Melina20 | 22.08.2014 11:10 | Hallo Schrauber,
alles ausgeführt, wie du geschrieben hast. Nachdem ich Mbam durchlaufen ließ, konnte ich wieder nicht ins Internet. Ich musste erst den Funknetzwerkadapter zurücksetzen. Nachdem letzen Suchlauf (JRT) war die zu Beginn heruntergeladene Shell-App leider auch verschwunden. Hier die Ergebnisse: Code:
# AdwCleaner v3.308 - Bericht erstellt am 22/08/2014 um 09:47:01
# Aktualisiert 20/08/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : user - IDEA-PC
# Gestartet von : C:\Users\user\Downloads\adwcleaner_3.308.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : BackupStack
Dienst Gelöscht : DptfParticipantProcessorService
Dienst Gelöscht : DptfPolicyConfigTDPService
[#] Dienst Gelöscht : DptfPolicyLpmService
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\AVG Security Toolbar
Ordner Gelöscht : C:\ProgramData\Systweak
Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\Program Files (x86)\System Speedup
Ordner Gelöscht : C:\Program Files (x86)\Common Files\Umbrella
Ordner Gelöscht : C:\Program Files\003
Ordner Gelöscht : C:\users\user\AppData\LocalLow\IminentToolbar
Ordner Gelöscht : C:\users\user\AppData\Roaming\System Speedup
Ordner Gelöscht : C:\users\user\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp
Datei Gelöscht : C:\WINDOWS\System32\roboot64.exe
Datei Gelöscht : C:\WINDOWS\System32\DptfParticipantProcessorService.exe
Datei Gelöscht : C:\WINDOWS\System32\DptfPolicyConfigTDPService.exe
Datei Gelöscht : C:\WINDOWS\System32\DptfPolicyLpmService.exe
Datei Gelöscht : C:\users\user\AppData\Roaming\aps.uninstall.scan.results
Datei Gelöscht : C:\users\user\Desktop\Continue Live Installation.lnk
Datei Gelöscht : C:\users\user\Desktop\Continue VuuPC Installation.lnk
Datei Gelöscht : C:\users\user\Desktop\MyPC Backup.lnk
Datei Gelöscht : C:\users\user\Desktop\Sync Folder.lnk
Datei Gelöscht : C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.iminent.com_0.localstorage
Datei Gelöscht : C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.iminent.com_0.localstorage-journal
***** [ Tasks ] *****
Task Gelöscht : Advanced System Protector_startup
Task Gelöscht : BrowserSafeguard Update Task
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{208D4124-3895-4974-B293-A159BD306078}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{460C3D19-B3D4-4964-A550-77D263B0CCCB}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{5C176BA0-6FC0-4EBD-8ACF-24AC592506B6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C58D664A-3DBC-4925-AE74-0382007DF113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C776D7F4-BA85-4B75-AAFC-3A0A11FE6E36}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\System Speedup
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\System Speedup
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.17054
-\\ Google Chrome v
[ Datei : C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Startup_urls] : hxxp://search.iminent.com/?appId=6834B3EF-E6FE-49EB-80EB-A3A13FA060FB
Gelöscht [Homepage] : hxxp://search.iminent.com/?appId=6834B3EF-E6FE-49EB-80EB-A3A13FA060FB
Gelöscht [Extension] : amfclgbdpgndipgoegfpkkgobahigbcl
Gelöscht [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
Gelöscht [Extension] : flpcjncodpafbgdpnkljologafpionhb
Gelöscht [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof
Gelöscht [Extension] : nikpibnbobmbdbheedjfogjlikpgpnhp
*************************
AdwCleaner[R0].txt - [6816 octets] - [22/08/2014 09:44:21]
AdwCleaner[S0].txt - [6422 octets] - [22/08/2014 09:47:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6482 octets] ########## Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 22.08.2014
Suchlauf-Zeit: 08:57:27
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.08.22.03
Rootkit Datenbank: v2014.08.21.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: user
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 305364
Verstrichene Zeit: 23 Min, 47 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.Iminent, C:\Program Files (x86)\Common Files\Umbrella\Umbrella268.exe, 2152, Löschen bei Neustart, [e4b75574b0cbcf67fada1300c9385ba5]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 27
PUP.Optional.Iminent, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SProtection, In Quarantäne, [e4b75574b0cbcf67fada1300c9385ba5],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\APPID\{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4}, In Quarantäne, [debdf2d72e4d7bbb76c6314434ce7c84],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{0E4B2CAB-B859-4C57-B96E-63DDEC692BC4}, In Quarantäne, [debdf2d72e4d7bbb76c6314434ce7c84],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}, In Quarantäne, [d7c4359495e62a0c1cabf8b07c8647b9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}, In Quarantäne, [d7c4359495e62a0c1cabf8b07c8647b9],
PUP.Optional.Snapdo.T, HKU\S-1-5-21-218488010-109497726-392906908-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, Löschen bei Neustart, [346794353a4192a44b88d0dc9d65dd23],
PUP.Optional.Snapdo.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, In Quarantäne, [346794353a4192a44b88d0dc9d65dd23],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, In Quarantäne, [4e4d01c87cfff541732daaff778b07f9],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, In Quarantäne, [7922bf0a3b40d165b4edbfea08faee12],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}, In Quarantäne, [aaf115b475068caae007a4cbd032649c],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\Iminent, In Quarantäne, [4c4f3396aad1f83e701bcd48d23151af],
PUP.Optional.SupraSavings, HKLM\SOFTWARE\suprasavings, In Quarantäne, [0299cffaf289ff3787f508e22dd5da26],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\CLASSES\APPID\Iminent.WebBooster.InternetExplorer.DLL, In Quarantäne, [7922696086f5c670cdf09b98a65efe02],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\IminentToolbar, In Quarantäne, [d9c24a7f0c6f71c5cdb0fc1a24df44bc],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\Iminent.WebBooster.InternetExplorer.DLL, In Quarantäne, [6239a128a5d6aa8c922bcc67d2326898],
PUP.Optional.PriceGong.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\bkomkajifikmkfnjgphkjcfeepbnojok, In Quarantäne, [4556b91095e681b568caf91e42c1d52b],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\igdhbblpcellaljokkpfhcjlagemhgjl, In Quarantäne, [534821a8dd9e1a1cacde1302c73cba46],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT, In Quarantäne, [485317b24536e84e39f5cb2635cdb24e],
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, In Quarantäne, [7f1c9b2e1764330367ce816ebd4502fe],
PUP.Optional.Umbrella.A, HKLM\SOFTWARE\WOW6432NODE\UMBRELLA, In Quarantäne, [c4d743861368d264f278929a94701ee2],
PUP.Optional.BrowserSafeGuard.A, HKU\S-1-5-21-218488010-109497726-392906908-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BrowsersafeguardInstalled, Löschen bei Neustart, [504beedb0b7068ce1628fff2a75be61a],
PUP.Optional.Iminent.A, HKU\S-1-5-21-218488010-109497726-392906908-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Iminent, Löschen bei Neustart, [75268049007bfc3a5933051026dd0bf5],
PUP.Optional.Iminent.A, HKU\S-1-5-21-218488010-109497726-392906908-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\IminentToolbar, Löschen bei Neustart, [4952507988f3de58d2ac7b9b0003fa06],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-218488010-109497726-392906908-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, Löschen bei Neustart, [623923a6e2990531759755bae51e55ab],
PUP.Optional.SupraSavings.A, HKU\S-1-5-21-218488010-109497726-392906908-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\suprasavings, Löschen bei Neustart, [d4c7a7222952a096337b9d69946f728e],
PUP.Optional.Iminent.A, HKU\S-1-5-21-218488010-109497726-392906908-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\Iminent, Löschen bei Neustart, [6c2f67625c1f76c004479b6527dc3bc5],
PUP.Optional.SystemSpeedup, HKU\S-1-5-21-218488010-109497726-392906908-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\ssd, Löschen bei Neustart, [6a316861accf69cd4be92ac540c26d93],
Registrierungswerte: 3
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT|InstallDir, C:\PROGRA~2\SearchProtect, In Quarantäne, [485317b24536e84e39f5cb2635cdb24e]
PUP.Optional.Umbrella.A, HKLM\SOFTWARE\WOW6432NODE\UMBRELLA|MUpdBlock, {
"MASSUPDATE" : {
"CHROME_MBAR" : {
"Checked" : 1,
"RetryIdx" : 0,
"Version" : 1
},
"FIREFOX_MBAR" : {
"Checked" : 1,
"RetryIdx" : 0,
"Version" : 1
},
"IEXPLORE_BHO" : {
"Checked" : 1,
"RetryIdx" : 0,
"Version" : 4
}
}
}
, In Quarantäne, [c4d743861368d264f278929a94701ee2]
PUP.Optional.Snapdo.T, HKU\S-1-5-21-218488010-109497726-392906908-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, Löschen bei Neustart, [6e2d4e7bd6a590a666ab6e7faa5807f9]
Registrierungsdaten: 4
PUP.Optional.HelperBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=6e96a7d7-6874-8293-910c-650244dd525f&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=09/02/2014&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=6e96a7d7-6874-8293-910c-650244dd525f&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=09/02/2014&type=hp1000),Ersetzt,[326909c06b105adcf9cf775a15efb848]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-218488010-109497726-392906908-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=6e96a7d7-6874-8293-910c-650244dd525f&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=09/02/2014&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=6e96a7d7-6874-8293-910c-650244dd525f&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=09/02/2014&type=hp1000),Löschen bei Neustart,[089321a83843d363e5e81cb505ffdd23]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-218488010-109497726-392906908-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=6e96a7d7-6874-8293-910c-650244dd525f&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=09/02/2014&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=6e96a7d7-6874-8293-910c-650244dd525f&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=09/02/2014&type=hp1000),Löschen bei Neustart,[0299a722a7d4f73f3f8f1fb2758f2cd4]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-218488010-109497726-392906908-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=6e96a7d7-6874-8293-910c-650244dd525f&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=09/02/2014&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=6e96a7d7-6874-8293-910c-650244dd525f&searchtype=ds&p={searchTerms}&fr=linkury-tb&installDate=09/02/2014&type=hp1000),Löschen bei Neustart,[1b80caffa7d42f0709c0923f758f857b]
Ordner: 22
PUP.Optional.SystemSpeedup, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Speedup, In Quarantäne, [25761eab6f0c0e2846ece50a45bd16ea],
PUP.Optional.OpenCandy, C:\Users\user\AppData\Roaming\OpenCandy, In Quarantäne, [96059336d5a674c2436e28940df58779],
PUP.Optional.OpenCandy, C:\Users\user\AppData\Roaming\OpenCandy\B0A2E26BB10941FB9904252985E29FB4, In Quarantäne, [96059336d5a674c2436e28940df58779],
PUP.Optional.OpenCandy, C:\Users\user\AppData\Roaming\OpenCandy\F18B6932284F4739ADE6895A16572732, In Quarantäne, [96059336d5a674c2436e28940df58779],
PUP.Optional.Iminent.A, C:\Users\user\AppData\Roaming\IminentToolbar, In Quarantäne, [bdde25a498e365d182f3546a748eb34d],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\CSS, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong, In Quarantäne, [633802c7fe7d221497c50bb8897909f7],
PUP.Optional.SearchProtect.A, C:\Users\user\AppData\Local\SearchProtect, In Quarantäne, [56459534a1daf93dccaed1011ae89868],
PUP.Optional.SearchProtect.A, C:\Users\user\AppData\Local\SearchProtect\SearchProtect, In Quarantäne, [56459534a1daf93dccaed1011ae89868],
PUP.Optional.SearchProtect.A, C:\Users\user\AppData\Local\SearchProtect\SearchProtect\rep, In Quarantäne, [56459534a1daf93dccaed1011ae89868],
PUP.Optional.SearchProtect.A, C:\Users\user\AppData\Local\SearchProtect\SearchProtect\STG, In Quarantäne, [56459534a1daf93dccaed1011ae89868],
PUP.Optional.SearchProtect.A, C:\Users\user\AppData\Local\SearchProtect\UI, In Quarantäne, [56459534a1daf93dccaed1011ae89868],
PUP.Optional.SearchProtect.A, C:\Users\user\AppData\Local\SearchProtect\UI\rep, In Quarantäne, [56459534a1daf93dccaed1011ae89868],
PUP.Optional.AmazonBrowserBar.A, C:\Program Files (x86)\Amazon\ABB, In Quarantäne, [fe9d5d6c1b60360097fd9f33f60c36ca],
PUP.Optional.SystemSpeedup, C:\Users\user\AppData\Roaming\systweak\ssd, In Quarantäne, [c1daf9d0ff7c69cd8a04e1f4808205fb],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced System Protector, In Quarantäne, [f2a920a91566f145750915cd62a0649c],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\user\AppData\Roaming\systweak\Advanced System Protector, In Quarantäne, [2a719435aecd48eea6d8439fd92912ee],
Dateien: 89
PUP.Optional.Iminent, C:\Program Files (x86)\Common Files\Umbrella\Umbrella268.exe, Löschen bei Neustart, [e4b75574b0cbcf67fada1300c9385ba5],
PUP.Optional.Linkury.A, C:\Users\user\AppData\Roaming\OpenCandy\B0A2E26BB10941FB9904252985E29FB4\Installer.exe, In Quarantäne, [3a6102c7017a191de87cd4c58084867a],
PUP.Optional.AdvancedSystemProtector, C:\Windows\System32\sasnative64.exe, In Quarantäne, [4853b019611a122414d115934db448b8],
PUP.Optional.GenericExt.A, C:\Users\user\AppData\Local\temp\igdhbblpcellaljokkpfhcjlagemhgjl19eac\minibarchrome.exe, In Quarantäne, [8b1039908eedbf77fd6665d8728e738d],
PUP.Optional.AppsInstaller, C:\Users\user\Downloads\Setup.exe, In Quarantäne, [8e0d5079dd9eab8bfc038e2d2fd59b65],
PUP.Optional.AdvancedSystemProtector, C:\Windows\System32\Tasks\Advanced System Protector_startup, In Quarantäne, [b8e346835328ca6c5b1d2fb8a35f0ef2],
PUP.Optional.SystemSpeedup, C:\Windows\Tasks\System Speedup_DEFAULT.job, In Quarantäne, [e8b33693a4d78ea8f6e228c681816a96],
PUP.Optional.SystemSpeedup, C:\Windows\System32\Tasks\System Speedup_DEFAULT, In Quarantäne, [6239a920a1dac175dbfe529c37cb8779],
PUP.Optional.SystemSpeedup, C:\Windows\Tasks\System Speedup_UPDATES.job, In Quarantäne, [f8a3dceddc9f122428b24ba39e64ee12],
PUP.Optional.SystemSpeedup, C:\Windows\System32\Tasks\System Speedup_UPDATES, In Quarantäne, [801bb118483389ad32a935b962a0c23e],
PUP.Optional.SystemSpeedup, C:\Users\Public\Desktop\System Speedup.lnk, In Quarantäne, [6a312b9e7a01320455db5c937a885fa1],
PUP.Optional.SystemSpeedup, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Speedup\System Speedup.lnk, In Quarantäne, [25761eab6f0c0e2846ece50a45bd16ea],
PUP.Optional.SystemSpeedup, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Speedup\Register System Speedup.lnk, In Quarantäne, [25761eab6f0c0e2846ece50a45bd16ea],
PUP.Optional.SystemSpeedup, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Speedup\System Speedup entfernen.lnk, In Quarantäne, [25761eab6f0c0e2846ece50a45bd16ea],
PUP.Optional.BrowserSafeGuard.A, C:\Windows\System32\Tasks\BrowserSafeguard Update Task, In Quarantäne, [b4e750793d3e45f1420af6fc1fe3a35d],
PUP.Optional.Iminent.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage, In Quarantäne, [8a1126a3611aaf87fb4e52ac887a24dc],
PUP.Optional.AdPeak.A, C:\Program Files\003\xmkysecqun64.exe, In Quarantäne, [a3f8c009c2b942f43169ec1517ec08f8],
PUP.Optional.Iminent.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_start.iminent.com_0.localstorage, In Quarantäne, [07940bbe3843b77fec2104461be97f81],
PUP.Optional.Iminent.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_start.iminent.com_0.localstorage-journal, In Quarantäne, [643708c153281422a46908425fa57888],
PUP.Optional.OpenCandy, C:\Users\user\AppData\Roaming\OpenCandy\F18B6932284F4739ADE6895A16572732\Trial-14.0.1000.89_de-DE_1004733_DE-2.exe, In Quarantäne, [96059336d5a674c2436e28940df58779],
PUP.Optional.Iminent.A, C:\Users\user\AppData\Roaming\IminentToolbar\sqlite3.dll, In Quarantäne, [bdde25a498e365d182f3546a748eb34d],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\bg.html, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\bg.js, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\GoogleChromeRemotePlugin.dll, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\manifest.json, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\options.htm, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\options.js, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\popup.html, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\popup.js, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\redirect.html, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\redirect.js, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\CSS\border.css, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down-1.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down-2.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down-3.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\fb.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\fblike.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\gmail.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\google.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\googleplus.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\hide-1.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\hide-2.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\hide-3.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\left.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\maximize-1.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\maximize-2.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\maximize-3.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\mgsplusvideo.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\minimize-1.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\minimize-2.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\minimize-3.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\pinit.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\right.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\searchBox.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\show-1.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\show-2.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\show-3.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\twitter.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up-1.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up-2.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up-3.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\BackPageRemove.js, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\defaultBlockList.js, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\documentEvents.js, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\externalJS.js, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\FBImagePreview.js, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\InternalJS.js, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\jquery-1.9.0.min.js, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\PluginWrapper.js, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\publisherDefinitions.js, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\tabReload.js, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\TopFrameJS.js, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\homePage.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\Linkury.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\Linkury128.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\Linkury16.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.SnapDo.A, C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\Linkury48.png, In Quarantäne, [8f0ce5e4502b83b3a43aa41b37cbbd43],
PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\PriceGong Contact Us.lnk, In Quarantäne, [633802c7fe7d221497c50bb8897909f7],
PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\PriceGong Help.lnk, In Quarantäne, [633802c7fe7d221497c50bb8897909f7],
PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\PriceGong Homepage.lnk, In Quarantäne, [633802c7fe7d221497c50bb8897909f7],
PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\Uninstall PriceGong.lnk, In Quarantäne, [633802c7fe7d221497c50bb8897909f7],
PUP.Optional.SearchProtect.A, C:\Users\user\AppData\Local\SearchProtect\SearchProtect\rep\Cvc.dat, In Quarantäne, [56459534a1daf93dccaed1011ae89868],
PUP.Optional.SearchProtect.A, C:\Users\user\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, In Quarantäne, [56459534a1daf93dccaed1011ae89868],
PUP.Optional.SearchProtect.A, C:\Users\user\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat, In Quarantäne, [56459534a1daf93dccaed1011ae89868],
PUP.Optional.SearchProtect.A, C:\Users\user\AppData\Local\SearchProtect\UI\rep\UIRepository.dat, In Quarantäne, [56459534a1daf93dccaed1011ae89868],
PUP.Optional.AmazonBrowserBar.A, C:\Program Files (x86)\Amazon\ABB\abb-bundler-uninstall.exe, In Quarantäne, [fe9d5d6c1b60360097fd9f33f60c36ca],
PUP.Optional.SystemSpeedup, C:\Users\user\AppData\Roaming\systweak\ssd\SSDPTstub.exe, In Quarantäne, [c1daf9d0ff7c69cd8a04e1f4808205fb],
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8 x64
Ran by user on 22.08.2014 at 9:58:46,02
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22.08.2014 at 10:33:00,21
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-08-2014
Ran by user (administrator) on IDEA-PC on 22-08-2014 10:47:44
Running from C:\Users\user\Downloads\FRST-OlderVersion
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(Lenovo) C:\ProgramData\YogaSmartSwicth\Server\x64\ymc.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
(Intel) C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Transition\Lenovo Transition.exe
() C:\ProgramData\YogaSmartSwicth\yogaserver.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Spotify Ltd) C:\Users\user\AppData\Roaming\Spotify\spotify.exe
(Spotify Ltd) C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
() C:\Program Files (x86)\Lenovo\MotionControl\MotionControl.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
() C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
() C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\McUICnt.exe
() C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyHelper.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [887968 2012-06-14] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\WINDOWS\system32\DptfPolicyLpmServiceHelper.exe [21888 2012-07-30] ()
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [449024 2012-08-29] (Realtek Semiconductor Corporation)
HKLM\...\Run: [SynLenovoGestureMgr] => C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [665400 2012-11-23] (Synaptics)
HKLM\...\Run: [Lenovo Transition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Lenovo Transition.exe [209488 2012-12-06] (Lenovo)
HKLM\...\Run: [yogaserver] => C:\ProgramData\YogaSmartSwicth\yogaserver.exe [208464 2012-12-06] ()
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2012-12-06] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2012-12-06] (Lenovo(beijing) Limited)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2968376 2012-11-23] (Synaptics Incorporated)
HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [508656 2012-07-25] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink Corp.)
HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537512 2013-09-24] (McAfee, Inc.)
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537512 2013-09-24] (McAfee, Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-14] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-218488010-109497726-392906908-1001\...\Run: [Spotify] => C:\Users\user\AppData\Roaming\Spotify\Spotify.exe [6162488 2014-07-10] (Spotify Ltd)
HKU\S-1-5-21-218488010-109497726-392906908-1001\...\Run: [Spotify Web Helper] => C:\Users\user\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1178168 2014-07-10] (Spotify Ltd)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Motion Control.lnk
ShortcutTarget: Motion Control.lnk -> C:\Program Files (x86)\Lenovo\MotionControl\MotionControl.exe ()
ShellIconOverlayIdentifiers: ShareOverlay -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
ShellIconOverlayIdentifiers: SugarSyncBackedUp -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
ShellIconOverlayIdentifiers: SugarSyncPending -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
ShellIconOverlayIdentifiers: SugarSyncRoot -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
ShellIconOverlayIdentifiers: SugarSyncShared -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
ShellIconOverlayIdentifiers-x32: ShareOverlay -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: http=127.0.0.1:58541;https=127.0.0.1:58541
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {B056DEF7-E1BA-429E-B971-7368C4B8EB4E} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\user\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 -> C:\Users\user\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2012-12-06]
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR DefaultSearchKeyword: search.iminent.com
CHR DefaultSearchProvider: SearchTheWeb
CHR DefaultSearchURL: hxxp://search.iminent.com/?appId=6834B3EF-E6FE-49EB-80EB-A3A13FA060FB&ref=toolbox&q={searchTerms}
CHR DefaultSuggestURL:
CHR Extension: (Google Docs) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-04]
CHR Extension: (Google Drive) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-04]
CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-04]
CHR Extension: (Google-Suche) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-04]
CHR Extension: (Google Wallet) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-04]
CHR Extension: (Google Mail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-04]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-14] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-14] (Avira Operations GmbH & Co. KG)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [51200 2012-08-31] () [File not signed]
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2451456 2012-07-13] (Realsil Microelectronics Inc.) [File not signed]
R2 irstrtsv; C:\WINDOWS\SysWOW64\irstrtsv.exe [193576 2012-07-19] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178048 2013-09-24] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\mcafee\msc\McAWFwk.exe [332080 2012-01-26] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [602944 2013-08-02] (McAfee, Inc.)
S4 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1017016 2013-09-20] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-11-04] (McAfee, Inc.)
R2 mfevtp; C:\WINDOWS\system32\mfevtps.exe [182752 2013-11-04] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2103096 2013-12-18] (TuneUp Software)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
R2 ymc; C:\ProgramData\YogaSmartSwicth\Server\x64\ymc.exe [27216 2012-12-06] (Lenovo)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [104960 2012-07-07] (ASIX Electronics Corp.)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-11-04] (McAfee, Inc.)
R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [96064 2012-07-13] (Intel Corporation)
R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [228672 2012-07-13] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [361792 2012-07-13] (Intel Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 irstrtdv; C:\Windows\System32\drivers\irstrtdv.sys [43800 2012-07-20] (Intel Corporation)
R3 leymc; C:\Windows\system32\DRIVERS\leymc.sys [17240 2012-12-06] (Lenovo)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-22] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179792 2013-11-04] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [311120 2013-11-04] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69344 2013-11-04] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [519576 2013-11-04] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [782360 2013-11-04] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [390552 2013-09-20] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [95984 2013-09-20] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [343696 2013-11-04] (McAfee, Inc.)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [696464 2012-09-01] (Realtek Semiconductor Corporation)
R3 RtlWlanu; C:\Windows\system32\DRIVERS\rtwlanu.sys [1574032 2012-09-11] (Realtek Semiconductor Corporation )
R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
R3 SensorsHIDClassDriver; C:\Windows\System32\drivers\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
R3 SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [36864 2012-11-06] (Synaptics Incorporated)
R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1058680 2012-08-11] (Sunplus)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-08-21] (TuneUp Software)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-22 10:33 - 2014-08-22 10:33 - 00000611 _____ () C:\Users\user\Desktop\JRT.txt
2014-08-22 09:58 - 2014-08-22 09:58 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-08-22 09:57 - 2014-08-22 09:57 - 01016261 _____ (Thisisu) C:\Users\user\Downloads\JRT.exe
2014-08-22 09:56 - 2014-08-22 09:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-08-22 09:46 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll
2014-08-22 09:44 - 2014-08-22 09:47 - 00000000 ____D () C:\AdwCleaner
2014-08-22 09:37 - 2014-08-22 09:39 - 01364531 _____ () C:\Users\user\Downloads\adwcleaner_3.308.exe
2014-08-22 09:28 - 2014-08-22 09:28 - 00029178 _____ () C:\Users\user\Desktop\mbam.txt
2014-08-22 08:56 - 2014-08-22 09:51 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-08-22 08:55 - 2014-08-22 08:55 - 00001109 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-22 08:55 - 2014-08-22 08:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-22 08:54 - 2014-08-22 08:55 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-22 08:54 - 2014-08-22 08:54 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-22 08:54 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-08-22 08:54 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-08-22 08:54 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-08-22 08:50 - 2014-08-22 08:51 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-19 10:08 - 2014-08-19 10:08 - 00027501 _____ () C:\ComboFix.txt
2014-08-19 09:43 - 2011-06-26 07:45 - 00256000 _____ () C:\WINDOWS\PEV.exe
2014-08-19 09:43 - 2010-11-07 18:20 - 00208896 _____ () C:\WINDOWS\MBR.exe
2014-08-19 09:43 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2014-08-19 09:43 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2014-08-19 09:43 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2014-08-19 09:43 - 2000-08-31 01:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2014-08-19 09:43 - 2000-08-31 01:00 - 00098816 _____ () C:\WINDOWS\sed.exe
2014-08-19 09:43 - 2000-08-31 01:00 - 00080412 _____ () C:\WINDOWS\grep.exe
2014-08-19 09:43 - 2000-08-31 01:00 - 00068096 _____ () C:\WINDOWS\zip.exe
2014-08-19 09:41 - 2014-08-19 10:08 - 00000000 ____D () C:\Qoobox
2014-08-19 09:41 - 2014-08-19 10:03 - 00000000 ____D () C:\WINDOWS\erdnt
2014-08-19 09:39 - 2014-08-19 09:40 - 05572251 ____R (Swearware) C:\Users\user\Downloads\ComboFix.exe
2014-08-17 18:05 - 2014-08-07 07:33 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2014-08-17 18:05 - 2014-08-07 04:09 - 00556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2014-08-14 10:34 - 2014-07-15 23:51 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys
2014-08-14 10:31 - 2014-06-10 23:44 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2014-08-14 10:31 - 2014-06-10 23:43 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2014-08-14 08:38 - 2014-07-24 13:09 - 19279872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-08-14 08:38 - 2014-06-13 02:57 - 01453400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2014-08-14 08:38 - 2014-06-13 02:55 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2014-08-14 08:37 - 2014-07-24 13:11 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-08-14 08:37 - 2014-07-24 13:10 - 02240000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-08-14 08:37 - 2014-07-24 13:10 - 01407488 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-08-14 08:37 - 2014-07-24 13:10 - 00915968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2014-08-14 08:37 - 2014-07-24 13:10 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2014-08-14 08:37 - 2014-07-24 13:09 - 15399936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-08-14 08:37 - 2014-07-24 13:09 - 03959296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-08-14 08:37 - 2014-07-24 13:09 - 02655232 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-08-14 08:37 - 2014-07-24 13:09 - 01508864 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-08-14 08:37 - 2014-07-24 13:09 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2014-08-14 08:37 - 2014-07-24 13:09 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-08-14 08:37 - 2014-07-24 13:09 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-08-14 08:37 - 2014-07-24 13:09 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-08-14 08:37 - 2014-07-24 13:09 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-08-14 08:37 - 2014-07-24 13:09 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-08-14 08:37 - 2014-07-24 13:09 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll
2014-08-14 08:37 - 2014-07-24 13:09 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-08-14 08:37 - 2014-07-24 13:09 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-08-14 08:37 - 2014-07-24 13:09 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-08-14 08:37 - 2014-07-24 11:52 - 01766400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-08-14 08:37 - 2014-07-24 11:52 - 01180672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-08-14 08:37 - 2014-07-24 11:52 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
2014-08-14 08:37 - 2014-07-24 11:51 - 14371328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-08-14 08:37 - 2014-07-24 11:51 - 13757440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-08-14 08:37 - 2014-07-24 11:51 - 02861568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-08-14 08:37 - 2014-07-24 11:51 - 02054656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-08-14 08:37 - 2014-07-24 11:51 - 01440768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-08-14 08:37 - 2014-07-24 11:51 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2014-08-14 08:37 - 2014-07-24 11:51 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-08-14 08:37 - 2014-07-24 11:51 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-08-14 08:37 - 2014-07-24 11:51 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-08-14 08:37 - 2014-07-24 11:51 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-08-14 08:37 - 2014-07-24 11:51 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-08-14 08:37 - 2014-07-24 11:51 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesysprep.dll
2014-08-14 08:37 - 2014-07-24 11:51 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-08-14 08:37 - 2014-07-24 11:51 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-08-14 08:37 - 2014-07-24 11:51 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-08-14 08:36 - 2014-07-24 13:09 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-08-14 08:36 - 2014-07-24 11:51 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-08-14 08:36 - 2014-07-24 11:33 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-08-14 08:36 - 2014-07-24 11:29 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-08-14 08:36 - 2014-07-24 09:03 - 00534528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2014-08-14 08:36 - 2014-07-16 00:03 - 01300992 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2014-08-14 08:36 - 2014-07-15 23:55 - 04035072 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-08-14 08:36 - 2014-07-12 03:36 - 01023488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2014-08-14 08:36 - 2014-06-20 00:35 - 01312768 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2014-08-14 08:36 - 2014-06-19 23:24 - 00694272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2014-08-14 08:36 - 2014-06-05 18:56 - 00112984 _____ (Microsoft Corporation) C:\WINDOWS\system32\consent.exe
2014-08-14 08:36 - 2014-06-05 18:30 - 10116608 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-08-14 08:36 - 2014-06-05 18:29 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2014-08-14 08:36 - 2014-06-05 18:29 - 00393216 _____ (Microsoft Corporation) C:\WINDOWS\system32\msihnd.dll
2014-08-14 08:36 - 2014-06-05 18:28 - 02306560 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-08-14 08:36 - 2014-06-05 18:28 - 02146304 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2014-08-14 08:36 - 2014-06-05 14:12 - 08857600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-08-14 08:36 - 2014-06-05 14:11 - 02416128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2014-08-14 08:36 - 2014-06-05 14:11 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msihnd.dll
2014-08-14 08:36 - 2014-06-05 14:10 - 02037760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-08-14 08:36 - 2014-06-05 14:10 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2014-08-14 08:29 - 2014-05-29 05:04 - 00094552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2014-08-14 08:29 - 2014-05-08 02:34 - 00328024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2014-08-13 08:49 - 2014-08-22 10:47 - 00000000 ____D () C:\Users\user\Downloads\FRST-OlderVersion
2014-08-13 08:43 - 2014-08-13 08:43 - 00001271 _____ () C:\Users\user\Desktop\Revo Uninstaller.lnk
2014-08-13 08:43 - 2014-08-13 08:43 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-08-13 08:42 - 2014-08-13 08:42 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\user\Downloads\revosetup95.exe
2014-08-12 09:08 - 2014-08-12 09:11 - 00027551 _____ () C:\Users\user\Downloads\Addition.txt
2014-08-12 09:05 - 2014-08-22 10:48 - 00000000 ____D () C:\FRST
2014-08-12 09:05 - 2014-08-12 09:11 - 00045779 _____ () C:\Users\user\Downloads\FRST.txt
2014-08-12 09:04 - 2014-08-13 08:49 - 01199104 _____ () C:\Users\user\Downloads\FRST64.exe
2014-08-10 13:22 - 2014-08-10 13:22 - 00000865 _____ () C:\Users\user\Downloads\TerminExport_140165179lmv1847.ics
2014-08-07 17:59 - 2014-08-07 17:59 - 00000168 _____ () C:\Users\user\Desktop\Neues Textdokument (11).txt
2014-08-04 10:29 - 2014-05-20 03:33 - 00059416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-08-04 10:29 - 2014-05-20 00:45 - 00629248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2014-08-04 10:29 - 2014-05-20 00:45 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2014-08-04 10:29 - 2014-05-20 00:24 - 03286528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-08-04 10:29 - 2014-05-20 00:24 - 01623040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2014-08-04 10:29 - 2014-05-20 00:24 - 00773632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-08-04 10:29 - 2014-05-20 00:24 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2014-08-04 10:29 - 2014-05-20 00:24 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2014-08-04 10:29 - 2014-05-20 00:24 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-08-04 10:29 - 2014-05-14 23:43 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2014-08-04 10:29 - 2014-05-14 23:43 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2014-08-04 10:29 - 2014-05-14 23:42 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2014-08-04 10:29 - 2014-05-14 23:42 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-22 10:49 - 2014-04-01 20:32 - 00001080 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-218488010-109497726-392906908-1001Core1cf4de120ffb11e.job
2014-08-22 10:49 - 2013-12-06 17:22 - 00001132 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-218488010-109497726-392906908-1001UA1cef29f5b894ece.job
2014-08-22 10:48 - 2014-08-12 09:05 - 00000000 ____D () C:\FRST
2014-08-22 10:47 - 2014-08-13 08:49 - 00000000 ____D () C:\Users\user\Downloads\FRST-OlderVersion
2014-08-22 10:33 - 2014-08-22 10:33 - 00000611 _____ () C:\Users\user\Desktop\JRT.txt
2014-08-22 10:13 - 2013-10-11 17:44 - 00003592 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-218488010-109497726-392906908-1001
2014-08-22 10:08 - 2013-10-11 17:38 - 00042803 _____ () C:\Users\user\AppData\Local\BTServer.log
2014-08-22 10:03 - 2012-12-06 11:39 - 01463222 _____ () C:\WINDOWS\WindowsUpdate.log
2014-08-22 10:02 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-08-22 09:58 - 2014-08-22 09:58 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-08-22 09:58 - 2012-12-06 20:35 - 00758792 _____ () C:\WINDOWS\system32\perfh007.dat
2014-08-22 09:58 - 2012-12-06 20:35 - 00158188 _____ () C:\WINDOWS\system32\perfc007.dat
2014-08-22 09:58 - 2012-07-26 08:28 - 01745416 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-08-22 09:57 - 2014-08-22 09:57 - 01016261 _____ (Thisisu) C:\Users\user\Downloads\JRT.exe
2014-08-22 09:57 - 2013-11-29 13:21 - 00000000 ____D () C:\Users\user\AppData\Roaming\ClassicShell
2014-08-22 09:56 - 2014-08-22 09:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-08-22 09:52 - 2014-02-14 11:12 - 00000000 ____D () C:\Users\user\AppData\Roaming\Spotify
2014-08-22 09:51 - 2014-08-22 08:56 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-08-22 09:50 - 2012-12-06 11:44 - 00000000 ____D () C:\ProgramData\Realtek
2014-08-22 09:50 - 2012-08-01 16:51 - 00070208 _____ () C:\WINDOWS\PFRO.log
2014-08-22 09:50 - 2012-07-26 08:22 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-08-22 09:50 - 2012-07-26 06:26 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-08-22 09:47 - 2014-08-22 09:44 - 00000000 ____D () C:\AdwCleaner
2014-08-22 09:39 - 2014-08-22 09:37 - 01364531 _____ () C:\Users\user\Downloads\adwcleaner_3.308.exe
2014-08-22 09:35 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-08-22 09:28 - 2014-08-22 09:28 - 00029178 _____ () C:\Users\user\Desktop\mbam.txt
2014-08-22 09:24 - 2012-07-26 06:26 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-08-22 09:22 - 2012-12-06 11:48 - 00000000 ____D () C:\Program Files (x86)\Amazon
2014-08-22 08:55 - 2014-08-22 08:55 - 00001109 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-22 08:55 - 2014-08-22 08:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-22 08:55 - 2014-08-22 08:54 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-22 08:54 - 2014-08-22 08:54 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-22 08:51 - 2014-08-22 08:50 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\user\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-22 08:31 - 2014-05-11 16:46 - 00003132 _____ () C:\WINDOWS\System32\Tasks\System Speedup
2014-08-20 21:31 - 2014-02-14 11:12 - 00000000 ____D () C:\Users\user\AppData\Local\Spotify
2014-08-19 10:15 - 2014-07-15 14:49 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2014-08-19 10:08 - 2014-08-19 10:08 - 00027501 _____ () C:\ComboFix.txt
2014-08-19 10:08 - 2014-08-19 09:41 - 00000000 ____D () C:\Qoobox
2014-08-19 10:07 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-08-19 10:03 - 2014-08-19 09:41 - 00000000 ____D () C:\WINDOWS\erdnt
2014-08-19 10:02 - 2012-07-26 06:26 - 00000215 _____ () C:\WINDOWS\system.ini
2014-08-19 09:40 - 2014-08-19 09:39 - 05572251 ____R (Swearware) C:\Users\user\Downloads\ComboFix.exe
2014-08-14 18:10 - 2014-07-15 14:49 - 00281248 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-08-14 18:07 - 2012-07-26 09:12 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-08-14 18:06 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\AUInstallAgent
2014-08-13 13:54 - 2013-11-04 12:13 - 00002320 _____ () C:\Users\user\Desktop\Google Chrome.lnk
2014-08-13 08:49 - 2014-08-12 09:04 - 01199104 _____ () C:\Users\user\Downloads\FRST64.exe
2014-08-13 08:43 - 2014-08-13 08:43 - 00001271 _____ () C:\Users\user\Desktop\Revo Uninstaller.lnk
2014-08-13 08:43 - 2014-08-13 08:43 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-08-13 08:42 - 2014-08-13 08:42 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\user\Downloads\revosetup95.exe
2014-08-12 09:11 - 2014-08-12 09:08 - 00027551 _____ () C:\Users\user\Downloads\Addition.txt
2014-08-12 09:11 - 2014-08-12 09:05 - 00045779 _____ () C:\Users\user\Downloads\FRST.txt
2014-08-10 13:22 - 2014-08-10 13:22 - 00000865 _____ () C:\Users\user\Downloads\TerminExport_140165179lmv1847.ics
2014-08-07 17:59 - 2014-08-07 17:59 - 00000168 _____ () C:\Users\user\Desktop\Neues Textdokument (11).txt
2014-08-07 07:33 - 2014-08-17 18:05 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2014-08-07 04:09 - 2014-08-17 18:05 - 00556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2014-08-02 01:15 - 2014-01-01 16:35 - 00704480 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-08-02 01:15 - 2014-01-01 16:35 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-29 10:47 - 2012-07-26 08:21 - 00037607 _____ () C:\WINDOWS\setupact.log
2014-07-24 13:11 - 2014-08-14 08:37 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-07-24 13:10 - 2014-08-14 08:37 - 02240000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-07-24 13:10 - 2014-08-14 08:37 - 01407488 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-07-24 13:10 - 2014-08-14 08:37 - 00915968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2014-07-24 13:10 - 2014-08-14 08:37 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2014-07-24 13:09 - 2014-08-14 08:38 - 19279872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-07-24 13:09 - 2014-08-14 08:37 - 15399936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-07-24 13:09 - 2014-08-14 08:37 - 03959296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-07-24 13:09 - 2014-08-14 08:37 - 02655232 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-07-24 13:09 - 2014-08-14 08:37 - 01508864 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-07-24 13:09 - 2014-08-14 08:37 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2014-07-24 13:09 - 2014-08-14 08:37 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-07-24 13:09 - 2014-08-14 08:37 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-07-24 13:09 - 2014-08-14 08:37 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-07-24 13:09 - 2014-08-14 08:37 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-07-24 13:09 - 2014-08-14 08:37 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-07-24 13:09 - 2014-08-14 08:37 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll
2014-07-24 13:09 - 2014-08-14 08:37 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-07-24 13:09 - 2014-08-14 08:37 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-07-24 13:09 - 2014-08-14 08:37 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-07-24 13:09 - 2014-08-14 08:36 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-07-24 11:52 - 2014-08-14 08:37 - 01766400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-07-24 11:52 - 2014-08-14 08:37 - 01180672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-07-24 11:52 - 2014-08-14 08:37 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
2014-07-24 11:51 - 2014-08-14 08:37 - 14371328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-07-24 11:51 - 2014-08-14 08:37 - 13757440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-07-24 11:51 - 2014-08-14 08:37 - 02861568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-07-24 11:51 - 2014-08-14 08:37 - 02054656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-07-24 11:51 - 2014-08-14 08:37 - 01440768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-07-24 11:51 - 2014-08-14 08:37 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2014-07-24 11:51 - 2014-08-14 08:37 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-07-24 11:51 - 2014-08-14 08:37 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-07-24 11:51 - 2014-08-14 08:37 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-07-24 11:51 - 2014-08-14 08:37 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-07-24 11:51 - 2014-08-14 08:37 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-07-24 11:51 - 2014-08-14 08:37 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesysprep.dll
2014-07-24 11:51 - 2014-08-14 08:37 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-07-24 11:51 - 2014-08-14 08:37 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-07-24 11:51 - 2014-08-14 08:37 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-07-24 11:51 - 2014-08-14 08:36 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-07-24 11:33 - 2014-08-14 08:36 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-07-24 11:29 - 2014-08-14 08:36 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-07-24 09:03 - 2014-08-14 08:36 - 00534528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
Some content of TEMP:
====================
C:\Users\user\AppData\Local\temp\avgnt.exe
C:\Users\user\AppData\Local\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-07 11:34
==================== End Of Log ============================ --- --- --- |