Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Werbung öffnet sich Immer

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 23.07.2013, 09:22   #1
Rejono
 
Werbung öffnet sich Immer - Standard

Werbung öffnet sich Immer



Hallo.

Seit gestern öffnet sich bei mir immer so eine Werbung.



Habe nichts installiert außer einmal auf eine Seiten Werbung geklickt.

Zitat:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:19:26, on 23.07.2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16635)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\ROCCAT\Kova[+] Mouse\Kova[+]Monitor.exe
E:\DriveMonitor\adm_tray.exe
C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\CNYHKEY.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Theo Hulok\Downloads\HiJackThis204.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK/4
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=ds&q={searchTerms}&installDate=14/06/2013
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=ds&q={searchTerms}&installDate=14/06/2013
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=hp&installDate=14/06/2013
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=ds&q={searchTerms}&installDate=14/06/2013
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=ds&q={searchTerms}&installDate=14/06/2013
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O2 - BHO: Updater For Spam Free Search Bar - {20a0be68-8fd9-4539-8712-ce3d1c1fdfc6} - C:\Program Files (x86)\blekkotb\auxi\blekkoAu.dll
O2 - BHO: Spam Free Search Bar - {26c9e18c-3717-4be1-a225-04e4471f5b6e} - C:\Program Files (x86)\blekkotb\blekkoDx.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: ChromeFrame BHO - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files (x86)\Google\Chrome Frame\Application\28.0.1500.71\npchrome_frame.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: Spam Free Search Bar - {26c9e18c-3717-4be1-a225-04e4471f5b6e} - C:\Program Files (x86)\blekkotb\blekkoDx.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
O4 - HKLM\..\Run: [LaunchHPOSIAPP] C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [RoccatKova+] "C:\Program Files (x86)\ROCCAT\Kova[+] Mouse\Kova[+]Monitor.EXE"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [adm_tray.exe] E:\DriveMonitor\adm_tray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [SSync] "C:\Users\Theo Hulok\AppData\Roaming\SSync\SSync.exe"
O4 - HKCU\..\Run: [DataMgr] "C:\Users\Theo Hulok\AppData\Roaming\DataMgr\DataMgr.exe"
O4 - HKCU\..\Run: [SCheck] "C:\Users\Theo Hulok\AppData\Roaming\SCheck\SCheck.exe" check nohp nods
O4 - HKCU\..\Run: [Snoozer] "C:\Users\Theo Hulok\AppData\Roaming\Snz\Snz.exe"
O4 - HKCU\..\Run: [Intermediate] "C:\Users\Theo Hulok\AppData\Roaming\Intermediate\Intermediate.exe"
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files (x86)\ICQ7.6\ICQ.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O18 - Protocol: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files (x86)\Google\Chrome Frame\Application\28.0.1500.71\npchrome_frame.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update-Dienst (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Netzmanager Infrastruktur Informationssystem Dienst (Netzmanager Service) - Deutsche Telekom AG - C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe
O23 - Service: Acronis OS Selector Activator (OS Selector) - Unknown owner - C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 15598 bytes

Alt 23.07.2013, 10:51   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Werbung öffnet sich Immer - Standard

Werbung öffnet sich Immer



hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)



So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________

__________________

Alt 23.07.2013, 11:19   #3
Rejono
 
Werbung öffnet sich Immer - Standard

Werbung öffnet sich Immer




FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-07-2013 01
Ran by Theo Hulok (administrator) on 23-07-2013 12:17:10
Running from C:\Users\Theo Hulok\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Windows\system32\atieclxx.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Hewlett-Packard ) C:\Program Files\IDT\WDM\beats64.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
() C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Roccat GmbH) C:\Program Files (x86)\ROCCAT\Kova[+] Mouse\Kova[+]Monitor.exe
() E:\DriveMonitor\adm_tray.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\CNYHKEY.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\NOTEPAD.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [BeatsOSDApp] - C:\Program Files\IDT\WDM\beats64.exe [37888 2010-08-15] (Hewlett-Packard )
HKLM\...\Run: [hpsysdrv] - c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [489472 2010-09-27] (IDT, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-03-15] (Adobe Systems Incorporated)
HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [462400 2011-02-12] (Acronis)
HKLM\...\Winlogon: [Userinit] c:\windows\system32\userinit.exe,C:\Windows\SysWOW64\MPK\mpk.exe
HKCU\...\Run: [SSync] - C:\Users\Theo Hulok\AppData\Roaming\SSync\SSync.exe [36864 2013-04-10] ()
HKCU\...\Run: [DataMgr] - C:\Users\Theo Hulok\AppData\Roaming\DataMgr\DataMgr.exe [168848 2013-06-26] (HTTO Group, Ltd.)
HKCU\...\Run: [SCheck] - C:\Users\Theo Hulok\AppData\Roaming\SCheck\SCheck.exe [36864 2013-04-10] ()
HKCU\...\Run: [Snoozer] - C:\Users\Theo Hulok\AppData\Roaming\Snz\Snz.exe [1137673 2013-07-21] ()
HKCU\...\Run: [Intermediate] - C:\Users\Theo Hulok\AppData\Roaming\Intermediate\Intermediate.exe [36864 2013-04-10] ()
HKCU\...\Policies\system: [DisableLockWorkstation] 0
HKCU\...\Policies\system: [DisableChangePassword] 0
MountPoints2: {ef5961cd-e1f9-11e1-b0e5-e0699581b5e4} - J:\raf_di_goty.exe
HKLM-x32\...\Run: [] -  [x]
HKLM-x32\...\Run: [BATINDICATOR] - C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe [2068992 2009-05-09] (Hewlett-Packard)
HKLM-x32\...\Run: [LaunchHPOSIAPP] - C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe [385024 2009-04-04] (Hewlett-Packard)
HKLM-x32\...\Run: [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4858968 2013-05-09] (AVAST Software)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-10-17] (Intel Corporation)
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [RoccatKova+] - "C:\Program Files (x86)\ROCCAT\Kova[+] Mouse\Kova[+]Monitor.EXE" [539688 2011-03-17] (Roccat GmbH)
HKLM-x32\...\Run: [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-08-27] (Apple Inc.)
HKLM-x32\...\Run: [adm_tray.exe] - E:\DriveMonitor\adm_tray.exe [470120 2011-02-24] ()
HKLM-x32\...\Run: [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [642656 2013-03-28] (Advanced Micro Devices, Inc.)
HKU\Mcx1-THEOHULOK-HP\...\Winlogon: [Shell] C:\Windows\eHome\McrMgr.exe [343552 2009-07-14] (Microsoft Corporation) <==== ATTENTION 

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=hp&installDate=14/06/2013
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPDSK/4
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=ds&q={searchTerms}&installDate=14/06/2013
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=ds&q={searchTerms}&installDate=14/06/2013
SearchScopes: HKLM - DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPDTDF
SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPDTDF
SearchScopes: HKLM - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms}
SearchScopes: HKLM - {d944bb61-2e34-4dbf-a683-47e505c587dc} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-0/4?satitle={searchTerms}&mfe=Desktops
SearchScopes: HKLM - {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=ds&q={searchTerms}&installDate=14/06/2013
SearchScopes: HKLM-x32 - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=ds&q={searchTerms}&installDate=14/06/2013
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=ds&q={searchTerms}&installDate=14/06/2013
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=ds&q={searchTerms}&installDate=14/06/2013
BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Updater For Spam Free Search Bar - {20a0be68-8fd9-4539-8712-ce3d1c1fdfc6} - C:\Program Files (x86)\blekkotb\auxi\blekkoAu.dll (Visicom Media)
BHO-x32: Spam Free Search Bar - {26c9e18c-3717-4be1-a225-04e4471f5b6e} - C:\Program Files (x86)\blekkotb\blekkoDx.dll ()
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ChromeFrame BHO - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files (x86)\Google\Chrome Frame\Application\28.0.1500.71\npchrome_frame.dll (Google Inc.)
BHO-x32: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - Spam Free Search Bar - {26c9e18c-3717-4be1-a225-04e4471f5b6e} - C:\Program Files (x86)\blekkotb\blekkoDx.dll ()
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM-x32 - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM-x32 - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} -  No File
Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} -  No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files (x86)\Google\Chrome Frame\Application\28.0.1500.71\npchrome_frame.dll (Google Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

Chrome: 
=======
CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=hp&installDate=14/06/2013
CHR RestoreOnStartup: "hxxp://google.de/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Users\Theo Hulok\AppData\Local\Google\Chrome\User Data\PepperFlash\11.5.31.139\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\pdf.dll ()
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll No File
CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U11) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Extension: (Angry Birds) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0
CHR Extension: (SocialReviver) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\beeidigicffecnkbanlfnmaplmkafdje\4.1_0
CHR Extension: (YouTube) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Adblock Plus) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.5_0
CHR Extension: (Google Search) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Grooveshark Germany unlocker) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\docdgimmdejoiemdafcgeodchlbllgac\2.3.4_0
CHR Extension: (OfferMosquito) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\0.5_0
CHR Extension: (avast! Online Security) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.8_0
CHR Extension: (Auto Replay for YouTube) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb\1.9.26_0
CHR Extension: (Gmail) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Users\Theo Hulok\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx

==================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2012-07-11] (SUPERAntiSpyware.com)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-05-26] ()
R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2404864 2011-03-24] (Deutsche Telekom AG)
S4 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [14848 2011-12-15] ()
R2 OS Selector; C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe [2155848 2010-05-25] ()
S4 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [80896 2010-09-16] ()
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1119768 2010-09-28] (PDF Complete Inc)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-06-07] ()
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2123584 2011-12-14] (TuneUp Software)

==================== Drivers (Whitelisted) ====================

R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software)
R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [28504 2012-03-07] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-28] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-28] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-28] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2011-12-24] ()
S3 CpqDfw; C:\Windows\System32\drivers\CpqDfw.sys [24376 2010-03-02] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-06-14] (DT Soft Ltd)
R3 KovaPlusFltr; C:\Windows\System32\drivers\KovaPlusFltr.sys [15104 2010-01-25] (ROCCAT Development, Inc.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2011-12-24] ()
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2011-11-08] (TuneUp Software)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-23 12:16 - 2013-07-23 12:16 - 01779447 _____ (Farbar) C:\Users\Theo Hulok\Downloads\FRST64.exe
2013-07-23 12:16 - 2013-07-23 12:16 - 00000000 ____D C:\FRST
2013-07-23 10:19 - 2013-07-23 10:19 - 00015600 _____ C:\Users\Theo Hulok\Downloads\hijackthis.log
2013-07-23 10:18 - 2013-07-23 10:18 - 00388608 _____ (Trend Micro Inc.) C:\Users\Theo Hulok\Downloads\HiJackThis204.exe
2013-07-21 18:01 - 2013-07-21 18:01 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Snz
2013-07-21 12:48 - 2013-07-21 13:10 - 00001284 _____ C:\Users\Theo Hulok\Desktop\stress mit grund.txt
2013-07-12 12:29 - 2013-07-12 12:29 - 00000196 _____ C:\Users\Theo Hulok\Desktop\Counter-Strike Global Offensive - SDK.url
2013-07-11 17:15 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-11 17:15 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-11 17:15 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-11 17:15 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-11 17:15 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-11 17:15 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-11 17:15 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-11 17:15 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-11 17:15 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-11 17:15 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-11 17:15 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-11 17:15 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-11 17:15 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-11 17:15 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-11 17:15 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-11 17:15 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-11 17:15 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-11 17:15 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-11 17:15 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-11 17:15 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-11 17:15 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-11 15:29 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-11 15:29 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-11 15:29 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-11 15:29 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-11 15:27 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-11 00:51 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-11 00:51 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-09 02:01 - 2013-07-09 02:01 - 00002052 _____ C:\Users\Theo Hulok\Downloads\1e35uym63e9zy78.dlc
2013-07-08 19:46 - 2013-07-08 19:53 - 00000000 ____D C:\Users\Theo Hulok\Desktop\Juli
2013-07-08 15:32 - 2013-07-08 15:32 - 00001796 _____ C:\Users\Theo Hulok\Downloads\Kontor59_splitted-e3nq0pmirkzw.dlc
2013-07-07 19:17 - 2013-07-12 13:57 - 00037174 _____ C:\Windows\DirectX.log
2013-07-04 13:45 - 2013-07-04 13:45 - 00175832 _____ C:\Users\Theo Hulok\Documents\ts3_clientui-win32-1361977727-2013-07-04 13_45_35.633085.dmp
2013-07-03 17:38 - 2013-07-21 18:01 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Intermediate
2013-07-03 17:38 - 2013-07-03 17:38 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\SSync
2013-07-03 17:38 - 2013-07-03 17:38 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\SCheck
2013-07-03 17:38 - 2013-07-03 17:38 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\DataMgr
2013-07-03 17:31 - 2013-07-03 17:31 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\PiccShare
2013-07-03 17:31 - 2013-07-03 17:31 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Common
2013-07-03 17:28 - 2013-07-03 17:28 - 00393040 _____ (Softonic                                        ) C:\Users\Theo Hulok\Downloads\SoftonicDownloader_fuer_morphvox.exe
2013-07-02 20:00 - 2013-07-02 20:00 - 02812928 _____ C:\Users\Theo Hulok\Downloads\Nahostkonflikt (halbfertig).ppt
2013-07-02 11:36 - 2013-07-23 10:06 - 00002623 _____ C:\Windows\setupact.log
2013-07-02 11:36 - 2013-07-12 11:03 - 00001434 _____ C:\Windows\PFRO.log
2013-07-02 11:36 - 2013-07-02 11:36 - 00000000 _____ C:\Windows\setuperr.log
2013-07-02 01:28 - 2013-07-02 01:29 - 00000000 ____D C:\ProgramData\SUPERSetup
2013-07-02 01:01 - 2013-07-02 01:01 - 00000000 ____D C:\Users\Theo Hulok\Documents\r3jn und co
2013-07-01 23:15 - 2013-07-01 23:15 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\Sony Online Entertainment
2013-06-29 01:08 - 2013-06-29 01:08 - 00001072 _____ C:\Users\Theo Hulok\Downloads\929byf978zrv88k.dlc
2013-06-28 13:21 - 2013-06-28 13:21 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-06-28 13:12 - 2013-06-28 13:20 - 63363736 _____ (Microsoft Corporation) C:\Users\Theo Hulok\Downloads\PowerPointViewer.exe
2013-06-28 08:21 - 2013-06-28 08:21 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum
2013-06-27 01:07 - 2013-06-27 01:07 - 00000000 ____D C:\ProgramData\ATI
2013-06-27 01:06 - 2013-06-27 01:06 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-06-27 00:41 - 2013-06-27 01:02 - 141110624 _____ (Advanced Micro Devices, Inc.) C:\Users\Theo Hulok\Downloads\13-4_win7_win8_64_dd_ccc_whql.exe
2013-06-27 00:21 - 2013-06-27 00:21 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\War Thunder
2013-06-27 00:19 - 2013-06-27 00:20 - 04089992 _____ (2013 Gaijin Entertainment Corporation                       ) C:\Users\Theo Hulok\Downloads\wt_launcher_1.0.1.246.exe
2013-06-26 23:36 - 2013-06-26 23:38 - 00000000 ____D C:\ProgramData\WarThunder
2013-06-26 23:36 - 2013-06-26 23:36 - 00000892 _____ C:\Users\Theo Hulok\Desktop\launcher - Verknüpfung.lnk
2013-06-26 23:36 - 2013-06-26 23:36 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\WarThunder
2013-06-26 21:31 - 2013-06-26 21:31 - 00000584 _____ C:\Users\Public\Desktop\Blender.lnk
2013-06-26 21:20 - 2013-06-26 21:30 - 48846068 _____ C:\Users\Theo Hulok\Downloads\blender-2.67b-windows64.exe
2013-06-26 20:56 - 2013-06-28 08:21 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum
2013-06-26 20:56 - 2013-06-28 08:21 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum
2013-06-26 17:53 - 2013-06-26 17:58 - 40932318 _____ C:\Users\Theo Hulok\Downloads\blender-2.67b-windows32.exe
2013-06-26 14:54 - 2013-06-26 14:54 - 00001816 _____ C:\Users\Theo Hulok\Downloads\VA-Kontor_House_of_House_18-3CD-2013-VOiCE-e1sv9nm3z2w3.dlc
2013-06-26 13:29 - 2013-06-26 13:29 - 00001368 _____ C:\Users\Theo Hulok\Downloads\Disco_House_2CD_2013_-s9dqxnm6t78y.dlc
2013-06-26 01:45 - 2013-06-26 01:45 - 00000000 ____D C:\Users\Theo Hulok\Desktop\EP-Harlekin
2013-06-25 22:29 - 2013-06-25 22:29 - 00001072 _____ C:\Users\Theo Hulok\Downloads\vxb3xb35y6h23la.dlc
2013-06-25 22:29 - 2013-06-25 22:29 - 00001072 _____ C:\Users\Theo Hulok\Downloads\vxb3xb35y6h23la (1).dlc
2013-06-24 14:15 - 2013-06-24 14:15 - 00015896 _____ C:\Users\Theo Hulok\Downloads\a9a161d2cb9f5da7706fb86c23f6b817.dlc
2013-06-24 14:10 - 2013-06-24 14:10 - 00009860 _____ C:\Users\Theo Hulok\Downloads\d5ef29da2fa393c081ec3c220c5343d2.dlc
2013-06-24 10:50 - 2013-06-24 10:50 - 00000923 _____ C:\Users\Theo Hulok\Desktop\CIM2 - Verknüpfung.lnk
2013-06-24 10:40 - 2013-06-24 10:40 - 00000000 ____D C:\ProgramData\Steam
2013-06-24 00:59 - 2013-06-24 00:59 - 00001092 _____ C:\Users\Theo Hulok\Downloads\Cities_in_Motion_2_-_ALiAS-dqo46lml2nyr.dlc
2013-06-23 22:47 - 2013-06-23 22:47 - 00000000 ____D C:\Users\Theo Hulok\Desktop\Foren und co
2013-06-23 22:38 - 2013-06-23 22:38 - 00019952 _____ C:\Users\Theo Hulok\Downloads\8482502c72949ae3af778675f4bcd351.dlc
2013-06-23 22:29 - 2013-06-23 22:29 - 00001776 _____ C:\Users\Theo Hulok\Downloads\Future_Trance_Vol.64_2013_3CD_-w5ztknm95ylv.dlc
2013-06-23 22:25 - 2013-06-23 22:25 - 00001240 _____ C:\Users\Theo Hulok\Downloads\417a854cxr3ym6s.dlc
2013-06-23 22:19 - 2013-06-23 22:19 - 00001368 _____ C:\Users\Theo Hulok\Downloads\Genetikk_-_D_N_A_Premium_Edition_-9zxjnombd60v.dlc
2013-06-23 22:15 - 2013-06-23 22:15 - 00001240 _____ C:\Users\Theo Hulok\Downloads\r398c42s8mi8b0t.dlc

==================== One Month Modified Files and Folders =======

2013-07-23 12:16 - 2013-07-23 12:16 - 01779447 _____ (Farbar) C:\Users\Theo Hulok\Downloads\FRST64.exe
2013-07-23 12:16 - 2013-07-23 12:16 - 00000000 ____D C:\FRST
2013-07-23 12:05 - 2012-05-29 01:09 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-23 11:36 - 2012-04-05 11:19 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-23 11:07 - 2011-04-24 13:35 - 00000000 ____D C:\ProgramData\PDFC
2013-07-23 11:05 - 2012-05-29 01:09 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-23 10:19 - 2013-07-23 10:19 - 00015600 _____ C:\Users\Theo Hulok\Downloads\hijackthis.log
2013-07-23 10:18 - 2013-07-23 10:18 - 00388608 _____ (Trend Micro Inc.) C:\Users\Theo Hulok\Downloads\HiJackThis204.exe
2013-07-23 10:15 - 2009-07-14 06:45 - 00015792 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-23 10:15 - 2009-07-14 06:45 - 00015792 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-23 10:11 - 2011-04-24 14:06 - 00697300 _____ C:\Windows\system32\perfh007.dat
2013-07-23 10:11 - 2011-04-24 14:06 - 00148338 _____ C:\Windows\system32\perfc007.dat
2013-07-23 10:11 - 2009-07-14 07:13 - 01614964 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-23 10:06 - 2013-07-02 11:36 - 00002623 _____ C:\Windows\setupact.log
2013-07-23 10:06 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-23 03:13 - 2011-04-24 13:27 - 02015125 _____ C:\Windows\WindowsUpdate.log
2013-07-23 00:35 - 2012-06-27 14:57 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\SoftGrid Client
2013-07-23 00:18 - 2011-08-03 00:02 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\TS3Client
2013-07-22 18:33 - 2013-03-10 20:03 - 00000000 ____D C:\Users\Theo Hulok\Desktop\bewerbung
2013-07-22 17:49 - 2011-07-28 22:23 - 00000000 ____D C:\steam
2013-07-21 18:01 - 2013-07-21 18:01 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Snz
2013-07-21 18:01 - 2013-07-03 17:38 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Intermediate
2013-07-21 18:00 - 2012-07-11 23:50 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-07-21 15:12 - 2011-07-28 22:50 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\ICQ
2013-07-21 13:10 - 2013-07-21 12:48 - 00001284 _____ C:\Users\Theo Hulok\Desktop\stress mit grund.txt
2013-07-16 22:16 - 2011-09-18 13:18 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\ArmA 2 OA
2013-07-13 11:00 - 2012-05-29 01:09 - 00004114 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-13 11:00 - 2012-05-29 01:09 - 00003862 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-12 13:57 - 2013-07-07 19:17 - 00037174 _____ C:\Windows\DirectX.log
2013-07-12 12:29 - 2013-07-12 12:29 - 00000196 _____ C:\Users\Theo Hulok\Desktop\Counter-Strike Global Offensive - SDK.url
2013-07-12 11:06 - 2009-07-24 21:22 - 00000000 ____D C:\Windows\Panther
2013-07-12 11:05 - 2009-07-14 06:45 - 04868648 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-12 11:03 - 2013-07-02 11:36 - 00001434 _____ C:\Windows\PFRO.log
2013-07-12 11:03 - 2013-03-14 00:30 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-12 11:03 - 2013-03-14 00:30 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-12 11:03 - 2009-07-14 09:45 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-12 11:03 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-12 11:03 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-09 02:01 - 2013-07-09 02:01 - 00002052 _____ C:\Users\Theo Hulok\Downloads\1e35uym63e9zy78.dlc
2013-07-08 19:53 - 2013-07-08 19:46 - 00000000 ____D C:\Users\Theo Hulok\Desktop\Juli
2013-07-08 15:32 - 2013-07-08 15:32 - 00001796 _____ C:\Users\Theo Hulok\Downloads\Kontor59_splitted-e3nq0pmirkzw.dlc
2013-07-04 13:45 - 2013-07-04 13:45 - 00175832 _____ C:\Users\Theo Hulok\Documents\ts3_clientui-win32-1361977727-2013-07-04 13_45_35.633085.dmp
2013-07-03 23:06 - 2012-12-27 18:11 - 00000000 ____D C:\Users\Theo Hulok\Documents\The War Z
2013-07-03 22:48 - 2011-08-31 12:30 - 00291128 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2013-07-03 22:48 - 2011-08-30 20:29 - 00291128 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-07-03 17:39 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-03 17:38 - 2013-07-03 17:38 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\SSync
2013-07-03 17:38 - 2013-07-03 17:38 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\SCheck
2013-07-03 17:38 - 2013-07-03 17:38 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\DataMgr
2013-07-03 17:38 - 2012-05-29 01:09 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\Google
2013-07-03 17:37 - 2012-05-29 01:09 - 00000000 ____D C:\Program Files (x86)\Google
2013-07-03 17:34 - 2013-02-24 17:13 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Screaming Bee
2013-07-03 17:31 - 2013-07-03 17:31 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\PiccShare
2013-07-03 17:31 - 2013-07-03 17:31 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Common
2013-07-03 17:28 - 2013-07-03 17:28 - 00393040 _____ (Softonic                                        ) C:\Users\Theo Hulok\Downloads\SoftonicDownloader_fuer_morphvox.exe
2013-07-03 06:54 - 2013-05-27 14:07 - 00000000 ____D C:\Users\Theo Hulok\Desktop\fük
2013-07-02 20:00 - 2013-07-02 20:00 - 02812928 _____ C:\Users\Theo Hulok\Downloads\Nahostkonflikt (halbfertig).ppt
2013-07-02 11:36 - 2013-07-02 11:36 - 00000000 _____ C:\Windows\setuperr.log
2013-07-02 02:04 - 2011-08-26 16:54 - 00000000 ____D C:\Fraps
2013-07-02 02:02 - 2011-07-28 22:15 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\CrashDumps
2013-07-02 01:57 - 2011-08-26 17:05 - 00000000 ____D C:\Users\Theo Hulok\Desktop\aufnahmen
2013-07-02 01:29 - 2013-07-02 01:28 - 00000000 ____D C:\ProgramData\SUPERSetup
2013-07-02 01:29 - 2012-11-11 15:33 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-07-02 01:27 - 2012-08-09 23:25 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\DAEMON Tools Lite
2013-07-02 01:27 - 2011-12-26 13:23 - 00000000 ____D C:\Windows\Minidump
2013-07-02 01:27 - 2011-08-30 02:27 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\LogMeIn Hamachi
2013-07-02 01:25 - 2012-12-16 13:17 - 00000000 ____D C:\Windows\pss
2013-07-02 01:25 - 2011-07-28 20:43 - 00000000 ___RD C:\Users\Theo Hulok\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-07-02 01:18 - 2011-04-24 13:25 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-07-02 01:13 - 2012-01-09 22:39 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2013-07-02 01:13 - 2012-01-09 22:39 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-07-02 01:13 - 2011-04-24 13:37 - 00000000 ____D C:\ProgramData\WildTangent
2013-07-02 01:13 - 2011-04-24 13:37 - 00000000 ____D C:\Program Files (x86)\HP Games
2013-07-02 01:10 - 2011-08-30 20:37 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
2013-07-02 01:09 - 2011-08-01 21:25 - 00000000 ____D C:\Users\Theo Hulok\Filme
2013-07-02 01:01 - 2013-07-02 01:01 - 00000000 ____D C:\Users\Theo Hulok\Documents\r3jn und co
2013-07-01 23:15 - 2013-07-01 23:15 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\Sony Online Entertainment
2013-07-01 15:38 - 2012-07-02 12:10 - 01591922 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-06-29 13:26 - 2013-05-20 12:35 - 00000000 ____D C:\Users\Theo Hulok\Desktop\auto
2013-06-29 01:08 - 2013-06-29 01:08 - 00001072 _____ C:\Users\Theo Hulok\Downloads\929byf978zrv88k.dlc
2013-06-28 17:08 - 2011-07-28 20:42 - 00071624 _____ C:\Users\THEOHU~1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-28 13:21 - 2013-06-28 13:21 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-06-28 13:20 - 2013-06-28 13:12 - 63363736 _____ (Microsoft Corporation) C:\Users\Theo Hulok\Downloads\PowerPointViewer.exe
2013-06-28 08:21 - 2013-06-28 08:21 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum
2013-06-28 08:21 - 2013-06-26 20:56 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum
2013-06-28 08:21 - 2013-06-26 20:56 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum
2013-06-28 08:21 - 2013-03-22 22:46 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-06-28 08:21 - 2011-09-26 16:51 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-06-28 08:21 - 2011-09-26 16:51 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-06-27 01:07 - 2013-06-27 01:07 - 00000000 ____D C:\ProgramData\ATI
2013-06-27 01:06 - 2013-06-27 01:06 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-06-27 01:06 - 2012-04-05 11:43 - 00000000 ____D C:\ProgramData\AMD
2013-06-27 01:06 - 2011-11-20 04:07 - 00000000 ____D C:\Program Files\ATI Technologies
2013-06-27 01:02 - 2013-06-27 00:41 - 141110624 _____ (Advanced Micro Devices, Inc.) C:\Users\Theo Hulok\Downloads\13-4_win7_win8_64_dd_ccc_whql.exe
2013-06-27 00:21 - 2013-06-27 00:21 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\War Thunder
2013-06-27 00:20 - 2013-06-27 00:19 - 04089992 _____ (2013 Gaijin Entertainment Corporation                       ) C:\Users\Theo Hulok\Downloads\wt_launcher_1.0.1.246.exe
2013-06-26 23:38 - 2013-06-26 23:36 - 00000000 ____D C:\ProgramData\WarThunder
2013-06-26 23:37 - 2011-08-25 22:22 - 00000000 ____D C:\Users\Theo Hulok\Documents\My Games
2013-06-26 23:36 - 2013-06-26 23:36 - 00000892 _____ C:\Users\Theo Hulok\Desktop\launcher - Verknüpfung.lnk
2013-06-26 23:36 - 2013-06-26 23:36 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\WarThunder
2013-06-26 23:36 - 2011-12-26 14:24 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-06-26 21:31 - 2013-06-26 21:31 - 00000584 _____ C:\Users\Public\Desktop\Blender.lnk
2013-06-26 21:30 - 2013-06-26 21:20 - 48846068 _____ C:\Users\Theo Hulok\Downloads\blender-2.67b-windows64.exe
2013-06-26 18:00 - 2011-08-01 14:05 - 00000000 ____D C:\Users\Theo Hulok\.thumbnails
2013-06-26 17:58 - 2013-06-26 17:53 - 40932318 _____ C:\Users\Theo Hulok\Downloads\blender-2.67b-windows32.exe
2013-06-26 14:54 - 2013-06-26 14:54 - 00001816 _____ C:\Users\Theo Hulok\Downloads\VA-Kontor_House_of_House_18-3CD-2013-VOiCE-e1sv9nm3z2w3.dlc
2013-06-26 13:29 - 2013-06-26 13:29 - 00001368 _____ C:\Users\Theo Hulok\Downloads\Disco_House_2CD_2013_-s9dqxnm6t78y.dlc
2013-06-26 01:45 - 2013-06-26 01:45 - 00000000 ____D C:\Users\Theo Hulok\Desktop\EP-Harlekin
2013-06-25 22:29 - 2013-06-25 22:29 - 00001072 _____ C:\Users\Theo Hulok\Downloads\vxb3xb35y6h23la.dlc
2013-06-25 22:29 - 2013-06-25 22:29 - 00001072 _____ C:\Users\Theo Hulok\Downloads\vxb3xb35y6h23la (1).dlc
2013-06-24 21:09 - 2011-08-30 20:29 - 00291088 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-06-24 14:15 - 2013-06-24 14:15 - 00015896 _____ C:\Users\Theo Hulok\Downloads\a9a161d2cb9f5da7706fb86c23f6b817.dlc
2013-06-24 14:10 - 2013-06-24 14:10 - 00009860 _____ C:\Users\Theo Hulok\Downloads\d5ef29da2fa393c081ec3c220c5343d2.dlc
2013-06-24 13:03 - 2011-09-01 14:28 - 00000000 ____D C:\Program Files (x86)\Origin
2013-06-24 11:47 - 2011-11-29 23:58 - 00000000 ____D C:\Users\Theo Hulok\Documents\Akte Husk aka Undizzable aka Giftgas
2013-06-24 10:50 - 2013-06-24 10:50 - 00000923 _____ C:\Users\Theo Hulok\Desktop\CIM2 - Verknüpfung.lnk
2013-06-24 10:40 - 2013-06-24 10:40 - 00000000 ____D C:\ProgramData\Steam
2013-06-24 00:59 - 2013-06-24 00:59 - 00001092 _____ C:\Users\Theo Hulok\Downloads\Cities_in_Motion_2_-_ALiAS-dqo46lml2nyr.dlc
2013-06-24 00:57 - 2012-08-07 01:06 - 00000000 ____D C:\Users\Theo Hulok\Desktop\Jdl
2013-06-23 22:47 - 2013-06-23 22:47 - 00000000 ____D C:\Users\Theo Hulok\Desktop\Foren und co
2013-06-23 22:38 - 2013-06-23 22:38 - 00019952 _____ C:\Users\Theo Hulok\Downloads\8482502c72949ae3af778675f4bcd351.dlc
2013-06-23 22:29 - 2013-06-23 22:29 - 00001776 _____ C:\Users\Theo Hulok\Downloads\Future_Trance_Vol.64_2013_3CD_-w5ztknm95ylv.dlc
2013-06-23 22:25 - 2013-06-23 22:25 - 00001240 _____ C:\Users\Theo Hulok\Downloads\417a854cxr3ym6s.dlc
2013-06-23 22:19 - 2013-06-23 22:19 - 00001368 _____ C:\Users\Theo Hulok\Downloads\Genetikk_-_D_N_A_Premium_Edition_-9zxjnombd60v.dlc
2013-06-23 22:15 - 2013-06-23 22:15 - 00001240 _____ C:\Users\Theo Hulok\Downloads\r398c42s8mi8b0t.dlc
2013-06-23 11:04 - 2011-12-28 00:51 - 00000000 ____D C:\Users\Theo Hulok\Desktop\Games

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-14 12:35

==================== End Of Log ============================
         
--- --- ---


Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-07-2013 01
Ran by Theo Hulok at 2013-07-23 12:17:32
Running from C:\Users\Theo Hulok\Downloads
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

   
Ace of Spades (x32 Version: 0.70.017)
Acronis Drive Monitor (x32 Version: 1.0.566)
Acronis*Disk*Director*Home (x32 Version: 11.0.216)
Adobe After Effects CS5.5 (x32 Version: 10.5.1)
Adobe AIR (x32 Version: 3.6.0.6090)
Adobe Download Assistant (x32 Version: 1.0.6)
Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224)
Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224)
AMD Accelerated Video Transcoding (Version: 12.10.100.30328)
AMD APP SDK Runtime (Version: 10.0.898.1)
AMD Catalyst Install Manager (Version: 8.0.911.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Media Foundation Decoders (Version: 1.0.80328.2204)
Apple Application Support (x32 Version: 2.2.2)
Apple Mobile Device Support (Version: 6.0.0.59)
Apple Software Update (x32 Version: 2.1.3.127)
Arma 2 (x32)
Arma 2: DayZ Mod (x32)
Arma 2: Operation Arrowhead (x32)
Assassin's Creed III - Complete Edition (x32 Version: 1.05)
Audacity 1.3.13 (Unicode) (x32)
Auslogics Disk Defrag (x32 Version: version 3.3)
avast! Free Antivirus (x32 Version: 8.0.1489.0)
Battlefield 2: Deluxe (x32)
Battlefield 3™ (x32 Version: 1.0.0.0)
Battlefield: Bad Company™ 2 (x32 Version: 1.0.0.0)
Battlelog Standalone (Version: 1.0.0)
Battlelog Web Plugins (x32 Version: 2.1.7)
BattlEye for OA Uninstall (x32)
Bonjour (Version: 3.0.0.10)
Catalyst Control Center - Branding (x32 Version: 1.00.0000)
Catalyst Control Center (x32 Version: 2013.0328.2218.38225)
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0328.2218.38225)
Catalyst Control Center InstallProxy (x32 Version: 2013.0328.2218.38225)
Catalyst Control Center Localization All (x32 Version: 2013.0328.2218.38225)
CCC Help Chinese Standard (x32 Version: 2013.0328.2217.38225)
CCC Help Chinese Traditional (x32 Version: 2013.0328.2217.38225)
CCC Help Czech (x32 Version: 2013.0328.2217.38225)
CCC Help Danish (x32 Version: 2013.0328.2217.38225)
CCC Help Dutch (x32 Version: 2013.0328.2217.38225)
CCC Help English (x32 Version: 2013.0328.2217.38225)
CCC Help Finnish (x32 Version: 2013.0328.2217.38225)
CCC Help French (x32 Version: 2013.0328.2217.38225)
CCC Help German (x32 Version: 2013.0328.2217.38225)
CCC Help Greek (x32 Version: 2013.0328.2217.38225)
CCC Help Hungarian (x32 Version: 2013.0328.2217.38225)
CCC Help Italian (x32 Version: 2013.0328.2217.38225)
CCC Help Japanese (x32 Version: 2013.0328.2217.38225)
CCC Help Korean (x32 Version: 2013.0328.2217.38225)
CCC Help Norwegian (x32 Version: 2013.0328.2217.38225)
CCC Help Polish (x32 Version: 2013.0328.2217.38225)
CCC Help Portuguese (x32 Version: 2013.0328.2217.38225)
CCC Help Russian (x32 Version: 2013.0328.2217.38225)
CCC Help Spanish (x32 Version: 2013.0328.2217.38225)
CCC Help Swedish (x32 Version: 2013.0328.2217.38225)
CCC Help Thai (x32 Version: 2013.0328.2217.38225)
CCC Help Turkish (x32 Version: 2013.0328.2217.38225)
ccc-utility64 (Version: 2013.0328.2218.38225)
CCleaner (Version: 3.15)
Cities in Motion 2 (c) Paradox Interactive version 1 (x32 Version: 1)
Counter-Strike: Global Offensive - SDK (x32)
Counter-Strike: Global Offensive (x32)
CrystalDiskInfo 5.3.1 (x32 Version: 5.3.1)
CyberLink DVD Suite Deluxe (x32 Version: 7.0.3210)
D3DX10 (x32 Version: 15.4.2368.0902)
DAEMON Tools Lite (x32 Version: 4.47.1.0333)
DayZ Commander (x32 Version: 0.92.69)
Dev-C++ 5 beta 9 release (4.9.9.2) (x32)
DiRT 3 (x32 Version: 1.0.0003.130)
Dota 2 (x32)
EasyBCD 2.1.2 (x32 Version: 2.1.2)
EAX4 Unified Redist (x32 Version: 4.001)
EPSON-Drucker-Software
ESC79_D78 Benutzerhandbuch (x32)
ESN Sonar (x32 Version: 0.70.4)
Fences (Version: 1.0)
Fences (x32)
FIFA 13 (x32 Version: 1.1.0.0)
Fraps (remove only) (x32)
gamelauncher-ps2-psg (HKCU)
GamersFirst LIVE! (x32)
GameTracker Lite (x32)
GIGA F-Tasten v6.0 (x32)
GIMP 2.8.4 (Version: 2.8.4)
Google Chrome (x32 Version: 28.0.1500.72)
Google Chrome Frame (x32 Version: 65.107.16500)
Google Earth Plug-in (x32 Version: 7.1.1.1580)
Google Update Helper (x32 Version: 1.3.21.153)
GTR Evolution (x32)
Guild Wars 2 (x32)
HP Auto (Version: 1.0.12494.3472)
HP Client Services (Version: 1.0.12656.3472)
HP Customer Experience Enhancements (x32 Version: 6.0.1.7)
HP MAINSTREAM KEYBOARD (x32 Version: 1.4.3.0)
HP MediaSmart Music (x32 Version: 4.2.4517)
HP MediaSmart Photo (x32 Version: 4.2.4513)
HP MediaSmart SmartMenu (Version: 3.1.2.4)
HP Odometer (x32 Version: 2.10.0000)
HP Setup (x32 Version: 8.4.4400.3525)
HP Setup Manager (x32 Version: 1.0.12844.3519)
HP Support Assistant (x32 Version: 7.0.39.15)
HP Support Information (x32 Version: 10.1.1000)
HP Update (x32 Version: 5.002.003.003)
HP Vision Hardware Diagnostics (Version: 2.1.6.0)
HTC Driver Installer (x32 Version: 3.0.0.005)
HxD Hex Editor Version 1.7.7.0 (x32 Version: 1.7.7.0)
ICQ7.6 (x32 Version: 7.6)
IDT Audio (x32 Version: 1.0.6302.0)
Intel(R) Control Center (x32 Version: 1.2.1.1007)
Intel(R) Management Engine Components (x32 Version: 7.0.0.1118)
Intel(R) Rapid Storage Technology (x32 Version: 10.8.0.1003)
Internet Explorer Toolbar 4.6 by SweetPacks (x32 Version: 4.6.0004)
iTunes (Version: 10.7.0.21)
Java 7 Update 17 (x32 Version: 7.0.170)
Java Auto Updater (x32 Version: 2.1.9.0)
Java(TM) 6 Update 33 (x32 Version: 6.0.330)
JDownloader 0.9 (x32 Version: 0.9)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
LabelPrint (x32 Version: 2.5.3130)
LightScribe System Software (x32 Version: 1.18.20.1)
LogMeIn Hamachi (x32 Version: 2.1.0.294)
Magic Bullet Suite 32-bit (x32 Version: 11.1.1)
Magic Bullet Suite 64-bit (Version: 11.1.0)
Magic Bullet Suite 64-bit (Version: 11.3.0)
Magic Bullet Suite 64-bit (x32 Version: 11.1.0)
Magic Bullet Suite 64-bit (x32 Version: 11.3.0)
Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300)
Medal of Honor™ Warfighter (x32 Version: 1.0.0.0)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.92.0)
Microsoft Games for Windows Marketplace (x32 Version: 3.5.50.0)
Microsoft Office 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000)
Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000)
Microsoft PowerPoint Viewer (x32 Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0)
Microsoft XNA Framework Redistributable 3.1 (x32 Version: 3.1.10527.0)
Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053)
Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053)
Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000)
Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000)
Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000)
Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000)
Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000)
Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000)
Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000)
Movie Theme Pack for HP MediaSmart Video (x32 Version: 4.2.4412)
MSI Afterburner 2.1.0 (x32 Version: 2.1.0)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT Redists (Version: 1.0)
MSVCRT Redists (x32 Version: 1.0)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0)
MusicStation (x32 Version: 1.0.1.5)
NC Launcher (GameForge) (x32)
nder (Version: 2.67b)
Netzmanager (Version: 1.06)
Netzmanager (x32 Version: 1.06)
Norton Online Backup (x32 Version: 2.1.17869)
Notepad++ (x32 Version: 5.9.6.2)
NVIDIA PhysX (x32 Version: 9.10.0513)
OpenAL (x32)
OpenOffice.org 3.3 (x32 Version: 3.3.9567)
OpenVPN 2.2.2 (x32 Version: 2.2.2)
Origin (x32 Version: 8.5.0.4554)
Pando Media Booster (x32 Version: 2.6.0.1)
PDF Complete Special Edition (x32 Version: 4.0.9)
PhotoNow! (x32 Version: 1.1.7717)
PictureMover (x32 Version: 3.5.0.33)
PlanetSide 2 (HKCU Version: 1.0.3.183)
PlayReady PC Runtime amd64 (Version: 1.3.0)
PowerDirector (x32 Version: 8.0.3129)
QuickTime (x32 Version: 7.70.80.34)
RACE 07 - Formula RaceRoom Add-On (x32)
RACE 07: Andy Priaulx Crowne Plaza Raceway (x32)
RACE On (x32)
Rapture3D 2.4.8 Game (x32)
Recovery Manager (x32 Version: 5.5.3219)
ROCCAT Kova[+] Mouse Driver (x32 Version: 1.10)
Skype Click to Call (x32 Version: 6.0.10297)
Skype™ 6.1 (x32 Version: 6.1.129)
Snap.Do (x32 Version: 1.20.1.10742)
Spam Free Search Bar (x32 Version: 1.0.0.12)
SpeedFan (remove only) (x32)
STCC: The Game (x32)
SUPERAntiSpyware (Version: 5.6.1010)
TeamSpeak 3 Client (HKCU Version: 3.0.10)
The Elder Scrolls V Skyrim - Legendary Edition (Game of the Year) Deutsche Version 1.9.32.0.8 (x32 Version: 1.9.32.0.8)
The War Z version 1.0 (x32 Version: 1.0)
The WTCC 2010 Pack (x32)
TmNationsForever (x32)
TuneUp Utilities 2012 (x32 Version: 12.0.2160.11)
TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.2160.11)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update Manager for SweetPacks 1.1 (x32 Version: 1.1.0008)
Vegas Pro 11.0 (64-bit) (Version: 11.0.511)
Vegas Pro 11.0 (x32 Version: 11.0.510)
War Thunder Launcher 1.0.1.246 (x32)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3502.0922)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Messenger (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3502.0922)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3502.0922)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8)
WinRAR 4.01 (64-Bit) (Version: 4.01.0)
WORLD IN CONFLICT (x32 Version: 1.0.1.1)
Zinio Reader 4 (x32 Version: 4.0.3184)

==================== Restore Points  =========================

16-07-2013 12:29:35 Windows Update
20-07-2013 18:34:29 Windows Update

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {2105BC1A-FC3D-44EA-8F17-BC698C42DA99} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe [2011-12-14] (TuneUp Software)
Task: {3C6731B7-B479-45D1-B649-6F30CC095AA6} - System32\Tasks\Microsoft\Windows\Media Center\Extender\Update media permissions for Mcx1-THEOHULOK-HP => C:\Windows\ehome\McxTask.exe [2009-07-14] (Microsoft Corporation)
Task: {486145E3-456E-4AD3-B37E-A988BA70B9B1} - System32\Tasks\User_Feed_Synchronization-{F0629B1F-78D9-4362-ADC8-49CA5BEAC673} => C:\Windows\system32\msfeedssync.exe [2013-04-30] (Microsoft Corporation)
Task: {49DFFC88-94D5-436D-86BE-2D7B4D7A18F1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-29] (Google Inc.)
Task: {53CDF7D3-BE64-4AB2-B502-7C14F3A6D092} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated)
Task: {6C77D02B-3273-4518-95B1-06C7F863DDAA} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software)
Task: {7DE66F65-D9C8-4DB4-AC69-86618C5C96A8} - System32\Tasks\HPOSIAPP64 => %ProgramFiles(x86)%\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe No File
Task: {7F534535-75D1-4560-A2B0-885CD88AE312} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-05-29] (Google Inc.)
Task: {8BF834A9-D748-4EC2-80C6-0D4192AB23F7} - System32\Tasks\HP-Online-Aktualisierungsprogramm => c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2008-12-08] (Hewlett-Packard)
Task: {8E4CB400-FE99-478B-B545-81F56E7C6C9C} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-09-27] ()
Task: {949DA1D8-1E23-4EBF-8B3F-96276F176D9B} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {9EC20718-ABA3-440E-B2D0-46437E6C6202} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2012-07-03] (Sun Microsystems, Inc.)
Task: {AFD7F726-4325-43D0-8F32-F7A8E5226327} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation)
Task: {B0E5550B-96E5-48FD-8853-94027C697924} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: {C177D8A0-60A4-48A6-9D20-CBA908E1D941} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe No File
Task: {E6D98983-36C6-418F-A16F-8F90736E580A} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation)
Task: {EAC79C33-89BA-4948-A893-2E135CA56867} - System32\Tasks\ServicePlan => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-09-27] ()
Task: {EEA73D04-4DCB-4ECF-9CFE-685FFA9D96E2} - System32\Tasks\Red Giant Link => C:\Program Files (x86)\Red Giant Link\Common\Red Giant Link.exe [2012-12-11] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (07/22/2013 03:25:52 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (07/22/2013 03:25:49 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (07/22/2013 03:25:43 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (07/22/2013 03:25:23 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (07/21/2013 09:31:31 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (07/21/2013 09:31:28 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (07/21/2013 09:31:23 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (07/21/2013 09:31:06 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (07/19/2013 01:46:24 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".

Error: (07/19/2013 01:46:19 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".


System errors:
=============
Error: (07/23/2013 10:09:29 AM) (Source: iaStor) (User: )
Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet.

Error: (07/23/2013 00:38:30 AM) (Source: iaStor) (User: )
Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet.

Error: (07/23/2013 00:38:05 AM) (Source: iaStor) (User: )
Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet.

Error: (07/23/2013 00:37:50 AM) (Source: iaStor) (User: )
Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet.

Error: (07/23/2013 00:37:45 AM) (Source: iaStor) (User: )
Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet.

Error: (07/23/2013 00:37:41 AM) (Source: iaStor) (User: )
Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet.

Error: (07/23/2013 00:37:36 AM) (Source: iaStor) (User: )
Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet.

Error: (07/23/2013 00:37:25 AM) (Source: iaStor) (User: )
Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet.

Error: (07/23/2013 00:37:14 AM) (Source: iaStor) (User: )
Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet.

Error: (07/22/2013 10:43:40 AM) (Source: iaStor) (User: )
Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet.


Microsoft Office Sessions:
=========================
Error: (07/22/2013 03:25:52 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"C:\Program Files (x86)\Common Files\Acronis\DiskDirector\WinPE\Files\mmsBundle.dll

Error: (07/22/2013 03:25:49 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"C:\Program Files (x86)\Common Files\Acronis\DiskDirector\WinPE\Files\ManagementConsole.exe

Error: (07/22/2013 03:25:43 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"C:\Program Files (x86)\Common Files\Acronis\DiskDirector\WinPE\Files\RecoveryExpert.exe

Error: (07/22/2013 03:25:23 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"C:\Program Files (x86)\Common Files\Acronis\DiskDirector\WinPE\Files\systeminfo.exe

Error: (07/21/2013 09:31:31 AM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"C:\Program Files (x86)\Common Files\Acronis\DiskDirector\WinPE\Files\mmsBundle.dll

Error: (07/21/2013 09:31:28 AM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"C:\Program Files (x86)\Common Files\Acronis\DiskDirector\WinPE\Files\ManagementConsole.exe

Error: (07/21/2013 09:31:23 AM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"C:\Program Files (x86)\Common Files\Acronis\DiskDirector\WinPE\Files\RecoveryExpert.exe

Error: (07/21/2013 09:31:06 AM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"C:\Program Files (x86)\Common Files\Acronis\DiskDirector\WinPE\Files\systeminfo.exe

Error: (07/19/2013 01:46:24 AM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"C:\Program Files (x86)\Common Files\Acronis\DiskDirector\WinPE\Files\mmsBundle.dll

Error: (07/19/2013 01:46:19 AM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"C:\Program Files (x86)\Common Files\Acronis\DiskDirector\WinPE\Files\ManagementConsole.exe


CodeIntegrity Errors:
===================================
  Date: 2011-08-21 19:00:21.959
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\THEOHU~1\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2011-08-21 19:00:21.937
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Users\THEOHU~1\AppData\Local\Temp\EverestDriver.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2011-08-21 19:00:21.696
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2011-08-21 19:00:21.671
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Lavalys\EVEREST Home Edition\kerneld.amd64" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info =========================== 

Percentage of memory in use: 54%
Total physical RAM: 6126.53 MB
Available physical RAM: 2785.92 MB
Total Pagefile: 12251.25 MB
Available Pagefile: 8377.48 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:628.87 GB) (Free:250.09 GB) NTFS (Disk=0 Partition=2)
Drive d: (HP_RECOVERY) (Fixed) (Total:13.73 GB) (Free:1.69 GB) NTFS (Disk=0 Partition=3) ==>[System with boot components (obtained from reading drive)]
Drive e: (Volume) (Fixed) (Total:288.81 GB) (Free:238.11 GB) NTFS (Disk=0 Partition=4)

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 5DF8032E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=629 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=289 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=14 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
__________________

Alt 23.07.2013, 12:00   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Werbung öffnet sich Immer - Standard

Werbung öffnet sich Immer



Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!
Downloade dir bitte Combofix vom folgenden Downloadspiegel

Link 1


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 23.07.2013, 16:07   #5
Rejono
 
Werbung öffnet sich Immer - Standard

Werbung öffnet sich Immer



Code:
ATTFilter
ComboFix 13-07-23.01 - Theo Hulok 23.07.2013  16:56:36.1.8 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.6127.3750 [GMT 2:00]
ausgeführt von:: c:\users\Theo Hulok\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\STF3FF2.tmp
C:\Thumbs.db
c:\users\Theo Hulok\AppData\Local\TempDIR
c:\windows\IsUn0407.exe
c:\windows\security\Database\tmp.edb
c:\windows\SysWow64\frapsvid.dll
.
.
(((((((((((((((((((((((   Dateien erstellt von 2013-06-23 bis 2013-07-23  ))))))))))))))))))))))))))))))
.
.
2013-07-23 15:02 . 2013-07-23 15:02	76232	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{E4B274CD-894C-4E57-92E4-75A945FFEBB1}\offreg.dll
2013-07-23 15:02 . 2013-07-23 15:02	--------	d-----w-	c:\users\Mcx1-THEOHULOK-HP\AppData\Local\temp
2013-07-23 15:02 . 2013-07-23 15:02	--------	d-----w-	c:\users\Default\AppData\Local\temp
2013-07-23 10:16 . 2013-07-23 10:16	--------	d-----w-	C:\FRST
2013-07-21 16:01 . 2013-07-21 16:01	--------	d-----w-	c:\users\Theo Hulok\AppData\Roaming\Snz
2013-07-20 18:35 . 2013-07-02 08:34	9460976	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{E4B274CD-894C-4E57-92E4-75A945FFEBB1}\mpengine.dll
2013-07-11 13:29 . 2013-05-27 05:50	1011712	----a-w-	c:\program files\Windows Defender\MpSvc.dll
2013-07-11 13:29 . 2013-05-27 05:50	571904	----a-w-	c:\program files\Windows Defender\MpClient.dll
2013-07-11 13:29 . 2013-05-27 05:50	314880	----a-w-	c:\program files\Windows Defender\MpCommu.dll
2013-07-11 13:29 . 2013-05-27 04:57	4608	----a-w-	c:\program files (x86)\Windows Defender\MsMpLics.dll
2013-07-11 13:29 . 2013-05-27 04:57	54784	----a-w-	c:\program files (x86)\Windows Defender\MpOAV.dll
2013-07-11 13:29 . 2013-05-27 04:57	392704	----a-w-	c:\program files (x86)\Windows Defender\MpClient.dll
2013-07-11 13:29 . 2013-05-27 03:15	9216	----a-w-	c:\program files (x86)\Windows Defender\MpAsDesc.dll
2013-07-11 13:29 . 2013-06-04 06:00	624128	----a-w-	c:\windows\system32\qedit.dll
2013-07-11 13:29 . 2013-06-04 04:53	509440	----a-w-	c:\windows\SysWow64\qedit.dll
2013-07-11 13:29 . 2013-05-06 06:03	1887744	----a-w-	c:\windows\system32\WMVDECOD.DLL
2013-07-11 13:29 . 2013-05-06 04:56	1620480	----a-w-	c:\windows\SysWow64\WMVDECOD.DLL
2013-07-11 13:27 . 2013-06-05 03:34	3153920	----a-w-	c:\windows\system32\win32k.sys
2013-07-11 13:27 . 2013-04-10 05:48	1732608	----a-w-	c:\program files\Windows Journal\NBDoc.DLL
2013-07-11 13:27 . 2013-04-10 05:46	1402880	----a-w-	c:\program files\Windows Journal\JNWDRV.dll
2013-07-11 13:27 . 2013-04-10 05:46	1393152	----a-w-	c:\program files\Windows Journal\JNTFiltr.dll
2013-07-11 13:27 . 2013-04-10 05:46	1367040	----a-w-	c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2013-07-11 13:27 . 2013-04-10 05:03	936448	----a-w-	c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-07-10 22:51 . 2013-04-09 23:34	1247744	----a-w-	c:\windows\SysWow64\DWrite.dll
2013-07-10 22:51 . 2013-04-02 22:51	1643520	----a-w-	c:\windows\system32\DWrite.dll
2013-07-03 15:38 . 2013-07-21 16:01	--------	d-----w-	c:\users\Theo Hulok\AppData\Roaming\Intermediate
2013-07-03 15:38 . 2013-07-03 15:38	--------	d-----w-	c:\users\Theo Hulok\AppData\Roaming\DataMgr
2013-07-03 15:38 . 2013-07-03 15:38	--------	d-----w-	c:\users\Theo Hulok\AppData\Roaming\SSync
2013-07-03 15:38 . 2013-07-03 15:38	--------	d-----w-	c:\users\Theo Hulok\AppData\Roaming\SCheck
2013-07-03 15:34 . 2013-07-03 15:34	--------	d-----w-	c:\program files (x86)\Common Files\Screaming Bee
2013-07-03 15:31 . 2013-07-03 15:31	--------	d-----w-	c:\users\Theo Hulok\AppData\Roaming\PiccShare
2013-07-03 15:31 . 2013-07-03 15:31	--------	d-----w-	c:\users\Theo Hulok\AppData\Roaming\Common
2013-07-01 23:28 . 2013-07-01 23:29	--------	d-----w-	c:\programdata\SUPERSetup
2013-07-01 21:15 . 2013-07-01 21:15	--------	d-----w-	c:\users\Theo Hulok\AppData\Local\Sony Online Entertainment
2013-06-28 11:21 . 2013-06-28 11:21	--------	d-----w-	c:\program files (x86)\MSECache
2013-06-26 23:07 . 2013-06-26 23:07	--------	d-----w-	c:\programdata\ATI
2013-06-26 23:06 . 2013-06-26 23:06	--------	d-----w-	c:\program files (x86)\AMD AVT
2013-06-26 21:36 . 2013-06-26 21:38	--------	d-----w-	c:\programdata\WarThunder
2013-06-26 21:36 . 2013-06-26 21:36	--------	d-----w-	c:\users\Theo Hulok\AppData\Local\WarThunder
2013-06-24 08:40 . 2013-06-24 08:40	--------	d-----w-	c:\programdata\Steam
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-03 20:48 . 2011-08-31 10:30	291128	----a-w-	c:\windows\SysWow64\PnkBstrB.xtr
2013-07-03 20:48 . 2011-08-30 18:29	291128	----a-w-	c:\windows\SysWow64\PnkBstrB.exe
2013-06-28 06:21 . 2013-03-22 20:46	189936	----a-w-	c:\windows\system32\drivers\aswVmm.sys
2013-06-28 06:21 . 2011-09-26 14:51	378944	----a-w-	c:\windows\system32\drivers\aswSP.sys
2013-06-28 06:21 . 2011-09-26 14:51	1030952	----a-w-	c:\windows\system32\drivers\aswSnx.sys
2013-06-24 19:09 . 2011-08-30 18:29	291088	----a-w-	c:\windows\SysWow64\PnkBstrB.ex0
2013-06-14 11:49 . 2013-06-14 11:49	283200	----a-w-	c:\windows\system32\drivers\dtsoftbus01.sys
2013-06-12 19:37 . 2012-04-05 09:19	692104	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2013-06-12 19:37 . 2011-07-28 20:14	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-12 19:37 . 2013-05-15 16:40	9089416	----a-w-	c:\windows\SysWow64\FlashPlayerInstaller.exe
2013-06-07 13:40 . 2011-08-30 18:29	76888	----a-w-	c:\windows\SysWow64\PnkBstrA.exe
2013-05-13 05:51 . 2013-06-12 09:34	184320	----a-w-	c:\windows\system32\cryptsvc.dll
2013-05-13 05:51 . 2013-06-12 09:34	1464320	----a-w-	c:\windows\system32\crypt32.dll
2013-05-13 05:51 . 2013-06-12 09:34	139776	----a-w-	c:\windows\system32\cryptnet.dll
2013-05-13 05:50 . 2013-06-12 09:34	52224	----a-w-	c:\windows\system32\certenc.dll
2013-05-13 04:45 . 2013-06-12 09:34	1160192	----a-w-	c:\windows\SysWow64\crypt32.dll
2013-05-13 04:45 . 2013-06-12 09:34	103936	----a-w-	c:\windows\SysWow64\cryptnet.dll
2013-05-13 04:45 . 2013-06-12 09:34	140288	----a-w-	c:\windows\SysWow64\cryptsvc.dll
2013-05-13 03:43 . 2013-06-12 09:34	1192448	----a-w-	c:\windows\system32\certutil.exe
2013-05-13 03:08 . 2013-06-12 09:34	903168	----a-w-	c:\windows\SysWow64\certutil.exe
2013-05-13 03:08 . 2013-06-12 09:34	43008	----a-w-	c:\windows\SysWow64\certenc.dll
2013-05-12 19:42 . 2010-06-24 18:33	22240	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-10 05:49 . 2013-06-12 09:34	30720	----a-w-	c:\windows\system32\cryptdlg.dll
2013-05-10 03:20 . 2013-06-12 09:34	24576	----a-w-	c:\windows\SysWow64\cryptdlg.dll
2013-05-09 08:59 . 2013-03-22 20:46	65336	----a-w-	c:\windows\system32\drivers\aswRvrt.sys
2013-05-09 08:59 . 2012-02-26 20:23	72016	----a-w-	c:\windows\system32\drivers\aswRdr2.sys
2013-05-09 08:59 . 2011-09-26 14:51	64288	----a-w-	c:\windows\system32\drivers\aswTdi.sys
2013-05-09 08:59 . 2011-09-26 14:51	33400	----a-w-	c:\windows\system32\drivers\aswFsBlk.sys
2013-05-09 08:59 . 2011-09-26 14:51	80816	----a-w-	c:\windows\system32\drivers\aswMonFlt.sys
2013-05-09 08:58 . 2011-09-26 14:50	41664	----a-w-	c:\windows\avastSS.scr
2013-05-09 08:58 . 2011-09-26 14:50	287840	----a-w-	c:\windows\system32\aswBoot.exe
2013-05-08 06:39 . 2013-06-12 09:34	1910632	----a-w-	c:\windows\system32\drivers\tcpip.sys
2013-05-02 00:06 . 2011-09-26 16:34	278800	------w-	c:\windows\system32\MpSigStub.exe
2013-04-30 19:45 . 2013-04-30 19:45	97280	----a-w-	c:\windows\system32\mshtmled.dll
2013-04-30 19:45 . 2013-04-30 19:45	92160	----a-w-	c:\windows\system32\SetIEInstalledDate.exe
2013-04-30 19:45 . 2013-04-30 19:45	905728	----a-w-	c:\windows\system32\mshtmlmedia.dll
2013-04-30 19:45 . 2013-04-30 19:45	81408	----a-w-	c:\windows\system32\icardie.dll
2013-04-30 19:45 . 2013-04-30 19:45	77312	----a-w-	c:\windows\system32\tdc.ocx
2013-04-30 19:45 . 2013-04-30 19:45	762368	----a-w-	c:\windows\system32\ieapfltr.dll
2013-04-30 19:45 . 2013-04-30 19:45	73728	----a-w-	c:\windows\SysWow64\SetIEInstalledDate.exe
2013-04-30 19:45 . 2013-04-30 19:45	719360	----a-w-	c:\windows\SysWow64\mshtmlmedia.dll
2013-04-30 19:45 . 2013-04-30 19:45	62976	----a-w-	c:\windows\system32\pngfilt.dll
2013-04-30 19:45 . 2013-04-30 19:45	61952	----a-w-	c:\windows\SysWow64\tdc.ocx
2013-04-30 19:45 . 2013-04-30 19:45	599552	----a-w-	c:\windows\system32\vbscript.dll
2013-04-30 19:45 . 2013-04-30 19:45	523264	----a-w-	c:\windows\SysWow64\vbscript.dll
2013-04-30 19:45 . 2013-04-30 19:45	52224	----a-w-	c:\windows\system32\msfeedsbs.dll
2013-04-30 19:45 . 2013-04-30 19:45	51200	----a-w-	c:\windows\system32\imgutil.dll
2013-04-30 19:45 . 2013-04-30 19:45	48640	----a-w-	c:\windows\SysWow64\mshtmler.dll
2013-04-30 19:45 . 2013-04-30 19:45	48640	----a-w-	c:\windows\system32\mshtmler.dll
2013-04-30 19:45 . 2013-04-30 19:45	452096	----a-w-	c:\windows\system32\dxtmsft.dll
2013-04-30 19:45 . 2013-04-30 19:45	441856	----a-w-	c:\windows\system32\html.iec
2013-04-30 19:45 . 2013-04-30 19:45	38400	----a-w-	c:\windows\SysWow64\imgutil.dll
2013-04-30 19:45 . 2013-04-30 19:45	361984	----a-w-	c:\windows\SysWow64\html.iec
2013-04-30 19:45 . 2013-04-30 19:45	281600	----a-w-	c:\windows\system32\dxtrans.dll
2013-04-30 19:45 . 2013-04-30 19:45	27648	----a-w-	c:\windows\system32\licmgr10.dll
2013-04-30 19:45 . 2013-04-30 19:45	270848	----a-w-	c:\windows\system32\iedkcs32.dll
2013-04-30 19:45 . 2013-04-30 19:45	247296	----a-w-	c:\windows\system32\webcheck.dll
2013-04-30 19:45 . 2013-04-30 19:45	235008	----a-w-	c:\windows\system32\url.dll
2013-04-30 19:45 . 2013-04-30 19:45	23040	----a-w-	c:\windows\SysWow64\licmgr10.dll
2013-04-30 19:45 . 2013-04-30 19:45	226304	----a-w-	c:\windows\system32\elshyph.dll
2013-04-30 19:45 . 2013-04-30 19:45	216064	----a-w-	c:\windows\system32\msls31.dll
2013-04-30 19:45 . 2013-04-30 19:45	197120	----a-w-	c:\windows\system32\msrating.dll
2013-04-30 19:45 . 2013-04-30 19:45	185344	----a-w-	c:\windows\SysWow64\elshyph.dll
2013-04-30 19:45 . 2013-04-30 19:45	173568	----a-w-	c:\windows\system32\ieUnatt.exe
2013-04-30 19:45 . 2013-04-30 19:45	167424	----a-w-	c:\windows\system32\iexpress.exe
2013-04-30 19:45 . 2013-04-30 19:45	158720	----a-w-	c:\windows\SysWow64\msls31.dll
2013-04-30 19:45 . 2013-04-30 19:45	1509376	----a-w-	c:\windows\system32\inetcpl.cpl
2013-04-30 19:45 . 2013-04-30 19:45	150528	----a-w-	c:\windows\SysWow64\iexpress.exe
2013-04-30 19:45 . 2013-04-30 19:45	149504	----a-w-	c:\windows\system32\occache.dll
2013-04-30 19:45 . 2013-04-30 19:45	144896	----a-w-	c:\windows\system32\wextract.exe
2013-04-30 19:45 . 2013-04-30 19:45	1441280	----a-w-	c:\windows\SysWow64\inetcpl.cpl
2013-04-30 19:45 . 2013-04-30 19:45	1400416	----a-w-	c:\windows\system32\ieapfltr.dat
2013-04-30 19:45 . 2013-04-30 19:45	138752	----a-w-	c:\windows\SysWow64\wextract.exe
2013-04-30 19:45 . 2013-04-30 19:45	13824	----a-w-	c:\windows\system32\mshta.exe
2013-04-30 19:45 . 2013-04-30 19:45	137216	----a-w-	c:\windows\SysWow64\ieUnatt.exe
2013-04-30 19:45 . 2013-04-30 19:45	136192	----a-w-	c:\windows\system32\iepeers.dll
2013-04-30 19:45 . 2013-04-30 19:45	135680	----a-w-	c:\windows\system32\IEAdvpack.dll
2013-04-30 19:45 . 2013-04-30 19:45	12800	----a-w-	c:\windows\SysWow64\mshta.exe
2013-04-30 19:45 . 2013-04-30 19:45	12800	----a-w-	c:\windows\system32\msfeedssync.exe
2013-04-30 19:45 . 2013-04-30 19:45	110592	----a-w-	c:\windows\SysWow64\IEAdvpack.dll
2013-04-30 19:45 . 2013-04-30 19:45	1054720	----a-w-	c:\windows\system32\MsSpellCheckingFacility.exe
2013-04-30 19:45 . 2013-04-30 19:45	102912	----a-w-	c:\windows\system32\inseng.dll
2013-04-26 05:51 . 2013-06-12 09:31	751104	----a-w-	c:\windows\system32\win32spl.dll
2013-04-26 04:55 . 2013-06-12 09:31	492544	----a-w-	c:\windows\SysWow64\win32spl.dll
2013-04-25 23:30 . 2013-06-12 09:34	1505280	----a-w-	c:\windows\SysWow64\d3d11.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{20a0be68-8fd9-4539-8712-ce3d1c1fdfc6}]
2012-01-17 19:28	262312	----a-w-	c:\program files (x86)\blekkotb\auxi\blekkoAu.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{26c9e18c-3717-4be1-a225-04e4471f5b6e}]
2012-01-17 19:28	86696	----a-w-	c:\program files (x86)\blekkotb\blekkoDx.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2012-07-04 13:03	1310040	----a-r-	c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{26c9e18c-3717-4be1-a225-04e4471f5b6e}"= "c:\program files (x86)\blekkotb\blekkoDx.dll" [2012-01-17 86696]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2012-07-04 1310040]
.
[HKEY_CLASSES_ROOT\clsid\{26c9e18c-3717-4be1-a225-04e4471f5b6e}]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SSync"="c:\users\Theo Hulok\AppData\Roaming\SSync\SSync.exe" [2013-04-09 36864]
"DataMgr"="c:\users\Theo Hulok\AppData\Roaming\DataMgr\DataMgr.exe" [2013-06-26 168848]
"SCheck"="c:\users\Theo Hulok\AppData\Roaming\SCheck\SCheck.exe" [2013-04-09 36864]
"Snoozer"="c:\users\Theo Hulok\AppData\Roaming\Snz\Snz.exe" [2013-07-21 1137673]
"Intermediate"="c:\users\Theo Hulok\AppData\Roaming\Intermediate\Intermediate.exe" [2013-04-09 36864]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BATINDICATOR"="c:\program files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe" [2009-05-08 2068992]
"LaunchHPOSIAPP"="c:\program files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe" [2009-04-04 385024]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-10-17 284440]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
"adm_tray.exe"="e:\drivemonitor\adm_tray.exe" [2011-02-24 470120]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-03-28 642656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"HP Software Update"=c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" -atboottime
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"PDF Complete"=c:\program files (x86)\PDF Complete\pdfsty.exe
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"Norton Online Backup"=c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
"AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
"AMD AVT"=Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "c:\program files (x86)\AMD AVT\bin\kdbsync.exe" aml
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe"
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"Sweetpacks Communicator"=c:\program files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys;c:\windows\SYSNATIVE\Drivers\ANDROIDUSB.sys [x]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys;c:\windows\SYSNATIVE\DRIVERS\htcnprot.sys [x]
R3 ScreamBAudioSvc;ScreamBee Audio;c:\windows\system32\drivers\ScreamingBAudio64.sys;c:\windows\SYSNATIVE\drivers\ScreamingBAudio64.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 TelekomNM6;Telekom Netzmanager Packet Filter Driver;c:\program files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys;c:\program files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 GS In-Game Service;GS In-Game Service;c:\program files (x86)\GameTracker\GSInGameService.exe;c:\program files (x86)\GameTracker\GSInGameService.exe [x]
R4 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
R4 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
R4 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [x]
R4 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
S0 aswRvrt;aswRvrt; [x]
S0 aswVmm;aswVmm; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [x]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe;c:\program files\IDT\WDM\AESTSr64.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 ezSharedSvc;Easybits Services for Windows;c:\windows\System32\ezSharedSvcHost.exe;c:\windows\SYSNATIVE\ezSharedSvcHost.exe [x]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Netzmanager Service;Netzmanager Infrastruktur Informationssystem Dienst;c:\program files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe ;c:\program files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe  [x]
S2 OS Selector;Acronis OS Selector Activator;c:\program files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe;c:\program files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe [x]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe;c:\program files (x86)\PDF Complete\pdfsvc.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 KovaPlusFltr;ROCCAT Kova[+] Mouse;c:\windows\system32\drivers\KovaPlusFltr.sys;c:\windows\SYSNATIVE\drivers\KovaPlusFltr.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [x]
S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-07-13 09:07	1173456	----a-w-	c:\program files (x86)\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-07-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 19:37]
.
2013-07-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-28 23:09]
.
2013-07-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-05-28 23:09]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-09 08:58	133840	----a-w-	c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BeatsOSDApp"="c:\program files\IDT\WDM\beats64.exe" [2010-08-15 37888]
"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2010-09-27 489472]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"Acronis Scheduler2 Service"="c:\program files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" [2011-02-12 462400]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files (x86)\Stardock\Fences\FencesMenu64.dll" [2010-06-22 253288]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
UxTuneUp
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=hp&installDate=14/06/2013
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=ds&q={searchTerms}&installDate=14/06/2013
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files (x86)\ICQ7.6\ICQ.exe
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.0.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{26C9E18C-3717-4BE1-A225-04E4471F5B6E}"=hex:51,66,7a,6c,4c,1d,38,12,e2,e2,da,
   22,25,79,8f,0e,dd,33,47,a4,42,41,1f,7a
"{8E5E2654-AD2D-48BF-AC2D-D17F00898D06}"=hex:51,66,7a,6c,4c,1d,38,12,3a,25,4d,
   8a,1f,e3,d1,0d,d3,3b,92,3f,05,d7,c9,12
"{EEE6C35B-6118-11DC-9C72-001320C79847}"=hex:51,66,7a,6c,4c,1d,38,12,35,c0,f5,
   ea,2a,2f,b2,54,e3,64,43,53,25,99,dc,53
"{AE07101B-46D4-4A98-AF68-0333EA26E113}"=hex:51,66,7a,6c,4c,1d,38,12,75,13,14,
   aa,e6,08,f6,0f,d0,7e,40,73,ef,78,a5,07
"{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}"=hex:51,66,7a,6c,4c,1d,38,12,15,21,99,
   35,ad,10,d3,00,f6,8f,3c,cf,15,94,08,e1
"{20A0BE68-8FD9-4539-8712-CE3D1C1FDFC6}"=hex:51,66,7a,6c,4c,1d,38,12,06,bd,b3,
   24,eb,c1,57,00,f8,04,8d,7d,19,41,9b,d2
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
   72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
   94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}"=hex:51,66,7a,6c,4c,1d,38,12,07,5b,93,
   aa,6e,60,ba,0b,f0,6d,b2,b7,80,44,00,83
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
   df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{EEE6C35C-6118-11DC-9C72-001320C79847}"=hex:51,66,7a,6c,4c,1d,38,12,32,c0,f5,
   ea,2a,2f,b2,54,e3,64,43,53,25,99,dc,53
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:a9,07,62,fc,02,78,ce,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b5,19,20,e0,19,80,68,4c,83,1c,53,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
   d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b5,19,20,e0,19,80,68,4c,83,1c,53,\
.
[HKEY_USERS\S-1-5-21-1201534454-2380176246-3172034216-1000\Software\SecuROM\License information*]
"datasecu"=hex:01,56,92,c7,7b,88,e5,34,d0,50,ec,76,dc,ab,3c,49,57,8a,18,75,46,
   73,40,1f,d3,c9,ab,bc,f5,3f,8a,7d,de,00,3c,f6,d5,98,cf,60,a4,d4,aa,b8,98,cf,\
"rkeysecu"=hex:b6,ea,c8,71,98,ec,08,1d,8d,63,e1,14,62,f5,34,44
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-07-23  17:04:49
ComboFix-quarantined-files.txt  2013-07-23 15:04
.
Vor Suchlauf: 21 Verzeichnis(se), 268.223.148.032 Bytes frei
Nach Suchlauf: 27 Verzeichnis(se), 267.818.168.320 Bytes frei
.
- - End Of File - - 099B708D0D1BB0A18FB38AAFA38C1835
D41D8CD98F00B204E9800998ECF8427E
         


Alt 23.07.2013, 18:53   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Werbung öffnet sich Immer - Standard

Werbung öffnet sich Immer



Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
--> Werbung öffnet sich Immer

Alt 24.07.2013, 08:38   #7
Rejono
 
Werbung öffnet sich Immer - Standard

Werbung öffnet sich Immer



So erstmal die ADW

Code:
ATTFilter
# AdwCleaner v2.306 - Datei am 24/07/2013 um 09:23:44 erstellt
# Aktualisiert am 19/07/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzer : Theo Hulok - HARLEKIN
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Theo Hulok\Desktop\adwcleaner.exe
# Option [Löschen]


**** [Dienste] ****


***** [Dateien / Ordner] *****

Datei Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
Ordner Gelöscht : C:\Program Files (x86)\blekkotb
Ordner Gelöscht : C:\Program Files (x86)\SweetIM
Ordner Gelöscht : C:\ProgramData\SweetIM
Ordner Gelöscht : C:\Users\Theo Hulok\AppData\Local\blekkotb
Ordner Gelöscht : C:\Users\Theo Hulok\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\Theo Hulok\AppData\Local\Smartbar
Ordner Gelöscht : C:\Users\Theo Hulok\AppData\LocalLow\blekkotb
Ordner Gelöscht : C:\Users\Theo Hulok\AppData\LocalLow\SweetIM
Ordner Gelöscht : C:\Users\Theo Hulok\AppData\Roaming\DataMgr
Ordner Gelöscht : C:\Users\Theo Hulok\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Windows\Installer\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}

***** [Registrierungsdatenbank] *****

Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\blekkotb
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{20A0BE68-8FD9-4539-8712-CE3D1C1FDFC6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{26C9E18C-3717-4BE1-A225-04E4471F5B6E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{20A0BE68-8FD9-4539-8712-CE3D1C1FDFC6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{26C9E18C-3717-4BE1-A225-04E4471F5B6E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\SmartbarBackup
Schlüssel Gelöscht : HKCU\Software\SmartbarLog
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.BandObjectAttribute
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.DockingPanel
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.IESmartBarBandObject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarDisplayState
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\IESmartBar.SmartbarMenuForm
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\9EE58E3C298524145B73CBBED3CAC4D3
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\EB6AF8AEEB922FA4392548F13812E50B
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\9EE58E3C298524145B73CBBED3CAC4D3
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\EB6AF8AEEB922FA4392548F13812E50B
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SweetIM_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{20A0BE68-8FD9-4539-8712-CE3D1C1FDFC6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{26C9E18C-3717-4BE1-A225-04E4471F5B6E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{00F12770-E60E-4DC6-9105-425BFACE7C73}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{20A0BE68-8FD9-4539-8712-CE3D1C1FDFC6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{26C9E18C-3717-4BE1-A225-04E4471F5B6E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7B0EE1CE-B2EF-49D6-AF4D-EBF8240EF2C2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\blekkotb
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [DataMgr]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs [C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll]
Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{26C9E18C-3717-4BE1-A225-04E4471F5B6E}]
Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Wert Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

***** [Internet Browser] *****

-\\ Internet Explorer v10.0.9200.16635

Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - ICQ Search] = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd --> hxxp://www.google.com

-\\ Google Chrome v28.0.1500.72

Datei : C:\Users\Theo Hulok\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Die Datei ist sauber.

*************************

AdwCleaner[S1].txt - [9996 octets] - [24/07/2013 09:23:44]

########## EOF - C:\AdwCleaner[S1].txt - [10056 octets] ##########
         
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.2.2 (07.22.2013:2)
OS: Windows 7 Home Premium x64
Ran by Theo Hulok on 24.07.2013 at  9:31:54,83
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-1201534454-2380176246-3172034216-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\Default_Search_URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL\\Default
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\searchURL\\Default
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\apnstub_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\tracing\apnstub_rasmancs



~~~ Files

Successfully deleted: [File] C:\Windows\syswow64\shoE2CD.tmp



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{01725579-BE71-4934-96AE-95AC6AF4BEEE}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{053434CA-F39E-4BC2-B891-8D69BC78AF75}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{089DED13-D192-4024-BCDC-79C98ECE99EC}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{1227C304-62CC-4829-B918-D9947587E9BC}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{137E809D-1BA4-4B3E-85FF-AEE50E3C3CB3}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{178E628A-4EC8-4965-B12B-E59B1E185A57}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{21638074-3F8F-4F02-AFDE-B8CA37324906}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{2338FA7A-B245-4ADA-BC0B-67F91DFEF845}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{2900AB9E-9B71-4314-AD01-A4AFF07C37FA}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{3813FC8B-AB38-49CA-853B-9BA426F06F08}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{3BD374E8-462E-4ADA-8E22-8C9CD4BA5601}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{47DF8D26-5F04-4764-A994-4D910F992D0F}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{481A68E8-7EA1-407E-AEFA-FCD422D306AD}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{48EBDCB9-615C-46A2-BDE0-C26CAD14F743}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{4FF944FE-64DB-4FE6-B512-9BB3C1CCE6B7}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{5A5624A2-692D-4F37-A38F-CD3EBE8A9F5E}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{5BC6F0AE-2180-41F3-9E94-E0992260478C}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{5DA12824-CF67-48D1-9004-1686CF47E30C}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{67ABD8F9-3DD7-444B-B8A7-F02D7F6065EB}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{6E58D6C5-0E24-4473-A717-3E4F8FAC3DCD}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{768522D0-4342-446F-8C6F-EC8A3BF74C15}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{76E913E7-DB35-4548-853A-3E171B85A272}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{870135BD-636E-4023-BFB2-C866DE0590B5}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{89CA7832-2A0D-47A3-9C56-890F0EB94EC8}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{8C18ABCE-B914-46F8-A457-1DEE7A91C9A1}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{94A90B4C-B8D7-45E7-9439-B8203B1F5AEC}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{95FEFE54-D6B0-4A6A-8126-1A0B53C9259D}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{962A682F-6D0C-4812-85E9-619835F97B05}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{9656E31F-21B4-44DE-8391-7ADA1FBE9F4A}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{974A9F8C-8DEC-4D74-9578-10B3BF6F74DC}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{97BDB04A-0A14-46CF-8584-B6206EB72213}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{9C2C5C35-1755-4AB0-895F-814FF7E981BE}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{9C7A2254-59C0-4A08-8406-76859C888D37}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{A3C3AFC5-9BF9-4536-821A-643080CF2747}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{A5CA68F3-8AD9-4F65-8909-10CBC99A4F5B}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{A9C6E102-3021-4D97-A03F-CA2DD7E3ECF5}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{B04F8AD6-9D46-44DD-AE99-11B2ED492421}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{B831BBBE-F251-49AE-8315-A51FBA1778DF}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{C225C8D2-25ED-490E-B3AC-A7F61F20EAD6}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{C2356046-2BF6-41CB-BA15-928990920E43}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{C2506965-4F71-436C-9E65-C9140608AFB6}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{C9F5EC43-645A-443E-9A9D-D26EBD965D24}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{CA5D8C69-18C7-468B-A0E4-DA9F5137C022}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{CB4E7C8A-4749-4936-BF77-8F7EC7B9363E}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{CE3AE797-B3A6-438E-9AD6-24E32DB5CBFF}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{DA81D03F-272A-473F-AE1F-E605ECFFD5BF}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{E24F2DE6-73AF-4B04-BBEA-D210D14D4C6C}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{E8CF8362-12B8-4378-9BE6-6A2B4C5F5E10}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{E9325C39-D820-4940-ADBB-E08EAF2B39AA}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{EB6AE2B3-D1E0-4FF4-A807-61327D76596B}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{F6A0907A-C9E4-4826-B9E3-5479EE3EC6A3}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{F8294CA8-8722-4318-902D-300DD7BF275B}
Successfully deleted: [Empty Folder] C:\Users\Theo Hulok\appdata\local\{FF471ADB-5DAD-4FBE-8F74-F61BFC2341A7}



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 24.07.2013 at  9:35:18,03
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
Muss hinzufügen das dieses Fenster leider immernoch kommt.


FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-07-2013 01
Ran by Theo Hulok (administrator) on 24-07-2013 09:37:40
Running from C:\Users\Theo Hulok\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\system32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(AMD) C:\Windows\system32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Hewlett-Packard ) C:\Program Files\IDT\WDM\beats64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
() C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Roccat GmbH) C:\Program Files (x86)\ROCCAT\Kova[+] Mouse\Kova[+]Monitor.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe
() E:\DriveMonitor\adm_tray.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\CNYHKEY.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) c:\program files\windows defender\MpCmdRun.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [BeatsOSDApp] - C:\Program Files\IDT\WDM\beats64.exe [37888 2010-08-15] (Hewlett-Packard )
HKLM\...\Run: [hpsysdrv] - c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [489472 2010-09-27] (IDT, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-03-15] (Adobe Systems Incorporated)
HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [462400 2011-02-12] (Acronis)
HKCU\...\Run: [SSync] - C:\Users\Theo Hulok\AppData\Roaming\SSync\SSync.exe [36864 2013-04-10] ()
HKCU\...\Run: [SCheck] - C:\Users\Theo Hulok\AppData\Roaming\SCheck\SCheck.exe [36864 2013-04-10] ()
HKCU\...\Run: [Snoozer] - C:\Users\Theo Hulok\AppData\Roaming\Snz\Snz.exe [1137673 2013-07-21] ()
HKCU\...\Run: [Intermediate] - C:\Users\Theo Hulok\AppData\Roaming\Intermediate\Intermediate.exe [36864 2013-04-10] ()
HKCU\...\Policies\system: [DisableLockWorkstation] 0
HKCU\...\Policies\system: [DisableChangePassword] 0
HKLM-x32\...\Run: [] -  [x]
HKLM-x32\...\Run: [BATINDICATOR] - C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe [2068992 2009-05-09] (Hewlett-Packard)
HKLM-x32\...\Run: [LaunchHPOSIAPP] - C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe [385024 2009-04-04] (Hewlett-Packard)
HKLM-x32\...\Run: [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui [4858968 2013-05-09] (AVAST Software)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-10-17] (Intel Corporation)
HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [RoccatKova+] - "C:\Program Files (x86)\ROCCAT\Kova[+] Mouse\Kova[+]Monitor.EXE" [539688 2011-03-17] (Roccat GmbH)
HKLM-x32\...\Run: [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-08-27] (Apple Inc.)
HKLM-x32\...\Run: [adm_tray.exe] - E:\DriveMonitor\adm_tray.exe [470120 2011-02-24] ()
HKLM-x32\...\Run: [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [642656 2013-03-28] (Advanced Micro Devices, Inc.)
HKU\Mcx1-THEOHULOK-HP\...\Winlogon: [Shell] C:\Windows\eHome\McrMgr.exe [343552 2009-07-14] (Microsoft Corporation) <==== ATTENTION 

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - "C:\Program Files (x86)\Internet Explorer\iexplore.exe"
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM - {d944bb61-2e34-4dbf-a683-47e505c587dc} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-0/4?satitle={searchTerms}&mfe=Desktops
SearchScopes: HKLM - {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://www.bing.com/search?q={searchTerms}&form=HPDTDF&pc=HPDTDF&src=IE-SearchBox
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ChromeFrame BHO - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files (x86)\Google\Chrome Frame\Application\28.0.1500.71\npchrome_frame.dll (Google Inc.)
Toolbar: HKLM - avast! WebRep - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} -  No File
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files (x86)\Google\Chrome Frame\Application\28.0.1500.71\npchrome_frame.dll (Google Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)

Chrome: 
=======
CHR HomePage: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=DE&userid=59b6da75-794e-48a1-938d-8e7baa0095f2&searchtype=hp&installDate=14/06/2013
CHR RestoreOnStartup: "hxxp://google.de/"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Users\Theo Hulok\AppData\Local\Google\Chrome\User Data\PepperFlash\11.5.31.139\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\pdf.dll ()
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files (x86)\Battlelog Web Plugins\1.140.0\npesnlaunch.dll No File
CHR Plugin: (ESN Sonar API) - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U11) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Extension: (Angry Birds) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0
CHR Extension: (SocialReviver) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\beeidigicffecnkbanlfnmaplmkafdje\4.1_0
CHR Extension: (YouTube) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Adblock Plus) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.5_0
CHR Extension: (Google Search) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Grooveshark Germany unlocker) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\docdgimmdejoiemdafcgeodchlbllgac\2.3.4_0
CHR Extension: (OfferMosquito) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\0.5_0
CHR Extension: (avast! Online Security) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.8_0
CHR Extension: (Auto Replay for YouTube) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb\1.9.26_0
CHR Extension: (Gmail) - C:\Users\THEOHU~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx

==================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2012-07-11] (SUPERAntiSpyware.com)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-05-26] ()
R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2404864 2011-03-24] (Deutsche Telekom AG)
S4 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [14848 2011-12-15] ()
R2 OS Selector; C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe [2155848 2010-05-25] ()
S4 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [80896 2010-09-16] ()
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1119768 2010-09-28] (PDF Complete Inc)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-06-07] ()
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2123584 2011-12-14] (TuneUp Software)

==================== Drivers (Whitelisted) ====================

R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software)
R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [28504 2012-03-07] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-28] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-28] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-28] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2011-12-24] ()
S3 CpqDfw; C:\Windows\System32\drivers\CpqDfw.sys [24376 2010-03-02] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-06-14] (DT Soft Ltd)
R3 KovaPlusFltr; C:\Windows\System32\drivers\KovaPlusFltr.sys [15104 2010-01-25] (ROCCAT Development, Inc.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2011-12-24] ()
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2011-11-08] (TuneUp Software)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-24 09:35 - 2013-07-24 09:35 - 00008132 _____ C:\Users\Theo Hulok\Desktop\JRT.txt
2013-07-24 09:31 - 2013-07-24 09:31 - 00000000 ____D C:\Windows\ERUNT
2013-07-24 09:30 - 2013-07-24 09:31 - 00560934 _____ (Oleg N. Scherbakov) C:\Users\Theo Hulok\Desktop\JRT.exe
2013-07-24 09:23 - 2013-07-24 09:24 - 00010098 _____ C:\AdwCleaner[S1].txt
2013-07-24 09:22 - 2013-07-24 09:22 - 00666633 _____ C:\Users\Theo Hulok\Desktop\adwcleaner.exe
2013-07-23 17:04 - 2013-07-23 17:04 - 00034383 _____ C:\ComboFix.txt
2013-07-23 16:54 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-07-23 16:54 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-07-23 16:54 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-07-23 16:54 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-07-23 16:54 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-07-23 16:54 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-07-23 16:54 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-07-23 16:54 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-07-23 16:52 - 2013-07-23 17:04 - 00000000 ____D C:\Qoobox
2013-07-23 16:52 - 2013-07-23 17:03 - 00000000 ____D C:\Windows\erdnt
2013-07-23 16:51 - 2013-07-23 16:52 - 05092552 ____R (Swearware) C:\Users\Theo Hulok\Desktop\ComboFix.exe
2013-07-23 12:17 - 2013-07-23 12:17 - 00046417 _____ C:\Users\Theo Hulok\Downloads\FRST.txt
2013-07-23 12:17 - 2013-07-23 12:17 - 00029141 _____ C:\Users\Theo Hulok\Downloads\Addition.txt
2013-07-23 12:16 - 2013-07-23 12:16 - 01779447 _____ (Farbar) C:\Users\Theo Hulok\Desktop\FRST64.exe
2013-07-23 12:16 - 2013-07-23 12:16 - 00000000 ____D C:\FRST
2013-07-23 10:19 - 2013-07-23 10:19 - 00015600 _____ C:\Users\Theo Hulok\Downloads\hijackthis.log
2013-07-23 10:18 - 2013-07-23 10:18 - 00388608 _____ (Trend Micro Inc.) C:\Users\Theo Hulok\Downloads\HiJackThis204.exe
2013-07-21 18:01 - 2013-07-21 18:01 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Snz
2013-07-21 12:48 - 2013-07-21 13:10 - 00001284 _____ C:\Users\Theo Hulok\Desktop\stress mit grund.txt
2013-07-12 12:29 - 2013-07-12 12:29 - 00000196 _____ C:\Users\Theo Hulok\Desktop\Counter-Strike Global Offensive - SDK.url
2013-07-11 17:15 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-11 17:15 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-11 17:15 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-11 17:15 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-11 17:15 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-11 17:15 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-11 17:15 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-11 17:15 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-11 17:15 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-11 17:15 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-11 17:15 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-11 17:15 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-11 17:15 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-11 17:15 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-11 17:15 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-11 17:15 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-11 17:15 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-11 17:15 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-11 17:15 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-11 17:15 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-11 17:15 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-11 17:15 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-11 15:29 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-11 15:29 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-11 15:29 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-11 15:29 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-11 15:27 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-11 00:51 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-11 00:51 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-07-09 02:01 - 2013-07-09 02:01 - 00002052 _____ C:\Users\Theo Hulok\Downloads\1e35uym63e9zy78.dlc
2013-07-08 19:46 - 2013-07-08 19:53 - 00000000 ____D C:\Users\Theo Hulok\Desktop\Juli
2013-07-08 15:32 - 2013-07-08 15:32 - 00001796 _____ C:\Users\Theo Hulok\Downloads\Kontor59_splitted-e3nq0pmirkzw.dlc
2013-07-07 19:17 - 2013-07-12 13:57 - 00037174 _____ C:\Windows\DirectX.log
2013-07-04 13:45 - 2013-07-04 13:45 - 00175832 _____ C:\Users\Theo Hulok\Documents\ts3_clientui-win32-1361977727-2013-07-04 13_45_35.633085.dmp
2013-07-03 17:38 - 2013-07-21 18:01 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Intermediate
2013-07-03 17:38 - 2013-07-03 17:38 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\SSync
2013-07-03 17:38 - 2013-07-03 17:38 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\SCheck
2013-07-03 17:31 - 2013-07-03 17:31 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\PiccShare
2013-07-03 17:31 - 2013-07-03 17:31 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Common
2013-07-03 17:28 - 2013-07-03 17:28 - 00393040 _____ (Softonic                                        ) C:\Users\Theo Hulok\Downloads\SoftonicDownloader_fuer_morphvox.exe
2013-07-02 20:00 - 2013-07-02 20:00 - 02812928 _____ C:\Users\Theo Hulok\Downloads\Nahostkonflikt (halbfertig).ppt
2013-07-02 11:36 - 2013-07-24 09:25 - 00002679 _____ C:\Windows\setupact.log
2013-07-02 11:36 - 2013-07-24 09:25 - 00001974 _____ C:\Windows\PFRO.log
2013-07-02 11:36 - 2013-07-02 11:36 - 00000000 _____ C:\Windows\setuperr.log
2013-07-02 01:28 - 2013-07-02 01:29 - 00000000 ____D C:\ProgramData\SUPERSetup
2013-07-02 01:01 - 2013-07-02 01:01 - 00000000 ____D C:\Users\Theo Hulok\Documents\r3jn und co
2013-07-01 23:15 - 2013-07-01 23:15 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\Sony Online Entertainment
2013-06-29 01:08 - 2013-06-29 01:08 - 00001072 _____ C:\Users\Theo Hulok\Downloads\929byf978zrv88k.dlc
2013-06-28 13:21 - 2013-06-28 13:21 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-06-28 13:12 - 2013-06-28 13:20 - 63363736 _____ (Microsoft Corporation) C:\Users\Theo Hulok\Downloads\PowerPointViewer.exe
2013-06-28 08:21 - 2013-06-28 08:21 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum
2013-06-27 01:07 - 2013-06-27 01:07 - 00000000 ____D C:\ProgramData\ATI
2013-06-27 01:06 - 2013-06-27 01:06 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-06-27 00:41 - 2013-06-27 01:02 - 141110624 _____ (Advanced Micro Devices, Inc.) C:\Users\Theo Hulok\Downloads\13-4_win7_win8_64_dd_ccc_whql.exe
2013-06-27 00:21 - 2013-06-27 00:21 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\War Thunder
2013-06-27 00:19 - 2013-06-27 00:20 - 04089992 _____ (2013 Gaijin Entertainment Corporation                       ) C:\Users\Theo Hulok\Downloads\wt_launcher_1.0.1.246.exe
2013-06-26 23:36 - 2013-06-26 23:38 - 00000000 ____D C:\ProgramData\WarThunder
2013-06-26 23:36 - 2013-06-26 23:36 - 00000892 _____ C:\Users\Theo Hulok\Desktop\launcher - Verknüpfung.lnk
2013-06-26 23:36 - 2013-06-26 23:36 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\WarThunder
2013-06-26 21:31 - 2013-06-26 21:31 - 00000584 _____ C:\Users\Public\Desktop\Blender.lnk
2013-06-26 21:20 - 2013-06-26 21:30 - 48846068 _____ C:\Users\Theo Hulok\Downloads\blender-2.67b-windows64.exe
2013-06-26 20:56 - 2013-06-28 08:21 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum
2013-06-26 20:56 - 2013-06-28 08:21 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum
2013-06-26 17:53 - 2013-06-26 17:58 - 40932318 _____ C:\Users\Theo Hulok\Downloads\blender-2.67b-windows32.exe
2013-06-26 14:54 - 2013-06-26 14:54 - 00001816 _____ C:\Users\Theo Hulok\Downloads\VA-Kontor_House_of_House_18-3CD-2013-VOiCE-e1sv9nm3z2w3.dlc
2013-06-26 13:29 - 2013-06-26 13:29 - 00001368 _____ C:\Users\Theo Hulok\Downloads\Disco_House_2CD_2013_-s9dqxnm6t78y.dlc
2013-06-26 01:45 - 2013-06-26 01:45 - 00000000 ____D C:\Users\Theo Hulok\Desktop\EP-Harlekin
2013-06-25 22:29 - 2013-06-25 22:29 - 00001072 _____ C:\Users\Theo Hulok\Downloads\vxb3xb35y6h23la.dlc
2013-06-25 22:29 - 2013-06-25 22:29 - 00001072 _____ C:\Users\Theo Hulok\Downloads\vxb3xb35y6h23la (1).dlc
2013-06-24 14:15 - 2013-06-24 14:15 - 00015896 _____ C:\Users\Theo Hulok\Downloads\a9a161d2cb9f5da7706fb86c23f6b817.dlc
2013-06-24 14:10 - 2013-06-24 14:10 - 00009860 _____ C:\Users\Theo Hulok\Downloads\d5ef29da2fa393c081ec3c220c5343d2.dlc
2013-06-24 10:50 - 2013-06-24 10:50 - 00000923 _____ C:\Users\Theo Hulok\Desktop\CIM2 - Verknüpfung.lnk
2013-06-24 10:40 - 2013-06-24 10:40 - 00000000 ____D C:\ProgramData\Steam
2013-06-24 00:59 - 2013-06-24 00:59 - 00001092 _____ C:\Users\Theo Hulok\Downloads\Cities_in_Motion_2_-_ALiAS-dqo46lml2nyr.dlc

==================== One Month Modified Files and Folders =======

2013-07-24 09:36 - 2012-04-05 11:19 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-24 09:35 - 2013-07-24 09:35 - 00008132 _____ C:\Users\Theo Hulok\Desktop\JRT.txt
2013-07-24 09:33 - 2009-07-14 06:45 - 00015792 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-24 09:33 - 2009-07-14 06:45 - 00015792 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-24 09:31 - 2013-07-24 09:31 - 00000000 ____D C:\Windows\ERUNT
2013-07-24 09:31 - 2013-07-24 09:30 - 00560934 _____ (Oleg N. Scherbakov) C:\Users\Theo Hulok\Desktop\JRT.exe
2013-07-24 09:30 - 2011-04-24 14:06 - 00697300 _____ C:\Windows\system32\perfh007.dat
2013-07-24 09:30 - 2011-04-24 14:06 - 00148338 _____ C:\Windows\system32\perfc007.dat
2013-07-24 09:30 - 2009-07-14 07:13 - 01614964 _____ C:\Windows\system32\PerfStringBackup.INI
2013-07-24 09:25 - 2013-07-02 11:36 - 00002679 _____ C:\Windows\setupact.log
2013-07-24 09:25 - 2013-07-02 11:36 - 00001974 _____ C:\Windows\PFRO.log
2013-07-24 09:25 - 2012-05-29 01:09 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-24 09:25 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-24 09:24 - 2013-07-24 09:23 - 00010098 _____ C:\AdwCleaner[S1].txt
2013-07-24 09:24 - 2011-04-24 13:27 - 02045523 _____ C:\Windows\WindowsUpdate.log
2013-07-24 09:22 - 2013-07-24 09:22 - 00666633 _____ C:\Users\Theo Hulok\Desktop\adwcleaner.exe
2013-07-24 09:19 - 2011-08-03 00:02 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\TS3Client
2013-07-24 09:19 - 2011-07-28 22:23 - 00000000 ____D C:\steam
2013-07-24 09:05 - 2012-05-29 01:09 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-23 23:34 - 2011-08-31 12:30 - 00291128 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2013-07-23 23:34 - 2011-08-30 20:29 - 00291128 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-07-23 23:31 - 2012-12-27 18:11 - 00000000 ____D C:\Users\Theo Hulok\Documents\The War Z
2013-07-23 17:04 - 2013-07-23 17:04 - 00034383 _____ C:\ComboFix.txt
2013-07-23 17:04 - 2013-07-23 16:52 - 00000000 ____D C:\Qoobox
2013-07-23 17:04 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-07-23 17:03 - 2013-07-23 16:52 - 00000000 ____D C:\Windows\erdnt
2013-07-23 17:02 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-07-23 16:52 - 2013-07-23 16:51 - 05092552 ____R (Swearware) C:\Users\Theo Hulok\Desktop\ComboFix.exe
2013-07-23 12:17 - 2013-07-23 12:17 - 00046417 _____ C:\Users\Theo Hulok\Downloads\FRST.txt
2013-07-23 12:17 - 2013-07-23 12:17 - 00029141 _____ C:\Users\Theo Hulok\Downloads\Addition.txt
2013-07-23 12:16 - 2013-07-23 12:16 - 01779447 _____ (Farbar) C:\Users\Theo Hulok\Desktop\FRST64.exe
2013-07-23 12:16 - 2013-07-23 12:16 - 00000000 ____D C:\FRST
2013-07-23 11:07 - 2011-04-24 13:35 - 00000000 ____D C:\ProgramData\PDFC
2013-07-23 10:19 - 2013-07-23 10:19 - 00015600 _____ C:\Users\Theo Hulok\Downloads\hijackthis.log
2013-07-23 10:18 - 2013-07-23 10:18 - 00388608 _____ (Trend Micro Inc.) C:\Users\Theo Hulok\Downloads\HiJackThis204.exe
2013-07-23 00:35 - 2012-06-27 14:57 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\SoftGrid Client
2013-07-22 18:33 - 2013-03-10 20:03 - 00000000 ____D C:\Users\Theo Hulok\Desktop\bewerbung
2013-07-21 18:01 - 2013-07-21 18:01 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Snz
2013-07-21 18:01 - 2013-07-03 17:38 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Intermediate
2013-07-21 18:00 - 2012-07-11 23:50 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-07-21 15:12 - 2011-07-28 22:50 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\ICQ
2013-07-21 13:10 - 2013-07-21 12:48 - 00001284 _____ C:\Users\Theo Hulok\Desktop\stress mit grund.txt
2013-07-16 22:16 - 2011-09-18 13:18 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\ArmA 2 OA
2013-07-13 11:00 - 2012-05-29 01:09 - 00004114 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-13 11:00 - 2012-05-29 01:09 - 00003862 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-12 13:57 - 2013-07-07 19:17 - 00037174 _____ C:\Windows\DirectX.log
2013-07-12 12:29 - 2013-07-12 12:29 - 00000196 _____ C:\Users\Theo Hulok\Desktop\Counter-Strike Global Offensive - SDK.url
2013-07-12 11:06 - 2009-07-24 21:22 - 00000000 ____D C:\Windows\Panther
2013-07-12 11:05 - 2009-07-14 06:45 - 04868648 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-12 11:03 - 2013-03-14 00:30 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-12 11:03 - 2013-03-14 00:30 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-12 11:03 - 2009-07-14 09:45 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-12 11:03 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-12 11:03 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-09 02:01 - 2013-07-09 02:01 - 00002052 _____ C:\Users\Theo Hulok\Downloads\1e35uym63e9zy78.dlc
2013-07-08 19:53 - 2013-07-08 19:46 - 00000000 ____D C:\Users\Theo Hulok\Desktop\Juli
2013-07-08 15:32 - 2013-07-08 15:32 - 00001796 _____ C:\Users\Theo Hulok\Downloads\Kontor59_splitted-e3nq0pmirkzw.dlc
2013-07-04 13:45 - 2013-07-04 13:45 - 00175832 _____ C:\Users\Theo Hulok\Documents\ts3_clientui-win32-1361977727-2013-07-04 13_45_35.633085.dmp
2013-07-03 22:48 - 2011-08-30 20:29 - 00291128 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2013-07-03 17:39 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-07-03 17:38 - 2013-07-03 17:38 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\SSync
2013-07-03 17:38 - 2013-07-03 17:38 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\SCheck
2013-07-03 17:38 - 2012-05-29 01:09 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\Google
2013-07-03 17:37 - 2012-05-29 01:09 - 00000000 ____D C:\Program Files (x86)\Google
2013-07-03 17:34 - 2013-02-24 17:13 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Screaming Bee
2013-07-03 17:31 - 2013-07-03 17:31 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\PiccShare
2013-07-03 17:31 - 2013-07-03 17:31 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Common
2013-07-03 17:28 - 2013-07-03 17:28 - 00393040 _____ (Softonic                                        ) C:\Users\Theo Hulok\Downloads\SoftonicDownloader_fuer_morphvox.exe
2013-07-03 06:54 - 2013-05-27 14:07 - 00000000 ____D C:\Users\Theo Hulok\Desktop\fük
2013-07-02 20:00 - 2013-07-02 20:00 - 02812928 _____ C:\Users\Theo Hulok\Downloads\Nahostkonflikt (halbfertig).ppt
2013-07-02 11:36 - 2013-07-02 11:36 - 00000000 _____ C:\Windows\setuperr.log
2013-07-02 02:04 - 2011-08-26 16:54 - 00000000 ____D C:\Fraps
2013-07-02 02:02 - 2011-07-28 22:15 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\CrashDumps
2013-07-02 01:57 - 2011-08-26 17:05 - 00000000 ____D C:\Users\Theo Hulok\Desktop\aufnahmen
2013-07-02 01:29 - 2013-07-02 01:28 - 00000000 ____D C:\ProgramData\SUPERSetup
2013-07-02 01:29 - 2012-11-11 15:33 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2013-07-02 01:27 - 2012-08-09 23:25 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\DAEMON Tools Lite
2013-07-02 01:27 - 2011-12-26 13:23 - 00000000 ____D C:\Windows\Minidump
2013-07-02 01:27 - 2011-08-30 02:27 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\LogMeIn Hamachi
2013-07-02 01:25 - 2012-12-16 13:17 - 00000000 ____D C:\Windows\pss
2013-07-02 01:25 - 2011-07-28 20:43 - 00000000 ___RD C:\Users\Theo Hulok\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-07-02 01:18 - 2011-04-24 13:25 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-07-02 01:13 - 2012-01-09 22:39 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2013-07-02 01:13 - 2012-01-09 22:39 - 00000000 ____D C:\Program Files (x86)\Freemake
2013-07-02 01:13 - 2011-04-24 13:37 - 00000000 ____D C:\ProgramData\WildTangent
2013-07-02 01:13 - 2011-04-24 13:37 - 00000000 ____D C:\Program Files (x86)\HP Games
2013-07-02 01:10 - 2011-08-30 20:37 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
2013-07-02 01:09 - 2011-08-01 21:25 - 00000000 ____D C:\Users\Theo Hulok\Filme
2013-07-02 01:01 - 2013-07-02 01:01 - 00000000 ____D C:\Users\Theo Hulok\Documents\r3jn und co
2013-07-01 23:15 - 2013-07-01 23:15 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\Sony Online Entertainment
2013-07-01 15:38 - 2012-07-02 12:10 - 01591922 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-06-29 13:26 - 2013-05-20 12:35 - 00000000 ____D C:\Users\Theo Hulok\Desktop\auto
2013-06-29 01:08 - 2013-06-29 01:08 - 00001072 _____ C:\Users\Theo Hulok\Downloads\929byf978zrv88k.dlc
2013-06-28 17:08 - 2011-07-28 20:42 - 00071624 _____ C:\Users\THEOHU~1\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-28 13:21 - 2013-06-28 13:21 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-06-28 13:20 - 2013-06-28 13:12 - 63363736 _____ (Microsoft Corporation) C:\Users\Theo Hulok\Downloads\PowerPointViewer.exe
2013-06-28 08:21 - 2013-06-28 08:21 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum
2013-06-28 08:21 - 2013-06-26 20:56 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum
2013-06-28 08:21 - 2013-06-26 20:56 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum
2013-06-28 08:21 - 2013-03-22 22:46 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-06-28 08:21 - 2011-09-26 16:51 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-06-28 08:21 - 2011-09-26 16:51 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-06-27 01:07 - 2013-06-27 01:07 - 00000000 ____D C:\ProgramData\ATI
2013-06-27 01:06 - 2013-06-27 01:06 - 00000000 ____D C:\Program Files (x86)\AMD AVT
2013-06-27 01:06 - 2012-04-05 11:43 - 00000000 ____D C:\ProgramData\AMD
2013-06-27 01:06 - 2011-11-20 04:07 - 00000000 ____D C:\Program Files\ATI Technologies
2013-06-27 01:02 - 2013-06-27 00:41 - 141110624 _____ (Advanced Micro Devices, Inc.) C:\Users\Theo Hulok\Downloads\13-4_win7_win8_64_dd_ccc_whql.exe
2013-06-27 00:21 - 2013-06-27 00:21 - 00000000 ____D C:\Users\Theo Hulok\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\War Thunder
2013-06-27 00:20 - 2013-06-27 00:19 - 04089992 _____ (2013 Gaijin Entertainment Corporation                       ) C:\Users\Theo Hulok\Downloads\wt_launcher_1.0.1.246.exe
2013-06-26 23:38 - 2013-06-26 23:36 - 00000000 ____D C:\ProgramData\WarThunder
2013-06-26 23:37 - 2011-08-25 22:22 - 00000000 ____D C:\Users\Theo Hulok\Documents\My Games
2013-06-26 23:36 - 2013-06-26 23:36 - 00000892 _____ C:\Users\Theo Hulok\Desktop\launcher - Verknüpfung.lnk
2013-06-26 23:36 - 2013-06-26 23:36 - 00000000 ____D C:\Users\THEOHU~1\AppData\Local\WarThunder
2013-06-26 23:36 - 2011-12-26 14:24 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-06-26 21:31 - 2013-06-26 21:31 - 00000584 _____ C:\Users\Public\Desktop\Blender.lnk
2013-06-26 21:30 - 2013-06-26 21:20 - 48846068 _____ C:\Users\Theo Hulok\Downloads\blender-2.67b-windows64.exe
2013-06-26 18:00 - 2011-08-01 14:05 - 00000000 ____D C:\Users\Theo Hulok\.thumbnails
2013-06-26 17:58 - 2013-06-26 17:53 - 40932318 _____ C:\Users\Theo Hulok\Downloads\blender-2.67b-windows32.exe
2013-06-26 14:54 - 2013-06-26 14:54 - 00001816 _____ C:\Users\Theo Hulok\Downloads\VA-Kontor_House_of_House_18-3CD-2013-VOiCE-e1sv9nm3z2w3.dlc
2013-06-26 13:29 - 2013-06-26 13:29 - 00001368 _____ C:\Users\Theo Hulok\Downloads\Disco_House_2CD_2013_-s9dqxnm6t78y.dlc
2013-06-26 01:45 - 2013-06-26 01:45 - 00000000 ____D C:\Users\Theo Hulok\Desktop\EP-Harlekin
2013-06-25 22:29 - 2013-06-25 22:29 - 00001072 _____ C:\Users\Theo Hulok\Downloads\vxb3xb35y6h23la.dlc
2013-06-25 22:29 - 2013-06-25 22:29 - 00001072 _____ C:\Users\Theo Hulok\Downloads\vxb3xb35y6h23la (1).dlc
2013-06-24 14:15 - 2013-06-24 14:15 - 00015896 _____ C:\Users\Theo Hulok\Downloads\a9a161d2cb9f5da7706fb86c23f6b817.dlc
2013-06-24 14:10 - 2013-06-24 14:10 - 00009860 _____ C:\Users\Theo Hulok\Downloads\d5ef29da2fa393c081ec3c220c5343d2.dlc
2013-06-24 13:03 - 2011-09-01 14:28 - 00000000 ____D C:\Program Files (x86)\Origin
2013-06-24 11:47 - 2011-11-29 23:58 - 00000000 ____D C:\Users\Theo Hulok\Documents\Akte Husk aka Undizzable aka Giftgas
2013-06-24 10:50 - 2013-06-24 10:50 - 00000923 _____ C:\Users\Theo Hulok\Desktop\CIM2 - Verknüpfung.lnk
2013-06-24 10:40 - 2013-06-24 10:40 - 00000000 ____D C:\ProgramData\Steam
2013-06-24 00:59 - 2013-06-24 00:59 - 00001092 _____ C:\Users\Theo Hulok\Downloads\Cities_in_Motion_2_-_ALiAS-dqo46lml2nyr.dlc
2013-06-24 00:57 - 2012-08-07 01:06 - 00000000 ____D C:\Users\Theo Hulok\Desktop\Jdl

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-23 16:25

==================== End Of Log ==========
         
--- --- ---

--- --- ---

Alt 24.07.2013, 11:35   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Werbung öffnet sich Immer - Standard

Werbung öffnet sich Immer




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Werbung öffnet sich Immer
adobe, adobe flash player, antivirus, avast, bho, bonjour, explorer, flash player, google, helper, hijack, hijackthis, icq, internet, internet explorer, logfile, microsoft, pdf, plug-in, security, seiten, snoozer, software, spam, sweetpacks, werbung, windows, öffnet



Ähnliche Themen: Werbung öffnet sich Immer


  1. Werbung in Firefox, Fenster mit PC Optimierung Werbung öffnet sich automatisch
    Log-Analyse und Auswertung - 10.04.2015 (11)
  2. Probleme mit dem IE (Öffnet immer wieder Werbung)
    Log-Analyse und Auswertung - 08.08.2011 (3)
  3. Firefox öffnet plötzlich, immer wieder unerwünschte Webseiten ...Internet Explorer öffnet Werbung
    Log-Analyse und Auswertung - 12.06.2011 (17)
  4. Beim Start öffnet sich immer kurz ein scwarzes fenster + Opera öffnet immer eine Seite
    Log-Analyse und Auswertung - 06.06.2011 (10)
  5. Es öffnet sich immer Werbung im Internet Explorer....
    Alles rund um Windows - 05.02.2011 (6)
  6. Fenster öffnet sich immer wieder mit Werbung
    Plagegeister aller Art und deren Bekämpfung - 12.10.2010 (2)
  7. Firefox öffnet Tabs mit Werbung / Anstelle einer verlinkten URL öffnet sich Werbung
    Plagegeister aller Art und deren Bekämpfung - 08.08.2010 (4)
  8. IE Öffnet sich immer mit Werbung was tun?
    Log-Analyse und Auswertung - 17.05.2010 (1)
  9. Nach Download von Video öffnet sich immer Werbung
    Plagegeister aller Art und deren Bekämpfung - 15.04.2010 (10)
  10. Internet Explorer öffnet sich immer + Werbung
    Log-Analyse und Auswertung - 13.10.2009 (18)
  11. Google öffnet falsche Seiten, Spybot öffnet sich nicht und PC geht immer wieder aus
    Plagegeister aller Art und deren Bekämpfung - 26.08.2009 (8)
  12. Media Player öffnet sich selbstständig immer und immer wieder
    Log-Analyse und Auswertung - 30.10.2008 (0)
  13. IE7 öffnet sich immer Automatisch mit Werbung
    Log-Analyse und Auswertung - 09.09.2008 (17)
  14. werbung öffnet sich immer hijacklog auswerten bitte
    Mülltonne - 18.08.2008 (0)
  15. IE öffnet immer Werbung!!
    Log-Analyse und Auswertung - 28.07.2008 (1)
  16. IE7 öffnet sich immer Automatisch mit Werbung
    Log-Analyse und Auswertung - 13.07.2008 (1)
  17. IE öffnet immer Werbung
    Log-Analyse und Auswertung - 16.07.2006 (3)

Zum Thema Werbung öffnet sich Immer - Hallo. Seit gestern öffnet sich bei mir immer so eine Werbung. Habe nichts installiert außer einmal auf eine Seiten Werbung geklickt. Zitat: Logfile of Trend Micro HijackThis v2.0.4 Scan saved - Werbung öffnet sich Immer...
Archiv
Du betrachtest: Werbung öffnet sich Immer auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.