Ronsen1965 | 03.08.2014 18:27 | mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 03.08.2014
Suchlauf-Zeit: 18:37:10
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.08.03.05
Rootkit Datenbank: v2014.08.01.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Cheffe
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 550706
Verstrichene Zeit: 16 Min, 44 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 12
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [5bd605bd6417c571c1b546548f739769],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [5bd605bd6417c571c1b546548f739769],
PUP.Optional.WebCake.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899}, In Quarantäne, [49e8259d611abc7a91e93367ff039e62],
PUP.Optional.WebCake.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DF84E609-C3A4-49CB-A160-61767DAF8899}, In Quarantäne, [49e8259d611abc7a91e93367ff039e62],
PUP.Optional.FaceMoods.A, HKU\S-1-5-21-4214647680-1892321443-2594664937-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0D7562AE-8EF6-416d-A838-AB665251703A}, In Quarantäne, [2e03e7db710a8ea8cc69382c41c144bc],
PUP.Optional.Babylon.A, HKU\S-1-5-21-4214647680-1892321443-2594664937-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, In Quarantäne, [5cd5ac16f3880a2c0ef54f12e22015eb],
PUP.Optional.FunMoods.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLCORE\funmoods, In Quarantäne, [35fc8f3333485bdbcc0c2bc746bd659b],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-4214647680-1892321443-2594664937-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, In Quarantäne, [f73afbc70d6e2c0a0c138b887094ea16],
PUP.FunMoods, HKU\S-1-5-21-4214647680-1892321443-2594664937-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Funmoods, In Quarantäne, [052c8c36700bc5717833699afe05e61a],
PUP.FunMoods, HKU\S-1-5-21-4214647680-1892321443-2594664937-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\funmoods, In Quarantäne, [33fe16ac63183ff7bfed996a5ea5ae52],
PUP.Optional.VideoPerformer.A, HKU\S-1-5-21-4214647680-1892321443-2594664937-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\PERFORMERSOFT LLC\Video Performer, In Quarantäne, [5ed38939dc9fa6903ec2fed77b8711ef],
PUP.Optional.Softonic.A, HKU\S-1-5-21-4214647680-1892321443-2594664937-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [cb663c86cbb057df5273767410f26e92],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 3
PUP.Optional.FaceMoods.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4, Gut: (www.google.com), Schlecht: (hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4),Ersetzt,[2d04b210443771c5a4b409b6a361d32d]
PUP.Optional.StartPage, HKU\S-1-5-21-4214647680-1892321443-2594664937-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www2.delta-search.com/?babsrc=HP_ss&mntrId=F4150019663E67BE&affID=123477&tsp=4995, Gut: (www.google.com), Schlecht: (hxxp://www2.delta-search.com/?babsrc=HP_ss&mntrId=F4150019663E67BE&affID=123477&tsp=4995),Ersetzt,[e34e962ce497ec4a839ea618b74d60a0]
PUM.Hijack.StartMenu, HKU\S-1-5-21-4214647680-1892321443-2594664937-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED|Start_ShowMyComputer, 0, Gut: (1), Schlecht: (0),Ersetzt,[ad84576b5b205dd96a6a2f8b53b1e61a]
Ordner: 6
PUP.Optional.SpeedAnalysis3.A, C:\Users\Cheffe\AppData\Roaming\SpeedAnalysis3, In Quarantäne, [89a88d352f4cf442591df320996b10f0],
PUP.Optional.FileScout.A, C:\Users\Cheffe\AppData\Roaming\File Scout, In Quarantäne, [6ac7952d0873c670fce226870df5c937],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\hdvidcodec.com, In Quarantäne, [a889972bde9dda5cdc58f5ba12f08f71],
PUP.Optional.FaceMoods.A, C:\Users\Gastzgang\AppData\LocalLow\facemoods.com, In Quarantäne, [86abd0f2314ae452dd25b302a55dcd33],
PUP.Optional.FaceMoods.A, C:\Users\Gastzgang\AppData\LocalLow\facemoods.com\facemoods, In Quarantäne, [86abd0f2314ae452dd25b302a55dcd33],
PUP.Optional.IBUpdater.A, C:\ProgramData\IBUpdaterService, In Quarantäne, [b081dde5de9d5cdaa63dbf0be61c02fe],
Dateien: 32
PUP.Optional.FileScout.A, C:\Users\Cheffe\AppData\Roaming\File Scout\filescout.exe, In Quarantäne, [131ead15463567cf017d33decb3616ea],
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, In Quarantäne, [f43d0bb74a31b284915e26fa758b04fc],
RiskWare.Tool.CK, C:\Windows\KMSAct.exe, In Quarantäne, [59d8e0e294e7fa3cd52b3aa9010057a9],
PUP.Optional.FunMoods.A, C:\Windows\System32\Tasks\Funmoods, In Quarantäne, [a58cdfe36e0daf87090f1fb844be837d],
PUP.Optional.FunMoods.A, C:\Users\Cheffe\AppData\Roaming\Funmoods\UpdateProc\UpdateTask.exe, In Quarantäne, [8ea3ccf64e2d0135e7aa2dc4798ac13f],
PUP.Optional.SpeedAnalysis2.A, C:\Users\Cheffe\AppData\Roaming\speedanalysis.ico, In Quarantäne, [4ae7f4ceff7c2610b20d50c28a7a2bd5],
PUP.Optional.SpeedAnalysis3.A, C:\Users\Cheffe\AppData\Roaming\SpeedAnalysis3\speedanalysis.crx, In Quarantäne, [89a88d352f4cf442591df320996b10f0],
PUP.Optional.FileScout.A, C:\Users\Cheffe\AppData\Roaming\File Scout\uninst.exe, In Quarantäne, [6ac7952d0873c670fce226870df5c937],
PUP.Optional.IBUpdater.A, C:\ProgramData\IBUpdaterService\repository.xml, In Quarantäne, [b081dde5de9d5cdaa63dbf0be61c02fe],
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.admin", false);), Ersetzt,[d35e3d8586f554e2e1ea648ab1538779]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.aflt", "babsst");), Ersetzt,[71c0942efb80e6501fac96581aea10f0]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");), Ersetzt,[121fbd056d0e3600943715d96a9a9f61]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.autoRvrt", "false");), Ersetzt,[53de9a28e69588aee8e3c529db29b749]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.dfltLng", "de");), Ersetzt,[220f2e94d8a3d66029a200ee9d678080]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.excTlbr", false);), Ersetzt,[3bf609b90b70d75f408b38b638cc9e62]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.ffxUnstlRst", true);), Ersetzt,[5ed3536f6417c86ef7d4a24cbd47e21e]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.id", "f415f8e10000000000000019663e67be");), Ersetzt,[de53e4de5a21c571705bf5f9cc3860a0]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.instlDay", "15952");), Ersetzt,[e84931911764320427a400ee897b946c]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.instlRef", "sst");), Ersetzt,[66cbe4de17642b0b814af8f6956fb14f]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.newTab", false);), Ersetzt,[8da44e744b3053e3cefd20ce60a4cc34]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.prdct", "delta");), Ersetzt,[33fe378b1c5f96a01bb0c42a08fcde22]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.prtnrId", "delta");), Ersetzt,[fd34ae140c6f9e987655fbf3be46c43c]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.rvrt", "false");), Ersetzt,[3af7259d572473c32f9c8965f50f718f]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.smplGrp", "none");), Ersetzt,[1d145f63e8931422cffc3eb0bb4911ef]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.tlbrId", "base");), Ersetzt,[73bef4ced6a57fb7fccf529c5ca8e61a]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.tlbrSrchUrl", "");), Ersetzt,[5dd4546e611afa3c0ebd846af90b02fe]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsn", "1.8.24.6");), Ersetzt,[83aed2f0b7c467cf29a27a74d33111ef]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsnTs", "1.8.24.619:20:35");), Ersetzt,[250cf9c9bcbf71c59a31c02eea1a659b]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsni", "1.8.24.6");), Ersetzt,[56db3a8848330c2a01caab43dd275da3]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta_i.babExt", "");), Ersetzt,[ab86d3ef79023006517ab9357e86f010]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta_i.babTrack", "affID=123477&tsp=4995");), Ersetzt,[76bbb70b0b7050e611ba1dd112f260a0]
PUP.Optional.Delta.A, C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta_i.srcExt", "ss");), Ersetzt,[062b1aa8562537ffcefd20ce7c8829d7]
Physische Sektoren: 0
(No malicious items detected)
(end) AdwCleaner.txt Code:
# AdwCleaner v3.302 - Bericht erstellt am 03/08/2014 um 19:08:05
# Aktualisiert 30/07/2014 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzername : Cheffe - CHEFFE-PC
# Gestartet von : C:\Users\Cheffe\Downloads\Rechner\2adwcleaner_3.302.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Users\Cheffe\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Cheffe\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Cheffe\AppData\Roaming\Funmoods
Ordner Gelöscht : C:\Users\Cheffe\AppData\Roaming\PerformerSoft
Datei Gelöscht : C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
Datei Gelöscht : C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\Extensions\hdvc@hdvc.com.xpi
Datei Gelöscht : C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\invalidprefs.js
Datei Gelöscht : C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\user.js
***** [ Tasks ] *****
Task Gelöscht : Funmoods
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\gjajpkikblccgefaibcafkfbanllpefi
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\kpkbnefaikfaeadgidhpoanckoiaheli
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\*\shell\filescout
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyDeltaTB_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyDeltaTB_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\startnow_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\startnow_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\YontooDesktop_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_google-play-store-apk_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_google-play-store-apk_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_sview5_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_sview5_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_unity-web-player_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_unity-web-player_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_vnc_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_vnc_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0AFD55C8-ADF8-4A33-A6E1-DEDB7A36AEB4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\filescout
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\performersoft llc
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKLM\Software\Cheat Engine\OpenCandy
Schlüssel Gelöscht : HKLM\Software\Delta
Schlüssel Gelöscht : HKLM\Software\Driver-Soft
Schlüssel Gelöscht : HKLM\Software\InstallCore
Schlüssel Gelöscht : HKLM\Software\Myfree Codec
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16421
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.delta.admin", false);
Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.dfltLng", "de");
Zeile gelöscht : user_pref("extensions.delta.excTlbr", false);
Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true);
Zeile gelöscht : user_pref("extensions.delta.id", "f415f8e10000000000000019663e67be");
Zeile gelöscht : user_pref("extensions.delta.instlDay", "15952");
Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.delta.newTab", false);
Zeile gelöscht : user_pref("extensions.delta.prdct", "delta");
Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta");
Zeile gelöscht : user_pref("extensions.delta.rvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.24.6");
Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.24.619:20:35");
Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.24.6");
Zeile gelöscht : user_pref("extensions.delta_i.babExt", "");
Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=123477&tsp=4995");
Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss");
Zeile gelöscht : user_pref("extensions.funmoods.aflt", "nv2");
Zeile gelöscht : user_pref("extensions.funmoods.appId", "{EA28B360-05E0-4F93-8150-02891F1D8D3C}");
Zeile gelöscht : user_pref("extensions.funmoods.brwsrsrc", "ietlbr");
Zeile gelöscht : user_pref("extensions.funmoods.cntry", "DE");
Zeile gelöscht : user_pref("extensions.funmoods.cv", "cv5");
Zeile gelöscht : user_pref("extensions.funmoods.dfltLng", "");
Zeile gelöscht : user_pref("extensions.funmoods.dfltSrch", true);
Zeile gelöscht : user_pref("extensions.funmoods.dfltlng", "en");
Zeile gelöscht : user_pref("extensions.funmoods.dfltsrch", true);
Zeile gelöscht : user_pref("extensions.funmoods.dnsErr", true);
Zeile gelöscht : user_pref("extensions.funmoods.envrmnt", "production");
Zeile gelöscht : user_pref("extensions.funmoods.excTlbr", false);
Zeile gelöscht : user_pref("extensions.funmoods.hdrMd5", "D1EC28F94210E4B4595D958DD7F8DD88");
Zeile gelöscht : user_pref("extensions.funmoods.hmpg", true);
Zeile gelöscht : user_pref("extensions.funmoods.hmpgUrl", "hxxp://searchfunmoods.com/?f=1&a=nv2&cd=2XzuyEtN2Y1L1QzutDtDtCzyyCyCtA0EyCyB0B0E0Fzz0EtCtN0D0Tzu0CyEzzyCtN1L2XzutBtFtBtFtCtFyDyByBtN1L1Czu1G2XtB&cr=1538510608[...]
Zeile gelöscht : user_pref("extensions.funmoods.hrdid", "0019663E67BEF8E1");
Zeile gelöscht : user_pref("extensions.funmoods.id", "0019663E67BEF8E1");
Zeile gelöscht : user_pref("extensions.funmoods.instlDay", "15825");
Zeile gelöscht : user_pref("extensions.funmoods.instlRef", "");
Zeile gelöscht : user_pref("extensions.funmoods.instlday", "15825");
Zeile gelöscht : user_pref("extensions.funmoods.instlref", "");
Zeile gelöscht : user_pref("extensions.funmoods.isdcmntcmplt", "false");
Zeile gelöscht : user_pref("extensions.funmoods.keywordurl", "");
Zeile gelöscht : user_pref("extensions.funmoods.mntrvrsn", "1.3.0");
Zeile gelöscht : user_pref("extensions.funmoods.monitorreport", true);
Zeile gelöscht : user_pref("extensions.funmoods.newTabUrl", "hxxp://searchfunmoods.com/?f=2&a=nv2&cd=2XzuyEtN2Y1L1QzutDtDtCzyyCyCtA0EyCyB0B0E0Fzz0EtCtN0D0Tzu0CyEzzyCtN1L2XzutBtFtBtFtCtFyDyByBtN1L1Czu1G2XtB&cr=15385106[...]
Zeile gelöscht : user_pref("extensions.funmoods.newtab", "false");
Zeile gelöscht : user_pref("extensions.funmoods.newtaburl", "hxxp://searchfunmoods.com/?f=2&a=nv2&cd=2XzuyEtN2Y1L1QzutDtDtCzyyCyCtA0EyCyB0B0E0Fzz0EtCtN0D0Tzu0CyEzzyCtN1L2XzutBtFtBtFtCtFyDyByBtN1L1Czu1G2XtB&cr=15385106[...]
Zeile gelöscht : user_pref("extensions.funmoods.prdct", "funmoods");
Zeile gelöscht : user_pref("extensions.funmoods.prtnrId", "funmoods");
Zeile gelöscht : user_pref("extensions.funmoods.prtnrid", "funmoods");
Zeile gelöscht : user_pref("extensions.funmoods.savedVrsnTs", "1");
Zeile gelöscht : user_pref("extensions.funmoods.sg", "none");
Zeile gelöscht : user_pref("extensions.funmoods.smplgrp", "free");
Zeile gelöscht : user_pref("extensions.funmoods.srch", "");
Zeile gelöscht : user_pref("extensions.funmoods.srchPrvdr", "Funmoods");
Zeile gelöscht : user_pref("extensions.funmoods.srchprvdr", "Funmoods");
Zeile gelöscht : user_pref("extensions.funmoods.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://searchfunmoods.com/?f=3&a=nv2&cd=2XzuyEtN2Y1L1QzutDtDtCzyyCyCtA0EyCyB0B0E0Fzz0EtCtN0D0Tzu0CyEzzyCtN1L2XzutBtFtBtFtCtFyDyByBtN1L1Czu1G2XtB&cr=153851[...]
Zeile gelöscht : user_pref("extensions.funmoods.tlbrid", "base");
Zeile gelöscht : user_pref("extensions.funmoods.tlbrsrchurl", "hxxp://searchfunmoods.com/?f=3&a=nv2&cd=2XzuyEtN2Y1L1QzutDtDtCzyyCyCtA0EyCyB0B0E0Fzz0EtCtN0D0Tzu0CyEzzyCtN1L2XzutBtFtBtFtCtFyDyByBtN1L1Czu1G2XtB&cr=153851[...]
Zeile gelöscht : user_pref("extensions.funmoods.vrsn", "1.8.11.0");
Zeile gelöscht : user_pref("extensions.funmoods.vrsni", "1.8.11.0");
Zeile gelöscht : user_pref("extensions.funmoods.vrsnts", "");
Zeile gelöscht : user_pref("extensions.funmoods.xpestat\\xpereportdata", "30-3-2013");
Zeile gelöscht : user_pref("extensions.funmoods_i.hmpg", true);
Zeile gelöscht : user_pref("extensions.funmoods_i.newTab", false);
Zeile gelöscht : user_pref("extensions.funmoods_i.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.funmoods_i.vrsnTs", "1.8.11.020:44:5");
[ Datei : C:\Users\Gastzgang\AppData\Roaming\Mozilla\Firefox\Profiles\rfxfh48u.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [12722 octets] - [03/08/2014 19:05:29]
AdwCleaner[S0].txt - [12206 octets] - [03/08/2014 19:08:05]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12267 octets] ########## JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Ultimate x64
Ran by Cheffe on 03.08.2014 at 19:14:40,99
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\ProgramData\drivergenius"
Successfully deleted: [Folder] "C:\Program Files (x86)\myfree codec"
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{03DA89E3-326B-44BC-A16A-C1A447AD15CD}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{219C6AF2-937C-4070-9EA1-6FD0165F8939}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{25F5F65C-6913-4E5F-95CA-117EA2DC743D}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{2650DE3F-70FC-4309-ACCB-5FA211ECF8F4}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{32A6DB54-ECE6-44B8-9754-C19C2056ED7A}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{488F61A2-B9BE-42AA-B4EC-3BEA9A28C45F}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{7A1F54FC-659A-452B-8004-71444FF60973}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{83DBE566-B111-4B62-A735-601F95272D57}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{85954259-CEEF-4B07-84CA-6AF943DDE096}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{8693CA77-9839-4FB2-B7DF-36C003E8E6AA}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{8772ABCD-5CCA-4C43-8EAF-3FEF21A7DD39}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{87F9BA6A-0AEE-4448-AF5D-79ACB9B47620}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{882F192C-8997-4AAB-8781-7389B5C0E4F6}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{97C7D9C9-2D44-4F9A-8475-C02F9F114FEB}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{A14D1E65-18F6-48CF-A381-08EF141B1F42}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{A343FE3A-93A1-466D-844C-D4772086CC80}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{AA59091D-4AA2-4D27-8044-1E83C6F479FC}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{B726CC47-F7A7-4830-B519-C801C5D116CF}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{B73E42B1-1CB5-4DA7-9D16-474C614B1A40}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{E4A4A3E3-4FA7-47D5-8CDE-4DFD35801BB5}
Successfully deleted: [Empty Folder] C:\Users\Cheffe\appdata\local\{F1403061-F552-4126-AFC0-354E9DB21FC6}
~~~ FireFox
Emptied folder: C:\Users\Cheffe\AppData\Roaming\mozilla\firefox\profiles\fbjdsa0o.default\minidumps [154 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.08.2014 at 19:22:36,58
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-08-2014
Ran by Cheffe (administrator) on CHEFFE-PC on 03-08-2014 19:24:19
Running from C:\Users\Cheffe\Downloads\Rechner
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7Debug\mdm.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero MediaHome 4\NMMediaServerService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Rocket Division Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
() C:\Program Files (x86)\VIA\RAID\vialogsv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 4620 series\Bin\HPNetworkCommunicator.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-01-08] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10144288 2010-04-06] (Realtek Semiconductor)
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe [344736 2010-05-07] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31072 2008-10-25] (Microsoft Corporation)
HKLM-x32\...\Run: [Nero MediaHome 4] => C:\Program Files (x86)\Nero\Nero MediaHome 4\NeroMediaHome.exe [5178664 2012-02-28] (Nero AG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-01-20] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-11-06] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-01-20] (Apple Inc.)
HKLM-x32\...\Run: [CloneCDTray] => C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-30] (SlySoft, Inc.)
Winlogon\Notify\klogon: C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)
HKU\S-1-5-21-4214647680-1892321443-2594664937-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1754816 2014-05-29] (Valve Corporation)
HKU\S-1-5-21-4214647680-1892321443-2594664937-1000\...\Run: [HP Officejet 4620 series (NET) #2] => C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe [2548072 2011-12-18] (Hewlett-Packard Co.)
HKU\S-1-5-21-4214647680-1892321443-2594664937-1000\...\Run: [MyTomTomSA.exe] => C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe [455608 2013-05-23] (TomTom)
HKU\S-1-5-21-4214647680-1892321443-2594664937-1000\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564528 2013-11-06] (Samsung)
HKU\S-1-5-21-4214647680-1892321443-2594664937-1000\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3595608 2014-07-26] (Electronic Arts)
AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\sbhook64.dll [71864 2010-05-07] (Kaspersky Lab ZAO)
AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1\x64\kloehk.dll => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\kloehk.dll [15544 2010-05-07] (Kaspersky Lab ZAO)
AppInit_DLLs-x32: C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\mzvkbd3.dll [109240 2010-05-07] (Kaspersky Lab ZAO)
AppInit_DLLs-x32: C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\sbhook.dll [76472 2010-05-07] (Kaspersky Lab ZAO)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Biet-O-Matic.lnk
ShortcutTarget: Biet-O-Matic.lnk -> C:\Program Files (x86)\Biet-O-Matic\Biet-O-Matic.exe (www.bid-o-matic.org)
Startup: C:\Users\Cheffe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 4620 series (Netzwerk).lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 4620 series (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet 4620 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\Cheffe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 4620 series (Netzwerkkopie 1).lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 4620 series (Netzwerkkopie 1).lnk -> C:\Program Files\HP\HP Officejet 4620 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xDE9FDA266CBACC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: IEVkbdBHO Class -> {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\ievkbd.dll (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: FilterBHO Class -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: IEVkbdBHO Class -> {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: FilterBHO Class -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default
FF Homepage: hxxp://www.t-online.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.7.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.7.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Cheffe\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: @www.flatcast.com/FlatViewer 5.2 - C:\Users\Cheffe\AppData\Roaming\Mozilla\Plugins\NpFv530.dll (1 mal 1 Software GmbH)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NpFv530.dll (1 mal 1 Software GmbH)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Cheffe\AppData\Roaming\mozilla\plugins\NpFv530.dll (1 mal 1 Software GmbH)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: iMacros for Firefox - C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\Extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670} [2014-05-26]
FF Extension: Secure Login - C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\Extensions\secureLogin@blueimp.net.xpi [2011-07-01]
FF Extension: FlashGot - C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2011-05-12]
FF Extension: Biet-O-Matic Firefox Erweiterung - C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\Extensions\{B0D70E72-2FC1-4b9f-A3D4-5921C854D906}.xpi [2011-07-31]
FF Extension: Adblock Plus - C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-05-14]
FF Extension: Download Manager Tweak - C:\Users\Cheffe\AppData\Roaming\Mozilla\Firefox\Profiles\fbjdsa0o.default\Extensions\{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}.xpi [2012-05-06]
FF Extension: Kaspersky Anti-Banner - C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru [2011-01-04]
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru [2011-01-04]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2012-08-04]
FF HKLM-x32\...\Thunderbird\Extensions: [{eea12ec4-729d-4703-bc37-106ce9879ce2}] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\THBExt
FF Extension: Kaspersky Anti-Spam Extension - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\THBExt [2011-01-04]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe [344736 2010-05-07] (Kaspersky Lab ZAO)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 NeroMediaHomeService.4; C:\Program Files (x86)\Nero\Nero MediaHome 4\NMMediaServerService.exe [517416 2012-02-28] (Nero AG)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [275968 2007-05-28] (Rocket Division Software) [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 VRAID Log Service; C:\Program Files (x86)\VIA\RAID\vialogsv.exe [52888 2008-09-24] () [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 DFX11_1; C:\Windows\System32\drivers\dfx11_1x64.sys [28008 2012-08-30] (Windows (R) Win 7 DDK provider)
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-07-18] () [File not signed]
S3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [460800 2010-10-22] (AVM GmbH)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [460888 2010-05-07] (Kaspersky Lab ZAO)
S1 kl2; C:\Windows\System32\DRIVERS\kl2.sys [460888 2010-05-07] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [560216 2011-01-04] (Kaspersky Lab)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [27736 2010-04-22] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [22544 2009-11-02] (Kaspersky Lab)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [868848 2010-12-31] (Duplex Secure Ltd.)
R0 viamrx64; C:\Windows\System32\DRIVERS\viamrx64.sys [157336 2008-09-26] (VIA Technologies Inc.,Ltd)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 dgderdrv; System32\drivers\dgderdrv.sys [X]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-03 19:22 - 2014-08-03 19:22 - 00003409 _____ () C:\Users\Cheffe\Desktop\JRT.txt
2014-08-03 19:14 - 2014-08-03 19:14 - 00000000 ____D () C:\Windows\ERUNT
2014-08-03 19:05 - 2014-08-03 19:08 - 00000000 ____D () C:\AdwCleaner
2014-08-03 18:35 - 2014-08-03 19:12 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-03 18:34 - 2014-08-03 18:34 - 00001066 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-03 18:34 - 2014-08-03 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-03 18:34 - 2014-08-03 18:34 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-03 18:34 - 2014-08-03 18:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-03 18:34 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-03 18:34 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-03 18:34 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-03 18:18 - 2014-07-25 15:50 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-08-03 18:18 - 2014-07-25 15:50 - 01291280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2014-08-03 18:17 - 2014-03-31 18:42 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-08-03 18:17 - 2014-03-31 18:42 - 00034760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-07-28 18:50 - 2014-07-28 18:50 - 00022137 _____ () C:\ComboFix.rar
2014-07-28 18:48 - 2014-07-28 18:48 - 00024286 _____ () C:\ComboFix.zip
2014-07-28 18:10 - 2014-07-28 18:10 - 00304030 _____ () C:\ComboFix.txt
2014-07-28 17:40 - 2014-07-28 18:10 - 00000000 ____D () C:\Qoobox
2014-07-28 17:40 - 2014-07-28 18:10 - 00000000 ____D () C:\ComboFix
2014-07-28 17:40 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-28 17:40 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-28 17:40 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-28 17:40 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-28 17:40 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-28 17:40 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-28 17:40 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-28 17:40 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-28 17:39 - 2014-07-28 18:07 - 00000000 ____D () C:\Windows\erdnt
2014-07-26 23:23 - 2014-08-03 19:24 - 00000000 ____D () C:\FRST
2014-07-26 22:00 - 2014-07-26 22:00 - 00000020 _____ () C:\Users\Cheffe\defogger_reenable
2014-07-26 21:44 - 2014-08-03 19:24 - 00000000 ____D () C:\Users\Cheffe\Downloads\Rechner
2014-07-09 21:33 - 2014-07-09 21:33 - 00000041 ___SH () C:\ProgramData\.zreglib
2014-07-09 21:32 - 2014-07-09 21:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlySoft
2014-07-09 21:32 - 2014-07-09 21:32 - 00000000 ____D () C:\Program Files (x86)\SlySoft
2014-07-09 21:26 - 2014-07-09 21:26 - 02734688 _____ () C:\Users\Cheffe\Downloads\SetupCloneCD5314.exe
2014-07-09 15:45 - 2014-07-09 15:45 - 11204096 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-07-07 18:59 - 2014-07-09 20:13 - 00000000 ____D () C:\Users\Cheffe\Downloads\Hansa
2014-07-06 20:21 - 2014-07-06 20:21 - 00012828 _____ () C:\Users\Cheffe\Downloads\Magic Dust Rechner.xlsx
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-03 19:24 - 2014-07-26 23:23 - 00000000 ____D () C:\FRST
2014-08-03 19:24 - 2014-07-26 21:44 - 00000000 ____D () C:\Users\Cheffe\Downloads\Rechner
2014-08-03 19:23 - 2010-12-29 13:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-08-03 19:22 - 2014-08-03 19:22 - 00003409 _____ () C:\Users\Cheffe\Desktop\JRT.txt
2014-08-03 19:15 - 2010-12-29 12:59 - 00010288 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-03 19:15 - 2010-12-29 12:59 - 00010288 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-03 19:14 - 2014-08-03 19:14 - 00000000 ____D () C:\Windows\ERUNT
2014-08-03 19:13 - 2012-09-08 12:13 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-03 19:12 - 2014-08-03 18:35 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-03 19:11 - 2014-05-04 22:15 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-08-03 19:11 - 2011-07-31 10:43 - 00000000 ____D () C:\Users\Cheffe\AppData\Roaming\BOM
2014-08-03 19:11 - 2010-12-29 15:12 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-08-03 19:10 - 2013-08-06 19:23 - 00051401 _____ () C:\Windows\setupact.log
2014-08-03 19:09 - 2013-09-05 14:54 - 00012274 _____ () C:\Windows\PFRO.log
2014-08-03 19:09 - 2011-08-15 16:22 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-08-03 19:09 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-03 19:08 - 2014-08-03 19:05 - 00000000 ____D () C:\AdwCleaner
2014-08-03 19:08 - 2010-12-29 13:09 - 02025279 _____ () C:\Windows\WindowsUpdate.log
2014-08-03 18:45 - 2012-12-17 17:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-03 18:34 - 2014-08-03 18:34 - 00001066 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-03 18:34 - 2014-08-03 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-03 18:34 - 2014-08-03 18:34 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-03 18:34 - 2014-08-03 18:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-03 18:29 - 2013-01-16 20:58 - 00000000 ____D () C:\Users\NeroMediaHomeUser.4
2014-08-03 18:29 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-08-03 18:19 - 2014-02-18 19:00 - 00000000 ____D () C:\Users\Cheffe\AppData\Local\NVIDIA Corporation
2014-08-03 18:18 - 2013-10-28 17:20 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-08-03 18:17 - 2010-12-29 23:18 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-08-03 18:17 - 2010-12-29 23:17 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-08-03 18:13 - 2012-11-01 18:13 - 00000000 ____D () C:\ProgramData\Origin
2014-07-28 19:21 - 2014-06-22 11:55 - 00000000 ____D () C:\Users\Cheffe\Downloads\facebook
2014-07-28 18:50 - 2014-07-28 18:50 - 00022137 _____ () C:\ComboFix.rar
2014-07-28 18:48 - 2014-07-28 18:48 - 00024286 _____ () C:\ComboFix.zip
2014-07-28 18:10 - 2014-07-28 18:10 - 00304030 _____ () C:\ComboFix.txt
2014-07-28 18:10 - 2014-07-28 17:40 - 00000000 ____D () C:\Qoobox
2014-07-28 18:10 - 2014-07-28 17:40 - 00000000 ____D () C:\ComboFix
2014-07-28 18:10 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-07-28 18:07 - 2014-07-28 17:39 - 00000000 ____D () C:\Windows\erdnt
2014-07-28 18:06 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-07-28 18:05 - 2010-12-29 13:00 - 00000000 ____D () C:\Users\Cheffe
2014-07-26 22:15 - 2013-12-19 21:05 - 00000000 ____D () C:\Program Files (x86)\Convar
2014-07-26 22:12 - 2011-01-01 14:50 - 00000000 ____D () C:\Users\Cheffe\AppData\Roaming\Apple Computer
2014-07-26 22:11 - 2013-09-21 12:20 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-07-26 22:10 - 2011-07-26 15:14 - 00000000 ____D () C:\Fraps
2014-07-26 22:00 - 2014-07-26 22:00 - 00000020 _____ () C:\Users\Cheffe\defogger_reenable
2014-07-25 15:50 - 2014-08-03 18:18 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-07-25 15:50 - 2014-08-03 18:18 - 01291280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2014-07-25 15:50 - 2013-10-28 18:10 - 01283136 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-07-25 15:50 - 2013-10-28 18:10 - 01126480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-07-24 18:21 - 2011-12-16 21:41 - 00000000 ____D () C:\Program Files (x86)\JDownloader
2014-07-18 20:49 - 2012-05-21 16:30 - 00000000 ____D () C:\Users\Cheffe\AppData\Roaming\MyPhoneExplorer
2014-07-18 14:43 - 2013-02-18 22:59 - 00000000 ____D () C:\Users\Cheffe\AppData\Roaming\calibre
2014-07-15 20:44 - 2013-09-15 21:59 - 00000096 _____ () C:\Users\Cheffe\AppData\Roaming\WB.CFG
2014-07-14 21:05 - 2011-01-19 21:57 - 00000000 ____D () C:\Users\Cheffe\AppData\Local\Paint.NET
2014-07-09 21:33 - 2014-07-09 21:33 - 00000041 ___SH () C:\ProgramData\.zreglib
2014-07-09 21:32 - 2014-07-09 21:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlySoft
2014-07-09 21:32 - 2014-07-09 21:32 - 00000000 ____D () C:\Program Files (x86)\SlySoft
2014-07-09 21:26 - 2014-07-09 21:26 - 02734688 _____ () C:\Users\Cheffe\Downloads\SetupCloneCD5314.exe
2014-07-09 20:13 - 2014-07-07 18:59 - 00000000 ____D () C:\Users\Cheffe\Downloads\Hansa
2014-07-09 15:46 - 2012-12-17 17:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-09 15:45 - 2014-07-09 15:45 - 11204096 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-07-09 15:45 - 2012-03-31 16:42 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-09 15:45 - 2011-05-23 15:16 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-09 14:51 - 2012-10-08 15:25 - 00000000 ____D () C:\Users\Cheffe\Downloads\tor
2014-07-06 20:21 - 2014-07-06 20:21 - 00012828 _____ () C:\Users\Cheffe\Downloads\Magic Dust Rechner.xlsx
2014-07-06 19:49 - 2014-02-02 14:56 - 00000000 ____D () C:\Users\Cheffe\Documents\Stundenübersicht
Some content of TEMP:
====================
C:\Users\Cheffe\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-28 15:41
==================== End Of Log ============================ --- --- ---
schönen Restsonntag |