Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 05.04.2015, 13:53   #1
MSE XIII
 
Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen - Standard

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen



Hallo,

vorab vielen Dank für die Möglichkeit, hier Hilfe zu finden. Und ein Wort zu mir. Ich bezeichne mich generell als DAU, da ich nur in ganz bestimmten Gebieten Teilwissen habe, dafür in vielen anderen Bereichen so gut wie Null Ahnung. Da kann es also auch vorkommen dass ich Anweisungen ohne Verzögerung nachkomme und im nächsten Moment nachfrage, wie ich was zu machen hätte. Bitte seht es mir nach.



Problem: ich habe mir ein Browser-Programm gefangen, das mir dauernd Alternativen aufzeigt, sobald ich auf käufliche Waren gehe (z.b. in Amazon.de oder ebay.de). Es bezeichnet sich selbst als "ShopGlider Deals", hat auch angeblich eine Möglichkeit zum Deaktivieren, die aber nicht funktioniert.



Bereits versucht: im Browser direkt habe ich es zwar "scheinbar" gelöscht, aber es ist immer noch da. Revo Uninstaller führt es nicht auf, daher konnte ich es da auch nicht löschen. Mit Agent Ransack habe ich versucht es manuell zu finden und zu löschen, hat aber leider auch nichts gebracht. Das Rücksetzen des Systems auf einen früheren Zeitpunkt brachte auch nichts. avast! konnte auch nichts finden. Daher habe ich auch keine weiteren logs.



Als Browser nutze ich SRWare Iron 39.0.2100.0



[...]Die folgenden Fehler traten bei der Verarbeitung auf:
Der Text, den Sie eingegeben haben, besteht aus 354686 Zeichen und ist damit zu lang. Bitte die Logs auf mehrere Beiträge aufspalten mit maximaler Länge von 120000 Zeichen.[...]




Die logs, die ich laut Anleitung machen sollte:

Code:
ATTFilter
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 12:59 on 05/04/2015 (mse13ssd)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-
         


FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by mse13ssd (administrator) on MSE13SSD-PC on 05-04-2015 13:02:19
Running from G:\Users\mse13ssd\Downloads
Loaded Profiles: mse13ssd (Available profiles: mse13ssd)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) G:\Windows\System32\atiesrxx.exe
(Logitech Inc.) G:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AMD) G:\Windows\System32\atieclxx.exe
(AVAST Software) G:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) G:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) G:\Program Files\Bonjour\mDNSResponder.exe
(Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
(Logitech Inc.) G:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) G:\Program Files\Windows Sidebar\sidebar.exe
(AVAST Software) G:\Program Files\AVAST Software\Avast\avastui.exe
() G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Advanced Micro Devices Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(Skype Technologies S.A.) G:\Program Files (x86)\Skype\Phone\Skype.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
() G:\Users\mse13ssd\Downloads\Defogger.exe
(Farbar) G:\Users\mse13ssd\Downloads\FRST64 (1).exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Launch LCore] => G:\Program Files\Logitech Gaming Software\LCore.exe [10801944 2014-07-28] (Logitech Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => G:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software)
HKLM-x32\...\Run: [DivXMediaServer] => G:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [StartCCC] => G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Raptr] => G:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-03-25] (Raptr, Inc)
HKU\S-1-5-21-3243151774-2580435505-251407729-1001\...\MountPoints2: {0a347fcb-dd9c-11e3-bf5d-806e6f6e6963} - F:\autorun.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => G:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-15] (AVAST Software)
BHO-x32: PDF Architect Helper -> {691B33B0-B86E-47F3-81C7-56E4FE3B929C} -> G:\Program Files (x86)\PDF Architect 2\creator-ie-helper.dll [2014-10-10] (pdfforge GmbH)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-26] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-15] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-26] (Oracle Corporation)
Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - G:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll [2014-10-10] (pdfforge GmbH)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0

FireFox:
========
FF ProfilePath: G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default
FF Plugin: @adobe.com/FlashPlayer -> G:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-15] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> G:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-15] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> G:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2012-04-05] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> G:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-26] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-26] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> G:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.)
FF Plugin-x32: Adobe Reader -> G:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Extension: Download videos and MP3s from YouTube - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-11-21]
FF Extension: Adblock Plus - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-09]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - G:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - G:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-17]
FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension
FF Extension: PDF Architect 2 Creator - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2014-12-09]
FF HKU\S-1-5-21-3243151774-2580435505-251407729-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF Extension: Download videos and MP3s from YouTube - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-11-21]

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Profile: G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-09]
CHR Extension: (Google Docs) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-09]
CHR Extension: (Google Drive) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-09]
CHR Extension: (Google Voice Search Hotword (Beta)) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-09]
CHR Extension: (YouTube) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-09]
CHR Extension: (Google Search) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-09]
CHR Extension: (Google Sheets) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-09]
CHR Extension: (Google Wallet) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-09]
CHR Extension: (Gmail) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-09]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - G:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-15]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; G:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-15] (AVAST Software)
S2 PDF Architect 2 Creator; G:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH)
S3 SandraAgentSrv; G:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3c\RpcAgentSrv.exe [73712 2014-09-19] (SiSoftware) [File not signed]
R2 WinDefend; G:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; G:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-15] ()
R2 aswMonFlt; G:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-15] (AVAST Software)
R1 aswRdr; G:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-15] (AVAST Software)
R0 aswRvrt; G:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-15] ()
R1 aswSnx; G:\Windows\system32\drivers\aswSnx.sys [1041168 2014-11-21] (AVAST Software)
R1 aswSP; G:\Windows\system32\drivers\aswSP.sys [427360 2014-07-15] (AVAST Software)
R2 aswStm; G:\Windows\system32\drivers\aswStm.sys [92008 2014-07-15] (AVAST Software)
R0 aswVmm; G:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-15] ()
R3 LGSHidFilt; G:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-05 13:02 - 2015-04-05 13:02 - 00012421 _____ () G:\Users\mse13ssd\Downloads\FRST.txt
2015-04-05 13:02 - 2015-04-05 13:02 - 00000000 ____D () G:\FRST
2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Downloads\FRST64.exe
2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Downloads\FRST64 (1).exe
2015-04-05 12:59 - 2015-04-05 12:59 - 00000478 _____ () G:\Users\mse13ssd\Downloads\defogger_disable.log
2015-04-05 12:59 - 2015-04-05 12:59 - 00000000 _____ () G:\Users\mse13ssd\defogger_reenable
2015-04-05 12:57 - 2015-04-05 12:57 - 00050477 _____ () G:\Users\mse13ssd\Downloads\Defogger.exe
2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (2).exe
2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (1).exe
2015-04-05 03:38 - 2015-04-05 03:47 - 00000000 ____D () G:\AdwCleaner
2015-04-05 03:37 - 2015-04-05 03:38 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200.exe
2015-03-31 05:26 - 2015-03-31 05:26 - 00008930 _____ () G:\Users\mse13ssd\Downloads\smime (1).p7s
2015-03-31 02:41 - 2015-03-31 02:41 - 00000069 _____ () G:\Users\mse13ssd\Desktop\BADLOGIC (German Fandub) - YouTube.url
2015-03-28 00:47 - 2015-03-28 00:47 - 00012288 _____ () G:\Users\mse13ssd\Downloads\Qual-Fraktal.xls
2015-03-27 07:14 - 2015-03-27 07:14 - 00000000 ____D () G:\Users\mse13ssd\Desktop\SciLor's Grooveshark.com Downloader
2015-03-26 21:20 - 2015-03-26 21:20 - 671367548 _____ () G:\Windows\MEMORY.DMP
2015-03-26 21:20 - 2015-03-26 21:20 - 00274624 _____ () G:\Windows\Minidump\032615-29718-01.dmp
2015-03-25 04:31 - 2015-03-25 04:31 - 00002123 _____ () G:\Users\Public\Desktop\CONTRACT J.A.C.K. .lnk
2015-03-25 04:05 - 2015-03-25 04:05 - 00000000 ____D () G:\Program Files (x86)\Sierra
2015-03-25 04:04 - 2015-03-25 04:04 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra
2015-03-25 04:00 - 2003-06-26 10:45 - 00499712 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcp71.dll
2015-03-25 04:00 - 2003-06-26 10:45 - 00348160 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcr71.dll
2015-03-25 04:00 - 2003-03-19 07:20 - 01060864 ____N (Microsoft Corporation) G:\Windows\SysWOW64\mfc71.dll
2015-03-22 18:27 - 2015-03-22 18:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files\Microsoft Silverlight
2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files (x86)\Microsoft Silverlight
2015-03-21 10:33 - 2015-03-21 10:33 - 13087456 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\Silverlight_x64.exe
2015-03-18 17:29 - 2015-03-18 17:29 - 00002023 _____ () G:\Users\mse13ssd\Desktop\Windows Phone-Desktopanwendung.lnk
2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Phone
2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\Program Files (x86)\Windows Phone
2015-03-18 17:25 - 2015-03-18 17:25 - 06745792 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\WindowsPhone.exe
2015-03-18 17:25 - 2015-03-18 17:25 - 00000000 ____D () G:\ProgramData\Applications
2015-03-16 19:19 - 2015-03-16 19:19 - 00001535 _____ () G:\Users\mse13ssd\Free YouTube to MP3 Converter.lnk
2015-03-15 17:32 - 2015-04-05 12:37 - 00001114 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-15 17:32 - 2015-04-05 03:49 - 00001110 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-15 17:32 - 2015-03-15 17:32 - 00004110 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-03-15 17:32 - 2015-03-15 17:32 - 00003858 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-03-15 17:32 - 2015-03-15 17:32 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2015-03-15 17:31 - 2015-03-15 17:31 - 00880208 _____ (Google Inc.) G:\Users\mse13ssd\Downloads\GoogleEarthSetup.exe
2015-03-14 07:06 - 2015-03-14 07:33 - 82044588 _____ () G:\Users\mse13ssd\Downloads\ES-X_DE.rar.crdownload
2015-03-12 09:28 - 2015-02-03 05:34 - 05554104 _____ (Microsoft Corporation) G:\Windows\system32\ntoskrnl.exe
2015-03-12 09:28 - 2015-02-03 05:34 - 00693176 _____ (Microsoft Corporation) G:\Windows\system32\winload.efi
2015-03-12 09:28 - 2015-02-03 05:34 - 00094656 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\mountmgr.sys
2015-03-12 09:28 - 2015-02-03 05:33 - 00616360 _____ (Microsoft Corporation) G:\Windows\system32\winresume.efi
2015-03-12 09:28 - 2015-02-03 05:31 - 14632960 _____ (Microsoft Corporation) G:\Windows\system32\wmp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 04121600 _____ (Microsoft Corporation) G:\Windows\system32\mf.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 01574400 _____ (Microsoft Corporation) G:\Windows\system32\quartz.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00782848 _____ (Microsoft Corporation) G:\Windows\system32\wmdrmsdk.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00641024 _____ (Microsoft Corporation) G:\Windows\system32\msscp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00503808 _____ (Microsoft Corporation) G:\Windows\system32\srcore.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00500224 _____ (Microsoft Corporation) G:\Windows\system32\AUDIOKSE.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00432128 _____ (Microsoft Corporation) G:\Windows\system32\mfplat.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00371712 _____ (Microsoft Corporation) G:\Windows\system32\qdvd.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00325632 _____ (Microsoft Corporation) G:\Windows\system32\msnetobj.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00229376 _____ (Microsoft Corporation) G:\Windows\system32\wintrust.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00206848 _____ (Microsoft Corporation) G:\Windows\system32\mfps.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00188416 _____ (Microsoft Corporation) G:\Windows\system32\pcasvc.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00063488 _____ (Microsoft Corporation) G:\Windows\system32\setbcdlocale.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00050176 _____ (Microsoft Corporation) G:\Windows\system32\srclient.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00037376 _____ (Microsoft Corporation) G:\Windows\system32\pcadm.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\msmmsp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\spwmp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\msdxm.ocx
2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\dxmasf.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 12625920 _____ (Microsoft Corporation) G:\Windows\system32\wmploc.DLL
2015-03-12 09:28 - 2015-02-03 05:30 - 01480192 _____ (Microsoft Corporation) G:\Windows\system32\crypt32.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 01202176 _____ (Microsoft Corporation) G:\Windows\system32\drmv2clt.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 01069056 _____ (Microsoft Corporation) G:\Windows\system32\cryptui.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00842240 _____ (Microsoft Corporation) G:\Windows\system32\blackbox.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00680960 _____ (Microsoft Corporation) G:\Windows\system32\audiosrv.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00631808 _____ (Microsoft Corporation) G:\Windows\system32\evr.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00497664 _____ (Microsoft Corporation) G:\Windows\system32\drmmgrtn.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00440832 _____ (Microsoft Corporation) G:\Windows\system32\AudioEng.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00296960 _____ (Microsoft Corporation) G:\Windows\system32\rstrui.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00296448 _____ (Microsoft Corporation) G:\Windows\system32\AudioSes.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00284672 _____ (Microsoft Corporation) G:\Windows\system32\EncDump.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00187904 _____ (Microsoft Corporation) G:\Windows\system32\cryptsvc.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00146944 _____ (Microsoft Corporation) G:\Windows\system32\appidpolicyconverter.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00140288 _____ (Microsoft Corporation) G:\Windows\system32\cryptnet.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00126464 _____ (Microsoft Corporation) G:\Windows\system32\audiodg.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00112640 _____ (Microsoft Corporation) G:\Windows\system32\smss.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00082432 _____ (Microsoft Corporation) G:\Windows\system32\cryptsp.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00058880 _____ (Microsoft Corporation) G:\Windows\system32\appidapi.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00055808 _____ (Microsoft Corporation) G:\Windows\system32\rrinstaller.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00043520 _____ (Microsoft Corporation) G:\Windows\system32\csrsrv.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00032256 _____ (Microsoft Corporation) G:\Windows\system32\appidsvc.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00024576 _____ (Microsoft Corporation) G:\Windows\system32\mfpmp.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00017920 _____ (Microsoft Corporation) G:\Windows\system32\appidcertstorecheck.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\pcawrk.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\pcalua.exe
2015-03-12 09:28 - 2015-02-03 05:29 - 00008704 _____ (Microsoft Corporation) G:\Windows\system32\pcaevts.dll
2015-03-12 09:28 - 2015-02-03 05:28 - 00006656 _____ (Microsoft Corporation) G:\Windows\system32\apisetschema.dll
2015-03-12 09:28 - 2015-02-03 05:28 - 00002048 _____ (Microsoft Corporation) G:\Windows\system32\mferror.dll
2015-03-12 09:28 - 2015-02-03 05:19 - 00663552 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\PEAuth.sys
2015-03-12 09:28 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntkrnlpa.exe
2015-03-12 09:28 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntoskrnl.exe
2015-03-12 09:28 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mf.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) G:\Windows\SysWOW64\quartz.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) G:\Windows\SysWOW64\crypt32.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptui.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmv2clt.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\blackbox.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmdrmsdk.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) G:\Windows\SysWOW64\qdvd.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msscp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\evr.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AUDIOKSE.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmmgrtn.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioEng.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfplat.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msnetobj.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioSes.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wintrust.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsvc.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptnet.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfps.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) G:\Windows\SysWOW64\appidapi.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) G:\Windows\SysWOW64\srclient.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\spwmp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msdxm.ocx
2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxmasf.dll
2015-03-12 09:28 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmploc.DLL
2015-03-12 09:28 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\rrinstaller.exe
2015-03-12 09:28 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfpmp.exe
2015-03-12 09:28 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mferror.dll
2015-03-12 09:28 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\apisetschema.dll
2015-03-12 09:28 - 2015-02-03 04:32 - 00061440 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\appid.sys
2015-03-12 09:28 - 2014-11-01 00:24 - 00619056 _____ (Microsoft Corporation) G:\Windows\system32\winload.exe
2015-03-12 09:28 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) G:\Windows\system32\winresume.exe
2015-03-12 09:28 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) G:\Windows\system32\ci.dll
2015-03-12 09:27 - 2015-03-06 07:56 - 00155576 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecpkg.sys
2015-03-12 09:27 - 2015-03-06 07:56 - 00095680 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecdd.sys
2015-03-12 09:27 - 2015-03-06 07:42 - 01461760 _____ (Microsoft Corporation) G:\Windows\system32\lsasrv.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00728064 _____ (Microsoft Corporation) G:\Windows\system32\kerberos.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00341504 _____ (Microsoft Corporation) G:\Windows\system32\schannel.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00314880 _____ (Microsoft Corporation) G:\Windows\system32\msv1_0.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00309760 _____ (Microsoft Corporation) G:\Windows\system32\ncrypt.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00210944 _____ (Microsoft Corporation) G:\Windows\system32\wdigest.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00136192 _____ (Microsoft Corporation) G:\Windows\system32\sspicli.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00086528 _____ (Microsoft Corporation) G:\Windows\system32\TSpkg.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00029184 _____ (Microsoft Corporation) G:\Windows\system32\sspisrv.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00028160 _____ (Microsoft Corporation) G:\Windows\system32\secur32.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00022016 _____ (Microsoft Corporation) G:\Windows\system32\credssp.dll
2015-03-12 09:27 - 2015-03-06 07:41 - 00064000 _____ (Microsoft Corporation) G:\Windows\system32\auditpol.exe
2015-03-12 09:27 - 2015-03-06 07:41 - 00031232 _____ (Microsoft Corporation) G:\Windows\system32\lsass.exe
2015-03-12 09:27 - 2015-03-06 07:39 - 00060416 _____ (Microsoft Corporation) G:\Windows\system32\msobjs.dll
2015-03-12 09:27 - 2015-03-06 07:38 - 00146432 _____ (Microsoft Corporation) G:\Windows\system32\msaudite.dll
2015-03-12 09:27 - 2015-03-06 07:36 - 00686080 _____ (Microsoft Corporation) G:\Windows\system32\adtschema.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) G:\Windows\SysWOW64\kerberos.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msv1_0.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) G:\Windows\SysWOW64\schannel.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ncrypt.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wdigest.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) G:\Windows\SysWOW64\TSpkg.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\secur32.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\credssp.dll
2015-03-12 09:27 - 2015-03-06 07:09 - 00096768 _____ (Microsoft Corporation) G:\Windows\SysWOW64\sspicli.dll
2015-03-12 09:27 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\auditpol.exe
2015-03-12 09:27 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msaudite.dll
2015-03-12 09:27 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msobjs.dll
2015-03-12 09:27 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) G:\Windows\SysWOW64\adtschema.dll
2015-03-12 09:27 - 2015-02-24 05:15 - 00389800 _____ (Microsoft Corporation) G:\Windows\system32\iedkcs32.dll
2015-03-12 09:27 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iedkcs32.dll
2015-03-12 09:27 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.dll
2015-03-12 09:27 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieframe.dll
2015-03-12 09:27 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtmsft.dll
2015-03-12 09:27 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtrans.dll
2015-03-12 09:27 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.dll
2015-03-12 09:27 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) G:\Windows\system32\mshtmled.dll
2015-03-12 09:27 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmled.dll
2015-03-12 09:27 - 2015-02-20 06:41 - 00041984 _____ (Microsoft Corporation) G:\Windows\system32\lpk.dll
2015-03-12 09:27 - 2015-02-20 06:40 - 00100864 _____ (Microsoft Corporation) G:\Windows\system32\fontsub.dll
2015-03-12 09:27 - 2015-02-20 06:40 - 00046080 _____ (Adobe Systems) G:\Windows\system32\atmlib.dll
2015-03-12 09:27 - 2015-02-20 06:40 - 00014336 _____ (Microsoft Corporation) G:\Windows\system32\dciman32.dll
2015-03-12 09:27 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\fontsub.dll
2015-03-12 09:27 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) G:\Windows\SysWOW64\atmlib.dll
2015-03-12 09:27 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dciman32.dll
2015-03-12 09:27 - 2015-02-20 06:12 - 00025600 _____ (Microsoft Corporation) G:\Windows\SysWOW64\lpk.dll
2015-03-12 09:27 - 2015-02-20 05:29 - 00372224 _____ (Adobe Systems Incorporated) G:\Windows\system32\atmfd.dll
2015-03-12 09:27 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\atmfd.dll
2015-03-12 09:27 - 2015-02-20 05:06 - 02724864 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.tlb
2015-03-12 09:27 - 2015-02-20 05:05 - 00004096 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollectorres.dll
2015-03-12 09:27 - 2015-02-20 04:50 - 00066560 _____ (Microsoft Corporation) G:\Windows\system32\iesetup.dll
2015-03-12 09:27 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) G:\Windows\system32\vbscript.dll
2015-03-12 09:27 - 2015-02-20 04:49 - 00048640 _____ (Microsoft Corporation) G:\Windows\system32\ieetwproxystub.dll
2015-03-12 09:27 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) G:\Windows\system32\iertutil.dll
2015-03-12 09:27 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) G:\Windows\system32\MshtmlDac.dll
2015-03-12 09:27 - 2015-02-20 04:41 - 00054784 _____ (Microsoft Corporation) G:\Windows\system32\jsproxy.dll
2015-03-12 09:27 - 2015-02-20 04:40 - 00034304 _____ (Microsoft Corporation) G:\Windows\system32\iernonce.dll
2015-03-12 09:27 - 2015-02-20 04:36 - 00633856 _____ (Microsoft Corporation) G:\Windows\system32\ieui.dll
2015-03-12 09:27 - 2015-02-20 04:35 - 00144384 _____ (Microsoft Corporation) G:\Windows\system32\ieUnatt.exe
2015-03-12 09:27 - 2015-02-20 04:35 - 00114688 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollector.exe
2015-03-12 09:27 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) G:\Windows\system32\jscript9diag.dll
2015-03-12 09:27 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) G:\Windows\system32\jscript9.dll
2015-03-12 09:27 - 2015-02-20 04:26 - 00968704 _____ (Microsoft Corporation) G:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-12 09:27 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.tlb
2015-03-12 09:27 - 2015-02-20 04:22 - 00490496 _____ (Microsoft Corporation) G:\Windows\system32\dxtmsft.dll
2015-03-12 09:27 - 2015-02-20 04:13 - 00077824 _____ (Microsoft Corporation) G:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-12 09:27 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) G:\Windows\SysWOW64\vbscript.dll
2015-03-12 09:27 - 2015-02-20 04:08 - 00199680 _____ (Microsoft Corporation) G:\Windows\system32\msrating.dll
2015-03-12 09:27 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iesetup.dll
2015-03-12 09:27 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieetwproxystub.dll
2015-03-12 09:27 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) G:\Windows\SysWOW64\MshtmlDac.dll
2015-03-12 09:27 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) G:\Windows\system32\dxtrans.dll
2015-03-12 09:27 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iertutil.dll
2015-03-12 09:27 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jsproxy.dll
2015-03-12 09:27 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iernonce.dll
2015-03-12 09:27 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieui.dll
2015-03-12 09:27 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9diag.dll
2015-03-12 09:27 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieUnatt.exe
2015-03-12 09:27 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) G:\Windows\system32\msfeeds.dll
2015-03-12 09:27 - 2015-02-20 03:49 - 00718848 _____ (Microsoft Corporation) G:\Windows\system32\ie4uinit.exe
2015-03-12 09:27 - 2015-02-20 03:47 - 01359360 _____ (Microsoft Corporation) G:\Windows\system32\mshtmlmedia.dll
2015-03-12 09:27 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) G:\Windows\system32\inetcpl.cpl
2015-03-12 09:27 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) G:\Windows\system32\ieframe.dll
2015-03-12 09:27 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-03-12 09:27 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msrating.dll
2015-03-12 09:27 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9.dll
2015-03-12 09:27 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) G:\Windows\system32\wininet.dll
2015-03-12 09:27 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) G:\Windows\SysWOW64\inetcpl.cpl
2015-03-12 09:27 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msfeeds.dll
2015-03-12 09:27 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmlmedia.dll
2015-03-12 09:27 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) G:\Windows\system32\urlmon.dll
2015-03-12 09:27 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) G:\Windows\system32\ieapfltr.dll
2015-03-12 09:27 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wininet.dll
2015-03-12 09:27 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) G:\Windows\SysWOW64\urlmon.dll
2015-03-12 09:27 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieapfltr.dll
2015-03-12 09:27 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) G:\Windows\SysWOW64\shell32.dll
2015-03-12 09:27 - 2015-02-13 07:22 - 14177280 _____ (Microsoft Corporation) G:\Windows\system32\shell32.dll
2015-03-12 09:27 - 2015-02-03 05:31 - 01424896 _____ (Microsoft Corporation) G:\Windows\system32\WindowsCodecs.dll
2015-03-12 09:27 - 2015-02-03 05:31 - 00215552 _____ (Microsoft Corporation) G:\Windows\system32\ubpm.dll
2015-03-12 09:27 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WindowsCodecs.dll
2015-03-12 09:27 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ubpm.dll
2015-03-12 09:27 - 2015-01-31 05:48 - 03179520 _____ (Microsoft Corporation) G:\Windows\system32\rdpcorets.dll
2015-03-12 09:27 - 2015-01-31 05:48 - 00016384 _____ (Microsoft Corporation) G:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-12 09:27 - 2015-01-31 01:56 - 00459336 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\cng.sys
2015-03-12 09:27 - 2015-01-31 01:56 - 00243200 _____ (Microsoft Corporation) G:\Windows\system32\rdpudd.dll
2015-03-12 09:27 - 2015-01-17 04:48 - 01067520 _____ (Microsoft Corporation) G:\Windows\system32\msctf.dll
2015-03-12 09:27 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msctf.dll
2015-03-12 09:26 - 2015-02-26 05:25 - 03204096 _____ (Microsoft Corporation) G:\Windows\system32\win32k.sys
2015-03-12 09:26 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) G:\Windows\system32\WMPhoto.dll
2015-03-12 09:26 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WMPhoto.dll
2015-03-10 01:20 - 2015-03-10 01:20 - 00001002 _____ () G:\Users\mse13ssd\Downloads\BAHN_Fahrplan_20150609.ics
2015-03-09 11:16 - 2015-03-09 11:56 - 124202474 _____ () G:\Users\mse13ssd\Downloads\#0325#.rar
2015-03-08 09:43 - 2015-03-08 09:43 - 01230365 _____ () G:\Users\mse13ssd\Downloads\2 (1).wmv
2015-03-08 09:43 - 2015-03-08 09:43 - 01222357 _____ () G:\Users\mse13ssd\Downloads\3.wmv
2015-03-06 16:14 - 2015-03-06 16:51 - 111138743 _____ () G:\Users\mse13ssd\Downloads\julins2014.rar

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-05 12:59 - 2014-05-17 11:54 - 00000000 ____D () G:\Users\mse13ssd
2015-04-05 12:46 - 2014-05-17 22:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Skype
2015-04-05 07:05 - 2014-05-17 10:22 - 01367011 _____ () G:\Windows\WindowsUpdate.log
2015-04-05 03:57 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-05 03:57 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-05 03:54 - 2009-07-14 19:58 - 00700986 _____ () G:\Windows\system32\perfh007.dat
2015-04-05 03:54 - 2009-07-14 19:58 - 00149886 _____ () G:\Windows\system32\perfc007.dat
2015-04-05 03:54 - 2009-07-14 07:13 - 01619284 _____ () G:\Windows\system32\PerfStringBackup.INI
2015-04-05 03:50 - 2014-07-13 00:21 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Raptr
2015-04-05 03:49 - 2014-05-17 22:03 - 00000000 _____ () G:\Windows\system32\Drivers\lvuvc.hs
2015-04-05 03:49 - 2014-05-17 15:20 - 00032476 _____ () G:\Windows\PFRO.log
2015-04-05 03:49 - 2009-07-14 07:08 - 00000006 ____H () G:\Windows\Tasks\SA.DAT
2015-04-05 03:49 - 2009-07-14 06:51 - 00055467 _____ () G:\Windows\setupact.log
2015-04-05 03:33 - 2015-03-05 14:19 - 00129752 _____ (Malwarebytes Corporation) G:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-05 03:26 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\Web
2015-04-05 02:39 - 2014-05-17 15:57 - 00004182 _____ () G:\Windows\System32\Tasks\avast! Emergency Update
2015-04-04 14:30 - 2014-05-17 20:13 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\TS3Client
2015-04-02 01:34 - 2009-07-14 07:32 - 00000000 ____D () G:\Windows\system32\FxsTmp
2015-03-30 21:24 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\NDF
2015-03-30 17:36 - 2015-02-28 05:38 - 00000000 ____D () G:\Users\mse13ssd\Desktop\aufgeräumt
2015-03-30 08:10 - 2014-11-01 08:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\25372
2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\DivX
2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
2015-03-30 04:33 - 2014-08-24 02:00 - 00000000 ____D () G:\ProgramData\DivX
2015-03-30 04:33 - 2014-05-17 15:57 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2015-03-30 04:33 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\AppCompat
2015-03-30 04:32 - 2014-08-24 02:01 - 00000000 ____D () G:\Program Files\DivX
2015-03-30 04:32 - 2014-08-24 02:00 - 00000000 ____D () G:\Program Files (x86)\DivX
2015-03-30 04:32 - 2014-06-18 17:31 - 00000000 ____D () G:\Program Files (x86)\Microsoft Office
2015-03-30 04:32 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\registration
2015-03-30 03:27 - 2009-07-14 20:18 - 00000000 ___RD () G:\Users\Public\Recorded TV
2015-03-26 21:20 - 2014-10-12 12:01 - 00000000 ____D () G:\Windows\Minidump
2015-03-26 18:51 - 2014-07-13 00:21 - 00000000 ____D () G:\Program Files (x86)\Raptr
2015-03-26 09:13 - 2014-06-18 17:31 - 00000000 ____D () G:\ProgramData\Microsoft Help
2015-03-22 18:29 - 2014-05-17 12:40 - 00070368 _____ () G:\Users\mse13ssd\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-22 18:29 - 2009-07-14 06:45 - 00307752 _____ () G:\Windows\system32\FNTCACHE.DAT
2015-03-22 18:25 - 2014-06-18 17:32 - 00000000 ____D () G:\Program Files (x86)\Microsoft Works
2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Google
2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Program Files (x86)\Google
2015-03-15 14:09 - 2014-08-24 13:49 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Adobe
2015-03-15 14:09 - 2014-05-17 15:53 - 00778928 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerApp.exe
2015-03-15 14:09 - 2014-05-17 15:53 - 00142512 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-03-15 05:05 - 2014-06-21 18:28 - 00000000 ____D () G:\Program Files (x86)\Steam
2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Glyph
2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glyph
2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Program Files (x86)\Glyph
2015-03-13 10:32 - 2009-07-14 07:09 - 00000000 ____D () G:\Windows\System32\Tasks\WPD
2015-03-12 12:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\rescache
2015-03-12 09:37 - 2015-02-28 09:01 - 00000000 ___RD () G:\Users\mse13ssd\Virtual Machines
2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\SysWOW64\Dism
2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\Dism
2015-03-12 09:31 - 2014-05-17 20:36 - 00000000 ____D () G:\Windows\system32\MRT
2015-03-12 09:29 - 2014-05-17 20:36 - 122905848 _____ (Microsoft Corporation) G:\Windows\system32\MRT.exe
2015-03-06 13:47 - 2014-10-13 17:23 - 00000000 ___RD () G:\Program Files (x86)\Skype
2015-03-06 13:47 - 2014-05-17 22:15 - 00000000 ____D () G:\ProgramData\Skype

==================== Files in the root of some directories =======

2014-10-02 16:29 - 2015-02-28 12:40 - 14286848 _____ () G:\Users\mse13ssd\AppData\Roaming\Sandra.mdb
2015-01-23 13:40 - 2015-01-23 13:40 - 0003584 _____ () G:\Users\mse13ssd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-01 14:58 - 2015-01-01 14:58 - 0007605 _____ () G:\Users\mse13ssd\AppData\Local\Resmon.ResmonCfg

Some content of TEMP:
====================
G:\Users\mse13ssd\AppData\Local\Temp\CmdLineExt03.dll
G:\Users\mse13ssd\AppData\Local\Temp\cres.dll
G:\Users\mse13ssd\AppData\Local\Temp\cshell.dll
G:\Users\mse13ssd\AppData\Local\Temp\DivXSetup.exe
G:\Users\mse13ssd\AppData\Local\Temp\DJAPI.dll
G:\Users\mse13ssd\AppData\Local\Temp\drm_dialogs.dll
G:\Users\mse13ssd\AppData\Local\Temp\drm_dyndata_7270006.dll
G:\Users\mse13ssd\AppData\Local\Temp\drm_dyndata_7340007.dll
G:\Users\mse13ssd\AppData\Local\Temp\FreeYouTubeDownload.exe
G:\Users\mse13ssd\AppData\Local\Temp\jre-8u31-windows-au.exe
G:\Users\mse13ssd\AppData\Local\Temp\MSETUP4.EXE
G:\Users\mse13ssd\AppData\Local\Temp\ose00000.exe
G:\Users\mse13ssd\AppData\Local\Temp\PamelaSetup_54845e3c.exe
G:\Users\mse13ssd\AppData\Local\Temp\PamFaxSetup.exe
G:\Users\mse13ssd\AppData\Local\Temp\Quarantine.exe
G:\Users\mse13ssd\AppData\Local\Temp\raptrpatch.exe
G:\Users\mse13ssd\AppData\Local\Temp\raptr_stub.exe
G:\Users\mse13ssd\AppData\Local\Temp\SIntf16.dll
G:\Users\mse13ssd\AppData\Local\Temp\SIntf32.dll
G:\Users\mse13ssd\AppData\Local\Temp\SIntfNT.dll
G:\Users\mse13ssd\AppData\Local\Temp\SkypeSetup.exe
G:\Users\mse13ssd\AppData\Local\Temp\sqlite3.dll
G:\Users\mse13ssd\AppData\Local\Temp\sres.dll
G:\Users\mse13ssd\AppData\Local\Temp\tmd_34011292.exe
G:\Users\mse13ssd\AppData\Local\Temp\tmd_34012212.exe
G:\Users\mse13ssd\AppData\Local\Temp\tmd_34012979.exe
G:\Users\mse13ssd\AppData\Local\Temp\tmd_34013116.exe
G:\Users\mse13ssd\AppData\Local\Temp\tmd_34013851.exe
G:\Users\mse13ssd\AppData\Local\Temp\tmd_34017196.exe
G:\Users\mse13ssd\AppData\Local\Temp\tmd_34018551.exe
G:\Users\mse13ssd\AppData\Local\Temp\tmp34C5.exe
G:\Users\mse13ssd\AppData\Local\Temp\tmp8B1F.exe
G:\Users\mse13ssd\AppData\Local\Temp\_is962D.exe
G:\Users\mse13ssd\AppData\Local\Temp\_isD8E7.exe
G:\Users\mse13ssd\AppData\Local\Temp\_isFC9.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

G:\Windows\System32\winlogon.exe => File is digitally signed
G:\Windows\System32\wininit.exe => File is digitally signed
G:\Windows\SysWOW64\wininit.exe => File is digitally signed
G:\Windows\explorer.exe => File is digitally signed
G:\Windows\SysWOW64\explorer.exe => File is digitally signed
G:\Windows\System32\svchost.exe => File is digitally signed
G:\Windows\SysWOW64\svchost.exe => File is digitally signed
G:\Windows\System32\services.exe => File is digitally signed
G:\Windows\System32\User32.dll => File is digitally signed
G:\Windows\SysWOW64\User32.dll => File is digitally signed
G:\Windows\System32\userinit.exe => File is digitally signed
G:\Windows\SysWOW64\userinit.exe => File is digitally signed
G:\Windows\System32\rpcss.dll => File is digitally signed
G:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-04 00:45

==================== End Of Log ============================
         
--- --- ---

--- --- ---


--- --- ---

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
Ran by mse13ssd at 2015-04-05 13:02:54
Running from G:\Users\mse13ssd\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
AGEIA PhysX v7.11.13 (HKLM-x32\...\{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}) (Version: 7.11.13 - AGEIA Technologies, Inc.)
Agent Ransack x64 (HKLM\...\{58C0AC50-8FA1-4A95-AEC6-5B2727E5CC6A}) (Version: 7.0.820.1 - Mythicsoft Ltd)
AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Apple Application Support (HKLM-x32\...\{122ADF8C-DDA1-480C-9936-C88F2825B265}) (Version: 2.1.9 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}) (Version: 5.2.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Archeage (HKLM-x32\...\Glyph Archeage) (Version:  - Trion Worlds, Inc.)
ArtMoney SE v7.43 (HKLM-x32\...\ArtMoney SE_is1) (Version: 7.43 - System SoftLab)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software)
Avery Wizard 5.0 (HKLM-x32\...\{FC3B3A5D-7058-4627-9F1E-F95CC38B6054}) (Version: 5.0.5 - Avery)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version:  - Gearbox Software)
Canon iP7200 series Benutzerregistrierung (HKLM-x32\...\Canon iP7200 series Benutzerregistrierung) (Version:  - Canon Inc.‎)
Canon iP7200 series Printer Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP7200_series) (Version:  - Canon Inc.)
Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version:  - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.0.0 - Canon Inc.)
CanoScan LiDE 110 Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2414) (Version:  - Canon Inc.)
ClipboardManager 1.6 (HKLM-x32\...\ClipboardManager_is1) (Version:  - )
Contract Jack (HKLM-x32\...\{374CAB30-2F61-4439-9A4A-24D3AEA2960A}) (Version:  - )
CPUID CPU-Z 1.70 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Die Siedler II - Die nächste Generation (HKLM-x32\...\S2TNG) (Version:  - )
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.7.0.31 - DivX, LLC)
Free YouTube Download version 3.2.53.128 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.53.128 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.12.50.1111 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.50.1111 - DVDVideoSoft Ltd.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
GUILD WARS (HKLM-x32\...\Guild Wars) (Version:  - )
iTunes (HKLM\...\{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}) (Version: 10.6.3.25 - Apple Inc.)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Logitech Gaming Software 8.55 (HKLM\...\Logitech Gaming Software) (Version: 8.55.137 - Logitech Inc.)
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Mozilla Firefox 36.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 36.0 (x86 de)) (Version: 36.0 - Mozilla)
paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC)
Pamela Pro 4.9 (HKLM-x32\...\Pamela) (Version: 4.9 - PamConsult GmbH)
PDF Architect 2 Create Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.0 - pdfforge)
Raptr (HKLM-x32\...\Raptr) (Version:  - )
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SciLor's grooveshark™.com Downloader 0.4.15 (HKLM-x32\...\{DDEAE484-D5FB-49CB-BD47-9512E8ACCA65}_is1) (Version: 0.4.15 - SciLor)
SiSoftware Sandra Lite 2014.SP3c (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2496}_is1) (Version: 20.47.2014.10 - SiSoftware)
Skype™ 7.1 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
SRWare Iron Version SRWare Iron 39.2100.0 (HKLM-x32\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: SRWare Iron 39.2100.0 - SRWare)
Steam (HKLM-x32\...\Steam) (Version:  - Valve Corporation)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Windows Phone app for desktop (HKLM-x32\...\{19773614-FC22-4ACC-AAA3-E6BDA81ACF92}) (Version: 1.1.2726.0 - Microsoft Corporation)
WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

29-03-2015 08:56:50 Revo Uninstaller's restore point - Archeage
30-03-2015 03:26:17 Wiederherstellungsvorgang
30-03-2015 04:29:37 avast! antivirus system restore point
30-03-2015 04:32:01 Wiederherstellungsvorgang
30-03-2015 18:28:06 Windows Update
01-04-2015 19:32:07 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A G:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {1FC3D3B2-F254-4B57-9695-FFF62B3AC150} - System32\Tasks\GoogleUpdateTaskMachineCore => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15] (Google Inc.)
Task: {34D4B971-AD1B-4F8D-8ED4-6F6BF7ABE60D} - System32\Tasks\avast! Emergency Update => G:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-07-15] (AVAST Software)
Task: {BD6EFB7D-29B9-4725-B4CB-C2F47B685F42} - System32\Tasks\Abelssoft\Updater scan => G:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe
Task: {DB431844-F8D5-409D-A115-BB442A487B85} - System32\Tasks\GoogleUpdateTaskMachineUA => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15] (Google Inc.)
Task: {E57F8AB1-453C-45BC-BF7F-E700E5C6EBA9} - System32\Tasks\Adobe Acrobat Update Task => G:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2014-07-28 20:29 - 2014-07-28 20:29 - 00866584 _____ () G:\Program Files\Logitech Gaming Software\libGLESv2.dll
2014-07-28 20:32 - 2014-07-28 20:32 - 01050904 _____ () G:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2014-07-28 20:29 - 2014-07-28 20:29 - 00059160 _____ () G:\Program Files\Logitech Gaming Software\libEGL.dll
2014-07-28 20:31 - 2014-07-28 20:31 - 00242456 _____ () G:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2014-01-10 07:26 - 2014-01-10 07:26 - 01861968 _____ () G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2015-04-05 12:57 - 2015-04-05 12:57 - 00050477 _____ () G:\Users\mse13ssd\Downloads\Defogger.exe
2014-07-15 08:28 - 2014-07-15 08:28 - 00301152 _____ () G:\Program Files\AVAST Software\Avast\aswProperty.dll
2015-04-05 02:39 - 2015-04-05 02:39 - 02923520 _____ () G:\Program Files\AVAST Software\Avast\defs\15040401\algo.dll
2015-04-05 11:50 - 2015-04-05 11:50 - 02923520 _____ () G:\Program Files\AVAST Software\Avast\defs\15040500\algo.dll
2012-05-30 20:06 - 2012-05-30 20:06 - 00087912 _____ () G:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2012-05-30 20:06 - 2012-05-30 20:06 - 01242512 _____ () G:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-07-15 08:28 - 2014-07-15 08:28 - 19329904 _____ () G:\Program Files\AVAST Software\Avast\libcef.dll
2014-01-10 07:28 - 2014-01-10 07:28 - 00100688 _____ () G:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
2014-05-17 12:27 - 2014-12-05 20:30 - 01359360 _____ () G:\Program Files (x86)\SRWare Iron\libglesv2.dll
2014-05-17 12:27 - 2014-12-05 20:31 - 00212992 _____ () G:\Program Files (x86)\SRWare Iron\libegl.dll
2015-01-08 21:01 - 2014-12-05 20:53 - 09299968 _____ () G:\Program Files (x86)\SRWare Iron\pdf.dll
2014-05-17 12:27 - 2014-12-05 20:32 - 00984576 _____ () G:\Program Files (x86)\SRWare Iron\ffmpegsumo.dll
2015-03-15 14:09 - 2015-03-15 14:09 - 16858288 _____ () G:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: G:\Users\mse13ssd\Downloads\email_5937_20150205205259.eml:OECustomProperty

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Control Panel\Desktop\\Wallpaper -> G:\Users\mse13ssd\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: bthserv => 3
MSCONFIG\Services: DPS => 2
MSCONFIG\Services: SensrSvc => 3
MSCONFIG\startupreg: Adobe ARM => "G:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "G:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: iTunesHelper => "G:\Program Files (x86)\iTunes\iTunesHelper.exe"

==================== Accounts: =============================

Administrator (S-1-5-21-3243151774-2580435505-251407729-500 - Administrator - Disabled)
Gast (S-1-5-21-3243151774-2580435505-251407729-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3243151774-2580435505-251407729-1002 - Limited - Enabled)
mse13ssd (S-1-5-21-3243151774-2580435505-251407729-1001 - Administrator - Enabled) => G:\Users\mse13ssd

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (04/05/2015 03:49:52 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x530
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3

Error: (04/05/2015 03:26:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x790
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3

Error: (04/05/2015 02:39:20 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x510
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3

Error: (04/03/2015 09:22:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x1bec
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3

Error: (04/02/2015 01:44:27 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x1a9c
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3

Error: (04/01/2015 07:55:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x7e8
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3

Error: (04/01/2015 06:57:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x818
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3

Error: (04/01/2015 06:29:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0xf84
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3

Error: (04/01/2015 07:02:36 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x5dc
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3

Error: (04/01/2015 04:31:52 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x430
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3


System errors:
=============
Error: (04/05/2015 03:49:58 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/05/2015 03:49:31 AM) (Source: Ntfs) (EventID: 137) (User: )
Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (04/05/2015 03:47:42 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/05/2015 03:47:41 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Media Player-Netzwerkfreigabedienst" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/05/2015 03:47:41 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/05/2015 03:47:41 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Dienst "Bonjour"" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/05/2015 03:47:41 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Apple Mobile Device" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/05/2015 03:47:41 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Adobe Acrobat Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/05/2015 03:47:41 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (04/05/2015 03:47:41 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "UMVPFSrv" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.


Microsoft Office Sessions:
=========================

==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz
Percentage of memory in use: 24%
Total physical RAM: 16384 MB
Available physical RAM: 12434.16 MB
Total Pagefile: 32766.19 MB
Available Pagefile: 28666.01 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.5 GB) (Free:736.3 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:0.01 GB) (Free:0 GB) NTFS
Drive f: (Nolf2xp_1) (CDROM) (Total:0.64 GB) (Free:0 GB) CDFS
Drive g: (SSD) (Fixed) (Total:119.24 GB) (Free:13.21 GB) NTFS
Drive m: (SAMSUNG) (Fixed) (Total:1396.92 GB) (Free:815.44 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: 7E008421)
Partition 1: (Active) - (Size=119.2 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 1CA61CA5)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=7 MB) - (Type=07 NTFS)

========================================================
Disk: 6 (Size: 1397.3 GB) (Disk ID: 5C9C6FA9)
Partition 1: (Not Active) - (Size=1397.3 GB) - (Type=0C)

==================== End Of Log ============================
         

Alt 05.04.2015, 13:57   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen - Standard

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen



hi,

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________

__________________

Alt 05.04.2015, 13:57   #3
MSE XIII
 
Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen - Standard

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen



Wow, das ging ja schnell. Brauche ich das logfile von GMER jetzt nicht mehr zu posten? Das muss ich nämlich auf drei Beiträge splitten.

Ich mach mich erstmal an Combofix.

Danke für das superschnelle Reagieren.



Fehlermeldung kam keine, allerdings konnte ich ComboFix nicht auf den Desktop speichern.

Code:
ATTFilter
 Dateien erstellt von 2015-03-05 bis 2015-04-05  ))))))))))))))))))))))))))))))
.
.
2015-04-05 13:09 . 2015-04-05 13:09	--------	d-----w-	g:\users\Default\AppData\Local\temp
2015-04-05 11:02 . 2015-04-05 11:03	--------	d-----w-	G:\FRST
2015-04-05 01:38 . 2015-04-05 01:47	--------	d-----w-	G:\AdwCleaner
2015-04-01 17:58 . 2015-03-23 00:32	12002392	----a-w-	g:\programdata\Microsoft\Windows Defender\Definition Updates\{0B4005F3-08BC-4508-9E4D-9F90FAABE072}\mpengine.dll
2015-03-25 02:05 . 2015-03-25 02:05	--------	d-----w-	g:\program files (x86)\Sierra
2015-03-25 02:00 . 2003-06-26 08:45	499712	------w-	g:\windows\SysWow64\msvcp71.dll
2015-03-25 02:00 . 2003-06-26 08:45	348160	------w-	g:\windows\SysWow64\msvcr71.dll
2015-03-25 02:00 . 2003-03-19 05:20	1060864	------w-	g:\windows\SysWow64\mfc71.dll
2015-03-25 01:59 . 2001-09-05 03:18	77824	----a-w-	g:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2015-03-25 01:59 . 2001-09-05 03:18	225280	----a-w-	g:\program files (x86)\Common Files\InstallShield\IScript\iscript.dll
2015-03-25 01:59 . 2001-09-05 03:14	176128	----a-w-	g:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2015-03-25 01:59 . 2001-09-05 03:13	32768	----a-w-	g:\program files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2015-03-22 16:27 . 2015-03-22 16:27	--------	d-----w-	g:\program files (x86)\Microsoft
2015-03-21 08:34 . 2015-03-21 08:34	--------	d-----w-	g:\program files\Microsoft Silverlight
2015-03-21 08:34 . 2015-03-21 08:34	--------	d-----w-	g:\program files (x86)\Microsoft Silverlight
2015-03-18 15:27 . 2015-03-18 15:27	--------	d-----w-	g:\program files (x86)\Windows Phone
2015-03-18 15:25 . 2015-03-18 15:25	--------	d-----w-	g:\programdata\Applications
2015-03-12 07:27 . 2015-03-06 05:56	95680	----a-w-	g:\windows\system32\drivers\ksecdd.sys
2015-03-12 07:26 . 2015-02-26 03:25	3204096	----a-w-	g:\windows\system32\win32k.sys
2015-03-12 07:26 . 2015-02-04 03:16	465920	----a-w-	g:\windows\system32\WMPhoto.dll
2015-03-12 07:26 . 2015-02-04 02:54	417792	----a-w-	g:\windows\SysWow64\WMPhoto.dll
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-04-05 01:33 . 2015-03-05 12:19	129752	----a-w-	g:\windows\system32\drivers\MBAMSwissArmy.sys
2015-03-15 12:09 . 2014-05-17 13:53	778928	----a-w-	g:\windows\SysWow64\FlashPlayerApp.exe
2015-03-15 12:09 . 2014-05-17 13:53	142512	----a-w-	g:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-03-12 07:29 . 2014-05-17 18:36	122905848	----a-w-	g:\windows\system32\MRT.exe
2015-02-24 02:17 . 2014-05-17 10:10	295552	------w-	g:\windows\system32\MpSigStub.exe
2015-02-17 15:04 . 2015-02-17 15:04	1202848	----a-w-	g:\windows\SysWow64\FM20.DLL
2015-01-26 06:25 . 2014-10-01 11:55	98216	----a-w-	g:\windows\SysWow64\WindowsAccessBridge-32.dll
2015-01-09 03:14 . 2015-02-16 05:18	91136	----a-w-	g:\windows\system32\wdi.dll
2015-01-09 03:14 . 2015-02-16 05:18	950272	----a-w-	g:\windows\system32\perftrack.dll
2015-01-09 03:14 . 2015-02-16 05:18	29696	----a-w-	g:\windows\system32\powertracker.dll
2015-01-09 02:48 . 2015-02-16 05:18	76800	----a-w-	g:\windows\SysWow64\wdi.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{691B33B0-B86E-47F3-81C7-56E4FE3B929C}]
2014-10-10 15:03	37928	----a-w-	g:\program files (x86)\PDF Architect 2\creator-ie-helper.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{DEEB13D7-CEA9-45FB-B77C-E039BEC85221}"= "g:\program files (x86)\PDF Architect 2\creator-ie-plugin.dll" [2014-10-10 478760]
.
[HKEY_CLASSES_ROOT\clsid\{deeb13d7-cea9-45fb-b77c-e039bec85221}]
[HKEY_CLASSES_ROOT\PDFIEPlugin.PDFIEConverter.1]
[HKEY_CLASSES_ROOT\TypeLib\{30CEDC3C-254F-4827-9A25-A4AA041826CC}]
[HKEY_CLASSES_ROOT\PDFIEPlugin.PDFIEConverter]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="g:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="g:\program files\AVAST Software\Avast\AvastUI.exe" [2014-07-31 4085896]
"DivXMediaServer"="g:\program files (x86)\DivX\DivX Media Server\DivXMediaServer.exe" [2014-11-17 448856]
"DivXUpdate"="g:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2014-01-10 1861968]
"StartCCC"="g:\program files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-11-20 767176]
"Raptr"="g:\program files (x86)\Raptr\raptrstub.exe" [2015-03-25 55568]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 aswStm;aswStm;g:\windows\system32\drivers\aswStm.sys;g:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;g:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;g:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 PDF Architect 2 Creator;PDF Architect 2 Creator;g:\program files (x86)\PDF Architect 2\creator-ws.exe;g:\program files (x86)\PDF Architect 2\creator-ws.exe [x]
R2 SkypeUpdate;Skype Updater;g:\program files (x86)\Skype\Updater\Updater.exe;g:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;g:\windows\system32\IEEtwCollector.exe;g:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;g:\windows\system32\drivers\rdpvideominiport.sys;g:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SandraAgentSrv;SiSoftware Deployment Agent Service;g:\program files\SiSoftware\SiSoftware Sandra Lite 2014.SP3c\RpcAgentSrv.exe;g:\program files\SiSoftware\SiSoftware Sandra Lite 2014.SP3c\RpcAgentSrv.exe [x]
R3 TsUsbFlt;TsUsbFlt;g:\windows\system32\drivers\tsusbflt.sys;g:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;g:\windows\system32\Drivers\usbaapl64.sys;g:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;g:\windows\system32\drivers\aswSnx.sys;g:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;g:\windows\system32\drivers\aswSP.sys;g:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;g:\windows\system32\atiesrxx.exe;g:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswHwid;avast! HardwareID;g:\windows\system32\drivers\aswHwid.sys;g:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;g:\windows\system32\drivers\aswMonFlt.sys;g:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 UMVPFSrv;UMVPFSrv;g:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;g:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;g:\windows\system32\drivers\AtihdW76.sys;g:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;g:\windows\system32\drivers\LGBusEnum.sys;g:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LGSHidFilt;Logitech Gaming KMDF HID Filter Driver;g:\windows\system32\DRIVERS\LGSHidFilt.Sys;g:\windows\SYSNATIVE\DRIVERS\LGSHidFilt.Sys [x]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;g:\windows\system32\drivers\LGVirHid.sys;g:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
S3 LVUVC64;Logitech Webcam 120(UVC);g:\windows\system32\DRIVERS\lvuvc64.sys;g:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;g:\windows\system32\DRIVERS\Rt64win7.sys;g:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2015-04-05 g:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- g:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15 15:32]
.
2015-04-05 g:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- g:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15 15:32]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-07-15 06:28	634872	----a-w-	g:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Launch LCore"="g:\program files\Logitech Gaming Software\LCore.exe" [2014-07-28 10801944]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = g:\windows\system32\blank.htm
mLocal Page = g:\windows\SysWOW64\blank.htm
IE: Free YouTube to MP3 Converter - g:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
IE: Nach Microsoft E&xel exportieren - g:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1 0.0.0.0
FF - ProfilePath - g:\users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-Glyph Archeage - g:\program files (x86)\Glyph\GlyphClient.exe
AddRemove-{DDEAE484-D5FB-49CB-BD47-9512E8ACCA65}_is1 - g:\users\mse13ssd\Desktop\SciLor's Grooveshark.com Downloader\SciLor's grooveshark(tm).com Downloader\unins000.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3243151774-2580435505-251407729-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:68,4b,29,37,4b,5c,4a,61,7c,26,e4,9e,c9,7c,95,7f,e2,70,84,b1,dd,0c,5d,
   6a,eb,18,0b,04,fb,b2,7f,1d,ec,62,0f,d4,49,95,2a,59,64,6e,68,ba,1e,c7,4a,ed,\
"??"=hex:23,25,64,46,71,6e,29,53,78,10,63,87,6d,b7,18,a6
.
[HKEY_USERS\S-1-5-21-3243151774-2580435505-251407729-1001\Software\SecuROM\License information*]
"datasecu"=hex:9d,0b,4f,33,80,34,ba,75,1a,06,4c,eb,99,ec,a4,2d,eb,60,70,f3,ff,
   d9,4e,91,85,01,2f,88,03,ef,a9,91,b6,36,fd,c0,a3,1d,36,4d,88,b8,8f,5b,0e,3a,\
"rkeysecu"=hex:33,cd,9a,d6,e9,4d,7b,53,58,90,40,9b,f8,82,34,9f
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2015-04-05  15:10:54
ComboFix-quarantined-files.txt  2015-04-05 13:10
.
Vor Suchlauf: 9 Verzeichnis(se), 24.165.081.088 Bytes frei
Nach Suchlauf: 13 Verzeichnis(se), 26.069.192.704 Bytes frei
.
- - End Of File - - CD247D1AF0BBA8CE1711B6CAB0FC58E0
A36C5E4F47E84449FF07ED3517B43A31
         
__________________

Geändert von MSE XIII (05.04.2015 um 14:17 Uhr)

Alt 05.04.2015, 17:00   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen - Standard

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 05.04.2015, 18:43   #5
MSE XIII
 
Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen - Standard

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen



Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 05.04.2015
Suchlauf-Zeit: 18:22:20
Logdatei: Malwarebytes.txt
Administrator: Ja

Version: 2.00.4.1028
Malware Datenbank: v2015.04.05.02
Rootkit Datenbank: v2015.03.31.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: mse13ssd

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 351386
Verstrichene Zeit: 5 Min, 1 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(Keine schädliche Elemente erkannt)

Module: 0
(Keine schädliche Elemente erkannt)

Registrierungsschlüssel: 0
(Keine schädliche Elemente erkannt)

Registrierungswerte: 0
(Keine schädliche Elemente erkannt)

Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)

Ordner: 0
(Keine schädliche Elemente erkannt)

Dateien: 0
(Keine schädliche Elemente erkannt)

Physische Sektoren: 0
(Keine schädliche Elemente erkannt)


(end)
         
AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v4.200 - Bericht erstellt 05/04/2015 um 18:38:15
# Aktualisiert 29/03/2015 von Xplode
# Datenbank : 2015-03-29.1 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : mse13ssd - MSE13SSD-PC
# Gestarted von : G:\Users\mse13ssd\Desktop\adwcleaner_4.200.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\Extensions\jpfpebmajhhopeonhlcgidhclcccjcik
Datei Gelöscht : G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\Local Extension Settings\npnkeeiehehhefofiekoflfedgehcdhl
Datei Gelöscht : G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\Local Storage\chrome-extension_jpfpebmajhhopeonhlcgidhclcccjcik_0.localstorage
Datei Gelöscht : G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\Local Storage\chrome-extension_jpfpebmajhhopeonhlcgidhclcccjcik_0.localstorage-journal
Datei Gelöscht : G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\databases\chrome-extension_jpfpebmajhhopeonhlcgidhclcccjcik_0

***** [ Geplante Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Internetbrowser ] *****

-\\ Internet Explorer v11.0.9600.17689


-\\ Mozilla Firefox v36.0 (x86 de)


-\\ Google Chrome v


-\\ Chromium v

[G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\Secure Preferences] - Gelöscht [Extension] : jpfpebmajhhopeonhlcgidhclcccjcik

*************************

AdwCleaner[R0].txt - [4105 Bytes] - [05/04/2015 03:46:08]
AdwCleaner[R1].txt - [1819 Bytes] - [05/04/2015 18:37:27]
AdwCleaner[S0].txt - [4067 Bytes] - [05/04/2015 03:47:41]
AdwCleaner[S1].txt - [1739 Bytes] - [05/04/2015 18:38:15]

########## EOF - G:\AdwCleaner\AdwCleaner[S1].txt - [1798  Bytes] ##########
         
--- --- ---JRT Logfile:
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.5.1 (04.02.2015:1)
OS: Windows 7 Home Premium x64
Ran by mse13ssd on 05.04.2015 at 19:33:40,14
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{691B33B0-B86E-47F3-81C7-56E4FE3B929C}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{691B33B0-B86E-47F3-81C7-56E4FE3B929C}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{691B33B0-B86E-47F3-81C7-56E4FE3B929C}



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05.04.2015 at 19:36:06,44
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
--- --- ---
FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by mse13ssd (administrator) on MSE13SSD-PC on 05-04-2015 19:37:00
Running from G:\Users\mse13ssd\Desktop
Loaded Profiles: mse13ssd (Available profiles: mse13ssd)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) G:\Windows\System32\atiesrxx.exe
(Logitech Inc.) G:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AMD) G:\Windows\System32\atieclxx.exe
(AVAST Software) G:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) G:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) G:\Program Files\Bonjour\mDNSResponder.exe
(Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
(Logitech Inc.) G:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) G:\Program Files\Windows Sidebar\sidebar.exe
(AVAST Software) G:\Program Files\AVAST Software\Avast\avastui.exe
() G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Advanced Micro Devices Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Launch LCore] => G:\Program Files\Logitech Gaming Software\LCore.exe [10801944 2014-07-28] (Logitech Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => G:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software)
HKLM-x32\...\Run: [DivXMediaServer] => G:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [StartCCC] => G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Raptr] => G:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-03-25] (Raptr, Inc)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => G:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3243151774-2580435505-251407729-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland ? mit Hotmail Nachfolger Outlook und Messenger Skype
HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-15] (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-26] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-15] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-26] (Oracle Corporation)
Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - G:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll [2014-10-10] (pdfforge GmbH)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0

FireFox:
========
FF ProfilePath: G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default
FF Plugin: @adobe.com/FlashPlayer -> G:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-15] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> G:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-15] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> G:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2012-04-05] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> G:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-26] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-26] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> G:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.)
FF Plugin-x32: Adobe Reader -> G:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Extension: Download videos and MP3s from YouTube - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-11-21]
FF Extension: Adblock Plus - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-09]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - G:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - G:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-17]
FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension
FF Extension: PDF Architect 2 Creator - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2014-12-09]
FF HKU\S-1-5-21-3243151774-2580435505-251407729-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF Extension: Download videos and MP3s from YouTube - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-11-21]

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Profile: G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-09]
CHR Extension: (Google Docs) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-09]
CHR Extension: (Google Drive) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-09]
CHR Extension: (Google Voice Search Hotword (Beta)) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-09]
CHR Extension: (YouTube) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-09]
CHR Extension: (Google Search) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-09]
CHR Extension: (Google Sheets) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-09]
CHR Extension: (Google Wallet) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-09]
CHR Extension: (Gmail) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-09]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - G:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-15]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; G:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-15] (AVAST Software)
S2 PDF Architect 2 Creator; G:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH)
S3 SandraAgentSrv; G:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3c\RpcAgentSrv.exe [73712 2014-09-19] (SiSoftware) [File not signed]
R2 WinDefend; G:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; G:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 aswHwid; G:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-15] ()
R2 aswMonFlt; G:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-15] (AVAST Software)
R1 aswRdr; G:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-15] (AVAST Software)
R0 aswRvrt; G:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-15] ()
R1 aswSnx; G:\Windows\system32\drivers\aswSnx.sys [1041168 2014-11-21] (AVAST Software)
R1 aswSP; G:\Windows\system32\drivers\aswSP.sys [427360 2014-07-15] (AVAST Software)
S2 aswStm; G:\Windows\system32\drivers\aswStm.sys [92008 2014-07-15] (AVAST Software)
R0 aswVmm; G:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-15] ()
R3 LGSHidFilt; G:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S3 catchme; \??\G:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-05 19:37 - 2015-04-05 19:37 - 00012050 _____ () G:\Users\mse13ssd\Desktop\FRST.txt
2015-04-05 19:36 - 2015-04-05 19:36 - 00001083 _____ () G:\Users\mse13ssd\Desktop\JRT.txt
2015-04-05 19:33 - 2015-04-05 19:33 - 00000207 _____ () G:\Windows\tweaking.com-regbackup-MSE13SSD-PC-Windows-7-Home-Premium-(64-bit).dat
2015-04-05 19:33 - 2015-04-05 19:33 - 00000000 ____D () G:\RegBackup
2015-04-05 18:40 - 2015-04-05 18:40 - 00001878 _____ () G:\Users\mse13ssd\Desktop\AdwCleaner[S1].txt
2015-04-05 18:35 - 2015-04-05 18:35 - 02690981 _____ (Thisisu) G:\Users\mse13ssd\Desktop\JRT.exe
2015-04-05 18:30 - 2015-04-05 18:30 - 00001212 _____ () G:\Users\mse13ssd\Desktop\Malwarebytes.txt
2015-04-05 15:10 - 2015-04-05 15:10 - 00011639 _____ () G:\ComboFix.txt
2015-04-05 15:03 - 2015-04-05 15:10 - 00000000 ____D () G:\Qoobox
2015-04-05 15:03 - 2015-04-05 15:09 - 00000000 ____D () G:\Windows\erdnt
2015-04-05 15:03 - 2011-06-26 08:45 - 00256000 _____ () G:\Windows\PEV.exe
2015-04-05 15:03 - 2010-11-07 19:20 - 00208896 _____ () G:\Windows\MBR.exe
2015-04-05 15:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) G:\Windows\NIRCMD.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) G:\Windows\SWREG.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) G:\Windows\SWSC.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00098816 _____ () G:\Windows\sed.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00080412 _____ () G:\Windows\grep.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00068096 _____ () G:\Windows\zip.exe
2015-04-05 15:01 - 2015-04-05 15:01 - 05617096 ____R (Swearware) G:\Users\mse13ssd\Desktop\ComboFix.exe
2015-04-05 13:19 - 2015-04-05 13:19 - 00279353 _____ () G:\Users\mse13ssd\Desktop\Gmer.txt
2015-04-05 13:10 - 2015-04-05 13:11 - 00380416 _____ () G:\Users\mse13ssd\Downloads\liqvrrec.exe
2015-04-05 13:02 - 2015-04-05 19:37 - 00000000 ____D () G:\FRST
2015-04-05 13:02 - 2015-04-05 13:03 - 00048734 _____ () G:\Users\mse13ssd\Downloads\FRST.txt
2015-04-05 13:02 - 2015-04-05 13:03 - 00024876 _____ () G:\Users\mse13ssd\Downloads\Addition.txt
2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Downloads\FRST64 (1).exe
2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Desktop\FRST64.exe
2015-04-05 12:59 - 2015-04-05 12:59 - 00000478 _____ () G:\Users\mse13ssd\Downloads\defogger_disable.log
2015-04-05 12:59 - 2015-04-05 12:59 - 00000000 _____ () G:\Users\mse13ssd\defogger_reenable
2015-04-05 12:57 - 2015-04-05 12:57 - 00050477 _____ () G:\Users\mse13ssd\Downloads\Defogger.exe
2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (2).exe
2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (1).exe
2015-04-05 03:38 - 2015-04-05 18:38 - 00000000 ____D () G:\AdwCleaner
2015-04-05 03:37 - 2015-04-05 03:38 - 02208768 _____ () G:\Users\mse13ssd\Desktop\adwcleaner_4.200.exe
2015-03-31 05:26 - 2015-03-31 05:26 - 00008930 _____ () G:\Users\mse13ssd\Downloads\smime (1).p7s
2015-03-31 02:41 - 2015-03-31 02:41 - 00000069 _____ () G:\Users\mse13ssd\Desktop\BADLOGIC (German Fandub) - YouTube.url
2015-03-28 00:47 - 2015-03-28 00:47 - 00012288 _____ () G:\Users\mse13ssd\Downloads\Qual-Fraktal.xls
2015-03-27 07:14 - 2015-03-27 07:14 - 00000000 ____D () G:\Users\mse13ssd\Desktop\SciLor's Grooveshark.com Downloader
2015-03-26 21:20 - 2015-03-26 21:20 - 671367548 _____ () G:\Windows\MEMORY.DMP
2015-03-26 21:20 - 2015-03-26 21:20 - 00274624 _____ () G:\Windows\Minidump\032615-29718-01.dmp
2015-03-25 04:31 - 2015-03-25 04:31 - 00002123 _____ () G:\Users\Public\Desktop\CONTRACT J.A.C.K. .lnk
2015-03-25 04:05 - 2015-03-25 04:05 - 00000000 ____D () G:\Program Files (x86)\Sierra
2015-03-25 04:04 - 2015-03-25 04:04 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra
2015-03-25 04:00 - 2003-06-26 10:45 - 00499712 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcp71.dll
2015-03-25 04:00 - 2003-06-26 10:45 - 00348160 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcr71.dll
2015-03-25 04:00 - 2003-03-19 07:20 - 01060864 ____N (Microsoft Corporation) G:\Windows\SysWOW64\mfc71.dll
2015-03-22 18:27 - 2015-03-22 18:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files\Microsoft Silverlight
2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files (x86)\Microsoft Silverlight
2015-03-21 10:33 - 2015-03-21 10:33 - 13087456 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\Silverlight_x64.exe
2015-03-18 17:29 - 2015-03-18 17:29 - 00002023 _____ () G:\Users\mse13ssd\Desktop\Windows Phone-Desktopanwendung.lnk
2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Phone
2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\Program Files (x86)\Windows Phone
2015-03-18 17:25 - 2015-03-18 17:25 - 06745792 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\WindowsPhone.exe
2015-03-18 17:25 - 2015-03-18 17:25 - 00000000 ____D () G:\ProgramData\Applications
2015-03-16 19:19 - 2015-03-16 19:19 - 00001535 _____ () G:\Users\mse13ssd\Free YouTube to MP3 Converter.lnk
2015-03-15 17:32 - 2015-04-05 19:37 - 00001114 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-15 17:32 - 2015-04-05 18:39 - 00001110 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-15 17:32 - 2015-03-15 17:32 - 00004110 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-03-15 17:32 - 2015-03-15 17:32 - 00003858 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-03-15 17:32 - 2015-03-15 17:32 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2015-03-15 17:31 - 2015-03-15 17:31 - 00880208 _____ (Google Inc.) G:\Users\mse13ssd\Downloads\GoogleEarthSetup.exe
2015-03-14 07:06 - 2015-03-14 07:33 - 82044588 _____ () G:\Users\mse13ssd\Downloads\ES-X_DE.rar.crdownload
2015-03-12 09:28 - 2015-02-03 05:34 - 05554104 _____ (Microsoft Corporation) G:\Windows\system32\ntoskrnl.exe
2015-03-12 09:28 - 2015-02-03 05:34 - 00693176 _____ (Microsoft Corporation) G:\Windows\system32\winload.efi
2015-03-12 09:28 - 2015-02-03 05:34 - 00094656 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\mountmgr.sys
2015-03-12 09:28 - 2015-02-03 05:33 - 00616360 _____ (Microsoft Corporation) G:\Windows\system32\winresume.efi
2015-03-12 09:28 - 2015-02-03 05:31 - 14632960 _____ (Microsoft Corporation) G:\Windows\system32\wmp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 04121600 _____ (Microsoft Corporation) G:\Windows\system32\mf.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 01574400 _____ (Microsoft Corporation) G:\Windows\system32\quartz.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00782848 _____ (Microsoft Corporation) G:\Windows\system32\wmdrmsdk.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00641024 _____ (Microsoft Corporation) G:\Windows\system32\msscp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00503808 _____ (Microsoft Corporation) G:\Windows\system32\srcore.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00500224 _____ (Microsoft Corporation) G:\Windows\system32\AUDIOKSE.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00432128 _____ (Microsoft Corporation) G:\Windows\system32\mfplat.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00371712 _____ (Microsoft Corporation) G:\Windows\system32\qdvd.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00325632 _____ (Microsoft Corporation) G:\Windows\system32\msnetobj.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00229376 _____ (Microsoft Corporation) G:\Windows\system32\wintrust.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00206848 _____ (Microsoft Corporation) G:\Windows\system32\mfps.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00188416 _____ (Microsoft Corporation) G:\Windows\system32\pcasvc.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00063488 _____ (Microsoft Corporation) G:\Windows\system32\setbcdlocale.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00050176 _____ (Microsoft Corporation) G:\Windows\system32\srclient.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00037376 _____ (Microsoft Corporation) G:\Windows\system32\pcadm.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\msmmsp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\spwmp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\msdxm.ocx
2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\dxmasf.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 12625920 _____ (Microsoft Corporation) G:\Windows\system32\wmploc.DLL
2015-03-12 09:28 - 2015-02-03 05:30 - 01480192 _____ (Microsoft Corporation) G:\Windows\system32\crypt32.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 01202176 _____ (Microsoft Corporation) G:\Windows\system32\drmv2clt.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 01069056 _____ (Microsoft Corporation) G:\Windows\system32\cryptui.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00842240 _____ (Microsoft Corporation) G:\Windows\system32\blackbox.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00680960 _____ (Microsoft Corporation) G:\Windows\system32\audiosrv.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00631808 _____ (Microsoft Corporation) G:\Windows\system32\evr.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00497664 _____ (Microsoft Corporation) G:\Windows\system32\drmmgrtn.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00440832 _____ (Microsoft Corporation) G:\Windows\system32\AudioEng.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00296960 _____ (Microsoft Corporation) G:\Windows\system32\rstrui.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00296448 _____ (Microsoft Corporation) G:\Windows\system32\AudioSes.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00284672 _____ (Microsoft Corporation) G:\Windows\system32\EncDump.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00187904 _____ (Microsoft Corporation) G:\Windows\system32\cryptsvc.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00146944 _____ (Microsoft Corporation) G:\Windows\system32\appidpolicyconverter.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00140288 _____ (Microsoft Corporation) G:\Windows\system32\cryptnet.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00126464 _____ (Microsoft Corporation) G:\Windows\system32\audiodg.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00112640 _____ (Microsoft Corporation) G:\Windows\system32\smss.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00082432 _____ (Microsoft Corporation) G:\Windows\system32\cryptsp.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00058880 _____ (Microsoft Corporation) G:\Windows\system32\appidapi.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00055808 _____ (Microsoft Corporation) G:\Windows\system32\rrinstaller.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00043520 _____ (Microsoft Corporation) G:\Windows\system32\csrsrv.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00032256 _____ (Microsoft Corporation) G:\Windows\system32\appidsvc.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00024576 _____ (Microsoft Corporation) G:\Windows\system32\mfpmp.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00017920 _____ (Microsoft Corporation) G:\Windows\system32\appidcertstorecheck.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\pcawrk.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\pcalua.exe
2015-03-12 09:28 - 2015-02-03 05:29 - 00008704 _____ (Microsoft Corporation) G:\Windows\system32\pcaevts.dll
2015-03-12 09:28 - 2015-02-03 05:28 - 00006656 _____ (Microsoft Corporation) G:\Windows\system32\apisetschema.dll
2015-03-12 09:28 - 2015-02-03 05:28 - 00002048 _____ (Microsoft Corporation) G:\Windows\system32\mferror.dll
2015-03-12 09:28 - 2015-02-03 05:19 - 00663552 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\PEAuth.sys
2015-03-12 09:28 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntkrnlpa.exe
2015-03-12 09:28 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntoskrnl.exe
2015-03-12 09:28 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mf.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) G:\Windows\SysWOW64\quartz.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) G:\Windows\SysWOW64\crypt32.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptui.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmv2clt.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\blackbox.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmdrmsdk.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) G:\Windows\SysWOW64\qdvd.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msscp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\evr.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AUDIOKSE.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmmgrtn.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioEng.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfplat.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msnetobj.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioSes.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wintrust.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsvc.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptnet.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfps.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) G:\Windows\SysWOW64\appidapi.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) G:\Windows\SysWOW64\srclient.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\spwmp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msdxm.ocx
2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxmasf.dll
2015-03-12 09:28 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmploc.DLL
2015-03-12 09:28 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\rrinstaller.exe
2015-03-12 09:28 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfpmp.exe
2015-03-12 09:28 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mferror.dll
2015-03-12 09:28 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\apisetschema.dll
2015-03-12 09:28 - 2015-02-03 04:32 - 00061440 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\appid.sys
2015-03-12 09:28 - 2014-11-01 00:24 - 00619056 _____ (Microsoft Corporation) G:\Windows\system32\winload.exe
2015-03-12 09:28 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) G:\Windows\system32\winresume.exe
2015-03-12 09:28 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) G:\Windows\system32\ci.dll
2015-03-12 09:27 - 2015-03-06 07:56 - 00155576 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecpkg.sys
2015-03-12 09:27 - 2015-03-06 07:56 - 00095680 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecdd.sys
2015-03-12 09:27 - 2015-03-06 07:42 - 01461760 _____ (Microsoft Corporation) G:\Windows\system32\lsasrv.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00728064 _____ (Microsoft Corporation) G:\Windows\system32\kerberos.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00341504 _____ (Microsoft Corporation) G:\Windows\system32\schannel.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00314880 _____ (Microsoft Corporation) G:\Windows\system32\msv1_0.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00309760 _____ (Microsoft Corporation) G:\Windows\system32\ncrypt.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00210944 _____ (Microsoft Corporation) G:\Windows\system32\wdigest.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00136192 _____ (Microsoft Corporation) G:\Windows\system32\sspicli.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00086528 _____ (Microsoft Corporation) G:\Windows\system32\TSpkg.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00029184 _____ (Microsoft Corporation) G:\Windows\system32\sspisrv.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00028160 _____ (Microsoft Corporation) G:\Windows\system32\secur32.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00022016 _____ (Microsoft Corporation) G:\Windows\system32\credssp.dll
2015-03-12 09:27 - 2015-03-06 07:41 - 00064000 _____ (Microsoft Corporation) G:\Windows\system32\auditpol.exe
2015-03-12 09:27 - 2015-03-06 07:41 - 00031232 _____ (Microsoft Corporation) G:\Windows\system32\lsass.exe
2015-03-12 09:27 - 2015-03-06 07:39 - 00060416 _____ (Microsoft Corporation) G:\Windows\system32\msobjs.dll
2015-03-12 09:27 - 2015-03-06 07:38 - 00146432 _____ (Microsoft Corporation) G:\Windows\system32\msaudite.dll
2015-03-12 09:27 - 2015-03-06 07:36 - 00686080 _____ (Microsoft Corporation) G:\Windows\system32\adtschema.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) G:\Windows\SysWOW64\kerberos.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msv1_0.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) G:\Windows\SysWOW64\schannel.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ncrypt.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wdigest.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) G:\Windows\SysWOW64\TSpkg.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\secur32.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\credssp.dll
2015-03-12 09:27 - 2015-03-06 07:09 - 00096768 _____ (Microsoft Corporation) G:\Windows\SysWOW64\sspicli.dll
2015-03-12 09:27 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\auditpol.exe
2015-03-12 09:27 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msaudite.dll
2015-03-12 09:27 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msobjs.dll
2015-03-12 09:27 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) G:\Windows\SysWOW64\adtschema.dll
2015-03-12 09:27 - 2015-02-24 05:15 - 00389800 _____ (Microsoft Corporation) G:\Windows\system32\iedkcs32.dll
2015-03-12 09:27 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iedkcs32.dll
2015-03-12 09:27 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.dll
2015-03-12 09:27 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieframe.dll
2015-03-12 09:27 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtmsft.dll
2015-03-12 09:27 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtrans.dll
2015-03-12 09:27 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.dll
2015-03-12 09:27 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) G:\Windows\system32\mshtmled.dll
2015-03-12 09:27 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmled.dll
2015-03-12 09:27 - 2015-02-20 06:41 - 00041984 _____ (Microsoft Corporation) G:\Windows\system32\lpk.dll
2015-03-12 09:27 - 2015-02-20 06:40 - 00100864 _____ (Microsoft Corporation) G:\Windows\system32\fontsub.dll
2015-03-12 09:27 - 2015-02-20 06:40 - 00046080 _____ (Adobe Systems) G:\Windows\system32\atmlib.dll
2015-03-12 09:27 - 2015-02-20 06:40 - 00014336 _____ (Microsoft Corporation) G:\Windows\system32\dciman32.dll
2015-03-12 09:27 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\fontsub.dll
2015-03-12 09:27 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) G:\Windows\SysWOW64\atmlib.dll
2015-03-12 09:27 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dciman32.dll
2015-03-12 09:27 - 2015-02-20 06:12 - 00025600 _____ (Microsoft Corporation) G:\Windows\SysWOW64\lpk.dll
2015-03-12 09:27 - 2015-02-20 05:29 - 00372224 _____ (Adobe Systems Incorporated) G:\Windows\system32\atmfd.dll
2015-03-12 09:27 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\atmfd.dll
2015-03-12 09:27 - 2015-02-20 05:06 - 02724864 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.tlb
2015-03-12 09:27 - 2015-02-20 05:05 - 00004096 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollectorres.dll
2015-03-12 09:27 - 2015-02-20 04:50 - 00066560 _____ (Microsoft Corporation) G:\Windows\system32\iesetup.dll
2015-03-12 09:27 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) G:\Windows\system32\vbscript.dll
2015-03-12 09:27 - 2015-02-20 04:49 - 00048640 _____ (Microsoft Corporation) G:\Windows\system32\ieetwproxystub.dll
2015-03-12 09:27 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) G:\Windows\system32\iertutil.dll
2015-03-12 09:27 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) G:\Windows\system32\MshtmlDac.dll
2015-03-12 09:27 - 2015-02-20 04:41 - 00054784 _____ (Microsoft Corporation) G:\Windows\system32\jsproxy.dll
2015-03-12 09:27 - 2015-02-20 04:40 - 00034304 _____ (Microsoft Corporation) G:\Windows\system32\iernonce.dll
2015-03-12 09:27 - 2015-02-20 04:36 - 00633856 _____ (Microsoft Corporation) G:\Windows\system32\ieui.dll
2015-03-12 09:27 - 2015-02-20 04:35 - 00144384 _____ (Microsoft Corporation) G:\Windows\system32\ieUnatt.exe
2015-03-12 09:27 - 2015-02-20 04:35 - 00114688 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollector.exe
2015-03-12 09:27 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) G:\Windows\system32\jscript9diag.dll
2015-03-12 09:27 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) G:\Windows\system32\jscript9.dll
2015-03-12 09:27 - 2015-02-20 04:26 - 00968704 _____ (Microsoft Corporation) G:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-12 09:27 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.tlb
2015-03-12 09:27 - 2015-02-20 04:22 - 00490496 _____ (Microsoft Corporation) G:\Windows\system32\dxtmsft.dll
2015-03-12 09:27 - 2015-02-20 04:13 - 00077824 _____ (Microsoft Corporation) G:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-12 09:27 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) G:\Windows\SysWOW64\vbscript.dll
2015-03-12 09:27 - 2015-02-20 04:08 - 00199680 _____ (Microsoft Corporation) G:\Windows\system32\msrating.dll
2015-03-12 09:27 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iesetup.dll
2015-03-12 09:27 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieetwproxystub.dll
2015-03-12 09:27 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) G:\Windows\SysWOW64\MshtmlDac.dll
2015-03-12 09:27 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) G:\Windows\system32\dxtrans.dll
2015-03-12 09:27 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iertutil.dll
2015-03-12 09:27 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jsproxy.dll
2015-03-12 09:27 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iernonce.dll
2015-03-12 09:27 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieui.dll
2015-03-12 09:27 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9diag.dll
2015-03-12 09:27 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieUnatt.exe
2015-03-12 09:27 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) G:\Windows\system32\msfeeds.dll
2015-03-12 09:27 - 2015-02-20 03:49 - 00718848 _____ (Microsoft Corporation) G:\Windows\system32\ie4uinit.exe
2015-03-12 09:27 - 2015-02-20 03:47 - 01359360 _____ (Microsoft Corporation) G:\Windows\system32\mshtmlmedia.dll
2015-03-12 09:27 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) G:\Windows\system32\inetcpl.cpl
2015-03-12 09:27 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) G:\Windows\system32\ieframe.dll
2015-03-12 09:27 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-03-12 09:27 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msrating.dll
2015-03-12 09:27 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9.dll
2015-03-12 09:27 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) G:\Windows\system32\wininet.dll
2015-03-12 09:27 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) G:\Windows\SysWOW64\inetcpl.cpl
2015-03-12 09:27 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msfeeds.dll
2015-03-12 09:27 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmlmedia.dll
2015-03-12 09:27 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) G:\Windows\system32\urlmon.dll
2015-03-12 09:27 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) G:\Windows\system32\ieapfltr.dll
2015-03-12 09:27 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wininet.dll
2015-03-12 09:27 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) G:\Windows\SysWOW64\urlmon.dll
2015-03-12 09:27 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieapfltr.dll
2015-03-12 09:27 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) G:\Windows\SysWOW64\shell32.dll
2015-03-12 09:27 - 2015-02-13 07:22 - 14177280 _____ (Microsoft Corporation) G:\Windows\system32\shell32.dll
2015-03-12 09:27 - 2015-02-03 05:31 - 01424896 _____ (Microsoft Corporation) G:\Windows\system32\WindowsCodecs.dll
2015-03-12 09:27 - 2015-02-03 05:31 - 00215552 _____ (Microsoft Corporation) G:\Windows\system32\ubpm.dll
2015-03-12 09:27 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WindowsCodecs.dll
2015-03-12 09:27 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ubpm.dll
2015-03-12 09:27 - 2015-01-31 05:48 - 03179520 _____ (Microsoft Corporation) G:\Windows\system32\rdpcorets.dll
2015-03-12 09:27 - 2015-01-31 05:48 - 00016384 _____ (Microsoft Corporation) G:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-12 09:27 - 2015-01-31 01:56 - 00459336 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\cng.sys
2015-03-12 09:27 - 2015-01-31 01:56 - 00243200 _____ (Microsoft Corporation) G:\Windows\system32\rdpudd.dll
2015-03-12 09:27 - 2015-01-17 04:48 - 01067520 _____ (Microsoft Corporation) G:\Windows\system32\msctf.dll
2015-03-12 09:27 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msctf.dll
2015-03-12 09:26 - 2015-02-26 05:25 - 03204096 _____ (Microsoft Corporation) G:\Windows\system32\win32k.sys
2015-03-12 09:26 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) G:\Windows\system32\WMPhoto.dll
2015-03-12 09:26 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WMPhoto.dll
2015-03-10 01:20 - 2015-03-10 01:20 - 00001002 _____ () G:\Users\mse13ssd\Downloads\BAHN_Fahrplan_20150609.ics
2015-03-09 11:16 - 2015-03-09 11:56 - 124202474 _____ () G:\Users\mse13ssd\Downloads\#0325#.rar
2015-03-08 09:43 - 2015-03-08 09:43 - 01230365 _____ () G:\Users\mse13ssd\Downloads\2 (1).wmv
2015-03-08 09:43 - 2015-03-08 09:43 - 01222357 _____ () G:\Users\mse13ssd\Downloads\3.wmv
2015-03-06 16:14 - 2015-03-06 16:51 - 111138743 _____ () G:\Users\mse13ssd\Downloads\julins2014.rar

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-05 18:47 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-05 18:47 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-05 18:45 - 2009-07-14 19:58 - 00700986 _____ () G:\Windows\system32\perfh007.dat
2015-04-05 18:45 - 2009-07-14 19:58 - 00149886 _____ () G:\Windows\system32\perfc007.dat
2015-04-05 18:45 - 2009-07-14 07:13 - 01619284 _____ () G:\Windows\system32\PerfStringBackup.INI
2015-04-05 18:43 - 2014-05-17 10:22 - 01378372 _____ () G:\Windows\WindowsUpdate.log
2015-04-05 18:40 - 2014-07-13 00:21 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Raptr
2015-04-05 18:39 - 2014-05-17 22:03 - 00000000 _____ () G:\Windows\system32\Drivers\lvuvc.hs
2015-04-05 18:39 - 2014-05-17 15:20 - 00033022 _____ () G:\Windows\PFRO.log
2015-04-05 18:39 - 2009-07-14 07:08 - 00000006 ____H () G:\Windows\Tasks\SA.DAT
2015-04-05 18:39 - 2009-07-14 06:51 - 00055579 _____ () G:\Windows\setupact.log
2015-04-05 18:19 - 2015-03-05 14:19 - 00129752 _____ (Malwarebytes Corporation) G:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-05 15:10 - 2009-07-14 05:20 - 00000000 __RHD () G:\Users\Default
2015-04-05 15:09 - 2009-07-14 04:34 - 00000215 _____ () G:\Windows\system.ini
2015-04-05 13:19 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\NDF
2015-04-05 13:06 - 2014-05-17 22:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Skype
2015-04-05 12:59 - 2014-05-17 11:54 - 00000000 ____D () G:\Users\mse13ssd
2015-04-05 03:26 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\Web
2015-04-05 02:39 - 2014-05-17 15:57 - 00004182 _____ () G:\Windows\System32\Tasks\avast! Emergency Update
2015-04-04 14:30 - 2014-05-17 20:13 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\TS3Client
2015-04-02 01:34 - 2009-07-14 07:32 - 00000000 ____D () G:\Windows\system32\FxsTmp
2015-03-30 17:36 - 2015-02-28 05:38 - 00000000 ____D () G:\Users\mse13ssd\Desktop\aufgeräumt
2015-03-30 08:10 - 2014-11-01 08:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\25372
2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\DivX
2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
2015-03-30 04:33 - 2014-08-24 02:00 - 00000000 ____D () G:\ProgramData\DivX
2015-03-30 04:33 - 2014-05-17 15:57 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2015-03-30 04:33 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\AppCompat
2015-03-30 04:32 - 2014-08-24 02:01 - 00000000 ____D () G:\Program Files\DivX
2015-03-30 04:32 - 2014-08-24 02:00 - 00000000 ____D () G:\Program Files (x86)\DivX
2015-03-30 04:32 - 2014-06-18 17:31 - 00000000 ____D () G:\Program Files (x86)\Microsoft Office
2015-03-30 04:32 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\registration
2015-03-30 03:27 - 2009-07-14 20:18 - 00000000 ___RD () G:\Users\Public\Recorded TV
2015-03-26 21:20 - 2014-10-12 12:01 - 00000000 ____D () G:\Windows\Minidump
2015-03-26 18:51 - 2014-07-13 00:21 - 00000000 ____D () G:\Program Files (x86)\Raptr
2015-03-26 09:13 - 2014-06-18 17:31 - 00000000 ____D () G:\ProgramData\Microsoft Help
2015-03-22 18:29 - 2014-05-17 12:40 - 00070368 _____ () G:\Users\mse13ssd\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-22 18:29 - 2009-07-14 06:45 - 00307752 _____ () G:\Windows\system32\FNTCACHE.DAT
2015-03-22 18:25 - 2014-06-18 17:32 - 00000000 ____D () G:\Program Files (x86)\Microsoft Works
2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Google
2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Program Files (x86)\Google
2015-03-15 14:09 - 2014-08-24 13:49 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Adobe
2015-03-15 14:09 - 2014-05-17 15:53 - 00778928 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerApp.exe
2015-03-15 14:09 - 2014-05-17 15:53 - 00142512 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-03-15 05:05 - 2014-06-21 18:28 - 00000000 ____D () G:\Program Files (x86)\Steam
2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Glyph
2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glyph
2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Program Files (x86)\Glyph
2015-03-13 10:32 - 2009-07-14 07:09 - 00000000 ____D () G:\Windows\System32\Tasks\WPD
2015-03-12 12:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\rescache
2015-03-12 09:37 - 2015-02-28 09:01 - 00000000 ___RD () G:\Users\mse13ssd\Virtual Machines
2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\SysWOW64\Dism
2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\Dism
2015-03-12 09:31 - 2014-05-17 20:36 - 00000000 ____D () G:\Windows\system32\MRT
2015-03-12 09:29 - 2014-05-17 20:36 - 122905848 _____ (Microsoft Corporation) G:\Windows\system32\MRT.exe
2015-03-06 13:47 - 2014-10-13 17:23 - 00000000 ___RD () G:\Program Files (x86)\Skype
2015-03-06 13:47 - 2014-05-17 22:15 - 00000000 ____D () G:\ProgramData\Skype

==================== Files in the root of some directories =======

2014-10-02 16:29 - 2015-02-28 12:40 - 14286848 _____ () G:\Users\mse13ssd\AppData\Roaming\Sandra.mdb
2015-01-23 13:40 - 2015-01-23 13:40 - 0003584 _____ () G:\Users\mse13ssd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-01 14:58 - 2015-01-01 14:58 - 0007605 _____ () G:\Users\mse13ssd\AppData\Local\Resmon.ResmonCfg

Some content of TEMP:
====================
G:\Users\mse13ssd\AppData\Local\Temp\Quarantine.exe
G:\Users\mse13ssd\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

G:\Windows\System32\winlogon.exe => File is digitally signed
G:\Windows\System32\wininit.exe => File is digitally signed
G:\Windows\SysWOW64\wininit.exe => File is digitally signed
G:\Windows\explorer.exe => File is digitally signed
G:\Windows\SysWOW64\explorer.exe => File is digitally signed
G:\Windows\System32\svchost.exe => File is digitally signed
G:\Windows\SysWOW64\svchost.exe => File is digitally signed
G:\Windows\System32\services.exe => File is digitally signed
G:\Windows\System32\User32.dll => File is digitally signed
G:\Windows\SysWOW64\User32.dll => File is digitally signed
G:\Windows\System32\userinit.exe => File is digitally signed
G:\Windows\SysWOW64\userinit.exe => File is digitally signed
G:\Windows\System32\rpcss.dll => File is digitally signed
G:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-04 00:45

==================== End Of Log ============================
         
--- --- ---

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by mse13ssd (administrator) on MSE13SSD-PC on 05-04-2015 19:37:00
Running from G:\Users\mse13ssd\Desktop
Loaded Profiles: mse13ssd (Available profiles: mse13ssd)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) G:\Windows\System32\atiesrxx.exe
(Logitech Inc.) G:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AMD) G:\Windows\System32\atieclxx.exe
(AVAST Software) G:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) G:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) G:\Program Files\Bonjour\mDNSResponder.exe
(Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
(Logitech Inc.) G:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) G:\Program Files\Windows Sidebar\sidebar.exe
(AVAST Software) G:\Program Files\AVAST Software\Avast\avastui.exe
() G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Advanced Micro Devices Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Launch LCore] => G:\Program Files\Logitech Gaming Software\LCore.exe [10801944 2014-07-28] (Logitech Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => G:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software)
HKLM-x32\...\Run: [DivXMediaServer] => G:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [StartCCC] => G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Raptr] => G:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-03-25] (Raptr, Inc)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => G:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3243151774-2580435505-251407729-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = MSN Deutschland ? mit Hotmail Nachfolger Outlook und Messenger Skype
HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-15] (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-26] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-15] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-26] (Oracle Corporation)
Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - G:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll [2014-10-10] (pdfforge GmbH)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0

FireFox:
========
FF ProfilePath: G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default
FF Plugin: @adobe.com/FlashPlayer -> G:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-15] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> G:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-15] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> G:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2012-04-05] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> G:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-26] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-26] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> G:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.)
FF Plugin-x32: Adobe Reader -> G:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Extension: Download videos and MP3s from YouTube - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-11-21]
FF Extension: Adblock Plus - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-09]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - G:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - G:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-17]
FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension
FF Extension: PDF Architect 2 Creator - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2014-12-09]
FF HKU\S-1-5-21-3243151774-2580435505-251407729-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF Extension: Download videos and MP3s from YouTube - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-11-21]

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Profile: G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-09]
CHR Extension: (Google Docs) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-09]
CHR Extension: (Google Drive) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-09]
CHR Extension: (Google Voice Search Hotword (Beta)) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-09]
CHR Extension: (YouTube) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-09]
CHR Extension: (Google Search) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-09]
CHR Extension: (Google Sheets) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-09]
CHR Extension: (Google Wallet) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-09]
CHR Extension: (Gmail) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-09]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - G:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-15]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; G:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-15] (AVAST Software)
S2 PDF Architect 2 Creator; G:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH)
S3 SandraAgentSrv; G:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3c\RpcAgentSrv.exe [73712 2014-09-19] (SiSoftware) [File not signed]
R2 WinDefend; G:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; G:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 aswHwid; G:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-15] ()
R2 aswMonFlt; G:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-15] (AVAST Software)
R1 aswRdr; G:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-15] (AVAST Software)
R0 aswRvrt; G:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-15] ()
R1 aswSnx; G:\Windows\system32\drivers\aswSnx.sys [1041168 2014-11-21] (AVAST Software)
R1 aswSP; G:\Windows\system32\drivers\aswSP.sys [427360 2014-07-15] (AVAST Software)
S2 aswStm; G:\Windows\system32\drivers\aswStm.sys [92008 2014-07-15] (AVAST Software)
R0 aswVmm; G:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-15] ()
R3 LGSHidFilt; G:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S3 catchme; \??\G:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-05 19:37 - 2015-04-05 19:37 - 00012050 _____ () G:\Users\mse13ssd\Desktop\FRST.txt
2015-04-05 19:36 - 2015-04-05 19:36 - 00001083 _____ () G:\Users\mse13ssd\Desktop\JRT.txt
2015-04-05 19:33 - 2015-04-05 19:33 - 00000207 _____ () G:\Windows\tweaking.com-regbackup-MSE13SSD-PC-Windows-7-Home-Premium-(64-bit).dat
2015-04-05 19:33 - 2015-04-05 19:33 - 00000000 ____D () G:\RegBackup
2015-04-05 18:40 - 2015-04-05 18:40 - 00001878 _____ () G:\Users\mse13ssd\Desktop\AdwCleaner[S1].txt
2015-04-05 18:35 - 2015-04-05 18:35 - 02690981 _____ (Thisisu) G:\Users\mse13ssd\Desktop\JRT.exe
2015-04-05 18:30 - 2015-04-05 18:30 - 00001212 _____ () G:\Users\mse13ssd\Desktop\Malwarebytes.txt
2015-04-05 15:10 - 2015-04-05 15:10 - 00011639 _____ () G:\ComboFix.txt
2015-04-05 15:03 - 2015-04-05 15:10 - 00000000 ____D () G:\Qoobox
2015-04-05 15:03 - 2015-04-05 15:09 - 00000000 ____D () G:\Windows\erdnt
2015-04-05 15:03 - 2011-06-26 08:45 - 00256000 _____ () G:\Windows\PEV.exe
2015-04-05 15:03 - 2010-11-07 19:20 - 00208896 _____ () G:\Windows\MBR.exe
2015-04-05 15:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) G:\Windows\NIRCMD.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) G:\Windows\SWREG.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) G:\Windows\SWSC.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00098816 _____ () G:\Windows\sed.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00080412 _____ () G:\Windows\grep.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00068096 _____ () G:\Windows\zip.exe
2015-04-05 15:01 - 2015-04-05 15:01 - 05617096 ____R (Swearware) G:\Users\mse13ssd\Desktop\ComboFix.exe
2015-04-05 13:19 - 2015-04-05 13:19 - 00279353 _____ () G:\Users\mse13ssd\Desktop\Gmer.txt
2015-04-05 13:10 - 2015-04-05 13:11 - 00380416 _____ () G:\Users\mse13ssd\Downloads\liqvrrec.exe
2015-04-05 13:02 - 2015-04-05 19:37 - 00000000 ____D () G:\FRST
2015-04-05 13:02 - 2015-04-05 13:03 - 00048734 _____ () G:\Users\mse13ssd\Downloads\FRST.txt
2015-04-05 13:02 - 2015-04-05 13:03 - 00024876 _____ () G:\Users\mse13ssd\Downloads\Addition.txt
2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Downloads\FRST64 (1).exe
2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Desktop\FRST64.exe
2015-04-05 12:59 - 2015-04-05 12:59 - 00000478 _____ () G:\Users\mse13ssd\Downloads\defogger_disable.log
2015-04-05 12:59 - 2015-04-05 12:59 - 00000000 _____ () G:\Users\mse13ssd\defogger_reenable
2015-04-05 12:57 - 2015-04-05 12:57 - 00050477 _____ () G:\Users\mse13ssd\Downloads\Defogger.exe
2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (2).exe
2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (1).exe
2015-04-05 03:38 - 2015-04-05 18:38 - 00000000 ____D () G:\AdwCleaner
2015-04-05 03:37 - 2015-04-05 03:38 - 02208768 _____ () G:\Users\mse13ssd\Desktop\adwcleaner_4.200.exe
2015-03-31 05:26 - 2015-03-31 05:26 - 00008930 _____ () G:\Users\mse13ssd\Downloads\smime (1).p7s
2015-03-31 02:41 - 2015-03-31 02:41 - 00000069 _____ () G:\Users\mse13ssd\Desktop\BADLOGIC (German Fandub) - YouTube.url
2015-03-28 00:47 - 2015-03-28 00:47 - 00012288 _____ () G:\Users\mse13ssd\Downloads\Qual-Fraktal.xls
2015-03-27 07:14 - 2015-03-27 07:14 - 00000000 ____D () G:\Users\mse13ssd\Desktop\SciLor's Grooveshark.com Downloader
2015-03-26 21:20 - 2015-03-26 21:20 - 671367548 _____ () G:\Windows\MEMORY.DMP
2015-03-26 21:20 - 2015-03-26 21:20 - 00274624 _____ () G:\Windows\Minidump\032615-29718-01.dmp
2015-03-25 04:31 - 2015-03-25 04:31 - 00002123 _____ () G:\Users\Public\Desktop\CONTRACT J.A.C.K. .lnk
2015-03-25 04:05 - 2015-03-25 04:05 - 00000000 ____D () G:\Program Files (x86)\Sierra
2015-03-25 04:04 - 2015-03-25 04:04 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra
2015-03-25 04:00 - 2003-06-26 10:45 - 00499712 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcp71.dll
2015-03-25 04:00 - 2003-06-26 10:45 - 00348160 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcr71.dll
2015-03-25 04:00 - 2003-03-19 07:20 - 01060864 ____N (Microsoft Corporation) G:\Windows\SysWOW64\mfc71.dll
2015-03-22 18:27 - 2015-03-22 18:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files\Microsoft Silverlight
2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files (x86)\Microsoft Silverlight
2015-03-21 10:33 - 2015-03-21 10:33 - 13087456 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\Silverlight_x64.exe
2015-03-18 17:29 - 2015-03-18 17:29 - 00002023 _____ () G:\Users\mse13ssd\Desktop\Windows Phone-Desktopanwendung.lnk
2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Phone
2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\Program Files (x86)\Windows Phone
2015-03-18 17:25 - 2015-03-18 17:25 - 06745792 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\WindowsPhone.exe
2015-03-18 17:25 - 2015-03-18 17:25 - 00000000 ____D () G:\ProgramData\Applications
2015-03-16 19:19 - 2015-03-16 19:19 - 00001535 _____ () G:\Users\mse13ssd\Free YouTube to MP3 Converter.lnk
2015-03-15 17:32 - 2015-04-05 19:37 - 00001114 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-15 17:32 - 2015-04-05 18:39 - 00001110 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-15 17:32 - 2015-03-15 17:32 - 00004110 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-03-15 17:32 - 2015-03-15 17:32 - 00003858 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-03-15 17:32 - 2015-03-15 17:32 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2015-03-15 17:31 - 2015-03-15 17:31 - 00880208 _____ (Google Inc.) G:\Users\mse13ssd\Downloads\GoogleEarthSetup.exe
2015-03-14 07:06 - 2015-03-14 07:33 - 82044588 _____ () G:\Users\mse13ssd\Downloads\ES-X_DE.rar.crdownload
2015-03-12 09:28 - 2015-02-03 05:34 - 05554104 _____ (Microsoft Corporation) G:\Windows\system32\ntoskrnl.exe
2015-03-12 09:28 - 2015-02-03 05:34 - 00693176 _____ (Microsoft Corporation) G:\Windows\system32\winload.efi
2015-03-12 09:28 - 2015-02-03 05:34 - 00094656 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\mountmgr.sys
2015-03-12 09:28 - 2015-02-03 05:33 - 00616360 _____ (Microsoft Corporation) G:\Windows\system32\winresume.efi
2015-03-12 09:28 - 2015-02-03 05:31 - 14632960 _____ (Microsoft Corporation) G:\Windows\system32\wmp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 04121600 _____ (Microsoft Corporation) G:\Windows\system32\mf.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 01574400 _____ (Microsoft Corporation) G:\Windows\system32\quartz.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00782848 _____ (Microsoft Corporation) G:\Windows\system32\wmdrmsdk.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00641024 _____ (Microsoft Corporation) G:\Windows\system32\msscp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00503808 _____ (Microsoft Corporation) G:\Windows\system32\srcore.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00500224 _____ (Microsoft Corporation) G:\Windows\system32\AUDIOKSE.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00432128 _____ (Microsoft Corporation) G:\Windows\system32\mfplat.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00371712 _____ (Microsoft Corporation) G:\Windows\system32\qdvd.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00325632 _____ (Microsoft Corporation) G:\Windows\system32\msnetobj.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00229376 _____ (Microsoft Corporation) G:\Windows\system32\wintrust.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00206848 _____ (Microsoft Corporation) G:\Windows\system32\mfps.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00188416 _____ (Microsoft Corporation) G:\Windows\system32\pcasvc.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00063488 _____ (Microsoft Corporation) G:\Windows\system32\setbcdlocale.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00050176 _____ (Microsoft Corporation) G:\Windows\system32\srclient.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00037376 _____ (Microsoft Corporation) G:\Windows\system32\pcadm.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\msmmsp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\spwmp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\msdxm.ocx
2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\dxmasf.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 12625920 _____ (Microsoft Corporation) G:\Windows\system32\wmploc.DLL
2015-03-12 09:28 - 2015-02-03 05:30 - 01480192 _____ (Microsoft Corporation) G:\Windows\system32\crypt32.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 01202176 _____ (Microsoft Corporation) G:\Windows\system32\drmv2clt.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 01069056 _____ (Microsoft Corporation) G:\Windows\system32\cryptui.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00842240 _____ (Microsoft Corporation) G:\Windows\system32\blackbox.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00680960 _____ (Microsoft Corporation) G:\Windows\system32\audiosrv.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00631808 _____ (Microsoft Corporation) G:\Windows\system32\evr.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00497664 _____ (Microsoft Corporation) G:\Windows\system32\drmmgrtn.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00440832 _____ (Microsoft Corporation) G:\Windows\system32\AudioEng.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00296960 _____ (Microsoft Corporation) G:\Windows\system32\rstrui.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00296448 _____ (Microsoft Corporation) G:\Windows\system32\AudioSes.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00284672 _____ (Microsoft Corporation) G:\Windows\system32\EncDump.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00187904 _____ (Microsoft Corporation) G:\Windows\system32\cryptsvc.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00146944 _____ (Microsoft Corporation) G:\Windows\system32\appidpolicyconverter.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00140288 _____ (Microsoft Corporation) G:\Windows\system32\cryptnet.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00126464 _____ (Microsoft Corporation) G:\Windows\system32\audiodg.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00112640 _____ (Microsoft Corporation) G:\Windows\system32\smss.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00082432 _____ (Microsoft Corporation) G:\Windows\system32\cryptsp.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00058880 _____ (Microsoft Corporation) G:\Windows\system32\appidapi.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00055808 _____ (Microsoft Corporation) G:\Windows\system32\rrinstaller.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00043520 _____ (Microsoft Corporation) G:\Windows\system32\csrsrv.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00032256 _____ (Microsoft Corporation) G:\Windows\system32\appidsvc.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00024576 _____ (Microsoft Corporation) G:\Windows\system32\mfpmp.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00017920 _____ (Microsoft Corporation) G:\Windows\system32\appidcertstorecheck.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\pcawrk.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\pcalua.exe
2015-03-12 09:28 - 2015-02-03 05:29 - 00008704 _____ (Microsoft Corporation) G:\Windows\system32\pcaevts.dll
2015-03-12 09:28 - 2015-02-03 05:28 - 00006656 _____ (Microsoft Corporation) G:\Windows\system32\apisetschema.dll
2015-03-12 09:28 - 2015-02-03 05:28 - 00002048 _____ (Microsoft Corporation) G:\Windows\system32\mferror.dll
2015-03-12 09:28 - 2015-02-03 05:19 - 00663552 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\PEAuth.sys
2015-03-12 09:28 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntkrnlpa.exe
2015-03-12 09:28 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntoskrnl.exe
2015-03-12 09:28 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mf.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) G:\Windows\SysWOW64\quartz.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) G:\Windows\SysWOW64\crypt32.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptui.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmv2clt.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\blackbox.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmdrmsdk.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) G:\Windows\SysWOW64\qdvd.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msscp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\evr.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AUDIOKSE.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmmgrtn.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioEng.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfplat.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msnetobj.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioSes.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wintrust.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsvc.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptnet.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfps.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) G:\Windows\SysWOW64\appidapi.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) G:\Windows\SysWOW64\srclient.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\spwmp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msdxm.ocx
2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxmasf.dll
2015-03-12 09:28 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmploc.DLL
2015-03-12 09:28 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\rrinstaller.exe
2015-03-12 09:28 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfpmp.exe
2015-03-12 09:28 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mferror.dll
2015-03-12 09:28 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\apisetschema.dll
2015-03-12 09:28 - 2015-02-03 04:32 - 00061440 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\appid.sys
2015-03-12 09:28 - 2014-11-01 00:24 - 00619056 _____ (Microsoft Corporation) G:\Windows\system32\winload.exe
2015-03-12 09:28 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) G:\Windows\system32\winresume.exe
2015-03-12 09:28 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) G:\Windows\system32\ci.dll
2015-03-12 09:27 - 2015-03-06 07:56 - 00155576 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecpkg.sys
2015-03-12 09:27 - 2015-03-06 07:56 - 00095680 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecdd.sys
2015-03-12 09:27 - 2015-03-06 07:42 - 01461760 _____ (Microsoft Corporation) G:\Windows\system32\lsasrv.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00728064 _____ (Microsoft Corporation) G:\Windows\system32\kerberos.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00341504 _____ (Microsoft Corporation) G:\Windows\system32\schannel.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00314880 _____ (Microsoft Corporation) G:\Windows\system32\msv1_0.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00309760 _____ (Microsoft Corporation) G:\Windows\system32\ncrypt.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00210944 _____ (Microsoft Corporation) G:\Windows\system32\wdigest.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00136192 _____ (Microsoft Corporation) G:\Windows\system32\sspicli.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00086528 _____ (Microsoft Corporation) G:\Windows\system32\TSpkg.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00029184 _____ (Microsoft Corporation) G:\Windows\system32\sspisrv.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00028160 _____ (Microsoft Corporation) G:\Windows\system32\secur32.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00022016 _____ (Microsoft Corporation) G:\Windows\system32\credssp.dll
2015-03-12 09:27 - 2015-03-06 07:41 - 00064000 _____ (Microsoft Corporation) G:\Windows\system32\auditpol.exe
2015-03-12 09:27 - 2015-03-06 07:41 - 00031232 _____ (Microsoft Corporation) G:\Windows\system32\lsass.exe
2015-03-12 09:27 - 2015-03-06 07:39 - 00060416 _____ (Microsoft Corporation) G:\Windows\system32\msobjs.dll
2015-03-12 09:27 - 2015-03-06 07:38 - 00146432 _____ (Microsoft Corporation) G:\Windows\system32\msaudite.dll
2015-03-12 09:27 - 2015-03-06 07:36 - 00686080 _____ (Microsoft Corporation) G:\Windows\system32\adtschema.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) G:\Windows\SysWOW64\kerberos.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msv1_0.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) G:\Windows\SysWOW64\schannel.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ncrypt.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wdigest.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) G:\Windows\SysWOW64\TSpkg.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\secur32.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\credssp.dll
2015-03-12 09:27 - 2015-03-06 07:09 - 00096768 _____ (Microsoft Corporation) G:\Windows\SysWOW64\sspicli.dll
2015-03-12 09:27 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\auditpol.exe
2015-03-12 09:27 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msaudite.dll
2015-03-12 09:27 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msobjs.dll
2015-03-12 09:27 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) G:\Windows\SysWOW64\adtschema.dll
2015-03-12 09:27 - 2015-02-24 05:15 - 00389800 _____ (Microsoft Corporation) G:\Windows\system32\iedkcs32.dll
2015-03-12 09:27 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iedkcs32.dll
2015-03-12 09:27 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.dll
2015-03-12 09:27 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieframe.dll
2015-03-12 09:27 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtmsft.dll
2015-03-12 09:27 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtrans.dll
2015-03-12 09:27 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.dll
2015-03-12 09:27 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) G:\Windows\system32\mshtmled.dll
2015-03-12 09:27 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmled.dll
2015-03-12 09:27 - 2015-02-20 06:41 - 00041984 _____ (Microsoft Corporation) G:\Windows\system32\lpk.dll
2015-03-12 09:27 - 2015-02-20 06:40 - 00100864 _____ (Microsoft Corporation) G:\Windows\system32\fontsub.dll
2015-03-12 09:27 - 2015-02-20 06:40 - 00046080 _____ (Adobe Systems) G:\Windows\system32\atmlib.dll
2015-03-12 09:27 - 2015-02-20 06:40 - 00014336 _____ (Microsoft Corporation) G:\Windows\system32\dciman32.dll
2015-03-12 09:27 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\fontsub.dll
2015-03-12 09:27 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) G:\Windows\SysWOW64\atmlib.dll
2015-03-12 09:27 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dciman32.dll
2015-03-12 09:27 - 2015-02-20 06:12 - 00025600 _____ (Microsoft Corporation) G:\Windows\SysWOW64\lpk.dll
2015-03-12 09:27 - 2015-02-20 05:29 - 00372224 _____ (Adobe Systems Incorporated) G:\Windows\system32\atmfd.dll
2015-03-12 09:27 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\atmfd.dll
2015-03-12 09:27 - 2015-02-20 05:06 - 02724864 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.tlb
2015-03-12 09:27 - 2015-02-20 05:05 - 00004096 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollectorres.dll
2015-03-12 09:27 - 2015-02-20 04:50 - 00066560 _____ (Microsoft Corporation) G:\Windows\system32\iesetup.dll
2015-03-12 09:27 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) G:\Windows\system32\vbscript.dll
2015-03-12 09:27 - 2015-02-20 04:49 - 00048640 _____ (Microsoft Corporation) G:\Windows\system32\ieetwproxystub.dll
2015-03-12 09:27 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) G:\Windows\system32\iertutil.dll
2015-03-12 09:27 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) G:\Windows\system32\MshtmlDac.dll
2015-03-12 09:27 - 2015-02-20 04:41 - 00054784 _____ (Microsoft Corporation) G:\Windows\system32\jsproxy.dll
2015-03-12 09:27 - 2015-02-20 04:40 - 00034304 _____ (Microsoft Corporation) G:\Windows\system32\iernonce.dll
2015-03-12 09:27 - 2015-02-20 04:36 - 00633856 _____ (Microsoft Corporation) G:\Windows\system32\ieui.dll
2015-03-12 09:27 - 2015-02-20 04:35 - 00144384 _____ (Microsoft Corporation) G:\Windows\system32\ieUnatt.exe
2015-03-12 09:27 - 2015-02-20 04:35 - 00114688 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollector.exe
2015-03-12 09:27 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) G:\Windows\system32\jscript9diag.dll
2015-03-12 09:27 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) G:\Windows\system32\jscript9.dll
2015-03-12 09:27 - 2015-02-20 04:26 - 00968704 _____ (Microsoft Corporation) G:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-12 09:27 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.tlb
2015-03-12 09:27 - 2015-02-20 04:22 - 00490496 _____ (Microsoft Corporation) G:\Windows\system32\dxtmsft.dll
2015-03-12 09:27 - 2015-02-20 04:13 - 00077824 _____ (Microsoft Corporation) G:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-12 09:27 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) G:\Windows\SysWOW64\vbscript.dll
2015-03-12 09:27 - 2015-02-20 04:08 - 00199680 _____ (Microsoft Corporation) G:\Windows\system32\msrating.dll
2015-03-12 09:27 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iesetup.dll
2015-03-12 09:27 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieetwproxystub.dll
2015-03-12 09:27 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) G:\Windows\SysWOW64\MshtmlDac.dll
2015-03-12 09:27 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) G:\Windows\system32\dxtrans.dll
2015-03-12 09:27 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iertutil.dll
2015-03-12 09:27 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jsproxy.dll
2015-03-12 09:27 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iernonce.dll
2015-03-12 09:27 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieui.dll
2015-03-12 09:27 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9diag.dll
2015-03-12 09:27 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieUnatt.exe
2015-03-12 09:27 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) G:\Windows\system32\msfeeds.dll
2015-03-12 09:27 - 2015-02-20 03:49 - 00718848 _____ (Microsoft Corporation) G:\Windows\system32\ie4uinit.exe
2015-03-12 09:27 - 2015-02-20 03:47 - 01359360 _____ (Microsoft Corporation) G:\Windows\system32\mshtmlmedia.dll
2015-03-12 09:27 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) G:\Windows\system32\inetcpl.cpl
2015-03-12 09:27 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) G:\Windows\system32\ieframe.dll
2015-03-12 09:27 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-03-12 09:27 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msrating.dll
2015-03-12 09:27 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9.dll
2015-03-12 09:27 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) G:\Windows\system32\wininet.dll
2015-03-12 09:27 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) G:\Windows\SysWOW64\inetcpl.cpl
2015-03-12 09:27 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msfeeds.dll
2015-03-12 09:27 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmlmedia.dll
2015-03-12 09:27 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) G:\Windows\system32\urlmon.dll
2015-03-12 09:27 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) G:\Windows\system32\ieapfltr.dll
2015-03-12 09:27 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wininet.dll
2015-03-12 09:27 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) G:\Windows\SysWOW64\urlmon.dll
2015-03-12 09:27 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieapfltr.dll
2015-03-12 09:27 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) G:\Windows\SysWOW64\shell32.dll
2015-03-12 09:27 - 2015-02-13 07:22 - 14177280 _____ (Microsoft Corporation) G:\Windows\system32\shell32.dll
2015-03-12 09:27 - 2015-02-03 05:31 - 01424896 _____ (Microsoft Corporation) G:\Windows\system32\WindowsCodecs.dll
2015-03-12 09:27 - 2015-02-03 05:31 - 00215552 _____ (Microsoft Corporation) G:\Windows\system32\ubpm.dll
2015-03-12 09:27 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WindowsCodecs.dll
2015-03-12 09:27 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ubpm.dll
2015-03-12 09:27 - 2015-01-31 05:48 - 03179520 _____ (Microsoft Corporation) G:\Windows\system32\rdpcorets.dll
2015-03-12 09:27 - 2015-01-31 05:48 - 00016384 _____ (Microsoft Corporation) G:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-12 09:27 - 2015-01-31 01:56 - 00459336 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\cng.sys
2015-03-12 09:27 - 2015-01-31 01:56 - 00243200 _____ (Microsoft Corporation) G:\Windows\system32\rdpudd.dll
2015-03-12 09:27 - 2015-01-17 04:48 - 01067520 _____ (Microsoft Corporation) G:\Windows\system32\msctf.dll
2015-03-12 09:27 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msctf.dll
2015-03-12 09:26 - 2015-02-26 05:25 - 03204096 _____ (Microsoft Corporation) G:\Windows\system32\win32k.sys
2015-03-12 09:26 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) G:\Windows\system32\WMPhoto.dll
2015-03-12 09:26 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WMPhoto.dll
2015-03-10 01:20 - 2015-03-10 01:20 - 00001002 _____ () G:\Users\mse13ssd\Downloads\BAHN_Fahrplan_20150609.ics
2015-03-09 11:16 - 2015-03-09 11:56 - 124202474 _____ () G:\Users\mse13ssd\Downloads\#0325#.rar
2015-03-08 09:43 - 2015-03-08 09:43 - 01230365 _____ () G:\Users\mse13ssd\Downloads\2 (1).wmv
2015-03-08 09:43 - 2015-03-08 09:43 - 01222357 _____ () G:\Users\mse13ssd\Downloads\3.wmv
2015-03-06 16:14 - 2015-03-06 16:51 - 111138743 _____ () G:\Users\mse13ssd\Downloads\julins2014.rar

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-05 18:47 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-05 18:47 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-05 18:45 - 2009-07-14 19:58 - 00700986 _____ () G:\Windows\system32\perfh007.dat
2015-04-05 18:45 - 2009-07-14 19:58 - 00149886 _____ () G:\Windows\system32\perfc007.dat
2015-04-05 18:45 - 2009-07-14 07:13 - 01619284 _____ () G:\Windows\system32\PerfStringBackup.INI
2015-04-05 18:43 - 2014-05-17 10:22 - 01378372 _____ () G:\Windows\WindowsUpdate.log
2015-04-05 18:40 - 2014-07-13 00:21 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Raptr
2015-04-05 18:39 - 2014-05-17 22:03 - 00000000 _____ () G:\Windows\system32\Drivers\lvuvc.hs
2015-04-05 18:39 - 2014-05-17 15:20 - 00033022 _____ () G:\Windows\PFRO.log
2015-04-05 18:39 - 2009-07-14 07:08 - 00000006 ____H () G:\Windows\Tasks\SA.DAT
2015-04-05 18:39 - 2009-07-14 06:51 - 00055579 _____ () G:\Windows\setupact.log
2015-04-05 18:19 - 2015-03-05 14:19 - 00129752 _____ (Malwarebytes Corporation) G:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-05 15:10 - 2009-07-14 05:20 - 00000000 __RHD () G:\Users\Default
2015-04-05 15:09 - 2009-07-14 04:34 - 00000215 _____ () G:\Windows\system.ini
2015-04-05 13:19 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\NDF
2015-04-05 13:06 - 2014-05-17 22:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Skype
2015-04-05 12:59 - 2014-05-17 11:54 - 00000000 ____D () G:\Users\mse13ssd
2015-04-05 03:26 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\Web
2015-04-05 02:39 - 2014-05-17 15:57 - 00004182 _____ () G:\Windows\System32\Tasks\avast! Emergency Update
2015-04-04 14:30 - 2014-05-17 20:13 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\TS3Client
2015-04-02 01:34 - 2009-07-14 07:32 - 00000000 ____D () G:\Windows\system32\FxsTmp
2015-03-30 17:36 - 2015-02-28 05:38 - 00000000 ____D () G:\Users\mse13ssd\Desktop\aufgeräumt
2015-03-30 08:10 - 2014-11-01 08:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\25372
2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\DivX
2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
2015-03-30 04:33 - 2014-08-24 02:00 - 00000000 ____D () G:\ProgramData\DivX
2015-03-30 04:33 - 2014-05-17 15:57 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2015-03-30 04:33 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\AppCompat
2015-03-30 04:32 - 2014-08-24 02:01 - 00000000 ____D () G:\Program Files\DivX
2015-03-30 04:32 - 2014-08-24 02:00 - 00000000 ____D () G:\Program Files (x86)\DivX
2015-03-30 04:32 - 2014-06-18 17:31 - 00000000 ____D () G:\Program Files (x86)\Microsoft Office
2015-03-30 04:32 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\registration
2015-03-30 03:27 - 2009-07-14 20:18 - 00000000 ___RD () G:\Users\Public\Recorded TV
2015-03-26 21:20 - 2014-10-12 12:01 - 00000000 ____D () G:\Windows\Minidump
2015-03-26 18:51 - 2014-07-13 00:21 - 00000000 ____D () G:\Program Files (x86)\Raptr
2015-03-26 09:13 - 2014-06-18 17:31 - 00000000 ____D () G:\ProgramData\Microsoft Help
2015-03-22 18:29 - 2014-05-17 12:40 - 00070368 _____ () G:\Users\mse13ssd\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-22 18:29 - 2009-07-14 06:45 - 00307752 _____ () G:\Windows\system32\FNTCACHE.DAT
2015-03-22 18:25 - 2014-06-18 17:32 - 00000000 ____D () G:\Program Files (x86)\Microsoft Works
2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Google
2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Program Files (x86)\Google
2015-03-15 14:09 - 2014-08-24 13:49 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Adobe
2015-03-15 14:09 - 2014-05-17 15:53 - 00778928 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerApp.exe
2015-03-15 14:09 - 2014-05-17 15:53 - 00142512 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-03-15 05:05 - 2014-06-21 18:28 - 00000000 ____D () G:\Program Files (x86)\Steam
2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Glyph
2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glyph
2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Program Files (x86)\Glyph
2015-03-13 10:32 - 2009-07-14 07:09 - 00000000 ____D () G:\Windows\System32\Tasks\WPD
2015-03-12 12:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\rescache
2015-03-12 09:37 - 2015-02-28 09:01 - 00000000 ___RD () G:\Users\mse13ssd\Virtual Machines
2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\SysWOW64\Dism
2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\Dism
2015-03-12 09:31 - 2014-05-17 20:36 - 00000000 ____D () G:\Windows\system32\MRT
2015-03-12 09:29 - 2014-05-17 20:36 - 122905848 _____ (Microsoft Corporation) G:\Windows\system32\MRT.exe
2015-03-06 13:47 - 2014-10-13 17:23 - 00000000 ___RD () G:\Program Files (x86)\Skype
2015-03-06 13:47 - 2014-05-17 22:15 - 00000000 ____D () G:\ProgramData\Skype

==================== Files in the root of some directories =======

2014-10-02 16:29 - 2015-02-28 12:40 - 14286848 _____ () G:\Users\mse13ssd\AppData\Roaming\Sandra.mdb
2015-01-23 13:40 - 2015-01-23 13:40 - 0003584 _____ () G:\Users\mse13ssd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-01 14:58 - 2015-01-01 14:58 - 0007605 _____ () G:\Users\mse13ssd\AppData\Local\Resmon.ResmonCfg

Some content of TEMP:
====================
G:\Users\mse13ssd\AppData\Local\Temp\Quarantine.exe
G:\Users\mse13ssd\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

G:\Windows\System32\winlogon.exe => File is digitally signed
G:\Windows\System32\wininit.exe => File is digitally signed
G:\Windows\SysWOW64\wininit.exe => File is digitally signed
G:\Windows\explorer.exe => File is digitally signed
G:\Windows\SysWOW64\explorer.exe => File is digitally signed
G:\Windows\System32\svchost.exe => File is digitally signed
G:\Windows\SysWOW64\svchost.exe => File is digitally signed
G:\Windows\System32\services.exe => File is digitally signed
G:\Windows\System32\User32.dll => File is digitally signed
G:\Windows\SysWOW64\User32.dll => File is digitally signed
G:\Windows\System32\userinit.exe => File is digitally signed
G:\Windows\SysWOW64\userinit.exe => File is digitally signed
G:\Windows\System32\rpcss.dll => File is digitally signed
G:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-04 00:45

==================== End Of Log ============================
         
--- --- ---


Alt 06.04.2015, 11:05   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen - Standard

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
--> Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen

Alt 07.04.2015, 09:40   #7
MSE XIII
 
Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen - Standard

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen



Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=9034e1cd59c35d4897ca59e7ac9185aa
# engine=23253
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-04-06 10:19:52
# local_time=2015-04-07 12:19:52 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='avast! Antivirus'
# compatibility_mode=783 16777213 100 95 676013 28023765 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 16002 179988642 0 0
# scanned=590292
# found=129
# cleaned=0
# scan_time=15599
sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe"
sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe"
sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe"
sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe"
sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll"
sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll"
sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe"
sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe"
sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe"
sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe"
sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe"
sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Temp\ct3297265\ism.exe"
sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll"
sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll"
sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe"
sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe"
sh=3BF736C24033F3E9302AD9339AB24946B84DBB22 ft=1 fh=16a157c9bf933752 vn="Variante von Win32/Toolbar.SearchSuite.Z evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe"
sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi"
sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe"
sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi"
sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe"
sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi"
sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe"
sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi"
sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe"
sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi"
sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe"
sh=A151080AB2A5C8FECCE625974FFE1EEEC7C40637 ft=1 fh=a0dd2ab90579dc22 vn="Variante von Win32/GetNow.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe"
sh=8A9C345E13E286F64B09520E8B374BE0F41FF958 ft=1 fh=6add8ca28ee0da1a vn="Win32/AdWare.1ClickDownload.AT Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\Der_knallharte_Prinzipal.exe"
sh=B68BF0E698A41B385F988BF936586CBEFAADF1B2 ft=1 fh=8f23a3e3ad9fbfbf vn="Variante von Win32/Toolbar.SearchSuite.J evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\jZipSetup-r113-n-bc.exe"
sh=F1157163FF747E652B9F0D5FFF7C122B04E702CA ft=1 fh=13352cc938f5dd09 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe"
sh=46100C3A7E115EA5D75C1E413D3735DEF566BC56 ft=1 fh=bc1f79bd33786c53 vn="Win32/Toolbar.Conduit.AE evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\Raidcall_TSV45QFV6.exe"
sh=C90DC54D89385CA31BDE44E879E11A498AAEFB8B ft=1 fh=bb5adeb19de8958e vn="Variante von Win32/SoftonicDownloader.F evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe"
sh=2DDE7AFBAD3F2903ED3BB46AD82698FD4371270C ft=1 fh=e68f4e0bfda3a157 vn="Variante von Win32/Amonetize.AG evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe"
sh=A08B6EC51DDD212A28C63680D05CCAB708CC09A9 ft=1 fh=8b799a2f1c89ab47 vn="Win32/AdWare.1ClickDownload.AT Anwendung" ac=I fn="C:\Documents and Settings\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe"
sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe"
sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe"
sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe"
sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe"
sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll"
sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll"
sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe"
sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe"
sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe"
sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe"
sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe"
sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe"
sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll"
sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll"
sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe"
sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe"
sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe"
sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe"
sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe"
sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\ct3297265\ism.exe"
sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll"
sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll"
sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe"
sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe"
sh=3BF736C24033F3E9302AD9339AB24946B84DBB22 ft=1 fh=16a157c9bf933752 vn="Variante von Win32/Toolbar.SearchSuite.Z evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe"
sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi"
sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe"
sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi"
sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe"
sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi"
sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe"
sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi"
sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe"
sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi"
sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe"
sh=A151080AB2A5C8FECCE625974FFE1EEEC7C40637 ft=1 fh=a0dd2ab90579dc22 vn="Variante von Win32/GetNow.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe"
sh=8A9C345E13E286F64B09520E8B374BE0F41FF958 ft=1 fh=6add8ca28ee0da1a vn="Win32/AdWare.1ClickDownload.AT Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\Der_knallharte_Prinzipal.exe"
sh=B68BF0E698A41B385F988BF936586CBEFAADF1B2 ft=1 fh=8f23a3e3ad9fbfbf vn="Variante von Win32/Toolbar.SearchSuite.J evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\jZipSetup-r113-n-bc.exe"
sh=F1157163FF747E652B9F0D5FFF7C122B04E702CA ft=1 fh=13352cc938f5dd09 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe"
sh=46100C3A7E115EA5D75C1E413D3735DEF566BC56 ft=1 fh=bc1f79bd33786c53 vn="Win32/Toolbar.Conduit.AE evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\Raidcall_TSV45QFV6.exe"
sh=C90DC54D89385CA31BDE44E879E11A498AAEFB8B ft=1 fh=bb5adeb19de8958e vn="Variante von Win32/SoftonicDownloader.F evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe"
sh=2DDE7AFBAD3F2903ED3BB46AD82698FD4371270C ft=1 fh=e68f4e0bfda3a157 vn="Variante von Win32/Amonetize.AG evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe"
sh=A08B6EC51DDD212A28C63680D05CCAB708CC09A9 ft=1 fh=8b799a2f1c89ab47 vn="Win32/AdWare.1ClickDownload.AT Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe"
sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe"
sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe"
sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe"
sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe"
sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll"
sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll"
sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe"
sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe"
sh=58B5ECA6356C4BE712A4376A3941E693B83E3C3F ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\HDvid-Codec V9.0\51356.crx"
sh=00A559F12816F1E9B5C6C6AEDF07D52556898077 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\HDvid-Codec V9.0\51356.xpi"
sh=E16893EC0AB084A8DB5F87A5C9A29B0B2846D7F9 ft=1 fh=cca47823c3292533 vn="Variante von Win32/Toolbar.Iminent.C evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\Iminent\inst\Bootstrapper\IminentUninstall.exe"
sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe"
sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe"
sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe"
sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\Temp\ct3297265\ism.exe"
sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll"
sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll"
sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe"
sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe"
sh=3BF736C24033F3E9302AD9339AB24946B84DBB22 ft=1 fh=16a157c9bf933752 vn="Variante von Win32/Toolbar.SearchSuite.Z evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe"
sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi"
sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe"
sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi"
sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe"
sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi"
sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe"
sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi"
sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe"
sh=F7EAA26375D35D1D3ACB3FC520D7CD1363EECD1E ft=0 fh=0000000000000000 vn="Win32/Toolbar.Conduit.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi"
sh=303754A4FA23B9DB2A4B16EBF11185620655C6CF ft=1 fh=78a191b07b4b8f54 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe"
sh=A151080AB2A5C8FECCE625974FFE1EEEC7C40637 ft=1 fh=a0dd2ab90579dc22 vn="Variante von Win32/GetNow.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe"
sh=8A9C345E13E286F64B09520E8B374BE0F41FF958 ft=1 fh=6add8ca28ee0da1a vn="Win32/AdWare.1ClickDownload.AT Anwendung" ac=I fn="C:\Users\mse13\Downloads\Der_knallharte_Prinzipal.exe"
sh=B68BF0E698A41B385F988BF936586CBEFAADF1B2 ft=1 fh=8f23a3e3ad9fbfbf vn="Variante von Win32/Toolbar.SearchSuite.J evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Downloads\jZipSetup-r113-n-bc.exe"
sh=F1157163FF747E652B9F0D5FFF7C122B04E702CA ft=1 fh=13352cc938f5dd09 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe"
sh=46100C3A7E115EA5D75C1E413D3735DEF566BC56 ft=1 fh=bc1f79bd33786c53 vn="Win32/Toolbar.Conduit.AE evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Downloads\Raidcall_TSV45QFV6.exe"
sh=C90DC54D89385CA31BDE44E879E11A498AAEFB8B ft=1 fh=bb5adeb19de8958e vn="Variante von Win32/SoftonicDownloader.F evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe"
sh=2DDE7AFBAD3F2903ED3BB46AD82698FD4371270C ft=1 fh=e68f4e0bfda3a157 vn="Variante von Win32/Amonetize.AG evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe"
sh=A08B6EC51DDD212A28C63680D05CCAB708CC09A9 ft=1 fh=8b799a2f1c89ab47 vn="Win32/AdWare.1ClickDownload.AT Anwendung" ac=I fn="C:\Users\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe"
sh=2FCDEB27C5315760C1114781FC2398499E431D24 ft=1 fh=c40b67351baa4f5e vn="Variante von Win32/Toolbar.Iminent.K evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe"
sh=E72D148A47B5C463732C9ABF68C4B8D902EF8622 ft=1 fh=4e1400c3bce382c7 vn="Variante von Win32/Adware.Synatix.A Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe"
sh=D1937AEB8ADBC5C7EB69C1AEFEEA4DEC6A1A90B5 ft=1 fh=e6c02fe7d3021daa vn="Win32/Wajam.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe"
sh=5E8AA35E52FA6EE0DCDBEA79E79DC36F72D959D5 ft=1 fh=eb3d7c8b3c91213d vn="Win32/Toolbar.Conduit.AP evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe"
sh=1A1FBE219B280494DAD078D673575D27DC8D1610 ft=1 fh=f5c8e958d12001c5 vn="Variante von Win32/Toolbar.SearchSuite.P evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll"
sh=DFB17FD98C37594BDD308479068492297EDB28F7 ft=1 fh=fa1ccee1e1a4e00a vn="Win32/Soffer.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll"
sh=FED7CAA2E24771B66065C8D30131FC8037B6BD2A ft=1 fh=b41296876ed186e5 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe"
sh=848C686280EAA04B172FCCFFBD312132A0C46172 ft=1 fh=7764b0effb0b9556 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe"
sh=31CE21FE36C11E107A6E315EFE1875743809B4CC ft=1 fh=48abcfa6ce4a4014 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="G:\AdwCleaner\Quarantine\G\Users\mse13ssd\AppData\Local\Temp\OCS\ocs_v71b.exe.vir"
sh=1153F638CB1AE4E7B26A1472F18D52A8603E6ACF ft=1 fh=53fcb0c52b4f621b vn="Variante von Win32/Amonetize.BY evtl. unerwünschte Anwendung" ac=I fn="G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\File System\002\t\00\00000000"
sh=D36B7EB47F1691BF8EAB2EA2805E0D1F1A3791F7 ft=1 fh=88789f35a0bf115b vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="G:\Users\mse13ssd\Downloads\Griffith - CHIP-Installer.exe"
sh=7BA0A01D63E1511F6101A736D157C4D1F885EDEB ft=1 fh=1aba12d0f1f8efc7 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="G:\Users\mse13ssd\Downloads\PDFCreator-2_0_0-setup.exe"
sh=697DB363C754CB50BB2AB17B95EB2633FAEE993F ft=0 fh=0000000000000000 vn="Win32/Emotet.AD Trojaner" ac=I fn="G:\Users\mse13ssd\Downloads\ZustellnachrichtDHL_bestellung_000029937728.zip"
         


diesmal hat es geklappt:

Code:
ATTFilter
 Results of screen317's Security Check version 0.99.99  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
avast! Antivirus   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:````````` 
 Java 8 Update 31  
 Java version 32-bit out of Date! 
 Adobe Flash Player 17.0.0.134  
 Adobe Reader XI  
 Mozilla Firefox (36.0) 
````````Process Check: objlist.exe by Laurent````````  
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast avastui.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive G:  
````````````````````End of Log``````````````````````
         



FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by mse13ssd (administrator) on MSE13SSD-PC on 07-04-2015 10:36:27
Running from G:\Users\mse13ssd\Desktop
Loaded Profiles: mse13ssd (Available profiles: mse13ssd)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) G:\Windows\System32\atiesrxx.exe
(Logitech Inc.) G:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AVAST Software) G:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) G:\Windows\System32\atieclxx.exe
(Apple Inc.) G:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) G:\Program Files\Bonjour\mDNSResponder.exe
(Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
(Logitech Inc.) G:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) G:\Program Files\Windows Sidebar\sidebar.exe
(AVAST Software) G:\Program Files\AVAST Software\Avast\avastui.exe
() G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Advanced Micro Devices Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(Microsoft Corporation) G:\Windows\SysWOW64\notepad.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Launch LCore] => G:\Program Files\Logitech Gaming Software\LCore.exe [10801944 2014-07-28] (Logitech Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => G:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software)
HKLM-x32\...\Run: [DivXMediaServer] => G:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [StartCCC] => G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Raptr] => G:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-03-25] (Raptr, Inc)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => G:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3243151774-2580435505-251407729-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-15] (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-26] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-15] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-26] (Oracle Corporation)
Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - G:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll [2014-10-10] (pdfforge GmbH)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0

FireFox:
========
FF ProfilePath: G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default
FF Plugin: @adobe.com/FlashPlayer -> G:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-15] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> G:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-15] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> G:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2012-04-05] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> G:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-26] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> G:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-26] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> G:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.)
FF Plugin-x32: Adobe Reader -> G:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Extension: Download videos and MP3s from YouTube - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-11-21]
FF Extension: Adblock Plus - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-09]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - G:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - G:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-17]
FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension
FF Extension: PDF Architect 2 Creator - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2014-12-09]
FF HKU\S-1-5-21-3243151774-2580435505-251407729-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF Extension: Download videos and MP3s from YouTube - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-11-21]

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Profile: G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-09]
CHR Extension: (Google Docs) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-09]
CHR Extension: (Google Drive) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-09]
CHR Extension: (Google Voice Search Hotword (Beta)) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-09]
CHR Extension: (YouTube) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-09]
CHR Extension: (Google Search) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-09]
CHR Extension: (Google Sheets) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-09]
CHR Extension: (Google Wallet) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-09]
CHR Extension: (Gmail) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-09]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - G:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-15]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; G:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-15] (AVAST Software)
S2 PDF Architect 2 Creator; G:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH)
S3 SandraAgentSrv; G:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3c\RpcAgentSrv.exe [73712 2014-09-19] (SiSoftware) [File not signed]
R2 WinDefend; G:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; G:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 aswHwid; G:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-15] ()
R2 aswMonFlt; G:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-15] (AVAST Software)
R1 aswRdr; G:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-15] (AVAST Software)
R0 aswRvrt; G:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-15] ()
R1 aswSnx; G:\Windows\system32\drivers\aswSnx.sys [1041168 2014-11-21] (AVAST Software)
R1 aswSP; G:\Windows\system32\drivers\aswSP.sys [427360 2014-07-15] (AVAST Software)
R2 aswStm; G:\Windows\system32\drivers\aswStm.sys [92008 2014-07-15] (AVAST Software)
R0 aswVmm; G:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-15] ()
R3 LGSHidFilt; G:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S3 catchme; \??\G:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-07 10:36 - 2015-04-07 10:36 - 00012219 _____ () G:\Users\mse13ssd\Desktop\FRST.txt
2015-04-07 10:26 - 2015-04-07 10:26 - 00852607 _____ () G:\Users\mse13ssd\Downloads\SecurityCheck (2).exe
2015-04-07 10:19 - 2015-04-07 10:19 - 00008930 _____ () G:\Users\mse13ssd\Downloads\smime (2).p7s
2015-04-06 19:59 - 2015-04-06 19:59 - 02347384 _____ (ESET) G:\Users\mse13ssd\Downloads\esetsmartinstaller_deu (1).exe
2015-04-06 17:43 - 2015-04-06 17:43 - 00852607 _____ () G:\Users\mse13ssd\Downloads\SecurityCheck (1).exe
2015-04-06 17:41 - 2015-04-06 17:41 - 00852607 _____ () G:\Users\mse13ssd\Downloads\SecurityCheck.exe
2015-04-06 12:27 - 2015-04-06 12:27 - 02347384 _____ (ESET) G:\Users\mse13ssd\Downloads\esetsmartinstaller_deu.exe
2015-04-06 12:27 - 2015-04-06 12:27 - 00000000 ____D () G:\Program Files (x86)\ESET
2015-04-05 19:33 - 2015-04-05 19:33 - 00000207 _____ () G:\Windows\tweaking.com-regbackup-MSE13SSD-PC-Windows-7-Home-Premium-(64-bit).dat
2015-04-05 19:33 - 2015-04-05 19:33 - 00000000 ____D () G:\RegBackup
2015-04-05 18:35 - 2015-04-05 18:35 - 02690981 _____ (Thisisu) G:\Users\mse13ssd\Desktop\JRT.exe
2015-04-05 15:10 - 2015-04-05 15:10 - 00011639 _____ () G:\ComboFix.txt
2015-04-05 15:03 - 2015-04-05 15:10 - 00000000 ____D () G:\Qoobox
2015-04-05 15:03 - 2015-04-05 15:09 - 00000000 ____D () G:\Windows\erdnt
2015-04-05 15:03 - 2011-06-26 08:45 - 00256000 _____ () G:\Windows\PEV.exe
2015-04-05 15:03 - 2010-11-07 19:20 - 00208896 _____ () G:\Windows\MBR.exe
2015-04-05 15:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) G:\Windows\NIRCMD.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) G:\Windows\SWREG.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) G:\Windows\SWSC.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00098816 _____ () G:\Windows\sed.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00080412 _____ () G:\Windows\grep.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00068096 _____ () G:\Windows\zip.exe
2015-04-05 15:01 - 2015-04-05 15:01 - 05617096 ____R (Swearware) G:\Users\mse13ssd\Desktop\ComboFix.exe
2015-04-05 13:10 - 2015-04-05 13:11 - 00380416 _____ () G:\Users\mse13ssd\Downloads\liqvrrec.exe
2015-04-05 13:02 - 2015-04-07 10:36 - 00000000 ____D () G:\FRST
2015-04-05 13:02 - 2015-04-05 13:03 - 00048734 _____ () G:\Users\mse13ssd\Downloads\FRST.txt
2015-04-05 13:02 - 2015-04-05 13:03 - 00024876 _____ () G:\Users\mse13ssd\Downloads\Addition.txt
2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Downloads\FRST64 (1).exe
2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Desktop\FRST64.exe
2015-04-05 12:59 - 2015-04-05 12:59 - 00000478 _____ () G:\Users\mse13ssd\Downloads\defogger_disable.log
2015-04-05 12:59 - 2015-04-05 12:59 - 00000000 _____ () G:\Users\mse13ssd\defogger_reenable
2015-04-05 12:57 - 2015-04-05 12:57 - 00050477 _____ () G:\Users\mse13ssd\Downloads\Defogger.exe
2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (2).exe
2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (1).exe
2015-04-05 03:38 - 2015-04-05 18:38 - 00000000 ____D () G:\AdwCleaner
2015-04-05 03:37 - 2015-04-05 03:38 - 02208768 _____ () G:\Users\mse13ssd\Desktop\adwcleaner_4.200.exe
2015-03-31 05:26 - 2015-03-31 05:26 - 00008930 _____ () G:\Users\mse13ssd\Downloads\smime (1).p7s
2015-03-31 02:41 - 2015-03-31 02:41 - 00000069 _____ () G:\Users\mse13ssd\Desktop\BADLOGIC (German Fandub) - YouTube.url
2015-03-28 00:47 - 2015-03-28 00:47 - 00012288 _____ () G:\Users\mse13ssd\Downloads\Qual-Fraktal.xls
2015-03-27 07:14 - 2015-03-27 07:14 - 00000000 ____D () G:\Users\mse13ssd\Desktop\SciLor's Grooveshark.com Downloader
2015-03-26 21:20 - 2015-03-26 21:20 - 671367548 _____ () G:\Windows\MEMORY.DMP
2015-03-26 21:20 - 2015-03-26 21:20 - 00274624 _____ () G:\Windows\Minidump\032615-29718-01.dmp
2015-03-25 04:31 - 2015-03-25 04:31 - 00002123 _____ () G:\Users\Public\Desktop\CONTRACT J.A.C.K. .lnk
2015-03-25 04:05 - 2015-03-25 04:05 - 00000000 ____D () G:\Program Files (x86)\Sierra
2015-03-25 04:04 - 2015-03-25 04:04 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra
2015-03-25 04:00 - 2003-06-26 10:45 - 00499712 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcp71.dll
2015-03-25 04:00 - 2003-06-26 10:45 - 00348160 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcr71.dll
2015-03-25 04:00 - 2003-03-19 07:20 - 01060864 ____N (Microsoft Corporation) G:\Windows\SysWOW64\mfc71.dll
2015-03-22 18:27 - 2015-03-22 18:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files\Microsoft Silverlight
2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files (x86)\Microsoft Silverlight
2015-03-21 10:33 - 2015-03-21 10:33 - 13087456 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\Silverlight_x64.exe
2015-03-18 17:29 - 2015-03-18 17:29 - 00002023 _____ () G:\Users\mse13ssd\Desktop\Windows Phone-Desktopanwendung.lnk
2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Phone
2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\Program Files (x86)\Windows Phone
2015-03-18 17:25 - 2015-03-18 17:25 - 06745792 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\WindowsPhone.exe
2015-03-18 17:25 - 2015-03-18 17:25 - 00000000 ____D () G:\ProgramData\Applications
2015-03-16 19:19 - 2015-03-16 19:19 - 00001535 _____ () G:\Users\mse13ssd\Free YouTube to MP3 Converter.lnk
2015-03-15 17:32 - 2015-04-07 10:10 - 00001110 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-15 17:32 - 2015-04-07 04:37 - 00001114 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-15 17:32 - 2015-03-15 17:32 - 00004110 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-03-15 17:32 - 2015-03-15 17:32 - 00003858 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-03-15 17:32 - 2015-03-15 17:32 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2015-03-15 17:31 - 2015-03-15 17:31 - 00880208 _____ (Google Inc.) G:\Users\mse13ssd\Downloads\GoogleEarthSetup.exe
2015-03-14 07:06 - 2015-03-14 07:33 - 82044588 _____ () G:\Users\mse13ssd\Downloads\ES-X_DE.rar.crdownload
2015-03-12 09:28 - 2015-02-03 05:34 - 05554104 _____ (Microsoft Corporation) G:\Windows\system32\ntoskrnl.exe
2015-03-12 09:28 - 2015-02-03 05:34 - 00693176 _____ (Microsoft Corporation) G:\Windows\system32\winload.efi
2015-03-12 09:28 - 2015-02-03 05:34 - 00094656 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\mountmgr.sys
2015-03-12 09:28 - 2015-02-03 05:33 - 00616360 _____ (Microsoft Corporation) G:\Windows\system32\winresume.efi
2015-03-12 09:28 - 2015-02-03 05:31 - 14632960 _____ (Microsoft Corporation) G:\Windows\system32\wmp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 04121600 _____ (Microsoft Corporation) G:\Windows\system32\mf.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 01574400 _____ (Microsoft Corporation) G:\Windows\system32\quartz.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00782848 _____ (Microsoft Corporation) G:\Windows\system32\wmdrmsdk.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00641024 _____ (Microsoft Corporation) G:\Windows\system32\msscp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00503808 _____ (Microsoft Corporation) G:\Windows\system32\srcore.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00500224 _____ (Microsoft Corporation) G:\Windows\system32\AUDIOKSE.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00432128 _____ (Microsoft Corporation) G:\Windows\system32\mfplat.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00371712 _____ (Microsoft Corporation) G:\Windows\system32\qdvd.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00325632 _____ (Microsoft Corporation) G:\Windows\system32\msnetobj.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00229376 _____ (Microsoft Corporation) G:\Windows\system32\wintrust.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00206848 _____ (Microsoft Corporation) G:\Windows\system32\mfps.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00188416 _____ (Microsoft Corporation) G:\Windows\system32\pcasvc.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00063488 _____ (Microsoft Corporation) G:\Windows\system32\setbcdlocale.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00050176 _____ (Microsoft Corporation) G:\Windows\system32\srclient.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00037376 _____ (Microsoft Corporation) G:\Windows\system32\pcadm.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\msmmsp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\spwmp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\msdxm.ocx
2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\dxmasf.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 12625920 _____ (Microsoft Corporation) G:\Windows\system32\wmploc.DLL
2015-03-12 09:28 - 2015-02-03 05:30 - 01480192 _____ (Microsoft Corporation) G:\Windows\system32\crypt32.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 01202176 _____ (Microsoft Corporation) G:\Windows\system32\drmv2clt.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 01069056 _____ (Microsoft Corporation) G:\Windows\system32\cryptui.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00842240 _____ (Microsoft Corporation) G:\Windows\system32\blackbox.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00680960 _____ (Microsoft Corporation) G:\Windows\system32\audiosrv.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00631808 _____ (Microsoft Corporation) G:\Windows\system32\evr.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00497664 _____ (Microsoft Corporation) G:\Windows\system32\drmmgrtn.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00440832 _____ (Microsoft Corporation) G:\Windows\system32\AudioEng.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00296960 _____ (Microsoft Corporation) G:\Windows\system32\rstrui.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00296448 _____ (Microsoft Corporation) G:\Windows\system32\AudioSes.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00284672 _____ (Microsoft Corporation) G:\Windows\system32\EncDump.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00187904 _____ (Microsoft Corporation) G:\Windows\system32\cryptsvc.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00146944 _____ (Microsoft Corporation) G:\Windows\system32\appidpolicyconverter.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00140288 _____ (Microsoft Corporation) G:\Windows\system32\cryptnet.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00126464 _____ (Microsoft Corporation) G:\Windows\system32\audiodg.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00112640 _____ (Microsoft Corporation) G:\Windows\system32\smss.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00082432 _____ (Microsoft Corporation) G:\Windows\system32\cryptsp.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00058880 _____ (Microsoft Corporation) G:\Windows\system32\appidapi.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00055808 _____ (Microsoft Corporation) G:\Windows\system32\rrinstaller.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00043520 _____ (Microsoft Corporation) G:\Windows\system32\csrsrv.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00032256 _____ (Microsoft Corporation) G:\Windows\system32\appidsvc.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00024576 _____ (Microsoft Corporation) G:\Windows\system32\mfpmp.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00017920 _____ (Microsoft Corporation) G:\Windows\system32\appidcertstorecheck.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\pcawrk.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\pcalua.exe
2015-03-12 09:28 - 2015-02-03 05:29 - 00008704 _____ (Microsoft Corporation) G:\Windows\system32\pcaevts.dll
2015-03-12 09:28 - 2015-02-03 05:28 - 00006656 _____ (Microsoft Corporation) G:\Windows\system32\apisetschema.dll
2015-03-12 09:28 - 2015-02-03 05:28 - 00002048 _____ (Microsoft Corporation) G:\Windows\system32\mferror.dll
2015-03-12 09:28 - 2015-02-03 05:19 - 00663552 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\PEAuth.sys
2015-03-12 09:28 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntkrnlpa.exe
2015-03-12 09:28 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntoskrnl.exe
2015-03-12 09:28 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mf.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) G:\Windows\SysWOW64\quartz.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) G:\Windows\SysWOW64\crypt32.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptui.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmv2clt.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\blackbox.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmdrmsdk.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) G:\Windows\SysWOW64\qdvd.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msscp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\evr.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AUDIOKSE.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmmgrtn.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioEng.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfplat.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msnetobj.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioSes.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wintrust.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsvc.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptnet.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfps.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) G:\Windows\SysWOW64\appidapi.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) G:\Windows\SysWOW64\srclient.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\spwmp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msdxm.ocx
2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxmasf.dll
2015-03-12 09:28 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmploc.DLL
2015-03-12 09:28 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\rrinstaller.exe
2015-03-12 09:28 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfpmp.exe
2015-03-12 09:28 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mferror.dll
2015-03-12 09:28 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\apisetschema.dll
2015-03-12 09:28 - 2015-02-03 04:32 - 00061440 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\appid.sys
2015-03-12 09:28 - 2014-11-01 00:24 - 00619056 _____ (Microsoft Corporation) G:\Windows\system32\winload.exe
2015-03-12 09:28 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) G:\Windows\system32\winresume.exe
2015-03-12 09:28 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) G:\Windows\system32\ci.dll
2015-03-12 09:27 - 2015-03-06 07:56 - 00155576 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecpkg.sys
2015-03-12 09:27 - 2015-03-06 07:56 - 00095680 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecdd.sys
2015-03-12 09:27 - 2015-03-06 07:42 - 01461760 _____ (Microsoft Corporation) G:\Windows\system32\lsasrv.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00728064 _____ (Microsoft Corporation) G:\Windows\system32\kerberos.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00341504 _____ (Microsoft Corporation) G:\Windows\system32\schannel.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00314880 _____ (Microsoft Corporation) G:\Windows\system32\msv1_0.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00309760 _____ (Microsoft Corporation) G:\Windows\system32\ncrypt.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00210944 _____ (Microsoft Corporation) G:\Windows\system32\wdigest.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00136192 _____ (Microsoft Corporation) G:\Windows\system32\sspicli.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00086528 _____ (Microsoft Corporation) G:\Windows\system32\TSpkg.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00029184 _____ (Microsoft Corporation) G:\Windows\system32\sspisrv.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00028160 _____ (Microsoft Corporation) G:\Windows\system32\secur32.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00022016 _____ (Microsoft Corporation) G:\Windows\system32\credssp.dll
2015-03-12 09:27 - 2015-03-06 07:41 - 00064000 _____ (Microsoft Corporation) G:\Windows\system32\auditpol.exe
2015-03-12 09:27 - 2015-03-06 07:41 - 00031232 _____ (Microsoft Corporation) G:\Windows\system32\lsass.exe
2015-03-12 09:27 - 2015-03-06 07:39 - 00060416 _____ (Microsoft Corporation) G:\Windows\system32\msobjs.dll
2015-03-12 09:27 - 2015-03-06 07:38 - 00146432 _____ (Microsoft Corporation) G:\Windows\system32\msaudite.dll
2015-03-12 09:27 - 2015-03-06 07:36 - 00686080 _____ (Microsoft Corporation) G:\Windows\system32\adtschema.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) G:\Windows\SysWOW64\kerberos.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msv1_0.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) G:\Windows\SysWOW64\schannel.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ncrypt.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wdigest.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) G:\Windows\SysWOW64\TSpkg.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\secur32.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\credssp.dll
2015-03-12 09:27 - 2015-03-06 07:09 - 00096768 _____ (Microsoft Corporation) G:\Windows\SysWOW64\sspicli.dll
2015-03-12 09:27 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\auditpol.exe
2015-03-12 09:27 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msaudite.dll
2015-03-12 09:27 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msobjs.dll
2015-03-12 09:27 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) G:\Windows\SysWOW64\adtschema.dll
2015-03-12 09:27 - 2015-02-24 05:15 - 00389800 _____ (Microsoft Corporation) G:\Windows\system32\iedkcs32.dll
2015-03-12 09:27 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iedkcs32.dll
2015-03-12 09:27 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.dll
2015-03-12 09:27 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieframe.dll
2015-03-12 09:27 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtmsft.dll
2015-03-12 09:27 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtrans.dll
2015-03-12 09:27 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.dll
2015-03-12 09:27 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) G:\Windows\system32\mshtmled.dll
2015-03-12 09:27 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmled.dll
2015-03-12 09:27 - 2015-02-20 06:41 - 00041984 _____ (Microsoft Corporation) G:\Windows\system32\lpk.dll
2015-03-12 09:27 - 2015-02-20 06:40 - 00100864 _____ (Microsoft Corporation) G:\Windows\system32\fontsub.dll
2015-03-12 09:27 - 2015-02-20 06:40 - 00046080 _____ (Adobe Systems) G:\Windows\system32\atmlib.dll
2015-03-12 09:27 - 2015-02-20 06:40 - 00014336 _____ (Microsoft Corporation) G:\Windows\system32\dciman32.dll
2015-03-12 09:27 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\fontsub.dll
2015-03-12 09:27 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) G:\Windows\SysWOW64\atmlib.dll
2015-03-12 09:27 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dciman32.dll
2015-03-12 09:27 - 2015-02-20 06:12 - 00025600 _____ (Microsoft Corporation) G:\Windows\SysWOW64\lpk.dll
2015-03-12 09:27 - 2015-02-20 05:29 - 00372224 _____ (Adobe Systems Incorporated) G:\Windows\system32\atmfd.dll
2015-03-12 09:27 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\atmfd.dll
2015-03-12 09:27 - 2015-02-20 05:06 - 02724864 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.tlb
2015-03-12 09:27 - 2015-02-20 05:05 - 00004096 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollectorres.dll
2015-03-12 09:27 - 2015-02-20 04:50 - 00066560 _____ (Microsoft Corporation) G:\Windows\system32\iesetup.dll
2015-03-12 09:27 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) G:\Windows\system32\vbscript.dll
2015-03-12 09:27 - 2015-02-20 04:49 - 00048640 _____ (Microsoft Corporation) G:\Windows\system32\ieetwproxystub.dll
2015-03-12 09:27 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) G:\Windows\system32\iertutil.dll
2015-03-12 09:27 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) G:\Windows\system32\MshtmlDac.dll
2015-03-12 09:27 - 2015-02-20 04:41 - 00054784 _____ (Microsoft Corporation) G:\Windows\system32\jsproxy.dll
2015-03-12 09:27 - 2015-02-20 04:40 - 00034304 _____ (Microsoft Corporation) G:\Windows\system32\iernonce.dll
2015-03-12 09:27 - 2015-02-20 04:36 - 00633856 _____ (Microsoft Corporation) G:\Windows\system32\ieui.dll
2015-03-12 09:27 - 2015-02-20 04:35 - 00144384 _____ (Microsoft Corporation) G:\Windows\system32\ieUnatt.exe
2015-03-12 09:27 - 2015-02-20 04:35 - 00114688 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollector.exe
2015-03-12 09:27 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) G:\Windows\system32\jscript9diag.dll
2015-03-12 09:27 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) G:\Windows\system32\jscript9.dll
2015-03-12 09:27 - 2015-02-20 04:26 - 00968704 _____ (Microsoft Corporation) G:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-12 09:27 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.tlb
2015-03-12 09:27 - 2015-02-20 04:22 - 00490496 _____ (Microsoft Corporation) G:\Windows\system32\dxtmsft.dll
2015-03-12 09:27 - 2015-02-20 04:13 - 00077824 _____ (Microsoft Corporation) G:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-12 09:27 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) G:\Windows\SysWOW64\vbscript.dll
2015-03-12 09:27 - 2015-02-20 04:08 - 00199680 _____ (Microsoft Corporation) G:\Windows\system32\msrating.dll
2015-03-12 09:27 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iesetup.dll
2015-03-12 09:27 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieetwproxystub.dll
2015-03-12 09:27 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) G:\Windows\SysWOW64\MshtmlDac.dll
2015-03-12 09:27 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) G:\Windows\system32\dxtrans.dll
2015-03-12 09:27 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iertutil.dll
2015-03-12 09:27 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jsproxy.dll
2015-03-12 09:27 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iernonce.dll
2015-03-12 09:27 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieui.dll
2015-03-12 09:27 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9diag.dll
2015-03-12 09:27 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieUnatt.exe
2015-03-12 09:27 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) G:\Windows\system32\msfeeds.dll
2015-03-12 09:27 - 2015-02-20 03:49 - 00718848 _____ (Microsoft Corporation) G:\Windows\system32\ie4uinit.exe
2015-03-12 09:27 - 2015-02-20 03:47 - 01359360 _____ (Microsoft Corporation) G:\Windows\system32\mshtmlmedia.dll
2015-03-12 09:27 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) G:\Windows\system32\inetcpl.cpl
2015-03-12 09:27 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) G:\Windows\system32\ieframe.dll
2015-03-12 09:27 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-03-12 09:27 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msrating.dll
2015-03-12 09:27 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9.dll
2015-03-12 09:27 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) G:\Windows\system32\wininet.dll
2015-03-12 09:27 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) G:\Windows\SysWOW64\inetcpl.cpl
2015-03-12 09:27 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msfeeds.dll
2015-03-12 09:27 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmlmedia.dll
2015-03-12 09:27 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) G:\Windows\system32\urlmon.dll
2015-03-12 09:27 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) G:\Windows\system32\ieapfltr.dll
2015-03-12 09:27 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wininet.dll
2015-03-12 09:27 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) G:\Windows\SysWOW64\urlmon.dll
2015-03-12 09:27 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieapfltr.dll
2015-03-12 09:27 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) G:\Windows\SysWOW64\shell32.dll
2015-03-12 09:27 - 2015-02-13 07:22 - 14177280 _____ (Microsoft Corporation) G:\Windows\system32\shell32.dll
2015-03-12 09:27 - 2015-02-03 05:31 - 01424896 _____ (Microsoft Corporation) G:\Windows\system32\WindowsCodecs.dll
2015-03-12 09:27 - 2015-02-03 05:31 - 00215552 _____ (Microsoft Corporation) G:\Windows\system32\ubpm.dll
2015-03-12 09:27 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WindowsCodecs.dll
2015-03-12 09:27 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ubpm.dll
2015-03-12 09:27 - 2015-01-31 05:48 - 03179520 _____ (Microsoft Corporation) G:\Windows\system32\rdpcorets.dll
2015-03-12 09:27 - 2015-01-31 05:48 - 00016384 _____ (Microsoft Corporation) G:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-12 09:27 - 2015-01-31 01:56 - 00459336 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\cng.sys
2015-03-12 09:27 - 2015-01-31 01:56 - 00243200 _____ (Microsoft Corporation) G:\Windows\system32\rdpudd.dll
2015-03-12 09:27 - 2015-01-17 04:48 - 01067520 _____ (Microsoft Corporation) G:\Windows\system32\msctf.dll
2015-03-12 09:27 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msctf.dll
2015-03-12 09:26 - 2015-02-26 05:25 - 03204096 _____ (Microsoft Corporation) G:\Windows\system32\win32k.sys
2015-03-12 09:26 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) G:\Windows\system32\WMPhoto.dll
2015-03-12 09:26 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WMPhoto.dll
2015-03-10 01:20 - 2015-03-10 01:20 - 00001002 _____ () G:\Users\mse13ssd\Downloads\BAHN_Fahrplan_20150609.ics
2015-03-09 11:16 - 2015-03-09 11:56 - 124202474 _____ () G:\Users\mse13ssd\Downloads\#0325#.rar
2015-03-08 09:43 - 2015-03-08 09:43 - 01230365 _____ () G:\Users\mse13ssd\Downloads\2 (1).wmv
2015-03-08 09:43 - 2015-03-08 09:43 - 01222357 _____ () G:\Users\mse13ssd\Downloads\3.wmv

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-07 10:17 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-07 10:17 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-07 10:14 - 2014-05-17 10:22 - 01439466 _____ () G:\Windows\WindowsUpdate.log
2015-04-07 10:14 - 2009-07-14 19:58 - 00700986 _____ () G:\Windows\system32\perfh007.dat
2015-04-07 10:14 - 2009-07-14 19:58 - 00149886 _____ () G:\Windows\system32\perfc007.dat
2015-04-07 10:14 - 2009-07-14 07:13 - 01619284 _____ () G:\Windows\system32\PerfStringBackup.INI
2015-04-07 10:10 - 2014-07-13 00:21 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Raptr
2015-04-07 10:10 - 2014-05-17 22:03 - 00000000 _____ () G:\Windows\system32\Drivers\lvuvc.hs
2015-04-07 10:10 - 2014-05-17 15:57 - 00004182 _____ () G:\Windows\System32\Tasks\avast! Emergency Update
2015-04-07 10:10 - 2009-07-14 07:08 - 00000006 ____H () G:\Windows\Tasks\SA.DAT
2015-04-07 10:10 - 2009-07-14 06:51 - 00055803 _____ () G:\Windows\setupact.log
2015-04-06 21:07 - 2014-05-17 20:13 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\TS3Client
2015-04-06 20:32 - 2014-05-17 22:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Skype
2015-04-06 19:55 - 2014-05-17 15:20 - 00033556 _____ () G:\Windows\PFRO.log
2015-04-05 20:55 - 2014-05-17 12:27 - 00000000 ____D () G:\Program Files (x86)\SRWare Iron
2015-04-05 18:19 - 2015-03-05 14:19 - 00129752 _____ (Malwarebytes Corporation) G:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-05 15:10 - 2009-07-14 05:20 - 00000000 __RHD () G:\Users\Default
2015-04-05 15:09 - 2009-07-14 04:34 - 00000215 _____ () G:\Windows\system.ini
2015-04-05 13:19 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\NDF
2015-04-05 12:59 - 2014-05-17 11:54 - 00000000 ____D () G:\Users\mse13ssd
2015-04-05 03:26 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\Web
2015-04-02 01:34 - 2009-07-14 07:32 - 00000000 ____D () G:\Windows\system32\FxsTmp
2015-03-30 17:36 - 2015-02-28 05:38 - 00000000 ____D () G:\Users\mse13ssd\Desktop\aufgeräumt
2015-03-30 08:10 - 2014-11-01 08:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\25372
2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\DivX
2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
2015-03-30 04:33 - 2014-08-24 02:00 - 00000000 ____D () G:\ProgramData\DivX
2015-03-30 04:33 - 2014-05-17 15:57 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2015-03-30 04:33 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\AppCompat
2015-03-30 04:32 - 2014-08-24 02:01 - 00000000 ____D () G:\Program Files\DivX
2015-03-30 04:32 - 2014-08-24 02:00 - 00000000 ____D () G:\Program Files (x86)\DivX
2015-03-30 04:32 - 2014-06-18 17:31 - 00000000 ____D () G:\Program Files (x86)\Microsoft Office
2015-03-30 04:32 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\registration
2015-03-30 03:27 - 2009-07-14 20:18 - 00000000 ___RD () G:\Users\Public\Recorded TV
2015-03-26 21:20 - 2014-10-12 12:01 - 00000000 ____D () G:\Windows\Minidump
2015-03-26 18:51 - 2014-07-13 00:21 - 00000000 ____D () G:\Program Files (x86)\Raptr
2015-03-26 09:13 - 2014-06-18 17:31 - 00000000 ____D () G:\ProgramData\Microsoft Help
2015-03-22 18:29 - 2014-05-17 12:40 - 00070368 _____ () G:\Users\mse13ssd\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-22 18:29 - 2009-07-14 06:45 - 00307752 _____ () G:\Windows\system32\FNTCACHE.DAT
2015-03-22 18:25 - 2014-06-18 17:32 - 00000000 ____D () G:\Program Files (x86)\Microsoft Works
2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Google
2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Program Files (x86)\Google
2015-03-15 14:09 - 2014-08-24 13:49 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Adobe
2015-03-15 14:09 - 2014-05-17 15:53 - 00778928 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerApp.exe
2015-03-15 14:09 - 2014-05-17 15:53 - 00142512 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-03-15 05:05 - 2014-06-21 18:28 - 00000000 ____D () G:\Program Files (x86)\Steam
2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Glyph
2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glyph
2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Program Files (x86)\Glyph
2015-03-13 10:32 - 2009-07-14 07:09 - 00000000 ____D () G:\Windows\System32\Tasks\WPD
2015-03-12 12:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\rescache
2015-03-12 09:37 - 2015-02-28 09:01 - 00000000 ___RD () G:\Users\mse13ssd\Virtual Machines
2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\SysWOW64\Dism
2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\Dism
2015-03-12 09:31 - 2014-05-17 20:36 - 00000000 ____D () G:\Windows\system32\MRT
2015-03-12 09:29 - 2014-05-17 20:36 - 122905848 _____ (Microsoft Corporation) G:\Windows\system32\MRT.exe

==================== Files in the root of some directories =======

2014-10-02 16:29 - 2015-02-28 12:40 - 14286848 _____ () G:\Users\mse13ssd\AppData\Roaming\Sandra.mdb
2015-01-23 13:40 - 2015-01-23 13:40 - 0003584 _____ () G:\Users\mse13ssd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-01 14:58 - 2015-01-01 14:58 - 0007605 _____ () G:\Users\mse13ssd\AppData\Local\Resmon.ResmonCfg

Some content of TEMP:
====================
G:\Users\mse13ssd\AppData\Local\Temp\Quarantine.exe
G:\Users\mse13ssd\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

G:\Windows\System32\winlogon.exe => File is digitally signed
G:\Windows\System32\wininit.exe => File is digitally signed
G:\Windows\SysWOW64\wininit.exe => File is digitally signed
G:\Windows\explorer.exe => File is digitally signed
G:\Windows\SysWOW64\explorer.exe => File is digitally signed
G:\Windows\System32\svchost.exe => File is digitally signed
G:\Windows\SysWOW64\svchost.exe => File is digitally signed
G:\Windows\System32\services.exe => File is digitally signed
G:\Windows\System32\User32.dll => File is digitally signed
G:\Windows\SysWOW64\User32.dll => File is digitally signed
G:\Windows\System32\userinit.exe => File is digitally signed
G:\Windows\SysWOW64\userinit.exe => File is digitally signed
G:\Windows\System32\rpcss.dll => File is digitally signed
G:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-04 00:45

==================== End Of Log ============================
         
--- --- ---

--- --- ---

--- --- ---





Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
Ran by mse13ssd at 2015-04-07 10:36:50
Running from G:\Users\mse13ssd\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
AGEIA PhysX v7.11.13 (HKLM-x32\...\{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}) (Version: 7.11.13 - AGEIA Technologies, Inc.)
Agent Ransack x64 (HKLM\...\{58C0AC50-8FA1-4A95-AEC6-5B2727E5CC6A}) (Version: 7.0.820.1 - Mythicsoft Ltd)
AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Apple Application Support (HKLM-x32\...\{122ADF8C-DDA1-480C-9936-C88F2825B265}) (Version: 2.1.9 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}) (Version: 5.2.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Archeage (HKLM-x32\...\Glyph Archeage) (Version:  - Trion Worlds, Inc.)
ArtMoney SE v7.43 (HKLM-x32\...\ArtMoney SE_is1) (Version: 7.43 - System SoftLab)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software)
Avery Wizard 5.0 (HKLM-x32\...\{FC3B3A5D-7058-4627-9F1E-F95CC38B6054}) (Version: 5.0.5 - Avery)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version:  - Gearbox Software)
Canon iP7200 series Benutzerregistrierung (HKLM-x32\...\Canon iP7200 series Benutzerregistrierung) (Version:  - Canon Inc.‎)
Canon iP7200 series Printer Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP7200_series) (Version:  - Canon Inc.)
Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version:  - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.0.0 - Canon Inc.)
CanoScan LiDE 110 Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2414) (Version:  - Canon Inc.)
ClipboardManager 1.6 (HKLM-x32\...\ClipboardManager_is1) (Version:  - )
Contract Jack (HKLM-x32\...\{374CAB30-2F61-4439-9A4A-24D3AEA2960A}) (Version:  - )
CPUID CPU-Z 1.70 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Die Siedler II - Die nächste Generation (HKLM-x32\...\S2TNG) (Version:  - )
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.7.0.31 - DivX, LLC)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
Free YouTube Download version 3.2.53.128 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.53.128 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.12.50.1111 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.50.1111 - DVDVideoSoft Ltd.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
GUILD WARS (HKLM-x32\...\Guild Wars) (Version:  - )
iTunes (HKLM\...\{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}) (Version: 10.6.3.25 - Apple Inc.)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Logitech Gaming Software 8.55 (HKLM\...\Logitech Gaming Software) (Version: 8.55.137 - Logitech Inc.)
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Mozilla Firefox 36.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 36.0 (x86 de)) (Version: 36.0 - Mozilla)
paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC)
Pamela Pro 4.9 (HKLM-x32\...\Pamela) (Version: 4.9 - PamConsult GmbH)
PDF Architect 2 Create Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.0 - pdfforge)
Raptr (HKLM-x32\...\Raptr) (Version:  - )
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SciLor's grooveshark™.com Downloader 0.4.15 (HKLM-x32\...\{DDEAE484-D5FB-49CB-BD47-9512E8ACCA65}_is1) (Version: 0.4.15 - SciLor)
SiSoftware Sandra Lite 2014.SP3c (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2496}_is1) (Version: 20.47.2014.10 - SiSoftware)
Skype™ 7.1 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
SRWare Iron Version SRWare Iron 39.2100.0 (HKLM-x32\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: SRWare Iron 39.2100.0 - SRWare)
Steam (HKLM-x32\...\Steam) (Version:  - Valve Corporation)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Windows Phone app for desktop (HKLM-x32\...\{19773614-FC22-4ACC-AAA3-E6BDA81ACF92}) (Version: 1.1.2726.0 - Microsoft Corporation)
WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

01-04-2015 19:32:07 Windows Update
05-04-2015 15:04:11 ComboFix created restore point

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2015-04-05 15:09 - 00000027 ____A G:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {1FC3D3B2-F254-4B57-9695-FFF62B3AC150} - System32\Tasks\GoogleUpdateTaskMachineCore => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15] (Google Inc.)
Task: {34D4B971-AD1B-4F8D-8ED4-6F6BF7ABE60D} - System32\Tasks\avast! Emergency Update => G:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-07-15] (AVAST Software)
Task: {BD6EFB7D-29B9-4725-B4CB-C2F47B685F42} - System32\Tasks\Abelssoft\Updater scan => G:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe
Task: {DB431844-F8D5-409D-A115-BB442A487B85} - System32\Tasks\GoogleUpdateTaskMachineUA => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15] (Google Inc.)
Task: {E57F8AB1-453C-45BC-BF7F-E700E5C6EBA9} - System32\Tasks\Adobe Acrobat Update Task => G:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2014-07-28 20:29 - 2014-07-28 20:29 - 00866584 _____ () G:\Program Files\Logitech Gaming Software\libGLESv2.dll
2014-07-28 20:32 - 2014-07-28 20:32 - 01050904 _____ () G:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2014-07-28 20:29 - 2014-07-28 20:29 - 00059160 _____ () G:\Program Files\Logitech Gaming Software\libEGL.dll
2014-07-28 20:31 - 2014-07-28 20:31 - 00242456 _____ () G:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2014-01-10 07:26 - 2014-01-10 07:26 - 01861968 _____ () G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2014-07-15 08:28 - 2014-07-15 08:28 - 00301152 _____ () G:\Program Files\AVAST Software\Avast\aswProperty.dll
2015-04-06 19:56 - 2015-04-06 19:56 - 02923520 _____ () G:\Program Files\AVAST Software\Avast\defs\15040601\algo.dll
2015-04-07 10:10 - 2015-04-07 10:10 - 02923520 _____ () G:\Program Files\AVAST Software\Avast\defs\15040700\algo.dll
2012-05-30 20:06 - 2012-05-30 20:06 - 00087912 _____ () G:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2012-05-30 20:06 - 2012-05-30 20:06 - 01242512 _____ () G:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-07-15 08:28 - 2014-07-15 08:28 - 19329904 _____ () G:\Program Files\AVAST Software\Avast\libcef.dll
2014-01-10 07:28 - 2014-01-10 07:28 - 00100688 _____ () G:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
2014-05-17 12:27 - 2014-12-05 20:30 - 01359360 _____ () G:\Program Files (x86)\SRWare Iron\libglesv2.dll
2014-05-17 12:27 - 2014-12-05 20:31 - 00212992 _____ () G:\Program Files (x86)\SRWare Iron\libegl.dll
2015-01-08 21:01 - 2014-12-05 20:53 - 09299968 _____ () G:\Program Files (x86)\SRWare Iron\pdf.dll
2014-05-17 12:27 - 2014-12-05 20:32 - 00984576 _____ () G:\Program Files (x86)\SRWare Iron\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: G:\Users\mse13ssd\Downloads\email_5937_20150205205259.eml:OECustomProperty

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Control Panel\Desktop\\Wallpaper -> G:\Users\mse13ssd\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: bthserv => 3
MSCONFIG\Services: DPS => 2
MSCONFIG\Services: SensrSvc => 3
MSCONFIG\startupreg: Adobe ARM => "G:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "G:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: iTunesHelper => "G:\Program Files (x86)\iTunes\iTunesHelper.exe"

==================== Accounts: =============================

Administrator (S-1-5-21-3243151774-2580435505-251407729-500 - Administrator - Disabled)
Gast (S-1-5-21-3243151774-2580435505-251407729-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3243151774-2580435505-251407729-1002 - Limited - Enabled)
mse13ssd (S-1-5-21-3243151774-2580435505-251407729-1001 - Administrator - Enabled) => G:\Users\mse13ssd

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (04/07/2015 10:10:33 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x5cc
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3

Error: (04/07/2015 03:22:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x514
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3

Error: (04/07/2015 00:47:54 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/06/2015 07:59:18 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/06/2015 07:55:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x50c
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3

Error: (04/06/2015 05:50:49 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/06/2015 05:44:22 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/06/2015 05:27:33 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.


System errors:
=============
Error: (04/07/2015 10:10:38 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/07/2015 10:10:12 AM) (Source: Ntfs) (EventID: 137) (User: )
Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (04/07/2015 03:22:44 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/07/2015 03:22:17 AM) (Source: Ntfs) (EventID: 137) (User: )
Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (04/06/2015 07:55:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/06/2015 07:55:30 PM) (Source: Ntfs) (EventID: 137) (User: )
Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (04/06/2015 10:14:00 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}


Microsoft Office Sessions:
=========================

==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz
Percentage of memory in use: 14%
Total physical RAM: 16384 MB
Available physical RAM: 14004.36 MB
Total Pagefile: 32766.19 MB
Available Pagefile: 30072.39 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.5 GB) (Free:737.58 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:0.01 GB) (Free:0 GB) NTFS
Drive f: (Nolf2xp_1) (CDROM) (Total:0.64 GB) (Free:0 GB) CDFS
Drive g: (SSD) (Fixed) (Total:119.24 GB) (Free:25.03 GB) NTFS
Drive m: (SAMSUNG) (Fixed) (Total:1396.92 GB) (Free:834.32 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: 7E008421)
Partition 1: (Active) - (Size=119.2 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 1CA61CA5)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=7 MB) - (Type=07 NTFS)

========================================================
Disk: 6 (Size: 1397.3 GB) (Disk ID: 5C9C6FA9)
Partition 1: (Not Active) - (Size=1397.3 GB) - (Type=0C)

==================== End Of Log ============================
         




Und keine Probleme mehr! Vielen lieben Dank!

LG, Hendrik Sander

Alt 07.04.2015, 17:37   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen - Standard

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen



Java updaten.

Revo Uninstaller - Download - Filepony
damit Chrome deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren.

Dann:
https://support.google.com/chrome/answer/3296214?hl=de



Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe

C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe

C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe

C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe

C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll

C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll

C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe

C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe

C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe

C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe

C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe

C:\Documents and Settings\mse13\AppData\Local\Temp\ct3297265\ism.exe

C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll

C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll

C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe

C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Documents and Settings\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe

C:\Documents and Settings\mse13\Downloads\Der_knallharte_Prinzipal.exe

C:\Documents and Settings\mse13\Downloads\jZipSetup-r113-n-bc.exe

C:\Documents and Settings\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe

C:\Documents and Settings\mse13\Downloads\Raidcall_TSV45QFV6.exe

C:\Documents and Settings\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe

C:\Documents and Settings\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe

C:\Documents and Settings\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe

C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe

C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe

C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe

C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe

C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll

C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll

C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe

C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\ct3297265\ism.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll

C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll

C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Dokumente und Einstellungen\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe

C:\Dokumente und Einstellungen\mse13\Downloads\Der_knallharte_Prinzipal.exe

C:\Dokumente und Einstellungen\mse13\Downloads\jZipSetup-r113-n-bc.exe

C:\Dokumente und Einstellungen\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe

C:\Dokumente und Einstellungen\mse13\Downloads\Raidcall_TSV45QFV6.exe

C:\Dokumente und Einstellungen\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe

C:\Dokumente und Einstellungen\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe

C:\Dokumente und Einstellungen\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe

C:\Program Files (x86)\HDvid-Codec V9.0\51356.crx

C:\Program Files (x86)\HDvid-Codec V9.0\51356.xpi

C:\Program Files (x86)\Iminent\inst\Bootstrapper\IminentUninstall.exe

C:\Users\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe

C:\Users\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe

C:\Users\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe

C:\Users\mse13\AppData\Local\Temp\ct3297265\ism.exe

C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll

C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll

C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe

C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Users\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe

C:\Users\mse13\Downloads\Der_knallharte_Prinzipal.exe

C:\Users\mse13\Downloads\jZipSetup-r113-n-bc.exe

C:\Users\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe

C:\Users\mse13\Downloads\Raidcall_TSV45QFV6.exe

C:\Users\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe

C:\Users\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe

C:\Users\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe

C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe

C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe

C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe

C:\Users\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe

C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll

C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll

C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe

C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe

G:\AdwCleaner\Quarantine\G\Users\mse13ssd\AppData\Local\Temp\OCS\ocs_v71b.exe.vir

G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\File System\002\t\00\00000000

G:\Users\mse13ssd\Downloads\Griffith - CHIP-Installer.exe

G:\Users\mse13ssd\Downloads\PDFCreator-2_0_0-setup.exe

G:\Users\mse13ssd\Downloads\ZustellnachrichtDHL_bestellung_000029937728.zip

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0
Emptytemp:
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.




Frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 08.04.2015, 09:39   #9
MSE XIII
 
Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen - Standard

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen



Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by mse13ssd at 2015-04-08 08:10:14 Run:1
Running from G:\Users\mse13ssd\Desktop
Loaded Profiles: mse13ssd (Available profiles: mse13ssd)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe

C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe

C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe

C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe

C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll

C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll

C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe

C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe

C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe

C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe

C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe

C:\Documents and Settings\mse13\AppData\Local\Temp\ct3297265\ism.exe

C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll

C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll

C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe

C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Documents and Settings\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe

C:\Documents and Settings\mse13\Downloads\Der_knallharte_Prinzipal.exe

C:\Documents and Settings\mse13\Downloads\jZipSetup-r113-n-bc.exe

C:\Documents and Settings\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe

C:\Documents and Settings\mse13\Downloads\Raidcall_TSV45QFV6.exe

C:\Documents and Settings\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe

C:\Documents and Settings\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe

C:\Documents and Settings\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe

C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe

C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe

C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe

C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe

C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll

C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll

C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe

C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\ct3297265\ism.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll

C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll

C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe

C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Dokumente und Einstellungen\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe

C:\Dokumente und Einstellungen\mse13\Downloads\Der_knallharte_Prinzipal.exe

C:\Dokumente und Einstellungen\mse13\Downloads\jZipSetup-r113-n-bc.exe

C:\Dokumente und Einstellungen\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe

C:\Dokumente und Einstellungen\mse13\Downloads\Raidcall_TSV45QFV6.exe

C:\Dokumente und Einstellungen\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe

C:\Dokumente und Einstellungen\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe

C:\Dokumente und Einstellungen\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe

C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe

C:\Program Files (x86)\HDvid-Codec V9.0\51356.crx

C:\Program Files (x86)\HDvid-Codec V9.0\51356.xpi

C:\Program Files (x86)\Iminent\inst\Bootstrapper\IminentUninstall.exe

C:\Users\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe

C:\Users\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe

C:\Users\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe

C:\Users\mse13\AppData\Local\Temp\ct3297265\ism.exe

C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll

C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll

C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe

C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi

C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe

C:\Users\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe

C:\Users\mse13\Downloads\Der_knallharte_Prinzipal.exe

C:\Users\mse13\Downloads\jZipSetup-r113-n-bc.exe

C:\Users\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe

C:\Users\mse13\Downloads\Raidcall_TSV45QFV6.exe

C:\Users\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe

C:\Users\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe

C:\Users\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe

C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe

C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe

C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe

C:\Users\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe

C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll

C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll

C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe

C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe

G:\AdwCleaner\Quarantine\G\Users\mse13ssd\AppData\Local\Temp\OCS\ocs_v71b.exe.vir

G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\File System\002\t\00\00000000

G:\Users\mse13ssd\Downloads\Griffith - CHIP-Installer.exe

G:\Users\mse13ssd\Downloads\PDFCreator-2_0_0-setup.exe

G:\Users\mse13ssd\Downloads\ZustellnachrichtDHL_bestellung_000029937728.zip

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0
Emptytemp:
         
*****************

C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe => Moved successfully.
C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe => Moved successfully.
C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe => Moved successfully.
C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe => Moved successfully.
C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll => Moved successfully.
C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll => Moved successfully.
C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe => Moved successfully.
C:\Documents and Settings\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe => Moved successfully.
"C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe" => File/Directory not found.
"C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe" => File/Directory not found.
"C:\Documents and Settings\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe" => File/Directory not found.
"C:\Documents and Settings\mse13\AppData\Local\Temp\ct3297265\ism.exe" => File/Directory not found.
"C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll" => File/Directory not found.
"C:\Documents and Settings\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll" => File/Directory not found.
"C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe" => File/Directory not found.
"C:\Documents and Settings\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe" => File/Directory not found.
C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe => Moved successfully.
C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi => Moved successfully.
Could not move "C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot.
C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi => Moved successfully.
Could not move "C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot.
C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi => Moved successfully.
Could not move "C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot.
C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi => Moved successfully.
C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Moved successfully.
Could not move "C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => Scheduled to move on reboot.
Could not move "C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot.
C:\Documents and Settings\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe => Moved successfully.
C:\Documents and Settings\mse13\Downloads\Der_knallharte_Prinzipal.exe => Moved successfully.
C:\Documents and Settings\mse13\Downloads\jZipSetup-r113-n-bc.exe => Moved successfully.
C:\Documents and Settings\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe => Moved successfully.
C:\Documents and Settings\mse13\Downloads\Raidcall_TSV45QFV6.exe => Moved successfully.
C:\Documents and Settings\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe => Moved successfully.
C:\Documents and Settings\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe => Moved successfully.
C:\Documents and Settings\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe => Moved successfully.
"C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe" => File/Directory not found.
"C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe" => File/Directory not found.
"C:\Documents and Settings\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe" => File/Directory not found.
"C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe" => File/Directory not found.
"C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll" => File/Directory not found.
"C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll" => File/Directory not found.
"C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe" => File/Directory not found.
"C:\Documents and Settings\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\IminentSetup.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\vis-freeware.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\DownloadGuide\Offers\wajam_download.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\ct3297265\ism.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\Helper.dll" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\nslFFC8.tmp\soffer.dll" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v71b.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\Anwendungsdaten\Temp\OCS\ocs_v7f.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\ct3297265\ism.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found.
Could not move "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot.
"C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found.
Could not move "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot.
"C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found.
Could not move "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot.
"C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => File/Directory not found.
Could not move "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => Scheduled to move on reboot.
Could not move "C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => Scheduled to move on reboot.
"C:\Dokumente und Einstellungen\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Downloads\Der_knallharte_Prinzipal.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Downloads\jZipSetup-r113-n-bc.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Downloads\Raidcall_TSV45QFV6.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe" => File/Directory not found.
"C:\Dokumente und Einstellungen\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe" => File/Directory not found.
C:\Program Files (x86)\HDvid-Codec V9.0\51356.crx => Moved successfully.
C:\Program Files (x86)\HDvid-Codec V9.0\51356.xpi => Moved successfully.
C:\Program Files (x86)\Iminent\inst\Bootstrapper\IminentUninstall.exe => Moved successfully.
"C:\Users\mse13\AppData\Local\DownloadGuide\Offers\IminentSetup.exe" => File/Directory not found.
"C:\Users\mse13\AppData\Local\DownloadGuide\Offers\vis-freeware.exe" => File/Directory not found.
"C:\Users\mse13\AppData\Local\DownloadGuide\Offers\wajam_download.exe" => File/Directory not found.
"C:\Users\mse13\AppData\Local\Temp\ct3297265\ism.exe" => File/Directory not found.
"C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\Helper.dll" => File/Directory not found.
"C:\Users\mse13\AppData\Local\Temp\nslFFC8.tmp\soffer.dll" => File/Directory not found.
"C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v71b.exe" => File/Directory not found.
"C:\Users\mse13\AppData\Local\Temp\OCS\ocs_v7f.exe" => File/Directory not found.
"C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\iLividSetupV1.exe" => File/Directory not found.
"C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found.
C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Moved successfully.
"C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found.
C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Moved successfully.
"C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found.
C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Moved successfully.
"C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Firefox.xpi" => File/Directory not found.
"C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Boese Tagebuecher - Unaussprechlich\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe" => File/Directory not found.
C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi => Moved successfully.
C:\Users\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Moved successfully.
"C:\Users\mse13\Downloads\BOMANN TSG 604 user guide provided through pdfretriever.com.exe" => File/Directory not found.
"C:\Users\mse13\Downloads\Der_knallharte_Prinzipal.exe" => File/Directory not found.
"C:\Users\mse13\Downloads\jZipSetup-r113-n-bc.exe" => File/Directory not found.
"C:\Users\mse13\Downloads\Logitech SetPoint 64 Bit - CHIP-Installer.exe" => File/Directory not found.
"C:\Users\mse13\Downloads\Raidcall_TSV45QFV6.exe" => File/Directory not found.
"C:\Users\mse13\Downloads\SoftonicDownloader_fuer_itunes-portable.exe" => File/Directory not found.
"C:\Users\mse13\Downloads\The.Big.Bang.Theory.S07E02.Eine.Koerbchengroesse.mehr.GERMAN.DUBBED.WebHDRiP.x264 SOF.mkv.flv__3339_i341116521_il36.exe" => File/Directory not found.
"C:\Users\mse13\Downloads\Zwei.vom.alten.Schlag.2013.German.WEBRip.AC3MD.Xvi_D-SMY.exe" => File/Directory not found.
"C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\IminentSetup.exe" => File/Directory not found.
"C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\vis-freeware.exe" => File/Directory not found.
"C:\Users\mse13\Lokale Einstellungen\DownloadGuide\Offers\wajam_download.exe" => File/Directory not found.
"C:\Users\mse13\Lokale Einstellungen\Temp\ct3297265\ism.exe" => File/Directory not found.
"C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\Helper.dll" => File/Directory not found.
"C:\Users\mse13\Lokale Einstellungen\Temp\nslFFC8.tmp\soffer.dll" => File/Directory not found.
"C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v71b.exe" => File/Directory not found.
"C:\Users\mse13\Lokale Einstellungen\Temp\OCS\ocs_v7f.exe" => File/Directory not found.
G:\AdwCleaner\Quarantine\G\Users\mse13ssd\AppData\Local\Temp\OCS\ocs_v71b.exe.vir => Moved successfully.
"G:\Users\mse13ssd\AppData\Local\Chromium\User Data\Default\File System\002\t\00\00000000" => File/Directory not found.
G:\Users\mse13ssd\Downloads\Griffith - CHIP-Installer.exe => Moved successfully.
G:\Users\mse13ssd\Downloads\PDFCreator-2_0_0-setup.exe => Moved successfully.
G:\Users\mse13ssd\Downloads\ZustellnachrichtDHL_bestellung_000029937728.zip => Moved successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer => value deleted successfully.
EmptyTemp: => Removed 647.4 MB temporary data.

=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-04-08 08:12:55)<=

C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully.
C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully.
C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully.
C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi => Is moved successfully.
C:\Documents and Settings\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully.
C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2003 - Männer sind Schweine, Frauen aber auch !\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully.
C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2004 - Langenscheidt Deutsch - Frau - Frau - Deutsch\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully.
C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mario Barth - 2006 - Männer sind primitiv, aber glücklich!\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully.
C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Firefox.xpi => Is moved successfully.
C:\Dokumente und Einstellungen\mse13\Desktop\SciLor's Grooveshark.com Downloader\Downloads\Downloads from net\Comedy - Mirja Boes - 2009 - Morgen Mach Ich Schluss Wahrscheinlich-2CD-Live\Brothers\Brothers Bar Community Toolbar für Internet Explorer.exe => Is moved successfully.

==== End of Fixlog 08:12:56 ====
         




FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by mse13ssd (administrator) on MSE13SSD-PC on 08-04-2015 10:35:24
Running from G:\Users\mse13ssd\Desktop
Loaded Profiles: mse13ssd (Available profiles: mse13ssd)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) G:\Windows\System32\atiesrxx.exe
(Logitech Inc.) G:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AVAST Software) G:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) G:\Windows\System32\atieclxx.exe
(Apple Inc.) G:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) G:\Program Files\Bonjour\mDNSResponder.exe
(Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Google Inc.) G:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
(Logitech Inc.) G:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) G:\Program Files\Windows Sidebar\sidebar.exe
(AVAST Software) G:\Program Files\AVAST Software\Avast\avastui.exe
() G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Advanced Micro Devices Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(SRWare) G:\Program Files (x86)\SRWare Iron\chrome.exe
(Microsoft Corporation) G:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Launch LCore] => G:\Program Files\Logitech Gaming Software\LCore.exe [10801944 2014-07-28] (Logitech Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => G:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software)
HKLM-x32\...\Run: [DivXMediaServer] => G:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-11-17] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [StartCCC] => G:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Raptr] => G:\Program Files (x86)\Raptr\raptrstub.exe [55568 2015-03-25] (Raptr, Inc)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => G:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3243151774-2580435505-251407729-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-15] (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> G:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-04-08] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> G:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-15] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> G:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-04-08] (Oracle Corporation)
Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - G:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll [2014-10-10] (pdfforge GmbH)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0

FireFox:
========
FF ProfilePath: G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default
FF Plugin: @adobe.com/FlashPlayer -> G:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_134.dll [2015-03-15] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> G:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll [2015-03-15] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> G:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2012-04-05] ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> G:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2014-11-21] (DivX, LLC)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> G:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> G:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-04-08] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> G:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-04-08] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> G:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> G:\Program Files (x86)\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> G:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-15] (Google Inc.)
FF Plugin-x32: Adobe Reader -> G:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Extension: Download videos and MP3s from YouTube - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-11-21]
FF Extension: Adblock Plus - G:\Users\mse13ssd\AppData\Roaming\Mozilla\Firefox\Profiles\255una7p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-09]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - G:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - G:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-17]
FF HKLM-x32\...\Firefox\Extensions: [pdf_architect_2_conv@pdfarchitect.org] - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension
FF Extension: PDF Architect 2 Creator - G:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2014-12-09]
FF HKU\S-1-5-21-3243151774-2580435505-251407729-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF Extension: Download videos and MP3s from YouTube - G:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-11-21]

Chrome: 
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Profile: G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-09]
CHR Extension: (Google Docs) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-09]
CHR Extension: (Google Drive) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-09]
CHR Extension: (Google Voice Search Hotword (Beta)) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-09]
CHR Extension: (YouTube) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-09]
CHR Extension: (Google Search) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-09]
CHR Extension: (Google Sheets) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-09]
CHR Extension: (Google Wallet) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-09]
CHR Extension: (Gmail) - G:\Users\mse13ssd\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-09]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - G:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-15]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; G:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-15] (AVAST Software)
S2 PDF Architect 2 Creator; G:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH)
S3 SandraAgentSrv; G:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.SP3c\RpcAgentSrv.exe [73712 2014-09-19] (SiSoftware) [File not signed]
R2 WinDefend; G:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; G:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 aswHwid; G:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-15] ()
R2 aswMonFlt; G:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-15] (AVAST Software)
R1 aswRdr; G:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-15] (AVAST Software)
R0 aswRvrt; G:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-15] ()
R1 aswSnx; G:\Windows\system32\drivers\aswSnx.sys [1041168 2014-11-21] (AVAST Software)
R1 aswSP; G:\Windows\system32\drivers\aswSP.sys [427360 2014-07-15] (AVAST Software)
R2 aswStm; G:\Windows\system32\drivers\aswStm.sys [92008 2014-07-15] (AVAST Software)
R0 aswVmm; G:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-15] ()
R3 LGSHidFilt; G:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S3 catchme; \??\G:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-08 10:35 - 2015-04-08 10:35 - 00012107 _____ () G:\Users\mse13ssd\Desktop\FRST.txt
2015-04-08 07:54 - 2015-04-08 07:54 - 00001019 _____ () G:\Users\Public\Desktop\SRWare Iron.lnk
2015-04-08 07:54 - 2015-04-08 07:54 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\SRWare Iron
2015-04-08 07:54 - 2015-04-08 07:54 - 00000000 ____D () G:\Program Files (x86)\SRWare Iron
2015-04-08 07:51 - 2015-04-08 07:51 - 44832392 _____ (SRWare ) G:\Users\mse13ssd\Downloads\srware_iron(2).exe
2015-04-08 07:49 - 2015-04-08 07:49 - 44827361 _____ (SRWare ) G:\Users\mse13ssd\Downloads\srware_iron(1).exe
2015-04-08 06:14 - 2015-04-08 06:14 - 00001267 _____ () G:\Users\mse13ssd\Desktop\Revo Uninstaller.lnk
2015-04-08 06:12 - 2015-04-08 06:12 - 02623656 _____ (VS Revo Group Ltd.) G:\Users\mse13ssd\Downloads\revosetup95.exe
2015-04-07 10:44 - 2015-04-07 10:44 - 00000000 ___SD () G:\Windows\SysWOW64\GWX
2015-04-07 10:44 - 2015-04-07 10:44 - 00000000 ___SD () G:\Windows\system32\GWX
2015-04-07 10:26 - 2015-04-07 10:26 - 00852607 _____ () G:\Users\mse13ssd\Downloads\SecurityCheck (2).exe
2015-04-07 10:19 - 2015-04-07 10:19 - 00008930 _____ () G:\Users\mse13ssd\Downloads\smime (2).p7s
2015-04-06 19:59 - 2015-04-06 19:59 - 02347384 _____ (ESET) G:\Users\mse13ssd\Downloads\esetsmartinstaller_deu (1).exe
2015-04-06 17:43 - 2015-04-06 17:43 - 00852607 _____ () G:\Users\mse13ssd\Downloads\SecurityCheck (1).exe
2015-04-06 17:41 - 2015-04-06 17:41 - 00852607 _____ () G:\Users\mse13ssd\Downloads\SecurityCheck.exe
2015-04-06 12:27 - 2015-04-06 12:27 - 02347384 _____ (ESET) G:\Users\mse13ssd\Downloads\esetsmartinstaller_deu.exe
2015-04-06 12:27 - 2015-04-06 12:27 - 00000000 ____D () G:\Program Files (x86)\ESET
2015-04-05 19:33 - 2015-04-05 19:33 - 00000207 _____ () G:\Windows\tweaking.com-regbackup-MSE13SSD-PC-Windows-7-Home-Premium-(64-bit).dat
2015-04-05 19:33 - 2015-04-05 19:33 - 00000000 ____D () G:\RegBackup
2015-04-05 18:35 - 2015-04-05 18:35 - 02690981 _____ (Thisisu) G:\Users\mse13ssd\Desktop\JRT.exe
2015-04-05 15:10 - 2015-04-05 15:10 - 00011639 _____ () G:\ComboFix.txt
2015-04-05 15:03 - 2015-04-05 15:10 - 00000000 ____D () G:\Qoobox
2015-04-05 15:03 - 2015-04-05 15:09 - 00000000 ____D () G:\Windows\erdnt
2015-04-05 15:03 - 2011-06-26 08:45 - 00256000 _____ () G:\Windows\PEV.exe
2015-04-05 15:03 - 2010-11-07 19:20 - 00208896 _____ () G:\Windows\MBR.exe
2015-04-05 15:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) G:\Windows\NIRCMD.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) G:\Windows\SWREG.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) G:\Windows\SWSC.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00098816 _____ () G:\Windows\sed.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00080412 _____ () G:\Windows\grep.exe
2015-04-05 15:03 - 2000-08-31 02:00 - 00068096 _____ () G:\Windows\zip.exe
2015-04-05 15:01 - 2015-04-05 15:01 - 05617096 ____R (Swearware) G:\Users\mse13ssd\Desktop\ComboFix.exe
2015-04-05 13:10 - 2015-04-05 13:11 - 00380416 _____ () G:\Users\mse13ssd\Downloads\liqvrrec.exe
2015-04-05 13:02 - 2015-04-08 10:35 - 00000000 ____D () G:\FRST
2015-04-05 13:02 - 2015-04-05 13:03 - 00048734 _____ () G:\Users\mse13ssd\Downloads\FRST.txt
2015-04-05 13:02 - 2015-04-05 13:03 - 00024876 _____ () G:\Users\mse13ssd\Downloads\Addition.txt
2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Downloads\FRST64 (1).exe
2015-04-05 13:00 - 2015-04-05 13:00 - 02095616 _____ (Farbar) G:\Users\mse13ssd\Desktop\FRST64.exe
2015-04-05 12:59 - 2015-04-05 12:59 - 00000478 _____ () G:\Users\mse13ssd\Downloads\defogger_disable.log
2015-04-05 12:59 - 2015-04-05 12:59 - 00000000 _____ () G:\Users\mse13ssd\defogger_reenable
2015-04-05 12:57 - 2015-04-05 12:57 - 00050477 _____ () G:\Users\mse13ssd\Downloads\Defogger.exe
2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (2).exe
2015-04-05 03:44 - 2015-04-05 03:44 - 02208768 _____ () G:\Users\mse13ssd\Downloads\adwcleaner_4.200 (1).exe
2015-04-05 03:38 - 2015-04-05 18:38 - 00000000 ____D () G:\AdwCleaner
2015-04-05 03:37 - 2015-04-05 03:38 - 02208768 _____ () G:\Users\mse13ssd\Desktop\adwcleaner_4.200.exe
2015-03-31 05:26 - 2015-03-31 05:26 - 00008930 _____ () G:\Users\mse13ssd\Downloads\smime (1).p7s
2015-03-28 00:47 - 2015-03-28 00:47 - 00012288 _____ () G:\Users\mse13ssd\Downloads\Qual-Fraktal.xls
2015-03-27 07:14 - 2015-03-27 07:14 - 00000000 ____D () G:\Users\mse13ssd\Desktop\SciLor's Grooveshark.com Downloader
2015-03-26 21:20 - 2015-03-26 21:20 - 671367548 _____ () G:\Windows\MEMORY.DMP
2015-03-26 21:20 - 2015-03-26 21:20 - 00274624 _____ () G:\Windows\Minidump\032615-29718-01.dmp
2015-03-25 04:31 - 2015-03-25 04:31 - 00002123 _____ () G:\Users\Public\Desktop\CONTRACT J.A.C.K. .lnk
2015-03-25 04:05 - 2015-03-25 04:05 - 00000000 ____D () G:\Program Files (x86)\Sierra
2015-03-25 04:04 - 2015-03-25 04:04 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sierra
2015-03-25 04:00 - 2003-06-26 10:45 - 00499712 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcp71.dll
2015-03-25 04:00 - 2003-06-26 10:45 - 00348160 ____N (Microsoft Corporation) G:\Windows\SysWOW64\msvcr71.dll
2015-03-25 04:00 - 2003-03-19 07:20 - 01060864 ____N (Microsoft Corporation) G:\Windows\SysWOW64\mfc71.dll
2015-03-22 18:27 - 2015-03-22 18:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files\Microsoft Silverlight
2015-03-21 10:34 - 2015-03-21 10:34 - 00000000 ____D () G:\Program Files (x86)\Microsoft Silverlight
2015-03-21 10:33 - 2015-03-21 10:33 - 13087456 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\Silverlight_x64.exe
2015-03-18 17:29 - 2015-03-18 17:29 - 00002023 _____ () G:\Users\mse13ssd\Desktop\Windows Phone-Desktopanwendung.lnk
2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Phone
2015-03-18 17:27 - 2015-03-18 17:27 - 00000000 ____D () G:\Program Files (x86)\Windows Phone
2015-03-18 17:25 - 2015-03-18 17:25 - 06745792 _____ (Microsoft Corporation) G:\Users\mse13ssd\Downloads\WindowsPhone.exe
2015-03-18 17:25 - 2015-03-18 17:25 - 00000000 ____D () G:\ProgramData\Applications
2015-03-16 19:19 - 2015-03-16 19:19 - 00001535 _____ () G:\Users\mse13ssd\Free YouTube to MP3 Converter.lnk
2015-03-15 17:32 - 2015-04-08 09:37 - 00001114 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-15 17:32 - 2015-04-08 08:12 - 00001110 _____ () G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-15 17:32 - 2015-03-15 17:32 - 00004110 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-03-15 17:32 - 2015-03-15 17:32 - 00003858 _____ () G:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-03-15 17:32 - 2015-03-15 17:32 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
2015-03-15 17:31 - 2015-03-15 17:31 - 00880208 _____ (Google Inc.) G:\Users\mse13ssd\Downloads\GoogleEarthSetup.exe
2015-03-14 07:06 - 2015-03-14 07:33 - 82044588 _____ () G:\Users\mse13ssd\Downloads\ES-X_DE.rar.crdownload
2015-03-12 09:28 - 2015-02-03 05:34 - 05554104 _____ (Microsoft Corporation) G:\Windows\system32\ntoskrnl.exe
2015-03-12 09:28 - 2015-02-03 05:34 - 00693176 _____ (Microsoft Corporation) G:\Windows\system32\winload.efi
2015-03-12 09:28 - 2015-02-03 05:34 - 00094656 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\mountmgr.sys
2015-03-12 09:28 - 2015-02-03 05:33 - 00616360 _____ (Microsoft Corporation) G:\Windows\system32\winresume.efi
2015-03-12 09:28 - 2015-02-03 05:31 - 14632960 _____ (Microsoft Corporation) G:\Windows\system32\wmp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 04121600 _____ (Microsoft Corporation) G:\Windows\system32\mf.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 01574400 _____ (Microsoft Corporation) G:\Windows\system32\quartz.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00782848 _____ (Microsoft Corporation) G:\Windows\system32\wmdrmsdk.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00641024 _____ (Microsoft Corporation) G:\Windows\system32\msscp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00503808 _____ (Microsoft Corporation) G:\Windows\system32\srcore.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00500224 _____ (Microsoft Corporation) G:\Windows\system32\AUDIOKSE.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00432128 _____ (Microsoft Corporation) G:\Windows\system32\mfplat.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00371712 _____ (Microsoft Corporation) G:\Windows\system32\qdvd.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00325632 _____ (Microsoft Corporation) G:\Windows\system32\msnetobj.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00229376 _____ (Microsoft Corporation) G:\Windows\system32\wintrust.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00206848 _____ (Microsoft Corporation) G:\Windows\system32\mfps.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00188416 _____ (Microsoft Corporation) G:\Windows\system32\pcasvc.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00063488 _____ (Microsoft Corporation) G:\Windows\system32\setbcdlocale.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00050176 _____ (Microsoft Corporation) G:\Windows\system32\srclient.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00037376 _____ (Microsoft Corporation) G:\Windows\system32\pcadm.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\msmmsp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\spwmp.dll
2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\msdxm.ocx
2015-03-12 09:28 - 2015-02-03 05:31 - 00005120 _____ (Microsoft Corporation) G:\Windows\system32\dxmasf.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 12625920 _____ (Microsoft Corporation) G:\Windows\system32\wmploc.DLL
2015-03-12 09:28 - 2015-02-03 05:30 - 01480192 _____ (Microsoft Corporation) G:\Windows\system32\crypt32.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 01202176 _____ (Microsoft Corporation) G:\Windows\system32\drmv2clt.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 01069056 _____ (Microsoft Corporation) G:\Windows\system32\cryptui.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00842240 _____ (Microsoft Corporation) G:\Windows\system32\blackbox.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00680960 _____ (Microsoft Corporation) G:\Windows\system32\audiosrv.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00631808 _____ (Microsoft Corporation) G:\Windows\system32\evr.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00497664 _____ (Microsoft Corporation) G:\Windows\system32\drmmgrtn.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00440832 _____ (Microsoft Corporation) G:\Windows\system32\AudioEng.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00296960 _____ (Microsoft Corporation) G:\Windows\system32\rstrui.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00296448 _____ (Microsoft Corporation) G:\Windows\system32\AudioSes.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00284672 _____ (Microsoft Corporation) G:\Windows\system32\EncDump.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00187904 _____ (Microsoft Corporation) G:\Windows\system32\cryptsvc.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00146944 _____ (Microsoft Corporation) G:\Windows\system32\appidpolicyconverter.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00140288 _____ (Microsoft Corporation) G:\Windows\system32\cryptnet.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00126464 _____ (Microsoft Corporation) G:\Windows\system32\audiodg.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00112640 _____ (Microsoft Corporation) G:\Windows\system32\smss.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00082432 _____ (Microsoft Corporation) G:\Windows\system32\cryptsp.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00058880 _____ (Microsoft Corporation) G:\Windows\system32\appidapi.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00055808 _____ (Microsoft Corporation) G:\Windows\system32\rrinstaller.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00043520 _____ (Microsoft Corporation) G:\Windows\system32\csrsrv.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00032256 _____ (Microsoft Corporation) G:\Windows\system32\appidsvc.dll
2015-03-12 09:28 - 2015-02-03 05:30 - 00024576 _____ (Microsoft Corporation) G:\Windows\system32\mfpmp.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00017920 _____ (Microsoft Corporation) G:\Windows\system32\appidcertstorecheck.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00011264 _____ (Microsoft Corporation) G:\Windows\system32\pcawrk.exe
2015-03-12 09:28 - 2015-02-03 05:30 - 00009728 _____ (Microsoft Corporation) G:\Windows\system32\pcalua.exe
2015-03-12 09:28 - 2015-02-03 05:29 - 00008704 _____ (Microsoft Corporation) G:\Windows\system32\pcaevts.dll
2015-03-12 09:28 - 2015-02-03 05:28 - 00006656 _____ (Microsoft Corporation) G:\Windows\system32\apisetschema.dll
2015-03-12 09:28 - 2015-02-03 05:28 - 00002048 _____ (Microsoft Corporation) G:\Windows\system32\mferror.dll
2015-03-12 09:28 - 2015-02-03 05:19 - 00663552 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\PEAuth.sys
2015-03-12 09:28 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntkrnlpa.exe
2015-03-12 09:28 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ntoskrnl.exe
2015-03-12 09:28 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mf.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) G:\Windows\SysWOW64\quartz.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) G:\Windows\SysWOW64\crypt32.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptui.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmv2clt.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\blackbox.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmdrmsdk.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) G:\Windows\SysWOW64\qdvd.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msscp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) G:\Windows\SysWOW64\evr.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AUDIOKSE.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\drmmgrtn.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioEng.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfplat.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msnetobj.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\AudioSes.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wintrust.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsvc.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptnet.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfps.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\cryptsp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) G:\Windows\SysWOW64\appidapi.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) G:\Windows\SysWOW64\srclient.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\spwmp.dll
2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msdxm.ocx
2015-03-12 09:28 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxmasf.dll
2015-03-12 09:28 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wmploc.DLL
2015-03-12 09:28 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\rrinstaller.exe
2015-03-12 09:28 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mfpmp.exe
2015-03-12 09:28 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mferror.dll
2015-03-12 09:28 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\apisetschema.dll
2015-03-12 09:28 - 2015-02-03 04:32 - 00061440 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\appid.sys
2015-03-12 09:28 - 2014-11-01 00:24 - 00619056 _____ (Microsoft Corporation) G:\Windows\system32\winload.exe
2015-03-12 09:28 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) G:\Windows\system32\winresume.exe
2015-03-12 09:28 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) G:\Windows\system32\ci.dll
2015-03-12 09:27 - 2015-03-06 07:56 - 00155576 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecpkg.sys
2015-03-12 09:27 - 2015-03-06 07:56 - 00095680 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\ksecdd.sys
2015-03-12 09:27 - 2015-03-06 07:42 - 01461760 _____ (Microsoft Corporation) G:\Windows\system32\lsasrv.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00728064 _____ (Microsoft Corporation) G:\Windows\system32\kerberos.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00341504 _____ (Microsoft Corporation) G:\Windows\system32\schannel.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00314880 _____ (Microsoft Corporation) G:\Windows\system32\msv1_0.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00309760 _____ (Microsoft Corporation) G:\Windows\system32\ncrypt.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00210944 _____ (Microsoft Corporation) G:\Windows\system32\wdigest.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00136192 _____ (Microsoft Corporation) G:\Windows\system32\sspicli.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00086528 _____ (Microsoft Corporation) G:\Windows\system32\TSpkg.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00029184 _____ (Microsoft Corporation) G:\Windows\system32\sspisrv.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00028160 _____ (Microsoft Corporation) G:\Windows\system32\secur32.dll
2015-03-12 09:27 - 2015-03-06 07:42 - 00022016 _____ (Microsoft Corporation) G:\Windows\system32\credssp.dll
2015-03-12 09:27 - 2015-03-06 07:41 - 00064000 _____ (Microsoft Corporation) G:\Windows\system32\auditpol.exe
2015-03-12 09:27 - 2015-03-06 07:41 - 00031232 _____ (Microsoft Corporation) G:\Windows\system32\lsass.exe
2015-03-12 09:27 - 2015-03-06 07:39 - 00060416 _____ (Microsoft Corporation) G:\Windows\system32\msobjs.dll
2015-03-12 09:27 - 2015-03-06 07:38 - 00146432 _____ (Microsoft Corporation) G:\Windows\system32\msaudite.dll
2015-03-12 09:27 - 2015-03-06 07:36 - 00686080 _____ (Microsoft Corporation) G:\Windows\system32\adtschema.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) G:\Windows\SysWOW64\kerberos.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msv1_0.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) G:\Windows\SysWOW64\schannel.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ncrypt.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wdigest.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) G:\Windows\SysWOW64\TSpkg.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) G:\Windows\SysWOW64\secur32.dll
2015-03-12 09:27 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) G:\Windows\SysWOW64\credssp.dll
2015-03-12 09:27 - 2015-03-06 07:09 - 00096768 _____ (Microsoft Corporation) G:\Windows\SysWOW64\sspicli.dll
2015-03-12 09:27 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) G:\Windows\SysWOW64\auditpol.exe
2015-03-12 09:27 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msaudite.dll
2015-03-12 09:27 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msobjs.dll
2015-03-12 09:27 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) G:\Windows\SysWOW64\adtschema.dll
2015-03-12 09:27 - 2015-02-24 05:15 - 00389800 _____ (Microsoft Corporation) G:\Windows\system32\iedkcs32.dll
2015-03-12 09:27 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iedkcs32.dll
2015-03-12 09:27 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.dll
2015-03-12 09:27 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieframe.dll
2015-03-12 09:27 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtmsft.dll
2015-03-12 09:27 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dxtrans.dll
2015-03-12 09:27 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.dll
2015-03-12 09:27 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) G:\Windows\system32\mshtmled.dll
2015-03-12 09:27 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmled.dll
2015-03-12 09:27 - 2015-02-20 06:41 - 00041984 _____ (Microsoft Corporation) G:\Windows\system32\lpk.dll
2015-03-12 09:27 - 2015-02-20 06:40 - 00100864 _____ (Microsoft Corporation) G:\Windows\system32\fontsub.dll
2015-03-12 09:27 - 2015-02-20 06:40 - 00046080 _____ (Adobe Systems) G:\Windows\system32\atmlib.dll
2015-03-12 09:27 - 2015-02-20 06:40 - 00014336 _____ (Microsoft Corporation) G:\Windows\system32\dciman32.dll
2015-03-12 09:27 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) G:\Windows\SysWOW64\fontsub.dll
2015-03-12 09:27 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) G:\Windows\SysWOW64\atmlib.dll
2015-03-12 09:27 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) G:\Windows\SysWOW64\dciman32.dll
2015-03-12 09:27 - 2015-02-20 06:12 - 00025600 _____ (Microsoft Corporation) G:\Windows\SysWOW64\lpk.dll
2015-03-12 09:27 - 2015-02-20 05:29 - 00372224 _____ (Adobe Systems Incorporated) G:\Windows\system32\atmfd.dll
2015-03-12 09:27 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\atmfd.dll
2015-03-12 09:27 - 2015-02-20 05:06 - 02724864 _____ (Microsoft Corporation) G:\Windows\system32\mshtml.tlb
2015-03-12 09:27 - 2015-02-20 05:05 - 00004096 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollectorres.dll
2015-03-12 09:27 - 2015-02-20 04:50 - 00066560 _____ (Microsoft Corporation) G:\Windows\system32\iesetup.dll
2015-03-12 09:27 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) G:\Windows\system32\vbscript.dll
2015-03-12 09:27 - 2015-02-20 04:49 - 00048640 _____ (Microsoft Corporation) G:\Windows\system32\ieetwproxystub.dll
2015-03-12 09:27 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) G:\Windows\system32\iertutil.dll
2015-03-12 09:27 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) G:\Windows\system32\MshtmlDac.dll
2015-03-12 09:27 - 2015-02-20 04:41 - 00054784 _____ (Microsoft Corporation) G:\Windows\system32\jsproxy.dll
2015-03-12 09:27 - 2015-02-20 04:40 - 00034304 _____ (Microsoft Corporation) G:\Windows\system32\iernonce.dll
2015-03-12 09:27 - 2015-02-20 04:36 - 00633856 _____ (Microsoft Corporation) G:\Windows\system32\ieui.dll
2015-03-12 09:27 - 2015-02-20 04:35 - 00144384 _____ (Microsoft Corporation) G:\Windows\system32\ieUnatt.exe
2015-03-12 09:27 - 2015-02-20 04:35 - 00114688 _____ (Microsoft Corporation) G:\Windows\system32\ieetwcollector.exe
2015-03-12 09:27 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) G:\Windows\system32\jscript9diag.dll
2015-03-12 09:27 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) G:\Windows\system32\jscript9.dll
2015-03-12 09:27 - 2015-02-20 04:26 - 00968704 _____ (Microsoft Corporation) G:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-12 09:27 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtml.tlb
2015-03-12 09:27 - 2015-02-20 04:22 - 00490496 _____ (Microsoft Corporation) G:\Windows\system32\dxtmsft.dll
2015-03-12 09:27 - 2015-02-20 04:13 - 00077824 _____ (Microsoft Corporation) G:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-12 09:27 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) G:\Windows\SysWOW64\vbscript.dll
2015-03-12 09:27 - 2015-02-20 04:08 - 00199680 _____ (Microsoft Corporation) G:\Windows\system32\msrating.dll
2015-03-12 09:27 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iesetup.dll
2015-03-12 09:27 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieetwproxystub.dll
2015-03-12 09:27 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) G:\Windows\SysWOW64\MshtmlDac.dll
2015-03-12 09:27 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) G:\Windows\system32\dxtrans.dll
2015-03-12 09:27 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iertutil.dll
2015-03-12 09:27 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jsproxy.dll
2015-03-12 09:27 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) G:\Windows\SysWOW64\iernonce.dll
2015-03-12 09:27 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieui.dll
2015-03-12 09:27 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9diag.dll
2015-03-12 09:27 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieUnatt.exe
2015-03-12 09:27 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) G:\Windows\system32\msfeeds.dll
2015-03-12 09:27 - 2015-02-20 03:49 - 00718848 _____ (Microsoft Corporation) G:\Windows\system32\ie4uinit.exe
2015-03-12 09:27 - 2015-02-20 03:47 - 01359360 _____ (Microsoft Corporation) G:\Windows\system32\mshtmlmedia.dll
2015-03-12 09:27 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) G:\Windows\system32\inetcpl.cpl
2015-03-12 09:27 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) G:\Windows\system32\ieframe.dll
2015-03-12 09:27 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) G:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-03-12 09:27 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msrating.dll
2015-03-12 09:27 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) G:\Windows\SysWOW64\jscript9.dll
2015-03-12 09:27 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) G:\Windows\system32\wininet.dll
2015-03-12 09:27 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) G:\Windows\SysWOW64\inetcpl.cpl
2015-03-12 09:27 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msfeeds.dll
2015-03-12 09:27 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) G:\Windows\SysWOW64\mshtmlmedia.dll
2015-03-12 09:27 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) G:\Windows\system32\urlmon.dll
2015-03-12 09:27 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) G:\Windows\system32\ieapfltr.dll
2015-03-12 09:27 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) G:\Windows\SysWOW64\wininet.dll
2015-03-12 09:27 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) G:\Windows\SysWOW64\urlmon.dll
2015-03-12 09:27 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ieapfltr.dll
2015-03-12 09:27 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) G:\Windows\SysWOW64\shell32.dll
2015-03-12 09:27 - 2015-02-13 07:22 - 14177280 _____ (Microsoft Corporation) G:\Windows\system32\shell32.dll
2015-03-12 09:27 - 2015-02-03 05:31 - 01424896 _____ (Microsoft Corporation) G:\Windows\system32\WindowsCodecs.dll
2015-03-12 09:27 - 2015-02-03 05:31 - 00215552 _____ (Microsoft Corporation) G:\Windows\system32\ubpm.dll
2015-03-12 09:27 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WindowsCodecs.dll
2015-03-12 09:27 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) G:\Windows\SysWOW64\ubpm.dll
2015-03-12 09:27 - 2015-01-31 05:48 - 03179520 _____ (Microsoft Corporation) G:\Windows\system32\rdpcorets.dll
2015-03-12 09:27 - 2015-01-31 05:48 - 00016384 _____ (Microsoft Corporation) G:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-12 09:27 - 2015-01-31 01:56 - 00459336 _____ (Microsoft Corporation) G:\Windows\system32\Drivers\cng.sys
2015-03-12 09:27 - 2015-01-31 01:56 - 00243200 _____ (Microsoft Corporation) G:\Windows\system32\rdpudd.dll
2015-03-12 09:27 - 2015-01-17 04:48 - 01067520 _____ (Microsoft Corporation) G:\Windows\system32\msctf.dll
2015-03-12 09:27 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) G:\Windows\SysWOW64\msctf.dll
2015-03-12 09:26 - 2015-02-26 05:25 - 03204096 _____ (Microsoft Corporation) G:\Windows\system32\win32k.sys
2015-03-12 09:26 - 2015-02-04 05:16 - 00465920 _____ (Microsoft Corporation) G:\Windows\system32\WMPhoto.dll
2015-03-12 09:26 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) G:\Windows\SysWOW64\WMPhoto.dll
2015-03-10 01:20 - 2015-03-10 01:20 - 00001002 _____ () G:\Users\mse13ssd\Downloads\BAHN_Fahrplan_20150609.ics
2015-03-09 11:16 - 2015-03-09 11:56 - 124202474 _____ () G:\Users\mse13ssd\Downloads\#0325#.rar

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-08 10:13 - 2014-05-17 10:22 - 01484543 _____ () G:\Windows\WindowsUpdate.log
2015-04-08 08:19 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-08 08:19 - 2009-07-14 06:45 - 00013552 ____H () G:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-08 08:16 - 2009-07-14 19:58 - 00700986 _____ () G:\Windows\system32\perfh007.dat
2015-04-08 08:16 - 2009-07-14 19:58 - 00149886 _____ () G:\Windows\system32\perfc007.dat
2015-04-08 08:16 - 2009-07-14 07:13 - 01619284 _____ () G:\Windows\system32\PerfStringBackup.INI
2015-04-08 08:13 - 2014-07-13 00:21 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Raptr
2015-04-08 08:12 - 2014-05-17 22:03 - 00000000 _____ () G:\Windows\system32\Drivers\lvuvc.hs
2015-04-08 08:12 - 2014-05-17 15:20 - 00034368 _____ () G:\Windows\PFRO.log
2015-04-08 08:12 - 2009-07-14 07:08 - 00000006 ____H () G:\Windows\Tasks\SA.DAT
2015-04-08 08:12 - 2009-07-14 06:51 - 00055859 _____ () G:\Windows\setupact.log
2015-04-08 06:14 - 2014-05-17 12:42 - 00000000 ____D () G:\Program Files (x86)\VS Revo Group
2015-04-08 05:43 - 2014-05-17 22:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\Skype
2015-04-08 00:59 - 2014-10-01 13:55 - 00098216 _____ (Oracle Corporation) G:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-04-08 00:59 - 2014-10-01 13:55 - 00000000 ____D () G:\Program Files (x86)\Java
2015-04-07 22:29 - 2014-05-17 20:13 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\TS3Client
2015-04-07 10:10 - 2014-05-17 15:57 - 00004182 _____ () G:\Windows\System32\Tasks\avast! Emergency Update
2015-04-05 18:19 - 2015-03-05 14:19 - 00129752 _____ (Malwarebytes Corporation) G:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-05 15:10 - 2009-07-14 05:20 - 00000000 __RHD () G:\Users\Default
2015-04-05 15:09 - 2009-07-14 04:34 - 00000215 _____ () G:\Windows\system.ini
2015-04-05 13:19 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\NDF
2015-04-05 12:59 - 2014-05-17 11:54 - 00000000 ____D () G:\Users\mse13ssd
2015-04-05 03:26 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\Web
2015-04-02 01:34 - 2009-07-14 07:32 - 00000000 ____D () G:\Windows\system32\FxsTmp
2015-03-30 17:36 - 2015-02-28 05:38 - 00000000 ____D () G:\Users\mse13ssd\Desktop\aufgeräumt
2015-03-30 08:10 - 2014-11-01 08:15 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\25372
2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\Users\mse13ssd\AppData\Roaming\DivX
2015-03-30 04:33 - 2014-08-24 02:01 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
2015-03-30 04:33 - 2014-08-24 02:00 - 00000000 ____D () G:\ProgramData\DivX
2015-03-30 04:33 - 2014-05-17 15:57 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2015-03-30 04:33 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\AppCompat
2015-03-30 04:32 - 2014-08-24 02:01 - 00000000 ____D () G:\Program Files\DivX
2015-03-30 04:32 - 2014-08-24 02:00 - 00000000 ____D () G:\Program Files (x86)\DivX
2015-03-30 04:32 - 2014-06-18 17:31 - 00000000 ____D () G:\Program Files (x86)\Microsoft Office
2015-03-30 04:32 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\registration
2015-03-30 03:27 - 2009-07-14 20:18 - 00000000 ___RD () G:\Users\Public\Recorded TV
2015-03-26 21:20 - 2014-10-12 12:01 - 00000000 ____D () G:\Windows\Minidump
2015-03-26 18:51 - 2014-07-13 00:21 - 00000000 ____D () G:\Program Files (x86)\Raptr
2015-03-26 09:13 - 2014-06-18 17:31 - 00000000 ____D () G:\ProgramData\Microsoft Help
2015-03-22 18:29 - 2014-05-17 12:40 - 00070368 _____ () G:\Users\mse13ssd\AppData\Local\GDIPFONTCACHEV1.DAT
2015-03-22 18:29 - 2009-07-14 06:45 - 00307752 _____ () G:\Windows\system32\FNTCACHE.DAT
2015-03-22 18:25 - 2014-06-18 17:32 - 00000000 ____D () G:\Program Files (x86)\Microsoft Works
2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Google
2015-03-15 17:32 - 2015-01-09 01:32 - 00000000 ____D () G:\Program Files (x86)\Google
2015-03-15 14:09 - 2014-08-24 13:49 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Adobe
2015-03-15 14:09 - 2014-05-17 15:53 - 00778928 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerApp.exe
2015-03-15 14:09 - 2014-05-17 15:53 - 00142512 _____ (Adobe Systems Incorporated) G:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-03-15 05:05 - 2014-06-21 18:28 - 00000000 ____D () G:\Program Files (x86)\Steam
2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Users\mse13ssd\AppData\Local\Glyph
2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glyph
2015-03-13 17:39 - 2015-02-17 02:30 - 00000000 ____D () G:\Program Files (x86)\Glyph
2015-03-13 10:32 - 2009-07-14 07:09 - 00000000 ____D () G:\Windows\System32\Tasks\WPD
2015-03-12 12:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\rescache
2015-03-12 09:37 - 2015-02-28 09:01 - 00000000 ___RD () G:\Users\mse13ssd\Virtual Machines
2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\SysWOW64\Dism
2015-03-12 09:34 - 2009-07-14 05:20 - 00000000 ____D () G:\Windows\system32\Dism
2015-03-12 09:31 - 2014-05-17 20:36 - 00000000 ____D () G:\Windows\system32\MRT
2015-03-12 09:29 - 2014-05-17 20:36 - 122905848 _____ (Microsoft Corporation) G:\Windows\system32\MRT.exe

==================== Files in the root of some directories =======

2014-10-02 16:29 - 2015-02-28 12:40 - 14286848 _____ () G:\Users\mse13ssd\AppData\Roaming\Sandra.mdb
2015-01-23 13:40 - 2015-01-23 13:40 - 0003584 _____ () G:\Users\mse13ssd\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-01 14:58 - 2015-01-01 14:58 - 0007605 _____ () G:\Users\mse13ssd\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

G:\Windows\System32\winlogon.exe => File is digitally signed
G:\Windows\System32\wininit.exe => File is digitally signed
G:\Windows\SysWOW64\wininit.exe => File is digitally signed
G:\Windows\explorer.exe => File is digitally signed
G:\Windows\SysWOW64\explorer.exe => File is digitally signed
G:\Windows\System32\svchost.exe => File is digitally signed
G:\Windows\SysWOW64\svchost.exe => File is digitally signed
G:\Windows\System32\services.exe => File is digitally signed
G:\Windows\System32\User32.dll => File is digitally signed
G:\Windows\SysWOW64\User32.dll => File is digitally signed
G:\Windows\System32\userinit.exe => File is digitally signed
G:\Windows\SysWOW64\userinit.exe => File is digitally signed
G:\Windows\System32\rpcss.dll => File is digitally signed
G:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-04 00:45

==================== End Of Log ============================
         
--- --- ---






Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
Ran by mse13ssd at 2015-04-08 10:35:59
Running from G:\Users\mse13ssd\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
AGEIA PhysX v7.11.13 (HKLM-x32\...\{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}) (Version: 7.11.13 - AGEIA Technologies, Inc.)
Agent Ransack x64 (HKLM\...\{58C0AC50-8FA1-4A95-AEC6-5B2727E5CC6A}) (Version: 7.0.820.1 - Mythicsoft Ltd)
AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Apple Application Support (HKLM-x32\...\{122ADF8C-DDA1-480C-9936-C88F2825B265}) (Version: 2.1.9 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}) (Version: 5.2.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Archeage (HKLM-x32\...\Glyph Archeage) (Version:  - Trion Worlds, Inc.)
ArtMoney SE v7.43 (HKLM-x32\...\ArtMoney SE_is1) (Version: 7.43 - System SoftLab)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software)
Avery Wizard 5.0 (HKLM-x32\...\{FC3B3A5D-7058-4627-9F1E-F95CC38B6054}) (Version: 5.0.5 - Avery)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Borderlands 2 (HKLM-x32\...\Steam App 49520) (Version:  - Gearbox Software)
Canon iP7200 series Benutzerregistrierung (HKLM-x32\...\Canon iP7200 series Benutzerregistrierung) (Version:  - Canon Inc.‎)
Canon iP7200 series Printer Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP7200_series) (Version:  - Canon Inc.)
Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version:  - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.0.0 - Canon Inc.)
CanoScan LiDE 110 Scanner Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ2414) (Version:  - Canon Inc.)
ClipboardManager 1.6 (HKLM-x32\...\ClipboardManager_is1) (Version:  - )
Contract Jack (HKLM-x32\...\{374CAB30-2F61-4439-9A4A-24D3AEA2960A}) (Version:  - )
CPUID CPU-Z 1.70 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Die Siedler II - Die nächste Generation (HKLM-x32\...\S2TNG) (Version:  - )
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.7.0.31 - DivX, LLC)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
Free YouTube Download version 3.2.53.128 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.53.128 - DVDVideoSoft Ltd.)
Free YouTube to MP3 Converter version 3.12.50.1111 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.50.1111 - DVDVideoSoft Ltd.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
GUILD WARS (HKLM-x32\...\Guild Wars) (Version:  - )
iTunes (HKLM\...\{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}) (Version: 10.6.3.25 - Apple Inc.)
Java 8 Update 40 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
Logitech Gaming Software 8.55 (HKLM\...\Logitech Gaming Software) (Version: 8.55.137 - Logitech Inc.)
Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Mozilla Firefox 36.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 36.0 (x86 de)) (Version: 36.0 - Mozilla)
paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC)
Pamela Pro 4.9 (HKLM-x32\...\Pamela) (Version: 4.9 - PamConsult GmbH)
PDF Architect 2 Create Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.0.0 - pdfforge)
Raptr (HKLM-x32\...\Raptr) (Version:  - )
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SciLor's grooveshark™.com Downloader 0.4.15 (HKLM-x32\...\{DDEAE484-D5FB-49CB-BD47-9512E8ACCA65}_is1) (Version: 0.4.15 - SciLor)
SiSoftware Sandra Lite 2014.SP3c (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2496}_is1) (Version: 20.47.2014.10 - SiSoftware)
Skype™ 7.1 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.)
SRWare Iron Version SRWare Iron 41.2200.0 (HKLM-x32\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: SRWare Iron 41.2200.0 - SRWare)
Steam (HKLM-x32\...\Steam) (Version:  - Valve Corporation)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version:  - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version:  - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version:  - Microsoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
Windows Phone app for desktop (HKLM-x32\...\{19773614-FC22-4ACC-AAA3-E6BDA81ACF92}) (Version: 1.1.2726.0 - Microsoft Corporation)
WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

01-04-2015 19:32:07 Windows Update
05-04-2015 15:04:11 ComboFix created restore point
07-04-2015 10:44:02 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2015-04-05 15:09 - 00000027 ____A G:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {1FC3D3B2-F254-4B57-9695-FFF62B3AC150} - System32\Tasks\GoogleUpdateTaskMachineCore => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15] (Google Inc.)
Task: {34D4B971-AD1B-4F8D-8ED4-6F6BF7ABE60D} - System32\Tasks\avast! Emergency Update => G:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-07-15] (AVAST Software)
Task: {4FEEE84D-7E59-4CDF-B74D-B91A75A59971} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => G:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation)
Task: {97825458-5F0E-4103-805A-204524B8F97C} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => G:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {BD6EFB7D-29B9-4725-B4CB-C2F47B685F42} - System32\Tasks\Abelssoft\Updater scan => G:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe
Task: {D34A6BF5-32B4-4467-9D46-CA4D3DED9394} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => G:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: {DB431844-F8D5-409D-A115-BB442A487B85} - System32\Tasks\GoogleUpdateTaskMachineUA => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-15] (Google Inc.)
Task: {E57F8AB1-453C-45BC-BF7F-E700E5C6EBA9} - System32\Tasks\Adobe Acrobat Update Task => G:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {F818CCEB-3516-47E4-BCF8-6CBFB192089F} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => G:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation)
Task: G:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: G:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => G:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) ==============

2014-07-28 20:29 - 2014-07-28 20:29 - 00866584 _____ () G:\Program Files\Logitech Gaming Software\libGLESv2.dll
2014-07-28 20:32 - 2014-07-28 20:32 - 01050904 _____ () G:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2014-07-28 20:29 - 2014-07-28 20:29 - 00059160 _____ () G:\Program Files\Logitech Gaming Software\libEGL.dll
2014-07-28 20:31 - 2014-07-28 20:31 - 00242456 _____ () G:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2014-01-10 07:26 - 2014-01-10 07:26 - 01861968 _____ () G:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2014-07-15 08:28 - 2014-07-15 08:28 - 00301152 _____ () G:\Program Files\AVAST Software\Avast\aswProperty.dll
2015-04-07 22:11 - 2015-04-07 22:11 - 02924544 _____ () G:\Program Files\AVAST Software\Avast\defs\15040701\algo.dll
2012-05-30 20:06 - 2012-05-30 20:06 - 00087912 _____ () G:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2012-05-30 20:06 - 2012-05-30 20:06 - 01242512 _____ () G:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-07-15 08:28 - 2014-07-15 08:28 - 19329904 _____ () G:\Program Files\AVAST Software\Avast\libcef.dll
2014-01-10 07:28 - 2014-01-10 07:28 - 00100688 _____ () G:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
2015-04-08 07:54 - 2015-03-04 10:54 - 01482240 _____ () G:\Program Files (x86)\SRWare Iron\libglesv2.dll
2015-04-08 07:54 - 2015-03-04 10:54 - 00073728 _____ () G:\Program Files (x86)\SRWare Iron\libegl.dll
2015-04-08 07:54 - 2015-03-08 11:12 - 09579008 _____ () G:\Program Files (x86)\SRWare Iron\pdf.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: G:\Users\mse13ssd\Downloads\email_5937_20150205205259.eml:OECustomProperty

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3243151774-2580435505-251407729-1001\Control Panel\Desktop\\Wallpaper -> G:\Users\mse13ssd\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.0.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: bthserv => 3
MSCONFIG\Services: DPS => 2
MSCONFIG\Services: SensrSvc => 3
MSCONFIG\startupreg: Adobe ARM => "G:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: APSDaemon => "G:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: iTunesHelper => "G:\Program Files (x86)\iTunes\iTunesHelper.exe"

==================== Accounts: =============================

Administrator (S-1-5-21-3243151774-2580435505-251407729-500 - Administrator - Disabled)
Gast (S-1-5-21-3243151774-2580435505-251407729-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3243151774-2580435505-251407729-1002 - Limited - Enabled)
mse13ssd (S-1-5-21-3243151774-2580435505-251407729-1001 - Administrator - Enabled) => G:\Users\mse13ssd

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (04/08/2015 08:12:35 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x6a0
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3

Error: (04/08/2015 06:14:44 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: chrome.exe, Version: 39.0.2171.65, Zeitstempel: 0x5482f276
Name des fehlerhaften Moduls: chrome.dll, Version: 39.0.2171.65, Zeitstempel: 0x5482f23e
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00043bcd
ID des fehlerhaften Prozesses: 0x128c
Startzeit der fehlerhaften Anwendung: 0xchrome.exe0
Pfad der fehlerhaften Anwendung: chrome.exe1
Pfad des fehlerhaften Moduls: chrome.exe2
Berichtskennung: chrome.exe3

Error: (04/08/2015 06:13:30 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/08/2015 06:13:30 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/08/2015 02:14:25 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/07/2015 10:10:33 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x5cc
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3

Error: (04/07/2015 03:22:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x514
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3

Error: (04/07/2015 00:47:54 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/06/2015 07:59:18 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: G:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: G:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/06/2015 07:55:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: creator-ws.exe, Version: 1.0.0.0, Zeitstempel: 0x5437c98f
Name des fehlerhaften Moduls: MSVCR110.dll, Version: 11.0.51106.1, Zeitstempel: 0x5098858e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000a327c
ID des fehlerhaften Prozesses: 0x50c
Startzeit der fehlerhaften Anwendung: 0xcreator-ws.exe0
Pfad der fehlerhaften Anwendung: creator-ws.exe1
Pfad des fehlerhaften Moduls: creator-ws.exe2
Berichtskennung: creator-ws.exe3


System errors:
=============
Error: (04/08/2015 08:12:39 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/08/2015 08:12:13 AM) (Source: Ntfs) (EventID: 137) (User: )
Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (04/07/2015 10:10:38 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/07/2015 10:10:12 AM) (Source: Ntfs) (EventID: 137) (User: )
Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (04/07/2015 03:22:44 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/07/2015 03:22:17 AM) (Source: Ntfs) (EventID: 137) (User: )
Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (04/06/2015 07:55:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "PDF Architect 2 Creator" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (04/06/2015 07:55:30 PM) (Source: Ntfs) (EventID: 137) (User: )
Description: Auf dem Volume "D:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (04/06/2015 10:14:00 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}


Microsoft Office Sessions:
=========================

==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz
Percentage of memory in use: 13%
Total physical RAM: 16384 MB
Available physical RAM: 14208.54 MB
Total Pagefile: 32766.19 MB
Available Pagefile: 30427.84 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.5 GB) (Free:736.3 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:0.01 GB) (Free:0 GB) NTFS
Drive f: (Nolf2xp_1) (CDROM) (Total:0.64 GB) (Free:0 GB) CDFS
Drive g: (SSD) (Fixed) (Total:119.24 GB) (Free:25.43 GB) NTFS
Drive m: (SAMSUNG) (Fixed) (Total:1396.92 GB) (Free:834.32 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: 7E008421)
Partition 1: (Active) - (Size=119.2 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 1CA61CA5)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=7 MB) - (Type=07 NTFS)

========================================================
Disk: 6 (Size: 1397.3 GB) (Disk ID: 5C9C6FA9)
Partition 1: (Not Active) - (Size=1397.3 GB) - (Type=0C)

==================== End Of Log ============================
         

Alt 08.04.2015, 17:42   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen - Standard

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen



Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 08.04.2015, 17:48   #11
MSE XIII
 
Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen - Standard

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen



Nein, kann keine feststellen. Vielen Dank dafür!

LG, MSE XIII

Alt 09.04.2015, 08:15   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen - Standard

Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen



Cleanup:
(Die Reihenfolge ist hier entscheidend)

Falls Defogger verwendet wurde: Erneut starten und auf Re-enable klicken.

Falls Combofix verwendet wurde:
Combofix deinstallieren .
  • Wichtig: Bitte Antivirus-Programm, evtl. vorhandenes Skript-Blocking und Anti-Malware Programme deaktivieren.
  • Drücke bitte die + R Taste und schreibe Combofix /Uninstall in das Ausführen-Fenster.
  • Klicke auf OK.
    Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert.
  • Nun die eben deaktivierten Programme wieder aktivieren.

Alle Logs gepostet? Dann lade Dir bitte DelFix herunter.
  • Schließe alle offenen Programme.
  • Starte die delfix.exe mit einem Doppelklick.
  • Setze vor jede Funktion ein Häkchen.
  • Klicke auf Start.

Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen.

Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...und/oder das Forum mit einer kleinen Spende unterstützen.

Absicherung:
Beim Betriebsystem Windows die automatischen Updates aktivieren. Auch die sicherheitsrelevante Software sollte immer nur in der aktuellsten Version vorliegen:

Browser
Java
Flash-Player
PDF-Reader

Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren.
Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen.

Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig.

Verwende ein Antivirusprogramm mit Echtzeitscanner und stets aktueller Signaturendatenbank.
Meine Empfehlung:

Emsisoft

Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und ESET scannen.

Optional:
NoScript verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen.
Malwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen.


Lade Software von einem sauberen Portal wie .
Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen.
Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwarecleaner .


Abschließend noch ein paar grundsätzliche Bemerkungen:
Ändere regelmäßig Deine wichtigen Online-Passwörter und erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems.
Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen
agent, alter, alternative, anderen, angeblich, anleitung, autostart, avast, beiträge, bestimmte, bestimmten, code, cpu-z, deaktivieren, direkt, entfernen, fehler, folge, folgende, gelöscht, installer, launch, nachfrage, nichts, revo uninstaller, versucht, win, zeichen




Ähnliche Themen: Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen


  1. Ads By Savepath Deals entfernen
    Anleitungen, FAQs & Links - 14.11.2015 (2)
  2. Awesome deals for you! entfernen
    Anleitungen, FAQs & Links - 06.11.2015 (2)
  3. Ads By Deals Cabin entfernen
    Anleitungen, FAQs & Links - 03.09.2015 (2)
  4. Ads By Linkey Deals entfernen
    Anleitungen, FAQs & Links - 26.08.2015 (2)
  5. Ads by Shopping Deals entfernen
    Anleitungen, FAQs & Links - 19.08.2015 (2)
  6. Ads By Tremendous Deals entfernen
    Anleitungen, FAQs & Links - 13.08.2015 (2)
  7. Kaspersky 15 installation konnte JETZT DOCH (nicht) durchgeführt werden wg. "Basefiltering engine nicht vorhanden" Super Arbeit.
    Lob, Kritik und Wünsche - 01.02.2015 (0)
  8. Champion Deals entfernen
    Anleitungen, FAQs & Links - 31.08.2014 (2)
  9. Deals Fox entfernen
    Anleitungen, FAQs & Links - 09.05.2014 (2)
  10. AVG konnte 2 Viren nicht entfernen
    Plagegeister aller Art und deren Bekämpfung - 02.05.2014 (13)
  11. Browse Pax Deals entfernen
    Anleitungen, FAQs & Links - 24.03.2014 (2)
  12. ShopGlider entfernen
    Anleitungen, FAQs & Links - 13.02.2014 (2)
  13. Deals App Browser entfernen
    Anleitungen, FAQs & Links - 20.11.2013 (2)
  14. OutoBox Deals entfernen
    Anleitungen, FAQs & Links - 16.11.2013 (2)
  15. Dingo Deals entfernen
    Anleitungen, FAQs & Links - 12.11.2013 (2)
  16. Savepath Deals entfernen
    Anleitungen, FAQs & Links - 12.09.2013 (2)
  17. Probleme fingen mit Avira update an!Konnte asktoolbar nicht entfernen!Pc langsam
    Plagegeister aller Art und deren Bekämpfung - 27.10.2012 (10)

Zum Thema Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen - Hallo, vorab vielen Dank für die Möglichkeit, hier Hilfe zu finden. Und ein Wort zu mir. Ich bezeichne mich generell als DAU, da ich nur in ganz bestimmten Gebieten Teilwissen - Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen...
Archiv
Du betrachtest: Win 7: konnte ShopGlider Deals bis jetzt nicht entfernen auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.