![]() |
|
Plagegeister aller Art und deren Bekämpfung: zilliontoolkitusa.info versehentlich installiert - was nun?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
![]() ![]() | ![]() zilliontoolkitusa.info versehentlich installiert - was nun?Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a1f5d95c2216544fb18c8e08c476d302 # engine=17835 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-10 10:03:42 # local_time=2014-04-11 12:03:42 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 17510714 148797272 0 0 # scanned=171405 # found=11 # cleaned=0 # scan_time=26255 sh=FDF652F803592E6840E076A89A19BF655686B8A8 ft=1 fh=de76e936397b25d2 vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setupx.dll.vir" sh=DCA031CCCD3513AF593688567E9A3F756E5077A9 ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-0507.DI trojan" ac=I fn="C:\Users\Gast\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\24dfd73e-66316722" sh=CA1E4D93CD990D7DFCA2DF924DAF7A80EF843936 ft=1 fh=7bc484465cd05020 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B0PZCN4F\laP2[1].exe" sh=3B2C90B0A0AF44B405D746E437ACBE2DA1E5E741 ft=1 fh=d0e8a9f046f91a20 vn="Win32/TrojanDownloader.Agent.AFD trojan" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C287NNXV\agup[1].exe" sh=E9E7EA2050CFA72869A01CFB9FAF114017EF7B3D ft=1 fh=533e37724d6c2993 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C287NNXV\g7k[1].exe" sh=606855FE0D4B22E39AFAEA7DB624E047226766C8 ft=1 fh=2f9b5bcf22757698 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C287NNXV\jP[1].exe" sh=4429F11FA3C7C6E412513C7C98A3378BF10726DF ft=1 fh=3542d40051fae3a3 vn="Win32/SpeedingUpMyPC.I application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E53KL4MD\OptimizerPro[1].exe" sh=8FBA22A5E4AA86D5CA80F41581E2760E6BBBACD9 ft=1 fh=c8344a20fb6fafb4 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E53KL4MD\TczzWYPZ3n[1].exe" sh=70A353D429725AF6A0FC4D8281463FB1532D874A ft=1 fh=7f1080b46eaed078 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N4DT5K2C\N[1].exe" sh=A87B7647DC34B5B6186209377786E946B677C574 ft=1 fh=c2834f18f25710d9 vn="multiple threats" ac=I fn="C:\Users\studentin mama\AppData\Local\Temp\{54F4A8AF-B61B-4054-956C-468B169B64BA}\setup.exe" sh=B7850E1015E19B1C857A15BD431F7DB04284BA9D ft=1 fh=7c08556eb62c5e16 vn="multiple threats" ac=I fn="C:\Users\studentin mama\AppData\Local\Temp\{8E4403EA-594F-4FA4-9C86-F601CEA292B9}\setup.exe" ESETSmartInstaller@High as downloader log: Can not read file from internet.ESETSmartInstaller@High as downloader log: Can not read file from internet.ESETSmartInstaller@High as downloader log: Can not read file from internet.ESETSmartInstaller@High as downloader log: Can not read file from internet.# version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a1f5d95c2216544fb18c8e08c476d302 # engine=17859 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-12 04:15:24 # local_time=2014-04-12 06:15:24 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 17662616 148949174 0 0 # scanned=242265 # found=11 # cleaned=0 # scan_time=19508 sh=FDF652F803592E6840E076A89A19BF655686B8A8 ft=1 fh=de76e936397b25d2 vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setupx.dll.vir" sh=DCA031CCCD3513AF593688567E9A3F756E5077A9 ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-0507.DI trojan" ac=I fn="C:\Users\Gast\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\24dfd73e-66316722" sh=CA1E4D93CD990D7DFCA2DF924DAF7A80EF843936 ft=1 fh=7bc484465cd05020 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B0PZCN4F\laP2[1].exe" sh=3B2C90B0A0AF44B405D746E437ACBE2DA1E5E741 ft=1 fh=d0e8a9f046f91a20 vn="Win32/TrojanDownloader.Agent.AFD trojan" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C287NNXV\agup[1].exe" sh=E9E7EA2050CFA72869A01CFB9FAF114017EF7B3D ft=1 fh=533e37724d6c2993 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C287NNXV\g7k[1].exe" sh=606855FE0D4B22E39AFAEA7DB624E047226766C8 ft=1 fh=2f9b5bcf22757698 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C287NNXV\jP[1].exe" sh=4429F11FA3C7C6E412513C7C98A3378BF10726DF ft=1 fh=3542d40051fae3a3 vn="Win32/SpeedingUpMyPC.I application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E53KL4MD\OptimizerPro[1].exe" sh=8FBA22A5E4AA86D5CA80F41581E2760E6BBBACD9 ft=1 fh=c8344a20fb6fafb4 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E53KL4MD\TczzWYPZ3n[1].exe" sh=70A353D429725AF6A0FC4D8281463FB1532D874A ft=1 fh=7f1080b46eaed078 vn="a variant of Win32/AdWare.MultiPlug.R application" ac=I fn="C:\Users\studentin mama\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N4DT5K2C\N[1].exe" sh=A87B7647DC34B5B6186209377786E946B677C574 ft=1 fh=c2834f18f25710d9 vn="multiple threats" ac=I fn="C:\Users\studentin mama\AppData\Local\Temp\{54F4A8AF-B61B-4054-956C-468B169B64BA}\setup.exe" sh=B7850E1015E19B1C857A15BD431F7DB04284BA9D ft=1 fh=7c08556eb62c5e16 vn="multiple threats" ac=I fn="C:\Users\studentin mama\AppData\Local\Temp\{8E4403EA-594F-4FA4-9C86-F601CEA292B9}\setup.exe" FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-04-2014 01 Ran by studentin mama (administrator) on STUDENTINMAMA on 12-04-2014 18:41:03 Running from C:\Users\studentin mama\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe (Hewlett-Packard) C:\Windows\system32\Hpservice.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (AMD) C:\Windows\system32\atieclxx.exe (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe () C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe (pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (TomTom) C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe () C:\Windows\Samsung\PanelMgr\SSMMgr.exe () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Easybits) C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe () C:\Windows\Samsung\PanelMgr\caller64.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (CyberLink) C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\system32\msiexec.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2281256 2011-10-30] (Synaptics Incorporated) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-06-09] (IDT, Inc.) HKLM\...\Run: [HPWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-06-18] (Hewlett-Packard Company) HKLM\...\Run: [SpywareTerminatorShield] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe HKLM\...\Run: [SpywareTerminatorUpdater] - C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-04-16] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [602168 2010-06-29] (Hewlett-Packard Company) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-06-09] (Hewlett-Packard) HKLM-x32\...\Run: [] - [X] HKLM-x32\...\Run: [DivXMediaServer] - C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe HKLM-x32\...\Run: [Samsung PanelMgr] - C:\Windows\Samsung\PanelMgr\SSMMgr.exe [548864 2009-02-04] () HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [DivXUpdate] - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] () HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKLM-x32\...\Run: [Magic Desktop for HP notification] - C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1258504 2013-12-30] (Easybits) HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707472 2013-12-13] (Cisco Systems, Inc.) HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-04-08] (Hewlett-Packard) HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2010-05-19] (Hewlett-Packard Company) HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [MyTomTomSA.exe] - C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe [434168 2012-05-18] (TomTom) HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Run: [EPSON Stylus DX5000 Series] - C:\Windows\system32\spool\DRIVERS\x64\3\E_FATIBVE.EXE [139264 2006-09-22] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\Policies\system: [DisableChangePassword] 0 HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\MountPoints2: G - G:\pushinst.exe HKU\S-1-5-21-1183461899-3623103710-1707053119-1001\...\MountPoints2: {2c95361d-2ce3-11e1-9892-f1a06df124b6} - G:\Setup.exe AppInit_DLLs: C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL => C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL File Not Found Startup: C:\Users\studentin mama\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT/4 SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {19089719-9401-4468-AE0B-8104E8D0D9EF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM - {654B965E-3DF5-6EBF-25F2-16047A3CEE0A} URL = SearchScopes: HKLM - {E81CDADA-1F06-414B-A58F-396B22D1CAFD} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM-x32 - {19089719-9401-4468-AE0B-8104E8D0D9EF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM-x32 - {E81CDADA-1F06-414B-A58F-396B22D1CAFD} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKCU - {19089719-9401-4468-AE0B-8104E8D0D9EF} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKCU - {E81CDADA-1F06-414B-A58F-396B22D1CAFD} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File DPF: HKLM-x32 {538793D5-659C-4639-A56C-A179AD87ED44} Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.137.1 FireFox: ======== FF ProfilePath: C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll (Adobe Systems, Inc.) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 - C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: YoutubeAdblocker - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\mriqu@dpfrjfc.com [2014-04-02] FF Extension: WEB.DE MailCheck - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\toolbar@web.de.xpi [2013-11-25] FF Extension: Adblock Plus - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-09-24] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-03-29] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2014-03-29] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2014-03-29] FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-04-27] Chrome: ======= CHR HomePage: hxxp://www.google.com CHR RestoreOnStartup: "hxxp://www.google.com" CHR Extension: (No Name) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\gladcbhcbkdeddbidiblppadjdjalidb [2012-11-17] CHR Extension: (SNT) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\jipdpdgjdgibngmaockoaenedejjnkgk [2014-04-02] CHR Extension: (tinyFilter) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlfgnnlnfbpcammlnibfkplpnbbbdeli [2014-04-02] CHR Extension: (YoutubeAdblocker) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\olodkgeocddnmkokdmamjnjdkdijnkgm [2014-04-02] ==================== Services (Whitelisted) ================= R2 EPSON_PM_RPCV4_01; C:\ProgramData\EPSON\EPW!3 SSRP\E_S30RP1.EXE [102400 2006-04-18] (SEIKO EPSON CORPORATION) R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [27192 2010-06-29] () R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151744 2014-01-11] (IObit) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation) R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH) R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH) ==================== Drivers (Whitelisted) ==================== R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-12] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation) S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52080 2013-12-13] (Cisco Systems, Inc.) S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-12 18:37 - 2014-04-12 18:40 - 02157568 _____ (Farbar) C:\Users\studentin mama\Downloads\FRST64.exe 2014-04-10 16:44 - 2014-04-10 16:44 - 02347384 _____ (ESET) C:\Users\studentin mama\Downloads\esetsmartinstaller_enu(1).exe 2014-04-10 16:29 - 2014-04-10 16:29 - 00001306 _____ () C:\Users\studentin mama\Desktop\mbam.txt 2014-04-10 14:11 - 2014-04-10 14:11 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-09 21:46 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-09 21:46 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-09 21:46 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-09 21:46 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-09 21:46 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-09 21:46 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-09 21:46 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-09 21:46 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-09 21:46 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-09 21:46 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-09 21:46 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-09 21:46 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-09 21:46 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-09 21:46 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-09 21:46 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-09 21:46 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-09 21:46 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-09 21:46 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-09 21:46 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-09 21:46 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-09 21:45 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-09 10:43 - 2014-04-09 10:43 - 00046375 _____ () C:\Users\studentin mama\Desktop\FRST_09-04-2014_10-43-38.txt 2014-04-09 10:43 - 2014-04-09 10:43 - 00043264 _____ () C:\Users\studentin mama\Desktop\Addition.txt 2014-04-09 10:41 - 2014-04-10 00:45 - 00045602 _____ () C:\Users\studentin mama\Downloads\Addition.txt 2014-04-09 10:39 - 2014-04-12 18:41 - 00020050 _____ () C:\Users\studentin mama\Downloads\FRST.txt 2014-04-09 10:38 - 2014-04-12 18:41 - 00000000 ____D () C:\FRST 2014-04-07 13:55 - 2014-04-07 14:04 - 10995296 _____ (Deutsche Telekom AG, Marmiko IT-Solutions GmbH ) C:\Users\studentin mama\Downloads\netzmanager_setup.exe 2014-04-05 22:42 - 2014-04-05 22:42 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000(1).exe 2014-04-05 22:27 - 2014-04-05 22:27 - 02347384 _____ (ESET) C:\Users\studentin mama\Downloads\esetsmartinstaller_enu.exe 2014-04-05 08:36 - 2014-04-05 08:36 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-04-05 08:30 - 2014-04-05 08:30 - 05049344 _____ (Crawler.com ) C:\Users\studentin mama\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2014-04-04 23:56 - 2014-04-04 23:57 - 00613200 _____ (Chip Digital GmbH) C:\Users\studentin mama\Downloads\AdwCleaner - CHIP-Downloader.exe 2014-04-04 23:07 - 2014-04-12 18:01 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-04 23:06 - 2014-04-10 14:12 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-04 23:06 - 2014-04-10 14:12 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-04 23:06 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-04 23:06 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-04 23:06 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-04 23:05 - 2014-04-04 23:06 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000.exe 2014-04-04 23:00 - 2014-04-04 23:04 - 00001420 _____ () C:\Users\studentin mama\Desktop\Rkill.txt 2014-04-04 22:59 - 2014-04-04 22:59 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\studentin mama\Downloads\wObiA.exe 2014-04-04 16:16 - 2014-04-04 16:20 - 00000000 ____D () C:\Users\studentin mama\Desktop\Documents\KWB 2014 2014-04-03 21:35 - 2014-04-04 16:08 - 00012603 _____ () C:\Users\studentin mama\Desktop\Documents\Bewertungsbögen Spezialaufgabe KWB 2014.xlsx 2014-04-02 20:02 - 2014-04-02 20:02 - 12400098 _____ () C:\Users\studentin mama\Desktop\Die Machtergreifung in Würzburg 1933, PDF.zip 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Packages 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator 2014-04-02 20:00 - 2014-04-02 20:02 - 00000000 ____D () C:\ProgramData\InstallMate 2014-03-29 20:33 - 2014-03-29 20:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-13 23:53 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-03-13 23:53 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-03-13 23:53 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-03-13 23:53 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-03-13 23:53 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-03-13 23:53 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-03-13 23:53 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-03-13 23:53 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-03-13 23:53 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-03-13 23:53 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-03-13 23:53 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-03-13 23:53 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-03-13 23:53 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-03-13 23:53 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-03-13 23:53 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-03-13 23:53 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-03-13 23:53 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-03-13 23:53 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-03-13 23:53 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-03-13 23:53 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-03-13 23:53 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-03-13 23:53 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-03-13 23:53 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-03-13 23:53 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-03-13 23:53 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-03-13 23:53 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-03-13 23:53 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-03-13 23:53 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-03-13 23:53 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-03-13 23:53 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-03-13 23:53 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-03-13 23:53 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-03-13 23:53 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-03-13 23:53 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-03-13 23:53 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-03-13 23:53 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-03-13 23:53 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2014-03-13 23:53 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2014-03-13 23:53 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2014-03-13 23:52 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-03-13 23:52 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2014-03-13 23:52 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2014-03-13 23:52 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2014-03-13 23:52 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll ==================== One Month Modified Files and Folders ======= 2014-04-12 18:41 - 2014-04-09 10:39 - 00020050 _____ () C:\Users\studentin mama\Downloads\FRST.txt 2014-04-12 18:41 - 2014-04-09 10:38 - 00000000 ____D () C:\FRST 2014-04-12 18:40 - 2014-04-12 18:37 - 02157568 _____ (Farbar) C:\Users\studentin mama\Downloads\FRST64.exe 2014-04-12 18:01 - 2014-04-04 23:07 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-12 17:57 - 2013-05-28 01:13 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-12 17:54 - 2011-10-31 17:48 - 00000356 _____ () C:\Windows\Tasks\HP Photo Creations Communicator.job 2014-04-12 17:43 - 2012-02-26 15:04 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-12 17:41 - 2011-03-10 02:07 - 01198799 _____ () C:\Windows\WindowsUpdate.log 2014-04-12 12:16 - 2009-07-14 06:45 - 00023024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-12 12:16 - 2009-07-14 06:45 - 00023024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-12 12:10 - 2012-02-26 15:04 - 00001122 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-12 12:09 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-12 12:08 - 2013-09-24 08:09 - 00029272 _____ () C:\Windows\setupact.log 2014-04-11 22:00 - 2013-01-09 20:35 - 00003986 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{D3FEFDA5-19CA-46DA-9710-E509D83A4478} 2014-04-11 06:31 - 2014-01-11 23:00 - 00000000 ____D () C:\ProgramData\ProductData 2014-04-10 16:44 - 2014-04-10 16:44 - 02347384 _____ (ESET) C:\Users\studentin mama\Downloads\esetsmartinstaller_enu(1).exe 2014-04-10 16:38 - 2013-09-24 08:09 - 01358410 _____ () C:\Windows\PFRO.log 2014-04-10 16:29 - 2014-04-10 16:29 - 00001306 _____ () C:\Users\studentin mama\Desktop\mbam.txt 2014-04-10 16:20 - 2013-06-14 10:08 - 00000000 ___HD () C:\Windows\msdownld.tmp 2014-04-10 14:12 - 2014-04-04 23:06 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-10 14:12 - 2014-04-04 23:06 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-10 14:11 - 2014-04-10 14:11 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.1.1004.exe 2014-04-10 07:18 - 2011-10-20 06:57 - 00000000 ____D () C:\Users\studentin mama\Desktop\Studium Lehramt an Gymnasien Deutsch und Geschichte 2014-04-10 01:00 - 2011-10-04 14:15 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-10 00:58 - 2013-09-25 21:32 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-10 00:54 - 2011-10-17 22:46 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-10 00:45 - 2014-04-09 10:41 - 00045602 _____ () C:\Users\studentin mama\Downloads\Addition.txt 2014-04-10 00:38 - 2014-01-29 20:56 - 00000008 __RSH () C:\ProgramData\ntuser.pol 2014-04-10 00:37 - 2014-02-13 17:40 - 00000368 _____ () C:\Windows\Tasks\HPCeeScheduleForstudentin mama.job 2014-04-10 00:35 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-04-09 20:30 - 2014-02-13 17:40 - 00003240 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForstudentin mama 2014-04-09 20:30 - 2011-11-09 22:07 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-04-09 20:30 - 2011-10-05 12:45 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-04-09 10:43 - 2014-04-09 10:43 - 00046375 _____ () C:\Users\studentin mama\Desktop\FRST_09-04-2014_10-43-38.txt 2014-04-09 10:43 - 2014-04-09 10:43 - 00043264 _____ () C:\Users\studentin mama\Desktop\Addition.txt 2014-04-08 23:12 - 2013-06-14 08:24 - 00000000 ____D () C:\Program Files (x86)\Windows Phone 2014-04-08 02:35 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-04-07 14:04 - 2014-04-07 13:55 - 10995296 _____ (Deutsche Telekom AG, Marmiko IT-Solutions GmbH ) C:\Users\studentin mama\Downloads\netzmanager_setup.exe 2014-04-07 07:40 - 2010-07-31 19:11 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-04-07 07:40 - 2010-07-31 19:11 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-04-07 07:40 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-05 22:42 - 2014-04-05 22:42 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000(1).exe 2014-04-05 22:27 - 2014-04-05 22:27 - 02347384 _____ (ESET) C:\Users\studentin mama\Downloads\esetsmartinstaller_enu.exe 2014-04-05 08:36 - 2014-04-05 08:36 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-04-05 08:30 - 2014-04-05 08:30 - 05049344 _____ (Crawler.com ) C:\Users\studentin mama\Downloads\SpywareTerminatorSetup_3.0.0.82.exe 2014-04-05 08:30 - 2011-10-07 23:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\CrashDumps 2014-04-05 00:02 - 2011-10-04 14:15 - 00000000 ____D () C:\Windows\SHELLNEW 2014-04-05 00:01 - 2013-09-22 13:51 - 00000000 ____D () C:\AdwCleaner 2014-04-04 23:57 - 2014-04-04 23:56 - 00613200 _____ (Chip Digital GmbH) C:\Users\studentin mama\Downloads\AdwCleaner - CHIP-Downloader.exe 2014-04-04 23:06 - 2014-04-04 23:05 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\studentin mama\Downloads\mbam-setup-2.0.0.1000.exe 2014-04-04 23:06 - 2012-10-08 11:49 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-04 23:04 - 2014-04-04 23:00 - 00001420 _____ () C:\Users\studentin mama\Desktop\Rkill.txt 2014-04-04 22:59 - 2014-04-04 22:59 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\studentin mama\Downloads\wObiA.exe 2014-04-04 16:20 - 2014-04-04 16:16 - 00000000 ____D () C:\Users\studentin mama\Desktop\Documents\KWB 2014 2014-04-04 16:08 - 2014-04-03 21:35 - 00012603 _____ () C:\Users\studentin mama\Desktop\Documents\Bewertungsbögen Spezialaufgabe KWB 2014.xlsx 2014-04-03 09:51 - 2014-04-04 23:06 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-04 23:06 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-04 23:06 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-02 20:02 - 2014-04-02 20:02 - 12400098 _____ () C:\Users\studentin mama\Desktop\Die Machtergreifung in Würzburg 1933, PDF.zip 2014-04-02 20:02 - 2014-04-02 20:00 - 00000000 ____D () C:\ProgramData\InstallMate 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Packages 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Kinder\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\HomeGroupUser$ 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Torch 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo 2014-04-02 20:01 - 2014-04-02 20:01 - 00000000 ____D () C:\Users\Administrator 2014-04-02 20:01 - 2012-02-26 15:04 - 00000000 ____D () C:\Users\studentin mama\AppData\Local\Google 2014-03-31 07:02 - 2013-09-24 08:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-31 03:16 - 2014-04-09 21:46 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-09 21:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-09 21:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-09 21:46 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-30 09:57 - 2014-02-15 10:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak 2014-03-29 20:33 - 2014-03-29 20:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-03-28 23:38 - 2012-02-26 15:04 - 00004122 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-03-28 23:38 - 2012-02-26 15:04 - 00003870 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-03-22 12:02 - 2013-06-16 17:42 - 00000000 ____D () C:\ProgramData\Origin 2014-03-22 12:01 - 2013-06-16 17:41 - 00000000 ____D () C:\Program Files (x86)\Origin 2014-03-15 22:51 - 2014-02-27 22:02 - 00000000 ____D () C:\Program Files (x86)\MediaViewV1 2014-03-14 16:50 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-03-14 10:36 - 2009-07-14 06:45 - 00397528 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-03-14 00:23 - 2012-08-25 16:29 - 00000000 ____D () C:\Program Files\Microsoft Silverlight 2014-03-14 00:23 - 2012-08-25 16:29 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight Some content of TEMP: ==================== C:\Users\Gast\AppData\Local\Temp\AskSLib.dll C:\Users\Gast\AppData\Local\Temp\DivXSetup.exe C:\Users\Gast\AppData\Local\Temp\drm_dyndata_7400009.dll C:\Users\Kinder\AppData\Local\Temp\AskSLib.dll C:\Users\Kinder\AppData\Local\Temp\DivXSetup.exe C:\Users\Kinder\AppData\Local\Temp\drm_dyndata_7400009.dll C:\Users\Kinder\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\Kinder\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-09 21:16 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-04-2014 01 Ran by studentin mama at 2014-04-12 18:42:39 Running from C:\Users\studentin mama\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== 7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - ) Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.9.0.1030 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.9.0.1030 - Adobe Systems Incorporated) Hidden Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) Adobe Shockwave Player 11.5 (HKLM-x32\...\{9ECF7817-DB11-4FBA-9DF1-296A578D513A}) (Version: 11.5.7.609 - Adobe Systems, Inc) Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.) AMD USB Filter Driver (x32 Version: 1.0.15.94 - Advanced Micro Devices, Inc.) Hidden Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}) (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 9.2 - Atheros) ATI Catalyst Install Manager (HKLM\...\{11A4D79B-672C-7FFF-B5F7-B4409B1194EF}) (Version: 3.0.765.0 - ATI Technologies, Inc.) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Core Implementation (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Full New (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Light (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0416.541.8279 - ATI) Hidden Catalyst Control Center InstallProxy (x32 Version: 2010.0416.541.8279 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2010.0416.541.8279 - ATI) Hidden CCC Help Chinese Standard (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Chinese Traditional (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Czech (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Danish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Dutch (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help English (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Finnish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help French (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help German (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Greek (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Hungarian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Italian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Japanese (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Korean (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Norwegian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Polish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Portuguese (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Russian (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Spanish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Swedish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Thai (x32 Version: 2010.0416.0540.8279 - ATI) Hidden CCC Help Turkish (x32 Version: 2010.0416.0540.8279 - ATI) Hidden ccc-core-static (x32 Version: 2010.0416.541.8279 - Ihr Firmenname) Hidden ccc-utility64 (Version: 2010.0416.541.8279 - ATI) Hidden Cisco AnyConnect Secure Mobility Client (HKLM-x32\...\Cisco AnyConnect Secure Mobility Client) (Version: 3.1.05152 - Cisco Systems, Inc.) Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.05152 - Cisco Systems, Inc.) Hidden CyberLink DVD Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 7.0.3003 - CyberLink Corp.) CyberLink DVD Suite (x32 Version: 7.0.3003 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5971CA1F-6BDE-498F-952C-9F2BF94070A4}) (Version: - Microsoft) Die Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.67.2 - Electronic Arts) Diercke Globus Online (HKLM-x32\...\Diercke Globus Online) (Version: 3.1.0 - Imagon GmbH) DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.90 - DivX, LLC) DVD Menu Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}) (Version: 4.1.4121 - Hewlett-Packard) DVD Menu Pack for HP MediaSmart Video (x32 Version: 4.1.4121 - Hewlett-Packard) Hidden EPSON File Manager (HKLM-x32\...\{D02F30FB-0BC4-419A-9B9C-ADC610029B50}) (Version: 1.3.2.0 - ) EPSON Scan Assistant (HKLM-x32\...\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}) (Version: 1.10.00 - ) EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version: - SEIKO EPSON Corporation) ESU for Microsoft Windows 7 (HKLM-x32\...\{3877C901-7B90-4727-A639-B6ED2DD59D43}) (Version: 1.0.0 - Hewlett-Packard) Free YouTube to MP3 Converter version 3.11.35.1031 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.35.1031 - DVDVideoSoft Ltd.) Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Customer Experience Enhancements (x32 Version: 6.0.1.4 - Hewlett-Packard) Hidden HP Documentation (HKLM-x32\...\{E5AE53A7-1A79-4840-998F-A18042A2F568}) (Version: 1.1.1.0 - Hewlett-Packard) HP MediaSmart Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 4.1.3024 - Hewlett-Packard) HP MediaSmart Webcam (x32 Version: 4.1.3024 - Hewlett-Packard) Hidden HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.12412 - HP Photo Creations Powered by RocketLife) HP Photosmart Plus B210 series - Grundlegende Software für das Gerät (HKLM\...\{7578548C-6F40-4CBE-B5CF-9310E66557FA}) (Version: 22.50.231.0 - Hewlett-Packard Co.) HP Photosmart Plus B210 series Hilfe (HKLM-x32\...\{7F5FDEA1-D0AC-4D80-9D95-59775FCCFA40}) (Version: 140.0.54.54 - Hewlett Packard) HP Power Manager (HKLM-x32\...\{4B156358-CE9C-4E9F-8CAD-79AE86A68C60}) (Version: 1.0.3 - Hewlett-Packard Company) HP Quick Launch (HKLM-x32\...\{E342D296-DB9D-4FC7-ACB0-39926C0BFA16}) (Version: 2.1.5 - Hewlett-Packard Company) HP Setup (HKLM-x32\...\{72D90DB3-A16A-4545-B555-868471101833}) (Version: 8.1.4186.3400 - Hewlett-Packard) HP Software Framework (HKLM-x32\...\{B446137B-18A1-4FAE-B0E4-ABE8F09705F1}) (Version: 4.1.6.1 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company) HP Update (HKLM-x32\...\{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}) (Version: 5.002.006.003 - Hewlett-Packard) HP Wireless Assistant (HKLM\...\{E342EC6B-5F25-47FE-B92C-DE616149B430}) (Version: 4.0.9.0 - Hewlett-Packard) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6288.0 - IDT) IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 3.0.4.922 - IObit) iTunes (HKLM\...\{D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0}) (Version: 11.1.3.8 - Apple Inc.) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217045FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden LightScribe System Software (HKLM-x32\...\{46BA053F-57B3-4153-BDB6-D37EEC8B12D7}) (Version: 1.18.15.1 - LightScribe) Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) MarkSpace Outlook Server Version 1.0 (HKLM-x32\...\{050F5BE0-A8F6-48E1-9815-97322C1C1DC5}_is1) (Version: 1.0 - Mark/Space, Inc.) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1 - Nokia) Hidden Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1 - Nokia) Hidden Movie Theme Pack for HP MediaSmart Video (HKLM-x32\...\InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}) (Version: 4.1.4030 - Hewlett-Packard) Movie Theme Pack for HP MediaSmart Video (x32 Version: 4.1.4030 - Hewlett-Packard) Hidden Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) MyTomTom 3.2.0.700 (HKLM-x32\...\MyTomTom) (Version: 3.2.0.700 - TomTom) Nokia Connectivity Cable Driver (HKLM-x32\...\{29373274-977E-413C-A4DE-DC0F8E80C429}) (Version: 7.1.172.0 - Nokia) OpenTTD 1.1.5 (HKLM-x32\...\OpenTTD) (Version: 1.1.5 - OpenTTD) Origin (HKLM-x32\...\Origin) (Version: 9.0.14.2148 - Electronic Arts, Inc.) PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia) PDF Architect (HKLM-x32\...\{064A929A-4DE8-40CF-A901-BD40C14E4D25}) (Version: 1.1.83.9982 - pdfforge GmbH) PDFCreator (HKLM-x32\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 1.7.0 - pdfforge) Photo to Movie 5.0 (HKLM-x32\...\{FA166F42-B86E-437A-9AC3-87FCC351973C}) (Version: 5.0.704 - LQ Graphics, Inc.) PhotoPad Foto-Editor (HKLM-x32\...\PhotoPad) (Version: - NCH Software) PhotoScape (HKLM-x32\...\PhotoScape) (Version: - ) Pixillion Imagedatei-Konverter (HKLM-x32\...\Pixillion) (Version: - NCH Software) PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.3003 - CyberLink Corp.) PowerDirector (x32 Version: 8.0.3003 - CyberLink Corp.) Hidden QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.) Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.11.1127.2009 - Realtek) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30113 - Realtek Semiconductor Corp.) Recovery Manager (x32 Version: 5.5.3023 - CyberLink Corp.) Hidden RuntimeLibsVC90 (HKLM-x32\...\{F000DE4C-B6CB-4181-BAFF-EC5DA2A9C156}) (Version: 1.1.0 - Microsoft) Samsung Universal Print Driver (HKLM-x32\...\Samsung Universal Print Driver) (Version: - Samsung Electronics CO.,LTD) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) StreamTransport version: 1.0.2.2171 (HKLM-x32\...\{FA0BBB87-91A1-4BFD-9005-EB058BBA0E14}_is1) (Version: - ) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden SW-Sustainer 1.80 (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}) (Version: - Certified Publisher) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.1.6.64 - Synaptics Incorporated) Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2837594) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{D3C85176-ACCC-4AF0-817D-1BC803303B74}) (Version: - Microsoft) Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2863818) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{83B1B530-7D9E-4C6A-907F-E979CEE9C295}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2878225) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{EFF5EBA3-40AD-4859-85E7-3C1CF4F297EB}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft) Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft) Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft) Update for Microsoft Visio 2010 (KB2553444) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{799005D3-9B70-4219-AFE0-BC479614CC4D}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft) Usenet.nl (HKLM-x32\...\Usenet.nl_is1) (Version: - ) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.) VLC media player 2.1.0 (HKLM-x32\...\VLC media player) (Version: 2.1.0 - VideoLAN) Welcome Home To Windows Phone Version 2.0 (HKLM-x32\...\{4B5EBB2A-A55C-40E9-A48F-AEBFBAA90EC1}_is1) (Version: 2.0 - ) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Sync (HKLM-x32\...\{586509F0-350D-48B5-B763-9CC2F8D96C4C}) (Version: 14.0.8117.416 - Microsoft Corporation) Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp) Windows Phone app for desktop (HKLM-x32\...\{19773614-FC22-4ACC-AAA3-E6BDA81ACF92}) (Version: 1.1.2726.0 - Microsoft Corporation) Windows-Treiberpaket - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia) WinRAR 5.00 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) YTD Video Downloader 4.0 (HKLM-x32\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.0 - GreenTree Applications SRL) ==================== Restore Points ========================= 13-03-2014 23:12:51 Windows Update 14-03-2014 08:25:34 Windows Update 16-03-2014 19:46:45 Windows-Sicherung 17-03-2014 22:21:58 Windows Update 23-03-2014 18:00:21 Windows-Sicherung 30-03-2014 18:13:33 Windows-Sicherung 04-04-2014 22:09:15 Installed SpyHunter 05-04-2014 06:29:17 Removed SpyHunter 07-04-2014 05:46:26 Windows-Sicherung 08-04-2014 21:10:33 Installed Windows Phone app for desktop 09-04-2014 22:52:10 Windows Update 12-04-2014 16:34:58 Removed MSXML 4.0 SP3 Parser (KB2758694) ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-03-28 22:37 - 00002676 ____A C:\Windows\system32\Drivers\etc\hosts 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de 132.187.1.5 vpngw.uni-wuerzburg.de There are 16 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {084C9023-C4A7-4FF3-AC7B-6DD84D7E3F8F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {1790A716-CE1A-400C-A0F4-691BBA163103} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-03-21] (Hewlett-Packard) Task: {279B66BC-725F-4DD9-8E70-48F6DC9D57F7} - System32\Tasks\RecoveryCDWin7 => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-23] () Task: {3B35629C-4734-47CB-8F43-965CC631670F} - System32\Tasks\ServicePlan => C:\Program Files (x86)\Hewlett-Packard\HP Setup\RemEngine.exe [2010-05-23] () Task: {515FE178-4D0C-4794-AD74-D406592B788D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2013-12-12] (Hewlett-Packard Company) Task: {5DD226C6-5D9F-4C8F-9EE9-9DBFE719B87D} - System32\Tasks\HPCeeScheduleForstudentin mama => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05] (Hewlett-Packard) Task: {6C768DA6-4B42-42E4-AB1C-61431C712A8B} - System32\Tasks\MirageAgent => C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe [2010-06-24] (CyberLink) Task: {6CCC4DF5-B34D-4EE5-9CB4-7FC8F60576DD} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe Task: {70AAF0CA-45FA-4555-97CA-0C3C48B42415} - System32\Tasks\RunAsStdUser Task for VeohWebPlayer => C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe <==== ATTENTION Task: {71906D7C-D3F3-4602-8E27-BFF3A331D87D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {77E4D3A2-5FE6-49D7-AE63-4605C32FAD15} - System32\Tasks\{2803D596-E189-426E-830F-D9729361D990} => Firefox.exe hxxp://ui.skype.com/ui/0/5.10.0.114/de/abandoninstall?page=tsProgressBar Task: {86FD4AF1-FE07-45E5-B7E8-1FCEE2AB8E8D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {A5622CED-0E8F-469A-A502-D665DC62DE9D} - System32\Tasks\HP Photo Creations Communicator => C:\ProgramData\HP Photo Creations\Communicator.exe [2013-04-22] () Task: {A7F5448C-DB93-4167-AF41-27EDC213AF63} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {BA793CA6-9407-45A2-AA1A-CD3DD810E037} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-26] (Google Inc.) Task: {C4D720E6-5B65-4B8C-91D7-22D95A4175F0} - System32\Tasks\{565485B0-CE07-4A43-8ADE-E590F93FC96D} => C:\Program Files (x86)\Windows Phone\WindowsPhone.exe [2014-03-26] (Microsoft Corporation) Task: {D5830753-8EB7-4505-8DBA-181401A67B2C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12] (Adobe Systems Incorporated) Task: {EF1AFC9F-1B9A-46C4-A996-A26D6A5EE20E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-02-26] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HP Photo Creations Communicator.job => C:\ProgramData\HP Photo Creations\Communicator.exe Task: C:\Windows\Tasks\HPCeeScheduleForstudentin mama.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Loaded Modules (whitelisted) ============= 2013-04-19 16:52 - 2008-06-04 15:53 - 00027648 _____ () C:\Windows\System32\spd__l6.dll 2010-06-29 19:00 - 2010-06-29 19:00 - 00027192 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe 2013-04-19 16:53 - 2009-02-04 18:55 - 00548864 _____ () C:\Windows\Samsung\PanelMgr\SSMMgr.exe 2013-08-29 02:23 - 2013-08-29 02:23 - 01861968 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe 2013-04-19 16:53 - 2008-07-22 10:00 - 00306688 _____ () C:\Windows\Samsung\PanelMgr\caller64.exe 2010-03-09 15:34 - 2010-03-09 15:34 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2011-03-10 02:06 - 2011-03-10 02:06 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2010-06-18 16:26 - 2010-06-18 16:26 - 00267832 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPCommon.XmlSerializers.dll 2010-06-18 16:26 - 2010-06-18 16:26 - 00030264 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_LogicLayer.dll 2010-06-18 16:26 - 2010-06-18 16:26 - 00052280 _____ () C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HardwareAccess.dll 2013-12-13 00:36 - 2013-12-13 00:36 - 00063376 _____ () C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\zlib1.dll 2013-09-13 20:51 - 2013-09-13 20:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-09-13 20:51 - 2013-09-13 20:51 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2010-05-19 11:05 - 2010-05-19 11:05 - 02121728 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll 2010-05-19 11:05 - 2010-05-19 11:05 - 07745536 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll 2010-05-19 11:05 - 2010-05-19 11:05 - 00135168 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00019456 _____ () C:\Program Files (x86)\MyTomTom 3\DeviceDetection.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00067576 _____ () C:\Program Files (x86)\MyTomTom 3\TomTomSupporterBase.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 02302464 _____ () C:\Program Files (x86)\MyTomTom 3\QtCore4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00252408 _____ () C:\Program Files (x86)\MyTomTom 3\TomTomSupporterProxy.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00980480 _____ () C:\Program Files (x86)\MyTomTom 3\QtNetwork4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 00357888 _____ () C:\Program Files (x86)\MyTomTom 3\QtXml4.dll 2012-05-18 11:04 - 2012-05-18 11:04 - 07964160 _____ () C:\Program Files (x86)\MyTomTom 3\QtGui4.dll 2013-08-29 02:25 - 2013-08-29 02:25 - 00100688 _____ () C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll 2014-03-29 20:33 - 2014-03-29 20:33 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\studentin mama\Downloads\StudiSoft_ Bestaetigung der Bestellung 0-00001349.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== ==================== Faulty Device Manager Devices ============= Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64 Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (04/12/2014 06:21:33 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/12/2014 00:18:18 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/12/2014 00:18:12 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/11/2014 08:37:50 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 659370 Error: (04/11/2014 08:37:50 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 659370 Error: (04/11/2014 08:37:50 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/11/2014 06:59:11 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/11/2014 06:59:03 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/11/2014 06:56:59 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/10/2014 09:59:03 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 21840 System errors: ============= Error: (04/12/2014 00:09:13 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/11/2014 11:56:44 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (04/11/2014 10:06:48 PM) (Source: WMPNetworkSvc) (User: ) Description: 0x80004004-1 Error: (04/11/2014 08:37:51 PM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Error: (04/11/2014 08:37:48 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst IPBusEnum erreicht. Error: (04/11/2014 06:52:41 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/11/2014 06:30:04 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (04/10/2014 10:30:24 PM) (Source: WMPNetworkSvc) (User: ) Description: 0x80004004-1 Error: (04/10/2014 10:30:24 PM) (Source: WMPNetworkSvc) (User: ) Description: 0x80004004-1 Error: (04/10/2014 04:39:17 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "DgiVecp" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Microsoft Office Sessions: ========================= Error: (04/12/2014 06:21:33 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (04/12/2014 00:18:18 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\studentin mama\Downloads\esetsmartinstaller_enu(1).exe Error: (04/12/2014 00:18:12 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\studentin mama\Downloads\esetsmartinstaller_enu(1).exe Error: (04/11/2014 08:37:50 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 659370 Error: (04/11/2014 08:37:50 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 659370 Error: (04/11/2014 08:37:50 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (04/11/2014 06:59:11 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\studentin mama\Downloads\esetsmartinstaller_enu(1).exe Error: (04/11/2014 06:59:03 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\studentin mama\Downloads\esetsmartinstaller_enu(1).exe Error: (04/11/2014 06:56:59 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\studentin mama\Downloads\esetsmartinstaller_enu(1).exe Error: (04/10/2014 09:59:03 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 21840 ==================== Memory info =========================== Percentage of memory in use: 54% Total physical RAM: 3834.9 MB Available physical RAM: 1733.86 MB Total Pagefile: 7667.98 MB Available Pagefile: 5418.89 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:576.02 GB) (Free:442.88 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:19.86 GB) (Free:2.89 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.09 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 596 GB) (Disk ID: 7C5910A0) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=576 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=20 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=103 MB) - (Type=0C) ==================== End Of Log ============================ Code:
ATTFilter # AdwCleaner v3.023 - Bericht erstellt am 12/04/2014 um 18:54:48 # Aktualisiert 01/04/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : studentin mama - STUDENTINMAMA # Gestartet von : C:\Users\studentin mama\Downloads\adwcleaner(1).exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gelöscht : C:\Windows\System32\Tasks\ProtectedSearch ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B} ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 -\\ Mozilla Firefox v28.0 (de) [ Datei : C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\prefs.js ] Zeile gelöscht : user_pref("extensions.3Abd.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumoro[...] Zeile gelöscht : user_pref("extensions.uzAWXR.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumo[...] Zeile gelöscht : user_pref("extensions.vEWkc.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumor[...] [ Datei : C:\Users\Kinder\AppData\Roaming\Mozilla\Firefox\Profiles\4p3g7r0l.default\prefs.js ] [ Datei : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\pen71xce.default\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [40059 octets] - [22/09/2013 13:51:27] AdwCleaner[R1].txt - [21700 octets] - [24/09/2013 13:19:07] AdwCleaner[R2].txt - [2224 octets] - [12/04/2014 18:50:02] AdwCleaner[S0].txt - [36277 octets] - [22/09/2013 13:53:19] AdwCleaner[S1].txt - [21032 octets] - [24/09/2013 13:21:06] AdwCleaner[S2].txt - [2145 octets] - [12/04/2014 18:54:48] ########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2205 octets] ########## |
![]() | #2 |
![]() ![]() | ![]() zilliontoolkitusa.info versehentlich installiert - was nun?Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by studentin mama on 12.04.2014 at 21:37:20,78 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1183461899-3623103710-1707053119-1001\Software\sweetim Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011501160} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011501160} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E81CDADA-1F06-414B-A58F-396B22D1CAFD} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{E81CDADA-1F06-414B-A58F-396B22D1CAFD} ~~~ Files Successfully deleted: [File] "C:\Users\studentin mama\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\driverscanner.lnk" ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\ytd video downloader" Successfully deleted: [Folder] "C:\Users\studentin mama\appdata\locallow\datamngr" Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader" Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{02A0E2FD-A310-4EB1-A0DB-07E258CAAB0F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{038E352E-EFED-4562-B97F-9CD13A2ABC8C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{0459E172-8264-402D-A4B1-5FAC3844274D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{08BB199F-F43E-445D-A2D1-FFE13603EA1C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{0AA19462-F4EE-41CD-81E9-8A82D6495F40} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{0BBE864E-7E95-4B59-8E1D-8C946D21CF60} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{0E55CCEF-862F-4E35-8C38-46067900A56D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{0EC19D43-26BE-4839-9A69-D89AA53E0745} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{0F66DD41-50AD-45EE-B7F6-00AEAC990859} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{0FBE695B-07E6-4CC1-8224-73A1D01E4654} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{115B93AE-D4C7-4CE9-ACDD-889F06292755} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{124C58BF-BCA3-4A32-92D9-8ACA4AE04837} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{12BF63A4-0B7E-4EBA-997B-99419DFE0816} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{12DB6CBB-5F41-41CD-93D1-F81D1C3AD6AE} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{137CB873-9C52-41DC-A7CD-80CD0B9525E3} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{13AEFA96-D383-4BAE-94C2-3668C69A857C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{14193BA7-9F61-418F-AE3C-9A73B89BEAC6} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{14298F3E-DCEA-42BD-B4F0-8AB1B8D88246} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{145FA6F7-574A-4D08-B397-88D941C9C51A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{14D14741-B2E9-4F84-A743-618B15EB3D3F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{154488A0-16F5-46B2-BA18-D5594CC6E3BB} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{158C76A5-C728-4DD6-97C3-96594401667F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{15D9E4AE-BF26-409C-AE28-30370CE7F873} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1663ED33-550A-40D3-86CF-1A39AB2C6B69} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1809A831-FA33-4F9D-8830-8F9CE85273FA} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1844DCFC-B4C9-404B-B6E1-D5E7A3A56F1E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{19D8068A-356B-47C2-A0B8-133075653A17} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1A262435-1415-41F8-8A21-B6732B761425} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1B24C57E-5C33-47D4-80EF-F9B37AE47A36} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1BCF7838-7C43-4BDC-B6D5-67C073C0728C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1CFA2F24-0EDF-4F24-A495-FD216AAC40FE} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{1D3BA977-7F5A-4DAC-B9FC-728C704B5DD0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2002B22C-BD3F-4ADE-B78F-91975215B45C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2077872F-9C35-4149-BFA0-9D653E4FA5F4} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{21C31B97-01F3-41A9-81CC-03057152A7D9} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{223D7EEF-4ECB-402D-8CBF-DE13621491B8} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{22CC8BA1-B7D6-4878-97A3-38A7AB353509} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{22CDA7E1-7129-480F-B038-94C24B71F34C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{22E4537F-3466-4202-8499-3C0670BB088A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{23B5B82D-E260-4C4F-BADF-EAAA770402F8} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{254F2DE0-F6F5-4450-AF64-14D85DD6585E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{25659C91-7858-48DE-817C-847391CD4A9A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{274D4365-B6DB-4B1B-9DB0-071785E7345A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2A046954-44ED-418A-93AB-1766F926D4C4} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2AC54E9B-6B5B-4A43-9B28-22476D93E88B} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2B4A4A9A-F8BD-4932-92AB-CFF9E3623FE5} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2B7EE89F-63CD-4D04-955F-DF4E6329A0C8} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2EA98E38-F89B-4139-8D02-5CFB3B7968F0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{2EBD99FA-4483-4646-8A5D-1CB855957ACA} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{31001556-9167-4283-BDAF-F07686B72613} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{327F59A6-A909-4143-8826-5A26D6AC0A5C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{330AE5B8-3049-4B8C-9557-EBCB9FC5160D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{33C55794-13A3-4631-B163-B495D15AE4B0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{33D258DB-820C-43C1-82D6-FFAA98CE334A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{34C19671-09C4-46AE-8DB8-DBAC1017B506} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{35ACE5E6-7CE7-45F9-BBDA-7D0769DF7ABF} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{36582EFF-9905-49B3-B222-B15121ADDD6F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{38812673-0E74-40A2-B161-D419B04D58F6} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{3A3F9720-D3FC-459A-B602-14C5BE39E721} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{3B8CD7E5-F96F-41F7-BCCC-D19C4E946A14} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{3D0230D6-E83F-4D29-A20D-B42C5FF7C665} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{3DFF0888-4201-4B12-A0F6-D73435939B9B} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{3E9389C5-B4CB-4C01-B347-A21B00CEB235} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{407ECB6F-9715-4292-A68E-EC14CD7E48EB} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{4113995C-829C-4486-B56E-0F53C1364E8E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{44A6E5FC-1AA0-4B53-9C87-FB562484E267} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{45B08BB4-C984-4C09-84EE-263768CF0541} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{46414FE2-4EFA-4601-A0C1-542E27367C84} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{46DDB271-1251-4BD3-82B0-8D971D83F3C5} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{49546540-E605-4BD4-9FBF-47AD9FCC5604} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{49C16653-4443-4A9B-BFCF-AB87B51B71CB} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{4B5247BF-6523-4218-B892-05B4C86423A0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{4C49CE8F-38AE-454C-B4F5-FCCE284CB015} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{4DEFFDBE-1AE3-4C3F-9D79-2D35B88DFD83} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{50387911-095A-4EFC-AE43-7164F7FABBD1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{506F2D8D-94B3-4E69-83B1-59B7B591E3FC} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5122E9B6-E1E9-4931-A1D5-26F83E1022FB} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{52B0D05F-F06B-4C55-AA97-F8730DBB88BF} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{52C45D17-89F4-465B-96F1-FBB0BC949ABC} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{52DEB93C-28A1-4A1C-A9EE-F7F8C76B86A2} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{52ED5A83-6385-4822-9FA3-FF9A3DF14720} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5566D6C1-3058-41AD-A7B5-F6D12D37D9B0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{55D17FCD-59F0-46F1-90F7-85F31231ADCB} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{565BD5A8-EAED-4522-9AFC-F2E1FD68A250} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{580D68A1-965E-4189-A03D-EF22EC847AEE} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{58C6B8CC-B0DF-4947-9CA2-EE5E4E6F032B} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5A480E58-A1E5-4E43-8994-1D5279CCF09F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5B56935D-C196-4519-859D-078D6AAF6242} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5B7553B0-0574-4200-A858-DB1364057AE3} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5C71CDE5-BA88-4CD0-B23F-665FB922CFED} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5E3A47FB-7C22-40DF-8E79-26C5AFCA1961} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5E6B9490-737A-4E0F-B72D-ADC40C4BC65F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5EC4FF61-C9C8-4AB0-AB7B-4D806936D7CD} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5F8A15DB-FF6E-45CC-9F37-3323BBA6D49A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{5FC4C0D4-9C25-4573-B0A4-FB4C817F0BB3} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{60A3B26E-00A4-4042-B044-124A06D39CB0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{629B7CBA-CEDF-4AC0-8883-8ED642971DC8} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{639B705E-D174-4841-B77C-C90970F29A16} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6796CB4F-C2F8-473C-8C5F-19C078AF0966} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6A31ECAB-E935-45D1-AE22-9A53263BF020} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6A9C5F5E-049F-4143-B4F2-BE5BB1998A6A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6AE66D5E-148B-4C9A-9AD9-FB67DC4487B8} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6B9FDA6C-258E-4CEE-A0CC-20293BB7C0E2} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6BC8C02A-DFEB-4635-BE28-B11708A66DAD} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6BDE077C-9A68-401E-A811-61B90590B687} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6C00FB44-BC3D-4BEC-9529-AD39E2BD48D9} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6C3A5C48-D0F0-414A-B9AF-0DEB35003616} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6D5FBFA2-737E-45FC-B819-746837EF742D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6E44101C-4ED1-4BE5-9614-8BA815E4524A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6E6DBAD1-46DA-4C73-96D3-0F2F087B8521} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6E964D5B-CF32-4836-B598-EE75AFF6B598} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{6F07E6FB-A92D-4F0D-BAC2-CC825154CB46} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7191B4E7-AB25-49AE-9DC6-4A331A866206} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{71C51E57-B346-4C08-B4D2-FD335157D788} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{728C6A12-7B95-4D69-8106-B7053556DB32} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{73263724-E0D0-4B35-ADFC-A6BE6107587C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{736F297C-8746-44EC-85B1-22F3B9F46D9E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{73769986-53CB-4B9A-BC5D-693C903743EC} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{748A3FD6-DA69-42E2-BFBB-FEDFED0C13B1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{74AA5D76-0EC3-4637-B7E6-120F4EA2B824} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{74BBC947-ACFB-4CDC-9989-690F10A87BA2} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{754D9B32-2248-473B-A73E-C0120280F572} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{75727CA4-BFC0-4FA6-AC98-D9C6D2059C8D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{75B05ECE-E789-4594-BC3B-5EBA3D1BAE1A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{76ADDD4F-0825-4146-9149-69022CA1CA6C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{76C0292A-B588-4D12-B082-5F25046F4E6F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7A7F0878-F329-4E8D-9102-9006C9F0B744} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7AAFD400-7F61-494C-AB23-EBA50B26C224} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7ABE28A7-3AC7-4BBC-9784-5CDD884D6522} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7ADE89F6-F720-4125-9F3A-0E9E3B11783B} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7B2AA8F2-3D67-43BD-AB4A-6B9A56923FFC} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7CA82CFF-D981-43A2-A364-B75170DCA2F1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7CB7C89A-B1E5-464E-990C-F493784205B3} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7D6903CA-0425-43DD-8650-1CA1579EF048} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7DB602D4-9062-4122-AE5C-723BAF695EE9} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7E31A761-892A-4C59-962F-8A6CC19FD6CD} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{7E894F2F-78DC-47EC-9F4C-A8C9F757B71C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{803AB659-4DEA-4887-A9B8-DB55EE2ED92F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{80D9608E-97F3-4E0E-8C48-6C362EA5BEF1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{80FE4996-7969-4AE2-8666-F65DB2B276A0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{81485EF3-68CE-43B8-8911-4D012856839F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{821573C8-0871-4837-9B7A-A4D0817B5267} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{8226F4A4-2F5C-44BA-80CF-C79BE4801CFE} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{82C5F99B-D5B4-4368-B33D-28911247A16F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{84C00263-8699-490D-A4DA-CA2BAC6880DD} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{85F8B740-30FD-4EAF-AFA3-BBA3EA2AAB6F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{86B6A188-7D8C-4D44-B407-0701619C1055} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{87BCC59D-CCB3-41EE-A013-9377CFDE5F25} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{87E1EF1D-A9F4-4168-8CC5-33D176F1195C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{88115DB5-01AC-4FF3-B31B-FB79DE72E0A4} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{88BC7322-5DC2-4C67-A4F4-F290BEF1982F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{8BCC869A-C323-458B-9953-C3C79E153184} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{8C3F52D3-4559-4C42-9E8F-F7476B6715A9} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{8FEBEFCA-3232-439A-87F9-62BCEBBAA968} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{91DCF8C3-4631-483E-9E6B-2DFCBFCCE68E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{953D727A-C101-497C-AC50-24E09E797F94} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{9557C4CB-EC45-4951-8177-F504C7FA4C2E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{991A6FF8-90C4-4F50-B2C7-D7E5432B7A22} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{9AAC90E4-43E4-4333-93E4-E761F5A4FC25} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{9AB525C4-9D32-4F61-98E0-BA063D96FA94} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{9AD7A3AB-A716-4D2E-938A-8F648157464A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{9BFBCB0B-0F7B-4C87-81C1-E1F8BC5AEF03} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{9DEDA339-B889-47AE-8B8A-568B0A285AAE} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{9FE94E91-5057-42C7-B96A-F13D83033D78} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A0DAC39B-C5BF-4BA5-AFBE-17D5770CF505} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A1F104E4-FBF4-4965-A9D3-BA1740DAC031} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A247E458-54E5-4272-A219-FBA50267A102} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A3E0D435-B2DB-499F-B1B6-9DDC3D2D0E4D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A589CD22-F599-4F81-85F7-4CF53B56097A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A5DF7341-AA00-48CC-9AB8-7221E3835E52} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A67328F8-4208-4FEA-9321-29787BA1339B} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A7B5E627-55A0-4211-B858-C3C2B549F016} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{A85A055A-F017-4319-BA17-B9CACB38E3CA} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{AB1BEFA7-B565-49C2-9435-321DEF704E81} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{AB41E802-1C4C-48AD-B482-953835BAC953} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{AC3F2F35-0173-4484-BA1D-A0721A760977} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{AE99CF63-F540-41DB-9324-73366D4A1701} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{AEF90276-7783-4CA8-B726-DDA709E4D9A3} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{AFA9614B-EA8B-47C4-B1D5-EDB135D776A5} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B0E55AC7-268A-4C3D-9179-CC75F5B25C23} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B1282970-6AFF-47A8-91A6-9E926E2657C5} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B2C75DF7-46E8-4078-A69E-FD1A44113D97} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B2EEFE88-BC64-4B38-AC83-39640755BC47} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B3069F9F-1731-4CA0-833C-7545CADA13A6} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B484F107-E67A-4874-AEE4-9A20DA0C01ED} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B4BC29A8-C84F-4383-9A32-EF4095B62C3B} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B6C5887D-F2EB-4F22-8514-A43DB64AC68B} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B74AA794-0632-4398-B88B-61CD5515AFE4} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B8442B68-A350-4AB7-BCD2-2382C340B826} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B900F55F-5987-490E-9AE8-EF3AE57EF89C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B92F3265-DE88-49FC-B184-8B02A330991C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{B9918CFD-5E70-44A9-917D-69063B9A6A4D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{BC7747C9-15F9-4321-B1A7-F920DDF233E1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{BC7ACC2F-A2C7-47DC-B322-ABE91B6AC213} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{BDAB9038-1824-4A19-A97D-34A740C34B54} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{BED48F10-DEBA-431F-A5C4-E91D8E6ABC53} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{BEE49CD9-0450-497B-AAD4-3B0636297BE7} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C03FA0C9-A9B6-43DD-AC61-79FA9F6F380D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C0F774B2-1EC2-47C3-B5CA-4B3924CF1968} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C1860320-4BC2-4B99-A2C6-F2FC55EB96ED} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C22B5086-4FCF-48E5-9076-986B5940BE46} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C2C35CD3-ECF5-42EF-818D-FBB473EBCF03} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C49B20F0-36A6-436D-BDA7-BEAC94FD15DB} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C4E24861-1FBC-4C65-B9EB-225DF82589B6} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C688C20D-6691-47CB-BAF4-A24A7C560F44} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C74DFEED-C73D-4BAC-B1B3-55734A42C0CF} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C7CA48DA-2F73-4D68-93D2-96C44A3ADB24} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C7DE8EA8-8214-4847-9D45-60AAF555179D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C8DFDBC5-4BE7-4F24-9E23-2C1D25EF3C89} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C923D22B-B996-4125-BFA5-D71F2FB2F295} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{C9B3C4B4-875A-401D-A667-2F6F825E3431} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{CC967126-8568-42DC-B734-ED9992CDBA9D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{CCAC6FBE-2349-4852-94AC-CE97248EF43E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{CD44FC9A-7526-4F94-B1FF-89F7E9734A91} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{CD8A824F-5132-497E-B346-0F5010AA78AD} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D0124D1E-5208-4A9E-8446-13D29EE8D7D7} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D15EDB03-9D47-4D90-AB61-D778E1CAE01E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D16A4ABD-6303-4E77-9ABA-9F33AEB59B1F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D255EE71-44F4-4D2B-B9D3-3AA32BE0900A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D2821E09-6000-47CE-AFE4-27F827FE5DD0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D2E979E3-FC3E-4E4A-9A82-58ED89B8ED84} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D3DC96CC-BBA0-42EE-8D8C-C363C1BDF588} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D3FE2AD2-53CF-4E82-B70B-08ED387457C7} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D5510D9F-E135-475A-8AB5-6E8D5CEBD94A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D7002B5B-A424-43CE-8269-7235C73ACC83} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D7ADE70E-4B1F-4E21-B985-563A6B687029} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D81CC346-7B35-476B-80FE-1F687B6B57A8} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D882DF63-3ECC-4065-A349-C3EF5EA07BF6} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D8A634B2-6242-4072-881E-D8B204E8B4A6} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{D90C6C0E-5810-401E-A4F9-00E7FB540727} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{DDF05AA6-A609-4593-ABED-604DA996FF6F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{DE8DBC05-9AAD-4EDB-AD0E-160BFA873C07} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{DED6F034-621A-4799-B454-FDA0AF89007F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E126D59D-1C09-46F2-B03D-098C7595E931} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E2489F9E-1D7A-4DFF-B41A-304D73D0D34E} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E2871B5F-8575-4324-883F-7B6AB331BC85} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E35496F9-AA69-4BAE-A025-7F734227BDFB} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E3B4A5AD-873D-4C81-A2A1-5F0C13F7FA9C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E4DE8E9F-A924-4E0E-BD81-D0C91F402C9D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E519E993-47BA-470F-8A8D-65610E69C1B5} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E51A4CB6-6961-4C2D-8441-8B37F17315F1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E5F29B34-1747-49B0-A976-45794FEB613C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{E71569F7-5188-4DB9-A8F9-EF818F211230} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EA5C46AF-7E1F-45AF-801B-2DA5B0868644} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EA70C13E-B584-4F34-B52E-E72D837D5171} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EAA90C41-BC3D-4FA4-A05C-CAF79B9EA992} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EB39CAE6-81F8-43C6-A61C-D20E55D4B5C5} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EB893632-DE1B-46FF-B555-490CD9DDEEF5} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EC24284C-4D8A-4D27-9473-43C6DAB4EB78} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EC2F779B-88F2-44CE-9966-DED19F640DAF} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{ECD9A9E4-58A2-4C45-BD8F-389A5642A922} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{ED2B2E79-B397-47DE-B549-6BE1DA6ACA3C} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{ED2D7ACB-CA41-4F78-A111-B2EE213F1341} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EEC7C8BC-DC28-472E-AA65-CDA79888B227} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{EFC00404-CF81-4C59-9C14-1037FD45FA8F} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{F0959AE0-BA81-42ED-8409-F3F26C37EF09} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{F1359D8F-C0C3-44EF-B153-664959D148C1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{F5DC86FB-0B74-4065-B9CD-16D2ED8AEDC8} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{F8365730-0C35-4F57-B18D-A6C91F739919} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{F83A9603-589D-4E29-8E91-4EB910089A5D} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{F84C2BD8-2347-4D57-8366-F4CDFCF74CF1} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{F9892F2E-E098-415F-87C8-208665DA6504} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{FB6B4857-D8BD-4D7B-9974-32A7AAB447DC} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{FDDE9C7D-6631-4C06-A56E-4E21CBAAD39A} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{FEA3D5A6-E1F4-4121-B8D5-8AEF5EDB6A91} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{FEB72F40-1E51-451F-ACBE-1E9B98E23F18} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{FF2B0749-5296-46E9-9446-7E162D8F12A0} Successfully deleted: [Empty Folder] C:\Users\studentin mama\appdata\local\{FF3C4137-DB0F-467F-B430-5044C15FE7BE} ~~~ FireFox Successfully deleted: [File] C:\user.js Successfully deleted the following from C:\Users\studentin mama\AppData\Roaming\mozilla\firefox\profiles\cknca95t.default\prefs.js user_pref("extensions.3Abd.url", "hxxp://getjpi2.info/sync2/?q=hfZ9ofV9CShEAen0rjn5rihTB6lKDzt4okmxtNtVh7n0rjnEqdaGrjYErjr8tMFHhd9Fqda9rjsFqTw5rHrMDMlGojUMAe4Uojr4qjU9pjg6qHsF Emptied folder: C:\Users\studentin mama\AppData\Roaming\mozilla\firefox\profiles\cknca95t.default\minidumps [153 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 12.04.2014 at 21:59:19,19 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-04-2014 01 Ran by studentin mama at 2014-04-12 22:18:49 Run:3 Running from C:\Users\studentin mama\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\Gast\AppData\Local\Temp\*.dll C:\Users\Gast\AppData\Local\Temp\*.exe C:\Users\Kinder\AppData\Local\Temp\*.dll C:\Users\Kinder\AppData\Local\Temp\*.exe ***************** C:\Users\Gast\AppData\Local\Temp\*.dll => Moved successfully. C:\Users\Gast\AppData\Local\Temp\*.exe => Moved successfully. C:\Users\Kinder\AppData\Local\Temp\*.dll => Moved successfully. C:\Users\Kinder\AppData\Local\Temp\*.exe => Moved successfully. ==== End of Fixlog ==== |
![]() | #3 |
![]() ![]() | ![]() zilliontoolkitusa.info versehentlich installiert - was nun?Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-04-2014 01 Ran by studentin mama at 2014-04-13 22:05:28 Run:4 Running from C:\Users\studentin mama\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** FF Extension: YoutubeAdblocker - C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\mriqu@dpfrjfc.com [2014-04-02] CHR Extension: (YoutubeAdblocker) - C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\olodkgeocddnmkokdmamjnjdkdijnkgm [2014-04-02] ***************** C:\Users\studentin mama\AppData\Roaming\Mozilla\Firefox\Profiles\cknca95t.default\Extensions\mriqu@dpfrjfc.com => Moved successfully. C:\Users\studentin mama\AppData\Local\Google\Chrome\User Data\Default\Extensions\olodkgeocddnmkokdmamjnjdkdijnkgm => Moved successfully. ==== End of Fixlog ==== momentan sieht es tatsächlich so aus, als würde die Werbung verschwunden sein. Ich danke dir so sehr! Mein Problem ist, die richtige aber kostengünstige Anti-Viren-Programmierung. Ich hatte mal eine sehr genaue, leider konnte ich dann nicht mehr auf Mediatheken von privaten Fernsehsendern zugreifen. Ich habe nämlich keinen Fernseher und schaue einige Sendungen, wenn ich eben gerade Zeit dazu habe. Leider blockierte mein damaliges Programm wohl die Werbung und ich konnte das nicht abstellen. Ich kenne mich da nicht so aus. Lieber Gruß abimama |
![]() |
Themen zu zilliontoolkitusa.info versehentlich installiert - was nun? |
artikel, coupondropdown, installier, installiert, interessante, leistung, pup.optional.somoto.a, seite, seiten, spyhunter, spyhunter entfernen, suche, thema, versehentlich, virus, werbe, werbung auf jeder internetseite |