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Tcpip\Parameters: [DhcpNameServer] 83.169.184.33 83.169.184.97
FireFox:
========
FF ProfilePath: C:\Users\geiche\AppData\Roaming\Mozilla\Firefox\Profiles\n1fi0cva.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin: @canon.com/MycameraPlugin - C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @real.com/nppl3260;version=17.0.9.17 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=17.0.9 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=17.0.9 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=17.0.9 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=17.0.9.17 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer Cloud)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\geiche\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\geiche\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\geiche\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\geiche\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\geiche\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\geiche\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-04-30]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-04-30]
FF HKLM\...\Firefox\Extensions: [{53D8DD28-1C83-41F3-B171-C2ED5B3E5DE8}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR Extension: (Avira SearchFree Toolbar plus Web Protection) - C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaacalgebmfelllfiaoknifldpngjh [2014-02-17]
CHR Extension: (Google Docs) - C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-17]
CHR Extension: (Google Drive) - C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-17]
CHR Extension: (YouTube) - C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-17]
CHR Extension: (Google-Suche) - C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-17]
CHR Extension: (Avira Browser Safety) - C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-03-22]
CHR Extension: (TinEye Reverse Image Search) - C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl [2014-03-24]
CHR Extension: (RealPlayer Downloader) - C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-03-03]
CHR Extension: (Google Wallet) - C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-17]
CHR Extension: (Google Mail) - C:\Users\geiche\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-17]
CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx [2014-02-21]
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2014-04-06]
========================== Services (Whitelisted) =================
R2 ADExchange; C:\Program Files\Common Files\ArcSoft\esinter\Bin\eservutil.exe [43072 2012-03-19] (ArcSoft, Inc.)
R2 AdobeActiveFileMonitor10.0; C:\Program Files\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [169624 2011-09-01] (Adobe Systems Incorporated)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-05-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-05-27] (Avira Operations GmbH & Co. KG)
S4 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] ()
S2 CLKMSVC10_B91CB6D3; C:\Program Files\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-04-20] (CyberLink)
R2 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG)
S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-04-06] ()
R2 RealPlayer Cloud Service; c:\program files\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2014-04-30] (RealNetworks, Inc.)
R2 RealPlayerUpdateSvc; C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe [23552 2014-04-07] ()
R2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [244904 2009-07-02] ()
S3 UPnPService; C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [544768 2006-12-14] (Magix AG)
S2 Adobe Version Cue CS2; "c:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service [X]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [93528 2014-05-27] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-05-27] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-31] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [69240 2013-12-18] (Avira Operations GmbH & Co. KG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-06-04] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation)
R3 MBfilt; C:\Windows\System32\drivers\MBfilt32.sys [24664 2009-11-18] (Creative Technology Ltd.)
R3 MEI; C:\Windows\System32\DRIVERS\HECI.sys [41088 2010-10-20] (Intel Corporation)
R3 MSI_DVD_010507; C:\Program Files\MSI\Live Update 5\DVDSYS32_100507.sys [22328 2010-05-10] (Your Corporation)
R3 MSI_MSIBIOS_010507; C:\Program Files\MSI\Live Update 5\msibios32_100507.sys [25912 2010-05-10] (Your Corporation)
R3 MSI_VGASYS_010507; C:\Program Files\MSI\Live Update 5\VGASYS32_100507.sys [16696 2010-05-10] ()
R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [60800 2010-07-27] (Renesas Electronics Corporation)
R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [140672 2010-07-27] (Renesas Electronics Corporation)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-10-31] (Avira GmbH)
S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [184192 2014-04-11] (DEVGURU Co., LTD.(www.devguru.co.kr))
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [14856 2010-05-21] ()
S3 cpuz134; \??\C:\Users\geiche\AppData\Local\Temp\cpuz134\cpuz134_x32.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-04 15:34 - 2014-06-04 15:34 - 02347384 _____ (ESET) C:\Users\geiche\Downloads\esetsmartinstaller_deu.exe
2014-06-04 15:22 - 2014-06-04 15:22 - 00037684 _____ () C:\Windows\PFRO.log
2014-06-04 15:01 - 2014-06-04 15:23 - 00058552 _____ () C:\Windows\setupact.log
2014-06-04 15:01 - 2014-06-04 15:01 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-04 14:31 - 2014-06-04 14:35 - 00402944 ___SH () C:\Users\geiche\Downloads\Thumbs.db
2014-06-04 12:40 - 2014-06-04 15:25 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-04 12:40 - 2014-06-04 15:08 - 00001070 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-04 12:40 - 2014-06-04 15:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-04 12:40 - 2014-06-04 15:08 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-04 12:40 - 2014-06-04 12:40 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-04 12:40 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-04 12:40 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-04 12:40 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-04 12:30 - 2014-06-04 12:30 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\geiche\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-04 12:28 - 2014-06-04 15:21 - 00054028 _____ () C:\Windows\WindowsUpdate.log
2014-06-04 06:35 - 2014-06-04 14:37 - 00064942 _____ () C:\Users\geiche\Downloads\Addition.txt
2014-06-04 06:34 - 2014-06-04 16:00 - 00019313 _____ () C:\Users\geiche\Downloads\FRST.txt
2014-06-04 06:33 - 2014-06-04 06:33 - 00000000 ____D () C:\Users\geiche\Downloads\FRST-OlderVersion
2014-06-04 06:21 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-06-04 06:20 - 2014-06-04 06:23 - 00000000 ____D () C:\AdwCleaner
2014-06-04 06:19 - 2014-06-04 06:20 - 01327971 _____ () C:\Users\geiche\Downloads\adwcleaner_3.211.exe
2014-06-03 08:48 - 2014-06-03 08:48 - 00380416 _____ () C:\Users\geiche\Downloads\Gmer-19357.exe
2014-06-03 08:44 - 2014-06-04 16:00 - 00000000 ____D () C:\FRST
2014-06-03 08:40 - 2014-06-03 08:40 - 00050477 _____ () C:\Users\geiche\Downloads\Defogger.exe
2014-06-01 09:48 - 2014-06-04 06:33 - 01059840 _____ (Farbar) C:\Users\geiche\Downloads\FRST.exe
2014-05-26 13:27 - 2014-05-26 13:27 - 00000000 ____D () C:\Program Files\Serif
2014-05-17 19:48 - 2014-05-17 19:48 - 00001144 _____ () C:\Users\geiche\Desktop\PortraitPro 12 Test.lnk
2014-05-17 19:48 - 2014-05-17 19:48 - 00000000 ____D () C:\Users\geiche\AppData\Roaming\Anthropics
2014-05-17 19:48 - 2014-05-17 19:48 - 00000000 ____D () C:\Users\geiche\AppData\Local\Anthropics
2014-05-17 19:48 - 2014-05-17 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PortraitPro 12 Test
2014-05-17 19:48 - 2014-05-17 19:48 - 00000000 ____D () C:\Program Files\PortraitPro 12 Test
2014-05-17 19:44 - 2014-05-17 19:44 - 76888904 _____ (Anthropics Technology Ltd. ) C:\Users\geiche\Downloads\PortraitProTrialSetup.exe
2014-05-16 13:44 - 2014-05-16 13:44 - 01746032 _____ (AnyProtect.com) C:\Users\geiche\AppData\Local\nsj8BDF.tmp
2014-05-15 05:48 - 2014-05-09 09:06 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-15 05:48 - 2014-05-09 09:04 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-15 05:47 - 2014-05-05 20:39 - 06041600 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-15 05:47 - 2014-05-05 20:39 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-15 05:47 - 2014-05-05 17:50 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-15 05:47 - 2014-04-12 04:15 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-15 05:47 - 2014-04-12 04:15 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-15 05:47 - 2014-04-12 04:12 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-15 05:47 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-05-15 05:47 - 2014-04-12 04:12 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-15 05:47 - 2014-04-12 04:11 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-15 05:47 - 2014-04-12 04:11 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-15 05:47 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-15 05:47 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2014-05-15 05:47 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-15 05:47 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-15 05:47 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-15 05:47 - 2014-03-04 11:17 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-15 05:47 - 2014-03-04 11:17 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-15 05:47 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-15 05:47 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-15 05:47 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-15 05:47 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-15 05:47 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-05-15 05:47 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-05-15 05:47 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-05-15 05:47 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-05-15 05:47 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-15 05:47 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-05-15 05:47 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 20:53 - 2014-05-14 20:53 - 00000000 ____D () C:\Users\geiche\AppData\Local\com
2014-05-13 14:23 - 2014-05-13 14:23 - 01746032 _____ (AnyProtect.com) C:\Users\geiche\AppData\Local\nspB31F.tmp
2014-05-11 13:04 - 2014-05-11 13:04 - 00000000 ____D () C:\Users\Public\Documents\NativeFus_Log
2014-05-11 13:03 - 2014-04-11 10:39 - 00184192 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudserd.sys
2014-05-11 13:03 - 2014-04-11 10:39 - 00184192 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys
2014-05-11 13:03 - 2014-04-11 10:39 - 00089856 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys
2014-05-11 13:01 - 2014-05-11 13:01 - 00000000 ____D () C:\Program Files\MarkAny
2014-05-11 13:00 - 2014-05-11 13:00 - 00001948 _____ () C:\Users\Public\Desktop\Samsung Kies.lnk
2014-05-11 13:00 - 2014-05-11 13:00 - 00000000 ____D () C:\Users\geiche\Documents\samsung
2014-05-11 13:00 - 2014-05-11 13:00 - 00000000 ____D () C:\Users\geiche\AppData\Roaming\Samsung
2014-05-11 13:00 - 2014-05-11 13:00 - 00000000 ____D () C:\Users\geiche\AppData\Local\Samsung
2014-05-11 12:38 - 2014-05-13 21:12 - 00000000 ____D () C:\Program Files\MyFree Codec
2014-05-11 12:38 - 2014-05-11 12:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2014-05-11 12:38 - 2014-01-23 18:23 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\system32\Redemption.dll
2014-05-11 12:38 - 2014-01-23 18:23 - 00144664 _____ (MAPILab Ltd. & Add-in Express Ltd.) C:\Windows\system32\secman.dll
2014-05-11 12:37 - 2014-05-11 12:39 - 00000000 ____D () C:\Program Files\Samsung
2014-05-11 12:37 - 2014-05-11 12:38 - 00000000 ____D () C:\ProgramData\Samsung
2014-05-11 12:37 - 2014-01-23 18:31 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\system32\dgderapi.dll
2014-05-11 12:34 - 2014-05-11 12:34 - 75397136 _____ (Samsung Electronics Co., Ltd.) C:\Users\geiche\Downloads\KiesSetup.exe
2014-05-10 11:16 - 2014-05-10 11:16 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-05-06 16:33 - 2014-05-16 05:38 - 00000000 ___SD () C:\Windows\system32\CompatTel
==================== One Month Modified Files and Folders =======
2014-06-04 16:00 - 2014-06-04 06:34 - 00019313 _____ () C:\Users\geiche\Downloads\FRST.txt
2014-06-04 16:00 - 2014-06-03 08:44 - 00000000 ____D () C:\FRST
2014-06-04 16:00 - 2014-02-16 14:10 - 00000000 ____D () C:\Users\geiche\AppData\Local\Temp
2014-06-04 15:40 - 2013-08-30 06:38 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-04 15:38 - 2010-11-20 23:01 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-04 15:34 - 2014-06-04 15:34 - 02347384 _____ (ESET) C:\Users\geiche\Downloads\esetsmartinstaller_deu.exe
2014-06-04 15:31 - 2009-07-14 06:34 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-04 15:31 - 2009-07-14 06:34 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-04 15:28 - 2014-06-04 12:28 - 00054028 _____ () C:\Windows\WindowsUpdate.log
2014-06-04 15:25 - 2014-06-04 12:40 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-04 15:25 - 2014-03-14 21:48 - 00000000 ___RD () C:\Users\geiche\Google Drive
2014-06-04 15:24 - 2013-08-30 06:38 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-04 15:23 - 2014-06-04 15:01 - 00058552 _____ () C:\Windows\setupact.log
2014-06-04 15:23 - 2014-02-16 14:09 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-06-04 15:23 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-04 15:22 - 2014-06-04 15:22 - 00037684 _____ () C:\Windows\PFRO.log
2014-06-04 15:21 - 2011-04-12 03:29 - 00000000 ____D () C:\Windows\DigitalLocker
2014-06-04 15:20 - 2013-09-12 14:48 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2917435617-3823699889-1472500709-1000UA.job
2014-06-04 15:18 - 2013-08-30 06:39 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-04 15:08 - 2014-06-04 12:40 - 00001070 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-04 15:08 - 2014-06-04 12:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-04 15:08 - 2014-06-04 12:40 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-04 15:01 - 2014-06-04 15:01 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-04 14:37 - 2014-06-04 06:35 - 00064942 _____ () C:\Users\geiche\Downloads\Addition.txt
2014-06-04 14:35 - 2014-06-04 14:31 - 00402944 ___SH () C:\Users\geiche\Downloads\Thumbs.db
2014-06-04 12:40 - 2014-06-04 12:40 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-04 12:30 - 2014-06-04 12:30 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\geiche\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-04 12:25 - 2014-01-30 09:46 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-06-04 12:23 - 2009-07-14 04:37 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-06-04 07:20 - 2013-09-12 14:48 - 00001072 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2917435617-3823699889-1472500709-1000Core.job
2014-06-04 06:33 - 2014-06-04 06:33 - 00000000 ____D () C:\Users\geiche\Downloads\FRST-OlderVersion
2014-06-04 06:33 - 2014-06-01 09:48 - 01059840 _____ (Farbar) C:\Users\geiche\Downloads\FRST.exe
2014-06-04 06:23 - 2014-06-04 06:20 - 00000000 ____D () C:\AdwCleaner
2014-06-04 06:22 - 2014-02-17 13:10 - 00001246 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-04 06:22 - 2014-02-17 13:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-06-04 06:22 - 2014-02-16 14:10 - 00000000 ____D () C:\Users\geiche
2014-06-04 06:20 - 2014-06-04 06:19 - 01327971 _____ () C:\Users\geiche\Downloads\adwcleaner_3.211.exe
2014-06-03 08:48 - 2014-06-03 08:48 - 00380416 _____ () C:\Users\geiche\Downloads\Gmer-19357.exe
2014-06-03 08:40 - 2014-06-03 08:40 - 00050477 _____ () C:\Users\geiche\Downloads\Defogger.exe
2014-06-02 13:39 - 2014-03-13 15:12 - 00000000 ____D () C:\Users\geiche\AppData\Roaming\XnView
2014-05-27 12:16 - 2013-11-15 21:00 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-05-27 12:16 - 2013-11-15 21:00 - 00093528 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-05-26 13:27 - 2014-05-26 13:27 - 00000000 ____D () C:\Program Files\Serif
2014-05-21 05:22 - 2013-09-10 15:04 - 00000000 ____D () C:\Users\geiche\AppData\Roaming\Mozilla
2014-05-19 07:57 - 2013-12-19 21:13 - 00000000 ____D () C:\Users\geiche\AppData\Roaming\vlc
2014-05-17 19:48 - 2014-05-17 19:48 - 00001144 _____ () C:\Users\geiche\Desktop\PortraitPro 12 Test.lnk
2014-05-17 19:48 - 2014-05-17 19:48 - 00000000 ____D () C:\Users\geiche\AppData\Roaming\Anthropics
2014-05-17 19:48 - 2014-05-17 19:48 - 00000000 ____D () C:\Users\geiche\AppData\Local\Anthropics
2014-05-17 19:48 - 2014-05-17 19:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PortraitPro 12 Test
2014-05-17 19:48 - 2014-05-17 19:48 - 00000000 ____D () C:\Program Files\PortraitPro 12 Test
2014-05-17 19:44 - 2014-05-17 19:44 - 76888904 _____ (Anthropics Technology Ltd. ) C:\Users\geiche\Downloads\PortraitProTrialSetup.exe
2014-05-16 13:44 - 2014-05-16 13:44 - 01746032 _____ (AnyProtect.com) C:\Users\geiche\AppData\Local\nsj8BDF.tmp
2014-05-16 06:32 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-05-16 06:16 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-05-16 05:43 - 2013-09-02 07:43 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-16 05:38 - 2014-05-06 16:33 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-05-16 05:38 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-05-15 21:59 - 2014-03-22 15:02 - 90547776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-15 05:46 - 2013-08-30 19:17 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-05-14 20:53 - 2014-05-14 20:53 - 00000000 ____D () C:\Users\geiche\AppData\Local\com
2014-05-14 15:40 - 2013-08-30 06:38 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-05-14 15:40 - 2013-08-30 06:38 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-05-13 21:12 - 2014-05-11 12:38 - 00000000 ____D () C:\Program Files\MyFree Codec
2014-05-13 14:23 - 2014-05-13 14:23 - 01746032 _____ (AnyProtect.com) C:\Users\geiche\AppData\Local\nspB31F.tmp
2014-05-12 07:26 - 2014-06-04 12:40 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-06-04 12:40 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:25 - 2014-06-04 12:40 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-11 13:04 - 2014-05-11 13:04 - 00000000 ____D () C:\Users\Public\Documents\NativeFus_Log
2014-05-11 13:01 - 2014-05-11 13:01 - 00000000 ____D () C:\Program Files\MarkAny
2014-05-11 13:00 - 2014-05-11 13:00 - 00001948 _____ () C:\Users\Public\Desktop\Samsung Kies.lnk
2014-05-11 13:00 - 2014-05-11 13:00 - 00000000 ____D () C:\Users\geiche\Documents\samsung
2014-05-11 13:00 - 2014-05-11 13:00 - 00000000 ____D () C:\Users\geiche\AppData\Roaming\Samsung
2014-05-11 13:00 - 2014-05-11 13:00 - 00000000 ____D () C:\Users\geiche\AppData\Local\Samsung
2014-05-11 12:39 - 2014-05-11 12:37 - 00000000 ____D () C:\Program Files\Samsung
2014-05-11 12:38 - 2014-05-11 12:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2014-05-11 12:38 - 2014-05-11 12:37 - 00000000 ____D () C:\ProgramData\Samsung
2014-05-11 12:37 - 2013-08-29 20:49 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-05-11 12:36 - 2013-12-16 23:11 - 00000000 ____D () C:\Users\geiche\AppData\Local\Downloaded Installations
2014-05-11 12:34 - 2014-05-11 12:34 - 75397136 _____ (Samsung Electronics Co., Ltd.) C:\Users\geiche\Downloads\KiesSetup.exe
2014-05-11 06:06 - 2014-04-29 19:28 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-05-10 11:16 - 2014-05-10 11:16 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-05-09 09:06 - 2014-05-15 05:48 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-05-09 09:04 - 2014-05-15 05:48 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-09 06:19 - 2014-03-14 21:39 - 00002006 _____ () C:\Users\Public\Desktop\Google Slides.lnk
2014-05-09 06:19 - 2014-03-14 21:39 - 00002004 _____ () C:\Users\Public\Desktop\Google Sheets.lnk
2014-05-09 06:19 - 2014-03-14 21:39 - 00001994 _____ () C:\Users\Public\Desktop\Google Docs.lnk
2014-05-09 06:19 - 2014-03-14 21:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-05-06 05:44 - 2009-07-14 06:33 - 02323952 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-05-05 20:39 - 2014-05-15 05:47 - 06041600 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-05 20:39 - 2014-05-15 05:47 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-05 17:50 - 2014-05-15 05:47 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-05 15:29 - 2014-02-16 15:08 - 00780808 _____ () C:\Users\geiche\AppData\Local\GDIPFONTCACHEV1.DAT
Some content of TEMP:
====================
C:\Users\geiche\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-29 08:18
==================== End Of Log ============================ --- --- ---
--- --- --- |