Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Trojaner SupTab u.a.

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 30.03.2014, 17:16   #1
randyandy66
 
Trojaner SupTab u.a. - Standard

Trojaner SupTab u.a.



Hallo, habe hier ein Problem mit einem Trojaner (mind.). Vermutlich durch den Download von jpgtopdf.exe

Ich habe schon FRST laufen lassen und die Dateien angehängt.

Hoffe, das genügt und dass irgendjemand sich mit diesem verrückten Zeug auskennt!!!
Vielen Dank!
Andreas
Angehängte Dateien
Dateityp: txt FRST Scan Result.txt (60,1 KB, 256x aufgerufen)
Dateityp: txt Addition.txt (68,4 KB, 188x aufgerufen)

Alt 30.03.2014, 18:53   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Trojaner SupTab u.a. - Standard

Trojaner SupTab u.a.



Hi,

Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen.


So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
__________________

__________________

Alt 30.03.2014, 22:15   #3
randyandy66
 
Trojaner SupTab u.a. - Standard

Trojaner SupTab u.a.



Also hier ist der Text 1:
FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by andreas (administrator) on ANDREAS-SAMS-PC on 30-03-2014 17:06:07
Running from C:\Users\andreas\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Microsoft Corporation) C:\Windows\System32\lpksetup.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe
(Arainia Solutions) C:\Program Files (x86)\Gizmo\gservice.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe
(PcWinTech.com) C:\Program Files (x86)\CleanMem\mini_monitor.exe
(Auslogics) C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Update\GoogleUpdate.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(Mister Group) C:\Program Files (x86)\System Explorer\SystemExplorer.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Copernic, a division of N. Harris Copernic Systems) C:\Program Files (x86)\Copernic

\DesktopSearch4\Copernic.DesktopSearch.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Arainia Solutions) C:\Program Files (x86)\Gizmo\gizmo.exe
(BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mindjet) C:\Program Files (x86)\Mindjet\MindManager 6\MmReminderService.exe
(Dropbox, Inc.) C:\Users\andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\netzmanager.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel_64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\33.0.1750.154\nacl64.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\33.0.1750.154\nacl64.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\system32\lpksetup.exe
(Mister Group) C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Samsung Electronics) C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Common Files\Samsung\SSCSettings\SSCSettings.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
(Microsoft Corporation) C:\Windows\sysWow64\SearchProtocolHost.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11660904 2010-12-01] (Realtek Semiconductor)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2782096 2010-07-26] (CANON INC.)
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft 

Corporation)
HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2817872 2012-04-25] (ELAN Microelectronics Corp.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 

2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [WinPatrol] - C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [400480 2012-01-30] (BillP 

Studios)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations 

GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe 

Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-

02] (Oracle Corporation)
HKLM-x32\...\Run: [MMReminderService] - C:\Program Files (x86)\Mindjet\MindManager 6\MMReminderService.exe [31232 2006-12-

14] (Mindjet)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-

Networking Ltd.)
HKLM\...\RunOnce: [NCInstallQueue] - rundll32 netman.dll,ProcessQueue [360448 2009-07-14] (Microsoft Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [Google Update] - C:\Users\andreas\AppData\Local\Google\Update

\GoogleUpdate.exe [136176 2011-05-13] (Google Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware

\SUPERAntiSpyware.exe [6563608 2014-01-15] (SUPERAntiSpyware)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office

\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [SystemExplorerAutoStart] - C:\Program Files (x86)\System 

Explorer\SystemExplorer.exe [2750936 2012-09-03] (Mister Group)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [GoogleDriveSync] - C:\Program Files (x86)\Google\Drive

\googledrivesync.exe [21822128 2014-01-30] (Google)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [B0D7A430849FA67EEA71A56253A48520238199B4._service_run] - C:

\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe [859976 2014-03-15] (Google Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple

\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple

\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [Facebook Update] - "C:\Users\andreas\AppData\Local\Facebook

\Update\FacebookUpdate.exe" /c /nocrashserver
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [Copernic Desktop Search 4] - C:\Program Files (x86)\Copernic

\DesktopSearch4\Copernic.DesktopSearch.exe [1568832 2014-02-25] (Copernic, a division of N. Harris Copernic Systems)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [GoogleChromeAutoLaunch_1DDDD6B09271C2EB3C06CC9B1731B636] - C:

\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe [859976 2014-03-15] (Google Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [GizmoDriveDelegate] - C:\Program Files (x86)\Gizmo\gizmo.exe 

[223640 2011-09-14] (Arainia Solutions)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\MountPoints2: {131db821-f56a-11e0-8ea6-e811322169d9} - F:

\NokiaPCIA_Autorun.exe
AppInit_DLLs: C:\PROGRA~2\SupTab\SearchProtect64.dll => C:\PROGRA~2\SupTab\SearchProtect64.dll File Not Found
AppInit_DLLs-x32: C:\PROGRA~2\SupTab\SearchProtect32.dll => "C:\PROGRA~2\SupTab\SearchProtect32.dll" File Not Found
Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled ()
Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk
ShortcutTarget: Netzmanager.lnk -> C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG)
Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- 

und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office

\Office14\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?

type=hp&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?

type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?

type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?

type=hp&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://istart.webssearches.com/?

type=hp&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?

type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?

type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?

type=hp&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://istart.webssearches.com/?

type=hp&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?

type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?

type=sc&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = 
SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx?

gd=&ctid=CT3324790&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=58&CUI=&UM=5&UP=SPD64F7ECC-B1EB-4DD1-8B2B-

FE27A7C23C95&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft 

Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office

\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX 

Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin

\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common 

Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows 

Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: W2PBrowser Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll 

()
BHO-x32: CmjBrowserHelperObject Object - {AC41D38F-B56D-40AD-94E0-B493D130C959} - C:\Program Files (x86)\Mindjet

\MindManager 6\Mm6InternetExplorer.dll (Mindjet)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office

\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin

\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Ask Toolbar - {4D594333-0076-A76A-76A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork

\Toolbar\MYC3\Passport.dll (APN LLC.)
Toolbar: HKLM-x32 - Ask Shopping Toolbar - {4D594333-2D53-4154-00A7-7A786E7484D7} - C:\Program Files 

(x86)\AskPartnerNetwork\Toolbar\MYC3-SAT\Passport.dll (APN LLC.)
Toolbar: HKCU - No Name - {4D594333-0076-A76A-76A7-7A786E7484D7} -  No File
Toolbar: HKCU - No Name - {4D594333-2D53-4154-00A7-7A786E7484D7} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll 

(Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default
FF NewTab: hxxp://istart.webssearches.com/newtab/?

type=nt&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX
FF DefaultSearchEngine: webssearches
FF SelectedSearchEngine: webssearches
FF Homepage: hxxp://istart.webssearches.com/?

type=hp&ts=1396123703&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft 

Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft 

Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player

\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, 

LLC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle 

Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle 

Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared

\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( 

Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft 

Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft 

Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll 

(Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll 

(Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll 

(Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll 

(Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update

\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update

\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @octoshape.com/Octoshape Streaming Services,version=1.0 - C:\Users\andreas\AppData\Roaming\Octoshape

\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\andreas\AppData\Local\Google\Update

\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\andreas\AppData\Local\Google\Update

\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\andreas\AppData\Roaming\mozilla\plugins\npoctoshape.dll (Octoshape ApS)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\webssearches.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: HQ-Vid-1.9f - C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default\Extensions\ee5ad154

-f909-4cc0-aa51-d7e94e3fb0af@36204afd-f43e-4917-9c71-8384e2e4d3ad.com [2014-03-29]
FF Extension: TinEye Reverse Image Search - C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default

\Extensions\tineye@ideeinc.com.xpi [2011-09-22]
FF Extension: Ask Toolbar - C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default\Extensions

\toolbar_MYC3@apn.ask.com.xpi [2013-08-23]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} 

[2012-10-20]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web 

Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 

[2013-05-23]
FF HKCU\...\Firefox\Extensions: [{b9aa91db-385d-4c69-8a2f-96790aa9405b}] - c:\program files (x86)\copernic

\desktopsearch4\firefoxconnector
FF Extension: Copernic Desktop Search - Search Firefox content - c:\program files (x86)\copernic

\desktopsearch4\firefoxconnector [2013-08-31]
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://istart.webssearches.com/?

type=sc&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX

Chrome: 
=======
CHR HomePage: hxxp://www.google.com/
CHR Extension: (Google Docs) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\aohghmighlieiainnegkcijnfilokake [2014-03-30]
CHR Extension: (Google Drive) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\apdfllckaahabafndbhieahigkjlhalf [2014-03-30]
CHR Extension: (YouTube) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-30]
CHR Extension: (Copernic Desktop Search Connector) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default

\Extensions\cnnbdaahphjgdgfhliignpepgnbnfomp [2014-03-30]
CHR Extension: (Google-Suche) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-30]
CHR Extension: (Gmail offline) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\ejidjjhkpiempkbhmpbfngldlkglhimk [2014-03-30]
CHR Extension: (Zotero Connector) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\ekhagklcjbdpajgpjgmbionohlpdbjgc [2014-03-30]
CHR Extension: (Highlight to Search) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\floipahigmmkfhkoapmnijnlnboniglg [2014-03-30]
CHR Extension: (TinEye Reverse Image Search) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\haebnnbpedcbhciplfhjjkbafijpncjl [2014-03-30]
CHR Extension: (WEB.DE MailCheck) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\jaogepninmlbinccpbiakcgiolijlllo [2014-03-30]
CHR Extension: (Hipmunk) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\jeabbdefhlelidlhahnfpbllaomkioke [2014-03-30]
CHR Extension: (Social Network Connector) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\jijghdpcfakjjecmadmkembnmmpojdfo [2014-03-30]
CHR Extension: (Klout (beta)) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\jjaakbhpcbpmojkhpiaacepfcaniglak [2014-03-30]
CHR Extension: (Webcam Toy) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\lfbgimoladefibpklnfmkpknadbklade [2014-03-30]
CHR Extension: (fIRST lOVE) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\lighpcanjnomdcjmfficdanifpdmgmhp [2014-03-30]
CHR Extension: (Google Maps) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\lneaknkopdijkpnocmklfnjbeapigfbh [2014-03-30]
CHR Extension: (Google Wallet) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\andreas\AppData\Local\Google\Chrome\User 

Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2014-03-30]
CHR Extension: (Buffer) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\noojglkidnpfjbincgijbaiedldjfbhh [2014-03-30]
CHR Extension: (Picasa) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\onlgmecjpnejhfeofkgbfgnmdlipdejb [2014-03-30]
CHR Extension: (Google Mail) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions

\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-30]
CHR HKCU\...\Chrome\Extension: [cnnbdaahphjgdgfhliignpepgnbnfomp] - c:\program files (x86)\copernic

\desktopsearch4\ChromeConnector\ChromeConnector.crx [2014-02-25]
CHR HKLM-x32\...\Chrome\Extension: [aaaajolaholnbffbeflpmmdnkjmgknom] - C:\ProgramData\AskPartnerNetwork\Toolbar\MYC3-SAT

\CRX\ToolbarCR.crx [2013-07-26]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player

\chrome\DivXHTML5\DivXHTML5.crx [2013-05-06]
CHR HKLM-x32\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\andreas\AppData\Local\Google\Chrome\User 

Data\Default\Extensions\newtabv3.crx [2014-03-29]
CHR StartMenuInternet: Google Chrome - C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe 

hxxp://istart.webssearches.com/?type=sc&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX

==================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2012-09-14] (SUPERAntiSpyware.com)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations 

GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & 

Co. KG)
S4 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [164816 2013-08-23] (APN LLC.)
R2 CTDevice_Srv; C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe [61440 2007-04-02] (Creative Technology Ltd)
S3 CTUPnPSv; C:\Program Files (x86)\Creative\Creative Centrale\CTUPnPSv.exe [64000 2008-05-21] (Creative Technology Ltd)
S4 DfSdkS; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe [544768 2009-08-24] (mst software 

GmbH, Germany)
R2 Gizmo Central; C:\Program Files (x86)\Gizmo\gservice.exe [34728 2011-09-14] (Arainia Solutions)
R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche 

Telekom AG)
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking 

Ltd.)
S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking 

Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking 

Ltd.)
R3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [821720 2012-08-

21] (Mister Group)

==================== Drivers (Whitelisted) ====================

S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2010-04-29] (Google Inc)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
R1 GizmoDrv; C:\Windows\System32\Drivers\GizmoDrv.sys [34704 2011-09-14] (Arainia Solutions LLC)
R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-03-30] (Malwarebytes Corporation)
R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC)
S4 pwdrvio; C:\Windows\system32\pwdrvio.sys [19936 2012-01-18] ()
S4 pwdspio; C:\Windows\system32\pwdspio.sys [13280 2012-01-18] ()
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S3 Rockusb; C:\Windows\System32\DRIVERS\rockusb.sys [66704 2013-09-09] (Fuzhou Rockchip Electronics Co,Ltd.)
S3 rtport; C:\Windows\SysWOW64\drivers\rtport.sys [15144 2011-02-14] (Windows (R) 2003 DDK 3790 provider)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and 

SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and 

SUPERAntiSpyware.com)
R3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, 

Marmiko IT-Solutions GmbH)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-30 17:06 - 2014-03-30 17:07 - 00033092 _____ () C:\Users\andreas\Downloads\FRST.txt
2014-03-30 17:05 - 2014-03-30 17:06 - 00000000 ____D () C:\FRST
2014-03-30 17:05 - 2014-03-30 17:05 - 02157056 _____ (Farbar) C:\Users\andreas\Downloads\FRST64.exe
2014-03-30 17:04 - 2014-03-30 17:04 - 01145856 _____ (Farbar) C:\Users\andreas\Downloads\FRST.exe
2014-03-30 15:50 - 2014-03-30 16:55 - 00000000 ____D () C:\AdwCleaner
2014-03-30 15:50 - 2014-03-30 15:50 - 01950720 _____ () C:\Users\andreas\Downloads\adwcleaner.exe
2014-03-30 15:48 - 2014-03-30 15:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\andreas\Downloads\revosetup95.exe
2014-03-30 15:48 - 2014-03-30 15:48 - 00001238 _____ () C:\Users\andreas\Desktop\Revo Uninstaller.lnk
2014-03-30 15:47 - 2014-03-30 16:44 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers

\MBAMSwissArmy.sys
2014-03-30 15:46 - 2014-03-30 15:46 - 00001078 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-03-30 15:46 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers

\mbamchameleon.sys
2014-03-30 15:46 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-30 15:46 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-30 15:45 - 2014-03-30 15:46 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\andreas\Downloads\mbam-setup-

2.0.0.1000.exe
2014-03-30 01:06 - 2014-03-30 01:06 - 49940480 _____ () C:\Program Files (x86)\GUT1321.tmp
2014-03-30 01:06 - 2014-03-30 01:06 - 00000000 ____D () C:\Program Files (x86)\GUM1320.tmp
2014-03-30 00:56 - 2014-03-30 00:56 - 00003144 _____ () C:\Windows\System32\Tasks\{203A3670-6A66-495F-B4A0-4907C6887A94}
2014-03-30 00:37 - 2014-03-30 00:44 - 00000643 _____ () C:\Windows\wininit.ini
2014-03-30 00:22 - 2014-03-30 00:22 - 00000000 ____D () C:\Users\andreas\AppData\Local\PDF Writer
2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\PDF Writer
2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\ProgramData\PDF Writer
2014-03-30 00:20 - 2013-07-13 12:15 - 00805376 _____ () C:\Windows\SysWOW64\EditCtlsU.ocx
2014-03-30 00:20 - 2013-07-12 22:57 - 00539648 _____ () C:\Windows\SysWOW64\LblCtlsU.ocx
2014-03-30 00:20 - 2013-04-05 13:55 - 00476160 _____ () C:\Windows\SysWOW64\TabStripCtlU.ocx
2014-03-30 00:20 - 2013-03-03 14:37 - 01061888 _____ () C:\Windows\SysWOW64\ExLvwU.ocx
2014-03-30 00:19 - 2013-09-01 12:59 - 01103872 _____ () C:\Windows\SysWOW64\CBLCtlsU.ocx
2014-03-30 00:19 - 2013-03-28 23:13 - 00645632 _____ () C:\Windows\SysWOW64\BtnCtlsU.ocx
2014-03-30 00:18 - 2014-03-30 00:18 - 08198048 _____ (Bullzip ) C:\Users\andreas\Downloads

\Setup_BullzipPDFPrinter_10_4_0_2240_STD.exe
2014-03-30 00:15 - 2014-03-30 00:15 - 00563720 _____ () C:\Users\andreas\Downloads\Java (1).exe
2014-03-29 22:10 - 2014-03-29 22:10 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-03-29 22:09 - 2014-03-30 00:35 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-03-29 22:09 - 2014-03-29 22:12 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-03-29 22:09 - 2014-03-29 22:09 - 00001357 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-03-29 22:09 - 2013-09-20 11:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2014-03-29 22:08 - 2014-03-29 22:08 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\spybot-2.2.exe
2014-03-29 22:06 - 2014-03-30 00:59 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Activeris
2014-03-29 22:04 - 2014-03-29 22:05 - 19425127 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\Nicht bestätigt 

322160.crdownload
2014-03-29 22:03 - 2014-03-29 22:03 - 00320520 _____ () C:\Users\andreas\Downloads\Java.exe
2014-03-29 21:51 - 2014-03-29 21:51 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\dlg
2014-03-29 21:50 - 2014-03-30 00:57 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-03-29 21:50 - 2014-03-29 21:51 - 00000000 ____D () C:\Program Files (x86)\Jpg2Pdf
2014-03-29 21:49 - 2014-03-29 21:49 - 00001065 _____ () C:\Users\Public\Desktop\7-PDF Maker.lnk
2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\7-PDFMaker
2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Program Files (x86)\7-PDF
2014-03-29 21:45 - 2014-03-29 21:46 - 55633177 _____ (7-PDF, Germany ) C:\Users\andreas\Downloads\7p141.exe
2014-03-29 21:43 - 2014-03-29 21:43 - 00930952 _____ (CNET Download.com) C:\Users\andreas\Downloads\cbsidlm-cbsi183-

Free_JPG_to_PDF-ORG-75732662.exe
2014-03-27 23:21 - 2014-03-27 23:21 - 00000000 ____D () C:\Users\andreas\AppData\Local\Skype
2014-03-27 23:20 - 2014-03-27 23:20 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-27 22:54 - 2014-03-27 22:54 - 00476024 _____ (1&1 Mail & Media GmbH) C:\Users\andreas\Downloads

\WEB.DE_MailCheck_chrome_setup (2).exe
2014-03-15 09:17 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-15 09:17 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-15 09:17 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-15 09:17 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-15 09:17 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-15 09:17 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-15 09:17 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-15 09:17 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-15 09:17 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-15 09:17 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-15 09:17 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-15 09:17 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-15 09:17 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-15 09:17 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows

\system32\MsSpellCheckingFacility.exe
2014-03-15 09:17 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-15 09:17 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-15 09:17 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-15 09:17 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-15 09:17 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-15 09:17 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-15 09:17 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-15 09:17 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-15 09:17 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-15 09:17 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-15 09:17 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-15 09:17 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-15 09:17 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-15 09:17 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-15 09:17 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-15 09:17 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-15 09:17 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-15 09:17 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-15 09:17 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-15 09:17 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-15 09:17 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-15 09:17 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-15 09:17 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-15 09:17 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-15 09:17 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-15 09:17 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-15 09:17 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-15 09:17 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-15 09:17 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-15 09:17 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-15 09:17 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-15 09:17 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-15 09:17 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-15 09:17 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-11 22:07 - 2014-03-11 22:07 - 04550656 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr
2014-03-01 14:26 - 2014-03-01 14:26 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iTunes
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iPod
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-03-01 14:00 - 2014-03-01 14:16 - 00000000 ____D () C:\ff602098354a13baca66adf688cd6c8a
2014-03-01 13:58 - 2014-03-01 13:58 - 00000000 ____D () C:\Program Files (x86)\QuickTime

==================== One Month Modified Files and Folders =======

2014-03-30 17:07 - 2014-03-30 17:06 - 00033092 _____ () C:\Users\andreas\Downloads\FRST.txt
2014-03-30 17:06 - 2014-03-30 17:05 - 00000000 ____D () C:\FRST
2014-03-30 17:06 - 2011-05-13 17:36 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718

-708133086-1000UA.job
2014-03-30 17:05 - 2014-03-30 17:05 - 02157056 _____ (Farbar) C:\Users\andreas\Downloads\FRST64.exe
2014-03-30 17:05 - 2010-12-17 23:56 - 00703176 _____ () C:\Windows\system32\perfh007.dat
2014-03-30 17:05 - 2010-12-17 23:56 - 00150784 _____ () C:\Windows\system32\perfc007.dat
2014-03-30 17:05 - 2009-07-14 07:13 - 01629212 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-30 17:04 - 2014-03-30 17:04 - 01145856 _____ (Farbar) C:\Users\andreas\Downloads\FRST.exe
2014-03-30 17:02 - 2013-10-03 13:29 - 00000000 ____D () C:\Users\andreas\AppData\Local\E2BABF81-CECF-40E0-A839-

5CA03E1839C9.aplzod
2014-03-30 17:02 - 2012-04-12 19:52 - 00001146 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-

235724718-708133086-1000UA.job
2014-03-30 17:01 - 2011-09-22 19:16 - 00000000 ____D () C:\Users\andreas\Videos\Documents\Outlook-Dateien
2014-03-30 17:00 - 2011-11-08 22:04 - 00000000 ___RD () C:\Users\andreas\Dropbox
2014-03-30 17:00 - 2011-11-08 22:00 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Dropbox
2014-03-30 16:59 - 2013-02-12 16:12 - 00000000 ___RD () C:\Users\andreas\Google Drive
2014-03-30 16:57 - 2012-02-09 01:07 - 00000330 _____ () C:\Windows\Tasks\GlaryInitialize.job
2014-03-30 16:57 - 2011-06-05 14:26 - 00051847 _____ () C:\Windows\setupact.log
2014-03-30 16:57 - 2011-05-21 22:56 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-30 16:57 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-30 16:56 - 2010-12-17 23:29 - 02000004 _____ () C:\Windows\WindowsUpdate.log
2014-03-30 16:55 - 2014-03-30 15:50 - 00000000 ____D () C:\AdwCleaner
2014-03-30 16:51 - 2011-05-13 17:39 - 00002450 _____ () C:\Users\andreas\Desktop\Google Chrome.lnk
2014-03-30 16:44 - 2014-03-30 15:47 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers

\MBAMSwissArmy.sys
2014-03-30 16:19 - 2012-05-16 19:55 - 00001152 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718

-708133086-500UA.job
2014-03-30 16:17 - 2011-05-21 22:56 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-30 16:08 - 2012-05-08 00:40 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-30 16:06 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-

1.C7483456-A289-439d-8115-601632D005A0
2014-03-30 16:06 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-

0.C7483456-A289-439d-8115-601632D005A0
2014-03-30 15:50 - 2014-03-30 15:50 - 01950720 _____ () C:\Users\andreas\Downloads\adwcleaner.exe
2014-03-30 15:48 - 2014-03-30 15:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\andreas\Downloads\revosetup95.exe
2014-03-30 15:48 - 2014-03-30 15:48 - 00001238 _____ () C:\Users\andreas\Desktop\Revo Uninstaller.lnk
2014-03-30 15:48 - 2011-05-13 19:19 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-03-30 15:46 - 2014-03-30 15:46 - 00001078 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-03-30 15:46 - 2014-03-30 15:45 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\andreas\Downloads\mbam-setup-

2.0.0.1000.exe
2014-03-30 15:16 - 2011-06-23 11:30 - 00489538 _____ () C:\Windows\PFRO.log
2014-03-30 01:06 - 2014-03-30 01:06 - 49940480 _____ () C:\Program Files (x86)\GUT1321.tmp
2014-03-30 01:06 - 2014-03-30 01:06 - 00000000 ____D () C:\Program Files (x86)\GUM1320.tmp
2014-03-30 01:06 - 2011-12-27 12:05 - 00008224 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-30 01:05 - 2012-07-12 09:30 - 00000000 ___RD () C:\Users\Administrator\Podcasts
2014-03-30 01:05 - 2012-05-16 19:55 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-03-30 01:05 - 2011-12-27 12:05 - 00001417 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start 

Menu\Programs\Internet Explorer.lnk
2014-03-30 01:05 - 2011-12-27 12:05 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start 

Menu\Programs\Startup
2014-03-30 01:05 - 2011-12-27 12:05 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start 

Menu\Programs\Administrative Tools
2014-03-30 01:02 - 2011-05-13 19:01 - 00000000 ____D () C:\Users\andreas\Desktop\weniger genutzte software
2014-03-30 00:59 - 2014-03-29 22:06 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Activeris
2014-03-30 00:57 - 2014-03-29 21:50 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-03-30 00:57 - 2011-05-13 11:23 - 00001421 _____ () C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu

\Programs\Internet Explorer.lnk
2014-03-30 00:56 - 2014-03-30 00:56 - 00003144 _____ () C:\Windows\System32\Tasks\{203A3670-6A66-495F-B4A0-4907C6887A94}
2014-03-30 00:44 - 2014-03-30 00:37 - 00000643 _____ () C:\Windows\wininit.ini
2014-03-30 00:35 - 2014-03-29 22:09 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-03-30 00:22 - 2014-03-30 00:22 - 00000000 ____D () C:\Users\andreas\AppData\Local\PDF Writer
2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\PDF Writer
2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\ProgramData\PDF Writer
2014-03-30 00:18 - 2014-03-30 00:18 - 08198048 _____ (Bullzip ) C:\Users\andreas\Downloads

\Setup_BullzipPDFPrinter_10_4_0_2240_STD.exe
2014-03-30 00:15 - 2014-03-30 00:15 - 00563720 _____ () C:\Users\andreas\Downloads\Java (1).exe
2014-03-29 22:38 - 2011-06-05 17:37 - 00000000 ____D () C:\Users\andreas\AppData\Local\CrashDumps
2014-03-29 22:12 - 2014-03-29 22:09 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-03-29 22:10 - 2014-03-29 22:10 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-03-29 22:09 - 2014-03-29 22:09 - 00001357 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-03-29 22:08 - 2014-03-29 22:08 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\spybot-2.2.exe
2014-03-29 22:06 - 2011-09-20 22:05 - 00001332 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-03-29 22:06 - 2011-05-13 17:36 - 00001076 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718

-708133086-1000Core.job
2014-03-29 22:05 - 2014-03-29 22:04 - 19425127 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\Nicht bestätigt 

322160.crdownload
2014-03-29 22:03 - 2014-03-29 22:03 - 00320520 _____ () C:\Users\andreas\Downloads\Java.exe
2014-03-29 21:51 - 2014-03-29 21:51 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\dlg
2014-03-29 21:51 - 2014-03-29 21:50 - 00000000 ____D () C:\Program Files (x86)\Jpg2Pdf
2014-03-29 21:50 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-03-29 21:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-03-29 21:49 - 2014-03-29 21:49 - 00001065 _____ () C:\Users\Public\Desktop\7-PDF Maker.lnk
2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\7-PDFMaker
2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Program Files (x86)\7-PDF
2014-03-29 21:48 - 2011-05-13 11:23 - 00000000 ___RD () C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu

\Programs\Startup
2014-03-29 21:46 - 2014-03-29 21:45 - 55633177 _____ (7-PDF, Germany ) C:\Users\andreas\Downloads\7p141.exe
2014-03-29 21:43 - 2014-03-29 21:43 - 00930952 _____ (CNET Download.com) C:\Users\andreas\Downloads\cbsidlm-cbsi183-

Free_JPG_to_PDF-ORG-75732662.exe
2014-03-29 16:35 - 2012-05-16 19:55 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718

-708133086-500Core.job
2014-03-29 16:35 - 2012-04-12 19:52 - 00001124 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-

235724718-708133086-1000Core.job
2014-03-27 23:56 - 2014-01-01 20:55 - 00001026 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-03-27 23:55 - 2011-05-23 21:57 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\vlc
2014-03-27 23:37 - 2011-10-09 22:18 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Skype
2014-03-27 23:21 - 2014-03-27 23:21 - 00000000 ____D () C:\Users\andreas\AppData\Local\Skype
2014-03-27 23:21 - 2011-05-13 11:21 - 00000000 ____D () C:\ProgramData\Skype
2014-03-27 23:20 - 2014-03-27 23:20 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-27 22:54 - 2014-03-27 22:54 - 00476024 _____ (1&1 Mail & Media GmbH) C:\Users\andreas\Downloads

\WEB.DE_MailCheck_chrome_setup (2).exe
2014-03-26 22:18 - 2011-06-14 19:06 - 00000000 ____D () C:\Users\andreas\Videos\Documents\Youcam
2014-03-21 15:59 - 2011-09-15 02:51 - 00147456 _____ (Bullzip) C:\Windows\SysWOW64\bzpdfc.dll
2014-03-19 20:38 - 2013-08-15 10:24 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-19 20:36 - 2011-05-13 16:38 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-19 19:13 - 2009-07-14 06:45 - 00459824 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-19 19:11 - 2013-03-13 10:05 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-19 19:11 - 2013-03-13 10:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-15 10:36 - 2011-09-14 21:22 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-15 10:08 - 2012-05-08 00:40 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-15 10:08 - 2012-05-08 00:40 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-15 10:08 - 2011-08-22 23:30 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-11 22:07 - 2014-03-11 22:07 - 04550656 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr
2014-03-10 22:52 - 2011-11-07 09:32 - 01603492 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-03-05 09:26 - 2014-03-30 15:46 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers

\mbamchameleon.sys
2014-03-05 09:26 - 2014-03-30 15:46 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-05 09:26 - 2014-03-30 15:46 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-01 14:26 - 2014-03-01 14:26 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iTunes
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iPod
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-03-01 14:16 - 2014-03-01 14:00 - 00000000 ____D () C:\ff602098354a13baca66adf688cd6c8a
2014-03-01 13:58 - 2014-03-01 13:58 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-03-01 08:05 - 2014-03-15 09:17 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-01 07:17 - 2014-03-15 09:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-01 07:16 - 2014-03-15 09:17 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-01 06:58 - 2014-03-15 09:17 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-01 06:52 - 2014-03-15 09:17 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-01 06:51 - 2014-03-15 09:17 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-01 06:42 - 2014-03-15 09:17 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-01 06:40 - 2014-03-15 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-01 06:37 - 2014-03-15 09:17 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-01 06:33 - 2014-03-15 09:17 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-01 06:33 - 2014-03-15 09:17 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-01 06:32 - 2014-03-15 09:17 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-01 06:30 - 2014-03-15 09:17 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-01 06:23 - 2014-03-15 09:17 - 00940032 _____ (Microsoft Corporation) C:\Windows

\system32\MsSpellCheckingFacility.exe
2014-03-01 06:17 - 2014-03-15 09:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-01 06:11 - 2014-03-15 09:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-01 06:02 - 2014-03-15 09:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-01 05:54 - 2014-03-15 09:17 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-01 05:52 - 2014-03-15 09:17 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-01 05:51 - 2014-03-15 09:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-01 05:47 - 2014-03-15 09:17 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-01 05:43 - 2014-03-15 09:17 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-01 05:43 - 2014-03-15 09:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-01 05:42 - 2014-03-15 09:17 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-01 05:40 - 2014-03-15 09:17 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-01 05:38 - 2014-03-15 09:17 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-01 05:37 - 2014-03-15 09:17 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-01 05:35 - 2014-03-15 09:17 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-01 05:18 - 2014-03-15 09:17 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-01 05:16 - 2014-03-15 09:17 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-01 05:14 - 2014-03-15 09:17 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-01 05:10 - 2014-03-15 09:17 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-01 05:03 - 2014-03-15 09:17 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-01 05:00 - 2014-03-15 09:17 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-01 04:57 - 2014-03-15 09:17 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-01 04:38 - 2014-03-15 09:17 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-01 04:32 - 2014-03-15 09:17 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-01 04:27 - 2014-03-15 09:17 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-01 04:25 - 2014-03-15 09:17 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-01 04:25 - 2014-03-15 09:17 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll

Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\avgnt.exe
C:\Users\Administrator\AppData\Local\Temp\DivXSetup.exe
C:\Users\Administrator\AppData\Local\Temp\MSN9A3E.exe
C:\Users\andreas\AppData\Local\Temp\avgnt.exe
C:\Users\andreas\AppData\Local\Temp\ose00000.exe
C:\Users\andreas\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-20 19:35

==================== End Of Log ============================
         
--- --- ---
__________________

Alt 30.03.2014, 22:20   #4
randyandy66
 
Trojaner SupTab u.a. - Standard

Trojaner SupTab u.a.



Und hier ist der Text 2:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014
Ran by andreas at 2014-03-30 17:08:12
Running from C:\Users\andreas\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Disabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

==================== Installed Programs ======================

„Messenger“ pagalbinė priemonė (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
„Windows Live Essentials“ (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
„Windows Live Mail“ (x32 Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden
„Windows Live Mesh ActiveX“ nuotolinių ryšių valdiklis (HKLM-x32\...\{9024FE65-46B8-4C8A-9D98-8DCB6BD5F598}) (Version:

15.4.5722.2 - Microsoft Corporation)
„Windows Live Messenger“ (x32 Version: 15.4.3538.0513 - „Microsoft Corporation“) Hidden
„Windows Live“ fotogalerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
7-PDF Maker Version 1.4.1 (Build 128) (HKLM-x32\...\7-PDF Maker_is1) (Version: 7-PDF Maker - Version 1.4.1 (Build 128) - 7

-PDF, Germany - Thorsten Hodes)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version: - )
ActiveX контрола на Windows Live Mesh за отдалечени връзки (HKLM-x32\...\{B3BA4D1C-23EF-4859-9C11-1B2CCB7FADBB}) (Version:

15.4.5722.2 - Microsoft Corporation)
ActiveX-kontroll för fjärranslutningar för Windows Live Mesh (HKLM-x32\...\{376D59B1-42D9-4FA2-B6CC-E346B6BE14F5})

(Version: 15.4.5722.2 - Microsoft Corporation)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.3.0.3670 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.3.0.3670 - Adobe Systems Incorporated) Hidden
Adobe Connect Add-in (HKCU\...\Adobe Connect Add-in) (Version: - )
Adobe Digital Editions (HKLM-x32\...\Digital Editions) (Version: - )
Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems

Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.3.633 - Adobe Systems, Inc.)
AIM for Windows (HKCU\...\AIM) (Version: - AOL Inc.)
Amazon Kindle (HKCU\...\Amazon Kindle) (Version: - Amazon)
Amazon MP3-Downloader 1.0.9 (HKLM-x32\...\Amazon MP3-Downloader) (Version: - )
Android Sync Manager WiFi (HKLM-x32\...\{13D946AF-DAD9-0200-0000-000000000000}) (Version: 11.10.2763 - Mobile Action)
Android-Sync v0.369 (HKLM-x32\...\{B148E192-F289-4297-85BF-70E2A422EB25}_is1) (Version: - Android-Sync.com)
Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ashampoo WinOptimizer 2010 Advanced (HKLM-x32\...\Ashampoo WinOptimizer 2010 Advanced_is1) (Version: 6.5.0 - Ashampoo GmbH

& Co. KG)
Ask Shopping Toolbar (HKLM-x32\...\{4D594333-2D53-4154-00A7-A758B70C0202}) (Version: 12.2.2.652 - Ask Partner Network)

<==== ATTENTION
Ask Toolbar (HKLM-x32\...\{4D594333-0076-A76A-76A7-A758B70C0300}) (Version: 12.3.0.959 - APN, LLC) <==== ATTENTION
Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros)
Audacity 2.0.3 (HKLM-x32\...\Audacity_is1) (Version: 2.0.3 - Audacity Team)
Auslogics Disk Defrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: version 3.3 - Auslogics Software

Pty Ltd)
Avidemux 2.5 (32-bit) (HKLM-x32\...\Avidemux 2.5) (Version: 2.5.4.7200 - )
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira)
BatteryLifeExtender (HKLM-x32\...\{EA257ECF-5F72-4461-B890-959394DCD087}) (Version: 1.0.10 - Samsung)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 5.60.48.55 - Broadcom Corporation)
Bullzip PDF Printer 10.4.0.2240 (HKLM\...\Bullzip PDF Printer_is1) (Version: 10.4.0.2240 - Bullzip)
Camfrog Video Chat 6.5 (HKLM-x32\...\Camfrog 6.5) (Version: 6.5.300 - Camshare, Inc.)
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - )
Canon MG5100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5100_series) (Version: - )
Canon MP Navigator 1.0 (HKLM-x32\...\MP Navigator 1.0) (Version: - )
Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - )
CleanMem (HKLM-x32\...\CleanMem) (Version: v2.2.0 - PcWinTech.com)
Complément Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Complemento Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544})

(Version: 15.4.5722.2 - Microsoft Corporation)
Control ActiveX Windows Live Mesh pentru conexiuni la distanță (HKLM-x32\...\{260E3D78-94E6-47EC-8E29-46301572BB1E})

(Version: 15.4.5722.2 - Microsoft Corporation)
Controle ActiveX do Windows Live Mesh para Conexões Remotas (HKLM-x32\...\{39B3184E-0BFB-40FA-ADDC-E7E2D535CDA9}) (Version:

15.4.5722.2 - Microsoft Corporation)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3})

(Version: 15.4.5722.2 - Microsoft Corporation)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version:

15.4.5722.2 - Microsoft Corporation)
Copernic Desktop Search 4 (HKLM-x32\...\CopernicDesktopSearch4) (Version: 4.0.5.1231 - Copernic)
Copernic Desktop Search 4 (x32 Version: 4.0.5.1231 - Copernic) Hidden
Creative Centrale (HKLM-x32\...\Creative Centrale) (Version: 1.19.02 - Creative Technology Ltd.)
Creative Centrale (x32 Version: 1.19.02 - Creative Technology Ltd.) Hidden
Creative Software Update (x32 Version: 1.03.01 - Creative Technology Ltd.) Hidden
Creative ZEN X-Fi2 Dokumentation (HKLM-x32\...\ZENXFI2UG) (Version: - Creative Technology Ltd.)
CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2227 - CyberLink

Corp.)
CyberLink Media Suite (x32 Version: 8.0.2227 - CyberLink Corp.) Hidden
CyberLink Media+ Player10 (HKLM-x32\...\InstallShield_{34FBC7C4-CD31-4D93-A428-0E524EAC4586}) (Version: 10.0.1110.00 -

CyberLink Corp.)
CyberLink Media+ Player10 (x32 Version: 10.0.1110.00 - CyberLink Corp.) Hidden
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3802 - CyberLink

Corp.)
CyberLink Power2Go (x32 Version: 6.1.3802 - CyberLink Corp.) Hidden
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3509 - CyberLink Corp.)
CyberLink YouCam (x32 Version: 3.1.3509 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{92C42EDD-6524-4577-B2EB-6C68C63B6D4A}) (Version: - Microsoft)
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.41 - DivX, LLC)
Doplnok programu Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Dropbox (HKCU\...\Dropbox) (Version: 2.4.11 - Dropbox, Inc.)
Easy Content Share (HKLM-x32\...\{2DDC70C1-C77A-4D08-89D2-9AB648504533}) (Version: 1.0 - Samsung Electronics Co., LTD)
Easy Display Manager (HKLM-x32\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 3.2 - Samsung Electronics Co., Ltd.)
Easy Migration (HKLM-x32\...\{AD86049C-3D9C-43E1-BE73-643F57D83D50}) (Version: 1.0.0.5 - Samsung Electronics Co., Ltd.)
Easy Network Manager (HKLM-x32\...\{FCF2085E-ABE5-4AA8-B07C-65BBD56DA243}) (Version: 4.4.6 - Samsung)
Easy SpeedUp Manager (HKLM-x32\...\{EF367AA4-070B-493C-9575-85BE59D789C9}) (Version: 2.1.1.1 - Samsung Electronics

Co.,Ltd.)
EasyBatteryManager (HKLM-x32\...\{4A331D24-A9E8-484F-835E-1BA7B139689C}) (Version: 4.0.0.4 - Samsung)
EasyFileShare (HKLM-x32\...\{EA76E65F-6679-495A-A8A6-42AD6602ED4C}) (Version: 1.0.11 - Samsung)
ETDWare PS/2-X64 10.7.14.12_WHQL (HKLM\...\Elantech) (Version: 10.7.14.12 - ELAN Microelectronic Corp.)
Extended Asian Language font pack for Adobe Reader XI (HKLM-x32\...\{AC76BA86-7AD7-2530-0000-A00000000004}) (Version:

11.0.0 - Adobe Systems Incorporated)
Facebook Messenger 2.1.4814.0 (HKLM-x32\...\{7204BDEE-1A48-4D95-A964-44A9250B439E}) (Version: 2.1.4814.0 - Facebook)
Fast Start (HKLM-x32\...\{77F45ECD-FAFC-45A8-8896-CFFB139DAAA3}) (Version: 2.2.0.0 - SAMSUNG)
FastConnect 1.2.2 (HKLM-x32\...\FastConnect) (Version: 1.2.2 - The Cloud Networks)
FeedReader (HKLM-x32\...\FeedReader_is1) (Version: - i-Systems Inc.)
FirstClass® Client (HKLM-x32\...\{2869279D-7AE2-4A13-96B8-46078BA3F75B}) (Version: 11.0 (build 11.033) - Open Text

Corporation.)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (HKLM-x32\...\{B04A0E2F-1E4C-4E61-

B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Free Download Manager 3.0 (HKLM-x32\...\Free Download Manager_is1) (Version: - FreeDownloadManager.ORG)
Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com)
FreeMind (HKLM-x32\...\B991B020-2968-11D8-AF23-444553540000_is1) (Version: 0.9.0 - )
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Gizmo Central (HKLM-x32\...\Gizmo Central) (Version: v2.7.9 - Arainia Solutions, LLC)
Glary Utilities 2.42.0.1389 (HKLM-x32\...\Glary Utilities_is1) (Version: 2.42.0.1389 - Glarysoft Ltd)
Google Chrome (HKCU\...\Google Chrome) (Version: 33.0.1750.154 - Google Inc.)
Google Drive (HKLM-x32\...\{E87022D3-C8C9-4C76-8E27-BC7F18F9B8FB}) (Version: 1.14.6059.644 - Google, Inc.)
Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden
Hoffnung für heute (HKLM-x32\...\{9447C5C8-6A1B-412F-B9A6-99AFE7C09773}) (Version: 3.2.1 - )
iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
ICQ7.5 (HKLM-x32\...\{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}) (Version: 7.5 - ICQ)
IHMC CmapTools v5.05.01 (HKLM-x32\...\IHMC CmapTools v5.05.01) (Version: 5.0.5.1 - Institute for Human & Machine Cognition)
iMODELER - Consideo GmbH (HKLM-x32\...\iMODELER) (Version: - )
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel

Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.3.1001 - Intel

Corporation)
Intel(R) Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.02.00.1002 -

Intel Corporation)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.28 - Irfan Skiljan)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
iWisoft Free Video Converter 1.2 (HKLM-x32\...\iWisoft Free Video Converter_is1) (Version: 1.2 - www.easy-video-

converter.com)
IZArc 4.1.6 (HKLM-x32\...\{97C82B44-D408-4F14-9252-47FC1636D23E}_is1) (Version: 4.1.6 - Ivan Zahariev)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 37 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216037FF}) (Version: 6.0.370 - Oracle)
JLC's Internet TV (HKLM-x32\...\JLC's Internet TV) (Version: - )
Jpg2Pdf version 1.2 (HKLM-x32\...\{533D415A-4151-4AC5-858E-4068524C8051}_is1) (Version: 1.2 - Office Necessities inc.)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
KaraFun Player (HKLM-x32\...\KaraFun Player_is1) (Version: 1.20.86.771 - Recisio)
K-Lite Codec Pack 6.0.4 (Basic) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 6.0.4 - )
Kontrola Windows Live Mesh ActiveX za daljinske veze (HKLM-x32\...\{19CBDE24-2761-49A5-816B-D2BA65D0CA8D}) (Version:

15.4.5722.2 - Microsoft Corporation)
Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (HKLM-x32\...\{CA227A9D-09BE-4BFB-9764-48FED2DA5454}) (Version:

15.4.5722.2 - Microsoft Corporation)
LinkedIn Outlook Connector (HKLM-x32\...\LinkedIn Outlook Connector) (Version: 1.1.10.0 - LinkedIn)
MagicDisc 2.7.106 (HKLM-x32\...\MagicDisc 2.7.106) (Version: - )
Malwarebytes Anti-Malware Version 2.00.0.1000 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.00.0.1000 -

Malwarebytes Corporation)
ManyCam 3.1.59 (HKLM-x32\...\ManyCam) (Version: 3.1.59 - ManyCam LLC)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Assistent (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger kísérő (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger Pratilac (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger Suradnik (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger 사이트 공유 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger 分享元件 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger 浏览器插件 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger-kumppani (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 -

Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft

Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Outlook Social Connector Provider for Facebook 32-bit (HKLM-x32\...\{95140000-007C-0409-0000-0000000FF1CE})

(Version: 14.0.6114.5003 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (HKLM-x32\...\{95140000-007D-0409-0000-

0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 -

Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118})

(Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM-x32\...\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version:

8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 -

Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version:

9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version:

9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version:

9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475})

(Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989})

(Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F})

(Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version:

10.0.40219 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft_VC90_CRT_x86 (HKLM-x32\...\{DF2035BE-5820-4965-BD97-7FAF8D4A7879}) (Version: 1.0.0 - Microsoft Corporation)
Mindjet MindManager Pro 6 (HKLM-x32\...\{9FC3EA3B-A6FB-436E-8A69-8595548CACBF}) (Version: 6.2.399 - Mindjet LLC)
MiniTool Partition Wizard Home Edition 7.1 (HKLM-x32\...\{34A153FE-6926-4C14-B48A-B71E68C672A8}_is1) (Version: - MiniTool

Solution Ltd.)
Mobipocket Reader 6.2 (HKLM-x32\...\{342126E1-173C-4585-BFBE-3EBDD20E3E9E}) (Version: 6.2.608 - Mobipocket.com)
Movie Color Enhancer (HKLM-x32\...\{7F6F62F0-7884-4CFB-B86C-597A4A6D9C4D}) (Version: 1.0 - Samsung Electronics Co., Ltd.)
Mozilla Firefox 14.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 14.0.1 (x86 de)) (Version: 14.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 14.0.1 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft

Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft

Corporation)
MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.2 - F.J. Wechselberger)
NAVIGON Fresh 3.4.1 (HKLM-x32\...\NAVIGON Fresh) (Version: 3.4.1 - NAVIGON)
Netzmanager (HKLM-x32\...\Netzmanager) (Version: 1.071 - Deutsche Telekom AG)
Netzmanager (Version: 1.071 - Deutsche Telekom AG, Marmiko IT-Solutions GmbH) Hidden
Nur Entfernen der CopyTrans Suite möglich (HKCU\...\CopyTrans Suite) (Version: 2.33 - WindSolutions)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation)
NVIDIA Grafiktreiber 267.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 267.54 - NVIDIA

Corporation)
NVIDIA Install Application (Version: 2.265.39.0 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 267.54 (Version: 267.54 - NVIDIA Corporation) Hidden
Octoshape Streaming Services (HKCU\...\Octoshape Streaming Services) (Version: - Octoshape ApS)
OpenOffice 4.0.0 (HKLM-x32\...\{B28DBCBA-60F8-40ED-B35B-F510C327946C}) (Version: 4.00.9702 - Apache Software Foundation)
Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (HKLM-x32\...\{B6190387-0036-4BEB-8D74-

A0AFC5F14706}) (Version: 15.4.5722.2 - Microsoft Corporation)
Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (HKLM-x32\...\{C2FD7DB5-FE30-49B6-8A2F-

C5652E053C31}) (Version: 15.4.5722.2 - Microsoft Corporation)
PDF24 Creator 5.3.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
PDFill PDF Editor with FREE Writer and FREE Tools (HKLM\...\{D1399216-81B2-457C-A0F7-73B9A2EF6902}) (Version: 9.0 -

PlotSoft LLC)
PDF-XChange 3 (HKLM-x32\...\PDF-XChange 3_is1) (Version: - Tracker Software)
PhoneShare (HKLM-x32\...\{E31F454E-4813-4C88-B0D3-4BB174993770}) (Version: 1.0.4 - Samsung)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pomocnik Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Python 2.7.2 (HKLM-x32\...\{2E295B5B-1AD4-4d36-97C2-A316084722CF}) (Version: 2.7.2150 - Python Software Foundation)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.33.1125.2010 -

Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6257 - Realtek

Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samsung AnyWeb Print (HKLM-x32\...\{318DBE01-1E6B-4243-84B0-210391FE789A}) (Version: 1.1.21.0 - Samsung Electronics Co.,

Ltd.)
Samsung AnyWeb Print (x32 Version: 1.0 - Samsung Electronics Co., Ltd.) Hidden
Samsung Recovery Solution 5 (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.0.8 - Samsung)
Samsung Support Center 1.0 (HKLM-x32\...\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.38 - Samsung)
Samsung Universal Print Driver (HKLM-x32\...\Samsung Universal Print Driver) (Version: 2.01.06.00:16 - Samsung Electronics

Co., Ltd.)
Samsung Universal Scan Driver (HKLM-x32\...\Samsung Universal Scan Driver) (Version: 1.2.1.0 - Samsung Electronics Co.,

Ltd.)
Samsung Update Plus (HKLM-x32\...\{142D8CA7-2C6F-45A7-83E3-099AAFD99133}) (Version: 3.0.1.17 - Samsung Electronics Co.,

Ltd.)
Screencast-O-Matic (HKCU\...\Screencast-O-Matic) (Version: - Screencast-O-Matic)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden
Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
Spotify (HKCU\...\Spotify) (Version: 0.9.7.16.g4b197456 - Spotify AB)
Spremljevalec Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking

Ltd.)
SRS Premium Sound Control Panel (HKLM\...\{2998191E-A35E-47E2-BE38-7702C731D722}) (Version: 1.10.1000 - SRS Labs, Inc.)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1108 - SUPERAntiSpyware.com)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
System Explorer 3.9.1 (HKLM-x32\...\System Explorer_is1) (Version: - Mister Group)
System Explorer 3.9.4 (HKLM-x32\...\{40F485F7-6478-4896-B0D5-F94BE677EB78}_is1) (Version: - Mister Group)
Tango (HKCU\...\Tango) (Version: 1.6.14117 - TangoMe, Inc.)
Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 (HKLM\...\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version:

2.0.82.0 - Intel)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}

_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_

{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}

_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}

_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}

_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}

_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}

_Office14.SingleImage_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}

_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}

_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}

_Office14.SingleImage_{81812245-FC84-426A-BC02-6659C88CC7B2}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2775360) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{80F56E3F-1D47-4E45-B6E0-FEF4E919F4F9}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-

0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft)
Update for Microsoft Visio 2010 (KB2878227) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{5D357893-40BA-4323-86BA-D97C66CD72F4}) (Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft)
Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{E78E2B68-8FD1-42EE-BB74-99A4D9E6222D}) (Version: - Microsoft)
UseNeXT by Tangysoft (HKLM-x32\...\UseNeXT by Tangysoft_is1) (Version: - Tangysoft Ltd.)
User Guide (HKLM-x32\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.0 - )
Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (HKLM-x32\...\{241E7104-937A-4366-AD57-8FDDDB003939}) (Version:

15.4.5722.2 - Microsoft Corporation)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.7000 - Broadcom Corporation)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live fotoattēlu galerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogaléria (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Foto-galerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Galeria de Fotos (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Galerija fotografija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-

0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX kontrola za daljinske veze (HKLM-x32\...\{8985AE5E-622A-4980-8BF8-0A1830643220}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX vadīkla attālajiem savienojumiem (HKLM-x32\...\{A3A775C9-5A63-4C55-8FDD-427A5B8F5D2B}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (HKLM-x32\...\{09B7C7EB-3140-4B5E-842F-9C79A7137139})

(Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX-objekt til fjernforbindelser (HKLM-x32\...\{57220148-3B2B-412A-A2E0-82B9DF423696}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (HKLM-x32\...\{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Meshin etäyhteyksien ActiveX-komponentti (HKLM-x32\...\{4CF6F287-5121-483C-A5A2-07BDE19D8B4E}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Pošta (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 메일 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 사진 갤러리 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 필수 패키지 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 照片库 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 软件包 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft

Corp)
Windows Mobile Device Updater Component (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation)
Windows-Treiberpaket - Android-Sync.com (WinUSB) AndroidUsbDeviceClass (10/21/2011 4.0.0000.11021) (HKLM\...

\6D51958587F750FB22B14F3587024652DE17F288) (Version: 10/21/2011 4.0.0000.11021 - Android-Sync.com)
WinPatrol (HKLM\...\{007811BF-E310-4285-BFC6-55DB29B3EDDE}) (Version: 24.1.2012 - BillP Studios)
WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
XING Outlook Connector (HKLM\...\{3B8AF990-AE63-481C-BC4B-8BB8D7A93B80}) (Version: 2.2.0 - XING)
xplorer² lite 32 bit (HKLM-x32\...\xplorer2l) (Version: 2.3.0.1 - Zabkat)
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.)
Yahoo! Software Update (HKLM-x32\...\Yahoo! Software Update) (Version: - )
Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version: - )
YouTube Song Downloader (HKLM-x32\...\{4281435C-AD1D-4C8A-B9C0-3961C11EF142}_is1) (Version: 8.2 - Abelssoft)
Zotero Standalone 3.0.14 (x86 en-US) (HKLM-x32\...\Zotero Standalone 3.0.14 (x86 en-US)) (Version: 3.0.14 - Zotero)
Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation)
Zune (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHT) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CSY) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DAN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DEU) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ELL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ESP) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FIN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FRA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (HUN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (IND) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ITA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (JPN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (KOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (MSL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NLD) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PLK) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTB) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTG) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (RUS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (SVE) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47-

FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Компаньон Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Помощник на Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2-

8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation)
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
מסייע Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (HKLM-x32\...\{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}) (Version: 15.4.5722.2 -

Microsoft Corporation)
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\...\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 -

Microsoft Corporation)
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
ตัวควบคุม ActiveX ใน Windows Live Mesh สำหรับการเชื่อมต่อระยะไกล (ไทย) (HKLM-x32\...\{A2EDAEEB-C981-46D5-8163-CF8F5F640EEE}) (Version: 15.4.5722.2

- Microsoft Corporation)
원격 연결을 위한 Windows Live Mesh ActiveX 컨트롤 (HKLM-x32\...\{61920449-0393-4707-B7DD-E6C0013C8B2C}) (Version: 15.4.5722.2 -

Microsoft Corporation)
用于远程连接的 Windows Live Mesh ActiveX 控件(简体中文) (HKLM-x32\...\{F992409C-9D10-4AE2-BAEB-B5409AD3785E}) (Version: 15.4.5722.2 -

Microsoft Corporation)
適用遠端連線的 Windows Live Mesh ActiveX 控制項 (HKLM-x32\...\{622DE1BE-9EDE-49D3-B349-29D64760342A}) (Version: 15.4.5722.2 -

Microsoft Corporation)

==================== Restore Points =========================

26-03-2014 18:24:35 Windows Update
29-03-2014 20:05:06 Uniblue SpeedUpMyPC installation
29-03-2014 22:41:47 S
30-03-2014 13:49:58 Revo Uninstaller's restore point - Ask Shopping Toolbar
30-03-2014 14:43:56 Revo Uninstaller's restore point - ooVoo
30-03-2014 14:44:50 Removed ooVoo

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {0666A132-9CBC-4EE0-885F-AB0465900A46} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung

\EasySpeedUpManager\EasySpeedUpManager2.exe [2010-12-01] (Samsung Electronics)
Task: {07409B9B-7821-4253-91E7-116AFCF83E69} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display

Manager\dmhkcore.exe [2010-11-28] (Samsung Electronics Co., Ltd.)
Task: {1318A8AD-A403-404D-ADFA-59FA3D8956FD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google

\Update\GoogleUpdate.exe [2011-05-21] (Google Inc.)
Task: {1623FBDB-E473-4D9E-9F23-7A929E229916} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for

updates => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdate.exe
Task: {185C37D1-20B4-4A1F-995A-0B3AE22033D1} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery

Solution 5\WCScheduler.exe [2010-11-17] (SEC)
Task: {24FF686B-BFF6-4A3C-9C78-0E00F254409B} - System32\Tasks\xingoscupdate => C:\Program Files\XING\XING Outlook

Connector\xingoscupdate.exe [2014-01-08] (XING)
Task: {256E2E78-825E-4930-B00E-E86DC6762ED9} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung

\Samsung Support Center\SSCKbdHk.exe [2011-09-04] (SAMSUNG Electronics)
Task: {299D73B6-AE07-4510-BDF3-53538E412FED} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple

Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {29C2FC45-A051-4254-A333-AC168384DC37} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung

\EasyBatteryManager\EasyBatteryMgr4.exe [2010-07-20] (SAMSUNG Electronics co., LTD.)
Task: {38B2690F-5140-4B97-8006-5B6105746F2F} - System32\Tasks\WifiManager => C:\Program Files (x86)\Samsung\Easy Display

Manager\WifiManager.exe [2010-11-28] (Samsung Electronics Co., Ltd.)
Task: {3927588F-2B07-4A40-A858-43BC63300A91} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh

immunization => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDImmunize.exe
Task: {420C63BC-0E55-4D7D-9746-3E5B9FF83E5D} - System32\Tasks\SRS Premium Sound => C:\Program Files\SRS Labs\SRS Premium

Sound Control Panel\srspremiumpanel_64.exe [2010-11-29] (SRS Labs, Inc.)
Task: {47656083-02C7-4E54-808F-7263466606B5} - System32\Tasks\Xing Social Recommendations => C:\Program Files\XING\XING

Outlook Connector\32-bit\XingSocial.exe [2014-01-08] (XING AG)
Task: {56E8FB28-DB36-48DC-8D7A-379AA0CF63F1} - System32\Tasks\{EB5A17F7-59B1-4914-80F9-8981CBF7FF0B} => C:\Program Files

(x86)\Gizmo\gizmo.exe [2011-09-14] (Arainia Solutions)
Task: {773AE63E-EACB-4047-8A3F-2E395CF9E670} - System32\Tasks\SUPBackground => C:\Program Files (x86)\Samsung\Samsung

Update Plus\SUPBackground.exe [2011-12-20] (Samsung Electronics)
Task: {7821C008-BFDF-45B6-B2A7-12BC3E0ACD8D} - System32\Tasks\CleanMem Mini Monitor => C:\Program Files (x86)\CleanMem

\mini_monitor.exe [2011-07-09] (PcWinTech.com)
Task: {8014A37B-FB9B-451C-A2B4-1BF82CC7DA59} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed

\Flash\FlashPlayerUpdateService.exe [2014-03-15] (Adobe Systems Incorporated)
Task: {83C4A256-9C9E-48ED-8770-83C3BFDE7ACF} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-

500UA => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-16] (Google Inc.)
Task: {8D8D58A3-BC0D-4C52-83BA-7F40EA4E7386} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google

\Update\GoogleUpdate.exe [2011-05-21] (Google Inc.)
Task: {97533C0E-FAF4-42D9-8670-CF1F351EFB00} - System32\Tasks\Auslogics\Disk Defrag\Start On andreas Logon => C:\Program

Files (x86)\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe [2011-11-14] (Auslogics)
Task: {9B159597-B87B-4B9E-A7F4-ECC53F52F214} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-

708133086-1000Core => C:\Users\andreas\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {A9405DF1-8498-42EB-9911-E2B1CBC0572C} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-

708133086-1000UA => C:\Users\andreas\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {AA11DF3E-CFAF-4851-AB5C-20C5BC31E5AE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-

500Core => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-16] (Google Inc.)
Task: {BFC3AF24-E903-4FA6-A78C-E1B0C2600A77} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system

=> C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDScan.exe
Task: {C5E417A0-E558-4656-8B2A-3B90AC109C24} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung

\BatteryLifeExtender\BatteryLifeExtender.exe [2010-12-01] (Samsung Electronics. Co. Ltd.)
Task: {CABA96D1-D5A0-43F3-9384-32474FD032E2} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Movie

Color Enhancer\MovieColorEnhancer.exe [2010-08-19] (Samsung Electronics Co., Ltd.)
Task: {CDD96E60-7A5E-426C-9FB3-4CF76D015A57} - System32\Tasks\SmartRestarter => C:\Program Files\Samsung\SamsungFastStart

\SmartRestarter.exe [2010-08-05] (Samsung Electronics Co., Ltd.)
Task: {CDE3AF8E-A54A-4CB4-B998-C76152EEE3F2} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam

\YCMMirage.exe [2010-11-10] (CyberLink)
Task: {D10419DA-B0D7-4A0D-98CB-AAFF7C8D73EA} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-

1000UA => C:\Users\andreas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-13] (Google Inc.)
Task: {D185EA38-12BC-44E7-9A58-DD32DED0AA3E} - System32\Tasks\Clean System Memory => C:\Windows\syswow64\CleanMem.exe

[2011-07-09] (PcWinTech.com)
Task: {E1C99093-2BA9-4FF4-AE92-92237CB501CF} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-

1000Core => C:\Users\andreas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-13] (Google Inc.)
Task: {FEB14CB6-EA1B-4FC4-B812-0C7DA408E53C} - System32\Tasks\GlaryInitialize => C:\Program Files (x86)\Glary Utilities

\initialize.exe [2012-02-03] (Glarysoft Ltd)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000Core.job => C:\Users\andreas

\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000UA.job => C:\Users\andreas

\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GlaryInitialize.job => C:\Program Files (x86)\Glary Utilities\initialize.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000Core.job => C:\Users\andreas

\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000UA.job => C:\Users\andreas\AppData

\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-500Core.job => C:\Users\Administrator

\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-500UA.job => C:\Users\Administrator

\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-05-13 11:20 - 2008-06-05 01:53 - 00027648 _____ () C:\Windows\System32\spd__l.dll
2010-10-19 09:31 - 2010-10-19 09:31 - 00205312 _____ () C:\Program Files\Netzmanager\NMInfraIS2\driver64\SoftplugLib.DLL
2011-05-13 11:20 - 2010-04-21 01:44 - 00719872 _____ () C:\Windows\system32\SnMinDrv.dll
2012-11-01 17:46 - 2012-09-19 19:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application

Support\zlib1.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application

Support\libxml2.dll
2012-02-02 03:41 - 2011-11-14 16:09 - 00348376 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag

\madExcept_.bpl
2012-02-02 03:41 - 2011-11-14 16:09 - 00182488 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag

\madBasic_.bpl
2012-02-02 03:41 - 2011-11-14 16:09 - 00048856 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag

\madDisAsm_.bpl
2012-02-02 03:41 - 2011-11-14 16:09 - 00254680 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag

\AusShellExt.dll
2010-12-17 06:51 - 2010-07-05 12:42 - 00203776 _____ () C:\Program Files (x86)\Samsung\Movie Color Enhancer\WinCRT.dll
2014-03-19 20:10 - 2014-03-15 02:50 - 00051016 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application

\33.0.1750.154\chrome_elf.dll
2013-09-14 01:51 - 2013-09-14 01:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services

\zlib1.dll
2013-09-14 01:50 - 2013-09-14 01:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services

\libxml2.dll
2014-02-25 18:52 - 2014-02-25 18:52 - 01563200 _____ () C:\Program Files (x86)\Copernic

\DesktopSearch4\Copernic.System.RT.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared

\office14\Cultures\office.odf
2011-09-14 23:44 - 2011-09-14 23:44 - 00166816 _____ () C:\Program Files (x86)\Gizmo\GImage.DLL
2011-09-14 23:44 - 2011-09-14 23:44 - 00315800 _____ () C:\Program Files (x86)\Gizmo\gmanager.DLL
2011-09-14 23:44 - 2011-09-14 23:44 - 00404384 _____ () C:\Program Files (x86)\Gizmo\gdatabase.dll
2011-09-14 23:44 - 2011-09-14 23:44 - 00394656 _____ () C:\Program Files (x86)\Gizmo\gdrive.dll
2011-09-14 23:44 - 2011-09-14 23:44 - 00339864 _____ () C:\Program Files (x86)\Gizmo\geditor.dll
2011-09-14 23:44 - 2011-09-14 23:44 - 00372632 _____ () C:\Program Files (x86)\Gizmo\ghash.dll
2011-09-14 23:44 - 2011-09-14 23:44 - 00339864 _____ () C:\Program Files (x86)\Gizmo\gscript.dll
2012-02-06 01:20 - 2011-04-15 03:01 - 00548854 ____N () C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll
2005-03-16 15:34 - 2005-03-16 15:34 - 00110592 ____R () C:\Program Files (x86)\Mindjet\MindManager 6\zlib.dll
2013-10-19 01:55 - 2013-10-19 01:55 - 25100288 _____ () C:\Users\andreas\AppData\Roaming\Dropbox\bin\libcef.dll
2010-12-17 06:49 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll
2014-03-29 22:09 - 2013-05-16 11:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy

2\snlThirdParty150.bpl
2014-03-29 22:09 - 2013-05-16 11:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2014-03-30 16:58 - 2014-03-30 16:58 - 00098816 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32api.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00110080 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pywintypes27.dll
2014-03-30 16:57 - 2014-03-30 16:57 - 00364544 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pythoncom27.dll
2014-03-30 16:58 - 2014-03-30 16:58 - 00044032 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_socket.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 01157120 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_ssl.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00320512 _____ () C:\Users\andreas\AppData\Local\Temp

\_MEI29722\win32com.shell.shell.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00712192 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_hashlib.pyd
2014-03-30 16:57 - 2014-03-30 16:57 - 01175040 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._core_.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00805888 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._gdi_.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00811008 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._windows_.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 01062400 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._controls_.pyd
2014-03-30 16:57 - 2014-03-30 16:57 - 00735232 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._misc_.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00128512 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_elementtree.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00127488 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pyexpat.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00557056 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pysqlite2._sqlite.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00087040 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_ctypes.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00119808 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32file.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00108544 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32security.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00018432 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32event.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00038912 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32inet.pyd
2014-03-30 16:57 - 2014-03-30 16:57 - 00122368 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._wizard.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00070656 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._html2.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00026624 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_multiprocessing.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00010240 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\select.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00024064 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32pipe.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00686080 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\unicodedata.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00025600 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32pdh.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00525640 _____ () C:\Users\andreas\AppData\Local\Temp

\_MEI29722\windows._lib_cacheinvalidation.pyd
2014-03-30 16:57 - 2014-03-30 16:57 - 00011264 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32crypt.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00035840 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32process.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00017408 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32profile.pyd
2014-03-30 16:57 - 2014-03-30 16:57 - 00022528 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32ts.pyd
2014-03-19 20:10 - 2014-03-15 02:50 - 00716616 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application

\33.0.1750.154\libglesv2.dll
2014-03-19 20:10 - 2014-03-15 02:50 - 00100168 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application

\33.0.1750.154\libegl.dll
2014-03-19 20:10 - 2014-03-15 02:50 - 04061000 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application

\33.0.1750.154\pdf.dll
2014-03-19 20:10 - 2014-03-15 02:50 - 00394568 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application

\33.0.1750.154\ppGoogleNaClPluginChrome.dll
2014-03-19 20:10 - 2014-03-15 02:50 - 01647432 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application

\33.0.1750.154\ffmpegsumo.dll
2014-03-19 20:10 - 2014-03-15 02:50 - 13637448 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application

\33.0.1750.154\PepperFlash\pepflashplayer.dll
2014-03-29 22:09 - 2013-05-16 11:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy

2\snlFileFormats150.bpl
2009-11-02 07:20 - 2009-11-02 07:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\Temp:07BF512B

==================== Safe Mode (whitelisted) ===================


==================== Disabled items from MSCONFIG ==============


==================== Faulty Device Manager Devices =============

Name: Bluetooth Device (Personal Area Network) #2
Description: Bluetooth-Gerät (PAN)
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: BthPan
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow

the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/30/2014 05:07:17 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: netzmanager.exe, Version: 1.71.0.301, Zeitstempel: 0x500948ae
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1677
Ausnahmecode: 0xe053534f
Fehleroffset: 0x000000000000940d
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xnetzmanager.exe0
Pfad der fehlerhaften Anwendung: netzmanager.exe1
Pfad des fehlerhaften Moduls: netzmanager.exe2
Berichtskennung: netzmanager.exe3

Error: (03/30/2014 04:49:44 PM) (Source: Application Hang) (User: )
Description: Programm chrome.exe, Version 33.0.1750.154 kann nicht mehr unter Windows ausgeführt werden und wurde beendet.

Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu

suchen.

Prozess-ID: 1d14

Startzeit: 01cf4c26b8061c6a

Endzeit: 7

Anwendungspfad: C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe

Berichts-ID: 7f21641c-b81a-11e3-aa82-e811322169d9

Error: (03/30/2014 03:52:02 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome

Error: (03/30/2014 03:52:01 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome

Error: (03/30/2014 03:51:59 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome

Error: (03/30/2014 03:51:56 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome

Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome

Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome

Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome

Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome


System errors:
=============
Error: (03/30/2014 05:10:41 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.

Error: (03/30/2014 05:06:46 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80004005

Error: (03/30/2014 05:02:36 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SSDP-Suche" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (03/30/2014 05:02:36 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SSDP-Suche erreicht.

Error: (03/30/2014 05:01:56 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (03/30/2014 05:01:52 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht.

Error: (03/30/2014 04:58:57 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Updating Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (03/30/2014 04:58:57 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Updating Service erreicht.

Error: (03/30/2014 04:58:13 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (03/30/2014 04:58:13 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht.


Microsoft Office Sessions:
=========================
Error: (03/30/2014 05:07:17 PM) (Source: Application Error)(User: )
Description: netzmanager.exe1.71.0.301500948aeKERNELBASE.dll6.1.7601.1822951fb1677e053534f000000000000940d

Error: (03/30/2014 04:49:44 PM) (Source: Application Hang)(User: )
Description: chrome.exe33.0.1750.1541d1401cf4c26b8061c6a7C:\Users\andreas\AppData\Local\Google\Chrome\Application

\chrome.exe7f21641c-b81a-11e3-aa82-e811322169d9

Error: (03/30/2014 03:52:02 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/30/2014 03:52:01 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/30/2014 03:51:59 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/30/2014 03:51:56 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)


==================== Memory info ===========================

Percentage of memory in use: 56%
Total physical RAM: 3956.56 MB
Available physical RAM: 1714.84 MB
Total Pagefile: 7911.3 MB
Available Pagefile: 4460.76 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:178 GB) (Free:38.82 GB) NTFS
Drive d: () (Fixed) (Total:266.14 GB) (Free:16.1 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 466 GB) (Disk ID: 741D8EA4)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=178 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=266 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=22 GB) - (Type=27)

==================== End Of Log ============================Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014
Ran by andreas at 2014-03-30 17:08:12
Running from C:\Users\andreas\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Disabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

==================== Installed Programs ======================

„Messenger“ pagalbinė priemonė (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
„Windows Live Essentials“ (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
„Windows Live Mail“ (x32 Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden
„Windows Live Mesh ActiveX“ nuotolinių ryšių valdiklis (HKLM-x32\...\{9024FE65-46B8-4C8A-9D98-8DCB6BD5F598}) (Version:

15.4.5722.2 - Microsoft Corporation)
„Windows Live Messenger“ (x32 Version: 15.4.3538.0513 - „Microsoft Corporation“) Hidden
„Windows Live“ fotogalerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
7-PDF Maker Version 1.4.1 (Build 128) (HKLM-x32\...\7-PDF Maker_is1) (Version: 7-PDF Maker - Version 1.4.1 (Build 128) - 7

-PDF, Germany - Thorsten Hodes)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
7-Zip 9.22beta (HKLM-x32\...\7-Zip) (Version: - )
ActiveX контрола на Windows Live Mesh за отдалечени връзки (HKLM-x32\...\{B3BA4D1C-23EF-4859-9C11-1B2CCB7FADBB}) (Version:

15.4.5722.2 - Microsoft Corporation)
ActiveX-kontroll för fjärranslutningar för Windows Live Mesh (HKLM-x32\...\{376D59B1-42D9-4FA2-B6CC-E346B6BE14F5})

(Version: 15.4.5722.2 - Microsoft Corporation)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.3.0.3670 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.3.0.3670 - Adobe Systems Incorporated) Hidden
Adobe Connect Add-in (HKCU\...\Adobe Connect Add-in) (Version: - )
Adobe Digital Editions (HKLM-x32\...\Digital Editions) (Version: - )
Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems

Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.3.633 - Adobe Systems, Inc.)
AIM for Windows (HKCU\...\AIM) (Version: - AOL Inc.)
Amazon Kindle (HKCU\...\Amazon Kindle) (Version: - Amazon)
Amazon MP3-Downloader 1.0.9 (HKLM-x32\...\Amazon MP3-Downloader) (Version: - )
Android Sync Manager WiFi (HKLM-x32\...\{13D946AF-DAD9-0200-0000-000000000000}) (Version: 11.10.2763 - Mobile Action)
Android-Sync v0.369 (HKLM-x32\...\{B148E192-F289-4297-85BF-70E2A422EB25}_is1) (Version: - Android-Sync.com)
Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ashampoo WinOptimizer 2010 Advanced (HKLM-x32\...\Ashampoo WinOptimizer 2010 Advanced_is1) (Version: 6.5.0 - Ashampoo GmbH

& Co. KG)
Ask Shopping Toolbar (HKLM-x32\...\{4D594333-2D53-4154-00A7-A758B70C0202}) (Version: 12.2.2.652 - Ask Partner Network)

<==== ATTENTION
Ask Toolbar (HKLM-x32\...\{4D594333-0076-A76A-76A7-A758B70C0300}) (Version: 12.3.0.959 - APN, LLC) <==== ATTENTION
Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Atheros)
Audacity 2.0.3 (HKLM-x32\...\Audacity_is1) (Version: 2.0.3 - Audacity Team)
Auslogics Disk Defrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: version 3.3 - Auslogics Software

Pty Ltd)
Avidemux 2.5 (32-bit) (HKLM-x32\...\Avidemux 2.5) (Version: 2.5.4.7200 - )
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira)
BatteryLifeExtender (HKLM-x32\...\{EA257ECF-5F72-4461-B890-959394DCD087}) (Version: 1.0.10 - Samsung)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 5.60.48.55 - Broadcom Corporation)
Bullzip PDF Printer 10.4.0.2240 (HKLM\...\Bullzip PDF Printer_is1) (Version: 10.4.0.2240 - Bullzip)
Camfrog Video Chat 6.5 (HKLM-x32\...\Camfrog 6.5) (Version: 6.5.300 - Camshare, Inc.)
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - )
Canon MG5100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5100_series) (Version: - )
Canon MP Navigator 1.0 (HKLM-x32\...\MP Navigator 1.0) (Version: - )
Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - )
CleanMem (HKLM-x32\...\CleanMem) (Version: v2.2.0 - PcWinTech.com)
Complément Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Complemento Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544})

(Version: 15.4.5722.2 - Microsoft Corporation)
Control ActiveX Windows Live Mesh pentru conexiuni la distanță (HKLM-x32\...\{260E3D78-94E6-47EC-8E29-46301572BB1E})

(Version: 15.4.5722.2 - Microsoft Corporation)
Controle ActiveX do Windows Live Mesh para Conexões Remotas (HKLM-x32\...\{39B3184E-0BFB-40FA-ADDC-E7E2D535CDA9}) (Version:

15.4.5722.2 - Microsoft Corporation)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3})

(Version: 15.4.5722.2 - Microsoft Corporation)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version:

15.4.5722.2 - Microsoft Corporation)
Copernic Desktop Search 4 (HKLM-x32\...\CopernicDesktopSearch4) (Version: 4.0.5.1231 - Copernic)
Copernic Desktop Search 4 (x32 Version: 4.0.5.1231 - Copernic) Hidden
Creative Centrale (HKLM-x32\...\Creative Centrale) (Version: 1.19.02 - Creative Technology Ltd.)
Creative Centrale (x32 Version: 1.19.02 - Creative Technology Ltd.) Hidden
Creative Software Update (x32 Version: 1.03.01 - Creative Technology Ltd.) Hidden
Creative ZEN X-Fi2 Dokumentation (HKLM-x32\...\ZENXFI2UG) (Version: - Creative Technology Ltd.)
CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2227 - CyberLink

Corp.)
CyberLink Media Suite (x32 Version: 8.0.2227 - CyberLink Corp.) Hidden
CyberLink Media+ Player10 (HKLM-x32\...\InstallShield_{34FBC7C4-CD31-4D93-A428-0E524EAC4586}) (Version: 10.0.1110.00 -

CyberLink Corp.)
CyberLink Media+ Player10 (x32 Version: 10.0.1110.00 - CyberLink Corp.) Hidden
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 6.1.3802 - CyberLink

Corp.)
CyberLink Power2Go (x32 Version: 6.1.3802 - CyberLink Corp.) Hidden
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.3509 - CyberLink Corp.)
CyberLink YouCam (x32 Version: 3.1.3509 - CyberLink Corp.) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{92C42EDD-6524-4577-B2EB-6C68C63B6D4A}) (Version: - Microsoft)
DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.41 - DivX, LLC)
Doplnok programu Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Dropbox (HKCU\...\Dropbox) (Version: 2.4.11 - Dropbox, Inc.)
Easy Content Share (HKLM-x32\...\{2DDC70C1-C77A-4D08-89D2-9AB648504533}) (Version: 1.0 - Samsung Electronics Co., LTD)
Easy Display Manager (HKLM-x32\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 3.2 - Samsung Electronics Co., Ltd.)
Easy Migration (HKLM-x32\...\{AD86049C-3D9C-43E1-BE73-643F57D83D50}) (Version: 1.0.0.5 - Samsung Electronics Co., Ltd.)
Easy Network Manager (HKLM-x32\...\{FCF2085E-ABE5-4AA8-B07C-65BBD56DA243}) (Version: 4.4.6 - Samsung)
Easy SpeedUp Manager (HKLM-x32\...\{EF367AA4-070B-493C-9575-85BE59D789C9}) (Version: 2.1.1.1 - Samsung Electronics

Co.,Ltd.)
EasyBatteryManager (HKLM-x32\...\{4A331D24-A9E8-484F-835E-1BA7B139689C}) (Version: 4.0.0.4 - Samsung)
EasyFileShare (HKLM-x32\...\{EA76E65F-6679-495A-A8A6-42AD6602ED4C}) (Version: 1.0.11 - Samsung)
ETDWare PS/2-X64 10.7.14.12_WHQL (HKLM\...\Elantech) (Version: 10.7.14.12 - ELAN Microelectronic Corp.)
Extended Asian Language font pack for Adobe Reader XI (HKLM-x32\...\{AC76BA86-7AD7-2530-0000-A00000000004}) (Version:

11.0.0 - Adobe Systems Incorporated)
Facebook Messenger 2.1.4814.0 (HKLM-x32\...\{7204BDEE-1A48-4D95-A964-44A9250B439E}) (Version: 2.1.4814.0 - Facebook)
Fast Start (HKLM-x32\...\{77F45ECD-FAFC-45A8-8896-CFFB139DAAA3}) (Version: 2.2.0.0 - SAMSUNG)
FastConnect 1.2.2 (HKLM-x32\...\FastConnect) (Version: 1.2.2 - The Cloud Networks)
FeedReader (HKLM-x32\...\FeedReader_is1) (Version: - i-Systems Inc.)
FirstClass® Client (HKLM-x32\...\{2869279D-7AE2-4A13-96B8-46078BA3F75B}) (Version: 11.0 (build 11.033) - Open Text

Corporation.)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (HKLM-x32\...\{B04A0E2F-1E4C-4E61-

B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Free Download Manager 3.0 (HKLM-x32\...\Free Download Manager_is1) (Version: - FreeDownloadManager.ORG)
Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com)
FreeMind (HKLM-x32\...\B991B020-2968-11D8-AF23-444553540000_is1) (Version: 0.9.0 - )
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Gizmo Central (HKLM-x32\...\Gizmo Central) (Version: v2.7.9 - Arainia Solutions, LLC)
Glary Utilities 2.42.0.1389 (HKLM-x32\...\Glary Utilities_is1) (Version: 2.42.0.1389 - Glarysoft Ltd)
Google Chrome (HKCU\...\Google Chrome) (Version: 33.0.1750.154 - Google Inc.)
Google Drive (HKLM-x32\...\{E87022D3-C8C9-4C76-8E27-BC7F18F9B8FB}) (Version: 1.14.6059.644 - Google, Inc.)
Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden
Hoffnung für heute (HKLM-x32\...\{9447C5C8-6A1B-412F-B9A6-99AFE7C09773}) (Version: 3.2.1 - )
iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
ICQ7.5 (HKLM-x32\...\{7578ADEA-D65F-4C89-A249-B1C88B6FFC20}) (Version: 7.5 - ICQ)
IHMC CmapTools v5.05.01 (HKLM-x32\...\IHMC CmapTools v5.05.01) (Version: 5.0.5.1 - Institute for Human & Machine Cognition)
iMODELER - Consideo GmbH (HKLM-x32\...\iMODELER) (Version: - )
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel

Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.3.1001 - Intel

Corporation)
Intel(R) Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.02.00.1002 -

Intel Corporation)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.28 - Irfan Skiljan)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
iWisoft Free Video Converter 1.2 (HKLM-x32\...\iWisoft Free Video Converter_is1) (Version: 1.2 - www.easy-video-

converter.com)
IZArc 4.1.6 (HKLM-x32\...\{97C82B44-D408-4F14-9252-47FC1636D23E}_is1) (Version: 4.1.6 - Ivan Zahariev)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 37 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216037FF}) (Version: 6.0.370 - Oracle)
JLC's Internet TV (HKLM-x32\...\JLC's Internet TV) (Version: - )
Jpg2Pdf version 1.2 (HKLM-x32\...\{533D415A-4151-4AC5-858E-4068524C8051}_is1) (Version: 1.2 - Office Necessities inc.)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
KaraFun Player (HKLM-x32\...\KaraFun Player_is1) (Version: 1.20.86.771 - Recisio)
K-Lite Codec Pack 6.0.4 (Basic) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 6.0.4 - )
Kontrola Windows Live Mesh ActiveX za daljinske veze (HKLM-x32\...\{19CBDE24-2761-49A5-816B-D2BA65D0CA8D}) (Version:

15.4.5722.2 - Microsoft Corporation)
Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (HKLM-x32\...\{CA227A9D-09BE-4BFB-9764-48FED2DA5454}) (Version:

15.4.5722.2 - Microsoft Corporation)
LinkedIn Outlook Connector (HKLM-x32\...\LinkedIn Outlook Connector) (Version: 1.1.10.0 - LinkedIn)
MagicDisc 2.7.106 (HKLM-x32\...\MagicDisc 2.7.106) (Version: - )
Malwarebytes Anti-Malware Version 2.00.0.1000 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.00.0.1000 -

Malwarebytes Corporation)
ManyCam 3.1.59 (HKLM-x32\...\ManyCam) (Version: 3.1.59 - ManyCam LLC)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Assistent (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger kísérő (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger Pratilac (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger Suradnik (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger 사이트 공유 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger 分享元件 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger 浏览器插件 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Messenger-kumppani (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 -

Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft

Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Outlook Social Connector Provider for Facebook 32-bit (HKLM-x32\...\{95140000-007C-0409-0000-0000000FF1CE})

(Version: 14.0.6114.5003 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (HKLM-x32\...\{95140000-007D-0409-0000-

0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 -

Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118})

(Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable - KB2467175 (HKLM-x32\...\{a0fe116e-9a8a-466f-aee0-625cb7c207e3}) (Version:

8.0.51011 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 -

Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version:

9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version:

9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version:

9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475})

(Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989})

(Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F})

(Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version:

10.0.40219 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft_VC90_CRT_x86 (HKLM-x32\...\{DF2035BE-5820-4965-BD97-7FAF8D4A7879}) (Version: 1.0.0 - Microsoft Corporation)
Mindjet MindManager Pro 6 (HKLM-x32\...\{9FC3EA3B-A6FB-436E-8A69-8595548CACBF}) (Version: 6.2.399 - Mindjet LLC)
MiniTool Partition Wizard Home Edition 7.1 (HKLM-x32\...\{34A153FE-6926-4C14-B48A-B71E68C672A8}_is1) (Version: - MiniTool

Solution Ltd.)
Mobipocket Reader 6.2 (HKLM-x32\...\{342126E1-173C-4585-BFBE-3EBDD20E3E9E}) (Version: 6.2.608 - Mobipocket.com)
Movie Color Enhancer (HKLM-x32\...\{7F6F62F0-7884-4CFB-B86C-597A4A6D9C4D}) (Version: 1.0 - Samsung Electronics Co., Ltd.)
Mozilla Firefox 14.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 14.0.1 (x86 de)) (Version: 14.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 14.0.1 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft

Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft

Corporation)
MyPhoneExplorer (HKLM-x32\...\MPE) (Version: 1.8.2 - F.J. Wechselberger)
NAVIGON Fresh 3.4.1 (HKLM-x32\...\NAVIGON Fresh) (Version: 3.4.1 - NAVIGON)
Netzmanager (HKLM-x32\...\Netzmanager) (Version: 1.071 - Deutsche Telekom AG)
Netzmanager (Version: 1.071 - Deutsche Telekom AG, Marmiko IT-Solutions GmbH) Hidden
Nur Entfernen der CopyTrans Suite möglich (HKCU\...\CopyTrans Suite) (Version: 2.33 - WindSolutions)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation)
NVIDIA Grafiktreiber 267.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 267.54 - NVIDIA

Corporation)
NVIDIA Install Application (Version: 2.265.39.0 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 267.54 (Version: 267.54 - NVIDIA Corporation) Hidden
Octoshape Streaming Services (HKCU\...\Octoshape Streaming Services) (Version: - Octoshape ApS)
OpenOffice 4.0.0 (HKLM-x32\...\{B28DBCBA-60F8-40ED-B35B-F510C327946C}) (Version: 4.00.9702 - Apache Software Foundation)
Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (HKLM-x32\...\{B6190387-0036-4BEB-8D74-

A0AFC5F14706}) (Version: 15.4.5722.2 - Microsoft Corporation)
Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (HKLM-x32\...\{C2FD7DB5-FE30-49B6-8A2F-

C5652E053C31}) (Version: 15.4.5722.2 - Microsoft Corporation)
PDF24 Creator 5.3.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
PDFill PDF Editor with FREE Writer and FREE Tools (HKLM\...\{D1399216-81B2-457C-A0F7-73B9A2EF6902}) (Version: 9.0 -

PlotSoft LLC)
PDF-XChange 3 (HKLM-x32\...\PDF-XChange 3_is1) (Version: - Tracker Software)
PhoneShare (HKLM-x32\...\{E31F454E-4813-4C88-B0D3-4BB174993770}) (Version: 1.0.4 - Samsung)
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pomocnik Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Python 2.7.2 (HKLM-x32\...\{2E295B5B-1AD4-4d36-97C2-A316084722CF}) (Version: 2.7.2150 - Python Software Foundation)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.33.1125.2010 -

Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6257 - Realtek

Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Samsung AnyWeb Print (HKLM-x32\...\{318DBE01-1E6B-4243-84B0-210391FE789A}) (Version: 1.1.21.0 - Samsung Electronics Co.,

Ltd.)
Samsung AnyWeb Print (x32 Version: 1.0 - Samsung Electronics Co., Ltd.) Hidden
Samsung Recovery Solution 5 (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.0.8 - Samsung)
Samsung Support Center 1.0 (HKLM-x32\...\{F687E657-F636-44DF-8125-9FEEA2C362F5}) (Version: 1.1.38 - Samsung)
Samsung Universal Print Driver (HKLM-x32\...\Samsung Universal Print Driver) (Version: 2.01.06.00:16 - Samsung Electronics

Co., Ltd.)
Samsung Universal Scan Driver (HKLM-x32\...\Samsung Universal Scan Driver) (Version: 1.2.1.0 - Samsung Electronics Co.,

Ltd.)
Samsung Update Plus (HKLM-x32\...\{142D8CA7-2C6F-45A7-83E3-099AAFD99133}) (Version: 3.0.1.17 - Samsung Electronics Co.,

Ltd.)
Screencast-O-Matic (HKCU\...\Screencast-O-Matic) (Version: - Screencast-O-Matic)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden
Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
Spotify (HKCU\...\Spotify) (Version: 0.9.7.16.g4b197456 - Spotify AB)
Spremljevalec Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.2.25 - Safer-Networking

Ltd.)
SRS Premium Sound Control Panel (HKLM\...\{2998191E-A35E-47E2-BE38-7702C731D722}) (Version: 1.10.1000 - SRS Labs, Inc.)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1108 - SUPERAntiSpyware.com)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
System Explorer 3.9.1 (HKLM-x32\...\System Explorer_is1) (Version: - Mister Group)
System Explorer 3.9.4 (HKLM-x32\...\{40F485F7-6478-4896-B0D5-F94BE677EB78}_is1) (Version: - Mister Group)
Tango (HKCU\...\Tango) (Version: 1.6.14117 - TangoMe, Inc.)
Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 (HKLM\...\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version:

2.0.82.0 - Intel)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}

_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_

{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}

_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}

_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}

_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}

_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}

_Office14.SingleImage_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}

_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}

_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}

_Office14.SingleImage_{81812245-FC84-426A-BC02-6659C88CC7B2}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2775360) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{80F56E3F-1D47-4E45-B6E0-FEF4E919F4F9}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-

0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft)
Update for Microsoft Visio 2010 (KB2878227) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{5D357893-40BA-4323-86BA-D97C66CD72F4}) (Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft)
Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}

_Office14.SingleImage_{E78E2B68-8FD1-42EE-BB74-99A4D9E6222D}) (Version: - Microsoft)
UseNeXT by Tangysoft (HKLM-x32\...\UseNeXT by Tangysoft_is1) (Version: - Tangysoft Ltd.)
User Guide (HKLM-x32\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.0 - )
Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (HKLM-x32\...\{241E7104-937A-4366-AD57-8FDDDB003939}) (Version:

15.4.5722.2 - Microsoft Corporation)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
WIDCOMM Bluetooth Software (HKLM\...\{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}) (Version: 6.3.0.7000 - Broadcom Corporation)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live fotoattēlu galerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogaléria (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Foto-galerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Galeria de Fotos (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Galerija fotografija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-

0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX kontrola za daljinske veze (HKLM-x32\...\{8985AE5E-622A-4980-8BF8-0A1830643220}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX vadīkla attālajiem savienojumiem (HKLM-x32\...\{A3A775C9-5A63-4C55-8FDD-427A5B8F5D2B}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (HKLM-x32\...\{09B7C7EB-3140-4B5E-842F-9C79A7137139})

(Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX-objekt til fjernforbindelser (HKLM-x32\...\{57220148-3B2B-412A-A2E0-82B9DF423696}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (HKLM-x32\...\{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Meshin etäyhteyksien ActiveX-komponentti (HKLM-x32\...\{4CF6F287-5121-483C-A5A2-07BDE19D8B4E}) (Version:

15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Pošta (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 메일 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 사진 갤러리 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 필수 패키지 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 照片库 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 软件包 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft

Corp)
Windows Mobile Device Updater Component (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Windows Mobile-Gerätecenter (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation)
Windows-Treiberpaket - Android-Sync.com (WinUSB) AndroidUsbDeviceClass (10/21/2011 4.0.0000.11021) (HKLM\...

\6D51958587F750FB22B14F3587024652DE17F288) (Version: 10/21/2011 4.0.0000.11021 - Android-Sync.com)
WinPatrol (HKLM\...\{007811BF-E310-4285-BFC6-55DB29B3EDDE}) (Version: 24.1.2012 - BillP Studios)
WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
XING Outlook Connector (HKLM\...\{3B8AF990-AE63-481C-BC4B-8BB8D7A93B80}) (Version: 2.2.0 - XING)
xplorer² lite 32 bit (HKLM-x32\...\xplorer2l) (Version: 2.3.0.1 - Zabkat)
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.)
Yahoo! Software Update (HKLM-x32\...\Yahoo! Software Update) (Version: - )
Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version: - )
YouTube Song Downloader (HKLM-x32\...\{4281435C-AD1D-4C8A-B9C0-3961C11EF142}_is1) (Version: 8.2 - Abelssoft)
Zotero Standalone 3.0.14 (x86 en-US) (HKLM-x32\...\Zotero Standalone 3.0.14 (x86 en-US)) (Version: 3.0.14 - Zotero)
Zune (HKLM\...\Zune) (Version: 04.08.2345.00 - Microsoft Corporation)
Zune (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CHT) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (CSY) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DAN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (DEU) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ELL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ESP) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FIN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (FRA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (HUN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (IND) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (ITA) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (JPN) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (KOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (MSL) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NLD) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (NOR) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PLK) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTB) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (PTG) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (RUS) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Zune Language Pack (SVE) (Version: 04.08.2345.00 - Microsoft Corporation) Hidden
Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47-

FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Компаньон Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Помощник на Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2-

8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation)
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
מסייע Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (HKLM-x32\...\{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}) (Version: 15.4.5722.2 -

Microsoft Corporation)
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\...\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 -

Microsoft Corporation)
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
ตัวควบคุม ActiveX ใน Windows Live Mesh สำหรับการเชื่อมต่อระยะไกล (ไทย) (HKLM-x32\...\{A2EDAEEB-C981-46D5-8163-CF8F5F640EEE}) (Version: 15.4.5722.2

- Microsoft Corporation)
원격 연결을 위한 Windows Live Mesh ActiveX 컨트롤 (HKLM-x32\...\{61920449-0393-4707-B7DD-E6C0013C8B2C}) (Version: 15.4.5722.2 -

Microsoft Corporation)
用于远程连接的 Windows Live Mesh ActiveX 控件(简体中文) (HKLM-x32\...\{F992409C-9D10-4AE2-BAEB-B5409AD3785E}) (Version: 15.4.5722.2 -

Microsoft Corporation)
適用遠端連線的 Windows Live Mesh ActiveX 控制項 (HKLM-x32\...\{622DE1BE-9EDE-49D3-B349-29D64760342A}) (Version: 15.4.5722.2 -

Microsoft Corporation)

==================== Restore Points =========================

26-03-2014 18:24:35 Windows Update
29-03-2014 20:05:06 Uniblue SpeedUpMyPC installation
29-03-2014 22:41:47 S
30-03-2014 13:49:58 Revo Uninstaller's restore point - Ask Shopping Toolbar
30-03-2014 14:43:56 Revo Uninstaller's restore point - ooVoo
30-03-2014 14:44:50 Removed ooVoo

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

Alt 30.03.2014, 22:22   #5
randyandy66
 
Trojaner SupTab u.a. - Standard

Trojaner SupTab u.a.



Und der zweite Teil der zweiten File (Additions)

==================== Scheduled Tasks (whitelisted) =============

Task: {0666A132-9CBC-4EE0-885F-AB0465900A46} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung

\EasySpeedUpManager\EasySpeedUpManager2.exe [2010-12-01] (Samsung Electronics)
Task: {07409B9B-7821-4253-91E7-116AFCF83E69} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display

Manager\dmhkcore.exe [2010-11-28] (Samsung Electronics Co., Ltd.)
Task: {1318A8AD-A403-404D-ADFA-59FA3D8956FD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google

\Update\GoogleUpdate.exe [2011-05-21] (Google Inc.)
Task: {1623FBDB-E473-4D9E-9F23-7A929E229916} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for

updates => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdate.exe
Task: {185C37D1-20B4-4A1F-995A-0B3AE22033D1} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery

Solution 5\WCScheduler.exe [2010-11-17] (SEC)
Task: {24FF686B-BFF6-4A3C-9C78-0E00F254409B} - System32\Tasks\xingoscupdate => C:\Program Files\XING\XING Outlook

Connector\xingoscupdate.exe [2014-01-08] (XING)
Task: {256E2E78-825E-4930-B00E-E86DC6762ED9} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung

\Samsung Support Center\SSCKbdHk.exe [2011-09-04] (SAMSUNG Electronics)
Task: {299D73B6-AE07-4510-BDF3-53538E412FED} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple

Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {29C2FC45-A051-4254-A333-AC168384DC37} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung

\EasyBatteryManager\EasyBatteryMgr4.exe [2010-07-20] (SAMSUNG Electronics co., LTD.)
Task: {38B2690F-5140-4B97-8006-5B6105746F2F} - System32\Tasks\WifiManager => C:\Program Files (x86)\Samsung\Easy Display

Manager\WifiManager.exe [2010-11-28] (Samsung Electronics Co., Ltd.)
Task: {3927588F-2B07-4A40-A858-43BC63300A91} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh

immunization => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDImmunize.exe
Task: {420C63BC-0E55-4D7D-9746-3E5B9FF83E5D} - System32\Tasks\SRS Premium Sound => C:\Program Files\SRS Labs\SRS Premium

Sound Control Panel\srspremiumpanel_64.exe [2010-11-29] (SRS Labs, Inc.)
Task: {47656083-02C7-4E54-808F-7263466606B5} - System32\Tasks\Xing Social Recommendations => C:\Program Files\XING\XING

Outlook Connector\32-bit\XingSocial.exe [2014-01-08] (XING AG)
Task: {56E8FB28-DB36-48DC-8D7A-379AA0CF63F1} - System32\Tasks\{EB5A17F7-59B1-4914-80F9-8981CBF7FF0B} => C:\Program Files

(x86)\Gizmo\gizmo.exe [2011-09-14] (Arainia Solutions)
Task: {773AE63E-EACB-4047-8A3F-2E395CF9E670} - System32\Tasks\SUPBackground => C:\Program Files (x86)\Samsung\Samsung

Update Plus\SUPBackground.exe [2011-12-20] (Samsung Electronics)
Task: {7821C008-BFDF-45B6-B2A7-12BC3E0ACD8D} - System32\Tasks\CleanMem Mini Monitor => C:\Program Files (x86)\CleanMem

\mini_monitor.exe [2011-07-09] (PcWinTech.com)
Task: {8014A37B-FB9B-451C-A2B4-1BF82CC7DA59} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed

\Flash\FlashPlayerUpdateService.exe [2014-03-15] (Adobe Systems Incorporated)
Task: {83C4A256-9C9E-48ED-8770-83C3BFDE7ACF} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-

500UA => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-16] (Google Inc.)
Task: {8D8D58A3-BC0D-4C52-83BA-7F40EA4E7386} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google

\Update\GoogleUpdate.exe [2011-05-21] (Google Inc.)
Task: {97533C0E-FAF4-42D9-8670-CF1F351EFB00} - System32\Tasks\Auslogics\Disk Defrag\Start On andreas Logon => C:\Program

Files (x86)\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe [2011-11-14] (Auslogics)
Task: {9B159597-B87B-4B9E-A7F4-ECC53F52F214} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-

708133086-1000Core => C:\Users\andreas\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {A9405DF1-8498-42EB-9911-E2B1CBC0572C} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-

708133086-1000UA => C:\Users\andreas\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: {AA11DF3E-CFAF-4851-AB5C-20C5BC31E5AE} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-

500Core => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-16] (Google Inc.)
Task: {BFC3AF24-E903-4FA6-A78C-E1B0C2600A77} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system

=> C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDScan.exe
Task: {C5E417A0-E558-4656-8B2A-3B90AC109C24} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung

\BatteryLifeExtender\BatteryLifeExtender.exe [2010-12-01] (Samsung Electronics. Co. Ltd.)
Task: {CABA96D1-D5A0-43F3-9384-32474FD032E2} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Movie

Color Enhancer\MovieColorEnhancer.exe [2010-08-19] (Samsung Electronics Co., Ltd.)
Task: {CDD96E60-7A5E-426C-9FB3-4CF76D015A57} - System32\Tasks\SmartRestarter => C:\Program Files\Samsung\SamsungFastStart

\SmartRestarter.exe [2010-08-05] (Samsung Electronics Co., Ltd.)
Task: {CDE3AF8E-A54A-4CB4-B998-C76152EEE3F2} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam

\YCMMirage.exe [2010-11-10] (CyberLink)
Task: {D10419DA-B0D7-4A0D-98CB-AAFF7C8D73EA} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-

1000UA => C:\Users\andreas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-13] (Google Inc.)
Task: {D185EA38-12BC-44E7-9A58-DD32DED0AA3E} - System32\Tasks\Clean System Memory => C:\Windows\syswow64\CleanMem.exe

[2011-07-09] (PcWinTech.com)
Task: {E1C99093-2BA9-4FF4-AE92-92237CB501CF} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-

1000Core => C:\Users\andreas\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-13] (Google Inc.)
Task: {FEB14CB6-EA1B-4FC4-B812-0C7DA408E53C} - System32\Tasks\GlaryInitialize => C:\Program Files (x86)\Glary Utilities

\initialize.exe [2012-02-03] (Glarysoft Ltd)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000Core.job => C:\Users\andreas

\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000UA.job => C:\Users\andreas

\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GlaryInitialize.job => C:\Program Files (x86)\Glary Utilities\initialize.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000Core.job => C:\Users\andreas

\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000UA.job => C:\Users\andreas\AppData

\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-500Core.job => C:\Users\Administrator

\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-500UA.job => C:\Users\Administrator

\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-05-13 11:20 - 2008-06-05 01:53 - 00027648 _____ () C:\Windows\System32\spd__l.dll
2010-10-19 09:31 - 2010-10-19 09:31 - 00205312 _____ () C:\Program Files\Netzmanager\NMInfraIS2\driver64\SoftplugLib.DLL
2011-05-13 11:20 - 2010-04-21 01:44 - 00719872 _____ () C:\Windows\system32\SnMinDrv.dll
2012-11-01 17:46 - 2012-09-19 19:17 - 00397088 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application

Support\zlib1.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application

Support\libxml2.dll
2012-02-02 03:41 - 2011-11-14 16:09 - 00348376 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag

\madExcept_.bpl
2012-02-02 03:41 - 2011-11-14 16:09 - 00182488 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag

\madBasic_.bpl
2012-02-02 03:41 - 2011-11-14 16:09 - 00048856 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag

\madDisAsm_.bpl
2012-02-02 03:41 - 2011-11-14 16:09 - 00254680 _____ () C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag

\AusShellExt.dll
2010-12-17 06:51 - 2010-07-05 12:42 - 00203776 _____ () C:\Program Files (x86)\Samsung\Movie Color Enhancer\WinCRT.dll
2014-03-19 20:10 - 2014-03-15 02:50 - 00051016 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application

\33.0.1750.154\chrome_elf.dll
2013-09-14 01:51 - 2013-09-14 01:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services

\zlib1.dll
2013-09-14 01:50 - 2013-09-14 01:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services

\libxml2.dll
2014-02-25 18:52 - 2014-02-25 18:52 - 01563200 _____ () C:\Program Files (x86)\Copernic

\DesktopSearch4\Copernic.System.RT.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared

\office14\Cultures\office.odf
2011-09-14 23:44 - 2011-09-14 23:44 - 00166816 _____ () C:\Program Files (x86)\Gizmo\GImage.DLL
2011-09-14 23:44 - 2011-09-14 23:44 - 00315800 _____ () C:\Program Files (x86)\Gizmo\gmanager.DLL
2011-09-14 23:44 - 2011-09-14 23:44 - 00404384 _____ () C:\Program Files (x86)\Gizmo\gdatabase.dll
2011-09-14 23:44 - 2011-09-14 23:44 - 00394656 _____ () C:\Program Files (x86)\Gizmo\gdrive.dll
2011-09-14 23:44 - 2011-09-14 23:44 - 00339864 _____ () C:\Program Files (x86)\Gizmo\geditor.dll
2011-09-14 23:44 - 2011-09-14 23:44 - 00372632 _____ () C:\Program Files (x86)\Gizmo\ghash.dll
2011-09-14 23:44 - 2011-09-14 23:44 - 00339864 _____ () C:\Program Files (x86)\Gizmo\gscript.dll
2012-02-06 01:20 - 2011-04-15 03:01 - 00548854 ____N () C:\Program Files (x86)\BillP Studios\WinPatrol\sqlite3.dll
2005-03-16 15:34 - 2005-03-16 15:34 - 00110592 ____R () C:\Program Files (x86)\Mindjet\MindManager 6\zlib.dll
2013-10-19 01:55 - 2013-10-19 01:55 - 25100288 _____ () C:\Users\andreas\AppData\Roaming\Dropbox\bin\libcef.dll
2010-12-17 06:49 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll
2014-03-29 22:09 - 2013-05-16 11:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy

2\snlThirdParty150.bpl
2014-03-29 22:09 - 2013-05-16 11:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2014-03-30 16:58 - 2014-03-30 16:58 - 00098816 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32api.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00110080 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pywintypes27.dll
2014-03-30 16:57 - 2014-03-30 16:57 - 00364544 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pythoncom27.dll
2014-03-30 16:58 - 2014-03-30 16:58 - 00044032 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_socket.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 01157120 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_ssl.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00320512 _____ () C:\Users\andreas\AppData\Local\Temp

\_MEI29722\win32com.shell.shell.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00712192 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_hashlib.pyd
2014-03-30 16:57 - 2014-03-30 16:57 - 01175040 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._core_.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00805888 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._gdi_.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00811008 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._windows_.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 01062400 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._controls_.pyd
2014-03-30 16:57 - 2014-03-30 16:57 - 00735232 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._misc_.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00128512 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_elementtree.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00127488 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pyexpat.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00557056 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\pysqlite2._sqlite.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00087040 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_ctypes.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00119808 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32file.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00108544 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32security.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00018432 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32event.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00038912 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32inet.pyd
2014-03-30 16:57 - 2014-03-30 16:57 - 00122368 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._wizard.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00070656 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\wx._html2.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00026624 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\_multiprocessing.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00010240 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\select.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00024064 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32pipe.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00686080 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\unicodedata.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00025600 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32pdh.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00525640 _____ () C:\Users\andreas\AppData\Local\Temp

\_MEI29722\windows._lib_cacheinvalidation.pyd
2014-03-30 16:57 - 2014-03-30 16:57 - 00011264 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32crypt.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00035840 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32process.pyd
2014-03-30 16:58 - 2014-03-30 16:58 - 00017408 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32profile.pyd
2014-03-30 16:57 - 2014-03-30 16:57 - 00022528 _____ () C:\Users\andreas\AppData\Local\Temp\_MEI29722\win32ts.pyd
2014-03-19 20:10 - 2014-03-15 02:50 - 00716616 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application

\33.0.1750.154\libglesv2.dll
2014-03-19 20:10 - 2014-03-15 02:50 - 00100168 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application

\33.0.1750.154\libegl.dll
2014-03-19 20:10 - 2014-03-15 02:50 - 04061000 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application

\33.0.1750.154\pdf.dll
2014-03-19 20:10 - 2014-03-15 02:50 - 00394568 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application

\33.0.1750.154\ppGoogleNaClPluginChrome.dll
2014-03-19 20:10 - 2014-03-15 02:50 - 01647432 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application

\33.0.1750.154\ffmpegsumo.dll
2014-03-19 20:10 - 2014-03-15 02:50 - 13637448 _____ () C:\Users\andreas\AppData\Local\Google\Chrome\Application

\33.0.1750.154\PepperFlash\pepflashplayer.dll
2014-03-29 22:09 - 2013-05-16 11:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy

2\snlFileFormats150.bpl
2009-11-02 07:20 - 2009-11-02 07:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\Temp:07BF512B

==================== Safe Mode (whitelisted) ===================


==================== Disabled items from MSCONFIG ==============


==================== Faulty Device Manager Devices =============

Name: Bluetooth Device (Personal Area Network) #2
Description: Bluetooth-Gerät (PAN)
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: BthPan
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow

the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/30/2014 05:07:17 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: netzmanager.exe, Version: 1.71.0.301, Zeitstempel: 0x500948ae
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1677
Ausnahmecode: 0xe053534f
Fehleroffset: 0x000000000000940d
ID des fehlerhaften Prozesses: 0x%9
Startzeit der fehlerhaften Anwendung: 0xnetzmanager.exe0
Pfad der fehlerhaften Anwendung: netzmanager.exe1
Pfad des fehlerhaften Moduls: netzmanager.exe2
Berichtskennung: netzmanager.exe3

Error: (03/30/2014 04:49:44 PM) (Source: Application Hang) (User: )
Description: Programm chrome.exe, Version 33.0.1750.154 kann nicht mehr unter Windows ausgeführt werden und wurde beendet.

Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu

suchen.

Prozess-ID: 1d14

Startzeit: 01cf4c26b8061c6a

Endzeit: 7

Anwendungspfad: C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe

Berichts-ID: 7f21641c-b81a-11e3-aa82-e811322169d9

Error: (03/30/2014 03:52:02 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome

Error: (03/30/2014 03:52:01 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome

Error: (03/30/2014 03:51:59 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome

Error: (03/30/2014 03:51:56 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome

Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome

Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome

Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome

Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller) (User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome


System errors:
=============
Error: (03/30/2014 05:10:41 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.

Error: (03/30/2014 05:06:46 PM) (Source: WMPNetworkSvc) (User: )
Description: WMPNetworkSvc0x80004005

Error: (03/30/2014 05:02:36 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "SSDP-Suche" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (03/30/2014 05:02:36 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SSDP-Suche erreicht.

Error: (03/30/2014 05:01:56 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (03/30/2014 05:01:52 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht.

Error: (03/30/2014 04:58:57 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Updating Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (03/30/2014 04:58:57 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Updating Service erreicht.

Error: (03/30/2014 04:58:13 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053

Error: (03/30/2014 04:58:13 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht.


Microsoft Office Sessions:
=========================
Error: (03/30/2014 05:07:17 PM) (Source: Application Error)(User: )
Description: netzmanager.exe1.71.0.301500948aeKERNELBASE.dll6.1.7601.1822951fb1677e053534f000000000000940d

Error: (03/30/2014 04:49:44 PM) (Source: Application Hang)(User: )
Description: chrome.exe33.0.1750.1541d1401cf4c26b8061c6a7C:\Users\andreas\AppData\Local\Google\Chrome\Application

\chrome.exe7f21641c-b81a-11e3-aa82-e811322169d9

Error: (03/30/2014 03:52:02 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/30/2014 03:52:01 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/30/2014 03:51:59 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/30/2014 03:51:56 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/30/2014 03:51:55 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (03/30/2014 03:51:54 PM) (Source: MsiInstaller)(User: andreas-sams-PC)
Description: Produkt: Ask Shopping Toolbar -- Fehler 25001. Die folgenden Anwendungen sollten geschlossen werden, bevor Sie

mit der Deinstallation fortfahren:

Google Chrome(NULL)(NULL)(NULL)(NULL)(NULL)


==================== Memory info ===========================

Percentage of memory in use: 56%
Total physical RAM: 3956.56 MB
Available physical RAM: 1714.84 MB
Total Pagefile: 7911.3 MB
Available Pagefile: 4460.76 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:178 GB) (Free:38.82 GB) NTFS
Drive d: () (Fixed) (Total:266.14 GB) (Free:16.1 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 466 GB) (Disk ID: 741D8EA4)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=178 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=266 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=22 GB) - (Type=27)

==================== End Of Log ============================


Alt 31.03.2014, 14:04   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Trojaner SupTab u.a. - Standard

Trojaner SupTab u.a.



So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.




Revo Uninstaller - Download - Filepony
Damit alles deinstallieren was Du in der Additional.txt findest mit dem Zusatz <== ATTENTION

Mit Revo auch Moderat die Reste entfernen lassen.



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
--> Trojaner SupTab u.a.

Alt 31.03.2014, 22:12   #7
randyandy66
 
Trojaner SupTab u.a. - Standard

Trojaner SupTab u.a.



Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 31.03.2014
Suchlauf-Zeit: 21:38:10
Logdatei: mbam.txt
Administrator: Ja

Version: 2.00.0.1000
Malware Datenbank: v2014.03.31.08
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: andreas

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 305876
Verstrichene Zeit: 1 Std, 5 Min, 35 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 0
(No malicious items detected)

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 0
(No malicious items detected)

Dateien: 1
PUP.Optional.WebsSearches.A, C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://istart.webssearches.com/?type=hp&ts=1396123703&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX");), Ersetzt,[cc342ad67f812cd4869790a89272966a]

Physische Sektoren: 0
(No malicious items detected)


(end)
         
Hallo Schrauber,

zunächst mal vielen Dank für die Unterstützung.Ich bin jetzt mit Malware durch, werde jetzt noch adwcleaner laufen lassen.

Aktuell beunruhigt mich, dass mein Winpatrol mir anzeigt (nach Malwarebytes Antimalware Durchlauf) dass ein neues Programm sich in das Startup eintragen will: Winlogon:Userinit

Soll ich das genehmigen?

Schönen Abend und Danke nochmal.
Andreas

Hier ist das Ergebnis von Adwcleaner:

AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v3.022 - Bericht erstellt am 31/03/2014 um 21:53:17
# Aktualisiert 13/03/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : andreas - ANDREAS-SAMS-PC
# Gestartet von : C:\Users\andreas\Downloads\adwcleaner.exe
# Option : Suchen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.16521


-\\ Mozilla Firefox v14.0.1 (de)

[ Datei : C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default\prefs.js ]


[ Datei : C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\4xvkcneo.default\prefs.js ]


-\\ Google Chrome v

[ Datei : C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\preferences ]


[ Datei : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [10536 octets] - [30/03/2014 15:50:46]
AdwCleaner[R1].txt - [1264 octets] - [30/03/2014 16:53:14]
AdwCleaner[R2].txt - [1123 octets] - [31/03/2014 21:53:17]
AdwCleaner[S0].txt - [10116 octets] - [30/03/2014 15:54:56]
AdwCleaner[S1].txt - [1325 octets] - [30/03/2014 16:55:29]

########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [1304 octets] ##########
         
--- --- ---

[/CODE]

Der Bericht JRT:

Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Home Premium x64
Ran by andreas on 31.03.2014 at 21:57:03,59
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\yt.ytnavassistplugin
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\yt.ytnavassistplugin.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\APNSetup1_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\APNSetup1_RASMANCS



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\Users\andreas\appdata\local\apn"
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{01F479DE-02E9-419C-BCCE-8EC2DC396856}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{03670469-3B61-47A0-A7E8-D0586E6B7301}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{04AF73CA-F6BF-4F03-9086-C3C6B74C5663}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{0B904789-8EB4-48A9-976E-CC64DAD12AB7}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{0E47285E-E020-46B3-A37E-85C75D6E5438}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{0E700F60-F823-4A4A-9F84-9D9324FC7A0A}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{0FAEDC09-9068-46AE-84EA-F9BF6F474E46}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{11210F71-8032-47DF-889A-004FD6CE5453}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{124BA32D-3BBC-4630-BAD3-38BCFD599014}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{188989FB-9930-4317-A687-66744B994952}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{18DF775B-A32D-4C67-BF9B-E7A124689DC1}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{22BEB94B-B425-499E-BDC6-70923397FB1F}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{269ED8E0-438C-4A5E-96C5-43FC029EBAF7}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{276C6A57-4674-4C2E-9CC4-CEE8FAC721BF}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{2863D2E0-D189-4A04-B63F-E15F754B76B0}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{2AE19B92-1B44-4528-9156-D03735FA8631}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{2B0948EA-7363-43EA-842E-2D70AB531C86}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{30E7BFF1-6EFD-4C79-8CD1-188ED773BC5A}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{31D7D9EF-0EDB-47F5-B174-1743089BC435}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{3680AB0C-8590-495C-96E0-6D74784BDDBF}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{38CEEFA7-30F7-4D9E-B76A-69F9664BFAEA}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{3D3A8D27-0924-4931-B430-8DA3C56A220F}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{3E25A31B-C2D8-4A52-8B32-02C0D15867D8}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{3F9C741E-4F6E-4A00-A846-F4D2007E839F}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{40FDB91F-059D-4463-A3E4-6FD2B9E14983}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{41B4178B-4A1B-424A-B54A-2D2F0B2EB161}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{41F5A304-5037-4798-AEA2-C78D3CFB19EF}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{4349D868-CC6A-4E42-A756-F22A048903CA}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{471E19FA-2841-4C5E-A078-61F8B8FB5A9C}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{4763342B-0B7A-46AE-ADDB-5EED4C350CAD}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{48002ACE-5994-4C12-98E5-4C39802D4EEA}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{4899E682-0447-423E-AD81-4CE30BE76DD6}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{498EEA5A-0DF2-4BAF-BAF1-187D0F1F8342}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{4A9D7DCC-5224-4048-AFFA-04E7461E5162}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{4BE84766-40B6-4E5A-84BC-F1F128859E2A}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{50B4187D-23F4-499C-8691-323FFBF5B292}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{5562880D-6844-41E3-8515-AD1B2C47794A}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{5799B68A-D29C-477C-8A56-4D79B539A275}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{5AB68723-AB79-43FB-937E-9E24795129AB}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{5C28E9EE-8A8A-443C-AEC5-4AB149E4B1DB}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{5DB5B319-FC09-43F2-B348-2F80D45FF318}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{5E7D33CD-F1F2-4272-B07F-4F80676A0744}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{5F71D9AE-AADD-49EB-AD8B-2EC71020EC46}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{6199A814-ED34-4A86-A361-455ABF0421FB}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{625616F3-ABC6-46F6-B642-58D073A7F065}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{62DFE49D-630A-482B-B343-96C40545A270}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{67B66530-0487-43DA-8511-87306E05EB20}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{680A577C-4F58-46BD-B046-A1FC2CC33758}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{6A57BC74-8D8F-4493-92D0-F5D2E4EEB33C}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{6C73AB49-8AF0-4437-A753-39BD4ADFD476}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{6E1C2FE5-8DE4-45DB-970C-A9E6268FA254}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{6ECA903B-A1A8-4FB6-A72A-F9FD3BBD08EB}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{7030BB90-E379-4F5F-A798-E0C45DFE21F3}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{7546E5A9-441D-4C60-83A0-B40711D956E7}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{7CB62F16-B93C-49E6-9D30-A81FC53A3BDF}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{7F98F680-84B7-40B8-B3E3-8F057C6A6579}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{81365A5F-7923-439D-980A-39132648EEDC}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{87B892B7-DD00-4D52-8A26-F3FE1D7DA5FC}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{87F8A9DD-A10E-43B6-9DFC-1D180F38950E}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{897FBDC0-4D4C-4543-B78F-BBD805D1197D}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{89D0F8F9-1924-494A-9B94-9F8E7E0FC07F}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{8ED99657-0F43-43FF-9996-3EB163ED0AA1}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{93AFFFE2-37DF-4DBB-AF44-79D3ADE29ED2}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{94722005-CED6-47B6-B990-982D0A546959}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{952BF56B-E63C-4026-A785-892EC1385F80}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{996A1F39-4A2D-4DE7-B798-31425AA4FB52}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{9CA78A19-3928-48E3-980C-FB39B1E95C51}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{9CB59B7C-9B92-4419-94A5-48D78AB1928B}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{9F9539BE-3997-4DF5-B935-47259F2E6AFB}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{A4299913-9E9B-4129-AE2D-029B40B16177}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{A56FD045-4915-4D54-862E-163419D49C5F}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{A87AFF25-6E6F-4B19-8414-A47DAAA9D074}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{A930FD36-CA67-48EA-9D0C-5E37C3831784}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{AB98AA02-4AB3-4FF2-A9F8-E1B8A7122D56}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{AC107F42-D6D0-45B4-BE11-721F30AB49D9}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{ADC36449-04E1-4BE3-9DA6-834DCCEAE55C}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{AE195860-8CD2-4E07-A80B-7924B4B599CB}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{AE4F5D47-0453-4743-9746-25AFB76830BA}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{AF003137-CF2A-403E-AF42-77D421DB8764}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{B26DB251-6FB4-4837-A863-FB17767F38F1}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{B5BBAD17-2C23-4FF5-BE5B-2FCF65C4259C}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{B610AA1C-0D04-4167-AA5D-25B27BCD6EEA}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{B7AEBD40-AEFB-44E3-994C-943BE049C9BF}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{BB4783C5-D0C4-4A50-B178-1A21BC662044}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{BE9ECFBC-9491-4829-B1AA-041425A089BF}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{C0A0C92F-E5A3-4070-8FCA-E55AA1FA32B1}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{C38D11B5-5037-4B82-BEDD-35D27A14F1CE}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{C5A795F9-2DF5-44F4-BA5B-9E4EC17F4AC5}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{C7DEDAF9-0108-4CA4-8C89-44BCBB559EB2}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{CA27D0DA-6F48-4FBA-A2EF-84007A3B2B78}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{CC1E993D-5F3C-4120-A52C-8B9614E18052}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{CF6AF331-84EC-40C8-88A9-6C1263547938}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{D30CDFF0-2D5F-43F3-9B4A-27CAFA5DD99B}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{D63980CA-5704-423F-B9DD-A134B4BD0A9F}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{D9D5FD53-BA5F-4B44-8A6F-94E05AFF5DCF}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{DBD91B71-F1BE-4E29-AFF4-563E9E86109C}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{DF63C20B-0F20-4F77-AD9A-A748A3EF800C}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{DFDB1748-6FE1-486C-AF2D-6993CA235677}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{E0A8433E-9558-4656-9863-96915C576075}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{E499963F-CA3E-4031-AB21-CAC26D395AAD}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{E7C271F8-F2CC-4459-9F8A-C3CD9E5F192D}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{E7FA5B45-0B8F-4364-8281-2BF22DDAC655}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{EC5208C4-A465-4471-8DD8-0DF49418E0F4}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{EDFEAA6C-1266-485A-8661-B2634362E529}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{F03F1AAF-3982-420A-91B0-D48A688DF3F4}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{F171035B-7A0F-412D-9637-2ECA506E3355}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{F1A1D697-C01F-428F-A38E-6BAAE1085117}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{F47AE261-FD18-4E84-AD26-A246C9B8421D}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{F8461A33-C917-4C9B-B1C5-600D99F9FCF9}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{FCD557BA-03FF-4980-9BB7-8A7016098351}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{FD118B8E-3D2E-41A6-8DA8-5DBFC16CE81B}
Successfully deleted: [Empty Folder] C:\Users\andreas\appdata\local\{FDEA7313-EB96-439A-AAB5-6E745DA34066}



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 31.03.2014 at 22:05:53,21
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
Und hier der neue FRST:


FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by andreas (administrator) on ANDREAS-SAMS-PC on 31-03-2014 22:10:48
Running from C:\Users\andreas\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe
(Arainia Solutions) C:\Program Files (x86)\Gizmo\gservice.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe
(PcWinTech.com) C:\Program Files (x86)\CleanMem\mini_monitor.exe
(Auslogics) C:\Program Files (x86)\Auslogics\Auslogics Disk Defrag\DiskDefrag.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel_64.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(Mister Group) C:\Program Files (x86)\System Explorer\SystemExplorer.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Mister Group) C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Copernic, a division of N. Harris Copernic Systems) C:\Program Files (x86)\Copernic\DesktopSearch4\Copernic.DesktopSearch.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
(Arainia Solutions) C:\Program Files (x86)\Gizmo\gizmo.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Dropbox, Inc.) C:\Users\andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Deutsche Telekom AG) C:\Program Files\Netzmanager\netzmanager.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mindjet) C:\Program Files (x86)\Mindjet\MindManager 6\MmReminderService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
(Samsung Electronics) C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\system32\taskmgr.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11660904 2010-12-01] (Realtek Semiconductor)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2782096 2010-07-26] (CANON INC.)
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2817872 2012-04-25] (ELAN Microelectronics Corp.)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [WinPatrol] - C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [400480 2012-01-30] (BillP Studios)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [MMReminderService] - C:\Program Files (x86)\Mindjet\MindManager 6\MMReminderService.exe [31232 2006-12-14] (Mindjet)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [Google Update] - C:\Users\andreas\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-05-13] (Google Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6563608 2014-01-15] (SUPERAntiSpyware)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [SystemExplorerAutoStart] - C:\Program Files (x86)\System Explorer\SystemExplorer.exe [2750936 2012-09-03] (Mister Group)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [GoogleDriveSync] - C:\Program Files (x86)\Google\Drive\googledrivesync.exe [21822128 2014-01-30] (Google)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [B0D7A430849FA67EEA71A56253A48520238199B4._service_run] - C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe [859976 2014-03-15] (Google Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [Facebook Update] - "C:\Users\andreas\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [Copernic Desktop Search 4] - C:\Program Files (x86)\Copernic\DesktopSearch4\Copernic.DesktopSearch.exe [1568832 2014-02-25] (Copernic, a division of N. Harris Copernic Systems)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [GoogleChromeAutoLaunch_1DDDD6B09271C2EB3C06CC9B1731B636] - C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe [859976 2014-03-15] (Google Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\Run: [GizmoDriveDelegate] - C:\Program Files (x86)\Gizmo\gizmo.exe [223640 2011-09-14] (Arainia Solutions)
HKU\S-1-5-21-1290605139-235724718-708133086-1000\...\MountPoints2: {131db821-f56a-11e0-8ea6-e811322169d9} - F:\NokiaPCIA_Autorun.exe
HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Google Update] - C:\Users\andreas\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-05-13] (Google Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SUPERAntiSpyware] - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6563608 2014-01-15] (SUPERAntiSpyware)
HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [SystemExplorerAutoStart] - C:\Program Files (x86)\System Explorer\SystemExplorer.exe [2750936 2012-09-03] (Mister Group)
HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GoogleDriveSync] - C:\Program Files (x86)\Google\Drive\googledrivesync.exe [21822128 2014-01-30] (Google)
HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [B0D7A430849FA67EEA71A56253A48520238199B4._service_run] - C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe [859976 2014-03-15] (Google Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Facebook Update] - "C:\Users\andreas\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Copernic Desktop Search 4] - C:\Program Files (x86)\Copernic\DesktopSearch4\Copernic.DesktopSearch.exe [1568832 2014-02-25] (Copernic, a division of N. Harris Copernic Systems)
HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GoogleChromeAutoLaunch_1DDDD6B09271C2EB3C06CC9B1731B636] - C:\Users\andreas\AppData\Local\Google\Chrome\Application\chrome.exe [859976 2014-03-15] (Google Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GizmoDriveDelegate] - C:\Program Files (x86)\Gizmo\gizmo.exe [223640 2011-09-14] (Arainia Solutions)
HKU\S-1-5-21-1290605139-235724718-708133086-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {131db821-f56a-11e0-8ea6-e811322169d9} - F:\NokiaPCIA_Autorun.exe
HKU\S-1-5-21-1290605139-235724718-708133086-500-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [Google Update] - C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-05-16] (Google Inc.)
HKU\S-1-5-21-1290605139-235724718-708133086-500-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0\...\Run: [GizmoDriveDelegate] - C:\Program Files (x86)\Gizmo\gizmo.exe [223640 2011-09-14] (Arainia Solutions)
AppInit_DLLs: C:\PROGRA~2\SupTab\SearchProtect64.dll => C:\PROGRA~2\SupTab\SearchProtect64.dll File Not Found
Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled ()
Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\andreas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Netzmanager.lnk
ShortcutTarget: Netzmanager.lnk -> C:\Program Files\Netzmanager\netzmanager.exe (Deutsche Telekom AG)
Startup: C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://istart.webssearches.com/?type=hp&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://istart.webssearches.com/web/?type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://istart.webssearches.com/web/?type=ds&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3324790&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=58&CUI=&UM=5&UP=SPD64F7ECC-B1EB-4DD1-8B2B-FE27A7C23C95&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: W2PBrowser Class - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
BHO-x32: CmjBrowserHelperObject Object - {AC41D38F-B56D-40AD-94E0-B493D130C959} - C:\Program Files (x86)\Mindjet\MindManager 6\Mm6InternetExplorer.dll (Mindjet)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {4D594333-0076-A76A-76A7-7A786E7484D7} -  No File
Toolbar: HKCU - No Name - {4D594333-2D53-4154-00A7-7A786E7484D7} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default
FF NewTab: hxxp://istart.webssearches.com/newtab/?type=nt&ts=1396123542&from=tugs&uid=HitachiXHTS545050B9A300_110105PBN403171BKSDEX
FF SelectedSearchEngine: webssearches
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @octoshape.com/Octoshape Streaming Services,version=1.0 - C:\Users\andreas\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\andreas\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\andreas\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\andreas\AppData\Roaming\mozilla\plugins\npoctoshape.dll (Octoshape ApS)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\webssearches.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml
FF Extension: TinEye Reverse Image Search - C:\Users\andreas\AppData\Roaming\Mozilla\Firefox\Profiles\o1u5vvg3.default\Extensions\tineye@ideeinc.com.xpi [2011-09-22]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2012-10-20]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-05-23]
FF HKCU\...\Firefox\Extensions: [{b9aa91db-385d-4c69-8a2f-96790aa9405b}] - c:\program files (x86)\copernic\desktopsearch4\firefoxconnector
FF Extension: Copernic Desktop Search - Search Firefox content - c:\program files (x86)\copernic\desktopsearch4\firefoxconnector [2013-08-31]
FF StartMenuInternet: FIREFOX.EXE - firefox.exe

Chrome: 
=======
CHR HomePage: hxxp://www.google.com/
CHR Extension: (Google Docs) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-30]
CHR Extension: (Google Drive) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-30]
CHR Extension: (YouTube) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-30]
CHR Extension: (Copernic Desktop Search Connector) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnnbdaahphjgdgfhliignpepgnbnfomp [2014-03-30]
CHR Extension: (Google-Suche) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-30]
CHR Extension: (Gmail offline) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2014-03-30]
CHR Extension: (Zotero Connector) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekhagklcjbdpajgpjgmbionohlpdbjgc [2014-03-30]
CHR Extension: (Highlight to Search) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\floipahigmmkfhkoapmnijnlnboniglg [2014-03-30]
CHR Extension: (TinEye Reverse Image Search) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\haebnnbpedcbhciplfhjjkbafijpncjl [2014-03-30]
CHR Extension: (WEB.DE MailCheck) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaogepninmlbinccpbiakcgiolijlllo [2014-03-30]
CHR Extension: (Hipmunk) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeabbdefhlelidlhahnfpbllaomkioke [2014-03-30]
CHR Extension: (Social Network Connector) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\jijghdpcfakjjecmadmkembnmmpojdfo [2014-03-30]
CHR Extension: (Klout (beta)) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjaakbhpcbpmojkhpiaacepfcaniglak [2014-03-30]
CHR Extension: (Webcam Toy) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2014-03-30]
CHR Extension: (fIRST lOVE) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lighpcanjnomdcjmfficdanifpdmgmhp [2014-03-30]
CHR Extension: (Google Maps) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2014-03-30]
CHR Extension: (Google Wallet) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2014-03-30]
CHR Extension: (Buffer) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\noojglkidnpfjbincgijbaiedldjfbhh [2014-03-30]
CHR Extension: (Picasa) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2014-03-30]
CHR Extension: (Google Mail) - C:\Users\andreas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-30]
CHR HKCU\...\Chrome\Extension: [cnnbdaahphjgdgfhliignpepgnbnfomp] - c:\program files (x86)\copernic\desktopsearch4\ChromeConnector\ChromeConnector.crx [2014-02-25]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2013-05-06]
CHR StartMenuInternet: Google Chrome - Chrome.exe

==================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2012-09-14] (SUPERAntiSpyware.com)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 CTDevice_Srv; C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe [61440 2007-04-02] (Creative Technology Ltd)
S3 CTUPnPSv; C:\Program Files (x86)\Creative\Creative Centrale\CTUPnPSv.exe [64000 2008-05-21] (Creative Technology Ltd)
S4 DfSdkS; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 2010 Advanced\Dfsdks.exe [544768 2009-08-24] (mst software GmbH, Germany)
R2 Gizmo Central; C:\Program Files (x86)\Gizmo\gservice.exe [34728 2011-09-14] (Arainia Solutions)
R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
R3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [821720 2012-08-21] (Mister Group)

==================== Drivers (Whitelisted) ====================

S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2010-04-29] (Google Inc)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
R1 GizmoDrv; C:\Windows\System32\Drivers\GizmoDrv.sys [34704 2011-09-14] (Arainia Solutions LLC)
R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-11] (ManyCam LLC)
R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2013-01-31] (ManyCam LLC)
S4 pwdrvio; C:\Windows\system32\pwdrvio.sys [19936 2012-01-18] ()
S4 pwdspio; C:\Windows\system32\pwdspio.sys [13280 2012-01-18] ()
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S3 Rockusb; C:\Windows\System32\DRIVERS\rockusb.sys [66704 2013-09-09] (Fuzhou Rockchip Electronics Co,Ltd.)
S3 rtport; C:\Windows\SysWOW64\drivers\rtport.sys [15144 2011-02-14] (Windows (R) 2003 DDK 3790 provider)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-31 22:05 - 2014-03-31 22:05 - 00013364 _____ () C:\Users\andreas\Desktop\JRT.txt
2014-03-31 21:56 - 2014-03-31 21:56 - 01038974 _____ (Thisisu) C:\Users\andreas\Downloads\JRT.exe
2014-03-31 21:56 - 2014-03-31 21:56 - 00000000 ____D () C:\Windows\ERUNT
2014-03-31 21:51 - 2014-03-31 21:51 - 00013391 _____ () C:\Users\andreas\Desktop\adwcleaner - Verknüpfung.lnk
2014-03-31 21:47 - 2014-03-31 21:52 - 00000000 ____D () C:\ProgramData\SecTaskMan
2014-03-31 21:47 - 2014-03-31 21:47 - 00000000 ____D () C:\Program Files (x86)\Security Task Manager
2014-03-31 21:46 - 2014-03-31 21:46 - 02365840 _____ () C:\Users\andreas\Downloads\SecurityTaskManager_Setup.exe
2014-03-31 21:40 - 2014-03-31 21:40 - 00001462 _____ () C:\Users\andreas\Desktop\mbam.txt
2014-03-31 20:39 - 2014-03-31 20:40 - 00008210 _____ () C:\Users\andreas\Downloads\contact_list.php
2014-03-30 17:16 - 2014-03-30 17:16 - 00070081 _____ () C:\Users\andreas\Desktop\Addition.txt
2014-03-30 17:15 - 2014-03-30 17:15 - 00061530 _____ () C:\Users\andreas\Desktop\FRST Scan Result.txt
2014-03-30 17:08 - 2014-03-30 17:11 - 00070081 _____ () C:\Users\andreas\Downloads\Addition.txt
2014-03-30 17:06 - 2014-03-31 22:10 - 00032873 _____ () C:\Users\andreas\Downloads\FRST.txt
2014-03-30 17:05 - 2014-03-31 22:10 - 00000000 ____D () C:\FRST
2014-03-30 17:05 - 2014-03-30 17:05 - 02157056 _____ (Farbar) C:\Users\andreas\Downloads\FRST64.exe
2014-03-30 17:04 - 2014-03-30 17:04 - 01145856 _____ (Farbar) C:\Users\andreas\Downloads\FRST.exe
2014-03-30 15:50 - 2014-03-31 21:53 - 00000000 ____D () C:\AdwCleaner
2014-03-30 15:50 - 2014-03-30 15:50 - 01950720 _____ () C:\Users\andreas\Downloads\adwcleaner.exe
2014-03-30 15:48 - 2014-03-30 15:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\andreas\Downloads\revosetup95.exe
2014-03-30 15:48 - 2014-03-30 15:48 - 00001238 _____ () C:\Users\andreas\Desktop\Revo Uninstaller.lnk
2014-03-30 15:47 - 2014-03-31 20:32 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-30 15:46 - 2014-03-30 15:46 - 00001078 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-03-30 15:46 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-30 15:46 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-30 15:46 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-30 15:45 - 2014-03-30 15:46 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\andreas\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-30 01:06 - 2014-03-30 01:06 - 49940480 _____ () C:\Program Files (x86)\GUT1321.tmp
2014-03-30 01:06 - 2014-03-30 01:06 - 00000000 ____D () C:\Program Files (x86)\GUM1320.tmp
2014-03-30 00:56 - 2014-03-30 00:56 - 00003144 _____ () C:\Windows\System32\Tasks\{203A3670-6A66-495F-B4A0-4907C6887A94}
2014-03-30 00:37 - 2014-03-30 00:44 - 00000643 _____ () C:\Windows\wininit.ini
2014-03-30 00:22 - 2014-03-30 00:22 - 00000000 ____D () C:\Users\andreas\AppData\Local\PDF Writer
2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\PDF Writer
2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\ProgramData\PDF Writer
2014-03-30 00:20 - 2013-07-13 12:15 - 00805376 _____ () C:\Windows\SysWOW64\EditCtlsU.ocx
2014-03-30 00:20 - 2013-07-12 22:57 - 00539648 _____ () C:\Windows\SysWOW64\LblCtlsU.ocx
2014-03-30 00:20 - 2013-04-05 13:55 - 00476160 _____ () C:\Windows\SysWOW64\TabStripCtlU.ocx
2014-03-30 00:20 - 2013-03-03 14:37 - 01061888 _____ () C:\Windows\SysWOW64\ExLvwU.ocx
2014-03-30 00:19 - 2013-09-01 12:59 - 01103872 _____ () C:\Windows\SysWOW64\CBLCtlsU.ocx
2014-03-30 00:19 - 2013-03-28 23:13 - 00645632 _____ () C:\Windows\SysWOW64\BtnCtlsU.ocx
2014-03-30 00:18 - 2014-03-30 00:18 - 08198048 _____ (Bullzip ) C:\Users\andreas\Downloads\Setup_BullzipPDFPrinter_10_4_0_2240_STD.exe
2014-03-29 22:10 - 2014-03-29 22:10 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-03-29 22:09 - 2014-03-30 00:35 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-03-29 22:09 - 2014-03-29 22:12 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-03-29 22:09 - 2014-03-29 22:09 - 00001357 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-03-29 22:09 - 2013-09-20 11:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2014-03-29 22:08 - 2014-03-29 22:08 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\spybot-2.2.exe
2014-03-29 22:06 - 2014-03-30 00:59 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Activeris
2014-03-29 22:04 - 2014-03-29 22:05 - 19425127 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\Nicht bestätigt 322160.crdownload
2014-03-29 21:51 - 2014-03-29 21:51 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\dlg
2014-03-29 21:50 - 2014-03-30 00:57 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-03-29 21:50 - 2014-03-29 21:51 - 00000000 ____D () C:\Program Files (x86)\Jpg2Pdf
2014-03-29 21:49 - 2014-03-29 21:49 - 00001065 _____ () C:\Users\Public\Desktop\7-PDF Maker.lnk
2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\7-PDFMaker
2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Program Files (x86)\7-PDF
2014-03-29 21:45 - 2014-03-29 21:46 - 55633177 _____ (7-PDF, Germany ) C:\Users\andreas\Downloads\7p141.exe
2014-03-29 21:43 - 2014-03-29 21:43 - 00930952 _____ (CNET Download.com) C:\Users\andreas\Downloads\cbsidlm-cbsi183-Free_JPG_to_PDF-ORG-75732662.exe
2014-03-27 23:21 - 2014-03-27 23:21 - 00000000 ____D () C:\Users\andreas\AppData\Local\Skype
2014-03-27 23:20 - 2014-03-27 23:20 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-27 22:54 - 2014-03-27 22:54 - 00476024 _____ (1&1 Mail & Media GmbH) C:\Users\andreas\Downloads\WEB.DE_MailCheck_chrome_setup (2).exe
2014-03-15 09:17 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-15 09:17 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-15 09:17 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-15 09:17 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-15 09:17 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-15 09:17 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-15 09:17 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-15 09:17 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-15 09:17 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-15 09:17 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-15 09:17 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-15 09:17 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-15 09:17 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-15 09:17 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-15 09:17 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-15 09:17 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-15 09:17 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-15 09:17 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-15 09:17 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-15 09:17 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-15 09:17 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-15 09:17 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-15 09:17 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-15 09:17 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-15 09:17 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-15 09:17 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-15 09:17 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-15 09:17 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-15 09:17 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-15 09:17 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-15 09:17 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-15 09:17 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-15 09:17 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-15 09:17 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-15 09:17 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-15 09:17 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-15 09:17 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-15 09:17 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-15 09:17 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-15 09:17 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-15 09:17 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-15 09:17 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-15 09:17 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-15 09:17 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-15 09:17 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-15 09:17 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-15 09:17 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-15 09:17 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-11 22:07 - 2014-03-11 22:07 - 04550656 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr
2014-03-01 14:26 - 2014-03-01 14:26 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iTunes
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iPod
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-03-01 14:00 - 2014-03-01 14:16 - 00000000 ____D () C:\ff602098354a13baca66adf688cd6c8a
2014-03-01 13:58 - 2014-03-01 13:58 - 00000000 ____D () C:\Program Files (x86)\QuickTime

==================== One Month Modified Files and Folders =======

2014-03-31 22:11 - 2014-03-30 17:06 - 00032873 _____ () C:\Users\andreas\Downloads\FRST.txt
2014-03-31 22:10 - 2014-03-30 17:05 - 00000000 ____D () C:\FRST
2014-03-31 22:08 - 2012-05-08 00:40 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-31 22:06 - 2011-05-13 17:36 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000UA.job
2014-03-31 22:05 - 2014-03-31 22:05 - 00013364 _____ () C:\Users\andreas\Desktop\JRT.txt
2014-03-31 21:56 - 2014-03-31 21:56 - 01038974 _____ (Thisisu) C:\Users\andreas\Downloads\JRT.exe
2014-03-31 21:56 - 2014-03-31 21:56 - 00000000 ____D () C:\Windows\ERUNT
2014-03-31 21:53 - 2014-03-30 15:50 - 00000000 ____D () C:\AdwCleaner
2014-03-31 21:52 - 2014-03-31 21:47 - 00000000 ____D () C:\ProgramData\SecTaskMan
2014-03-31 21:51 - 2014-03-31 21:51 - 00013391 _____ () C:\Users\andreas\Desktop\adwcleaner - Verknüpfung.lnk
2014-03-31 21:47 - 2014-03-31 21:47 - 00000000 ____D () C:\Program Files (x86)\Security Task Manager
2014-03-31 21:46 - 2014-03-31 21:46 - 02365840 _____ () C:\Users\andreas\Downloads\SecurityTaskManager_Setup.exe
2014-03-31 21:40 - 2014-03-31 21:40 - 00001462 _____ () C:\Users\andreas\Desktop\mbam.txt
2014-03-31 21:19 - 2012-05-16 19:55 - 00001152 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-500UA.job
2014-03-31 21:17 - 2011-05-21 22:56 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-31 21:06 - 2011-05-13 17:36 - 00001076 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000Core.job
2014-03-31 20:40 - 2014-03-31 20:39 - 00008210 _____ () C:\Users\andreas\Downloads\contact_list.php
2014-03-31 20:32 - 2014-03-30 15:47 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-31 20:12 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-31 20:12 - 2009-07-14 06:45 - 00014144 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-31 20:09 - 2011-09-22 19:16 - 00000000 ____D () C:\Users\andreas\Videos\Documents\Outlook-Dateien
2014-03-31 20:08 - 2010-12-17 23:29 - 02036827 _____ () C:\Windows\WindowsUpdate.log
2014-03-31 20:02 - 2012-04-12 19:52 - 00001146 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000UA.job
2014-03-31 19:46 - 2013-10-03 13:29 - 00000000 ____D () C:\Users\andreas\AppData\Local\E2BABF81-CECF-40E0-A839-5CA03E1839C9.aplzod
2014-03-31 19:42 - 2011-11-08 22:04 - 00000000 ___RD () C:\Users\andreas\Dropbox
2014-03-31 19:42 - 2011-11-08 22:00 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Dropbox
2014-03-31 19:41 - 2013-02-12 16:12 - 00000000 ___RD () C:\Users\andreas\Google Drive
2014-03-31 19:38 - 2012-02-09 01:07 - 00000330 _____ () C:\Windows\Tasks\GlaryInitialize.job
2014-03-31 19:38 - 2011-05-21 22:56 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-31 19:38 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-31 19:37 - 2011-06-05 14:26 - 00051959 _____ () C:\Windows\setupact.log
2014-03-30 22:25 - 2011-06-23 11:30 - 00509628 _____ () C:\Windows\PFRO.log
2014-03-30 22:15 - 2012-06-19 23:25 - 00000000 ____D () C:\Windows\sk
2014-03-30 17:16 - 2014-03-30 17:16 - 00070081 _____ () C:\Users\andreas\Desktop\Addition.txt
2014-03-30 17:15 - 2014-03-30 17:15 - 00061530 _____ () C:\Users\andreas\Desktop\FRST Scan Result.txt
2014-03-30 17:11 - 2014-03-30 17:08 - 00070081 _____ () C:\Users\andreas\Downloads\Addition.txt
2014-03-30 17:05 - 2014-03-30 17:05 - 02157056 _____ (Farbar) C:\Users\andreas\Downloads\FRST64.exe
2014-03-30 17:05 - 2010-12-17 23:56 - 00703176 _____ () C:\Windows\system32\perfh007.dat
2014-03-30 17:05 - 2010-12-17 23:56 - 00150784 _____ () C:\Windows\system32\perfc007.dat
2014-03-30 17:05 - 2009-07-14 07:13 - 01629212 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-30 17:04 - 2014-03-30 17:04 - 01145856 _____ (Farbar) C:\Users\andreas\Downloads\FRST.exe
2014-03-30 16:51 - 2011-05-13 17:39 - 00002450 _____ () C:\Users\andreas\Desktop\Google Chrome.lnk
2014-03-30 15:50 - 2014-03-30 15:50 - 01950720 _____ () C:\Users\andreas\Downloads\adwcleaner.exe
2014-03-30 15:48 - 2014-03-30 15:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\andreas\Downloads\revosetup95.exe
2014-03-30 15:48 - 2014-03-30 15:48 - 00001238 _____ () C:\Users\andreas\Desktop\Revo Uninstaller.lnk
2014-03-30 15:48 - 2011-05-13 19:19 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-03-30 15:46 - 2014-03-30 15:46 - 00001078 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-30 15:46 - 2014-03-30 15:46 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-03-30 15:46 - 2014-03-30 15:45 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\andreas\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-30 01:06 - 2014-03-30 01:06 - 49940480 _____ () C:\Program Files (x86)\GUT1321.tmp
2014-03-30 01:06 - 2014-03-30 01:06 - 00000000 ____D () C:\Program Files (x86)\GUM1320.tmp
2014-03-30 01:06 - 2011-12-27 12:05 - 00008224 _____ () C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2014-03-30 01:05 - 2012-07-12 09:30 - 00000000 ___RD () C:\Users\Administrator\Podcasts
2014-03-30 01:05 - 2012-05-16 19:55 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-03-30 01:05 - 2011-12-27 12:05 - 00001417 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-30 01:05 - 2011-12-27 12:05 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-30 01:05 - 2011-12-27 12:05 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-30 01:02 - 2011-05-13 19:01 - 00000000 ____D () C:\Users\andreas\Desktop\weniger genutzte software
2014-03-30 00:59 - 2014-03-29 22:06 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Activeris
2014-03-30 00:57 - 2014-03-29 21:50 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-03-30 00:57 - 2011-05-13 11:23 - 00001421 _____ () C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-03-30 00:56 - 2014-03-30 00:56 - 00003144 _____ () C:\Windows\System32\Tasks\{203A3670-6A66-495F-B4A0-4907C6887A94}
2014-03-30 00:44 - 2014-03-30 00:37 - 00000643 _____ () C:\Windows\wininit.ini
2014-03-30 00:35 - 2014-03-29 22:09 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-03-30 00:22 - 2014-03-30 00:22 - 00000000 ____D () C:\Users\andreas\AppData\Local\PDF Writer
2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\PDF Writer
2014-03-30 00:20 - 2014-03-30 00:20 - 00000000 ____D () C:\ProgramData\PDF Writer
2014-03-30 00:18 - 2014-03-30 00:18 - 08198048 _____ (Bullzip ) C:\Users\andreas\Downloads\Setup_BullzipPDFPrinter_10_4_0_2240_STD.exe
2014-03-29 22:38 - 2011-06-05 17:37 - 00000000 ____D () C:\Users\andreas\AppData\Local\CrashDumps
2014-03-29 22:12 - 2014-03-29 22:09 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-03-29 22:10 - 2014-03-29 22:10 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-03-29 22:09 - 2014-03-29 22:09 - 00001357 _____ () C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2014-03-29 22:08 - 2014-03-29 22:08 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\spybot-2.2.exe
2014-03-29 22:06 - 2011-09-20 22:05 - 00001332 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-03-29 22:05 - 2014-03-29 22:04 - 19425127 _____ (Safer-Networking Ltd. ) C:\Users\andreas\Downloads\Nicht bestätigt 322160.crdownload
2014-03-29 21:51 - 2014-03-29 21:51 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\dlg
2014-03-29 21:51 - 2014-03-29 21:50 - 00000000 ____D () C:\Program Files (x86)\Jpg2Pdf
2014-03-29 21:50 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-03-29 21:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-03-29 21:49 - 2014-03-29 21:49 - 00001065 _____ () C:\Users\Public\Desktop\7-PDF Maker.lnk
2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\7-PDFMaker
2014-03-29 21:49 - 2014-03-29 21:49 - 00000000 ____D () C:\Program Files (x86)\7-PDF
2014-03-29 21:48 - 2011-05-13 11:23 - 00000000 ___RD () C:\Users\andreas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-29 21:46 - 2014-03-29 21:45 - 55633177 _____ (7-PDF, Germany ) C:\Users\andreas\Downloads\7p141.exe
2014-03-29 21:43 - 2014-03-29 21:43 - 00930952 _____ (CNET Download.com) C:\Users\andreas\Downloads\cbsidlm-cbsi183-Free_JPG_to_PDF-ORG-75732662.exe
2014-03-29 16:35 - 2012-05-16 19:55 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-500Core.job
2014-03-29 16:35 - 2012-04-12 19:52 - 00001124 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1290605139-235724718-708133086-1000Core.job
2014-03-27 23:56 - 2014-01-01 20:55 - 00001026 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-03-27 23:55 - 2011-05-23 21:57 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\vlc
2014-03-27 23:37 - 2011-10-09 22:18 - 00000000 ____D () C:\Users\andreas\AppData\Roaming\Skype
2014-03-27 23:21 - 2014-03-27 23:21 - 00000000 ____D () C:\Users\andreas\AppData\Local\Skype
2014-03-27 23:21 - 2011-05-13 11:21 - 00000000 ____D () C:\ProgramData\Skype
2014-03-27 23:20 - 2014-03-27 23:20 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-27 22:54 - 2014-03-27 22:54 - 00476024 _____ (1&1 Mail & Media GmbH) C:\Users\andreas\Downloads\WEB.DE_MailCheck_chrome_setup (2).exe
2014-03-26 22:18 - 2011-06-14 19:06 - 00000000 ____D () C:\Users\andreas\Videos\Documents\Youcam
2014-03-21 15:59 - 2011-09-15 02:51 - 00147456 _____ (Bullzip) C:\Windows\SysWOW64\bzpdfc.dll
2014-03-19 20:38 - 2013-08-15 10:24 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-19 20:36 - 2011-05-13 16:38 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-19 19:13 - 2009-07-14 06:45 - 00459824 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-19 19:11 - 2013-03-13 10:05 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-19 19:11 - 2013-03-13 10:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-15 10:36 - 2011-09-14 21:22 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-15 10:08 - 2012-05-08 00:40 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-15 10:08 - 2012-05-08 00:40 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-15 10:08 - 2011-08-22 23:30 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-11 22:07 - 2014-03-11 22:07 - 04550656 _____ (Google Inc.) C:\Windows\SysWOW64\GPhotos.scr
2014-03-10 22:52 - 2011-11-07 09:32 - 01603492 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-03-05 09:26 - 2014-03-30 15:46 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-05 09:26 - 2014-03-30 15:46 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-05 09:26 - 2014-03-30 15:46 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-01 14:26 - 2014-03-01 14:26 - 00001743 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iTunes
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files\iPod
2014-03-01 14:26 - 2014-03-01 14:26 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-03-01 14:16 - 2014-03-01 14:00 - 00000000 ____D () C:\ff602098354a13baca66adf688cd6c8a
2014-03-01 13:58 - 2014-03-01 13:58 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-03-01 08:05 - 2014-03-15 09:17 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-01 07:17 - 2014-03-15 09:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-01 07:16 - 2014-03-15 09:17 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-01 06:58 - 2014-03-15 09:17 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-01 06:52 - 2014-03-15 09:17 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-01 06:51 - 2014-03-15 09:17 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-01 06:42 - 2014-03-15 09:17 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-01 06:40 - 2014-03-15 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-01 06:37 - 2014-03-15 09:17 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-01 06:33 - 2014-03-15 09:17 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-01 06:33 - 2014-03-15 09:17 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-01 06:32 - 2014-03-15 09:17 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-01 06:30 - 2014-03-15 09:17 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-01 06:23 - 2014-03-15 09:17 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-01 06:17 - 2014-03-15 09:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-01 06:11 - 2014-03-15 09:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-01 06:02 - 2014-03-15 09:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-01 05:54 - 2014-03-15 09:17 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-01 05:52 - 2014-03-15 09:17 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-01 05:51 - 2014-03-15 09:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-01 05:47 - 2014-03-15 09:17 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-01 05:43 - 2014-03-15 09:17 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-01 05:43 - 2014-03-15 09:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-01 05:42 - 2014-03-15 09:17 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-01 05:40 - 2014-03-15 09:17 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-01 05:38 - 2014-03-15 09:17 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-01 05:37 - 2014-03-15 09:17 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-01 05:35 - 2014-03-15 09:17 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-01 05:18 - 2014-03-15 09:17 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-01 05:16 - 2014-03-15 09:17 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-01 05:14 - 2014-03-15 09:17 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-01 05:10 - 2014-03-15 09:17 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-01 05:03 - 2014-03-15 09:17 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-01 05:00 - 2014-03-15 09:17 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-01 04:57 - 2014-03-15 09:17 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-01 04:38 - 2014-03-15 09:17 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-01 04:32 - 2014-03-15 09:17 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-01 04:27 - 2014-03-15 09:17 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-01 04:25 - 2014-03-15 09:17 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-01 04:25 - 2014-03-15 09:17 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll

Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\Temp\avgnt.exe
C:\Users\Administrator\AppData\Local\Temp\DivXSetup.exe
C:\Users\Administrator\AppData\Local\Temp\MSN9A3E.exe
C:\Users\andreas\AppData\Local\Temp\avgnt.exe
C:\Users\andreas\AppData\Local\Temp\ose00000.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-20 19:35

==================== End Of Log ============================
         
--- --- ---

--- --- ---

Alt 01.04.2014, 13:42   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Trojaner SupTab u.a. - Standard

Trojaner SupTab u.a.




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Trojaner SupTab u.a.
auskennt, dateien, download, jpg, laufe, laufen, problem, suptab, troja, trojaner, vermutlich, verrückte




Zum Thema Trojaner SupTab u.a. - Hallo, habe hier ein Problem mit einem Trojaner (mind.). Vermutlich durch den Download von jpgtopdf.exe Ich habe schon FRST laufen lassen und die Dateien angehängt. Hoffe, das genügt und dass - Trojaner SupTab u.a....
Archiv
Du betrachtest: Trojaner SupTab u.a. auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.