YaSoKuhl | 11.02.2015 20:27 | Zitat:
Zitat:
Ich hab es aktuell nicht auf dem Deskopt gespeichert sondern unter Downloads, ich hoffe das ist aber nicht verkehrt.
Warum macht man sowas wenn es explizit anders in der Anleitung steht?
| Weil der es von selbst dort installiert wurde und ich nicht gefragt wurde wo ich es installieren will :D
so nun erstmal das mbam Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 11.02.2015
Suchlauf-Zeit: 19:18:12
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.02.11.06
Rootkit Datenbank: v2015.02.03.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Felix
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 403884
Verstrichene Zeit: 30 Min, 39 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 8
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, 1220, Löschen bei Neustart, [f43e53ca078352e40e0187f623deab55]
Trojan.Agent, C:\Windows\rcore.exe, 2104, Löschen bei Neustart, [33ffe13c0e7c26109f494bb32fd313ed]
PUP.Optional.OptimizerPro, C:\ProgramData\{9d67839a-1e27-3658-9d67-7839a1e20e68}\optimizerpro.exe, 9348, Löschen bei Neustart, [7bb7bd6094f6c175a5520e0cec16b44c]
PUP.Optional.LuckyTab.A, C:\Program Files (x86)\LuckyTab\LuckyTab.exe, 7720, Löschen bei Neustart, [68cad4496e1c75c1d1e2549c46bfbf41]
PUP.Optional.Score.A, C:\Windows\rcore.exe, 2104, Löschen bei Neustart, [a98969b4f79380b6fc84e12fb154ae52]
PUP.Optional.ContextTrue.A, C:\Users\Felix\AppData\Local\ContextTrue\nvhlpr.exe, 2740, Löschen bei Neustart, [151d8e8f85053006bd60f08135ce48b8]
PUP.Optional.VOPackage.A, C:\Users\Felix\AppData\Roaming\VOPackage\JOSrv.exe, 1084, Löschen bei Neustart, [3df5f726e1a987af155e1c698b788f71]
PUP.Optional.VOPackage.A, C:\Users\Felix\AppData\Roaming\VOPackage\nsdF9B8.tmpfs, 6088, Löschen bei Neustart, [3df5f726e1a987af155e1c698b788f71]
Module: 1
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [042e95885c2ec175f6062e7e52af17e9],
Registrierungsschlüssel: 61
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginService, In Quarantäne, [f43e53ca078352e40e0187f623deab55],
Trojan.Agent, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\rcores, In Quarantäne, [33ffe13c0e7c26109f494bb32fd313ed],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [122019045733c96d71dfce3b35ce4eb2],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [122019045733c96d71dfce3b35ce4eb2],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [4ce6130a6822e650388356b2d52e24dc],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [4ce6130a6822e650388356b2d52e24dc],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [4ce6130a6822e650388356b2d52e24dc],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [4ce6130a6822e650388356b2d52e24dc],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [4ce6130a6822e650388356b2d52e24dc],
PUP.Optional.SupTab.A, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [4ce6130a6822e650388356b2d52e24dc],
PUP.Optional.SupTab.A, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [4ce6130a6822e650388356b2d52e24dc],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [4ce6130a6822e650388356b2d52e24dc],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{bdc6addf-3c72-484a-a614-9e470f5bfb74}Gw64, In Quarantäne, [2a08d4494c3ed85e205ac1eaab58f50b],
PUP.Optional.DomaIQ.A, HKLM\SOFTWARE\DomaIQ, In Quarantäne, [4be7ab728cfeec4a85b2fadd45beee12],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21636, In Quarantäne, [af8372abe5a5112578bc1fa9db28ff01],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [8da58895800a360003ce4da8f410f40c],
PUP.Optional.AdevertisingSupport.A, HKLM\SOFTWARE\WOW6432NODE\AdvertisingSupport, In Quarantäne, [41f1de3fa7e3c76f33eaf3a5937014ec],
PUP.Optional.DiscountDragon.A, HKLM\SOFTWARE\WOW6432NODE\Discount Dragon, In Quarantäne, [a9890e0fdcaeba7cc32dc1fa7390926e],
PUP.Optional.FreeSoftToday.A, HKLM\SOFTWARE\WOW6432NODE\free_soft_today, In Quarantäne, [2d05af6ed4b6d363d3d98b808382916f],
PUP.Optional.LuckyTab.A, HKLM\SOFTWARE\WOW6432NODE\LuckyTab, In Quarantäne, [032ff32ac4c61b1b9d625eb4b55059a7],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, In Quarantäne, [d65cc9547d0d270f8123159044bfb749],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, In Quarantäne, [d85a9f7ee1a9d66065b0478129da9d63],
PUP.Optional.Bench.A, HKLM\SOFTWARE\WOW6432NODE\BENCH\BService, In Quarantäne, [d35fe637ee9cfc3af405f89a976c08f8],
PUP.Optional.Bench.A, HKLM\SOFTWARE\WOW6432NODE\BENCH\Updater, In Quarantäne, [ca6839e4810986b0ceacaa0f758e728e],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\21636, In Quarantäne, [0230f02ddfabf4420f25fcccec17f50b],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [9d95100df8927bbb6d6495604cb8da26],
PUP.Optional.FastSearchings, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}, In Quarantäne, [5cd6cc5188021b1b1a5da665897cdb25],
PUP.Optional.Booster.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1146AC44-2F03-4431-B4FD-889BC837521F}{4ef60154}, In Quarantäne, [250d53ca701aa88e7f19d7d9eb188779],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, In Quarantäne, [e2509786fd8d2e08841f5451bb48fb05],
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, In Quarantäne, [e052b16c99f1979f0199a90654af659b],
PUP.Optional.BundleInstaller.A, HKLM\SOFTWARE\WOW6432NODE\VITTALIA\AxtanInstaller, In Quarantäne, [052d0b124c3ef640658a339e9c671be5],
PUP.Optional.cherimoya.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\cherimoya, In Quarantäne, [4ce666b75832e353db43800e7e85cb35],
PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginService, In Quarantäne, [7eb477a65e2c8fa7a2c89dface3501ff],
PUP.Optional.Score.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RCORES, In Quarantäne, [a98969b4f79380b6fc84e12fb154ae52],
PUP.Optional.CinemaPlus.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Cinemax Plus 1.9cV09.02-nv-ie, In Quarantäne, [6ac829f46f1baf8785520f8ffc0758a8],
PUP.Optional.Feven.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Feven 1.5, In Quarantäne, [5dd5b5687b0f84b2eaeb0fc0ac57da26],
PUP.Optional.Feven.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Freeven Pro 1.3, In Quarantäne, [73bf34e9d2b8092d8814efc6ee15c23e],
PUP.Optional.PlusHD.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-1.3, In Quarantäne, [3101dc41b1d90b2b459b6f58b2515ba5],
PUP.Optional.CinemaPlus.A, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Cinemax Plus 1.9cV09.02-nv-ie, In Quarantäne, [69c90716cdbd9e98a0378618f90a3ac6],
PUP.Optional.Softonic.A, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, In Quarantäne, [ed45d04d48422e0894bf72225ca705fb],
PUP.Optional.Tuto4PC.A, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\TutoTag, In Quarantäne, [83afba6390fab086926c62aac63f0cf4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, In Quarantäne, [61d1e63704864de97ceeac52bd47d32d],
PUP.Optional.MultiIE.A, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\DynConIE, In Quarantäne, [b9791effbcce6dc94f368f7814f143bd],
PUP.Optional.ReMarkit.A, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Re_markit, In Quarantäne, [eb47de3fcbbf9f979eef1a85bb48e61a],
PUP.Optional.AlexaTB.A, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DISTROMATIC\Toolbars, In Quarantäne, [7cb647d654365ed83682609056ae956b],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21636, In Quarantäne, [e34f1607860495a112b0a0019f6411ef],
PUP.Optional.Qone8, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [a48e78a5563470c622ae579edb2958a8],
PUP.Optional.WebSearchInfo, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}, In Quarantäne, [2909bf5ebdcd83b39abe22d60301c23e],
PUP.Optional.SystemSpeedup, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\ssd, In Quarantäne, [b280a07d7f0bfb3b0d8c842bf013f709],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2313461222-161440706-2079219573-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21636, In Quarantäne, [969ced30b0dab680467ceab7f11212ee],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [8aa877a699f195a131b074f61ee523dd],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [8aa877a699f195a131b074f61ee523dd],
PUP.Optional.ContextTrue.A, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ContextTrue, In Quarantäne, [151d8e8f85053006bd60f08135ce48b8],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B5C4833B-847B-49CD-8EBE-CDD9B43C882F}, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D1661A59-E9D3-4603-8822-2FBEADA5E097}, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E309D526-009C-490B-9BB1-CF9D525F6854}, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D1661A59-E9D3-4603-8822-2FBEADA5E097}, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E309D526-009C-490B-9BB1-CF9D525F6854}, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{B5C4833B-847B-49CD-8EBE-CDD9B43C882F}, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.VOPackage.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\serverjo, In Quarantäne, [3df5f726e1a987af155e1c698b788f71],
PUP.Optional.VOPackage.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\notudijo, In Quarantäne, [3df5f726e1a987af155e1c698b788f71],
Registrierungswerte: 10
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{5081D2D4-1637-404c-B74F-50526718257D}, C:\Program Files\shopperz\Firefox, In Quarantäne, [959dfc21107a56e05c061c75758ed32d]
PUP.Optional.WebSearchInfo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}, In Quarantäne, [250d51ccbcce3afcbcddaf5ef60f14ec]
PUP.Optional.FirstSeenToday.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|fst_de_6, In Quarantäne, [b37f6eaf44467bbb3e20eed37a892cd4],
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|quick_start@gmail.com, C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\jd0sy5rv.default\extensions\quick_start@gmail.com, In Quarantäne, [3200f825f49659dd676892366a99d729]
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{5081D2D4-1637-404c-B74F-50526718257D}, C:\Program Files\shopperz\Firefox, In Quarantäne, [91a19b825139fa3c90d299f8e32013ed]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, tugs, In Quarantäne, [e2509786fd8d2e08841f5451bb48fb05]
PUP.Optional.Score.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RCORES|ImagePath, C:\WINDOWS\rcore.exe, In Quarantäne, [a98969b4f79380b6fc84e12fb154ae52]
PUP.Optional.QuickStart.A, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, quick_start@gmail.com, In Quarantäne, [58da96877e0caf87be8eded5b54e50b0]
PUP.Optional.ContextTrue.A, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|cnthlpr, C:\Users\Felix\AppData\Local\ContextTrue\cnthlpr.exe, In Quarantäne, [151d8e8f85053006bd60f08135ce48b8]
PUP.Optional.ContextTrue.A, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|nvhlpr, C:\Users\Felix\AppData\Local\ContextTrue\nvhlpr.exe, In Quarantäne, [151d8e8f85053006bd60f08135ce48b8]
Registrierungsdaten: 7
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1398361091&from=tugs&uid=ST500LT012-9WS142_W0V139DMXXXXW0V139DM, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1398361091&from=tugs&uid=ST500LT012-9WS142_W0V139DMXXXXW0V139DM),Ersetzt,[e84a0f0e375337ffbbf4842d699c9b65]
PUP.Optional.WebsSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1398361091&from=tugs&uid=ST500LT012-9WS142_W0V139DMXXXXW0V139DM&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1398361091&from=tugs&uid=ST500LT012-9WS142_W0V139DMXXXXW0V139DM&q={searchTerms}),Ersetzt,[ae84021bee9cf73f75b29b146c99748c]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1398361091&from=tugs&uid=ST500LT012-9WS142_W0V139DMXXXXW0V139DM, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1398361091&from=tugs&uid=ST500LT012-9WS142_W0V139DMXXXXW0V139DM),Ersetzt,[5dd57ba23357ff374d60971a65a07c84]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1398361091&from=tugs&uid=ST500LT012-9WS142_W0V139DMXXXXW0V139DM&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1398361091&from=tugs&uid=ST500LT012-9WS142_W0V139DMXXXXW0V139DM&q={searchTerms}),Ersetzt,[ee44bb6277133501505eebc6a164bf41]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[12208a93e5a5e4526e1eb803768f847c]
PUP.Optional.TheSearchPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://websearch.thesearchpage.info/?pid=2832&r=2015/01/26&hid=2248094435555077090&lg=EN&cc=DE&unqvl=74, Gut: (www.google.com), Schlecht: (hxxp://websearch.thesearchpage.info/?pid=2832&r=2015/01/26&hid=2248094435555077090&lg=EN&cc=DE&unqvl=74),Ersetzt,[e44e40ddd1b920160a2e119e0ff6ec14]
PUP.Optional.Tikotin.A, HKU\S-1-5-21-2313461222-161440706-2079219573-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://tikotin.com, Gut: (www.google.com), Schlecht: (hxxp://tikotin.com),Ersetzt,[3200f627aedc3006806b832cdc290cf4]
Ordner: 51
PUP.Optional.AdwarePlugin, C:\Program Files (x86)\Bench\Updater, In Quarantäne, [73bfa776523855e1bc33cf83e320728e],
PUP.Optional.AdwarePlugin, C:\Program Files (x86)\Bench\Updater\1.7.0.0, In Quarantäne, [73bfa776523855e1bc33cf83e320728e],
PUP.Optional.Visualbee, C:\Users\Felix\AppData\Local\VisualBeeExe, In Quarantäne, [81b1918cb4d655e13e0376dd5ca712ee],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService, Löschen bei Neustart, [e2504fcefe8caa8c5902272dfa0935cb],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update, In Quarantäne, [e2504fcefe8caa8c5902272dfa0935cb],
PUP.Optional.Datamngr.A, C:\Users\Felix\AppData\LocalLow\DataMngr, In Quarantäne, [181aaf6efd8d80b6d2250552ad5616ea],
PUP.Optional.WebsSearches.A, C:\Users\Felix\AppData\Roaming\webssearches, In Quarantäne, [ec464fce404a5bdb61d8ed6b838049b7],
PUP.Optional.WebsSearches.A, C:\Users\Felix\AppData\Roaming\webssearches\images, In Quarantäne, [ec464fce404a5bdb61d8ed6b838049b7],
PUP.Optional.WebsSearches.A, C:\Users\Felix\AppData\Roaming\webssearches\log, In Quarantäne, [ec464fce404a5bdb61d8ed6b838049b7],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchquband, In Quarantäne, [f33f7ca17d0dd4628fa2194a40c33ac6],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar\weather, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SystemSpeedup, C:\Users\Felix\AppData\Roaming\systweak\ssd, In Quarantäne, [dc56e6377b0fa096eba90f5a956e7c84],
PUP.Optional.GlobalUpdate.A, C:\Users\Felix\AppData\Local\Temp\comh.419215, In Quarantäne, [8aa877a699f195a131b074f61ee523dd],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, Löschen bei Neustart, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Users\Felix\AppData\Roaming\SupTab, In Quarantäne, [3df59588236769cde9650e60d52e37c9],
PUP.Optional.VisualBee, C:\ProgramData\VisualBee, In Quarantäne, [bc76968790fa82b4abf8fc739a6916ea],
PUP.Optional.ContextTrue.A, C:\Users\Felix\AppData\Local\ContextTrue, Löschen bei Neustart, [151d8e8f85053006bd60f08135ce48b8],
PUP.Optional.SearchResultsTB.A, C:\Users\Felix\AppData\LocalLow\searchresultstb, In Quarantäne, [b181af6eb4d6ca6cf6a4b7be22e154ac],
PUP.Optional.YellowAdblocker.A, C:\ProgramData\Yellow AdBlocker, In Quarantäne, [5ad88697c8c29e982cca01798a798080],
PUP.Optional.LuckyTab.A, C:\Program Files (x86)\LuckyTab, Löschen bei Neustart, [e05227f654360432cdcd5f2058ab9b65],
PUP.Optional.LuckyTab.A, C:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\LuckyTab, In Quarantäne, [ee446bb2fa90b086a3e6d5ab05fe34cc],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.VOPackage.A, C:\Users\Felix\AppData\Roaming\VOPackage, Löschen bei Neustart, [3df5f726e1a987af155e1c698b788f71],
PUP.Optional.BoxRock.A, C:\Users\Felix\AppData\Local\Temp\Box Rock, In Quarantäne, [56dc24f9107a2016ef6ba8df43c040c0],
PUP.Optional.MagnoPlayer.A, C:\Users\Felix\AppData\Local\com\MagnoPlayer.exe_Url_1mhbegbsljequujxisnv3adbpqk4e3ar, In Quarantäne, [38fa6eaff6946ec81762097f24dfb64a],
PUP.Optional.MagnoPlayer.A, C:\Users\Felix\AppData\Local\com\MagnoPlayer.exe_Url_1mhbegbsljequujxisnv3adbpqk4e3ar\2.1.2.10, In Quarantäne, [38fa6eaff6946ec81762097f24dfb64a],
Dateien: 153
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, Löschen bei Neustart, [f43e53ca078352e40e0187f623deab55],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [042e95885c2ec175f6062e7e52af17e9],
Trojan.Agent, C:\Windows\rcore.exe, Löschen bei Neustart, [33ffe13c0e7c26109f494bb32fd313ed],
PUP.Optional.OptimizerPro, C:\ProgramData\{9d67839a-1e27-3658-9d67-7839a1e20e68}\optimizerpro.exe, Löschen bei Neustart, [7bb7bd6094f6c175a5520e0cec16b44c],
PUP.Optional.LuckyTab.A, C:\Program Files (x86)\LuckyTab\LuckyTab.exe, Löschen bei Neustart, [68cad4496e1c75c1d1e2549c46bfbf41],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, In Quarantäne, [4ce6130a6822e650388356b2d52e24dc],
PUP.Optional.CrossRider.A, C:\Users\Felix\AppData\Roaming\BTHO.exe, In Quarantäne, [52e0ad70206acd6989a9b5399471cb35],
PUP.Optional.CrossRider.A, C:\Users\Felix\AppData\Roaming\BVQP.exe, In Quarantäne, [270bbd60375337ffc36ff2fce1242ad6],
PUP.Optional.SupTab.A, C:\Users\Felix\AppData\Roaming\SupTab\SupTab.dll, In Quarantäne, [82b030ede8a2b680fdc24beafa06e719],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, In Quarantäne, [c86ade3fa1e939fdeb118a22867b49b7],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterfacef32.dll, In Quarantäne, [e54d190445451f176894d7d59e6328d8],
PUP.Optional.IEPluginService.A, C:\Program Files (x86)\SupTab\RSHP.exe, In Quarantäne, [9c96d24bf595171f05f3c2cd38c9a858],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, In Quarantäne, [34fedd402b5f77bfbe3ed6d653aede22],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, In Quarantäne, [9d958d908505a2947e7e5755867ba35d],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SpAPPSv32.dll, In Quarantäne, [6dc5839ae8a2b5813cc0a408748ddd23],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SpAPPSv64.dll, In Quarantäne, [e64c5ac3880250e65f9d3478c23f867a],
PUP.Optional.LuckyTab.A, C:\Users\Felix\AppData\Local\Temp\nQEV14k4TH.tmp, In Quarantäne, [38fab469573365d1e6cdef01c540d42c],
PUP.Optional.BPlug, C:\Users\Felix\AppData\Local\Temp\WkLrpRRT9Y.exe, In Quarantäne, [49e9aa73a3e7f73fc787b31e16eb15eb],
PUP.Optional.SFInstaller, C:\Users\Felix\AppData\Local\Temp\fJdGC5oE8T.tmp, In Quarantäne, [60d2e73639514aec18c460b4bb479868],
PUP.Optional.SFInstaller, C:\Users\Felix\AppData\Local\Temp\l9Q8RP88R5.tmp, In Quarantäne, [be74c6576f1b4fe7f4e8b65e8979eb15],
PUP.Optional.MagnoPlayer.A, C:\Users\Felix\AppData\Local\Temp\2cd68b60-2cc2-4661-a499-dfc83ac50f05\magnoplayersetup.exe, In Quarantäne, [b67c4cd17e0cbf77ce8fc7a28b756c94],
PUP.Optional.EZDownloader.A, C:\Users\Felix\AppData\Local\Temp\3C32dAF69Cab\temp\EzDownloader_setup.exe, In Quarantäne, [3af8001d206aec4a877e80a0cd336898],
PUP.Optional.MultiPlug.A, C:\Users\Felix\AppData\Local\Temp\3C32dAF69Cab\temp\hpds_setup.exe, In Quarantäne, [3002fb22a6e402341b703cf706fc7888],
PUP.Optional.OptimizerPro, C:\Users\Felix\AppData\Local\Temp\f711a4a5-d0d9-4747-8a97-8edc7fe3a69f\optimizerpro.exe, In Quarantäne, [0b272bf2f6941c1a2dcaba60d230a858],
PUP.Optional.SFInstaller, C:\Users\Felix\Downloads\MPAutoSave-01232015-153639.svx_downloader.exe, In Quarantäne, [9d95b766cbbf45f138a4858f0cf6b749],
PUP.Optional.Bandoo, C:\Users\Felix\Downloads\iLividSetup.exe, In Quarantäne, [023068b57a108bab425270c0d031768a],
PUP.Optional.SoftPulse, C:\Users\Felix\Downloads\Installation.exe, In Quarantäne, [052de538d3b7270f34ba57c5828019e7],
PUP.Optional.Europa, C:\Users\Felix\Downloads\installer_age_of_mythology_1_Deutsch.exe, In Quarantäne, [54debf5e404aed4998ee81176c9520e0],
PUP.Optional.Bandoo, C:\Users\Felix\Downloads\jZipSetup-r0-n.exe, In Quarantäne, [c2706db0c4c65cda756738a68978a957],
PUP.Optional.BundleInstaller.A, C:\Users\Felix\Downloads\Setup(3).exe, In Quarantäne, [d45ece4f3753ce68302693d748b9e11f],
PUP.Optional.Softonic.A, C:\Users\Felix\Downloads\SoftonicDownloader_fuer_zipgenius.exe, In Quarantäne, [280ae637f9912a0c6788b096976a8080],
PUP.Optional.OptimumInstaller.A, C:\Users\Felix\Downloads\Updater_Setup(1).exe, In Quarantäne, [36fccb52dcae89ade989d0a453aefa06],
PUP.Optional.OptimumInstaller.A, C:\Users\Felix\Downloads\Updater_Setup(2).exe, In Quarantäne, [ac86e538abdf69cdc4ae096b22df04fc],
PUP.Optional.OptimumInstaller.A, C:\Users\Felix\Downloads\Updater_Setup.exe, In Quarantäne, [f2408b925c2ebe783b377ff5d130e917],
PUP.Optional.Somoto, C:\Users\Felix\Downloads\VLCMediaPlayerSetup-4WlK0q8.exe, In Quarantäne, [e44e8a93ff8bca6cc36c37aab451ce32],
PUP.Optional.Somoto.A, C:\Users\Felix\Downloads\VLCMediaPlayerSetup.exe, In Quarantäne, [d35fe03d286268ced5a673c5b34d9868],
PUP.Optional.RegCleanPro, C:\Users\Felix\Downloads\rcpsetup_apptvlatest_apptvlatest.exe, In Quarantäne, [48ea29f43852979f8c7280b40af653ad],
PUP.Optional.Patsearch.A, C:\Windows\patsearch.bin, In Quarantäne, [d45e68b5cfbbf93ddc2918760003c33d],
PUP.Optional.WebInstr.A, C:\Windows\System32\drivers\Msft_Kernel_webinstrNHKT_01009.Wdf, In Quarantäne, [5ed48e8fc4c682b441ec8609f211d32d],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{bdc6addf-3c72-484a-a614-9e470f5bfb74}Gw64.sys, In Quarantäne, [2a08d4494c3ed85e205ac1eaab58f50b],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\48c972a6-1d03-4df8-a32c-efb7cd94e1e7-4, In Quarantäne, [c36f04192466f046770b2e7fe91a58a8],
PUP.Optional.BenchUpdater.A, C:\Windows\System32\Tasks\bench-sys, In Quarantäne, [29093be297f380b69387f8ba3cc7c838],
PUP.Optional.WebsSearches.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\webssearches.xml, In Quarantäne, [47ebcb5295f5092de03701c7aa592ad6],
PUP.Optional.BenchUpdater.A, C:\Windows\Tasks\bench-sys.job, In Quarantäne, [a88a79a499f10e2851a614c1ee15e11f],
PUP.Optional.BenchUpdater.A, C:\Windows\Tasks\bench-Updater removing.job, In Quarantäne, [fe34908d810944f2f502478e45be956b],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\48c972a6-1d03-4df8-a32c-efb7cd94e1e7-4.job, In Quarantäne, [33ff1c011c6e49ed4d5716f4af56867a],
PUP.Optional.LuckyTab.A, C:\Windows\System32\Tasks\LuckyTab, In Quarantäne, [5ad88a93aedc0e2817e758ba50b519e7],
PUP.Optional.Score.A, C:\Windows\rcore.exe, Löschen bei Neustart, [a98969b4f79380b6fc84e12fb154ae52],
PUP.Optional.AdwarePlugin, C:\Program Files (x86)\Bench\Updater\products.xml, In Quarantäne, [73bfa776523855e1bc33cf83e320728e],
PUP.Optional.AdwarePlugin, C:\Program Files (x86)\Bench\Updater\updater.exe, In Quarantäne, [73bfa776523855e1bc33cf83e320728e],
PUP.Optional.AdwarePlugin, C:\Program Files (x86)\Bench\Updater\1.7.0.0\updater.exe, In Quarantäne, [73bfa776523855e1bc33cf83e320728e],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update\conf, In Quarantäne, [e2504fcefe8caa8c5902272dfa0935cb],
PUP.Optional.Datamngr.A, C:\Users\Felix\AppData\LocalLow\DataMngr\{7CA1F051-A4FB-4143-B263-02B41E571EED}, In Quarantäne, [181aaf6efd8d80b6d2250552ad5616ea],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar\dtx.ini, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar\geodata.xml, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar\geoip.xml, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar\guid.dat, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar\log.txt, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar\preferences.dat, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar\stats.dat, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar\uninstallIE.dat, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar\version.xml, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar\weatherbutton_prefs.xml, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar\weather\aec28717eae38b0b83ff801b26202088, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar\weather\f2760bd67e91d544ec20b21e87429533, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar\weather\forecasts_cache.xml, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SearchQu.A, C:\Users\Felix\AppData\LocalLow\searchqutoolbar\weather\observations_cache.xml, In Quarantäne, [d55d21fc7119270fb57daab930d3d828],
PUP.Optional.SystemSpeedup, C:\Users\Felix\AppData\Roaming\systweak\ssd\SSDPTstub.exe, In Quarantäne, [dc56e6377b0fa096eba90f5a956e7c84],
PUP.Optional.GlobalUpdate.A, C:\Users\Felix\AppData\Local\Temp\comh.419215\GoogleCrashHandler.exe, In Quarantäne, [8aa877a699f195a131b074f61ee523dd],
PUP.Optional.GlobalUpdate.A, C:\Users\Felix\AppData\Local\Temp\comh.419215\GoogleUpdate.exe, In Quarantäne, [8aa877a699f195a131b074f61ee523dd],
PUP.Optional.GlobalUpdate.A, C:\Users\Felix\AppData\Local\Temp\comh.419215\GoogleUpdateBroker.exe, In Quarantäne, [8aa877a699f195a131b074f61ee523dd],
PUP.Optional.GlobalUpdate.A, C:\Users\Felix\AppData\Local\Temp\comh.419215\GoogleUpdateHelper.msi, In Quarantäne, [8aa877a699f195a131b074f61ee523dd],
PUP.Optional.GlobalUpdate.A, C:\Users\Felix\AppData\Local\Temp\comh.419215\GoogleUpdateOnDemand.exe, In Quarantäne, [8aa877a699f195a131b074f61ee523dd],
PUP.Optional.GlobalUpdate.A, C:\Users\Felix\AppData\Local\Temp\comh.419215\goopdate.dll, In Quarantäne, [8aa877a699f195a131b074f61ee523dd],
PUP.Optional.GlobalUpdate.A, C:\Users\Felix\AppData\Local\Temp\comh.419215\goopdateres_en.dll, In Quarantäne, [8aa877a699f195a131b074f61ee523dd],
PUP.Optional.GlobalUpdate.A, C:\Users\Felix\AppData\Local\Temp\comh.419215\npGoogleUpdate4.dll, In Quarantäne, [8aa877a699f195a131b074f61ee523dd],
PUP.Optional.GlobalUpdate.A, C:\Users\Felix\AppData\Local\Temp\comh.419215\psmachine.dll, In Quarantäne, [8aa877a699f195a131b074f61ee523dd],
PUP.Optional.GlobalUpdate.A, C:\Users\Felix\AppData\Local\Temp\comh.419215\psuser.dll, In Quarantäne, [8aa877a699f195a131b074f61ee523dd],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WebDataJs, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\arrow.png, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo.png, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo_hover.png, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_logo.png, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo.png, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo2.png, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\0.png, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ie8.js, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, In Quarantäne, [42f04fcea3e75fd7103d1d518f743ac6],
PUP.Optional.VisualBee, C:\ProgramData\VisualBee\VisualBeeDB.exe, In Quarantäne, [bc76968790fa82b4abf8fc739a6916ea],
PUP.Optional.VisualBee, C:\ProgramData\VisualBee\VisualBeeSoftware.exe, In Quarantäne, [bc76968790fa82b4abf8fc739a6916ea],
PUP.Optional.ContextTrue.A, C:\Users\Felix\AppData\Local\ContextTrue\cnthlpr.exe, In Quarantäne, [151d8e8f85053006bd60f08135ce48b8],
PUP.Optional.ContextTrue.A, C:\Users\Felix\AppData\Local\ContextTrue\ContextTrue_Uninstaller.exe, In Quarantäne, [151d8e8f85053006bd60f08135ce48b8],
PUP.Optional.ContextTrue.A, C:\Users\Felix\AppData\Local\ContextTrue\notifications.exe, In Quarantäne, [151d8e8f85053006bd60f08135ce48b8],
PUP.Optional.ContextTrue.A, C:\Users\Felix\AppData\Local\ContextTrue\nvhlpr.exe, Löschen bei Neustart, [151d8e8f85053006bd60f08135ce48b8],
PUP.Optional.ContextTrue.A, C:\Users\Felix\AppData\Local\ContextTrue\windoclib.exe, In Quarantäne, [151d8e8f85053006bd60f08135ce48b8],
PUP.Optional.YellowAdblocker.A, C:\ProgramData\Yellow AdBlocker\Yellow AdBlocker.exe, In Quarantäne, [5ad88697c8c29e982cca01798a798080],
PUP.Optional.LuckyTab.A, C:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\LuckyTab\Get Lucky.lnk, In Quarantäne, [ee446bb2fa90b086a3e6d5ab05fe34cc],
PUP.Optional.LuckyTab.A, C:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\LuckyTab\Help.lnk, In Quarantäne, [ee446bb2fa90b086a3e6d5ab05fe34cc],
PUP.Optional.LuckyTab.A, C:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\LuckyTab\Uninstall.lnk, In Quarantäne, [ee446bb2fa90b086a3e6d5ab05fe34cc],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\grunt.exe, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\kasumi32.dll, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\kasumi64.dll, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\krios.dll, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\liara.dll, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\liara64.dll, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\spdata.exe, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\tsoni.dll, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\tsoni64.dll, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\wrex.exe, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\wrex64.exe, In Quarantäne, [53df46d76d1dc86e279b30545aa9bc44],
PUP.Optional.VOPackage.A, C:\Users\Felix\AppData\Roaming\VOPackage\JOSrv.exe, Löschen bei Neustart, [3df5f726e1a987af155e1c698b788f71],
PUP.Optional.VOPackage.A, C:\Users\Felix\AppData\Roaming\VOPackage\nsdF9B8.tmpfs, Löschen bei Neustart, [3df5f726e1a987af155e1c698b788f71],
PUP.Optional.VOPackage.A, C:\Users\Felix\AppData\Roaming\VOPackage\VOPackage.exe, In Quarantäne, [3df5f726e1a987af155e1c698b788f71],
PUP.Optional.MagnoPlayer.A, C:\Users\Felix\AppData\Local\com\MagnoPlayer.exe_Url_1mhbegbsljequujxisnv3adbpqk4e3ar\2.1.2.10\user.config, In Quarantäne, [38fa6eaff6946ec81762097f24dfb64a],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end)
und dann das adwcleaner Code:
# AdwCleaner v4.110 - Bericht erstellt 11/02/2015 um 20:07:57
# Aktualisiert 05/02/2015 von Xplode
# Datenbank : 2015-02-09.1 [Server]
# Betriebssystem : Windows 8.1 (x64)
# Benutzername : Felix - FELIX
# Gestarted von : C:\Users\Felix\Downloads\AdwCleaner_4.110.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\ProgramData\6826811331309999200
Ordner Gelöscht : C:\ProgramData\727a4a8400002781
Ordner Gelöscht : C:\ProgramData\774b772000003d1c
Ordner Gelöscht : C:\ProgramData\afe9897c000007d3
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip
Ordner Gelöscht : C:\Program Files (x86)\Amazon\ABB
Ordner Gelöscht : C:\Program Files (x86)\Bench
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Program Files (x86)\Optimizer Pro
Ordner Gelöscht : C:\Program Files (x86)\predm
Ordner Gelöscht : C:\Program Files (x86)\BBestSSavveForYOu
Ordner Gelöscht : C:\Program Files (x86)\DiscouinttExtEEnsii
Ordner Gelöscht : C:\Program Files (x86)\FunDEals
Ordner Gelöscht : C:\Program Files (x86)\FuoN2SSave
Ordner Gelöscht : C:\Program Files (x86)\IsAAvver
Ordner Gelöscht : C:\Program Files (x86)\ISiavEr
Ordner Gelöscht : C:\Program Files (x86)\NNetoCOupON
Ordner Gelöscht : C:\Program Files (x86)\TakkeTheCooupon
Ordner Gelöscht : C:\Program Files (x86)\uunIisalEs
Ordner Gelöscht : C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\AnyProtectEx
Ordner Gelöscht : C:\Users\Felix\AppData\Local\emaze
Ordner Gelöscht : C:\Users\Felix\AppData\Local\Genesis
Ordner Gelöscht : C:\Users\Felix\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Felix\AppData\Local\lollipop
Ordner Gelöscht : C:\Users\Felix\AppData\LocalLow\ilividtoolbarguid
Ordner Gelöscht : C:\Users\Felix\AppData\Roaming\AnyProtectEx
Ordner Gelöscht : C:\Users\Felix\AppData\Roaming\SimpleFiles
Ordner Gelöscht : C:\Users\Felix\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Felix\Documents\Optimizer Pro
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\Public\Desktop\Get The Best Facebook Chat Messenger.lnk
Datei Gelöscht : C:\Users\Felix\AppData\Local\Temp\Uninstall.exe
Datei Gelöscht : C:\WINDOWS\System32\roboot64.exe
Datei Gelöscht : C:\Users\Felix\Desktop\Continue Live Installation.lnk
***** [ Geplante Tasks ] *****
Task Gelöscht : APSnotifierPP1
Task Gelöscht : APSnotifierPP2
Task Gelöscht : APSnotifierPP3
Task Gelöscht : LaunchSignup
Task Gelöscht : LuckyTab
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [framei]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\driverscanner
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
Schlüssel Gelöscht : HKCU\Software\Mozilla\Extends
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P5685125f_26e7_41b4_86d1_0ce53dc5ad77_.P5685125f_26e7_41b4_86d1_0ce53dc5ad77_
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P5685125f_26e7_41b4_86d1_0ce53dc5ad77_.P5685125f_26e7_41b4_86d1_0ce53dc5ad77_.9
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P618c26cc_7498_459d_8867_c16217159b43_.P618c26cc_7498_459d_8867_c16217159b43_
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P618c26cc_7498_459d_8867_c16217159b43_.P618c26cc_7498_459d_8867_c16217159b43_.9
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Pd224b8ea_cfc8_4105_8b98_03176b522007_.Pd224b8ea_cfc8_4105_8b98_03176b522007_
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Pd224b8ea_cfc8_4105_8b98_03176b522007_.Pd224b8ea_cfc8_4105_8b98_03176b522007_.9
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Pf773edb6_bddd_45ac_907e_0ac3aefed72b_.Pf773edb6_bddd_45ac_907e_0ac3aefed72b_
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Pf773edb6_bddd_45ac_907e_0ac3aefed72b_.Pf773edb6_bddd_45ac_907e_0ac3aefed72b_.9
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5685125f-26e7-41b4-86d1-0ce53dc5ad77}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{618c26cc-7498-459d-8867-c16217159b43}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{d224b8ea-cfc8-4105-8b98-03176b522007}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{f773edb6-bddd-45ac-907e-0ac3aefed72b}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{079E2F0F-FCA0-4163-BC82-5355B879E86E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{5D6736D5-0D77-46CE-9906-C4B2C679BF88}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C7405EEB-2E16-40FE-9E27-1F48CAAB15E1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5685125f-26e7-41b4-86d1-0ce53dc5ad77}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{618c26cc-7498-459d-8867-c16217159b43}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{d224b8ea-cfc8-4105-8b98-03176b522007}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{f773edb6-bddd-45ac-907e-0ac3aefed72b}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5685125f-26e7-41b4-86d1-0ce53dc5ad77}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{618c26cc-7498-459d-8867-c16217159b43}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{d224b8ea-cfc8-4105-8b98-03176b522007}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{f773edb6-bddd-45ac-907e-0ac3aefed72b}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5685125f-26e7-41b4-86d1-0ce53dc5ad77}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{618c26cc-7498-459d-8867-c16217159b43}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{d224b8ea-cfc8-4105-8b98-03176b522007}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{f773edb6-bddd-45ac-907e-0ac3aefed72b}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{618c26cc-7498-459d-8867-c16217159b43}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{f773edb6-bddd-45ac-907e-0ac3aefed72b}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\distromatic
Schlüssel Gelöscht : HKCU\Software\genesis
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\SimpleFiles
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\visualbee
Schlüssel Gelöscht : HKCU\Software\ContextTrue
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SpeeditUp
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Bench
Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gelöscht : HKLM\SOFTWARE\SimpleFiles
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Tutorials
Schlüssel Gelöscht : HKLM\SOFTWARE\Uniblue
Schlüssel Gelöscht : HKLM\SOFTWARE\VBMZ
Schlüssel Gelöscht : HKLM\SOFTWARE\visualbee
Schlüssel Gelöscht : HKLM\SOFTWARE\Vittalia
Schlüssel Gelöscht : HKLM\SOFTWARE\Wpm
Schlüssel Gelöscht : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Taronja
Schlüssel Gelöscht : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\istart.webssearches.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\portaldosites.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\searchnu.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\tikotin.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\webssearches.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.portaldosites.com
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17416
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
-\\ Mozilla Firefox v35.0.1 (x86 de)
*************************
AdwCleaner[R0].txt - [10812 Bytes] - [11/02/2015 20:06:17]
AdwCleaner[S0].txt - [10103 Bytes] - [11/02/2015 20:07:57]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [10163 Bytes] ##########
dann das jrt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 8.1 x64
Ran by Felix on 11.02.2015 at 20:14:41,37
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] C:\WINDOWS\prefetch\DRIVERSCANNER.TMP-C3838236.pf
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Felix\AppData\Roaming\mozilla\firefox\profiles\zbjctoqm.default-1423487753600\minidumps [1 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 11.02.2015 at 20:16:19,93
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ das neue frst log
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-02-2015 02
Ran by Felix (administrator) on FELIX on 11-02-2015 20:17:39
Running from C:\Users\Felix\Downloads
Loaded Profiles: Felix (Available profiles: Felix & Administrator)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Update\Lenovo Smart Update Service.exe
(Absolute Software Corp.) C:\Windows\SysWOW64\rpcnet.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
() C:\Program Files (x86)\Lenovo EasyCamera\Monitor.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12937872 2012-07-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-07-10] (Realtek Semiconductor)
HKLM\...\Run: [HotKeysCmds] => C:\WINDOWS\system32\hkcmd.exe
HKLM\...\Run: [Persistence] => C:\WINDOWS\system32\igfxpers.exe
HKLM\...\Run: [SynLenovoGestureMgr] => C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [665400 2012-08-27] (Synaptics)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17080376 2012-10-06] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [191544 2012-10-06] (Lenovo(beijing) Limited)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-27] (Synaptics Incorporated)
HKLM-x32\...\Run: [Lenovo EasyCamera_Monitor] => C:\Program Files (x86)\Lenovo EasyCamera\monitor.exe [267128 2012-06-04] ()
HKLM-x32\...\Run: [Smart Update] => C:\Program Files (x86)\Lenovo\Lenovo Smart Update\Lenovo Smart Update.exe [1706576 2012-08-02] (Lenovo)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2012-07-27] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167024 2012-07-27] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2313461222-161440706-2079219573-1001\...\Run: [Spotify] => C:\Users\Felix\AppData\Roaming\Spotify\Spotify.exe [6737976 2014-12-10] (Spotify Ltd)
HKU\S-1-5-21-2313461222-161440706-2079219573-1001\...\Run: [Spotify Web Helper] => C:\Users\Felix\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-10] (Spotify Ltd)
HKU\S-1-5-21-2313461222-161440706-2079219573-1001\...\Run: [Polar FlowSync] => C:\Games\Polar FlowSync\FlowSync.exe [1125376 2014-11-11] (Polar Electro Oy)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Felix\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MPAutoSave-01232015-153639.svx.lnk
ShortcutTarget: MPAutoSave-01232015-153639.svx.lnk -> C:\ProgramData\{91e0f5e0-82d7-6431-91e0-0f5e082dd782}\MPAutoSave-01232015-153639.svx.exe ()
Startup: C:\Users\Felix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\optimizerpro.lnk
ShortcutTarget: optimizerpro.lnk -> C:\ProgramData\{9d67839a-1e27-3658-9d67-7839a1e20e68}\optimizerpro.exe (No File)
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-2313461222-161440706-2079219573-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-2313461222-161440706-2079219573-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Felix\AppData\Roaming\Mozilla\Firefox\Profiles\zbjctoqm.default-1423487753600
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF HKU\S-1-5-21-2313461222-161440706-2079219573-1001\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - No Path
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-12] (Microsoft Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [314696 2014-05-21] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 Lenovo Smart Update Service; C:\Program Files (x86)\Lenovo\Lenovo Smart Update\Lenovo Smart Update Service.exe [66640 2012-07-18] (Lenovo)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-09-24] (Microsoft Corporation)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [857472 2012-08-29] (Motorola Solutions, Inc.)
R3 LAD; C:\Windows\System32\drivers\LAD.sys [8704 2012-06-08] (TODO: <Company name>)
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew00.sys [3345376 2013-10-08] (Intel Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-27] (Synaptics Incorporated)
R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1070712 2012-08-11] (Sunplus)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-11 20:17 - 2015-02-11 20:17 - 00000000 ____D () C:\Users\Felix\Downloads\FRST-OlderVersion
2015-02-11 20:16 - 2015-02-11 20:16 - 00000841 _____ () C:\Users\Felix\Desktop\JRT.txt
2015-02-11 20:13 - 2015-02-11 20:14 - 01388274 _____ (Thisisu) C:\Users\Felix\Downloads\JRT.exe
2015-02-11 20:11 - 2015-02-11 20:11 - 00010268 _____ () C:\Users\Felix\Desktop\AdwCleaner[S0].txt
2015-02-11 20:09 - 2015-02-11 20:09 - 00017408 _____ () C:\WINDOWS\SysWOW64\rpcnetp.dll
2015-02-11 20:05 - 2015-02-11 20:08 - 00000000 ____D () C:\AdwCleaner
2015-02-11 20:05 - 2015-02-11 20:05 - 02112512 _____ () C:\Users\Felix\Downloads\AdwCleaner_4.110.exe
2015-02-11 20:02 - 2015-02-11 20:02 - 00043838 _____ () C:\Users\Felix\Desktop\mbam.txt
2015-02-11 19:57 - 2015-02-11 19:57 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2015-02-11 19:17 - 2015-02-11 20:10 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-02-11 19:16 - 2015-02-11 19:16 - 00001125 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-11 19:16 - 2015-02-11 19:16 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-11 19:16 - 2015-02-11 19:16 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-11 19:16 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-02-11 19:16 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-02-11 19:16 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-02-11 19:14 - 2015-02-11 19:15 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Felix\Desktop\mbam-setup-2.0.4.1028.exe
2015-02-11 19:02 - 2015-02-11 19:02 - 00001291 _____ () C:\Users\Felix\Desktop\Revo Uninstaller.lnk
2015-02-11 19:02 - 2015-02-11 19:02 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-02-11 19:00 - 2015-02-11 19:00 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Felix\Desktop\revosetup95.exe
2015-02-11 14:30 - 2015-02-11 14:31 - 00029581 _____ () C:\Users\Felix\Downloads\Addition.txt
2015-02-11 14:27 - 2015-02-11 20:17 - 00013402 _____ () C:\Users\Felix\Downloads\FRST.txt
2015-02-11 14:25 - 2015-02-11 20:17 - 02134016 _____ (Farbar) C:\Users\Felix\Downloads\FRST64.exe
2015-02-11 14:25 - 2015-02-11 20:17 - 00000000 ____D () C:\FRST
2015-02-11 10:40 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-02-11 10:40 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-02-11 10:40 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-02-11 10:40 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-02-11 10:40 - 2015-01-12 03:34 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-02-11 10:40 - 2015-01-12 03:32 - 06041088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-02-11 10:40 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-02-11 10:40 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2015-02-11 10:40 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-02-11 10:40 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-02-11 10:40 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-02-11 10:40 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-02-11 10:40 - 2015-01-12 02:58 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-02-11 10:40 - 2015-01-12 02:55 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-02-11 10:40 - 2015-01-12 02:51 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-02-11 10:40 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-02-11 10:40 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-02-11 10:40 - 2015-01-12 02:48 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-02-11 10:40 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-02-11 10:40 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2015-02-11 10:40 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-02-11 10:40 - 2015-01-12 02:34 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-02-11 10:40 - 2015-01-12 02:29 - 04300800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-02-11 10:40 - 2015-01-12 02:27 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-02-11 10:40 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-02-11 10:40 - 2015-01-12 02:25 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-02-11 10:40 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-02-11 10:40 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-02-11 10:40 - 2015-01-12 02:23 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-02-11 10:40 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-02-11 10:40 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-02-11 10:40 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-02-11 10:40 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-02-11 10:40 - 2015-01-10 10:10 - 07472960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-02-11 10:40 - 2015-01-10 10:10 - 01733440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-02-11 10:40 - 2015-01-10 09:28 - 01498360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-02-11 10:40 - 2015-01-10 09:22 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-02-11 10:40 - 2015-01-10 08:00 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-02-11 10:40 - 2015-01-10 07:38 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2015-02-11 10:40 - 2014-10-29 03:02 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2015-02-11 10:40 - 2014-10-29 03:02 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2015-02-11 10:40 - 2014-10-29 02:57 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntvdm64.dll
2015-02-11 10:40 - 2014-10-29 02:15 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll
2015-02-11 10:40 - 2014-10-29 02:15 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll
2015-02-11 10:40 - 2014-10-29 02:14 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe
2015-02-11 10:40 - 2014-10-29 02:13 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe
2015-02-11 10:40 - 2014-10-29 02:13 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\instnm.exe
2015-02-11 10:39 - 2015-01-19 19:42 - 01487976 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2015-02-11 10:39 - 2015-01-12 02:30 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-02-11 10:39 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-02-11 10:39 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-02-11 10:23 - 2015-01-15 23:43 - 00563504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-02-11 10:23 - 2015-01-15 23:43 - 00177984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-02-11 10:23 - 2015-01-14 05:22 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-02-11 10:23 - 2015-01-14 04:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-02-11 10:23 - 2014-12-19 09:57 - 00788680 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2015-02-11 10:23 - 2014-12-19 09:25 - 00602776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2015-02-11 10:23 - 2014-12-09 04:45 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scesrv.dll
2015-02-11 10:23 - 2014-12-09 02:56 - 00538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\scesrv.dll
2015-02-11 10:23 - 2014-12-09 00:12 - 00391526 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-02-11 10:23 - 2014-10-29 03:51 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll
2015-02-11 10:23 - 2014-10-29 03:50 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2015-02-11 10:23 - 2014-10-29 03:06 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2015-02-11 10:23 - 2014-10-29 03:06 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll
2015-02-11 10:23 - 2014-10-29 02:31 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-02-11 10:22 - 2015-01-13 23:11 - 01762840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2015-02-11 10:22 - 2015-01-13 23:04 - 01489072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2015-02-09 14:16 - 2015-02-09 14:16 - 00000000 ____D () C:\Users\Felix\Desktop\Alte Firefox-Daten
2015-02-09 14:07 - 2015-02-09 14:07 - 00001182 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-02-09 14:07 - 2015-02-09 14:07 - 00001170 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-02-09 12:16 - 2015-02-11 20:09 - 00001346 _____ () C:\WINDOWS\Tasks\BVQP.job
2015-02-09 12:16 - 2015-02-11 20:09 - 00001346 _____ () C:\WINDOWS\Tasks\BTHO.job
2015-02-09 12:16 - 2015-02-09 12:16 - 00004346 _____ () C:\WINDOWS\System32\Tasks\BVQP
2015-02-09 12:16 - 2015-02-09 12:16 - 00004346 _____ () C:\WINDOWS\System32\Tasks\BTHO
2015-02-09 11:10 - 2015-02-11 19:50 - 00000000 ____D () C:\Users\Felix\AppData\Local\com
2015-02-09 11:10 - 2015-02-09 18:15 - 00000000 ___HD () C:\Users\Public\Temp
2015-02-09 11:08 - 2015-02-11 19:55 - 00000000 ____D () C:\ProgramData\{9d67839a-1e27-3658-9d67-7839a1e20e68}
2015-02-09 11:00 - 2015-02-09 11:00 - 00000000 ____D () C:\Program Files (x86)\New Tab Redirect Plus
2015-02-04 15:47 - 2015-02-04 15:47 - 00010168 _____ () C:\Users\Felix\Downloads\Facharbeit2.odt
2015-02-04 15:02 - 2015-02-04 15:02 - 00061514 _____ () C:\Users\Felix\Downloads\Facharbeit.odt
2015-02-03 16:06 - 2015-02-03 16:06 - 00017943 _____ () C:\Users\Felix\Downloads\valdation2.odt
2015-02-03 15:34 - 2015-02-03 15:34 - 00072315 _____ () C:\Users\Felix\Downloads\valdation.odt
2015-02-03 01:18 - 2015-02-03 01:18 - 00000000 ____D () C:\Program Files (x86)\Instair
2015-02-03 00:38 - 2015-02-11 04:11 - 00000079 _____ () C:\Program Files (x86)\prefs.js
2015-02-02 16:18 - 2015-02-02 16:18 - 00000000 ____D () C:\Program Files (x86)\WasteNoTime
2015-02-02 09:46 - 2015-02-02 09:46 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Warner Bros. Interactive Entertainment
2015-01-27 05:01 - 2015-02-09 14:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-26 15:51 - 2015-01-26 15:51 - 00628496 _____ (CMI Limited) C:\Users\Felix\AppData\Local\nscC585.tmp
2015-01-26 15:12 - 2015-01-26 15:12 - 00613057 _____ (CMI Limited) C:\Users\Felix\AppData\Local\nseD81F.tmp
2015-01-26 14:37 - 2015-01-26 14:38 - 07493934 _____ () C:\Users\Felix\Downloads\MPAutoSave-01232015-153639.svx
2015-01-26 14:32 - 2015-01-26 17:34 - 00000000 ____D () C:\ProgramData\{91e0f5e0-82d7-6431-91e0-0f5e082dd782}
2015-01-26 14:32 - 2015-01-26 14:32 - 01371000 _____ () C:\Users\Felix\Downloads\MPAutoSave-01232015-153639.svx.exe
2015-01-26 14:32 - 2015-01-26 14:32 - 01371000 _____ () C:\Users\Felix\Downloads\Download.exe
2015-01-25 17:12 - 2015-01-25 17:12 - 00002086 _____ () C:\Users\Felix\AppData\Roaming\BVQP
2015-01-25 17:12 - 2015-01-25 17:12 - 00001248 _____ () C:\Users\Felix\AppData\Roaming\BTHO
2015-01-21 07:05 - 2015-01-21 07:06 - 24075564 _____ (diclovit ) C:\Users\Felix\Downloads\dmp_9.5.2_setup.exe
2015-01-14 05:09 - 2014-12-19 07:26 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2015-01-14 05:09 - 2014-12-12 03:04 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2015-01-14 05:09 - 2014-12-12 01:51 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2015-01-14 05:09 - 2014-12-09 02:50 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-01-14 05:09 - 2014-12-08 20:42 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-01-14 05:09 - 2014-12-08 20:42 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-01-14 05:09 - 2014-12-08 20:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2015-01-14 05:09 - 2014-12-08 20:42 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2015-01-14 05:09 - 2014-12-08 20:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2015-01-14 05:09 - 2014-12-08 20:42 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-01-14 05:09 - 2014-12-08 20:42 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2015-01-14 05:09 - 2014-12-08 20:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2015-01-14 05:09 - 2014-12-06 04:17 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-01-14 05:09 - 2014-12-06 02:41 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-01-14 05:09 - 2014-12-06 02:35 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-01-14 05:09 - 2014-10-29 05:00 - 00465320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2015-01-14 05:09 - 2014-10-29 05:00 - 00139984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2015-01-14 05:09 - 2014-10-29 04:52 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-01-14 05:09 - 2014-10-29 04:52 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-01-14 05:09 - 2014-10-29 04:52 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2015-01-14 05:09 - 2014-10-29 04:52 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2015-01-14 05:09 - 2014-10-29 04:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2015-01-14 05:09 - 2014-10-29 04:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2015-01-14 05:09 - 2014-10-29 04:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-01-14 05:09 - 2014-10-29 04:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-01-14 05:09 - 2014-10-29 04:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2015-01-14 05:09 - 2014-10-29 03:44 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2015-01-14 05:09 - 2014-10-29 02:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2015-01-14 05:09 - 2014-10-29 02:24 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2015-01-14 05:09 - 2014-10-29 02:02 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-01-14 05:09 - 2014-10-29 02:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-11 20:15 - 2014-04-20 08:32 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-02-11 20:15 - 2013-12-03 19:56 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2313461222-161440706-2079219573-1001
2015-02-11 20:11 - 2014-10-27 20:20 - 00000000 ___DO () C:\Users\Felix\OneDrive
2015-02-11 20:10 - 2014-10-27 18:56 - 00017408 _____ () C:\WINDOWS\system32\rpcnetp.exe
2015-02-11 20:09 - 2014-10-27 18:56 - 00017408 ____N () C:\WINDOWS\SysWOW64\rpcnetp.exe
2015-02-11 20:09 - 2014-09-23 22:06 - 00071814 _____ () C:\WINDOWS\PFRO.log
2015-02-11 20:09 - 2013-12-03 20:01 - 00069792 _____ (Absolute Software Corp.) C:\WINDOWS\SysWOW64\rpcnet.dll
2015-02-11 20:09 - 2013-08-22 15:46 - 00332816 _____ () C:\WINDOWS\setupact.log
2015-02-11 20:09 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-02-11 20:08 - 2014-10-27 19:11 - 01728116 _____ () C:\WINDOWS\WindowsUpdate.log
2015-02-11 20:08 - 2014-10-27 18:56 - 00029336 _____ () C:\WINDOWS\system32\wpbbin.exe
2015-02-11 20:08 - 2013-08-22 14:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2015-02-11 20:02 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-02-11 19:56 - 2013-08-22 15:44 - 00448552 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-02-11 17:34 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-02-11 17:33 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-02-11 16:14 - 2014-11-17 20:15 - 00003918 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{B7179F6F-434D-4912-BFB7-E813CCBD713F}
2015-02-11 14:21 - 2014-09-24 07:17 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-02-11 14:21 - 2014-09-24 06:43 - 00765582 _____ () C:\WINDOWS\system32\perfh007.dat
2015-02-11 14:21 - 2014-09-24 06:43 - 00159366 _____ () C:\WINDOWS\system32\perfc007.dat
2015-02-11 10:55 - 2013-12-04 19:39 - 00000000 ____D () C:\Users\Felix\AppData\Roaming\Skype
2015-02-09 20:09 - 2013-12-03 20:54 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-09 11:10 - 2014-04-20 08:32 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-02-09 11:10 - 2013-12-03 20:16 - 00000000 ____D () C:\Users\Felix\AppData\Local\Adobe
2015-02-07 06:59 - 2013-01-13 18:11 - 00000000 ____D () C:\Users\Felix\Documents\Universität
2015-02-05 00:47 - 2014-12-15 22:05 - 00000000 ____D () C:\Program Files\paint.net
2015-02-03 20:31 - 2014-09-24 08:46 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-02-03 20:31 - 2014-09-24 08:46 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-26 18:45 - 2012-07-26 06:26 - 00000290 _____ () C:\WINDOWS\win.ini
2015-01-26 15:45 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\GroupPolicy
2015-01-21 07:09 - 2014-04-21 14:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\diclovit's mod pack
2015-01-21 06:05 - 2014-09-24 08:21 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-21 06:05 - 2013-12-04 19:39 - 00000000 ____D () C:\ProgramData\Skype
2015-01-14 05:58 - 2013-12-05 12:28 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-01-14 05:54 - 2013-12-05 12:28 - 113365784 ____N (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
==================== Files in the root of some directories =======
2015-02-03 00:38 - 2015-02-11 04:11 - 0000079 _____ () C:\Program Files (x86)\prefs.js
2013-12-03 19:46 - 2013-12-06 01:00 - 0003836 _____ () C:\Users\Felix\AppData\Roaming\AbsoluteReminder.xml
2015-01-25 17:12 - 2015-01-25 17:12 - 0001248 _____ () C:\Users\Felix\AppData\Roaming\BTHO
2015-01-25 17:12 - 2015-01-25 17:12 - 0002086 _____ () C:\Users\Felix\AppData\Roaming\BVQP
2014-05-10 09:41 - 2014-12-15 22:10 - 0000757 _____ () C:\Users\Felix\AppData\Roaming\mainhst.zgh
2015-01-26 15:51 - 2015-01-26 15:51 - 0628496 _____ (CMI Limited) C:\Users\Felix\AppData\Local\nscC585.tmp
2015-01-26 15:12 - 2015-01-26 15:12 - 0613057 _____ (CMI Limited) C:\Users\Felix\AppData\Local\nseD81F.tmp
2014-04-24 18:39 - 2014-04-24 18:39 - 1107304 _____ (AnyProtect.com) C:\Users\Felix\AppData\Local\nsfC334.tmp
2014-02-11 19:02 - 2014-02-11 19:02 - 0901662 _____ () C:\ProgramData\1392140374.bdinstall.bin
2014-04-20 01:37 - 2014-04-20 01:37 - 0258477 _____ () C:\ProgramData\1397954067.bdinstall.bin
2013-12-03 20:09 - 2013-12-03 20:09 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some content of TEMP:
====================
C:\Users\Felix\AppData\Local\Temp\0sUfHhlKBX.exe
C:\Users\Felix\AppData\Local\Temp\255e50CCb9286.exe
C:\Users\Felix\AppData\Local\Temp\7sTBzQNspC.exe
C:\Users\Felix\AppData\Local\Temp\BackupSetup.exe
C:\Users\Felix\AppData\Local\Temp\D8B7EA8E-F929-29BC-958B-E3FDA65C1CC0.exe
C:\Users\Felix\AppData\Local\Temp\DF3EF2A8-33D7-597B-3F85-603AB40DCDA0.dll
C:\Users\Felix\AppData\Local\Temp\DF3EF2A8-33D7-597B-3F85-603AB40DCDA0.exe
C:\Users\Felix\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpimqif9.dll
C:\Users\Felix\AppData\Local\Temp\jYtbdtnNaA.exe
C:\Users\Felix\AppData\Local\Temp\optprosetup.exe
C:\Users\Felix\AppData\Local\Temp\Quarantine.exe
C:\Users\Felix\AppData\Local\Temp\sdfE6B7.exe
C:\Users\Felix\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-03 16:24
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
hoffe ich hab nix vergessen |