Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 8.1: Werbe-Popups in Google Chrome und Opera

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 21.07.2014, 08:56   #1
flo344i
 
Windows 8.1: Werbe-Popups in Google Chrome und Opera - Standard

Windows 8.1: Werbe-Popups in Google Chrome und Opera



Guten Morgen!

Seit Ende letzter Woche habe ich das nervige Problem das in Google Chrome und auch Opera ständig Werbe-Popups aufgehen. Es sind verschieden Seiten die aufgehen, 123srv, ein angebliches Java Update, Alldaysavings...! Das installierte Kaspersky Internet Security meckert nicht! Auf manchen Seiten erscheinen auch Werbebanner in Form von kleinen Fenstern!

Habe jetzt alles wie in der Anleitung beschrieben durchgeführt! Unten dann die Logfiles. GMER funktioniert nicht richtig, startet zwar meldet dann aber "C:/Windows/system32/config/system: Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird" Dann lässt es mich den Scan durchführen und danach kommt die selbe Meldung. Logfile ist auch unten!

Code:
ATTFilter
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 09:22 on 21/07/2014 (Florian-KFZMeister)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-
         
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-07-2014
Ran by Florian-KFZMeister (administrator) on WERKSTATT-PC on 21-07-2014 09:25:52
Running from C:\Users\Florian-KFZMeister\Desktop
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ 
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ 
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files\005\cyycfhtzro64.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
(WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
() C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Opera Software) C:\Program Files (x86)\Opera\opera.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191824 2012-08-10] (Realtek Semiconductor)
HKLM\...\Run: [BtTray] => C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [766080 2012-12-05] (Qualcomm Atheros)
HKLM\...\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [128640 2012-12-05] (Atheros Communications)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2917688 2012-10-16] (Synaptics Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [40312 2014-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [97392 2012-08-15] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-12] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de)
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\runner_avp.exe [24504 2012-12-14] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [StartDDM] => C:\Program Files (x86)\Bosch\DownloadManager\bin\runDDM.exe [260608 2012-02-10] (Robert Bosch GmbH)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-18] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1825984 2014-04-24] (Valve Corporation)
HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Florian-KFZMeister\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHel (the data entry has 8 more characters).
HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [Amazon Cloud Player] => C:\Users\Florian-KFZMeister\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3145536 2013-12-12] ()
HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Policies\system: [DisableLockWorkstation] 0
IFEO: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk
ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com
SearchScopes: HKLM - DefaultScope {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKLM - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKCU - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = 
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
DPF: HKLM-x32 {55369874-02F5-47E2-A0F7-AC67E1B1866E} hxxp://www.centrodigital.de/smart/setup.ocx
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Florian-KFZMeister\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Florian-KFZMeister\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF HKLM-x32\...\Firefox\Extensions:  - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013-05-15]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013-05-15]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013-05-15]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2013-05-15]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2013-05-15]

Chrome: 
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "hxxp://www.google.com/"
CHR Extension: (Google Docs) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-23]
CHR Extension: (Modul zur Link-Untersuchung) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-01-23]
CHR Extension: (Sicherer Zahlungsverkehr) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-01-23]
CHR Extension: (Modul für das Blockieren gefährlicher Webseiten) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-01-23]
CHR Extension: (Virtuelle Tastatur) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-01-23]
CHR Extension: (Google Wallet) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-23]
CHR Extension: (Anti-Banner) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-01-23]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-12-14]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-12-14]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-12-14]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2013-05-15]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-12-14]

==================== Services (Whitelisted) =================

R2 AllDaySavingsService64; C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe [172544 2014-07-10] () [File not signed]
S4 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [231552 2012-12-05] (Qualcomm Atheros Commnucations)
S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
R2 cyycfhtzro64; C:\Program Files\005\cyycfhtzro64.exe [709120 2014-07-16] () [File not signed]
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593976 2012-09-05] (Samsung Electronics CO., LTD.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 Simraceway Update Service; C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe [1630720 2013-07-11] () [File not signed]
S4 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2412344 2014-01-28] (TuneUp Software)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
S4 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-12-05] (Atheros) [File not signed]

==================== Drivers (Whitelisted) ====================

R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2013-05-21] (Advanced Micro Devices, Inc.)
R3 BTATH_HID; C:\Windows\system32\DRIVERS\btath_hid.sys [222360 2012-12-05] (Qualcomm Atheros)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2012-12-05] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
S3 CH341SER_A64; C:\Windows\System32\Drivers\CH341S64.SYS [58368 2011-11-04] (www.winchiphead.com)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [146856 2013-06-04] (Windows (R) Win 7 DDK provider)
R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [21928 2013-06-04] (Windows (R) Win 7 DDK provider)
S3 IntcDAud; C:\Windows\system32\DRIVERS\IntcDAud.sys [342528 2012-06-19] (Intel(R) Corporation) [File not signed]
S3 intelkmd; C:\Windows\system32\DRIVERS\igdpmd64.sys [5338848 2012-09-17] (Intel Corporation) [File not signed]
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [627296 2014-05-20] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2013-12-11] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [50448 2013-05-15] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178448 2013-05-15] (Kaspersky Lab ZAO)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2014-07-10] (NetFilterSDK.com)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2012-11-16] (TuneUp Software)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
U3 kgloquow; \??\C:\Users\FLORIA~1\AppData\Local\Temp\kgloquow.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-21 09:46 - 2014-07-21 09:46 - 00007268 _____ () C:\Users\Florian-KFZMeister\Desktop\GMER.log
2014-07-21 09:29 - 2014-07-21 09:29 - 704339485 _____ () C:\WINDOWS\MEMORY.DMP
2014-07-21 09:29 - 2014-07-21 09:29 - 00299272 _____ () C:\WINDOWS\Minidump\072114-35515-01.dmp
2014-07-21 09:29 - 2014-07-21 09:29 - 00000000 ____D () C:\WINDOWS\Minidump
2014-07-21 09:25 - 2014-07-21 09:49 - 00021583 _____ () C:\Users\Florian-KFZMeister\Desktop\FRST.txt
2014-07-21 09:25 - 2014-07-21 09:49 - 00000000 ____D () C:\FRST
2014-07-21 09:25 - 2014-07-21 09:26 - 00053834 _____ () C:\Users\Florian-KFZMeister\Desktop\Addition.txt
2014-07-21 09:24 - 2014-07-21 09:32 - 00000498 _____ () C:\Users\Florian-KFZMeister\Desktop\defogger_disable.log
2014-07-21 09:24 - 2014-07-21 09:24 - 00000000 _____ () C:\Users\Florian-KFZMeister\defogger_reenable
2014-07-21 09:22 - 2014-07-21 09:22 - 02089984 _____ (Farbar) C:\Users\Florian-KFZMeister\Desktop\FRST64.exe
2014-07-21 09:22 - 2014-07-21 09:22 - 00380416 _____ () C:\Users\Florian-KFZMeister\Desktop\8kgufznd.exe
2014-07-21 09:21 - 2014-07-21 09:21 - 00050477 _____ () C:\Users\Florian-KFZMeister\Desktop\Defogger.exe
2014-07-21 09:00 - 2014-07-21 09:00 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-07-21 08:59 - 2014-07-21 08:59 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe
2014-07-21 08:59 - 2014-07-21 08:59 - 02088532 _____ () C:\Users\Florian-KFZMeister\Downloads\FRST64.exe
2014-07-19 08:41 - 2014-07-19 08:41 - 00000000 ____H () C:\ProgramData\cm-lock
2014-07-19 08:31 - 2014-07-19 08:31 - 00000697 _____ () C:\Users\Florian-KFZMeister\Desktop\JRT.txt
2014-07-19 08:28 - 2014-07-19 08:28 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-07-19 08:13 - 2014-07-19 08:13 - 00003228 _____ () C:\WINDOWS\System32\Tasks\{195AC1F4-9216-4E5D-970E-EE662B1F6FAB}
2014-07-19 08:10 - 2014-07-19 08:10 - 01707144 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer (1).exe
2014-07-19 08:08 - 2014-07-21 09:35 - 00000000 ____D () C:\Program Files\AllDaySavings
2014-07-19 08:05 - 2014-07-19 08:05 - 00822568 _____ (Reimage®) C:\Users\Florian-KFZMeister\Downloads\ReimageRepair.exe
2014-07-19 08:03 - 2014-07-19 08:04 - 01705692 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer.exe
2014-07-19 07:51 - 2014-07-19 07:51 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LavasoftStatistics
2014-07-19 07:50 - 2014-07-19 07:50 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft
2014-07-19 07:43 - 2014-07-19 07:43 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-07-18 17:17 - 2014-07-19 08:40 - 00004440 _____ () C:\WINDOWS\PFRO.log
2014-07-18 17:17 - 2014-07-18 17:18 - 00491000 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-07-18 17:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll
2014-07-18 17:13 - 2014-07-19 08:39 - 00000000 ____D () C:\AdwCleaner
2014-07-18 12:28 - 2014-07-19 07:57 - 00003496 _____ () C:\WINDOWS\System32\Tasks\Reimage Reminder
2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Reimage Protector
2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
2014-07-18 12:16 - 2014-07-18 12:28 - 00000000 ____D () C:\rei
2014-07-18 12:15 - 2014-07-18 12:28 - 00000163 _____ () C:\WINDOWS\Reimage.ini
2014-07-18 09:07 - 2014-07-18 09:07 - 00000000 _____ () C:\Users\Florian-KFZMeister\com.attensity.bosch.esi.updateclient.StartUpdateClient.tmp
2014-07-16 11:55 - 2014-07-17 07:20 - 00000000 ____D () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131
2014-07-16 11:54 - 2014-07-16 11:54 - 00000000 ____D () C:\Program Files\005
2014-07-14 08:31 - 2014-07-14 08:31 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\.eva
2014-07-14 08:29 - 2014-07-14 08:29 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Daimler
2014-07-10 21:40 - 2014-07-10 21:40 - 00046376 _____ (NetFilterSDK.com) C:\WINDOWS\system32\Drivers\netfilter64.sys
2014-07-09 07:58 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2014-07-09 07:43 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe
2014-07-09 07:43 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe
2014-07-09 07:43 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-07-09 07:43 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2014-07-09 07:43 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2014-07-09 07:43 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2014-07-09 07:43 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2014-07-09 07:43 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2014-07-09 07:43 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2014-07-09 07:43 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-07-09 07:42 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-07-09 07:42 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-07-09 07:42 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-07-09 07:42 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-07-09 07:42 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-07-09 07:42 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-07-09 07:42 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-07-09 07:42 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-07-09 07:42 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-07-09 07:42 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-07-09 07:42 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-07-09 07:42 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-07-09 07:42 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-07-09 07:42 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-07-09 07:42 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-07-09 07:42 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-07-09 07:42 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-07-09 07:42 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-07-09 07:42 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-07-09 07:42 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-07-09 07:42 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-07-09 07:42 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-07-09 07:42 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-07-09 07:42 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-07-09 07:42 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-07-09 07:42 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-07-09 07:42 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-07-09 07:42 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2014-07-09 07:42 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2014-07-09 07:42 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-07-09 07:42 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2014-07-09 07:42 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-07-09 07:42 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-07-09 07:42 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-09 07:42 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-07-09 07:42 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-07-09 07:42 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-09 07:42 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2014-07-09 07:42 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2014-07-09 07:42 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-07-09 07:42 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2014-07-09 07:42 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-07-09 07:42 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2014-07-09 07:42 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-06-30 13:53 - 2014-06-30 13:53 - 00001674 _____ () C:\Users\Florian-KFZMeister\AppData\Local\recently-used.xbel
2014-06-30 13:44 - 2014-07-19 07:53 - 00000000 ____D () C:\Users\Florian-KFZMeister\Downloads\Musikjunkie - Guano Apes 2014 Offline Bitrate VBR 04 Numen

==================== One Month Modified Files and Folders =======

2014-07-21 09:50 - 2014-07-21 09:25 - 00021583 _____ () C:\Users\Florian-KFZMeister\Desktop\FRST.txt
2014-07-21 09:49 - 2014-07-21 09:25 - 00000000 ____D () C:\FRST
2014-07-21 09:46 - 2014-07-21 09:46 - 00007268 _____ () C:\Users\Florian-KFZMeister\Desktop\GMER.log
2014-07-21 09:46 - 2013-04-14 11:43 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2830974330-3213038589-3334289725-1002
2014-07-21 09:35 - 2014-07-19 08:08 - 00000000 ____D () C:\Program Files\AllDaySavings
2014-07-21 09:35 - 2013-10-30 13:04 - 01576606 _____ () C:\WINDOWS\WindowsUpdate.log
2014-07-21 09:35 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-07-21 09:34 - 2013-09-30 06:14 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-07-21 09:34 - 2013-09-30 05:56 - 00766620 _____ () C:\WINDOWS\system32\perfh007.dat
2014-07-21 09:34 - 2013-09-30 05:56 - 00159902 _____ () C:\WINDOWS\system32\perfc007.dat
2014-07-21 09:33 - 2013-05-15 10:19 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-07-21 09:32 - 2014-07-21 09:24 - 00000498 _____ () C:\Users\Florian-KFZMeister\Desktop\defogger_disable.log
2014-07-21 09:32 - 2014-01-23 12:31 - 00002195 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-21 09:31 - 2014-01-23 12:30 - 00001156 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-21 09:30 - 2014-04-17 11:11 - 00000000 __RDO () C:\Users\Florian-KFZMeister\SkyDrive
2014-07-21 09:30 - 2013-04-15 09:52 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\FreePDF_XP
2014-07-21 09:30 - 2012-11-26 08:01 - 00000868 _____ () C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-07-21 09:29 - 2014-07-21 09:29 - 704339485 _____ () C:\WINDOWS\MEMORY.DMP
2014-07-21 09:29 - 2014-07-21 09:29 - 00299272 _____ () C:\WINDOWS\Minidump\072114-35515-01.dmp
2014-07-21 09:29 - 2014-07-21 09:29 - 00000000 ____D () C:\WINDOWS\Minidump
2014-07-21 09:29 - 2013-10-30 12:44 - 00000000 ____D () C:\Users\Florian-KFZMeister
2014-07-21 09:29 - 2013-10-30 10:43 - 00000064 __RSH () C:\WINDOWS\system32\Drivers\VSTXRAID.winsecurity
2014-07-21 09:29 - 2013-10-30 10:14 - 00000064 __RSH () C:\WINDOWS\system32\Drivers\WUDFPf.winsecurity
2014-07-21 09:29 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-07-21 09:29 - 2013-08-06 13:50 - 00599635 _____ () C:\Simraceway.log
2014-07-21 09:26 - 2014-07-21 09:25 - 00053834 _____ () C:\Users\Florian-KFZMeister\Desktop\Addition.txt
2014-07-21 09:24 - 2014-07-21 09:24 - 00000000 _____ () C:\Users\Florian-KFZMeister\defogger_reenable
2014-07-21 09:22 - 2014-07-21 09:22 - 02089984 _____ (Farbar) C:\Users\Florian-KFZMeister\Desktop\FRST64.exe
2014-07-21 09:22 - 2014-07-21 09:22 - 00380416 _____ () C:\Users\Florian-KFZMeister\Desktop\8kgufznd.exe
2014-07-21 09:21 - 2014-07-21 09:21 - 00050477 _____ () C:\Users\Florian-KFZMeister\Desktop\Defogger.exe
2014-07-21 09:03 - 2014-01-23 12:31 - 00001160 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-21 09:00 - 2014-07-21 09:00 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-07-21 09:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-07-21 08:59 - 2014-07-21 08:59 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe
2014-07-21 08:59 - 2014-07-21 08:59 - 02088532 _____ () C:\Users\Florian-KFZMeister\Downloads\FRST64.exe
2014-07-21 08:27 - 2013-12-13 13:46 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LumacDaemon
2014-07-21 08:17 - 2014-03-03 13:54 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Battle.net
2014-07-19 09:56 - 2012-11-26 08:09 - 00000000 ____D () C:\ProgramData\WinClon
2014-07-19 08:41 - 2014-07-19 08:41 - 00000000 ____H () C:\ProgramData\cm-lock
2014-07-19 08:40 - 2014-07-18 17:17 - 00004440 _____ () C:\WINDOWS\PFRO.log
2014-07-19 08:40 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-07-19 08:39 - 2014-07-18 17:13 - 00000000 ____D () C:\AdwCleaner
2014-07-19 08:31 - 2014-07-19 08:31 - 00000697 _____ () C:\Users\Florian-KFZMeister\Desktop\JRT.txt
2014-07-19 08:28 - 2014-07-19 08:28 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-07-19 08:13 - 2014-07-19 08:13 - 00003228 _____ () C:\WINDOWS\System32\Tasks\{195AC1F4-9216-4E5D-970E-EE662B1F6FAB}
2014-07-19 08:10 - 2014-07-19 08:10 - 01707144 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer (1).exe
2014-07-19 08:05 - 2014-07-19 08:05 - 00822568 _____ (Reimage®) C:\Users\Florian-KFZMeister\Downloads\ReimageRepair.exe
2014-07-19 08:04 - 2014-07-19 08:03 - 01705692 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer.exe
2014-07-19 08:01 - 2013-08-24 08:39 - 00000000 ____D () C:\Games
2014-07-19 07:57 - 2014-07-18 12:28 - 00003496 _____ () C:\WINDOWS\System32\Tasks\Reimage Reminder
2014-07-19 07:53 - 2014-06-30 13:44 - 00000000 ____D () C:\Users\Florian-KFZMeister\Downloads\Musikjunkie - Guano Apes 2014 Offline Bitrate VBR 04 Numen
2014-07-19 07:51 - 2014-07-19 07:51 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LavasoftStatistics
2014-07-19 07:50 - 2014-07-19 07:50 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft
2014-07-19 07:43 - 2014-07-19 07:43 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-07-19 07:40 - 2013-04-15 08:19 - 00000000 ____D () C:\KfzKaufmann
2014-07-19 07:30 - 2013-07-12 17:24 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\re
2014-07-18 17:18 - 2014-07-18 17:17 - 00491000 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-07-18 17:17 - 2013-04-15 08:37 - 00000000 ____D () C:\Users\Florian-KFZMeister\.thumbnails
2014-07-18 17:12 - 2013-03-28 17:40 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\repline
2014-07-18 15:55 - 2012-11-26 08:01 - 00000870 _____ () C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2014-07-18 13:01 - 2013-09-19 08:20 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\vlc
2014-07-18 12:28 - 2014-07-18 12:16 - 00000000 ____D () C:\rei
2014-07-18 12:28 - 2014-07-18 12:15 - 00000163 _____ () C:\WINDOWS\Reimage.ini
2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Reimage Protector
2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
2014-07-18 09:07 - 2014-07-18 09:07 - 00000000 _____ () C:\Users\Florian-KFZMeister\com.attensity.bosch.esi.updateclient.StartUpdateClient.tmp
2014-07-17 13:56 - 2014-04-16 10:02 - 00000000 ____D () C:\ProgramData\WarThunder
2014-07-17 07:29 - 2013-06-11 09:43 - 00000000 ____D () C:\ProgramData\Bosch
2014-07-17 07:28 - 2013-06-11 09:43 - 00000488 _____ () C:\WINDOWS\RbSystem.ini
2014-07-17 07:20 - 2014-07-16 11:55 - 00000000 ____D () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131
2014-07-16 17:11 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-07-16 12:06 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-07-16 11:54 - 2014-07-16 11:54 - 00000000 ____D () C:\Program Files\005
2014-07-16 07:13 - 2014-04-16 10:02 - 00000000 ____D () C:\Program Files (x86)\WarThunder
2014-07-14 16:39 - 2013-04-24 10:52 - 00133799 _____ () C:\Users\Florian-KFZMeister\ewa_client_0.log
2014-07-14 16:39 - 2013-04-24 10:52 - 00000000 ____D () C:\Users\Florian-KFZMeister\XFER
2014-07-14 16:24 - 2013-04-24 10:52 - 00000122 _____ () C:\Users\Florian-KFZMeister\.ewanapi_cookie
2014-07-14 08:55 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-07-14 08:31 - 2014-07-14 08:31 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\.eva
2014-07-14 08:29 - 2014-07-14 08:29 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Daimler
2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore
2014-07-10 21:40 - 2014-07-10 21:40 - 00046376 _____ (NetFilterSDK.com) C:\WINDOWS\system32\Drivers\netfilter64.sys
2014-07-10 17:42 - 2014-03-03 13:54 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-07-09 08:03 - 2013-04-14 20:50 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-07-09 08:03 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-07-09 08:02 - 2013-07-23 09:05 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-07-09 08:00 - 2013-04-15 07:41 - 96441528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-07-09 07:58 - 2013-09-30 05:59 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-08 08:05 - 2014-03-03 13:55 - 00000000 ____D () C:\Program Files (x86)\Diablo III
2014-07-04 13:02 - 2014-01-23 17:12 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\Schaltpläne
2014-07-02 16:35 - 2013-06-19 10:56 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\Formulare und Vorlagen
2014-06-30 13:53 - 2014-06-30 13:53 - 00001674 _____ () C:\Users\Florian-KFZMeister\AppData\Local\recently-used.xbel
2014-06-30 13:53 - 2013-04-15 08:36 - 00000000 ____D () C:\Users\Florian-KFZMeister\.gimp-2.8
2014-06-30 08:50 - 2013-09-16 07:27 - 00002487 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-06-30 08:50 - 2013-09-16 07:27 - 00002039 _____ () C:\Users\Public\Desktop\Adobe Reader X.lnk
2014-06-26 22:55 - 2014-04-30 08:06 - 00703968 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-06-26 22:55 - 2014-04-30 08:06 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-25 17:58 - 2014-01-23 12:31 - 00004132 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-25 17:58 - 2014-01-23 12:30 - 00003896 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-23 10:16 - 2013-04-14 11:49 - 00001382 _____ () C:\Users\Public\Desktop\CENTROdigital SmartClient.lnk

Files to move or delete:
====================
C:\ProgramData\MakeMarkerFile.exe
C:\Users\EasySurvey\EasySurvey.exe


Some content of TEMP:
====================
C:\Users\Florian-KFZMeister\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-19 08:52

==================== End Of Log ============================
         
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-07-2014
Ran by Florian-KFZMeister at 2014-07-21 09:25:52
Running from C:\Users\Florian-KFZMeister\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Kaspersky Internet Security (Enabled - Up to date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Internet Security (Enabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}

==================== Installed Programs ======================

7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.125 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Adobe SVG Viewer 3.0 (HKLM-x32\...\Adobe SVG Viewer) (Version:  3.0 - )
AllSharePlayLink (HKLM-x32\...\{CE1836A8-3F2B-49BD-8395-93DD414068D2}) (Version: 1.0.0 - Samsung Electronics Co., Ltd.)
Amazon Cloud Player (HKCU\...\Amazon Amazon Cloud Player) (Version: 2.2.0.399 - Amazon Services LLC)
Amazon MP3-Downloader 1.0.18 (HKCU\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC)
AMD Accelerated Video Transcoding (Version: 13.15.100.30918 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Control Center (x32 Version: 2013.0918.1802.30548 - Ihr Firmenname) Hidden
AMD Catalyst Install Manager (HKLM\...\{4BA4F2F5-F19F-AF23-DE7C-F417B7E78B51}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Artcut2009 (HKLM-x32\...\{FA01D751-CE47-4533-BB5D-9BB34514A43B}) (Version: 7.0 - Beijing Wentai Technology Co. Ltd)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Bierbuden Autoupdate (remove only) (HKCU\...\Bierbuden Autoupdate) (Version:  - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Bosch Diagnostic Download Manager (HKLM-x32\...\{8A0A5999-CABE-402F-8527-88B5995DA5EC}) (Version: 2.1.3 (2013-04-10_414) - Robert Bosch GmbH)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2013.0918.1802.30548 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.0918.1802.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.0918.1801.30548 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.0918.1802.30548 - Advanced Micro Devices, Inc.) Hidden
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.1.4003 - CDBurnerXP)
CENTROdigital SmartClient (HKLM-x32\...\{78046543-DBBE-4CBC-B7DB-AC608221E29C}) (Version: 14.03.000 - vidicom)
CodeMeter Runtime Kit v4.50c (HKLM\...\{D2ABD3EE-94BD-48BB-A6C6-E4FFDA64001E}) (Version: 4.50.906.503 - WIBU-SYSTEMS AG)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.0.1912 - CyberLink Corp.)
CyberLink Power2Go 8 (x32 Version: 8.0.0.1912 - CyberLink Corp.) Hidden
CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4421.02 - CyberLink Corp.)
CyberLink PowerDVD 10 (x32 Version: 10.0.4421.02 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5C78021E-3C8E-4EDF-97EA-E9B8D808FD6D}) (Version:  - Microsoft)
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
Easy File Share (HKLM-x32\...\{A7C37D4B-F37A-42E8-9B6A-B28C18AD4C12}) (Version: 1.3.6 - Samsung Electronics CO.,LTD.)
E-POP (HKLM-x32\...\{F06DD8D9-9DC8-430C-835C-C9BF21E05CC1}) (Version: 1.0.1 - Samsung Electronics CO., LTD.)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
Fotogalerie (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Free Zip Viewer (HKLM-x32\...\Free Zip Viewer) (Version: 1.0 - Tripro Limited)
FreePDF (Remove only) (HKLM-x32\...\FreePDF_XP) (Version:  - )
Galerie de photos (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
GIMP 2.8.4 (HKLM\...\GIMP-2_is1) (Version: 2.8.4 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
GPL Ghostscript (HKLM\...\GPL Ghostscript 9.04) (Version: 9.04 - Artifex Software Inc.)
GT Power Expansion (HKLM-x32\...\Steam App 44650) (Version:  - SimBin)
GTR Evolution (HKLM-x32\...\Steam App 8660) (Version:  - SimBin)
helo_usb_drv_x64 (HKLM-x32\...\{8169725C-186E-4F92-AE39-26611F45ACE3}) (Version: 1.00.0000 - HELO)
HeloCut 5 (HKLM-x32\...\{8580EDDE-ACD8-4AC5-A5A3-309C41B16BF4}) (Version: 5.09.8000 - )
HeloCut 5 (HKLM-x32\...\{BC79822D-3183-4AA0-AC02-E1DF4C4183EC}) (Version: 5.09.8000 - VECAP Software Solutions)
Help Desk (HKLM\...\{22B32087-797D-4A1B-AFA7-072C87580ADC}) (Version: 1.0.9 - Samsung Electronics CO., LTD.)
Inkscape 0.48.3.1 (HKLM-x32\...\Inkscape) (Version: 0.48.3.1 - )
Intel AppUp(SM) center (HKLM-x32\...\Intel AppUp(SM) center 33070) (Version: 3.6.1.33070.11 - Intel)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.36354 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3316 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.6.0.1030 - Intel Corporation)
Intel® Trusted Connect Service Client (Version: 1.24.388.1 - Intel Corporation) Hidden
iTunes (HKLM\...\{D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0}) (Version: 11.1.3.8 - Apple Inc.)
Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.550 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Kaspersky Internet Security 2013 (HKLM-x32\...\InstallWIX_{560985FB-4B76-4121-9189-7A2CDC7886D6}) (Version: 13.0.1.4190 - Kaspersky Lab)
Kaspersky Internet Security 2013 (x32 Version: 13.0.1.4190 - Kaspersky Lab) Hidden
KfzKaufmann (HKLM-x32\...\{BB16C933-8638-4A33-B68D-FFCF5FF332C0}_is1) (Version:  - RU-Software)
Lumac (HKLM-x32\...\InstallShield_{5DE11949-2B11-4F13-BAD5-1C237122CFDB}) (Version: 1.1.92.0 - Firstload)
Lumac (x32 Version: 1.1.92.0 - Firstload) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft-Maus- und Tastatur-Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.2.173.0 - Microsoft Corporation)
Microsoft-Maus- und Tastatur-Center (Version: 2.2.173.0 - Microsoft Corporation) Hidden
Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1108.0727 - Microsoft) Hidden
Need for Speed 5 Porsche Unleashed (HKLM-x32\...\{4CA7F8A0-DB20-11D4-8B30-000021015D1C}) (Version:  - )
Need For Speed™ World (HKLM-x32\...\{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1) (Version: 1.0.0.1398 - Electronic Arts)
Onlinesupport 5.0.8232 QS (HKLM-x32\...\{9520BD31-226A-4D5D-B900-6C0CDBA75BF0}_is1) (Version:  - Robert Bosch GmbH)
Opera 12.17 (HKLM-x32\...\Opera 12.17.1863) (Version: 12.17.1863 - Opera Software ASA)
Photo Common (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
Python 2.7.5 (64-bit) (HKLM\...\{DBDD570E-0952-475f-9453-AB88F3DD565a}) (Version: 2.7.5150 - Python Software Foundation)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.0.216 - Qualcomm Atheros Communications)
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
Raccolta foto (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
RACE 07 (HKLM-x32\...\Steam App 8600) (Version:  - SimBin)
Race Injection (HKLM-x32\...\Steam App 44680) (Version:  - SimBin Studios AB)
RaceRoom Racing Experience  (HKLM-x32\...\Steam App 211500) (Version:  - SimBin Studios AB)
RaceRoom Racing Experience Launcher (HKLM-x32\...\{1FD9F07F-7BBF-4C91-B3F0-A23714A3A913}_is1) (Version: 1.0 - SimBin)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6702 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.39030 - Realtek Semiconductor Corp.)
Recovery (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 6.0.10.0 - Samsung Electronics CO., LTD.)
RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version:  - )
Reimage Repair (HKLM\...\Reimage Repair) (Version: 1.6.6.4 - Reimage)
RU Kfz-Kaufman  (HKLM-x32\...\RU Kfz-Kaufman ) (Version:  - )
S Agent (Version: 1.1.45 - Samsung Electronics CO., LTD.) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version:  - Microsoft) Hidden
Settings (HKLM-x32\...\{52E5DE60-C96B-42CC-9A37-FE04725940AE}) (Version: 2.0.0 - Samsung Electronics CO., LTD.)
Simraceway 28.92 (HKLM-x32\...\Simraceway) (Version: 28.92 - Simraceway)
STCC II (HKLM-x32\...\Steam App 44620) (Version:  - SimBin)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
SteelSeries SRW-S1 (HKLM-x32\...\SteelSeries SRW-S1) (Version: 1.0 - SteelSeries ApS)
Support Center (HKLM\...\{843A1BDC-0879-4E5B-83E1-B81CC0CF3580}) (Version: 2.1.1201 - Samsung Electronics CO., LTD.)
Support Center FAQ (x32 Version: 1.0.9 - Samsung Electronics CO., LTD.) Hidden
SW Update (HKLM-x32\...\{DA06101F-FD76-4BF0-88BD-B26A197005E3}) (Version: 2.1.21 - Samsung Electronics CO., LTD.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.2.14.2 - Synaptics Incorporated)
The Retro Expansion (HKLM-x32\...\Steam App 44660) (Version:  - SimBin)
The WTCC 2010 Pack (HKLM-x32\...\Steam App 44670) (Version:  - SimBin)
Total Access Components 2007 (HKLM-x32\...\Total Access Components 2007) (Version:  - )
TuneUp Utilities 2013 (HKLM-x32\...\TuneUp Utilities 2013) (Version: 13.0.4000.245 - TuneUp Software)
TuneUp Utilities 2013 (x32 Version: 13.0.4000.245 - TuneUp Software) Hidden
TuneUp Utilities Language Pack (de-DE) (x32 Version: 13.0.4000.245 - TuneUp Software) Hidden
Unity Web Player (HKCU\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version:  - Microsoft)
Update for Microsoft Excel 2010 (KB2837600) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4ACD847E-547D-493F-9A86-F73EAE1B5174}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version:  - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B0D672F7-883E-4279-8E75-D97A5445AB46}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{EAD7BEF9-B28C-425F-B2C5-538CB27EF013}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{C0BDC1DE-C35E-422B-8CBD-C1D555468720}) (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{089DBFD7-8211-43B2-AAAE-5BDD8C23E3A8}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version:  - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version:  - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version:  - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version:  - Microsoft)
Update for Microsoft Word 2010 (KB2880529) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B9B89E01-5B6B-4F73-BC34-B2C0D8ACB4CD}) (Version:  - Microsoft)
User Guide (HKLM-x32\...\{C7588111-1A12-4EFE-8CA0-DA4344480D92}) (Version: 1.4.00 - Samsung Electronics CO., LTD.)
VLC media player 2.0.3 (HKLM-x32\...\VLC media player) (Version: 2.0.3 - VideoLAN)
VLC media player 2.0.7 (HKLM\...\VLC media player) (Version: 2.0.7 - VideoLAN)
War Thunder Launcher 1.0.1.353 (HKLM-x32\...\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version:  - Gaijin Entertainment)
Winamp (HKLM-x32\...\Winamp) (Version: 5.63  - Nullsoft, Inc)
Winamp Erkennungs-Plug-in (HKCU\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Windows Driver Package - wch.cn (CH341SER_A64) Ports  (11/04/2011 3.3.2011.11) (HKLM\...\97C9A01181CB4369C61AF9B1459B09809636C13D) (Version: 11/04/2011 3.3.2011.11 - wch.cn)
Windows Live (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live Communications Platform (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version:  - Wargaming.net)
wxPython 2.8.12.1 (unicode) for Python 2.7 (HKLM\...\wxPython2.8-unicode-py27_is1) (Version: 2.8.12.1-unicode - Total Control Software)
Xerox PhotoCafe (HKLM-x32\...\Xerox PhotoCafe) (Version: 1.0.0.6162 - Xerox)

==================== Restore Points  =========================

16-07-2014 12:39:17 Geplanter Prüfpunkt
19-07-2014 05:43:33 AA11
21-07-2014 07:07:53 AA11

==================== Hosts content: ==========================

2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {01224181-5D3F-40BE-A91C-7F99EAF59049} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe [2012-10-16] (Synaptics Incorporated)
Task: {040F7F1F-A9FF-4425-92C3-93F73412F4A7} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {14953268-B4A5-467C-BE17-F978CBBB5E1A} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-05-13] (Microsoft)
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {2B8F2C7F-8F11-4EB4-A4FC-CC7298473982} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-04-16] (Intel Corporation)
Task: {2BBFD98F-6EBC-480F-A7D1-CE11692BC00A} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {3E60A8C8-4E9B-4C68-A606-00EBF984E096} - System32\Tasks\Reimage Reminder => C:\Program Files\Reimage\Reimage Repair\ReimageReminder.exe
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {4BCCC83B-C81C-4A12-B4FD-76F0AD334CEF} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {60CBA487-14D5-41E3-B0FF-C88FF461B092} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {662FBA0B-4F9B-42DA-B987-2D5FB31ADC57} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6D1F9747-94E3-4428-A027-4633C2468BA9} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2012-04-16] (Intel Corporation)
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {719D6477-981D-4075-B9EB-A491E00CC838} - System32\Tasks\Xerox PhotoCafe Communicator => C:\ProgramData\Xerox PhotoCafe\MessageCheck.exe [2011-10-26] ()
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {77FEBEC5-A53A-452A-9362-535DCD4F1D61} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
Task: {84460274-B38B-487E-A2E1-7E8CF72561D5} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {99367B58-21BA-4C70-97B4-498A49794EF0} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated)
Task: {9A15AAE9-763B-4F3D-963E-1C8AD1A52D41} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload
Task: {9BB6D06F-8C76-4E16-B15F-A2A0E5E50151} - System32\Tasks\SAgent => C:\Program Files\Samsung\S Agent\CommonAgent.exe [2013-10-16] (Samsung Electronics CO., LTD.)
Task: {9BD9601F-772B-4F46-8403-DF5D28EFDD5E} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 => C:\Program Files (x86)\TuneUp Utilities 2013\OneClick.exe [2014-01-28] (TuneUp Software)
Task: {9D8C51FE-440E-427E-AEB9-9283E49A61AC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-23] (Google Inc.)
Task: {9F6CE7DE-FCCB-44FA-AFB5-DD9D3CCE29D9} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {A019CC72-234A-41D0-89CB-522B2C46F6F7} - System32\Tasks\Settings => C:\Program Files (x86)\Samsung\Settings\sSettings.exe [2012-09-05] (Samsung Electronics CO., LTD.)
Task: {A8C89B3D-C3FA-40C5-9C1F-92D29B62AF1D} - System32\Tasks\WLANStartup => C:\Program Files (x86)\Samsung\Easy Settings\WLANStartup.exe
Task: {B6166A99-AE09-4DB3-B587-9C2D1569E710} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {B7D9F543-294D-4910-B4B4-EF53CBE0D9F7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-23] (Google Inc.)
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {E6B35171-09C0-4E57-A00F-26D0472B79D8} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation)
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {E9ECD765-9DD0-4BB5-8935-DCA6967C4D28} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-07-09] (Microsoft Corporation)
Task: {F9BC2B20-A801-44A6-8DED-BEA03BFF5367} - System32\Tasks\advRecovery => C:\Program Files\Samsung\Recovery\WCScheduler.exe [2013-08-23] (SEC)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Task: C:\WINDOWS\Tasks\Xerox PhotoCafe Communicator.job => C:\ProgramData\Xerox PhotoCafe\MessageCheck.exe

==================== Loaded Modules (whitelisted) =============

2013-04-15 09:51 - 2010-06-17 20:56 - 00087040 _____ () C:\WINDOWS\System32\redmonnt.dll
2014-07-10 21:40 - 2014-07-10 21:40 - 00172544 _____ () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe
2014-07-10 21:40 - 2014-07-10 21:40 - 00110080 _____ () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\nfapi.dll
2014-07-10 21:40 - 2014-07-10 21:40 - 00456192 _____ () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\ProtocolFilters.dll
2014-07-16 11:54 - 2014-07-16 11:54 - 00709120 _____ () C:\Program Files\005\cyycfhtzro64.exe
2013-07-11 23:04 - 2013-07-11 23:04 - 01630720 _____ () C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe
2014-01-28 10:37 - 2014-01-28 10:37 - 00741176 _____ () C:\Program Files (x86)\TuneUp Utilities 2013\avgrepliba.dll
2012-09-05 09:50 - 2012-09-05 09:50 - 00085112 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
2013-10-04 00:42 - 2013-10-04 00:42 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2013-10-16 19:15 - 2013-10-16 19:15 - 00088624 _____ () C:\Program Files\Samsung\S Agent\ToastX64.dll
2014-07-21 09:21 - 2014-07-21 09:21 - 00050477 _____ () C:\Users\Florian-KFZMeister\Desktop\Defogger.exe
2013-09-13 20:51 - 2013-09-13 20:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2013-09-13 20:51 - 2013-09-13 20:51 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2013-07-11 23:03 - 2013-07-11 23:03 - 00252832 _____ () C:\Program Files (x86)\SimracewayUpdater\PATCHW32.dll
2012-11-26 08:01 - 2012-06-25 19:41 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2012-09-05 09:50 - 2012-09-05 09:50 - 00028792 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdWrapper.dll
2012-09-05 09:50 - 2012-09-05 09:50 - 01012856 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmd.dll
2012-09-05 09:50 - 2012-09-05 09:50 - 00110712 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsBase.dll
2012-09-05 09:50 - 2012-09-05 09:50 - 00056440 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\HookDllPS2.dll
2012-09-05 09:50 - 2012-09-05 09:50 - 00211064 _____ () C:\Program Files (x86)\Samsung\Settings\CmdServer\WinCRT.dll
2012-09-05 09:50 - 2012-09-05 09:50 - 00026744 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsAPI.dll
2012-09-05 09:50 - 2012-09-05 09:50 - 00110712 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsBase.dll
2012-09-05 09:50 - 2012-09-05 09:50 - 00060536 _____ () C:\Program Files (x86)\Samsung\Settings\EasyMovieEnhancer.dll
2012-09-05 09:50 - 2012-09-05 09:50 - 00103544 _____ () C:\Program Files (x86)\Samsung\Settings\EasySettingsCmdClient.dll
2013-07-11 11:00 - 2014-05-05 07:27 - 00835584 _____ () C:\Program Files (x86)\Opera\gstreamer\gstreamer.dll
2013-07-11 11:00 - 2014-05-05 07:27 - 00093696 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstaudioconvert.dll
2013-07-11 11:00 - 2014-05-05 07:27 - 00094208 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstaudioresample.dll
2013-07-11 11:00 - 2014-05-05 07:27 - 00057344 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstautodetect.dll
2013-07-11 11:00 - 2014-05-05 07:27 - 00096256 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstcoreplugins.dll
2013-07-11 11:00 - 2014-05-05 07:27 - 00062976 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstdecodebin2.dll
2013-07-11 11:00 - 2014-05-05 07:27 - 00067072 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstdirectsound.dll
2013-07-11 11:00 - 2014-05-05 07:27 - 00158208 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstffmpegcolorspace.dll
2013-07-11 11:00 - 2014-05-05 07:27 - 00312832 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstoggdec.dll
2013-07-11 11:00 - 2014-05-05 07:27 - 00038912 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstwaveform.dll
2013-07-11 11:00 - 2014-05-05 07:27 - 00073728 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstwavparse.dll
2013-07-11 11:00 - 2014-05-05 07:27 - 00101888 _____ () C:\Program Files (x86)\Opera\gstreamer\plugins\gstwebmdec.dll
2014-07-10 07:15 - 2014-07-10 07:16 - 26065408 _____ () C:\Program Files (x86)\Battle.net\Battle.net.4826\libcef.dll
2012-08-17 21:38 - 2012-08-17 21:38 - 00479160 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\dblite.dll
2012-12-14 13:45 - 2012-12-14 13:45 - 01310136 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\kpcengine.2.2.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Windows:CM_1f24a44e6b128c2d77667e26df6bc247ed05d9ea5eb435533ab783378d367198
AlternateDataStreams: C:\Windows:CM_4c09c6a837b828f8e71ff53bdfa462592466a103481eefe431e5b35c94a386a5
AlternateDataStreams: C:\Users\Florian-KFZMeister\SkyDrive:ms-properties

==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== MSCONFIG/TASK MANAGER disabled items =========

HKLM\...\StartupApproved\StartupFolder: => "CodeMeter Control Center.lnk"
HKLM\...\StartupApproved\Run: => "BtTray"
HKLM\...\StartupApproved\Run: => "BtvStack"
HKLM\...\StartupApproved\Run32: => "Adobe Reader Speed Launcher"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "RemoteControl10"
HKLM\...\StartupApproved\Run32: => "CLMLServer_For_P2G8"
HKLM\...\StartupApproved\Run32: => "CLVirtualDrive"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "StartDDM"
HKLM\...\StartupApproved\Run32: => "ApnTBMon"
HKLM\...\StartupApproved\Run32: => "APSDaemon"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKCU\...\StartupApproved\Run: => "Steam"
HKCU\...\StartupApproved\Run: => "AmazonMP3DownloaderHelper"
HKCU\...\StartupApproved\Run: => "Amazon Cloud Player"

==================== Faulty Device Manager Devices =============

Name: Bluetooth Audio Device
Description: Bluetooth Audio Device
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: Qualcomm Atheros Communications
Service: BTATH_A2DP
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Virtual Bluetooth Support (Include Audio)
Description: Virtual Bluetooth Support (Include Audio)
Class Guid: {c7c038ad-1f2d-44d4-b2fe-d912be20e6d5}
Manufacturer: Qualcomm Atheros Communications
Service: AthBTPort
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Bluetooth LWFLT Device
Description: Bluetooth LWFLT Device
Class Guid: {c7c038ad-1f2d-44d4-b2fe-d912be20e6d5}
Manufacturer: Qualcomm Atheros Communications
Service: BTATH_LWFLT
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver


==================== Event log errors: =========================

Application errors:
==================
Error: (07/21/2014 09:09:52 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (07/21/2014 09:09:50 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (07/21/2014 09:05:28 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (07/21/2014 09:00:33 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (07/21/2014 09:00:31 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (07/21/2014 09:00:25 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.

Error: (07/21/2014 09:00:25 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest2" in Zeile C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
Komponente 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.


System errors:
=============

Microsoft Office Sessions:
=========================
Error: (07/21/2014 09:09:52 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe

Error: (07/21/2014 09:09:50 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe

Error: (07/21/2014 09:05:28 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe

Error: (07/21/2014 09:00:33 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe

Error: (07/21/2014 09:00:31 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe

Error: (07/21/2014 09:00:25 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe

Error: (07/21/2014 09:00:25 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe


CodeIntegrity Errors:
===================================
  Date: 2013-11-21 07:27:38.589
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\igdpmd64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info =========================== 

Percentage of memory in use: 25%
Total physical RAM: 8083.55 MB
Available physical RAM: 6006.16 MB
Total Pagefile: 9363.55 MB
Available Pagefile: 6599.69 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:437.92 GB) (Free:202.45 GB) NTFS
Drive d: (KfzKaufmann) (CDROM) (Total:0.2 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 466 GB) (Disk ID: 1F995863)

Partition: GPT Partition Type.

==================== End Of Log ============================
         
Code:
ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-07-21 09:46:27
Windows 6.2.9200  x64 \Device\Harddisk0\DR0 -> \Device\00000023 Hitachi_HTS547550A9E384 rev.JE3OA50A 465,76GB
Running: 8kgufznd.exe; Driver: C:\Users\FLORIA~1\AppData\Local\Temp\kgloquow.sys


---- User code sections - GMER 2.1 ----

.text   C:\WINDOWS\system32\atiesrxx.exe[988] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                               00007ffb2f81169a 4 bytes [81, 2F, FB, 7F]
.text   C:\WINDOWS\system32\atiesrxx.exe[988] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                               00007ffb2f8116a2 4 bytes [81, 2F, FB, 7F]
.text   C:\WINDOWS\system32\atiesrxx.exe[988] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                                  00007ffb2f81181a 4 bytes [81, 2F, FB, 7F]
.text   C:\WINDOWS\system32\atiesrxx.exe[988] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                                  00007ffb2f811832 4 bytes [81, 2F, FB, 7F]
.text   C:\WINDOWS\system32\atieclxx.exe[1140] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                              00007ffb2f81169a 4 bytes [81, 2F, FB, 7F]
.text   C:\WINDOWS\system32\atieclxx.exe[1140] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                              00007ffb2f8116a2 4 bytes [81, 2F, FB, 7F]
.text   C:\WINDOWS\system32\atieclxx.exe[1140] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                                 00007ffb2f81181a 4 bytes [81, 2F, FB, 7F]
.text   C:\WINDOWS\system32\atieclxx.exe[1140] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                                 00007ffb2f811832 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe[1692] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506  00007ffb2f81169a 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe[1692] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514  00007ffb2f8116a2 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe[1692] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118     00007ffb2f81181a 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe[1692] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142     00007ffb2f811832 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files\005\cyycfhtzro64.exe[1760] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                         00007ffb2f81169a 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files\005\cyycfhtzro64.exe[1760] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                         00007ffb2f8116a2 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files\005\cyycfhtzro64.exe[1760] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                            00007ffb2f81181a 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files\005\cyycfhtzro64.exe[1760] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                            00007ffb2f811832 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe[2068] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506     00007ffb2f81169a 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe[2068] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514     00007ffb2f8116a2 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe[2068] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118        00007ffb2f81181a 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe[2068] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142        00007ffb2f811832 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe[3216] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506         00007ffb2f81169a 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe[3216] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514         00007ffb2f8116a2 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe[3216] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118            00007ffb2f81181a 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe[3216] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142            00007ffb2f811832 4 bytes [81, 2F, FB, 7F]
.text   C:\Windows\System32\igfxpers.exe[4888] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                                              00007ffb2f81169a 4 bytes [81, 2F, FB, 7F]
.text   C:\Windows\System32\igfxpers.exe[4888] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                                              00007ffb2f8116a2 4 bytes [81, 2F, FB, 7F]
.text   C:\Windows\System32\igfxpers.exe[4888] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                                                 00007ffb2f81181a 4 bytes [81, 2F, FB, 7F]
.text   C:\Windows\System32\igfxpers.exe[4888] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                                                 00007ffb2f811832 4 bytes [81, 2F, FB, 7F]
.text   C:\Program Files\Windows Media Player\wmpnetwk.exe[5264] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194                                  00007ffb23841f6a 4 bytes [84, 23, FB, 7F]
.text   C:\Program Files\Windows Media Player\wmpnetwk.exe[5264] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218                                  00007ffb23841f82 4 bytes [84, 23, FB, 7F]

---- Threads - GMER 2.1 ----

Thread  C:\WINDOWS\system32\csrss.exe [844:868]                                                                                                    fffff960009bbb90
Thread  c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [3200:4624]                                                                 00007ffb0df5c680
Thread  c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [3232:3036]                                                                00007ffb0dcb838c
Thread  c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [3232:5976]                                                                00007ffb0df5c680
Thread  C:\Windows\System32\SettingSyncHost.exe [5148:4340]                                                                                        00007ffb2f531b54
Thread  C:\Windows\System32\SettingSyncHost.exe [5148:4260]                                                                                        00007ffb0dec41f4

---- Disk sectors - GMER 2.1 ----

Disk    \Device\Harddisk0\DR0                                                                                                                      unknown MBR code

---- EOF - GMER 2.1 ----
         
So das müsste alles gewesen sein!

Vielen Dank für eure Mühen im Vorraus!

Florian

Alt 21.07.2014, 09:12   #2
Warlord711
/// TB-Ausbilder
 
Windows 8.1: Werbe-Popups in Google Chrome und Opera - Standard

Windows 8.1: Werbe-Popups in Google Chrome und Opera



Hallo flo344i



Mein Name ist Timo und ich werde Dir bei deinem Problem behilflich sein.
  • Bitte arbeite alle Schritte der Reihe nach ab.
  • Lese die Anleitungen sorgfältig. Sollte es Probleme geben, bitte stoppen und hier so gut es geht beschreiben.
  • Nur Scans durchführen zu denen Du von einem Helfer aufgefordert wirst.
  • Bitte kein Crossposting ( posten in mehreren Foren).
  • Installiere oder Deinstalliere während der Bereinigung keine Software ausser Du wurdest dazu aufgefordert.
  • Lese Dir die Anleitung zuerst vollständig durch. Sollte etwas unklar sein, frage bevor Du beginnst.
  • Poste die Logfiles direkt in deinen Thread. Nicht anhängen ausser ich fordere Dich dazu auf.

Hinweis:
Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist immer der sicherste Weg.

Wir "arbeiten" hier alle freiwillig und in unserer Freizeit *hust*. Daher kann es bei Antworten zu Verzögerungen kommen.
Solltest du innerhalb 48 Std keine Antwort von mir erhalten, dann schreib mit eine PM
Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis ich oder jemand vom Team sagt, dass Du clean bist.

Wichtig:
Ich habe dein Thema in Arbeit und melde mich so schnell als möglich mit weiteren Anweisungen. Bitte beachte, dass alle meine Antworten zuerst von einem Ausbilder freigegeben werden müssen, bevor ich diese hier posten darf. Dies garantiert, dass Du Hilfe von einem ausgebildeten Helfer bekommst. Ich bedanke mich für deine Geduld
__________________


Alt 21.07.2014, 10:34   #3
Warlord711
/// TB-Ausbilder
 
Windows 8.1: Werbe-Popups in Google Chrome und Opera - Standard

Windows 8.1: Werbe-Popups in Google Chrome und Opera



Hinweis: Registry Cleaner

Ich sehe, dass du sogenannte Registry Cleaner installiert hast.
In deinem Fall TuneUp Utilities.

Wir raten von der Verwendung jeglicher Art von Registry Cleaner ab.

Der Grund ist ganz einfach:
Die Registry ist das Hirn des Systems. Funktioniert das Hirn nicht, funktioniert der Rest nicht mehr wirklich.
Man sollte nicht unnötigerweise an der Registry rumbasteln. Schon ein kleiner Fehler kann gravierende Folgen haben und auch Programme machen manchmal Fehler.
Zerstörst du die Registry, zerstörst du Windows.

Zudem ist der Nutzen zur Performancesteigerung umstritten und meist kaum im wahrnehmbaren Bereich.

Ich würde dir empfehlen, Registry Cleaner nicht weiterhin zu verwenden und über
Start --> Systemsteuerung --> Software (bei Windows XP)
Start --> Systemsteuerung --> Programme und Funktionen (bei Vista / Win 7)
zu deinstallieren.



Schritt 1

Deinstallation von Programmen:
  • Klicke auf Start
  • Klicke auf Systemsteuerung
  • Klicke auf Programme und Funktionen
  • suche den Einträge
    Code:
    ATTFilter
    Adobe Reader X
    Java 7 Update 55
             
  • klicke jeweils mit der rechten Maustaste und wähle deinstallieren

Deinstalliere auch - falls du es nicht absichtlich installiert hast - alles was den Zusatz "Toolbar" enthält, sowie Downloader-Anwendungen

Gehe bitte die folgende Liste durch und deinstalliere die genannten Programme, falls vorhanden:
CCleaner oder andere Registry-Cleaner, TuneUp Utilities (inkl. Language Pack), Glary Utilities, Spybot S & D (inklusive Teatimer), Zonealarm Firewall, McAfee Security Scan, Spyware Hunter, Spyware Terminator, Java 6 (alle), Pokersoftware, xp-Antispy, Hotspot Shield, iLivid, Amazon Icon, DriverEasy, Advanced Driver Updater, DriverCure, Uniblue DriverScanner, FireJump, SearchAnonymizer, SpeedMaxPC

Schritt 2
Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).


Schritt 3

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.



Schritt 4
Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.



Schritt 5
Starte noch einmal FRST.
  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, werden ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.

Bitte in der Antwort posten:
  • AdwCleaner Log
  • JRT Log
  • Malwarebytes Log
  • frisches FRST Log
__________________

Alt 21.07.2014, 12:46   #4
flo344i
 
Windows 8.1: Werbe-Popups in Google Chrome und Opera - Standard

Windows 8.1: Werbe-Popups in Google Chrome und Opera



Alles ausgeführt wie du mir aufgetragen hast:-)

Hier die Log Files

Code:
ATTFilter
# AdwCleaner v3.216 - Bericht erstellt am 21/07/2014 um 11:50:06
# Aktualisiert 17/07/2014 von Xplode
# Betriebssystem : Windows 8.1  (64 bits)
# Benutzername : Florian-KFZMeister - WERKSTATT-PC
# Gestartet von : C:\Users\Florian-KFZMeister\Desktop\adwcleaner_3.216.exe
# Option : Suchen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Datei Gefunden : C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gefunden : C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17126


-\\ Google Chrome v35.0.1916.153

[ Datei : C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************


AdwCleaner[R0].txt - [1157 octets] - [21/07/2014 11:50:06]

########## EOF - C:\AdwCleaner\AdwCleaner[R3].txt - [1397 octets] ##########
         
Code:
ATTFilter
# AdwCleaner v3.216 - Bericht erstellt am 21/07/2014 um 11:50:36
# Aktualisiert 17/07/2014 von Xplode
# Betriebssystem : Windows 8.1  (64 bits)
# Benutzername : Florian-KFZMeister - WERKSTATT-PC
# Gestartet von : C:\Users\Florian-KFZMeister\Desktop\adwcleaner_3.216.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Datei Gelöscht : C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17126


-\\ Google Chrome v35.0.1916.153

[ Datei : C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************


AdwCleaner[R0].txt - [1477 octets] - [21/07/2014 11:50:06]
AdwCleaner[S0].txt - [1398 octets] - [21/07/2014 11:50:36]

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1458 octets] ##########
         
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Florian-KFZMeister on 21.07.2014 at 11:58:39,54
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 21.07.2014 at 12:01:40,08
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 21.07.2014
Suchlauf-Zeit: 12:05:42
Logdatei: mbam.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.03.04.09
Rootkit Datenbank: v2014.02.20.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Florian-KFZMeister

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 294804
Verstrichene Zeit: 7 Min, 54 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 0
(No malicious items detected)

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 0
(No malicious items detected)

Dateien: 0
(No malicious items detected)

Physische Sektoren: 0
(No malicious items detected)


(end)
         
FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-07-2014
Ran by Florian-KFZMeister (administrator) on WERKSTATT-PC on 21-07-2014 13:40:21
Running from C:\Users\Florian-KFZMeister\Desktop
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files\005\cyycfhtzro64.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
() C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\SAMSUNG\SW Update Service\SWMAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe
(Opera Software) C:\Program Files (x86)\Opera\opera.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191824 2012-08-10] (Realtek Semiconductor)
HKLM\...\Run: [BtTray] => C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [766080 2012-12-05] (Qualcomm Atheros)
HKLM\...\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [128640 2012-12-05] (Atheros Communications)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2917688 2012-10-16] (Synaptics Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [97392 2012-08-15] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-12] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de)
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\runner_avp.exe [24504 2012-12-14] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [StartDDM] => C:\Program Files (x86)\Bosch\DownloadManager\bin\runDDM.exe [260608 2012-02-10] (Robert Bosch GmbH)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-18] (Advanced Micro Devices, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1825984 2014-04-24] (Valve Corporation)
HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Florian-KFZMeister\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHel (the data entry has 8 more characters).
HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [Amazon Cloud Player] => C:\Users\Florian-KFZMeister\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3145536 2013-12-12] ()
HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Policies\system: [DisableLockWorkstation] 0
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk
ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com
SearchScopes: HKLM - DefaultScope {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKLM - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKCU - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = 
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
DPF: HKLM-x32 {55369874-02F5-47E2-A0F7-AC67E1B1866E} hxxp://www.centrodigital.de/smart/setup.ocx
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Florian-KFZMeister\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Florian-KFZMeister\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF HKLM-x32\...\Firefox\Extensions:  - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013-05-15]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013-05-15]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013-05-15]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2013-05-15]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2013-05-15]

Chrome: 
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "hxxp://www.google.com/"
CHR Extension: (Google Docs) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-23]
CHR Extension: (Modul zur Link-Untersuchung) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-01-23]
CHR Extension: (Sicherer Zahlungsverkehr) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-01-23]
CHR Extension: (Modul für das Blockieren gefährlicher Webseiten) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-01-23]
CHR Extension: (Virtuelle Tastatur) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-01-23]
CHR Extension: (Google Wallet) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-23]
CHR Extension: (Anti-Banner) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-01-23]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-12-14]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-12-14]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-12-14]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2013-05-15]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-12-14]

==================== Services (Whitelisted) =================

R2 AllDaySavingsService64; C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe [172544 2014-07-10] () [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [231552 2012-12-05] (Qualcomm Atheros Commnucations)
S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
R2 cyycfhtzro64; C:\Program Files\005\cyycfhtzro64.exe [709120 2014-07-16] () [File not signed]
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593976 2012-09-05] (Samsung Electronics CO., LTD.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 Simraceway Update Service; C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe [1630720 2013-07-11] () [File not signed]
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-12-05] (Atheros) [File not signed]

==================== Drivers (Whitelisted) ====================

R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2013-05-21] (Advanced Micro Devices, Inc.)
R3 BTATH_HID; C:\Windows\system32\DRIVERS\btath_hid.sys [222360 2012-12-05] (Qualcomm Atheros)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2012-12-05] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
S3 CH341SER_A64; C:\Windows\System32\Drivers\CH341S64.SYS [58368 2011-11-04] (www.winchiphead.com)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [146856 2013-06-04] (Windows (R) Win 7 DDK provider)
R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [21928 2013-06-04] (Windows (R) Win 7 DDK provider)
S3 IntcDAud; C:\Windows\system32\DRIVERS\IntcDAud.sys [342528 2012-06-19] (Intel(R) Corporation) [File not signed]
S3 intelkmd; C:\Windows\system32\DRIVERS\igdpmd64.sys [5338848 2012-09-17] (Intel Corporation) [File not signed]
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [627296 2014-05-20] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2013-12-11] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [50448 2013-05-15] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178448 2013-05-15] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-21] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2014-07-10] (NetFilterSDK.com)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-21 13:39 - 2014-07-21 13:39 - 00001156 _____ () C:\Users\Florian-KFZMeister\Desktop\mbam.txt
2014-07-21 12:03 - 2014-07-21 12:30 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-07-21 12:03 - 2014-07-21 12:03 - 00001118 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-21 12:03 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-07-21 12:03 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-07-21 12:03 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-07-21 12:02 - 2014-07-21 12:02 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Florian-KFZMeister\Desktop\mbam-setup-2.0.2.1012.exe
2014-07-21 12:01 - 2014-07-21 12:01 - 00000627 _____ () C:\Users\Florian-KFZMeister\Desktop\JRT.txt
2014-07-21 11:57 - 2014-07-21 11:57 - 01016261 _____ (Thisisu) C:\Users\Florian-KFZMeister\Desktop\JRT.exe
2014-07-21 11:52 - 2014-07-21 11:52 - 00000000 ___RD () C:\Users\Florian-KFZMeister\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-07-21 11:51 - 2014-07-21 11:51 - 00000000 ____H () C:\ProgramData\cm-lock
2014-07-21 11:48 - 2014-07-21 11:48 - 01354223 _____ () C:\Users\Florian-KFZMeister\Desktop\adwcleaner_3.216.exe
2014-07-21 09:46 - 2014-07-21 09:46 - 00007268 _____ () C:\Users\Florian-KFZMeister\Desktop\GMER.log
2014-07-21 09:29 - 2014-07-21 09:29 - 704339485 _____ () C:\WINDOWS\MEMORY.DMP
2014-07-21 09:29 - 2014-07-21 09:29 - 00299272 _____ () C:\WINDOWS\Minidump\072114-35515-01.dmp
2014-07-21 09:29 - 2014-07-21 09:29 - 00000000 ____D () C:\WINDOWS\Minidump
2014-07-21 09:25 - 2014-07-21 13:40 - 00021138 _____ () C:\Users\Florian-KFZMeister\Desktop\FRST.txt
2014-07-21 09:25 - 2014-07-21 13:40 - 00000000 ____D () C:\FRST
2014-07-21 09:25 - 2014-07-21 09:26 - 00053834 _____ () C:\Users\Florian-KFZMeister\Desktop\Addition.txt
2014-07-21 09:24 - 2014-07-21 09:32 - 00000498 _____ () C:\Users\Florian-KFZMeister\Desktop\defogger_disable.log
2014-07-21 09:24 - 2014-07-21 09:24 - 00000000 _____ () C:\Users\Florian-KFZMeister\defogger_reenable
2014-07-21 09:22 - 2014-07-21 09:22 - 02089984 _____ (Farbar) C:\Users\Florian-KFZMeister\Desktop\FRST64.exe
2014-07-21 09:22 - 2014-07-21 09:22 - 00380416 _____ () C:\Users\Florian-KFZMeister\Desktop\8kgufznd.exe
2014-07-21 09:21 - 2014-07-21 09:21 - 00050477 _____ () C:\Users\Florian-KFZMeister\Desktop\Defogger.exe
2014-07-21 09:00 - 2014-07-21 09:00 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-07-21 08:59 - 2014-07-21 08:59 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe
2014-07-21 08:59 - 2014-07-21 08:59 - 02088532 _____ () C:\Users\Florian-KFZMeister\Downloads\FRST64.exe
2014-07-19 08:28 - 2014-07-19 08:28 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-07-19 08:13 - 2014-07-19 08:13 - 00003228 _____ () C:\WINDOWS\System32\Tasks\{195AC1F4-9216-4E5D-970E-EE662B1F6FAB}
2014-07-19 08:10 - 2014-07-19 08:10 - 01707144 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer (1).exe
2014-07-19 08:08 - 2014-07-21 09:56 - 00000000 ____D () C:\Program Files\AllDaySavings
2014-07-19 08:05 - 2014-07-19 08:05 - 00822568 _____ (Reimage®) C:\Users\Florian-KFZMeister\Downloads\ReimageRepair.exe
2014-07-19 08:03 - 2014-07-19 08:04 - 01705692 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer.exe
2014-07-19 07:51 - 2014-07-19 07:51 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LavasoftStatistics
2014-07-19 07:50 - 2014-07-19 07:50 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft
2014-07-19 07:43 - 2014-07-19 07:43 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-07-18 17:17 - 2014-07-21 11:51 - 00005694 _____ () C:\WINDOWS\PFRO.log
2014-07-18 17:17 - 2014-07-18 17:18 - 00491000 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-07-18 17:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll
2014-07-18 17:13 - 2014-07-21 11:56 - 00000000 ____D () C:\AdwCleaner
2014-07-18 12:28 - 2014-07-21 11:46 - 00003494 _____ () C:\WINDOWS\System32\Tasks\Reimage Reminder
2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Reimage Protector
2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
2014-07-18 12:16 - 2014-07-18 12:28 - 00000000 ____D () C:\rei
2014-07-18 12:15 - 2014-07-18 12:28 - 00000163 _____ () C:\WINDOWS\Reimage.ini
2014-07-18 09:07 - 2014-07-18 09:07 - 00000000 _____ () C:\Users\Florian-KFZMeister\com.attensity.bosch.esi.updateclient.StartUpdateClient.tmp
2014-07-16 11:55 - 2014-07-17 07:20 - 00000000 ____D () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131
2014-07-16 11:54 - 2014-07-16 11:54 - 00000000 ____D () C:\Program Files\005
2014-07-14 08:31 - 2014-07-14 08:31 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\.eva
2014-07-14 08:29 - 2014-07-14 08:29 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Daimler
2014-07-10 21:40 - 2014-07-10 21:40 - 00046376 _____ (NetFilterSDK.com) C:\WINDOWS\system32\Drivers\netfilter64.sys
2014-07-09 07:58 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2014-07-09 07:43 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe
2014-07-09 07:43 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe
2014-07-09 07:43 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-07-09 07:43 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2014-07-09 07:43 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2014-07-09 07:43 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2014-07-09 07:43 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2014-07-09 07:43 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2014-07-09 07:43 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2014-07-09 07:43 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-07-09 07:42 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-07-09 07:42 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-07-09 07:42 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-07-09 07:42 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-07-09 07:42 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-07-09 07:42 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-07-09 07:42 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-07-09 07:42 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-07-09 07:42 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-07-09 07:42 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-07-09 07:42 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-07-09 07:42 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-07-09 07:42 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-07-09 07:42 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-07-09 07:42 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-07-09 07:42 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-07-09 07:42 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-07-09 07:42 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-07-09 07:42 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-07-09 07:42 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-07-09 07:42 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-07-09 07:42 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-07-09 07:42 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-07-09 07:42 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-07-09 07:42 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-07-09 07:42 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-07-09 07:42 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-07-09 07:42 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2014-07-09 07:42 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2014-07-09 07:42 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-07-09 07:42 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2014-07-09 07:42 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-07-09 07:42 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-07-09 07:42 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-09 07:42 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-07-09 07:42 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-07-09 07:42 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-09 07:42 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2014-07-09 07:42 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2014-07-09 07:42 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-07-09 07:42 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2014-07-09 07:42 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-07-09 07:42 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2014-07-09 07:42 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-06-30 13:53 - 2014-06-30 13:53 - 00001674 _____ () C:\Users\Florian-KFZMeister\AppData\Local\recently-used.xbel
2014-06-30 13:44 - 2014-07-19 07:53 - 00000000 ____D () C:\Users\Florian-KFZMeister\Downloads\Musikjunkie - Guano Apes 2014 Offline Bitrate VBR 04 Numen

==================== One Month Modified Files and Folders =======

2014-07-21 13:40 - 2014-07-21 09:25 - 00021138 _____ () C:\Users\Florian-KFZMeister\Desktop\FRST.txt
2014-07-21 13:40 - 2014-07-21 09:25 - 00000000 ____D () C:\FRST
2014-07-21 13:39 - 2014-07-21 13:39 - 00001156 _____ () C:\Users\Florian-KFZMeister\Desktop\mbam.txt
2014-07-21 13:13 - 2013-10-30 10:43 - 00000064 __RSH () C:\WINDOWS\system32\Drivers\VSTXRAID.winsecurity
2014-07-21 13:10 - 2013-10-30 13:04 - 01722873 _____ () C:\WINDOWS\WindowsUpdate.log
2014-07-21 13:04 - 2014-01-23 12:31 - 00001160 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-21 13:02 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-07-21 13:01 - 2012-11-26 08:17 - 00000360 _____ () C:\WINDOWS\Tasks\Xerox PhotoCafe Communicator.job
2014-07-21 12:47 - 2013-10-30 10:14 - 00000064 __RSH () C:\WINDOWS\system32\Drivers\WUDFPf.winsecurity
2014-07-21 12:30 - 2014-07-21 12:03 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-07-21 12:14 - 2013-04-14 11:43 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2830974330-3213038589-3334289725-1002
2014-07-21 12:03 - 2014-07-21 12:03 - 00001118 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-21 12:02 - 2014-07-21 12:02 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Florian-KFZMeister\Desktop\mbam-setup-2.0.2.1012.exe
2014-07-21 12:01 - 2014-07-21 12:01 - 00000627 _____ () C:\Users\Florian-KFZMeister\Desktop\JRT.txt
2014-07-21 11:58 - 2013-09-30 06:14 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-07-21 11:58 - 2013-09-30 05:56 - 00766620 _____ () C:\WINDOWS\system32\perfh007.dat
2014-07-21 11:58 - 2013-09-30 05:56 - 00159902 _____ () C:\WINDOWS\system32\perfc007.dat
2014-07-21 11:57 - 2014-07-21 11:57 - 01016261 _____ (Thisisu) C:\Users\Florian-KFZMeister\Desktop\JRT.exe
2014-07-21 11:56 - 2014-07-18 17:13 - 00000000 ____D () C:\AdwCleaner
2014-07-21 11:55 - 2012-11-26 08:09 - 00000000 ____D () C:\ProgramData\WinClon
2014-07-21 11:54 - 2014-01-23 12:31 - 00002195 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-21 11:54 - 2013-05-15 10:19 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-07-21 11:53 - 2014-01-23 12:30 - 00001156 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-21 11:52 - 2014-07-21 11:52 - 00000000 ___RD () C:\Users\Florian-KFZMeister\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-07-21 11:52 - 2014-04-17 11:11 - 00000000 __RDO () C:\Users\Florian-KFZMeister\SkyDrive
2014-07-21 11:52 - 2013-04-15 09:52 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\FreePDF_XP
2014-07-21 11:52 - 2012-11-26 08:01 - 00000868 _____ () C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-07-21 11:51 - 2014-07-21 11:51 - 00000000 ____H () C:\ProgramData\cm-lock
2014-07-21 11:51 - 2014-07-18 17:17 - 00005694 _____ () C:\WINDOWS\PFRO.log
2014-07-21 11:51 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-07-21 11:51 - 2013-08-06 13:50 - 00599686 _____ () C:\Simraceway.log
2014-07-21 11:50 - 2013-10-30 12:44 - 00000000 ____D () C:\Users\Florian-KFZMeister
2014-07-21 11:50 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-07-21 11:49 - 2013-04-15 08:19 - 00000000 ____D () C:\KfzKaufmann
2014-07-21 11:48 - 2014-07-21 11:48 - 01354223 _____ () C:\Users\Florian-KFZMeister\Desktop\adwcleaner_3.216.exe
2014-07-21 11:47 - 2013-04-14 21:37 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-07-21 11:46 - 2014-07-18 12:28 - 00003494 _____ () C:\WINDOWS\System32\Tasks\Reimage Reminder
2014-07-21 11:46 - 2012-11-26 08:17 - 00003298 _____ () C:\WINDOWS\System32\Tasks\Xerox PhotoCafe Communicator
2014-07-21 11:45 - 2012-11-26 08:11 - 00000000 ____D () C:\ProgramData\Adobe
2014-07-21 11:10 - 2014-01-23 17:12 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\Schaltpläne
2014-07-21 09:56 - 2014-07-19 08:08 - 00000000 ____D () C:\Program Files\AllDaySavings
2014-07-21 09:46 - 2014-07-21 09:46 - 00007268 _____ () C:\Users\Florian-KFZMeister\Desktop\GMER.log
2014-07-21 09:41 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-07-21 09:32 - 2014-07-21 09:24 - 00000498 _____ () C:\Users\Florian-KFZMeister\Desktop\defogger_disable.log
2014-07-21 09:29 - 2014-07-21 09:29 - 704339485 _____ () C:\WINDOWS\MEMORY.DMP
2014-07-21 09:29 - 2014-07-21 09:29 - 00299272 _____ () C:\WINDOWS\Minidump\072114-35515-01.dmp
2014-07-21 09:29 - 2014-07-21 09:29 - 00000000 ____D () C:\WINDOWS\Minidump
2014-07-21 09:26 - 2014-07-21 09:25 - 00053834 _____ () C:\Users\Florian-KFZMeister\Desktop\Addition.txt
2014-07-21 09:24 - 2014-07-21 09:24 - 00000000 _____ () C:\Users\Florian-KFZMeister\defogger_reenable
2014-07-21 09:22 - 2014-07-21 09:22 - 02089984 _____ (Farbar) C:\Users\Florian-KFZMeister\Desktop\FRST64.exe
2014-07-21 09:22 - 2014-07-21 09:22 - 00380416 _____ () C:\Users\Florian-KFZMeister\Desktop\8kgufznd.exe
2014-07-21 09:21 - 2014-07-21 09:21 - 00050477 _____ () C:\Users\Florian-KFZMeister\Desktop\Defogger.exe
2014-07-21 09:00 - 2014-07-21 09:00 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-07-21 08:59 - 2014-07-21 08:59 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe
2014-07-21 08:59 - 2014-07-21 08:59 - 02088532 _____ () C:\Users\Florian-KFZMeister\Downloads\FRST64.exe
2014-07-21 08:27 - 2013-12-13 13:46 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LumacDaemon
2014-07-21 08:17 - 2014-03-03 13:54 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Battle.net
2014-07-19 08:28 - 2014-07-19 08:28 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-07-19 08:13 - 2014-07-19 08:13 - 00003228 _____ () C:\WINDOWS\System32\Tasks\{195AC1F4-9216-4E5D-970E-EE662B1F6FAB}
2014-07-19 08:10 - 2014-07-19 08:10 - 01707144 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer (1).exe
2014-07-19 08:05 - 2014-07-19 08:05 - 00822568 _____ (Reimage®) C:\Users\Florian-KFZMeister\Downloads\ReimageRepair.exe
2014-07-19 08:04 - 2014-07-19 08:03 - 01705692 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer.exe
2014-07-19 08:01 - 2013-08-24 08:39 - 00000000 ____D () C:\Games
2014-07-19 07:53 - 2014-06-30 13:44 - 00000000 ____D () C:\Users\Florian-KFZMeister\Downloads\Musikjunkie - Guano Apes 2014 Offline Bitrate VBR 04 Numen
2014-07-19 07:51 - 2014-07-19 07:51 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LavasoftStatistics
2014-07-19 07:50 - 2014-07-19 07:50 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft
2014-07-19 07:43 - 2014-07-19 07:43 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-07-19 07:30 - 2013-07-12 17:24 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\re
2014-07-18 17:18 - 2014-07-18 17:17 - 00491000 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-07-18 17:17 - 2013-04-15 08:37 - 00000000 ____D () C:\Users\Florian-KFZMeister\.thumbnails
2014-07-18 17:12 - 2013-03-28 17:40 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\repline
2014-07-18 15:55 - 2012-11-26 08:01 - 00000870 _____ () C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2014-07-18 13:01 - 2013-09-19 08:20 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\vlc
2014-07-18 12:28 - 2014-07-18 12:16 - 00000000 ____D () C:\rei
2014-07-18 12:28 - 2014-07-18 12:15 - 00000163 _____ () C:\WINDOWS\Reimage.ini
2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Reimage Protector
2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
2014-07-18 09:07 - 2014-07-18 09:07 - 00000000 _____ () C:\Users\Florian-KFZMeister\com.attensity.bosch.esi.updateclient.StartUpdateClient.tmp
2014-07-17 13:56 - 2014-04-16 10:02 - 00000000 ____D () C:\ProgramData\WarThunder
2014-07-17 07:29 - 2013-06-11 09:43 - 00000000 ____D () C:\ProgramData\Bosch
2014-07-17 07:28 - 2013-06-11 09:43 - 00000488 _____ () C:\WINDOWS\RbSystem.ini
2014-07-17 07:20 - 2014-07-16 11:55 - 00000000 ____D () C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131
2014-07-16 17:11 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-07-16 12:06 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-07-16 11:54 - 2014-07-16 11:54 - 00000000 ____D () C:\Program Files\005
2014-07-16 07:13 - 2014-04-16 10:02 - 00000000 ____D () C:\Program Files (x86)\WarThunder
2014-07-14 16:39 - 2013-04-24 10:52 - 00133799 _____ () C:\Users\Florian-KFZMeister\ewa_client_0.log
2014-07-14 16:39 - 2013-04-24 10:52 - 00000000 ____D () C:\Users\Florian-KFZMeister\XFER
2014-07-14 16:24 - 2013-04-24 10:52 - 00000122 _____ () C:\Users\Florian-KFZMeister\.ewanapi_cookie
2014-07-14 08:55 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-07-14 08:31 - 2014-07-14 08:31 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\.eva
2014-07-14 08:29 - 2014-07-14 08:29 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Daimler
2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore
2014-07-10 21:40 - 2014-07-10 21:40 - 00046376 _____ (NetFilterSDK.com) C:\WINDOWS\system32\Drivers\netfilter64.sys
2014-07-10 17:42 - 2014-03-03 13:54 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-07-09 08:03 - 2013-04-14 20:50 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-07-09 08:03 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-07-09 08:02 - 2013-07-23 09:05 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-07-09 08:00 - 2013-04-15 07:41 - 96441528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-07-09 07:58 - 2013-09-30 05:59 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-08 08:05 - 2014-03-03 13:55 - 00000000 ____D () C:\Program Files (x86)\Diablo III
2014-07-02 16:35 - 2013-06-19 10:56 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\Formulare und Vorlagen
2014-06-30 13:53 - 2014-06-30 13:53 - 00001674 _____ () C:\Users\Florian-KFZMeister\AppData\Local\recently-used.xbel
2014-06-30 13:53 - 2013-04-15 08:36 - 00000000 ____D () C:\Users\Florian-KFZMeister\.gimp-2.8
2014-06-26 22:55 - 2014-04-30 08:06 - 00703968 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-06-26 22:55 - 2014-04-30 08:06 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-25 17:58 - 2014-01-23 12:31 - 00004132 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-25 17:58 - 2014-01-23 12:30 - 00003896 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-23 10:16 - 2013-04-14 11:49 - 00001382 _____ () C:\Users\Public\Desktop\CENTROdigital SmartClient.lnk

Files to move or delete:
====================
C:\ProgramData\MakeMarkerFile.exe
C:\Users\EasySurvey\EasySurvey.exe


Some content of TEMP:
====================
C:\Users\Florian-KFZMeister\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-21 12:14

==================== End Of Log ============================
         
--- --- ---

--- --- ---

Alt 21.07.2014, 12:54   #5
Warlord711
/// TB-Ausbilder
 
Windows 8.1: Werbe-Popups in Google Chrome und Opera - Standard

Windows 8.1: Werbe-Popups in Google Chrome und Opera



Hm, ok - hier müssen wir von Hand nachhelfen:

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
() C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe
() C:\Program Files\005\cyycfhtzro64.exe
R2 AllDaySavingsService64; C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe [172544 2014-07-10] () [File not signed]
R2 cyycfhtzro64; C:\Program Files\005\cyycfhtzro64.exe [709120 2014-07-16] () [File not signed]
AlternateDataStreams: C:\Windows:CM_1f24a44e6b128c2d77667e26df6bc247ed05d9ea5eb435533ab783378d367198
AlternateDataStreams: C:\Windows:CM_4c09c6a837b828f8e71ff53bdfa462592466a103481eefe431e5b35c94a386a5
C:\Program Files\005
C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Alt 21.07.2014, 13:00   #6
flo344i
 
Windows 8.1: Werbe-Popups in Google Chrome und Opera - Standard

Windows 8.1: Werbe-Popups in Google Chrome und Opera



Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-07-2014
Ran by Florian-KFZMeister at 2014-07-21 13:59:16 Run:1
Running from C:\Users\Florian-KFZMeister\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
() C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe
() C:\Program Files\005\cyycfhtzro64.exe
R2 AllDaySavingsService64; C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe [172544 2014-07-10] () [File not signed]
R2 cyycfhtzro64; C:\Program Files\005\cyycfhtzro64.exe [709120 2014-07-16] () [File not signed]
AlternateDataStreams: C:\Windows:CM_1f24a44e6b128c2d77667e26df6bc247ed05d9ea5eb435533ab783378d367198
AlternateDataStreams: C:\Windows:CM_4c09c6a837b828f8e71ff53bdfa462592466a103481eefe431e5b35c94a386a5
C:\Program Files\005
C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\
         
*****************

[1712] C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131\sbmrwsyodt64.exe => Process closed successfully.
[1856] C:\Program Files\005\cyycfhtzro64.exe => Process closed successfully.
AllDaySavingsService64 => Service stopped successfully.
AllDaySavingsService64 => Service deleted successfully.
cyycfhtzro64 => Service deleted successfully.
C:\Windows => ":CM_1f24a44e6b128c2d77667e26df6bc247ed05d9ea5eb435533ab783378d367198" ADS removed successfully.
C:\Windows => ":CM_4c09c6a837b828f8e71ff53bdfa462592466a103481eefe431e5b35c94a386a5" ADS removed successfully.
C:\Program Files\005 => Moved successfully.
C:\Program Files (x86)\A7F8482B-1D99-4EC9-B887-8B130AB7E131 => Moved successfully.

==== End of Fixlog ====
         

Alt 21.07.2014, 13:05   #7
Warlord711
/// TB-Ausbilder
 
Windows 8.1: Werbe-Popups in Google Chrome und Opera - Standard

Windows 8.1: Werbe-Popups in Google Chrome und Opera



OK, dann machen wir so weiter:


ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Der Scan dauert länger. Sind die Popups noch da ?

Alt 21.07.2014, 13:18   #8
flo344i
 
Windows 8.1: Werbe-Popups in Google Chrome und Opera - Standard

Windows 8.1: Werbe-Popups in Google Chrome und Opera



Zitat:
Zitat von Warlord711 Beitrag anzeigen


Sind die Popups noch da ?
Nein die Popups sind weg

Alt 21.07.2014, 13:24   #9
Warlord711
/// TB-Ausbilder
 
Windows 8.1: Werbe-Popups in Google Chrome und Opera - Standard

Windows 8.1: Werbe-Popups in Google Chrome und Opera



Hab auch nix anderes erwartet

Dann schauen wir noch was ESET sagt.

Alt 22.07.2014, 07:16   #10
flo344i
 
Windows 8.1: Werbe-Popups in Google Chrome und Opera - Standard

Windows 8.1: Werbe-Popups in Google Chrome und Opera



Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
Can not extract cabC:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScanner.cabErr:Der Vorgang wurde erfolgreich beendet.
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=aff4aa0471552244977369db06e6f747
# engine=19274
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-07-21 03:25:17
# local_time=2014-07-21 05:25:17 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT 
# compatibility_mode_1='Kaspersky Internet Security'
# compatibility_mode=1291 16777214 100 98 19946 60726239 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 5392504 30837610 0 0
# scanned=651398
# found=4
# cleaned=0
# scan_time=10884
sh=41EA136148FB653782E8A2479EA0D86666F30377 ft=1 fh=51a53a33d3e8c027 vn="Variante von MSIL/Adware.iBryte.D Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Browsersafeguard\uninstall.BrowserSafeguard.exe.vir"
sh=96A5AEBAF5A2C96B869168D409FAF54BC52F4BFB ft=1 fh=95a04965e73ede3e vn="Variante von Win64/Adware.Adpeak.C Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\005\cyycfhtzro64.exe"
sh=D8C35097E17E1FD96E1A04F66D828C386B758310 ft=1 fh=56ce06f6adf24540 vn="Win32/Toolbar.Babylon.T evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Florian-KFZMeister\AppData\Local\Microsoft\Windows\INetCache\IE\LGWG11SD\ProtectorPackage2001x64[1].exe"
sh=E5B4DFCD56B817D4B03316FFE8CE05F535E856E8 ft=1 fh=36a8d984243397e5 vn="Win32/DriverBoss.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Florian-KFZMeister\Downloads\hp-laserjet-3050-driver-utility.exe"
         
gerade ist noch Malwarebyte aufgegangen und meldet folgendes:

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 22.07.2014
Suchlauf-Zeit: 07:39:42
Logdatei: mbam1.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.07.21.09
Rootkit Datenbank: v2014.07.17.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Florian-KFZMeister

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 356565
Verstrichene Zeit: 16 Min, 8 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 4
PUP.Optional.Adpeak.A, HKLM\SOFTWARE\AllDaySavings, , [cb622d75c5b6c274dcfaf9caff0315eb], 
PUP.Optional.Adpeak.A, HKLM\SOFTWARE\WOW6432NODE\AllDaySavings, , [51dc059d116a62d4dff76c579b6720e0], 
PUP.Optional.AdPeak, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\netfilter64, , [e9443969b1ca9a9caa0a0ab842c0b64a], 
PUP.Optional.SuperFish.A, HKU\S-1-5-21-2830974330-3213038589-3334289725-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com, , [cc6151517cffbe78bf7be7e28e74b34d], 

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 2
PUP.Optional.Adpeak.A, C:\Program Files\AllDaySavings, , [72bbdfc3fa81be78abe05f614bb72bd5], 
PUP.Optional.Adpeak.A, C:\Program Files\AllDaySavings\SSL, , [72bbdfc3fa81be78abe05f614bb72bd5], 

Dateien: 5
PUP.Optional.BetterDeals.A, C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage, , [95989111483387af3e7ffbd415edd12f], 
PUP.Optional.BetterDeals.A, C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage-journal, , [59d4554dc5b66fc705b8468979899a66], 
PUP.Optional.Superfish.A, C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, , [eb42c6dc3546f04662963f9517eb26da], 
PUP.Optional.Superfish.A, C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, , [fc31b7eb6c0fff378276e3f139c97e82], 
PUP.Optional.AdPeak, C:\Windows\System32\drivers\netfilter64.sys, , [e9443969b1ca9a9caa0a0ab842c0b64a], 

Physische Sektoren: 0
(No malicious items detected)


(end)
         
Habe noch nichts weiteres unternommen, Fenster ist noch offen!

Alt 22.07.2014, 07:31   #11
Warlord711
/// TB-Ausbilder
 
Windows 8.1: Werbe-Popups in Google Chrome und Opera - Standard

Windows 8.1: Werbe-Popups in Google Chrome und Opera



Ok, ESET hat auch nur noch marginales gefunden.

Das löschen wir grad und dann noch ein frisches FRST Log:

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
C:\Users\Florian-KFZMeister\Downloads\hp-laserjet-3050-driver-utility.exe
C:\Users\Florian-KFZMeister\AppData\Local\Microsoft\Windows\INetCache\IE\LGWG11SD\ProtectorPackage2001x64[1].exe
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Starte noch einmal FRST.
  • Ändere keine der Voreinstellungen und drücke auf Scan.
  • Wenn der Scan abgeschlossen ist, werden ein neues Logfile FRST.txt erstellt und auf dem Desktop gespeichert.
  • Poste den Inhalt dieses Logfiles bitte hier in deinen Thread.

Alt 22.07.2014, 07:44   #12
flo344i
 
Windows 8.1: Werbe-Popups in Google Chrome und Opera - Standard

Windows 8.1: Werbe-Popups in Google Chrome und Opera



Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 21-07-2014
Ran by Florian-KFZMeister at 2014-07-22 08:42:09 Run:2
Running from C:\Users\Florian-KFZMeister\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\Users\Florian-KFZMeister\Downloads\hp-laserjet-3050-driver-utility.exe
C:\Users\Florian-KFZMeister\AppData\Local\Microsoft\Windows\INetCache\IE\LGWG11SD\ProtectorPackage2001x64[1].exe
         
*****************

C:\Users\Florian-KFZMeister\Downloads\hp-laserjet-3050-driver-utility.exe => Moved successfully.
C:\Users\Florian-KFZMeister\AppData\Local\Microsoft\Windows\INetCache\IE\LGWG11SD\ProtectorPackage2001x64[1].exe => Moved successfully.

==== End of Fixlog ====
         

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-07-2014
Ran by Florian-KFZMeister (administrator) on WERKSTATT-PC on 22-07-2014 08:42:28
Running from C:\Users\Florian-KFZMeister\Desktop
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
() C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(shbox.de) C:\Program Files (x86)\FreePDF_XP\fpassist.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\SAMSUNG\SW Update Service\SWMAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9654.17044_x64__8wekyb3d8bbwe\glcnd.exe
(Opera Software) C:\Program Files (x86)\Opera\opera.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSACCESS.EXE


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191824 2012-08-10] (Realtek Semiconductor)
HKLM\...\Run: [BtTray] => C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [766080 2012-12-05] (Qualcomm Atheros)
HKLM\...\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [128640 2012-12-05] (Atheros Communications)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2917688 2012-10-16] (Synaptics Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [97392 2012-08-15] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-12] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation)
HKLM-x32\...\Run: [FreePDF Assistant] => C:\Program Files (x86)\FreePDF_XP\fpassist.exe [373760 2013-03-14] (shbox.de)
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\runner_avp.exe [24504 2012-12-14] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [StartDDM] => C:\Program Files (x86)\Bosch\DownloadManager\bin\runDDM.exe
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-18] (Advanced Micro Devices, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1825984 2014-04-24] (Valve Corporation)
HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Florian-KFZMeister\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHel (the data entry has 8 more characters).
HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Run: [Amazon Cloud Player] => C:\Users\Florian-KFZMeister\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3145536 2013-12-12] ()
HKU\S-1-5-21-2830974330-3213038589-3334289725-1002\...\Policies\system: [DisableLockWorkstation] 0
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk
ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com
SearchScopes: HKLM - DefaultScope {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKLM - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKCU - {5F6AE902-9EA7-4329-89CC-8F8737BA95CD} URL = 
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
DPF: HKLM-x32 {55369874-02F5-47E2-A0F7-AC67E1B1866E} hxxp://www.centrodigital.de/smart/setup.ocx
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Florian-KFZMeister\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Florian-KFZMeister\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF HKLM-x32\...\Firefox\Extensions:  - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013-05-15]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013-05-15]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013-05-15]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2013-05-15]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2013-05-15]

Chrome: 
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "hxxp://www.google.com/"
CHR Extension: (Google Docs) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-23]
CHR Extension: (Modul zur Link-Untersuchung) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-01-23]
CHR Extension: (Sicherer Zahlungsverkehr) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-01-23]
CHR Extension: (Modul für das Blockieren gefährlicher Webseiten) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-01-23]
CHR Extension: (Virtuelle Tastatur) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-01-23]
CHR Extension: (Google Wallet) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-23]
CHR Extension: (Anti-Banner) - C:\Users\Florian-KFZMeister\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-01-23]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2012-12-14]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\online_banking_chrome.crx [2012-12-14]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2012-12-14]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2013-05-15]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\ab.crx [2012-12-14]

==================== Services (Whitelisted) =================

R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [231552 2012-12-05] (Qualcomm Atheros Commnucations)
S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1593976 2012-09-05] (Samsung Electronics CO., LTD.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 Simraceway Update Service; C:\Program Files (x86)\SimracewayUpdater\SRWUpdate.exe [1630720 2013-07-11] () [File not signed]
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-12-05] (Atheros) [File not signed]

==================== Drivers (Whitelisted) ====================

R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2013-05-21] (Advanced Micro Devices, Inc.)
R3 BTATH_HID; C:\Windows\system32\DRIVERS\btath_hid.sys [222360 2012-12-05] (Qualcomm Atheros)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2012-12-05] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
S3 CH341SER_A64; C:\Windows\System32\Drivers\CH341S64.SYS [58368 2011-11-04] (www.winchiphead.com)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [146856 2013-06-04] (Windows (R) Win 7 DDK provider)
R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [21928 2013-06-04] (Windows (R) Win 7 DDK provider)
S3 IntcDAud; C:\Windows\system32\DRIVERS\IntcDAud.sys [342528 2012-06-19] (Intel(R) Corporation) [File not signed]
S3 intelkmd; C:\Windows\system32\DRIVERS\igdpmd64.sys [5338848 2012-09-17] (Intel Corporation) [File not signed]
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [29616 2012-07-27] (Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [627296 2014-05-20] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [30304 2013-12-11] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [50448 2013-05-15] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [178448 2013-05-15] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-22] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2014-07-10] (NetFilterSDK.com)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-22 08:42 - 2014-07-22 08:42 - 00000000 ____D () C:\Users\Florian-KFZMeister\Desktop\FRST-OlderVersion
2014-07-22 08:14 - 2014-07-22 08:14 - 00002722 _____ () C:\Users\Florian-KFZMeister\Desktop\mbam1.txt
2014-07-21 14:08 - 2014-07-21 14:09 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Desktop\esetsmartinstaller_deu.exe
2014-07-21 13:39 - 2014-07-21 13:39 - 00001156 _____ () C:\Users\Florian-KFZMeister\Desktop\mbam.txt
2014-07-21 12:03 - 2014-07-22 07:39 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-07-21 12:03 - 2014-07-21 12:03 - 00001118 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-21 12:03 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-07-21 12:03 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-07-21 12:03 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-07-21 12:02 - 2014-07-21 12:02 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Florian-KFZMeister\Desktop\mbam-setup-2.0.2.1012.exe
2014-07-21 12:01 - 2014-07-21 12:01 - 00000627 _____ () C:\Users\Florian-KFZMeister\Desktop\JRT.txt
2014-07-21 11:57 - 2014-07-21 11:57 - 01016261 _____ (Thisisu) C:\Users\Florian-KFZMeister\Desktop\JRT.exe
2014-07-21 11:52 - 2014-07-21 11:52 - 00000000 ___RD () C:\Users\Florian-KFZMeister\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-07-21 11:51 - 2014-07-21 11:51 - 00000000 ____H () C:\ProgramData\cm-lock
2014-07-21 11:48 - 2014-07-21 11:48 - 01354223 _____ () C:\Users\Florian-KFZMeister\Desktop\adwcleaner_3.216.exe
2014-07-21 09:46 - 2014-07-21 09:46 - 00007268 _____ () C:\Users\Florian-KFZMeister\Desktop\GMER.log
2014-07-21 09:29 - 2014-07-21 09:29 - 704339485 _____ () C:\WINDOWS\MEMORY.DMP
2014-07-21 09:29 - 2014-07-21 09:29 - 00299272 _____ () C:\WINDOWS\Minidump\072114-35515-01.dmp
2014-07-21 09:29 - 2014-07-21 09:29 - 00000000 ____D () C:\WINDOWS\Minidump
2014-07-21 09:25 - 2014-07-22 08:42 - 00020819 _____ () C:\Users\Florian-KFZMeister\Desktop\FRST.txt
2014-07-21 09:25 - 2014-07-22 08:42 - 00000000 ____D () C:\FRST
2014-07-21 09:25 - 2014-07-21 09:26 - 00053834 _____ () C:\Users\Florian-KFZMeister\Desktop\Addition.txt
2014-07-21 09:24 - 2014-07-21 09:32 - 00000498 _____ () C:\Users\Florian-KFZMeister\Desktop\defogger_disable.log
2014-07-21 09:24 - 2014-07-21 09:24 - 00000000 _____ () C:\Users\Florian-KFZMeister\defogger_reenable
2014-07-21 09:22 - 2014-07-22 08:42 - 02090496 _____ (Farbar) C:\Users\Florian-KFZMeister\Desktop\FRST64.exe
2014-07-21 09:22 - 2014-07-21 09:22 - 00380416 _____ () C:\Users\Florian-KFZMeister\Desktop\8kgufznd.exe
2014-07-21 09:21 - 2014-07-21 09:21 - 00050477 _____ () C:\Users\Florian-KFZMeister\Desktop\Defogger.exe
2014-07-21 08:59 - 2014-07-21 08:59 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe
2014-07-21 08:59 - 2014-07-21 08:59 - 02088532 _____ () C:\Users\Florian-KFZMeister\Downloads\FRST64.exe
2014-07-19 08:28 - 2014-07-19 08:28 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-07-19 08:13 - 2014-07-19 08:13 - 00003228 _____ () C:\WINDOWS\System32\Tasks\{195AC1F4-9216-4E5D-970E-EE662B1F6FAB}
2014-07-19 08:10 - 2014-07-19 08:10 - 01707144 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer (1).exe
2014-07-19 08:08 - 2014-07-21 13:57 - 00000000 ____D () C:\Program Files\AllDaySavings
2014-07-19 08:05 - 2014-07-19 08:05 - 00822568 _____ (Reimage®) C:\Users\Florian-KFZMeister\Downloads\ReimageRepair.exe
2014-07-19 08:03 - 2014-07-19 08:04 - 01705692 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer.exe
2014-07-19 07:51 - 2014-07-19 07:51 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LavasoftStatistics
2014-07-19 07:50 - 2014-07-19 07:50 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft
2014-07-19 07:43 - 2014-07-19 07:43 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-07-18 17:17 - 2014-07-21 11:51 - 00005694 _____ () C:\WINDOWS\PFRO.log
2014-07-18 17:17 - 2014-07-18 17:18 - 00491000 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-07-18 17:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll
2014-07-18 17:13 - 2014-07-21 13:43 - 00000000 ____D () C:\AdwCleaner
2014-07-18 12:28 - 2014-07-21 11:46 - 00003494 _____ () C:\WINDOWS\System32\Tasks\Reimage Reminder
2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Reimage Protector
2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
2014-07-18 12:16 - 2014-07-18 12:28 - 00000000 ____D () C:\rei
2014-07-18 12:15 - 2014-07-18 12:28 - 00000163 _____ () C:\WINDOWS\Reimage.ini
2014-07-18 09:07 - 2014-07-18 09:07 - 00000000 _____ () C:\Users\Florian-KFZMeister\com.attensity.bosch.esi.updateclient.StartUpdateClient.tmp
2014-07-14 08:31 - 2014-07-14 08:31 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\.eva
2014-07-14 08:29 - 2014-07-14 08:29 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Daimler
2014-07-10 21:40 - 2014-07-10 21:40 - 00046376 _____ (NetFilterSDK.com) C:\WINDOWS\system32\Drivers\netfilter64.sys
2014-07-09 07:58 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2014-07-09 07:43 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe
2014-07-09 07:43 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe
2014-07-09 07:43 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-07-09 07:43 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2014-07-09 07:43 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2014-07-09 07:43 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2014-07-09 07:43 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2014-07-09 07:43 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2014-07-09 07:43 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2014-07-09 07:43 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-07-09 07:42 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-07-09 07:42 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-07-09 07:42 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-07-09 07:42 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-07-09 07:42 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-07-09 07:42 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-07-09 07:42 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-07-09 07:42 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-07-09 07:42 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-07-09 07:42 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-07-09 07:42 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-07-09 07:42 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-07-09 07:42 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-07-09 07:42 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-07-09 07:42 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-07-09 07:42 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-07-09 07:42 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-07-09 07:42 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-07-09 07:42 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-07-09 07:42 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-07-09 07:42 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-07-09 07:42 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-07-09 07:42 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-07-09 07:42 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-07-09 07:42 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-07-09 07:42 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-07-09 07:42 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-07-09 07:42 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2014-07-09 07:42 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2014-07-09 07:42 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-07-09 07:42 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2014-07-09 07:42 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-07-09 07:42 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-07-09 07:42 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-09 07:42 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-07-09 07:42 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-07-09 07:42 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-09 07:42 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2014-07-09 07:42 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2014-07-09 07:42 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-07-09 07:42 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2014-07-09 07:42 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-07-09 07:42 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2014-07-09 07:42 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-06-30 13:53 - 2014-06-30 13:53 - 00001674 _____ () C:\Users\Florian-KFZMeister\AppData\Local\recently-used.xbel
2014-06-30 13:44 - 2014-07-19 07:53 - 00000000 ____D () C:\Users\Florian-KFZMeister\Downloads\Musikjunkie - Guano Apes 2014 Offline Bitrate VBR 04 Numen

==================== One Month Modified Files and Folders =======

2014-07-22 08:42 - 2014-07-22 08:42 - 00000000 ____D () C:\Users\Florian-KFZMeister\Desktop\FRST-OlderVersion
2014-07-22 08:42 - 2014-07-21 09:25 - 00020819 _____ () C:\Users\Florian-KFZMeister\Desktop\FRST.txt
2014-07-22 08:42 - 2014-07-21 09:25 - 00000000 ____D () C:\FRST
2014-07-22 08:42 - 2014-07-21 09:22 - 02090496 _____ (Farbar) C:\Users\Florian-KFZMeister\Desktop\FRST64.exe
2014-07-22 08:39 - 2013-10-30 13:04 - 01759912 _____ () C:\WINDOWS\WindowsUpdate.log
2014-07-22 08:39 - 2013-04-14 11:43 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2830974330-3213038589-3334289725-1002
2014-07-22 08:34 - 2014-01-23 12:31 - 00002195 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-22 08:34 - 2014-01-23 12:31 - 00001160 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-22 08:20 - 2013-10-30 10:43 - 00000064 __RSH () C:\WINDOWS\system32\Drivers\VSTXRAID.winsecurity
2014-07-22 08:14 - 2014-07-22 08:14 - 00002722 _____ () C:\Users\Florian-KFZMeister\Desktop\mbam1.txt
2014-07-22 08:04 - 2013-05-15 10:19 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-07-22 08:02 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-07-22 08:01 - 2012-11-26 08:17 - 00000360 _____ () C:\WINDOWS\Tasks\Xerox PhotoCafe Communicator.job
2014-07-22 07:56 - 2013-03-28 17:40 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\repline
2014-07-22 07:54 - 2013-10-30 10:14 - 00000064 __RSH () C:\WINDOWS\system32\Drivers\WUDFPf.winsecurity
2014-07-22 07:47 - 2013-04-15 08:19 - 00000000 ____D () C:\KfzKaufmann
2014-07-22 07:42 - 2013-09-30 06:14 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-07-22 07:42 - 2013-09-30 05:56 - 00766620 _____ () C:\WINDOWS\system32\perfh007.dat
2014-07-22 07:42 - 2013-09-30 05:56 - 00159902 _____ () C:\WINDOWS\system32\perfc007.dat
2014-07-22 07:39 - 2014-07-21 12:03 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-07-21 18:03 - 2014-01-23 12:30 - 00001156 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-21 15:55 - 2012-11-26 08:01 - 00000870 _____ () C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2014-07-21 14:09 - 2014-07-21 14:08 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Desktop\esetsmartinstaller_deu.exe
2014-07-21 13:57 - 2014-07-19 08:08 - 00000000 ____D () C:\Program Files\AllDaySavings
2014-07-21 13:43 - 2014-07-18 17:13 - 00000000 ____D () C:\AdwCleaner
2014-07-21 13:39 - 2014-07-21 13:39 - 00001156 _____ () C:\Users\Florian-KFZMeister\Desktop\mbam.txt
2014-07-21 12:03 - 2014-07-21 12:03 - 00001118 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-21 12:03 - 2014-07-21 12:03 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-21 12:02 - 2014-07-21 12:02 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Florian-KFZMeister\Desktop\mbam-setup-2.0.2.1012.exe
2014-07-21 12:01 - 2014-07-21 12:01 - 00000627 _____ () C:\Users\Florian-KFZMeister\Desktop\JRT.txt
2014-07-21 11:57 - 2014-07-21 11:57 - 01016261 _____ (Thisisu) C:\Users\Florian-KFZMeister\Desktop\JRT.exe
2014-07-21 11:55 - 2012-11-26 08:09 - 00000000 ____D () C:\ProgramData\WinClon
2014-07-21 11:52 - 2014-07-21 11:52 - 00000000 ___RD () C:\Users\Florian-KFZMeister\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-07-21 11:52 - 2014-04-17 11:11 - 00000000 __RDO () C:\Users\Florian-KFZMeister\SkyDrive
2014-07-21 11:52 - 2013-04-15 09:52 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\FreePDF_XP
2014-07-21 11:52 - 2012-11-26 08:01 - 00000868 _____ () C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-07-21 11:51 - 2014-07-21 11:51 - 00000000 ____H () C:\ProgramData\cm-lock
2014-07-21 11:51 - 2014-07-18 17:17 - 00005694 _____ () C:\WINDOWS\PFRO.log
2014-07-21 11:51 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-07-21 11:51 - 2013-08-06 13:50 - 00599686 _____ () C:\Simraceway.log
2014-07-21 11:50 - 2013-10-30 12:44 - 00000000 ____D () C:\Users\Florian-KFZMeister
2014-07-21 11:50 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-07-21 11:48 - 2014-07-21 11:48 - 01354223 _____ () C:\Users\Florian-KFZMeister\Desktop\adwcleaner_3.216.exe
2014-07-21 11:47 - 2013-04-14 21:37 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-07-21 11:46 - 2014-07-18 12:28 - 00003494 _____ () C:\WINDOWS\System32\Tasks\Reimage Reminder
2014-07-21 11:46 - 2012-11-26 08:17 - 00003298 _____ () C:\WINDOWS\System32\Tasks\Xerox PhotoCafe Communicator
2014-07-21 11:45 - 2012-11-26 08:11 - 00000000 ____D () C:\ProgramData\Adobe
2014-07-21 11:10 - 2014-01-23 17:12 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\Schaltpläne
2014-07-21 09:46 - 2014-07-21 09:46 - 00007268 _____ () C:\Users\Florian-KFZMeister\Desktop\GMER.log
2014-07-21 09:41 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-07-21 09:32 - 2014-07-21 09:24 - 00000498 _____ () C:\Users\Florian-KFZMeister\Desktop\defogger_disable.log
2014-07-21 09:29 - 2014-07-21 09:29 - 704339485 _____ () C:\WINDOWS\MEMORY.DMP
2014-07-21 09:29 - 2014-07-21 09:29 - 00299272 _____ () C:\WINDOWS\Minidump\072114-35515-01.dmp
2014-07-21 09:29 - 2014-07-21 09:29 - 00000000 ____D () C:\WINDOWS\Minidump
2014-07-21 09:26 - 2014-07-21 09:25 - 00053834 _____ () C:\Users\Florian-KFZMeister\Desktop\Addition.txt
2014-07-21 09:24 - 2014-07-21 09:24 - 00000000 _____ () C:\Users\Florian-KFZMeister\defogger_reenable
2014-07-21 09:22 - 2014-07-21 09:22 - 00380416 _____ () C:\Users\Florian-KFZMeister\Desktop\8kgufznd.exe
2014-07-21 09:21 - 2014-07-21 09:21 - 00050477 _____ () C:\Users\Florian-KFZMeister\Desktop\Defogger.exe
2014-07-21 08:59 - 2014-07-21 08:59 - 02347384 _____ (ESET) C:\Users\Florian-KFZMeister\Downloads\esetsmartinstaller_deu.exe
2014-07-21 08:59 - 2014-07-21 08:59 - 02088532 _____ () C:\Users\Florian-KFZMeister\Downloads\FRST64.exe
2014-07-21 08:27 - 2013-12-13 13:46 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LumacDaemon
2014-07-21 08:17 - 2014-03-03 13:54 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Battle.net
2014-07-19 08:28 - 2014-07-19 08:28 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-07-19 08:13 - 2014-07-19 08:13 - 00003228 _____ () C:\WINDOWS\System32\Tasks\{195AC1F4-9216-4E5D-970E-EE662B1F6FAB}
2014-07-19 08:10 - 2014-07-19 08:10 - 01707144 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer (1).exe
2014-07-19 08:05 - 2014-07-19 08:05 - 00822568 _____ (Reimage®) C:\Users\Florian-KFZMeister\Downloads\ReimageRepair.exe
2014-07-19 08:04 - 2014-07-19 08:03 - 01705692 _____ () C:\Users\Florian-KFZMeister\Downloads\Adaware_Installer.exe
2014-07-19 08:01 - 2013-08-24 08:39 - 00000000 ____D () C:\Games
2014-07-19 07:53 - 2014-06-30 13:44 - 00000000 ____D () C:\Users\Florian-KFZMeister\Downloads\Musikjunkie - Guano Apes 2014 Offline Bitrate VBR 04 Numen
2014-07-19 07:51 - 2014-07-19 07:51 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\LavasoftStatistics
2014-07-19 07:50 - 2014-07-19 07:50 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft
2014-07-19 07:43 - 2014-07-19 07:43 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-07-19 07:30 - 2013-07-12 17:24 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\re
2014-07-18 17:18 - 2014-07-18 17:17 - 00491000 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-07-18 17:17 - 2013-04-15 08:37 - 00000000 ____D () C:\Users\Florian-KFZMeister\.thumbnails
2014-07-18 13:01 - 2013-09-19 08:20 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\vlc
2014-07-18 12:28 - 2014-07-18 12:16 - 00000000 ____D () C:\rei
2014-07-18 12:28 - 2014-07-18 12:15 - 00000163 _____ () C:\WINDOWS\Reimage.ini
2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Reimage Protector
2014-07-18 12:27 - 2014-07-18 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
2014-07-18 09:07 - 2014-07-18 09:07 - 00000000 _____ () C:\Users\Florian-KFZMeister\com.attensity.bosch.esi.updateclient.StartUpdateClient.tmp
2014-07-17 13:56 - 2014-04-16 10:02 - 00000000 ____D () C:\ProgramData\WarThunder
2014-07-17 07:29 - 2013-06-11 09:43 - 00000000 ____D () C:\ProgramData\Bosch
2014-07-17 07:28 - 2013-06-11 09:43 - 00000488 _____ () C:\WINDOWS\RbSystem.ini
2014-07-16 17:11 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-07-16 12:06 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-07-16 07:13 - 2014-04-16 10:02 - 00000000 ____D () C:\Program Files (x86)\WarThunder
2014-07-14 16:39 - 2013-04-24 10:52 - 00133799 _____ () C:\Users\Florian-KFZMeister\ewa_client_0.log
2014-07-14 16:39 - 2013-04-24 10:52 - 00000000 ____D () C:\Users\Florian-KFZMeister\XFER
2014-07-14 16:24 - 2013-04-24 10:52 - 00000122 _____ () C:\Users\Florian-KFZMeister\.ewanapi_cookie
2014-07-14 08:55 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-07-14 08:31 - 2014-07-14 08:31 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Roaming\.eva
2014-07-14 08:29 - 2014-07-14 08:29 - 00000000 ____D () C:\Users\Florian-KFZMeister\AppData\Local\Daimler
2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-14 07:28 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore
2014-07-10 21:40 - 2014-07-10 21:40 - 00046376 _____ (NetFilterSDK.com) C:\WINDOWS\system32\Drivers\netfilter64.sys
2014-07-10 17:42 - 2014-03-03 13:54 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-07-09 08:03 - 2013-04-14 20:50 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-07-09 08:03 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-07-09 08:02 - 2013-07-23 09:05 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-07-09 08:00 - 2013-04-15 07:41 - 96441528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-07-09 07:58 - 2013-09-30 05:59 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-08 08:05 - 2014-03-03 13:55 - 00000000 ____D () C:\Program Files (x86)\Diablo III
2014-07-02 16:35 - 2013-06-19 10:56 - 00000000 ____D () C:\Users\Florian-KFZMeister\Documents\Formulare und Vorlagen
2014-06-30 13:53 - 2014-06-30 13:53 - 00001674 _____ () C:\Users\Florian-KFZMeister\AppData\Local\recently-used.xbel
2014-06-30 13:53 - 2013-04-15 08:36 - 00000000 ____D () C:\Users\Florian-KFZMeister\.gimp-2.8
2014-06-26 22:55 - 2014-04-30 08:06 - 00703968 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-06-26 22:55 - 2014-04-30 08:06 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-25 17:58 - 2014-01-23 12:31 - 00004132 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-25 17:58 - 2014-01-23 12:30 - 00003896 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-23 10:16 - 2013-04-14 11:49 - 00001382 _____ () C:\Users\Public\Desktop\CENTROdigital SmartClient.lnk

Files to move or delete:
====================
C:\ProgramData\MakeMarkerFile.exe
C:\Users\EasySurvey\EasySurvey.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-21 12:14

==================== End Of Log ============================
         
--- --- ---

Alt 22.07.2014, 09:53   #13
Warlord711
/// TB-Ausbilder
 
Windows 8.1: Werbe-Popups in Google Chrome und Opera - Standard

Windows 8.1: Werbe-Popups in Google Chrome und Opera



Die Logs sehen für mich jetzt sauber aus

Noch 1-2 Sachen:

Update: Adobe Reader
Deinstalliere bitte deine aktuelle Version von Adobe Reader
Start--> Systemsteuerung--> Software--> Adobe Reader
und lade dir die neue Version von Hier herunter-
Entferne den Haken für den McAfee SecurityScan bzw. Google Chrome.



Dein Java ist nicht mehr aktuell.
Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
  • Downloade dir bitte die neueste Java-Version von hier
  • Speichere die jxpiinstall.exe
  • Schließe alle laufenden Programme. Speziell deinen Browser.
  • Starte die jxpiinstall.exe. Diese wird den Installer für die neueste Java Version ( Java 7 Update 60 ) herunter laden.
  • Entferne den Haken bei "Installieren Sie die Ask-Toolbar ..." während der Installation.
  • Wenn die Installation beendet wurde
    Start --> Systemsteuerung --> Programme und deinstalliere alle älteren Java Versionen.
  • Starte deinen Rechner neu sobald alle älteren Versionen deinstalliert wurden.
Nach dem Neustart
  • Öffne erneut die Systemsteuerung --> Programme und klicke auf das Java Symbol.
  • Im Reiter Allgemein, klicke unter Temporäre Internetdateien auf Einstellungen.
  • Klicke auf Dateien löschen....
  • Gehe sicher das überall ein Haken gesetzt ist und klicke OK.
  • Klicke erneut OK.
schneller Plugin-Test: PluginCheck

Reste entfernen:

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems.


Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7 / 8 : Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti-Viren-Programm und zusätzlicher Schutz
  • Gehe sicher, dass du immer nur eine Anti-Viren Software installiert hast und dass diese auch up to date ist!
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion bietet zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • AdwCleaner
    Dieses Tool erkennt eine Vielzahl von Werbeprogrammen (Adware) und unerwümschten Programmen (PUPs).
    Starte das Tool einmal die Woche und lass es laufen. Sollte eine neue Version verfügbar sein, so wird dies angezeigt und du kannst dir die neueste Version direkt auf den Desktop downloaden.
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • WOT (Web of trust)
    Dieses AddOn warnt dich, bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser
Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Mozilla Firefox
  • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
  • NoScript
    Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt, wenn Du es bestätigst.
  • AdblockPlus
    Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
    Es spart außerdem Downloadkapazität.


Performance
  • Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
  • Halte dich fern von Registry Cleanern.
    Diese Schaden deinem System mehr als dass sie helfen. Hier ein englischer Link:
    Miekemoes Blogspot ( MVP )


Was du vermeiden solltest:
  • Klicke nicht auf alles, nur weil es dich dazu auffordert und schön bunt ist.
  • Verwende keine P2P oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie z.B. deinFoto.jpg.exe.
  • Lade keine Software von Softonic oder Chip herunter, da diese Installer oft mit Adware oder unerünschter Software versehen sind!



Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen?

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann.

Alt 22.07.2014, 11:18   #14
flo344i
 
Windows 8.1: Werbe-Popups in Google Chrome und Opera - Standard

Windows 8.1: Werbe-Popups in Google Chrome und Opera



Zitat:
Zitat von Warlord711 Beitrag anzeigen
Anti-Viren-Programm und zusätzlicher Schutz[list][*] Gehe sicher, dass du immer nur eine Anti-Viren Software installiert hast und dass diese auch up to date ist![*] MalwareBytes Anti Malware
Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion bietet zudem noch einen Hintergrundwächter.
Ein Tutorial zur Verwendung findest Du hier.
Dazu eine kleine Frage, kann ich das Malwareyte zusammen mit dem Kaspersky laufen lassen oder nicht? Oder würdest du generell ein anderes Anti-Viren Programm empfehlen? Die Kaspersky Lizenz läuft jetzt nämlich in einem Monat sowieso aus...

Mehr Fragen hab ich nicht und ansonsten bleibt mir nur zu sagen Vielen Vielen Dank für die verdammt schnelle und gute Hilfe!!!!!

Alt 22.07.2014, 12:08   #15
Warlord711
/// TB-Ausbilder
 
Windows 8.1: Werbe-Popups in Google Chrome und Opera - Standard

Windows 8.1: Werbe-Popups in Google Chrome und Opera



IMHO:

Wir haben auf Arbeit auch Kaspersky, find die Erkennungsrate sehr gut. Gibt zwar (für mich als Sysadmin) andere Ärgernisse bei Kaspersky, aber die haben eher mit administrativen Aufgaben zu tun ;-)
Malwarebytes kannst du problemlos zusätzlich einsetzen, da ein On-Demand Scanner, also "Auf Aufforderung". Somit hat Kaspersky oder jeder andere On-Access (Bei Zugriff auf Dateien) freie Bahn und wird nicht gestört.

Daheim nutz ich Emsisoft Anti Malware als Virenschutz.

Das "beste" Virenschutzprogramm gibts eh nicht.
Avira unterstütze ich, sowie ein Großteil der Board-Mitarbeiter nicht, da Avira die Ask-Toolbar mit der Free-Version koppelt.

Das ist, wie gesagt, meine persönliche Meinung und muss sich nicht mit den Aussagen anderer Boardmitarbeiter decken.

Antwort

Themen zu Windows 8.1: Werbe-Popups in Google Chrome und Opera
branding, device driver, ebanking, flash player, homepage, igdpmd64.sys, installation, internet, kaspersky, monitor, msil/adware.ibryte.d, problem, prozess, pup.optional.adpeak, pup.optional.adpeak.a, pup.optional.betterdeals.a, pup.optional.superfish.a, required, security, software, svchost.exe, tastatur, usb, win32/driverboss.b, win32/toolbar.babylon.t, win64/adware.adpeak.c, windows, windowsapps




Ähnliche Themen: Windows 8.1: Werbe-Popups in Google Chrome und Opera


  1. Win7 : Google Chrome - Bei klick im Bereich auf Webseite ,öffnet sich Werbe Tab
    Log-Analyse und Auswertung - 04.08.2015 (13)
  2. Chrome/Opera öffnet werbe-tabs automatisch!
    Log-Analyse und Auswertung - 04.06.2015 (21)
  3. Internetbrowser (Chrome) wird mit Werbe-popups zugespammt
    Plagegeister aller Art und deren Bekämpfung - 22.02.2015 (14)
  4. Google Chrome unzählige Werbe Tabs
    Log-Analyse und Auswertung - 10.01.2015 (3)
  5. Google Chrome und Opera Absturz
    Plagegeister aller Art und deren Bekämpfung - 30.10.2014 (11)
  6. Web-Browser Google Chrome öffnet ständig Werbe-Fenster und neue Tabs
    Plagegeister aller Art und deren Bekämpfung - 15.10.2014 (11)
  7. Google Chrome unzählige Werbe Tabs
    Log-Analyse und Auswertung - 06.09.2014 (7)
  8. Google Chrome öffnet eigene Werbe-Tabs (marketittzer.net - Weiterleitung zu andere Werbeseiten)
    Plagegeister aller Art und deren Bekämpfung - 21.07.2014 (24)
  9. Trojanerbefall, Werbe-popups nach sich ständig selbst installierender Chrome-Extension - Hilfe auch für jemanden der Englisch spricht?
    Plagegeister aller Art und deren Bekämpfung - 21.07.2014 (3)
  10. [Google Chrome] Ständige Popups (Spyware, FreeScan) und Verlinkungen in allen Textpassagen
    Plagegeister aller Art und deren Bekämpfung - 08.04.2014 (12)
  11. Windows 7: Verlinkungen und Popups in Chrome
    Log-Analyse und Auswertung - 26.03.2014 (6)
  12. Windows 7 Chrome Trojaner, Werbe-Popup Horror!
    Log-Analyse und Auswertung - 05.02.2014 (16)
  13. Windows 7: rvzr-a.akamaihd.net - permanente Werbe PopUps
    Plagegeister aller Art und deren Bekämpfung - 09.12.2013 (10)
  14. Windows 7: rvzr-a.akamaihd.net - permanente Werbe PopUps- wie kann ich (Laie) das entfernen ?
    Plagegeister aller Art und deren Bekämpfung - 04.12.2013 (9)
  15. Windows 7 - Flashwerbung u. Popups in Firefox sowie google Chrome
    Log-Analyse und Auswertung - 18.10.2013 (18)
  16. Windows 7: Werbe-PopUps (Warnung vor Spyware, wenig Speicherplatz,...)
    Log-Analyse und Auswertung - 23.09.2013 (12)
  17. Google Chrome und Opera starten nicht
    Plagegeister aller Art und deren Bekämpfung - 03.11.2010 (8)

Zum Thema Windows 8.1: Werbe-Popups in Google Chrome und Opera - Guten Morgen! Seit Ende letzter Woche habe ich das nervige Problem das in Google Chrome und auch Opera ständig Werbe-Popups aufgehen. Es sind verschieden Seiten die aufgehen, 123srv, ein angebliches - Windows 8.1: Werbe-Popups in Google Chrome und Opera...
Archiv
Du betrachtest: Windows 8.1: Werbe-Popups in Google Chrome und Opera auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.