Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Fake Flash-Player Update gedownloadet :((

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 05.07.2014, 18:34   #1
JJ11
 
Fake Flash-Player Update gedownloadet :(( - Standard

Fake Flash-Player Update gedownloadet :((



Moin Moin,
Eine Freundinn von mir hat auf einer Streaming Seite ein Fake Flash-Player Update gedownloadet. Da sie dachte das dieses Update wichtig wäre.
Da hat sie mich um rat gebeten und da ich selbst ein Laie bin, bitte ich um Hilfe bei diesem Problem. Ich habe auf ihrem PC schon AdwCleaner und Anti Malwarebytes.
Beide haben was gefunden. Auch vieles schon unter quarantäne gestellt.
Doch ich glaube das da noch etwas ist. Da sie in gewissen abständen in Google Chrome eine Genesis-Offers seite öffnet ?


Vielen dank schon im Vorauf für eure hilfe


Hier die Logs

AdwCleaner:

Code:
ATTFilter
# AdwCleaner v3.214 - Bericht erstellt am 05/07/2014 um 13:56:00
# Aktualisiert 29/06/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Yasmin - YASMIN-TOSH
# Gestartet von : C:\Users\Yasmin\Downloads\adwcleaner_3.214.exe
# Option : Löschen

***** [ Dienste ] *****

[#] Dienst Gelöscht : BackupStack
Dienst Gelöscht : CltMngSvc
[#] Dienst Gelöscht : globalUpdate
[#] Dienst Gelöscht : globalUpdatem
Dienst Gelöscht : IePluginServices
Dienst Gelöscht : NewPlayerUpdaterService
Dienst Gelöscht : pcsuservice

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\IePluginServices
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewPlayer
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Elite Max
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pc speed up
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\Program Files (x86)\NewPlayer
Ordner Gelöscht : C:\Program Files (x86)\Optimizer Elite Max
Ordner Gelöscht : C:\Program Files (x86)\pc speed up
Ordner Gelöscht : C:\Program Files (x86)\Plus-HD-9.1
Ordner Gelöscht : C:\Program Files (x86)\SearchProtect
Ordner Gelöscht : C:\Program Files (x86)\SupTab
Ordner Gelöscht : C:\Program Files (x86)\fst_de_88
Ordner Gelöscht : C:\Users\Yasmin\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Yasmin\AppData\Local\NewPlayer
Ordner Gelöscht : C:\Users\Yasmin\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\Yasmin\AppData\Local\fst_de_88
Ordner Gelöscht : C:\Users\Yasmin\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\Yasmin\AppData\Roaming\InetStat
Ordner Gelöscht : C:\Users\Yasmin\AppData\Roaming\Optimizer Elite Max
Ordner Gelöscht : C:\Users\Yasmin\AppData\Roaming\VOPackage
Ordner Gelöscht : C:\Users\Yasmin\AppData\Roaming\webssearches
Ordner Gelöscht : C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Ordner Gelöscht : C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
Datei Gelöscht : C:\Users\Yasmin\Desktop\PC Speed Up.lnk
Datei Gelöscht : C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx
Datei Gelöscht : C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Datei Gelöscht : C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
Datei Gelöscht : C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
Datei Gelöscht : C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
Datei Gelöscht : C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
Datei Gelöscht : C:\Windows\Tasks\PC SpeedUp Service Deactivator.job
Datei Gelöscht : C:\Windows\System32\Tasks\PC SpeedUp Service Deactivator
Datei Gelöscht : C:\Windows\Tasks\PCHelpers_period.job
Datei Gelöscht : C:\Windows\System32\Tasks\PCHelpers_period
Datei Gelöscht : C:\Windows\Tasks\PCHelpers1st.job
Datei Gelöscht : C:\Windows\System32\Tasks\PCHelpers1st
Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-1.job
Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-1
Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-11.job
Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-11
Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-2.job
Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-2
Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-3.job
Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-3
Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-4.job
Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-4
Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-5.job
Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-5
Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-5_user.job
Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-5_user
Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-6.job
Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-6
Datei Gelöscht : C:\Windows\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-7.job
Datei Gelöscht : C:\Windows\System32\Tasks\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-7

***** [ Verknüpfungen ] *****

Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\Yasmin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Yasmin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\Yasmin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Yasmin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk

***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ainbkicbloikcngphmjfpjdemblcojdd
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [InetStat]
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [pcspeedup]
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [fst_de_88]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0060346.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0060346.BHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0060346.Sandbox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0060346.Sandbox.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B89F5C49-51DB-4974-AB5A-E25901AA339C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E9B5B0D2-D08A-49FC-8B5C-159B60BAA268}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{09B73D47-DE1A-89C6-EE3B-3DEC891DE5E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611031146}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622032246}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655035546}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666036646}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644034446}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{09B73D47-DE1A-89C6-EE3B-3DEC891DE5E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611031146}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{09B73D47-DE1A-89C6-EE3B-3DEC891DE5E4}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611031146}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{09B73D47-DE1A-89C6-EE3B-3DEC891DE5E4}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611031146}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611031146}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622032246}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655035546}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666036646}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611031146}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Daten Wiederhergestellt : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command
Schlüssel Gelöscht : HKCU\Software\genesis
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Optimizer Elite Max
Schlüssel Gelöscht : HKCU\Software\Speedchecker Limited
Schlüssel Gelöscht : HKCU\Software\Tutorials
Schlüssel Gelöscht : HKCU\Software\TutoTag
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKLM\Software\installedbrowserextensions
Schlüssel Gelöscht : HKLM\Software\NewPlayer
Schlüssel Gelöscht : HKLM\Software\Plus-HD-9.1
Schlüssel Gelöscht : HKLM\Software\PriceMeterLiveUpdate
Schlüssel Gelöscht : HKLM\Software\SearchProtect
Schlüssel Gelöscht : HKLM\Software\Speedchecker Limited
Schlüssel Gelöscht : HKLM\Software\SupDp
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\Tutorials
Schlüssel Gelöscht : HKLM\Software\webssearchesSoftware
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeSoftToday_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NewPlayer
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Elite Max_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Plus-HD-9.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\installedbrowserextensions
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Speedchecker Limited
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCSU-SL_is1
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~1.DLL
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~2.DLL

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17126

Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Google Chrome v35.0.1916.114

[ Datei : C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=ds&ts=1404551260&from=tugs&uid=TOSHIBAXMK3275GSX_22LPCSXUTXX22LPCSXUT&q={searchTerms}
Gelöscht [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325376&octid=EB_ORIGINAL_CTID&ISID=M2F425585-7467-4F98-9BF6-3BF4B16B7094&SearchSource=58&CUI=&UM=6&UP=SP298F7D06-A19A-4299-99BB-6902736674E4&q={searchTerms}&SSPV=
Gelöscht [Startup_urls] : hxxp://istart.webssearches.com/?type=hp&ts=1404551260&from=tugs&uid=TOSHIBAXMK3275GSX_22LPCSXUTXX22LPCSXUT
Gelöscht [Homepage] : hxxp://www.trovi.com/?gd=&ctid=CT3325376&octid=EB_ORIGINAL_CTID&ISID=M2F425585-7467-4F98-9BF6-3BF4B16B7094&SearchSource=55&CUI=&UM=6&UP=SP298F7D06-A19A-4299-99BB-6902736674E4&SSPV=
Gelöscht [Extension] : ainbkicbloikcngphmjfpjdemblcojdd
Gelöscht [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
Gelöscht [Extension] : flpcjncodpafbgdpnkljologafpionhb
Gelöscht [Extension] : pelmeidfhdlhlbjimpabfcbnnojbboma

*************************

AdwCleaner[R0].txt - [24473 octets] - [15/06/2014 14:19:01]
AdwCleaner[R1].txt - [21733 octets] - [05/07/2014 13:51:01]
AdwCleaner[S0].txt - [20206 octets] - [15/06/2014 14:21:27]
AdwCleaner[S1].txt - [16933 octets] - [05/07/2014 13:56:00]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [16994 octets] ##########
         
Anti Malwarebaytes

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 05.07.2014
Suchlauf-Zeit: 14:16:21
Logdatei: Ergebnisse.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.07.05.04
Rootkit Datenbank: v2014.07.03.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Yasmin

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 275750
Verstrichene Zeit: 48 Min, 32 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 3
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1288, Löschen bei Neustart, [b4342c6fa9d261d5b7bd26695da4ce32]
PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerBz174.exe, 4320, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34]
PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\wdNewPlayerE.exe, 3652, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34]

Module: 2
PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerBz174.dll, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34], 
PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerBz174.dll, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34], 

Registrierungsschlüssel: 10
PUP.Optional.WPM.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, Keine Aktion durch Benutzer, [b4342c6fa9d261d5b7bd26695da4ce32], 
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WindowsMangerProtect, In Quarantäne, [b4342c6fa9d261d5b7bd26695da4ce32], 
PUP.Optional.BrowserApp.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Browser App, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [67816a3188f3c96d399efa144db79070], 
PUP.Optional.FreeSoftToday.A, HKLM\SOFTWARE\WOW6432NODE\FST\fst_de_37, In Quarantäne, [ae3aebb0136838fe2fbee6d5b84aa957], 
PUP.Optional.PriceMeter.A, HKU\S-1-5-21-2410883006-3698484201-3815030499-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\PriceMeter, In Quarantäne, [9157cfcc1665f442b0c2646717ebfe02], 
PUP.Optional.Ciuvo.A, HKU\S-1-5-21-2410883006-3698484201-3815030499-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\ciuvo.com, In Quarantäne, [618793088cef999d4ffd4c683fc3bf41], 
PUP.Optional.SuperFish.A, HKU\S-1-5-21-2410883006-3698484201-3815030499-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com, In Quarantäne, [ba2e6f2c26550a2c0744aa0a9d6515eb], 
PUP.Optional.NewPlayer.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\A6163528-B826-5EA9-5BC2-B379600F4AB8, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], 
PUP.Optional.NewPlayer.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NewPlayer, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], 

Registrierungswerte: 1
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2410883006-3698484201-3815030499-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|BlockAndSurf, C:\Program Files (x86)\BlockAndSurf-soft\BlockAndSurf.exe, In Quarantäne, [539578239dde44f2d426dbde36cc2fd1]

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 8
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.Extutil.A, C:\Users\Yasmin\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B, In Quarantäne, [64845447d6a54ee8dd4011a02cd6fa06], 
PUP.Optional.Managera.A, C:\Users\Yasmin\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42, In Quarantäne, [7b6d6c2fff7c42f4ad71664bf11154ac], 
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Löschen bei Neustart, [16d2fba0a6d54de92706e0d1dd25d828], 
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, In Quarantäne, [16d2fba0a6d54de92706e0d1dd25d828], 
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [16d2fba0a6d54de92706e0d1dd25d828], 
PUP.Optional.FreeSoftwareToday.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FrEeSoFtOdAy, In Quarantäne, [5a8eb4e78deea78ffc5c961b32d0bc44], 
PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34], 

Dateien: 90
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Löschen bei Neustart, [b4342c6fa9d261d5b7bd26695da4ce32], 
PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsa4B4D.exe, In Quarantäne, [58909cff532890a6b0a855331ee36b95], 
PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nseCD65.exe, In Quarantäne, [9d4b85161566b383abad40481ce539c7], 
PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nseF7AD.exe, In Quarantäne, [f9efc4d787f49c9a48103850976aa060], 
PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsj5CC4.exe, In Quarantäne, [95536734fa814fe74414691f2ad702fe], 
PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsjEF43.exe, In Quarantäne, [82666b30433854e24f091f694bb6e020], 
PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nskA2F9.exe, In Quarantäne, [09df9b00d9a2b77fc395a8e0c33ebe42], 
PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsp964B.exe, In Quarantäne, [f8f0504b0378f244bc9c9eea31d06799], 
PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nspBBA9.exe, In Quarantäne, [0ddbc9d2bebd88aeb4a40286cc3529d7], 
PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsu4968.exe, In Quarantäne, [1bcde4b78eede05641171672a8594bb5], 
PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsu4E14.exe, In Quarantäne, [8d5b83186813fa3ce2766721fa0706fa], 
PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsu5413.exe, In Quarantäne, [14d49209a6d5033376e267216e93b749], 
PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\nsv2F15.exe, In Quarantäne, [86627a21fb80c670c692becacc35c63a], 
PUP.Optional.SearchProtect.A, C:\Users\Yasmin\AppData\Local\Temp\nszF0C8.tmp, In Quarantäne, [3eaa6239a9d2ba7c3745c5cdf80917e9], 
PUP.Optional.SearchProtect.A, C:\Users\Yasmin\AppData\Local\Temp\nsjACD6\SpSetup.exe, In Quarantäne, [7d6b504bb5c689ad8bf12a6853ae08f8], 
PUP.Optional.SearchProtect.A, C:\Users\Yasmin\AppData\Local\Temp\nsjB68\SpSetup.exe, In Quarantäne, [f6f24853d4a783b31b619ef49d64936d], 
PUP.Optional.SkyTech.A, C:\Users\Yasmin\AppData\Local\Temp\7473461\7473461.zipDir\alilog.dll, In Quarantäne, [bd2b1a81582346f00f1e2909fd03eb15], 
PUP.Optional.V9.A, C:\Users\Yasmin\AppData\Local\Temp\7473461\7473461.zipDir\qSE.exe, In Quarantäne, [bb2df6a5e596c76f2ca03e0af20eac54], 
PUP.Optional.Skytech.A, C:\Users\Yasmin\AppData\Local\Temp\7473461\7473461.zipDir\UninstallManager.exe, In Quarantäne, [09df475484f761d5606597f49071b54b], 
PUP.Optional.IePluginService.A, C:\Users\Yasmin\AppData\Local\Temp\7473461\7473461.zipDir\tmp\SupTab_Setup302.exe, In Quarantäne, [ac3cf3a8f78460d67b1f64f816ebcb35], 
PUP.Optional.WpManager, C:\Users\Yasmin\AppData\Local\Temp\7473461\7473461.zipDir\tmp\wpm_v18.8.0.304.exe, In Quarantäne, [05e3d6c5b0cb2b0bab6a5314aa57dc24], 
PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\7Dtmp\spidentifierimpl.exe, In Quarantäne, [29bfcbd083f8f442427f66236899c838], 
PUP.Optional.NewPlayer.A, C:\Users\Yasmin\AppData\Local\Temp\8965tmp\newvideoplayersetup.exe, In Quarantäne, [d216e6b5e29942f4d5fbceb62cd507f9], 
PUP.Optional.FreeSoft, C:\Users\Yasmin\AppData\Local\Temp\8A61tmp\freesofttoday.exe, In Quarantäne, [24c48b107cffc86e63522956dc25926e], 
PUP.Optional.Conduit.A, C:\Users\Yasmin\AppData\Local\Temp\DLG\exe\conduit-ltd-ultra-search-protect-1.0-de-de\sp-downloader.exe, In Quarantäne, [5098f2a93942b3830cc5fd25bd44669a], 
PUP.Optional.Wajam.A, C:\Users\Yasmin\AppData\Local\Temp\is45637729\7414018_stp\wajam_download.exe, In Quarantäne, [3eaad5c62952221410ef73d3fe02649c], 
PUP.Optional.PriceMeter.A, C:\Users\Yasmin\AppData\Local\Temp\is45637729\9922322_stp\pm.exe, In Quarantäne, [2abed0cbb6c5f73fb54a691e2fd2758b], 
PUP.Optional.SearchHijacker.A, C:\Users\Yasmin\AppData\Local\Temp\8BF9tmp\lly_webssearches.exe, In Quarantäne, [f4f43764374479bdabf1c4d09e6326da], 
PUP.Optional.OutBrowse, C:\Users\Yasmin\Downloads\setup.exe, In Quarantäne, [f0f83f5c7803d95dc0c8c9b45aa78977], 
PUP.Optional.DomaIQ, C:\Users\Yasmin\Downloads\Java (1).exe, In Quarantäne, [1eca603bcbb0c3735331182a5ca4e917], 
PUP.Optional.DomaIQ, C:\Users\Yasmin\Downloads\Java (2).exe, In Quarantäne, [eafe9506f883d85e8afa6ad8ef11827e], 
PUP.Optional.BundleInstaller.A, C:\Users\Yasmin\Downloads\Java.exe, In Quarantäne, [cb1dd4c7b8c36ec85f6372d9f9080bf5], 
PUP.Optional.Downloader, C:\Users\Yasmin\Downloads\Player (1).exe, In Quarantäne, [4b9dddbe512aa492a032820642c28d73], 
PUP.Optional.OptimumInstaller.A, C:\Users\Yasmin\Downloads\Player-Chrome.exe, In Quarantäne, [5593afecdaa10333cd28c48f4fb2c23e], 
PUP.Optional.Downloader, C:\Users\Yasmin\Downloads\Player.exe, In Quarantäne, [43a5eead4635bb7b19b9662293710ef2], 
PUP.Optional.RegCleanPro, C:\Users\Yasmin\Downloads\regclean_my582531.exe, In Quarantäne, [d51362393546c076e5bdee46fb059b65], 
PUP.Optional.DomaIQ, C:\Users\Yasmin\Downloads\Setup (1).exe, In Quarantäne, [fcec5942ec8faa8c23ae6eda42be659b], 
PUP.Optional.DomaIQ, C:\Users\Yasmin\Downloads\Setup (5).exe, In Quarantäne, [70781f7c4f2c6cca6e632b1db050827e], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\background.html, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\1293297481.mxaddon, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\360-60346.crx, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\60346.crx, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\60346.xpi, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\bgNova.html, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App-bg.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App-bho.dll, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App-bho64.dll, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App-codedownloader.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App-nova.dll, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App-nova.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App-novainstaller.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Browser App.ico, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-11.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-2.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-3.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-4.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-5.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\ef05a80e-b2ff-41e3-a6df-d7629cff6aa9.crx, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\Uninstall.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.BrowserApp.A, C:\Program Files (x86)\Browser App\utils.exe, In Quarantäne, [42a68d0e99e2ff370c07f8ba45bd7d83], 
PUP.Optional.NewPlayer.A, C:\Windows\System32\Tasks\NewPlayer Update, In Quarantäne, [b4340e8d6e0dde587f85a51009f9956b], 
PUP.Optional.NewPlayer.A, C:\Windows\System32\Tasks\NewPlayer_wd, In Quarantäne, [17d15249166562d453b23e777c861ce4], 
PUP.Optional.Ciuvo.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage, In Quarantäne, [31b7abf01d5ee74fdd3b15a4649e17e9], 
PUP.Optional.Ciuvo.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage-journal, In Quarantäne, [796f9506740750e6dc3cb306cd359868], 
PUP.Optional.BetterDeals.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage, In Quarantäne, [8c5c42592a51dd591cbf1e9c1ee4ae52], 
PUP.Optional.BetterDeals.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage-journal, In Quarantäne, [a7418b1088f38da9538802b88c76a759], 
PUP.Optional.SelectNGo.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage, In Quarantäne, [ac3c3b6082f9ba7c2f951e9e06fc8878], 
PUP.Optional.SelectNGo.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage-journal, In Quarantäne, [c820445738438da9428207b509f9bc44], 
PUP.Optional.NewPlayer.A, C:\Windows\Tasks\NewPlayer Update.job, In Quarantäne, [816714871c5fef471da807b61ae859a7], 
PUP.Optional.NewPlayer.A, C:\Windows\Tasks\NewPlayer_wd.job, In Quarantäne, [feeaa3f8dc9f9d9916b0c1fc5ba78779], 
PUP.Optional.Superfish.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, In Quarantäne, [b8308615f18a56e09782457bbe44c63a], 
PUP.Optional.Superfish.A, C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, In Quarantäne, [a7415a411764b87ec2579e22e022a15f], 
PUP.Optional.Extutil.A, C:\Users\Yasmin\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\bk.js, In Quarantäne, [64845447d6a54ee8dd4011a02cd6fa06], 
PUP.Optional.Extutil.A, C:\Users\Yasmin\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\cs.js, In Quarantäne, [64845447d6a54ee8dd4011a02cd6fa06], 
PUP.Optional.Extutil.A, C:\Users\Yasmin\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\manifest.json, In Quarantäne, [64845447d6a54ee8dd4011a02cd6fa06], 
PUP.Optional.Managera.A, C:\Users\Yasmin\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\cs.js, In Quarantäne, [7b6d6c2fff7c42f4ad71664bf11154ac], 
PUP.Optional.Managera.A, C:\Users\Yasmin\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\manifest.json, In Quarantäne, [7b6d6c2fff7c42f4ad71664bf11154ac], 
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-07-05[11-09-17-175].log, In Quarantäne, [16d2fba0a6d54de92706e0d1dd25d828], 
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [16d2fba0a6d54de92706e0d1dd25d828], 
PUP.Optional.FreeSoftwareToday.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FrEeSoFtOdAy\Freesofttoday.lnk, In Quarantäne, [5a8eb4e78deea78ffc5c961b32d0bc44], 
PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\174.dat, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], 
PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\a.db, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], 
PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\b.db, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], 
PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\Uninstall.exe, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], 
PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerBz174.bin, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], 
PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerBz174.dll, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34], 
PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerBz174.exe, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34], 
PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerBz174.ini, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], 
PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\v01NewPlayerR06.exe, In Quarantäne, [6e7aa1fa0a714de9982b5160bf43cc34], 
PUP.Optional.NewPlayer.A, C:\Program Files (x86)\v01NewPlayer\wdNewPlayerE.exe, Löschen bei Neustart, [6e7aa1fa0a714de9982b5160bf43cc34], 

Physische Sektoren: 0
(No malicious items detected)


(end)
         

Alt 05.07.2014, 18:40   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Fake Flash-Player Update gedownloadet :(( - Standard

Fake Flash-Player Update gedownloadet :((



hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________

__________________

Alt 05.07.2014, 18:57   #3
JJ11
 
Fake Flash-Player Update gedownloadet :(( - Standard

Fake Flash-Player Update gedownloadet :((



Moin,
Alles klar hier die Posts

Addition .txt
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-07-2014 01
Ran by Yasmin at 2014-07-05 19:50:40
Running from C:\Users\Yasmin\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: McAfee  Anti-Virus und Anti-Spyware (Enabled - Up to date) {86355677-4064-3EA7-ABB3-1B136EB04637}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee  Anti-Virus und Anti-Spyware (Enabled - Up to date) {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee  Firewall (Enabled) {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

==================== Installed Programs ======================

Adobe Flash Player 11 ActiveX (HKLM-x32\...\{41042E28-CCA1-4147-869F-9E928B38F04C}) (Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader 9.4.0 - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-A94000000001}) (Version: 9.4.0 - Adobe Systems Incorporated)
AMD Media Foundation Decoders (Version: 1.0.60628.2255 - ATI Technologies Inc.) Hidden
AMD VISION Engine Control Center (x32 Version: 2011.0628.2340.40663 - Ihr Firmenname) Hidden
ATI Catalyst Install Manager (HKLM\...\{6167672A-758D-9960-C32C-47A15E180A70}) (Version: 3.0.829.0 - ATI Technologies, Inc.)
Audials (HKLM-x32\...\{DA6EBFC9-8869-4B61-8D38-2668A395C5B0}) (Version: 11.0.54400.0 - Audials AG)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bejeweled 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2011.0628.2340.40663 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2011.0628.2340.40663 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2011.0628.2340.40663 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Czech (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Danish (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Dutch (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help English (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Finnish (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help French (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help German (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Greek (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Italian (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Japanese (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Korean (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Polish (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Russian (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Spanish (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Swedish (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Thai (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
CCC Help Turkish (x32 Version: 2011.0628.2339.40663 - ATI) Hidden
ccc-utility64 (Version: 2011.0628.2340.40663 - ATI) Hidden
Chicken Invaders 3 - Revenge of the Yolk (x32 Version: 2.2.0.95 - WildTangent) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden
FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden
Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.0 - Google Inc.) Hidden
High-Definition Video Playback (x32 Version: 7.3.10900.8.0 - Nero AG) Hidden
InetStat (HKCU\...\InetStat) (Version: 0.4 - InetStat)
Insaniquarium Deluxe (x32 Version: 2.2.0.97 - WildTangent) Hidden
Java Auto Updater (x32 Version: 2.0.2.1 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 20 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216020FF}) (Version: 6.0.200 - Sun Microsystems, Inc.)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
McAfee Internet Security (HKLM-x32\...\MSC) (Version: 11.0.678 - McAfee, Inc.)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.5128.5002 - Microsoft Corporation)
Microsoft PowerPoint Viewer (HKLM-x32\...\{95140000-00AF-0407-0000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Primary Interoperability Assemblies 2005 (HKLM-x32\...\{2C303EE0-A595-3543-A71A-931C7AC40EDE}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Name (HKCU\...\name_07050906) (Version:  - )
Nero 10 Movie ThemePack Basic (x32 Version: 10.6.10000.1.0 - Nero AG) Hidden
Nero BackItUp 10 (HKLM-x32\...\{68AB6930-5BFF-4FF6-923B-516A91984FE6}) (Version: 5.8.10900.8.100 - Nero AG)
Nero BackItUp 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden
Nero BurnRights 10 (HKLM-x32\...\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.4.10400.2.100 - Nero AG)
Nero BurnRights 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden
Nero Control Center 10 (x32 Version: 10.6.12700.0.7 - Nero AG) Hidden
Nero ControlCenter 10 Help (CHM) (x32 Version: 10.6.10800 - Nero AG) Hidden
Nero Core Components 10 (x32 Version: 2.0.20000.9.12 - Nero AG) Hidden
Nero Express 10 (HKLM-x32\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.6.10700.5.100 - Nero AG)
Nero Express 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden
Nero InfoTool 10 (HKLM-x32\...\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.4.10300.1.100 - Nero AG)
Nero InfoTool 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden
Nero Kwik Media (HKLM-x32\...\{1F7D9F37-C39C-486C-BDF8-8F440FFB3352}) (Version: 1.6.15100.59.100 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM-x32\...\{2063D199-D79F-471A-9019-9E647296394D}) (Version: 10.6.10300 - Nero AG)
Nero RescueAgent 10 (HKLM-x32\...\{E337E787-CF61-4B7B-B84F-509202A54023}) (Version: 3.6.10500.3.100 - Nero AG)
Nero RescueAgent 10 Help (CHM) (x32 Version: 10.6.10800 - Nero AG) Hidden
Nero StartSmart 10 (HKLM-x32\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.6.10500.3.100 - Nero AG)
Nero StartSmart 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden
Nero Update (HKLM-x32\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.10900.31.0 - Nero AG)
NeroKwikMedia Help (CHM) (x32 Version: 10.6.10900 - Nero AG) Hidden
OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation)
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
PriceMeter Express (remove only) (HKCU\...\PriceMeter Express) (Version: 7.7.0.0 - PriceMeter Express) <==== ATTENTION
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.30.1019.2010 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6241 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30123 - Realtek Semiconductor Corp.)
Realtek WLAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4fed-B2B9-173001290E16}) (Version: 2.00.0016 - REALTEK Semiconductor Corp.)
Skype Click to Call (HKLM-x32\...\{BB285C9F-C821-4770-8970-56C4AB52C87E}) (Version: 7.2.15747.10003 - Microsoft Corporation)
Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
Slingo Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.1.16.0 - Synaptics Incorporated)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.29947 - TeamViewer)
TOSHIBA Assist (HKLM-x32\...\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}) (Version: 4.01.00 - TOSHIBA CORPORATION)
TOSHIBA Bulletin Board (HKLM-x32\...\InstallShield_{43DBC64B-3DD1-47E2-8788-D3C3B110C574}) (Version: 2.1.10.64 - TOSHIBA Corporation)
TOSHIBA Bulletin Board (Version: 2.1.10.64 - TOSHIBA Corporation) Hidden
TOSHIBA ConfigFree (HKLM-x32\...\{F52618B2-A995-4F8D-A6C8-9E235A470C68}) (Version: 8.0.36 - TOSHIBA CORPORATION)
TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.4 for x64 - TOSHIBA Corporation)
TOSHIBA Face Recognition (HKLM-x32\...\InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}) (Version: 3.1.3.64 - TOSHIBA Corporation)
TOSHIBA Face Recognition (Version: 3.1.3.64 - TOSHIBA Corporation) Hidden
TOSHIBA Flash Cards Support Utility (HKLM-x32\...\InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}) (Version: 1.63.0.11C - TOSHIBA CORPORATION)
TOSHIBA Flash Cards Support Utility (x32 Version: 1.63.0.11C - TOSHIBA CORPORATION) Hidden
TOSHIBA Hardware Setup (HKLM-x32\...\InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}) (Version: 1.63.0.34C - TOSHIBA CORPORATION)
TOSHIBA Hardware Setup (x32 Version: 1.63.0.34C - TOSHIBA CORPORATION) Hidden
TOSHIBA HDD/SSD Alert (HKLM-x32\...\InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: 3.1.64.6 - TOSHIBA Corporation)
TOSHIBA HDD/SSD Alert (Version: 3.1.64.6 - TOSHIBA Corporation) Hidden
TOSHIBA HDD/SSD Alert (x32 Version: 3.1.64.6 - TOSHIBA Corporation) Hidden
Toshiba Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.02 - TOSHIBA)
TOSHIBA Media Controller (HKLM-x32\...\{983CD6FE-8320-4B80-A8F6-0D0366E0AA22}) (Version: 1.0.80.8.64 - TOSHIBA CORPORATION)
TOSHIBA Online Product Information (HKLM-x32\...\{2290A680-4083-410A-ADCC-7092C67FC052}) (Version: 4.01.0000 - TOSHIBA)
TOSHIBA Places Icon Utility (HKLM-x32\...\{461F6F0D-7173-4902-9604-AB1A29108AF2}) (Version: 1.1.0.12 - TOSHIBA Corporation)
TOSHIBA Recovery Media Creator (HKLM\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.0.5 x64 - TOSHIBA Corporation)
TOSHIBA Recovery Media Creator Reminder (HKLM-x32\...\InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}) (Version: 1.00.0019 - TOSHIBA)
TOSHIBA Recovery Media Creator Reminder (x32 Version: 1.00.0019 - TOSHIBA) Hidden
TOSHIBA ReelTime (HKLM-x32\...\InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C}) (Version: 1.7.17.64 - TOSHIBA Corporation)
TOSHIBA ReelTime (Version: 1.7.17.64 - TOSHIBA Corporation) Hidden
TOSHIBA Service Station (HKLM-x32\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.1.45 - TOSHIBA)
TOSHIBA Supervisor Password (x32 Version: 1.63.51.2C - TOSHIBA CORPORATION) Hidden
TOSHIBA Supervisorkennwort (HKLM-x32\...\InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}) (Version: 1.63.51.2C - TOSHIBA CORPORATION)
TOSHIBA TEMPRO (HKLM-x32\...\{F082CB11-4794-4259-99A1-D91BA762AD15}) (Version: 3.35 - Toshiba Europe GmbH)
TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.3.22.64 - TOSHIBA Corporation)
TOSHIBA Value Added Package (Version: 1.3.22.64 - TOSHIBA Corporation) Hidden
TOSHIBA Value Added Package (x32 Version: 1.3.22.64 - TOSHIBA Corporation) Hidden
TOSHIBA Web Camera Application (HKLM-x32\...\InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}) (Version: 1.1.5.7 - TOSHIBA Corporation)
TOSHIBA Web Camera Application (x32 Version: 1.1.5.7 - TOSHIBA Corporation) Hidden
TOSHIBA Wireless LAN Indicator (HKLM-x32\...\{5BA99779-6E12-49EF-BE49-F35B1EDB4DF9}) (Version: 1.0.4 - TOSHIBA CORPORATION)
TRORMCLauncher (HKLM-x32\...\InstallShield_{E65C7D8E-186D-484B-BEA8-DEF0331CE600}) (Version:  - )
TRORMCLauncher (Version: 1.0.0.10 - TOSHIBA) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
Utility Common Driver (x32 Version: 1.0.52.2C - TOSHIBA) Hidden
webssearches uninstall (HKLM-x32\...\webssearches uninstall) (Version:  - webssearches) <==== ATTENTION
Wedding Dash 2 - Rings Around the World (x32 Version: 2.2.0.95 - WildTangent) Hidden
WildTangent Games App (Toshiba Games) (x32 Version: 4.0.5.5 - WildTangent) Hidden
WildTangent-Spiele (HKLM-x32\...\WildTangent toshiba Master Uninstall) (Version: 1.0.2.5 - WildTangent)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Zuma Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden

==================== Restore Points  =========================

15-05-2014 11:37:51 Windows Update
11-06-2014 20:15:51 OpenOffice 4.1.0 wird installiert
11-06-2014 21:53:04 RegClean Pro Mi, Jun 11, 14  23:52
12-06-2014 10:41:51 Windows Update
14-06-2014 12:44:17 Windows Update
14-06-2014 14:58:42 Wiederherstellungsvorgang
15-06-2014 12:37:01 OpenOffice 4.1.0 wird entfernt
15-06-2014 13:40:14 OpenOffice 4.1.0 wird installiert
05-07-2014 11:20:25 Gerätetreiber-Paketinstallation: RapidSolution Software Audio-, Video- und Gamecontroller
05-07-2014 11:24:55 Gerätetreiber-Paketinstallation: Audials AG Netzwerkdienst

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {06E604A3-0060-42D7-98AF-F503FE6AC481} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-4 No Task File <==== ATTENTION
Task: {136333E3-4E4F-4FC9-A20C-DAC370FF8645} - System32\Tasks\ehhiar => C:\Users\Yasmin\AppData\Local\ehhiar.bat [2014-07-05] ()
Task: {1916F79D-C406-4C2A-87BE-9BEA0F85C8A1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {23919E98-98B7-4612-A70D-2781033B29D3} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-5_user No Task File <==== ATTENTION
Task: {2443E6AC-280A-4521-8BA9-FE27A197B1FE} - \pricemeterdownloader No Task File <==== ATTENTION
Task: {2D20B108-4C81-49DC-A067-DD69D760024D} - \APSnotifierPP1 No Task File <==== ATTENTION
Task: {2F6FC6E0-BDA4-4786-B431-6B73835BF5EA} - \APSnotifierPP2 No Task File <==== ATTENTION
Task: {2FA34A0E-950A-4570-ABFA-B293D4CBC08A} - \pricemetertask No Task File <==== ATTENTION
Task: {35AFF216-5C1D-4DD8-AF79-7CEEBDEC3000} - \pricemeterwatcher No Task File <==== ATTENTION
Task: {4182C2DA-65CC-4C7E-AA9A-D812EAD426B0} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-2 No Task File <==== ATTENTION
Task: {420E0743-FC1C-4E5C-B566-57317858FFD7} - \BlockAndSurf_wd No Task File <==== ATTENTION
Task: {481D3BE3-B678-4DF8-9FD3-6A0E61A72164} - \RegClean Pro_UPDATES No Task File <==== ATTENTION
Task: {4AF40711-0CE9-4F32-8C04-3BBC8D805ADF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {527586D9-6647-490C-BB46-B133425C3ACD} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-11 No Task File <==== ATTENTION
Task: {58F88E88-2174-4827-B296-1294F654FC43} - System32\Tasks\mrxota => C:\Users\Yasmin\AppData\Local\mrxota.bat [2014-07-05] ()
Task: {60053A6E-1599-4F39-8B18-E564FBAEE7F4} - \c0dea5a2-14ac-4e72-9483-1db7a1278170-5 No Task File <==== ATTENTION
Task: {62B5BFE8-2F70-4EF0-A5E0-2DE2EF6A24F7} - \PC SpeedUp Service Deactivator No Task File <==== ATTENTION
Task: {6E2F1320-239B-41DD-BF1A-2803A16C23C5} - \RegClean Pro_DEFAULT No Task File <==== ATTENTION
Task: {7F94A7B6-A38B-4525-8CC9-D733F281FA19} - \PCHelpers_period No Task File <==== ATTENTION
Task: {81AE58A0-2399-405B-A53F-25D4BBAA97C1} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-7 No Task File <==== ATTENTION
Task: {820C3ADA-160F-4285-AA42-14841F0E5317} - \2754ae73-35dd-4fab-a5ea-1ed8f35dbfa2-5 No Task File <==== ATTENTION
Task: {872FDB1D-7F86-493D-AA0D-C55D648E2BC3} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-6 No Task File <==== ATTENTION
Task: {924CF1A4-4437-44BB-8DF6-C31004F8EE7D} - \RegClean Pro No Task File <==== ATTENTION
Task: {A008EB6B-7033-480E-85F8-5ED34D7F8D30} - \2754ae73-35dd-4fab-a5ea-1ed8f35dbfa2-7 No Task File <==== ATTENTION
Task: {A2EE9636-E20A-44C3-8229-34B65AC0A9FA} - \2754ae73-35dd-4fab-a5ea-1ed8f35dbfa2-11 No Task File <==== ATTENTION
Task: {AEF506D8-63E9-4D64-8C1E-168E8A735889} - \globalUpdateUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {B2CC710F-DE94-4F17-8F20-10EFDCD2EF20} - \2754ae73-35dd-4fab-a5ea-1ed8f35dbfa2-3 No Task File <==== ATTENTION
Task: {B6FDB691-13F1-4767-8B4B-DFE48575496B} - System32\Tasks\ConfigFree Startup Programs => C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe [2010-12-03] (TOSHIBA CORPORATION)
Task: {B8A9FA13-C00E-411D-9CFC-5A67DCE25F43} - System32\Tasks\cfkxbi => C:\Users\Yasmin\AppData\Local\cfkxbi.bat
Task: {C348F5EE-A56D-4FDC-BBED-6932E8F64515} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-1 No Task File <==== ATTENTION
Task: {C3F48DA6-7138-4F60-ADAB-EF932888B004} - \APSnotifierPP3 No Task File <==== ATTENTION
Task: {CBE11B04-EA35-4FB0-8819-9C0B168EBF64} - \PC Speed Maximizer Schedule No Task File <==== ATTENTION
Task: {CEF5DE98-827C-4379-8AB5-533B9A49E361} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-5 No Task File <==== ATTENTION
Task: {D1674CDA-B710-4E1C-8D72-3ABBACDECF6D} - \ef05a80e-b2ff-41e3-a6df-d7629cff6aa9-3 No Task File <==== ATTENTION
Task: {D5C0943F-768E-443B-86D2-5BDBBD8F3FB6} - \PCHelpers1st No Task File <==== ATTENTION
Task: {D9289FDC-4274-4E77-BC6F-912CFB899264} - \2754ae73-35dd-4fab-a5ea-1ed8f35dbfa2-4 No Task File <==== ATTENTION
Task: {DB9D1B70-CE94-4A7F-BAAA-8833D13DC225} - \Advanced System Protector_startup No Task File <==== ATTENTION
Task: {E15AE0B3-953E-4E0C-8AF0-7932194AFF0D} - System32\Tasks\qscfhzbe => C:\Users\Yasmin\AppData\Local\qscfhzbe.bat [2014-07-05] ()
Task: {E360B299-6C01-49ED-ADDD-D67C24EA7E2C} - \globalUpdateUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {EB449933-DD80-494E-A2CD-067D7CD195CE} - System32\Tasks\PerfMonitor_strtp => C:\Program Files (x86)\Optimizer Elite Max\PerformanceMonitor.exe <==== ATTENTION
Task: {F21A0ABE-F58A-4E44-8B68-9A69399385B8} - \BlockAndSurf Update No Task File <==== ATTENTION
Task: {F532E7DC-EF91-4B0A-A8A3-6670BC98A06B} - System32\Tasks\elsbix => C:\Users\Yasmin\AppData\Local\elsbix.bat [2014-07-05] ()
Task: {F5F105CF-F79C-4AD5-AC66-A5B23088C06C} - System32\Tasks\cmelajsb => C:\Users\Yasmin\AppData\Local\cmelajsb.bat [2014-07-05] ()
Task: {F936F827-7CB5-4007-9ACA-5C6E41F99714} - \2754ae73-35dd-4fab-a5ea-1ed8f35dbfa2-2 No Task File <==== ATTENTION
Task: {FD4DE7E6-85D5-4B87-81DD-2D2CF744030F} - System32\Tasks\difkadc => C:\Users\Yasmin\AppData\Local\difkadc.bat [2014-07-05] ()
Task: {FD825BD4-8052-4198-9B4C-500A76D2A480} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-11] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\PerfMonitor_strtp.job => C:\Program Files (x86)\Optimizer Elite Max\PerformanceMonitor.exe <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2011-03-03 23:21 - 2011-03-03 23:21 - 03420584 _____ () C:\Program Files\TOSHIBA\BulletinBoard\TosNcUi.dll
2010-10-28 15:27 - 2010-10-28 15:27 - 09468728 _____ () C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll
2010-10-28 15:27 - 2010-10-28 15:27 - 00053560 _____ () C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnZ.dll
2010-10-28 15:27 - 2010-10-28 15:27 - 00019256 _____ () C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnF10.dll
2010-10-28 15:27 - 2010-10-28 15:27 - 00019256 _____ () C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnF11.dll
2011-08-22 11:10 - 2010-08-31 15:21 - 00017272 _____ () C:\Program Files\TOSHIBA\TOSHIBA Assist\NotifyX.dll
2009-03-12 20:08 - 2009-03-12 20:08 - 00048640 _____ () C:\Program Files (x86)\Toshiba\PCDiag\NotifyPCD.dll
2009-07-25 17:38 - 2009-07-25 17:38 - 00017800 _____ () C:\Program Files\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll
2011-08-22 11:27 - 2011-02-22 11:16 - 00559104 _____ () C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\de\Humphrey.resources.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 02208520 _____ () C:\Program Files (x86)\Audials\Audials 11\AudialsNotifier.exe
2011-08-22 11:51 - 2011-08-02 15:56 - 00022400 _____ () C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\de\TosDILangPack.resources.dll
2011-08-22 11:51 - 2011-08-02 15:56 - 00063360 _____ () C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIInternal.XmlSerializers.dll
2014-07-05 11:06 - 2014-07-05 11:07 - 02990080 _____ () C:\Users\Yasmin\AppData\Local\name_07050906\name_07050906.exe
2011-06-29 00:38 - 2011-06-29 00:38 - 00243712 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2011-03-22 11:17 - 2011-03-22 11:17 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2010-02-05 18:44 - 2010-02-05 18:44 - 00079192 _____ () C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00046080 _____ () C:\Program Files (x86)\Audials\Audials 11\boost_thread-vc90-mt-1_39.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00045056 _____ () C:\Program Files (x86)\Audials\Audials 11\boost_date_time-vc90-mt-1_39.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00545032 _____ () C:\Program Files (x86)\Audials\Audials 11\StreamingClient.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00012800 _____ () C:\Program Files (x86)\Audials\Audials 11\boost_system-vc90-mt-1_39.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00068360 _____ () C:\Program Files (x86)\Audials\Audials 11\CrashRpt.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00409352 _____ () C:\Program Files (x86)\Audials\Audials 11\SQLite3.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00614912 _____ () C:\Program Files (x86)\Audials\Audials 11\boost_regex-vc90-mt-1_39.dll
2014-07-05 13:17 - 2014-07-05 13:17 - 00290816 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Utils\475aaa01867f0f91e9bb3b3945a7e75e\Utils.ni.dll
2014-07-05 13:17 - 2014-07-05 13:17 - 00590336 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ManagedInterfaces\2c469d1b5dd6af3398ba8536e042da21\ManagedInterfaces.ni.dll
2014-07-05 13:17 - 2014-07-05 13:17 - 02977280 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\AudialsComponents\061edcd67606321f9b82b085808114ca\AudialsComponents.ni.dll
2014-07-05 13:17 - 2014-07-05 13:17 - 00178688 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\fastJSON\d280aed23ee738bcb288ac17febd0772\fastJSON.ni.dll
2014-05-24 00:08 - 2014-05-14 01:40 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libglesv2.dll
2014-05-24 00:08 - 2014-05-14 01:40 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libegl.dll
2014-05-24 00:08 - 2014-05-14 01:40 - 04217672 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll
2014-05-24 00:08 - 2014-05-14 01:40 - 00414536 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll
2014-05-24 00:08 - 2014-05-14 01:40 - 01732424 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"

==================== EXE Association (whitelisted) =============


==================== MSCONFIG/TASK MANAGER disabled items =========


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (07/05/2014 04:28:20 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/05/2014 02:00:21 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/05/2014 11:23:26 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/05/2014 11:10:00 AM) (Source: MsiInstaller) (EventID: 11309) (User: Yasmin-TOSH)
Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt.  System error 3.  Verify that the file exists and that you can access it.

Error: (07/05/2014 10:25:33 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/04/2014 03:19:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/03/2014 09:25:07 PM) (Source: TOSHIBA Service Station) (EventID: 0) (User: )
Description: TSS Load: could not communicate with TMachInfo service

Error: (07/03/2014 09:22:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/02/2014 06:16:09 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/01/2014 09:08:26 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (07/05/2014 04:27:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "WindowsMangerProtect Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (07/05/2014 04:25:35 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Error: (07/05/2014 01:57:16 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {3EB3C877-1F16-487C-9050-104DBCD66683}

Error: (07/05/2014 01:57:14 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Error: (07/05/2014 01:19:01 PM) (Source: Schannel) (EventID: 4120) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.

Error: (07/05/2014 01:17:48 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {ABC01078-F197-4B0B-ADBC-CFE684B39C82}

Error: (07/05/2014 11:22:32 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Computer Backup (MyPC Backup)" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (07/05/2014 11:22:32 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Computer Backup (MyPC Backup) erreicht.

Error: (07/05/2014 11:20:41 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Error: (07/05/2014 01:09:11 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}


Microsoft Office Sessions:
=========================
Error: (07/05/2014 04:28:20 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/05/2014 02:00:21 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/05/2014 11:23:26 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/05/2014 11:10:00 AM) (Source: MsiInstaller) (EventID: 11309) (User: Yasmin-TOSH)
Description: Product: Google Update Helper -- Error 1309. Error reading from file: C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\Google\Update\RequiredFile.txt.  System error 3.  Verify that the file exists and that you can access it.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (07/05/2014 10:25:33 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/04/2014 03:19:15 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/03/2014 09:25:07 PM) (Source: TOSHIBA Service Station) (EventID: 0) (User: )
Description: TSS Load: could not communicate with TMachInfo service

Error: (07/03/2014 09:22:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/02/2014 06:16:09 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/01/2014 09:08:26 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


==================== Memory info =========================== 

Percentage of memory in use: 44%
Total physical RAM: 3691.64 MB
Available physical RAM: 2055.92 MB
Total Pagefile: 7681.45 MB
Available Pagefile: 4891.95 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: (WINDOWS) (Fixed) (Total:149.04 GB) (Free:101.82 GB) NTFS
Drive d: (Data) (Fixed) (Total:148.65 GB) (Free:85.05 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 41D68339)
Partition 1: (Active) - (Size=400 MB) - (Type=27)
Partition 2: (Not Active) - (Size=149 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=149 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         

FRST .txt


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-07-2014 01
Ran by Yasmin (administrator) on YASMIN-TOSH on 05-07-2014 19:48:41
Running from C:\Users\Yasmin\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Program Files (x86)\Audials\Audials 11\AudialsNotifier.exe
(Toshiba) C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe
() C:\Users\Yasmin\AppData\Local\name_07050906\name_07050906.exe
(McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcagent.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Desktop.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [TosNC] => C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [597928 2011-03-03] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38304 2010-12-14] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba TEMPRO] => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1546720 2011-02-10] (Toshiba Europe GmbH)
HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [566184 2010-09-28] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] => C:\Program Files\Toshiba\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [915320 2010-10-28] (TOSHIBA Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11580520 2010-11-10] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2181224 2010-11-03] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2387752 2010-09-30] (Synaptics Incorporated)
HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2010-02-05] (TOSHIBA Corporation)
HKLM\...\Run: [SmartFaceVWatcher] => C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-10-19] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba Registration] => C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe [150992 2011-08-22] (Toshiba Europe GmbH)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NBAgent] => c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1409424 2011-06-29] (Nero AG)
HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [1675160 2012-03-21] (McAfee, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-06-29] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SVPWUTIL] => C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe [532480 2010-11-09] (TOSHIBA)
HKLM-x32\...\Run: [HWSetup] => C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [423936 2010-03-04] (TOSHIBA Electronics, Inc.)
HKLM-x32\...\Run: [KeNotify] => C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [34160 2010-08-15] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [TWebCamera] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2475384 2010-11-02] (TOSHIBA CORPORATION.)
HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1295224 2010-07-01] (TOSHIBA Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\.DEFAULT\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-19\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-20\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21444224 2014-05-08] (Skype Technologies S.A.)
HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [name_07050906] => c:\users\yasmin\appdata\local\name_07050906\name_07050906.exe [2990080 2014-07-05] ()
HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-08-22] (Google Inc.)
HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [AudialsNotifier] => C:\Program Files (x86)\Audials\Audials 11\AudialsNotifier.exe [2208520 2014-06-11] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Toshiba Places Icon Utility.lnk
ShortcutTarget: Toshiba Places Icon Utility.lnk -> C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe (Toshiba)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\name_07050906.lnk
ShortcutTarget: name_07050906.lnk -> C:\Users\Yasmin\AppData\Local\name_07050906\name_07050906.exe ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

ProxyServer: http=127.0.0.1:13957;https=127.0.0.1:13957
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {15D1CCBD-7C64-49C2-B1D3-65DD51820FDA} URL = hxxp://url24.info/?id=2111s9412a6224&q={searchTerms}
SearchScopes: HKLM - {15D1CCBD-7C64-49C2-B1D3-65DD51820FDA} URL = hxxp://url24.info/?id=2111s9412a6224&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - {15D1CCBD-7C64-49C2-B1D3-65DD51820FDA} URL = hxxp://url24.info/?id=2111s9412a6224&q={searchTerms}
BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20140112153556.dll (McAfee, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20140112153556.dll (McAfee, Inc.)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore
FF Extension: McAfee ScriptScan for Firefox - C:\Program Files (x86)\Common Files\McAfee\SystemCore [2011-08-22]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2011-08-22]
FF HKCU\...\Firefox\Extensions: [{C498947A-67CC-C868-A155-E77523522BAE}] - C:\Program Files (x86)\BlockAndSurf-soft\172.xpi

Chrome: 
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "hxxp://www.google.de/"
CHR Extension: (Google Docs) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-14]
CHR Extension: (Google Drive) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-14]
CHR Extension: (WOT) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-07-05]
CHR Extension: (YouTube) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-14]
CHR Extension: (Adblock Plus) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-05]
CHR Extension: (Google-Suche) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-14]
CHR Extension: (Google Wallet) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-12]
CHR Extension: (Google Mail) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-14]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]

==================== Services (Whitelisted) =================

R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [1809920 2010-08-04] (Realsil Microelectronics Inc.) [File not signed]
R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\mcafee\msc\McAWFwk.exe [225216 2011-01-28] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
R2 mcmscsvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
R2 McNASvc; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [501768 2011-03-17] (McAfee, Inc.)
R2 McOobeSv; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [199304 2012-05-25] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [210616 2012-05-25] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [162224 2012-05-25] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [249936 2011-01-27] (McAfee, Inc.)
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH)
S2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service [X]

==================== Drivers (Whitelisted) ====================

R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [65264 2012-02-22] (McAfee, Inc.)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [160792 2012-02-22] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [229528 2012-02-22] (McAfee, Inc.)
U3 mfeavfk01; No ImagePath
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [487296 2012-02-22] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [647208 2012-02-22] (McAfee, Inc.)
R1 mfenlfk; C:\Windows\System32\DRIVERS\mfenlfk.sys [75936 2012-02-22] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [100912 2012-02-22] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [289664 2012-02-22] (McAfee, Inc.)
R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-06-11] (Audials AG)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-05 19:48 - 2014-07-05 19:49 - 00021023 _____ () C:\Users\Yasmin\Downloads\FRST.txt
2014-07-05 19:48 - 2014-07-05 19:48 - 00000000 ____D () C:\FRST
2014-07-05 19:47 - 2014-07-05 19:48 - 02084352 _____ (Farbar) C:\Users\Yasmin\Downloads\FRST64.exe
2014-07-05 16:32 - 2014-07-05 16:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-07-05 15:20 - 2014-07-05 15:20 - 00017609 _____ () C:\Ergebnisse.txt
2014-07-05 14:14 - 2014-07-05 15:18 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-05 14:14 - 2014-07-05 14:14 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-05 14:14 - 2014-07-05 14:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-05 14:13 - 2014-07-05 14:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-05 14:13 - 2014-07-05 14:13 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-05 14:13 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-05 14:13 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-05 14:13 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-05 14:09 - 2014-07-05 14:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Yasmin\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-05 13:49 - 2014-07-05 13:50 - 01346519 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.214.exe
2014-07-05 13:35 - 2014-07-05 13:35 - 00001185 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-07-05 13:35 - 2014-07-05 13:35 - 00001173 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-07-05 13:35 - 2014-07-05 13:35 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-07-05 13:19 - 2014-07-05 13:19 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\CrashRpt
2014-07-05 13:15 - 2014-07-05 13:15 - 00000954 _____ () C:\Users\Public\Desktop\Audials 11.lnk
2014-07-05 13:14 - 2014-07-05 13:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audials 11
2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\ProgramData\RapidSolution
2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\Program Files (x86)\Audials
2014-07-05 13:11 - 2014-07-05 13:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\RapidSolution
2014-07-05 13:07 - 2014-07-05 13:07 - 00470552 _____ () C:\Users\Yasmin\Downloads\soft32_TeamViewer_1.0.exe
2014-07-05 11:20 - 2014-07-05 11:20 - 00003224 _____ () C:\Windows\System32\Tasks\cmelajsb
2014-07-05 11:20 - 2014-07-05 11:20 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\cmelajsb.bat
2014-07-05 11:18 - 2014-07-05 11:18 - 00003220 _____ () C:\Windows\System32\Tasks\elsbix
2014-07-05 11:18 - 2014-07-05 11:18 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\elsbix.bat
2014-07-05 11:16 - 2014-07-05 11:16 - 00003222 _____ () C:\Windows\System32\Tasks\difkadc
2014-07-05 11:16 - 2014-07-05 11:16 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\difkadc.bat
2014-07-05 11:14 - 2014-07-05 11:14 - 00003220 _____ () C:\Windows\System32\Tasks\ehhiar
2014-07-05 11:14 - 2014-07-05 11:14 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\ehhiar.bat
2014-07-05 11:12 - 2014-07-05 11:12 - 00003220 _____ () C:\Windows\System32\Tasks\mrxota
2014-07-05 11:12 - 2014-07-05 11:12 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\mrxota.bat
2014-07-05 11:11 - 2014-07-05 11:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\com
2014-07-05 11:10 - 2014-07-05 11:10 - 00003224 _____ () C:\Windows\System32\Tasks\qscfhzbe
2014-07-05 11:10 - 2014-07-05 11:10 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\qscfhzbe.bat
2014-07-05 11:09 - 2014-07-05 16:27 - 00000288 _____ () C:\Windows\Tasks\PerfMonitor_strtp.job
2014-07-05 11:09 - 2014-07-05 11:14 - 00002504 _____ () C:\Windows\System32\Tasks\PerfMonitor_strtp
2014-07-05 11:07 - 2014-07-05 11:07 - 00003220 _____ () C:\Windows\System32\Tasks\cfkxbi
2014-07-05 11:06 - 2014-07-05 19:47 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\name_07050906
2014-07-04 23:44 - 2014-07-04 23:44 - 00000030 _____ () C:\Users\Yasmin\Downloads\streamurl.ram
2014-07-04 22:09 - 2014-07-04 22:09 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{37404FF7-030E-48E2-A558-14DFA93EEE9E}
2014-07-03 21:58 - 2014-07-03 21:59 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E9BB536-0BF2-446D-8D48-DC87C01C2FC3}
2014-06-29 12:28 - 2014-06-29 12:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E1CAE782-0FD8-41B0-9FD8-7E33BBD98301}
2014-06-28 23:52 - 2014-06-28 23:52 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{810DEC4A-80C1-4FD5-B28B-5BFC530AE508}
2014-06-27 21:32 - 2014-06-27 21:32 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{24E647D5-B426-4A01-AF7E-14A6AE314912}
2014-06-26 20:30 - 2014-06-26 20:30 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{D8B715AD-B34D-4D33-A09C-C33244F9D5C0}
2014-06-25 19:28 - 2014-06-25 19:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E893FD49-F480-401D-914A-5942727764A4}
2014-06-24 21:22 - 2014-06-24 21:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{41D84405-36F0-449C-9EFA-213D56C3AA10}
2014-06-23 22:00 - 2014-06-23 22:00 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F110FA2D-C85B-4F52-B108-8E9ED1857A01}
2014-06-22 15:23 - 2014-06-22 15:23 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{75B97884-1D8B-4CCB-83FC-048BB61EB30E}
2014-06-21 20:24 - 2014-06-21 20:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{9C7EDFC2-FB6C-49EB-9193-23E5598340C5}
2014-06-20 23:26 - 2014-06-20 23:27 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B713B85D-3B2D-4962-8CA2-F1C383D94808}
2014-06-19 14:24 - 2014-06-19 14:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{FC9ED3F9-DD7E-411E-9269-3766501127B5}
2014-06-18 21:20 - 2014-06-18 21:20 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{EB3FAF98-E5F5-4F1E-8E10-ABA85A38A761}
2014-06-16 20:22 - 2014-06-16 20:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{3BF0F0AD-2D46-4BED-A50C-18E664F4F590}
2014-06-15 21:57 - 2014-06-15 21:57 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{19CDCCD7-B9FD-4316-A1B1-2D06A27CF368}
2014-06-15 20:58 - 2014-06-15 20:58 - 04631095 _____ () C:\Users\Yasmin\Documents\Unbenannt 1.odp
2014-06-15 15:41 - 2014-06-15 15:42 - 00000000 ___SD () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0
2014-06-15 15:41 - 2014-06-15 15:41 - 00001192 _____ () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0.lnk
2014-06-15 15:40 - 2014-06-15 15:41 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-06-15 15:38 - 2014-06-15 15:38 - 00000000 ____D () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0 (de) Installation Files
2014-06-15 15:21 - 2014-06-15 15:21 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer (1).exe
2014-06-15 15:01 - 2014-06-15 15:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero_AG
2014-06-15 15:00 - 2014-06-15 15:26 - 164962843 _____ () C:\Users\Yasmin\Downloads\Apache_OpenOffice_4.1.0_Win_x86_install_de.exe
2014-06-15 15:00 - 2014-06-15 15:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero
2014-06-15 14:59 - 2014-06-15 14:59 - 00003106 _____ () C:\Windows\System32\Tasks\{DCDD5B02-D205-4113-8043-ABDAB776D6F9}
2014-06-15 14:57 - 2014-06-15 14:59 - 106801603 _____ () C:\Users\Yasmin\Downloads\Nicht bestätigt 864307.crdownload
2014-06-15 14:51 - 2014-06-15 14:51 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer.exe
2014-06-15 14:20 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-15 14:17 - 2014-07-05 13:56 - 00000000 ____D () C:\AdwCleaner
2014-06-15 14:15 - 2014-06-15 14:16 - 01333465 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.212.exe
2014-06-14 17:48 - 2014-06-14 17:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-14 17:12 - 2014-06-14 17:13 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Adobe
2014-06-14 15:53 - 2014-06-14 15:53 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E519259-ADFA-4445-9FF2-A60967D85830}
2014-06-14 14:41 - 2014-06-14 14:41 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{51B5E13B-B124-4678-B7E1-59E1D21E084E}
2014-06-12 13:43 - 2014-06-12 13:43 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6D0186BE-0396-43A5-8D71-4D0C5779FE26}
2014-06-12 12:58 - 2014-06-12 12:58 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0 (1).exe
2014-06-11 22:38 - 2014-06-11 22:38 - 00830792 _____ (Click Me In Limited) C:\Users\Yasmin\AppData\Local\nstE584.tmp
2014-06-11 22:31 - 2014-06-14 17:54 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\OpenOffice
2014-06-11 22:31 - 2014-06-11 22:31 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-06-11 22:24 - 2014-06-14 17:54 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Opera Software
2014-06-11 22:24 - 2014-06-11 22:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Opera Software
2014-06-11 22:23 - 2014-06-14 17:56 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMeterExpress
2014-06-11 22:22 - 2014-06-14 17:56 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\PriceMeter Express
2014-06-11 22:20 - 2014-06-15 14:29 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-11 22:19 - 2014-06-14 17:56 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér
2014-06-11 21:38 - 2014-07-05 19:37 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-11 21:38 - 2014-06-11 21:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-11 21:38 - 2014-06-11 21:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-11 21:38 - 2014-06-11 21:38 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-11 21:38 - 2014-06-11 21:38 - 00000000 ____D () C:\Windows\system32\Macromed
2014-06-11 21:16 - 2014-06-11 21:16 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0.exe
2014-06-11 20:07 - 2014-06-11 20:08 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F63CE874-95F4-4014-9FFA-E120BA697A33}
2014-06-11 19:44 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-11 19:44 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-11 19:44 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-11 19:44 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-11 19:44 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-11 19:44 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-11 19:44 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-11 19:44 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-11 19:44 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-11 19:44 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-11 19:44 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-11 19:44 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-11 19:44 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-11 19:44 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-11 19:44 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-11 19:44 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-11 19:44 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-11 19:44 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-11 19:44 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-11 19:44 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-11 19:44 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-11 19:44 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-11 19:44 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-11 19:44 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-11 19:44 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-11 19:44 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-11 19:44 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-11 19:44 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-11 19:44 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-11 19:44 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-11 19:44 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-11 19:44 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-11 19:44 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-11 19:44 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-11 19:44 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-11 19:44 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-11 19:44 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-11 19:44 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-11 19:44 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-11 19:44 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-11 19:44 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-11 19:44 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-11 19:44 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-11 19:44 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-11 19:44 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-11 19:44 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-11 19:44 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-11 19:44 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-11 19:44 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-11 19:44 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-11 19:44 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-11 19:44 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-11 19:44 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-11 19:44 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-11 19:44 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-11 19:44 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-11 19:44 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-11 19:44 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-11 19:44 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-11 19:44 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-11 19:44 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-11 19:44 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-11 19:44 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-11 19:44 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-11 19:43 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-11 19:43 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00047240 _____ (RapidSolution Software AG) C:\Windows\system32\Drivers\tbhsd.sys
2014-06-11 17:31 - 2014-06-11 17:31 - 00024744 _____ (Audials AG) C:\Windows\system32\Drivers\RrNetCapFilterDriver.sys
2014-06-10 20:28 - 2014-06-10 20:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{8DDAE57A-5162-4B54-83CA-34A6D1AD5A76}
2014-06-09 19:29 - 2014-06-09 19:29 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B679CC51-C608-4AE5-8429-423D93E97BB1}
2014-06-08 15:04 - 2014-06-08 15:04 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{BE799AB3-FEC9-439F-9EE9-50C2DEB968DE}

==================== One Month Modified Files and Folders =======

2014-07-05 19:49 - 2014-07-05 19:48 - 00021023 _____ () C:\Users\Yasmin\Downloads\FRST.txt
2014-07-05 19:48 - 2014-07-05 19:48 - 00000000 ____D () C:\FRST
2014-07-05 19:48 - 2014-07-05 19:47 - 02084352 _____ (Farbar) C:\Users\Yasmin\Downloads\FRST64.exe
2014-07-05 19:47 - 2014-07-05 11:06 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\name_07050906
2014-07-05 19:39 - 2010-11-21 08:50 - 00699370 _____ () C:\Windows\system32\perfh007.dat
2014-07-05 19:39 - 2010-11-21 08:50 - 00149220 _____ () C:\Windows\system32\perfc007.dat
2014-07-05 19:39 - 2009-07-14 07:13 - 01619896 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-05 19:38 - 2014-01-12 03:20 - 02000693 _____ () C:\Windows\WindowsUpdate.log
2014-07-05 19:37 - 2014-06-11 21:38 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-05 19:37 - 2014-01-13 20:52 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Skype
2014-07-05 19:37 - 2011-08-22 11:52 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-05 16:35 - 2009-07-14 06:45 - 00024912 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-05 16:35 - 2009-07-14 06:45 - 00024912 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-05 16:32 - 2014-07-05 16:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-07-05 16:32 - 2011-08-22 11:41 - 00001835 _____ () C:\Users\Public\Desktop\McAfee Internet Security.lnk
2014-07-05 16:27 - 2014-07-05 11:09 - 00000288 _____ () C:\Windows\Tasks\PerfMonitor_strtp.job
2014-07-05 16:27 - 2011-08-22 11:52 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-05 16:27 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-05 16:27 - 2009-07-14 06:51 - 00062190 _____ () C:\Windows\setupact.log
2014-07-05 16:26 - 2010-11-21 05:47 - 00149776 _____ () C:\Windows\PFRO.log
2014-07-05 15:20 - 2014-07-05 15:20 - 00017609 _____ () C:\Ergebnisse.txt
2014-07-05 15:18 - 2014-07-05 14:14 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-05 14:14 - 2014-07-05 14:14 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-05 14:14 - 2014-07-05 14:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-05 14:14 - 2014-07-05 14:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-05 14:13 - 2014-07-05 14:13 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-05 14:10 - 2014-07-05 14:09 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Yasmin\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-05 14:04 - 2014-01-12 04:01 - 00064024 _____ () C:\Users\Yasmin\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-05 13:58 - 2009-07-14 06:45 - 00294736 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-05 13:56 - 2014-06-15 14:17 - 00000000 ____D () C:\AdwCleaner
2014-07-05 13:56 - 2014-01-12 03:59 - 00000998 _____ () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-07-05 13:56 - 2011-08-22 11:52 - 00001289 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-05 13:56 - 2011-08-22 11:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-07-05 13:50 - 2014-07-05 13:49 - 01346519 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.214.exe
2014-07-05 13:35 - 2014-07-05 13:35 - 00001185 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-07-05 13:35 - 2014-07-05 13:35 - 00001173 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-07-05 13:35 - 2014-07-05 13:35 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-07-05 13:19 - 2014-07-05 13:19 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\CrashRpt
2014-07-05 13:15 - 2014-07-05 13:15 - 00000954 _____ () C:\Users\Public\Desktop\Audials 11.lnk
2014-07-05 13:15 - 2014-07-05 13:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audials 11
2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\ProgramData\RapidSolution
2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\Program Files (x86)\Audials
2014-07-05 13:11 - 2014-07-05 13:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\RapidSolution
2014-07-05 13:07 - 2014-07-05 13:07 - 00470552 _____ () C:\Users\Yasmin\Downloads\soft32_TeamViewer_1.0.exe
2014-07-05 11:20 - 2014-07-05 11:20 - 00003224 _____ () C:\Windows\System32\Tasks\cmelajsb
2014-07-05 11:20 - 2014-07-05 11:20 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\cmelajsb.bat
2014-07-05 11:18 - 2014-07-05 11:18 - 00003220 _____ () C:\Windows\System32\Tasks\elsbix
2014-07-05 11:18 - 2014-07-05 11:18 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\elsbix.bat
2014-07-05 11:16 - 2014-07-05 11:16 - 00003222 _____ () C:\Windows\System32\Tasks\difkadc
2014-07-05 11:16 - 2014-07-05 11:16 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\difkadc.bat
2014-07-05 11:14 - 2014-07-05 11:14 - 00003220 _____ () C:\Windows\System32\Tasks\ehhiar
2014-07-05 11:14 - 2014-07-05 11:14 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\ehhiar.bat
2014-07-05 11:14 - 2014-07-05 11:09 - 00002504 _____ () C:\Windows\System32\Tasks\PerfMonitor_strtp
2014-07-05 11:12 - 2014-07-05 11:12 - 00003220 _____ () C:\Windows\System32\Tasks\mrxota
2014-07-05 11:12 - 2014-07-05 11:12 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\mrxota.bat
2014-07-05 11:11 - 2014-07-05 11:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\com
2014-07-05 11:10 - 2014-07-05 11:10 - 00003224 _____ () C:\Windows\System32\Tasks\qscfhzbe
2014-07-05 11:10 - 2014-07-05 11:10 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\qscfhzbe.bat
2014-07-05 11:07 - 2014-07-05 11:07 - 00003220 _____ () C:\Windows\System32\Tasks\cfkxbi
2014-07-05 10:24 - 2011-08-22 11:38 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-07-04 23:44 - 2014-07-04 23:44 - 00000030 _____ () C:\Users\Yasmin\Downloads\streamurl.ram
2014-07-04 22:09 - 2014-07-04 22:09 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{37404FF7-030E-48E2-A558-14DFA93EEE9E}
2014-07-03 21:59 - 2014-07-03 21:58 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E9BB536-0BF2-446D-8D48-DC87C01C2FC3}
2014-06-29 12:28 - 2014-06-29 12:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E1CAE782-0FD8-41B0-9FD8-7E33BBD98301}
2014-06-28 23:52 - 2014-06-28 23:52 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{810DEC4A-80C1-4FD5-B28B-5BFC530AE508}
2014-06-27 21:32 - 2014-06-27 21:32 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{24E647D5-B426-4A01-AF7E-14A6AE314912}
2014-06-26 20:30 - 2014-06-26 20:30 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{D8B715AD-B34D-4D33-A09C-C33244F9D5C0}
2014-06-25 19:28 - 2014-06-25 19:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E893FD49-F480-401D-914A-5942727764A4}
2014-06-24 21:22 - 2014-06-24 21:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{41D84405-36F0-449C-9EFA-213D56C3AA10}
2014-06-23 22:00 - 2014-06-23 22:00 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F110FA2D-C85B-4F52-B108-8E9ED1857A01}
2014-06-22 15:23 - 2014-06-22 15:23 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{75B97884-1D8B-4CCB-83FC-048BB61EB30E}
2014-06-21 20:24 - 2014-06-21 20:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{9C7EDFC2-FB6C-49EB-9193-23E5598340C5}
2014-06-20 23:27 - 2014-06-20 23:26 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B713B85D-3B2D-4962-8CA2-F1C383D94808}
2014-06-19 14:24 - 2014-06-19 14:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{FC9ED3F9-DD7E-411E-9269-3766501127B5}
2014-06-18 21:20 - 2014-06-18 21:20 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{EB3FAF98-E5F5-4F1E-8E10-ABA85A38A761}
2014-06-16 20:22 - 2014-06-16 20:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{3BF0F0AD-2D46-4BED-A50C-18E664F4F590}
2014-06-15 21:57 - 2014-06-15 21:57 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{19CDCCD7-B9FD-4316-A1B1-2D06A27CF368}
2014-06-15 20:58 - 2014-06-15 20:58 - 04631095 _____ () C:\Users\Yasmin\Documents\Unbenannt 1.odp
2014-06-15 15:42 - 2014-06-15 15:41 - 00000000 ___SD () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0
2014-06-15 15:41 - 2014-06-15 15:41 - 00001192 _____ () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0.lnk
2014-06-15 15:41 - 2014-06-15 15:40 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-06-15 15:38 - 2014-06-15 15:38 - 00000000 ____D () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0 (de) Installation Files
2014-06-15 15:26 - 2014-06-15 15:00 - 164962843 _____ () C:\Users\Yasmin\Downloads\Apache_OpenOffice_4.1.0_Win_x86_install_de.exe
2014-06-15 15:21 - 2014-06-15 15:21 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer (1).exe
2014-06-15 15:01 - 2014-06-15 15:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero_AG
2014-06-15 15:01 - 2014-06-15 15:00 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero
2014-06-15 14:59 - 2014-06-15 14:59 - 00003106 _____ () C:\Windows\System32\Tasks\{DCDD5B02-D205-4113-8043-ABDAB776D6F9}
2014-06-15 14:59 - 2014-06-15 14:57 - 106801603 _____ () C:\Users\Yasmin\Downloads\Nicht bestätigt 864307.crdownload
2014-06-15 14:51 - 2014-06-15 14:51 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer.exe
2014-06-15 14:29 - 2014-06-11 22:20 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-15 14:16 - 2014-06-15 14:15 - 01333465 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.212.exe
2014-06-15 14:02 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-06-14 18:11 - 2009-07-14 04:34 - 00000537 _____ () C:\Windows\win.ini
2014-06-14 17:59 - 2014-01-12 03:57 - 00000000 ____D () C:\Users\Yasmin
2014-06-14 17:56 - 2014-06-11 22:23 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMeterExpress
2014-06-14 17:56 - 2014-06-11 22:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\PriceMeter Express
2014-06-14 17:56 - 2014-06-11 22:19 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér
2014-06-14 17:56 - 2014-05-07 19:09 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-14 17:56 - 2014-01-12 04:45 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\TOSHIBA_Corporation
2014-06-14 17:56 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-06-14 17:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-06-14 17:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-06-14 17:55 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-06-14 17:54 - 2014-06-11 22:31 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\OpenOffice
2014-06-14 17:54 - 2014-06-11 22:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Opera Software
2014-06-14 17:54 - 2014-02-21 01:06 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\SoftGrid Client
2014-06-14 17:54 - 2011-08-22 11:38 - 00000000 ____D () C:\ProgramData\McAfee
2014-06-14 17:48 - 2014-06-14 17:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-14 17:13 - 2014-06-14 17:12 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Adobe
2014-06-14 17:12 - 2014-01-12 16:08 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Adobe
2014-06-14 16:51 - 2014-01-12 04:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Toshiba
2014-06-14 15:53 - 2014-06-14 15:53 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E519259-ADFA-4445-9FF2-A60967D85830}
2014-06-14 14:41 - 2014-06-14 14:41 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{51B5E13B-B124-4678-B7E1-59E1D21E084E}
2014-06-12 13:43 - 2014-06-12 13:43 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6D0186BE-0396-43A5-8D71-4D0C5779FE26}
2014-06-12 12:58 - 2014-06-12 12:58 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0 (1).exe
2014-06-11 22:38 - 2014-06-11 22:38 - 00830792 _____ (Click Me In Limited) C:\Users\Yasmin\AppData\Local\nstE584.tmp
2014-06-11 22:31 - 2014-06-11 22:31 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-06-11 22:24 - 2014-06-11 22:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Opera Software
2014-06-11 21:38 - 2014-06-11 21:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-11 21:38 - 2014-06-11 21:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-11 21:38 - 2014-06-11 21:38 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-11 21:38 - 2014-06-11 21:38 - 00000000 ____D () C:\Windows\system32\Macromed
2014-06-11 21:16 - 2014-06-11 21:16 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0.exe
2014-06-11 20:08 - 2014-06-11 20:07 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F63CE874-95F4-4014-9FFA-E120BA697A33}
2014-06-11 17:31 - 2014-06-11 17:31 - 00047240 _____ (RapidSolution Software AG) C:\Windows\system32\Drivers\tbhsd.sys
2014-06-11 17:31 - 2014-06-11 17:31 - 00024744 _____ (Audials AG) C:\Windows\system32\Drivers\RrNetCapFilterDriver.sys
2014-06-10 20:28 - 2014-06-10 20:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{8DDAE57A-5162-4B54-83CA-34A6D1AD5A76}
2014-06-09 19:29 - 2014-06-09 19:29 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B679CC51-C608-4AE5-8429-423D93E97BB1}
2014-06-08 15:04 - 2014-06-08 15:04 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{BE799AB3-FEC9-439F-9EE9-50C2DEB968DE}
2014-06-08 11:13 - 2014-06-11 19:43 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-11 19:43 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll

Some content of TEMP:
====================
C:\Users\Yasmin\AppData\Local\Temp\-23pzvcf.dll
C:\Users\Yasmin\AppData\Local\Temp\-zw7ebio.dll
C:\Users\Yasmin\AppData\Local\Temp\04czr0ef.dll
C:\Users\Yasmin\AppData\Local\Temp\0y4qs-v8.dll
C:\Users\Yasmin\AppData\Local\Temp\3j3exo3z.dll
C:\Users\Yasmin\AppData\Local\Temp\4nyosznz.dll
C:\Users\Yasmin\AppData\Local\Temp\59bg2dsi.dll
C:\Users\Yasmin\AppData\Local\Temp\73-oiasl.dll
C:\Users\Yasmin\AppData\Local\Temp\8hwvac6t.dll
C:\Users\Yasmin\AppData\Local\Temp\BackupSetup.exe
C:\Users\Yasmin\AppData\Local\Temp\bfk954rp.dll
C:\Users\Yasmin\AppData\Local\Temp\bjsyqg_c.dll
C:\Users\Yasmin\AppData\Local\Temp\dw_kcoie.dll
C:\Users\Yasmin\AppData\Local\Temp\eqebiofn.dll
C:\Users\Yasmin\AppData\Local\Temp\fenrybn2.dll
C:\Users\Yasmin\AppData\Local\Temp\h3tcdzan.dll
C:\Users\Yasmin\AppData\Local\Temp\i8syhl6v.dll
C:\Users\Yasmin\AppData\Local\Temp\itavi2y-.dll
C:\Users\Yasmin\AppData\Local\Temp\jn5lqovs.dll
C:\Users\Yasmin\AppData\Local\Temp\k_312ihf.dll
C:\Users\Yasmin\AppData\Local\Temp\lagmpmi6.dll
C:\Users\Yasmin\AppData\Local\Temp\lgb3nyio.dll
C:\Users\Yasmin\AppData\Local\Temp\melbg6oc.dll
C:\Users\Yasmin\AppData\Local\Temp\oemsetup.exe
C:\Users\Yasmin\AppData\Local\Temp\ognwvd9v.dll
C:\Users\Yasmin\AppData\Local\Temp\om_ohj5c.dll
C:\Users\Yasmin\AppData\Local\Temp\OpenOffice_4.1.0_Win_x86_install_de.exe
C:\Users\Yasmin\AppData\Local\Temp\optprosetup.exe
C:\Users\Yasmin\AppData\Local\Temp\p6ijzaea.dll
C:\Users\Yasmin\AppData\Local\Temp\pirm6xjt.dll
C:\Users\Yasmin\AppData\Local\Temp\PrefJsonCpp.exe
C:\Users\Yasmin\AppData\Local\Temp\pxhrabew.dll
C:\Users\Yasmin\AppData\Local\Temp\qces_gra.dll
C:\Users\Yasmin\AppData\Local\Temp\qu7inx1k.dll
C:\Users\Yasmin\AppData\Local\Temp\Quarantine.exe
C:\Users\Yasmin\AppData\Local\Temp\sizrcajk.dll
C:\Users\Yasmin\AppData\Local\Temp\spta3k3e.dll
C:\Users\Yasmin\AppData\Local\Temp\sptgfvme.dll
C:\Users\Yasmin\AppData\Local\Temp\sqlite3.exe
C:\Users\Yasmin\AppData\Local\Temp\vkk8qkt0.dll
C:\Users\Yasmin\AppData\Local\Temp\vsskyyrf.dll
C:\Users\Yasmin\AppData\Local\Temp\vyahhbh2.dll
C:\Users\Yasmin\AppData\Local\Temp\xsglum2y.dll
C:\Users\Yasmin\AppData\Local\Temp\yf7lvekt.dll
C:\Users\Yasmin\AppData\Local\Temp\zer9fyk5.dll
C:\Users\Yasmin\AppData\Local\Temp\_yualj7d.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-11 20:02

==================== End Of Log ============================
         
--- --- ---





Danke schon mal für die Hilfe
__________________

Alt 06.07.2014, 11:14   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Fake Flash-Player Update gedownloadet :(( - Standard

Fake Flash-Player Update gedownloadet :((



Adware & Co. deinstallieren
  • Lade Dir bitte von hier Revo Uninstaller herunter.
  • Installiere und starte das Programm.
  • Suche im Uninstallerfeld nach den Programmen, die unter:

    diesen Zusatz haben:
  • Wähle die Programme nacheinander aus und klicke jedesmal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .

Solltest Du ein Programm nicht finden oder nicht deinstallieren können, mache bitte mit dem nächsten Schritt weiter:



Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 06.07.2014, 14:01   #5
JJ11
 
Fake Flash-Player Update gedownloadet :(( - Standard

Fake Flash-Player Update gedownloadet :((



Hallo,
Ich habe ein Problem. beim Klicken des Links zum downladen von Combofix. Läd er das zwar herunter aber dann steht plötzlich "Fehler-Fehler beim Herunterladen"
Gruß


Alt 06.07.2014, 17:52   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Fake Flash-Player Update gedownloadet :(( - Standard

Fake Flash-Player Update gedownloadet :((



Andere Browser getestet? AV Programm abgeschaltet?
__________________
--> Fake Flash-Player Update gedownloadet :((

Alt 07.07.2014, 17:53   #7
JJ11
 
Fake Flash-Player Update gedownloadet :(( - Standard

Fake Flash-Player Update gedownloadet :((



Moin,
hier ist der cobofix log

Code:
ATTFilter
ComboFix 14-07-03.01 - Yasmin 06.07.2014  21:30:05.1.2 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.3692.2383 [GMT 2:00]
ausgeführt von:: c:\users\Yasmin\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Yasmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\SpadeCast_iels
c:\users\Yasmin\AppData\Local\nstE584.tmp
.
.
(((((((((((((((((((((((   Dateien erstellt von 2014-06-06 bis 2014-07-06  ))))))))))))))))))))))))))))))
.
.
2014-07-06 21:16 . 2014-07-06 21:16	--------	d-----w-	c:\users\Default\AppData\Local\temp
2014-07-05 17:48 . 2014-07-05 17:53	--------	d-----w-	C:\FRST
2014-07-05 12:14 . 2014-07-05 13:18	122584	----a-w-	c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-07-05 12:13 . 2014-05-12 05:26	63704	----a-w-	c:\windows\system32\drivers\mwac.sys
2014-07-05 12:13 . 2014-05-12 05:26	91352	----a-w-	c:\windows\system32\drivers\mbamchameleon.sys
2014-07-05 12:13 . 2014-07-05 12:14	--------	d-----w-	c:\program files (x86)\ Malwarebytes Anti-Malware 
2014-07-05 12:13 . 2014-07-05 12:13	--------	d-----w-	c:\programdata\Malwarebytes
2014-07-05 12:13 . 2014-05-12 05:25	25816	----a-w-	c:\windows\system32\drivers\mbam.sys
2014-07-05 11:35 . 2014-07-05 11:35	--------	d-----w-	c:\program files (x86)\TeamViewer
2014-07-05 11:19 . 2014-07-05 11:19	--------	d-----w-	c:\users\Yasmin\AppData\Local\CrashRpt
2014-07-05 11:14 . 2014-07-05 11:14	--------	d-----w-	c:\programdata\RapidSolution
2014-07-05 11:14 . 2014-07-05 11:14	--------	d-----w-	c:\program files (x86)\Audials
2014-07-05 11:11 . 2014-07-05 11:11	--------	d-----w-	c:\users\Yasmin\AppData\Local\RapidSolution
2014-07-05 09:20 . 2014-07-05 09:20	266	----a-w-	c:\users\Yasmin\AppData\Local\cmelajsb.bat
2014-07-05 09:18 . 2014-07-05 09:18	266	----a-w-	c:\users\Yasmin\AppData\Local\elsbix.bat
2014-07-05 09:16 . 2014-07-05 09:16	266	----a-w-	c:\users\Yasmin\AppData\Local\difkadc.bat
2014-07-05 09:14 . 2014-07-05 09:14	266	----a-w-	c:\users\Yasmin\AppData\Local\ehhiar.bat
2014-07-05 09:12 . 2014-07-05 09:12	266	----a-w-	c:\users\Yasmin\AppData\Local\mrxota.bat
2014-07-05 09:11 . 2014-07-05 09:11	--------	d-----w-	c:\users\Yasmin\AppData\Local\com
2014-07-05 09:10 . 2014-07-05 09:10	266	----a-w-	c:\users\Yasmin\AppData\Local\qscfhzbe.bat
2014-07-05 09:06 . 2014-07-05 18:03	--------	d-----w-	c:\users\Yasmin\AppData\Local\name_07050906
2014-06-15 13:40 . 2014-06-15 13:41	--------	d-----w-	c:\program files (x86)\OpenOffice 4
2014-06-15 13:00 . 2014-06-15 13:01	--------	d-----w-	c:\users\Yasmin\AppData\Local\Nero
2014-06-15 12:20 . 2010-08-30 06:34	536576	----a-w-	c:\windows\SysWow64\sqlite3.dll
2014-06-15 12:17 . 2014-07-05 11:56	--------	d-----w-	C:\AdwCleaner
2014-06-14 15:12 . 2014-06-14 15:13	--------	d-----w-	c:\users\Yasmin\AppData\Local\Adobe
2014-06-11 20:31 . 2014-06-14 15:54	--------	d-----w-	c:\users\Yasmin\AppData\Roaming\OpenOffice
2014-06-11 20:24 . 2014-06-11 20:24	--------	d-----w-	c:\users\Yasmin\AppData\Local\Opera Software
2014-06-11 20:24 . 2014-06-14 15:54	--------	d-----w-	c:\users\Yasmin\AppData\Roaming\Opera Software
2014-06-11 20:22 . 2014-06-14 15:56	--------	d-----w-	c:\users\Yasmin\AppData\Local\PriceMeter Express
2014-06-11 20:20 . 2014-06-15 12:29	--------	d-----w-	c:\program files (x86)\Opera
2014-06-11 20:19 . 2014-06-11 20:19	--------	d-----w-	c:\users\Yasmin\AppData\Local\Programs
2014-06-11 19:38 . 2014-06-11 19:38	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-06-11 19:38 . 2014-06-11 19:38	692616	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2014-06-11 19:38 . 2014-06-11 19:38	--------	d-----w-	c:\windows\system32\Macromed
2014-06-11 17:43 . 2014-06-08 09:13	506368	----a-w-	c:\windows\system32\aepdu.dll
2014-06-11 17:43 . 2014-06-08 09:08	424448	----a-w-	c:\windows\system32\aeinv.dll
2014-06-11 15:31 . 2014-06-11 15:31	47240	----a-w-	c:\windows\system32\drivers\tbhsd.sys
2014-06-11 15:31 . 2014-06-11 15:31	24744	----a-w-	c:\windows\system32\drivers\RrNetCapFilterDriver.sys
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-04-12 02:22 . 2014-05-14 16:12	155072	----a-w-	c:\windows\system32\drivers\ksecpkg.sys
2014-04-12 02:22 . 2014-05-14 16:12	95680	----a-w-	c:\windows\system32\drivers\ksecdd.sys
2014-04-12 02:19 . 2014-05-14 16:12	136192	----a-w-	c:\windows\system32\sspicli.dll
2014-04-12 02:19 . 2014-05-14 16:12	29184	----a-w-	c:\windows\system32\sspisrv.dll
2014-04-12 02:19 . 2014-05-14 16:12	28160	----a-w-	c:\windows\system32\secur32.dll
2014-04-12 02:19 . 2014-05-14 16:12	1460736	----a-w-	c:\windows\system32\lsasrv.dll
2014-04-12 02:19 . 2014-05-14 16:12	31232	----a-w-	c:\windows\system32\lsass.exe
2014-04-12 02:12 . 2014-05-14 16:12	22016	----a-w-	c:\windows\SysWow64\secur32.dll
2014-04-12 02:10 . 2014-05-14 16:12	96768	----a-w-	c:\windows\SysWow64\sspicli.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe" [2011-05-16 846936]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-05-08 21444224]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-22 39408]
"AudialsNotifier"="c:\program files (x86)\Audials\Audials 11\AudialsNotifier.exe" [2014-06-11 2208520]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"NBAgent"="c:\program files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2011-06-29 1409424]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-06-28 336384]
"SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-11-09 532480]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2010-03-04 423936]
"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2010-08-15 34160]
"TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-11-02 2475384]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2010-07-01 1295224]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOPI.EXE"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2011-05-16 846936]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Toshiba Places Icon Utility.lnk - c:\program files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe [2011-8-22 1493888]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 0140851404674326mcinstcleanup;McAfee Application Installer Cleanup (0140851404674326);c:\users\Yasmin\AppData\Local\Temp\014085~1.EXE;c:\users\Yasmin\AppData\Local\Temp\014085~1.EXE [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [x]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe;c:\windows\SYSNATIVE\mfevtps.exe [x]
R2 WindowsMangerProtect;WindowsMangerProtect Service;c:\programdata\WindowsMangerProtect\ProtectWindowsManager.exe;c:\programdata\WindowsMangerProtect\ProtectWindowsManager.exe [x]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys;c:\windows\SYSNATIVE\drivers\cfwids.sys [x]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys;c:\windows\SYSNATIVE\drivers\mfefirek.sys [x]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys;c:\windows\SYSNATIVE\drivers\mferkdet.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe;c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys;c:\windows\SYSNATIVE\drivers\mfewfpk.sys [x]
S1 RrNetCapFilterDriver;RadioRip Filter Driver;c:\windows\system32\DRIVERS\RrNetCapFilterDriver.sys;c:\windows\SYSNATIVE\DRIVERS\RrNetCapFilterDriver.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [x]
S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [x]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S3 CeKbFilter;CeKbFilter;c:\windows\system32\DRIVERS\CeKbFilter.sys;c:\windows\SYSNATIVE\DRIVERS\CeKbFilter.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys;c:\windows\SYSNATIVE\DRIVERS\pgeffect.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys;c:\windows\SYSNATIVE\DRIVERS\rtl8192Ce.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - mfeavfk01
*Deregistered* - mfenlfk
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-05-23 22:08	1091912	----a-w-	c:\program files (x86)\Google\Chrome\Application\35.0.1916.114\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-07-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-06-11 19:38]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2011-02-10 1546720]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-10 11580520]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2010-11-03 2181224]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 709976]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"Toshiba Registration"="c:\program files\TOSHIBA\Registration\ToshibaReminder.exe" [2011-08-22 150992]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com
mDefault_Search_URL = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://www.google.com
uInternet Settings,ProxyServer = http=127.0.0.1:13957;https=127.0.0.1:13957
IE: Zu TOSHIBA Bulletin Board hinzufügen - c:\program files\TOSHIBA\BulletinBoard\TosBBCom.dll/1000
TCP: DhcpNameServer = 192.168.0.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe
HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe
HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
AddRemove-webssearches uninstall - c:\users\Yasmin\AppData\Roaming\webssearches\UninstallManager.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-07-06  23:20:13
ComboFix-quarantined-files.txt  2014-07-06 21:20
.
Vor Suchlauf: 9 Verzeichnis(se), 109.639.327.744 Bytes frei
Nach Suchlauf: 11 Verzeichnis(se), 109.745.770.496 Bytes frei
.
- - End Of File - - 7B7060BB101885427B6AA96380368764
A36C5E4F47E84449FF07ED3517B43A31
         
Gruß

Alt 08.07.2014, 09:36   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Fake Flash-Player Update gedownloadet :(( - Standard

Fake Flash-Player Update gedownloadet :((



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 08.07.2014, 20:50   #9
JJ11
 
Fake Flash-Player Update gedownloadet :(( - Standard

Fake Flash-Player Update gedownloadet :((



Moin hier die verschiedene Logs

FRST

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-07-2014 01
Ran by Yasmin (administrator) on YASMIN-TOSH on 08-07-2014 16:26:46
Running from C:\Users\Yasmin\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Program Files (x86)\Audials\Audials 11\AudialsNotifier.exe
(Toshiba) C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Desktop.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [TosNC] => C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [597928 2011-03-03] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38304 2010-12-14] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba TEMPRO] => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1546720 2011-02-10] (Toshiba Europe GmbH)
HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [566184 2010-09-28] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] => C:\Program Files\Toshiba\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [915320 2010-10-28] (TOSHIBA Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11580520 2010-11-10] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2181224 2010-11-03] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2387752 2010-09-30] (Synaptics Incorporated)
HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2010-02-05] (TOSHIBA Corporation)
HKLM\...\Run: [SmartFaceVWatcher] => C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-10-19] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba Registration] => C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe [150992 2011-08-22] (Toshiba Europe GmbH)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NBAgent] => c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1409424 2011-06-29] (Nero AG)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-06-29] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SVPWUTIL] => C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe [532480 2010-11-09] (TOSHIBA)
HKLM-x32\...\Run: [HWSetup] => C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [423936 2010-03-04] (TOSHIBA Electronics, Inc.)
HKLM-x32\...\Run: [KeNotify] => C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [34160 2010-08-15] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [TWebCamera] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2475384 2010-11-02] (TOSHIBA CORPORATION.)
HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1295224 2010-07-01] (TOSHIBA Corporation)
HKU\.DEFAULT\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [TOPI.EXE] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21444224 2014-05-08] (Skype Technologies S.A.)
HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-08-22] (Google Inc.)
HKU\S-1-5-21-2410883006-3698484201-3815030499-1000\...\Run: [AudialsNotifier] => C:\Program Files (x86)\Audials\Audials 11\AudialsNotifier.exe [2208520 2014-06-11] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Toshiba Places Icon Utility.lnk
ShortcutTarget: Toshiba Places Icon Utility.lnk -> C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe (Toshiba)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

ProxyServer: http=127.0.0.1:13957;https=127.0.0.1:13957
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {15D1CCBD-7C64-49C2-B1D3-65DD51820FDA} URL = hxxp://url24.info/?id=2111s9412a6224&q={searchTerms}
SearchScopes: HKLM - {15D1CCBD-7C64-49C2-B1D3-65DD51820FDA} URL = hxxp://url24.info/?id=2111s9412a6224&q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - {15D1CCBD-7C64-49C2-B1D3-65DD51820FDA} URL = hxxp://url24.info/?id=2111s9412a6224&q={searchTerms}
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2011-08-22]
FF HKCU\...\Firefox\Extensions: [{C498947A-67CC-C868-A155-E77523522BAE}] - C:\Program Files (x86)\BlockAndSurf-soft\172.xpi

Chrome: 
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "hxxp://www.google.de/"
CHR Extension: (Google Docs) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-14]
CHR Extension: (Google Drive) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-14]
CHR Extension: (WOT) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2014-07-05]
CHR Extension: (YouTube) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-14]
CHR Extension: (Adblock Plus) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-05]
CHR Extension: (Google-Suche) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-14]
CHR Extension: (Google Wallet) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-12]
CHR Extension: (Google Mail) - C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-14]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]

==================== Services (Whitelisted) =================

R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [1809920 2010-08-04] (Realsil Microelectronics Inc.) [File not signed]
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH)
S2 0140851404674326mcinstcleanup; C:\Users\Yasmin\AppData\Local\Temp\014085~1.EXE -cleanup -nolog [X]
S2 McAfee SiteAdvisor Service; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 WindowsMangerProtect; C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe -service [X]

==================== Drivers (Whitelisted) ====================

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [24744 2014-06-11] (Audials AG)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-08 16:25 - 2014-07-08 16:25 - 00001160 _____ () C:\Users\Yasmin\Desktop\mbam.txt
2014-07-08 15:55 - 2014-07-08 15:55 - 00001059 _____ () C:\Users\Yasmin\Desktop\AdwCleaner[R2].txt
2014-07-07 18:55 - 2014-07-07 19:02 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-07 18:54 - 2014-07-07 18:55 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Yasmin\Downloads\revosetup95.exe
2014-07-06 21:27 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-06 21:27 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-06 21:27 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-06 21:27 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-06 21:27 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-06 21:27 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-06 21:27 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-06 21:27 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-06 21:25 - 2014-07-06 23:20 - 00000000 ____D () C:\Qoobox
2014-07-06 21:25 - 2014-07-06 23:17 - 00000000 ____D () C:\Windows\erdnt
2014-07-06 18:36 - 2014-07-06 21:22 - 05213907 ____R (Swearware) C:\Users\Yasmin\Desktop\ComboFix.exe
2014-07-05 19:50 - 2014-07-05 19:53 - 00037880 _____ () C:\Users\Yasmin\Downloads\Addition.txt
2014-07-05 19:48 - 2014-07-08 16:26 - 00016714 _____ () C:\Users\Yasmin\Downloads\FRST.txt
2014-07-05 19:48 - 2014-07-08 16:26 - 00000000 ____D () C:\FRST
2014-07-05 19:47 - 2014-07-05 19:48 - 02084352 _____ (Farbar) C:\Users\Yasmin\Downloads\FRST64.exe
2014-07-05 15:20 - 2014-07-05 15:20 - 00017609 _____ () C:\Ergebnisse.txt
2014-07-05 14:14 - 2014-07-08 15:57 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-05 14:14 - 2014-07-05 14:14 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-05 14:14 - 2014-07-05 14:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-05 14:13 - 2014-07-05 14:14 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-05 14:13 - 2014-07-05 14:13 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-05 14:13 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-05 14:13 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-05 14:13 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-05 14:09 - 2014-07-05 14:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Yasmin\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-05 13:49 - 2014-07-05 13:50 - 01346519 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.214.exe
2014-07-05 13:35 - 2014-07-05 13:35 - 00001185 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-07-05 13:35 - 2014-07-05 13:35 - 00001173 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-07-05 13:35 - 2014-07-05 13:35 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-07-05 13:19 - 2014-07-05 13:19 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\CrashRpt
2014-07-05 13:15 - 2014-07-05 13:15 - 00000954 _____ () C:\Users\Public\Desktop\Audials 11.lnk
2014-07-05 13:14 - 2014-07-05 13:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audials 11
2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\ProgramData\RapidSolution
2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\Program Files (x86)\Audials
2014-07-05 13:11 - 2014-07-05 13:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\RapidSolution
2014-07-05 13:07 - 2014-07-05 13:07 - 00470552 _____ () C:\Users\Yasmin\Downloads\soft32_TeamViewer_1.0.exe
2014-07-05 11:20 - 2014-07-05 11:20 - 00003224 _____ () C:\Windows\System32\Tasks\cmelajsb
2014-07-05 11:20 - 2014-07-05 11:20 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\cmelajsb.bat
2014-07-05 11:18 - 2014-07-05 11:18 - 00003220 _____ () C:\Windows\System32\Tasks\elsbix
2014-07-05 11:18 - 2014-07-05 11:18 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\elsbix.bat
2014-07-05 11:16 - 2014-07-05 11:16 - 00003222 _____ () C:\Windows\System32\Tasks\difkadc
2014-07-05 11:16 - 2014-07-05 11:16 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\difkadc.bat
2014-07-05 11:14 - 2014-07-05 11:14 - 00003220 _____ () C:\Windows\System32\Tasks\ehhiar
2014-07-05 11:14 - 2014-07-05 11:14 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\ehhiar.bat
2014-07-05 11:12 - 2014-07-05 11:12 - 00003220 _____ () C:\Windows\System32\Tasks\mrxota
2014-07-05 11:12 - 2014-07-05 11:12 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\mrxota.bat
2014-07-05 11:11 - 2014-07-05 11:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\com
2014-07-05 11:10 - 2014-07-05 11:10 - 00003224 _____ () C:\Windows\System32\Tasks\qscfhzbe
2014-07-05 11:10 - 2014-07-05 11:10 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\qscfhzbe.bat
2014-07-05 11:07 - 2014-07-05 11:07 - 00003220 _____ () C:\Windows\System32\Tasks\cfkxbi
2014-07-05 11:06 - 2014-07-05 20:03 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\name_07050906
2014-07-04 23:44 - 2014-07-04 23:44 - 00000030 _____ () C:\Users\Yasmin\Downloads\streamurl.ram
2014-07-04 22:09 - 2014-07-04 22:09 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{37404FF7-030E-48E2-A558-14DFA93EEE9E}
2014-07-03 21:58 - 2014-07-03 21:59 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E9BB536-0BF2-446D-8D48-DC87C01C2FC3}
2014-06-29 12:28 - 2014-06-29 12:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E1CAE782-0FD8-41B0-9FD8-7E33BBD98301}
2014-06-28 23:52 - 2014-06-28 23:52 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{810DEC4A-80C1-4FD5-B28B-5BFC530AE508}
2014-06-27 21:32 - 2014-06-27 21:32 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{24E647D5-B426-4A01-AF7E-14A6AE314912}
2014-06-26 20:30 - 2014-06-26 20:30 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{D8B715AD-B34D-4D33-A09C-C33244F9D5C0}
2014-06-25 19:28 - 2014-06-25 19:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E893FD49-F480-401D-914A-5942727764A4}
2014-06-24 21:22 - 2014-06-24 21:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{41D84405-36F0-449C-9EFA-213D56C3AA10}
2014-06-23 22:00 - 2014-06-23 22:00 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F110FA2D-C85B-4F52-B108-8E9ED1857A01}
2014-06-22 15:23 - 2014-06-22 15:23 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{75B97884-1D8B-4CCB-83FC-048BB61EB30E}
2014-06-21 20:24 - 2014-06-21 20:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{9C7EDFC2-FB6C-49EB-9193-23E5598340C5}
2014-06-20 23:26 - 2014-06-20 23:27 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B713B85D-3B2D-4962-8CA2-F1C383D94808}
2014-06-19 14:24 - 2014-06-19 14:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{FC9ED3F9-DD7E-411E-9269-3766501127B5}
2014-06-18 21:20 - 2014-06-18 21:20 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{EB3FAF98-E5F5-4F1E-8E10-ABA85A38A761}
2014-06-16 20:22 - 2014-06-16 20:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{3BF0F0AD-2D46-4BED-A50C-18E664F4F590}
2014-06-15 21:57 - 2014-06-15 21:57 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{19CDCCD7-B9FD-4316-A1B1-2D06A27CF368}
2014-06-15 20:58 - 2014-06-15 20:58 - 04631095 _____ () C:\Users\Yasmin\Documents\Unbenannt 1.odp
2014-06-15 15:41 - 2014-06-15 15:42 - 00000000 ___SD () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0
2014-06-15 15:41 - 2014-06-15 15:41 - 00001192 _____ () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0.lnk
2014-06-15 15:40 - 2014-06-15 15:41 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-06-15 15:38 - 2014-06-15 15:38 - 00000000 ____D () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0 (de) Installation Files
2014-06-15 15:21 - 2014-06-15 15:21 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer (1).exe
2014-06-15 15:01 - 2014-06-15 15:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero_AG
2014-06-15 15:00 - 2014-06-15 15:26 - 164962843 _____ () C:\Users\Yasmin\Downloads\Apache_OpenOffice_4.1.0_Win_x86_install_de.exe
2014-06-15 15:00 - 2014-06-15 15:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero
2014-06-15 14:59 - 2014-06-15 14:59 - 00003106 _____ () C:\Windows\System32\Tasks\{DCDD5B02-D205-4113-8043-ABDAB776D6F9}
2014-06-15 14:57 - 2014-06-15 14:59 - 106801603 _____ () C:\Users\Yasmin\Downloads\Nicht bestätigt 864307.crdownload
2014-06-15 14:51 - 2014-06-15 14:51 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer.exe
2014-06-15 14:20 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-15 14:17 - 2014-07-08 15:54 - 00000000 ____D () C:\AdwCleaner
2014-06-15 14:15 - 2014-06-15 14:16 - 01333465 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.212.exe
2014-06-14 17:48 - 2014-06-14 17:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-14 17:12 - 2014-06-14 17:13 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Adobe
2014-06-14 15:53 - 2014-06-14 15:53 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E519259-ADFA-4445-9FF2-A60967D85830}
2014-06-14 14:41 - 2014-06-14 14:41 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{51B5E13B-B124-4678-B7E1-59E1D21E084E}
2014-06-12 13:43 - 2014-06-12 13:43 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6D0186BE-0396-43A5-8D71-4D0C5779FE26}
2014-06-12 12:58 - 2014-06-12 12:58 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0 (1).exe
2014-06-11 22:31 - 2014-06-14 17:54 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\OpenOffice
2014-06-11 22:31 - 2014-06-11 22:31 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-06-11 22:24 - 2014-06-14 17:54 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Opera Software
2014-06-11 22:24 - 2014-06-11 22:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Opera Software
2014-06-11 22:23 - 2014-06-14 17:56 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMeterExpress
2014-06-11 22:22 - 2014-06-14 17:56 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\PriceMeter Express
2014-06-11 22:20 - 2014-06-15 14:29 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-11 22:19 - 2014-06-14 17:56 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér
2014-06-11 21:38 - 2014-07-08 16:17 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-11 21:38 - 2014-06-11 21:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-11 21:38 - 2014-06-11 21:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-11 21:38 - 2014-06-11 21:38 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-11 21:38 - 2014-06-11 21:38 - 00000000 ____D () C:\Windows\system32\Macromed
2014-06-11 21:16 - 2014-06-11 21:16 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0.exe
2014-06-11 20:07 - 2014-06-11 20:08 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F63CE874-95F4-4014-9FFA-E120BA697A33}
2014-06-11 19:44 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-11 19:44 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-11 19:44 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-11 19:44 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-11 19:44 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-11 19:44 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-11 19:44 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-11 19:44 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-11 19:44 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-11 19:44 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-11 19:44 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-11 19:44 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-11 19:44 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-11 19:44 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-11 19:44 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-11 19:44 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-11 19:44 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-11 19:44 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-11 19:44 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-11 19:44 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-11 19:44 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-11 19:44 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-11 19:44 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-11 19:44 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-11 19:44 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-11 19:44 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-11 19:44 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-11 19:44 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-11 19:44 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-11 19:44 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-11 19:44 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-11 19:44 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-11 19:44 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-11 19:44 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-11 19:44 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-11 19:44 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-11 19:44 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-11 19:44 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-11 19:44 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-11 19:44 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-11 19:44 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-11 19:44 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-11 19:44 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-11 19:44 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-11 19:44 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-11 19:44 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-11 19:44 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-11 19:44 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-11 19:44 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-11 19:44 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-11 19:44 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-11 19:44 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-11 19:44 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-11 19:44 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-11 19:44 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-11 19:44 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-11 19:44 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-11 19:44 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-11 19:44 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-11 19:44 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-11 19:44 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-11 19:44 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-11 19:44 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-11 19:44 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-11 19:43 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-11 19:43 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-11 17:31 - 2014-06-11 17:31 - 00047240 _____ (RapidSolution Software AG) C:\Windows\system32\Drivers\tbhsd.sys
2014-06-11 17:31 - 2014-06-11 17:31 - 00024744 _____ (Audials AG) C:\Windows\system32\Drivers\RrNetCapFilterDriver.sys
2014-06-10 20:28 - 2014-06-10 20:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{8DDAE57A-5162-4B54-83CA-34A6D1AD5A76}
2014-06-09 19:29 - 2014-06-09 19:29 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B679CC51-C608-4AE5-8429-423D93E97BB1}
2014-06-08 15:04 - 2014-06-08 15:04 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{BE799AB3-FEC9-439F-9EE9-50C2DEB968DE}

==================== One Month Modified Files and Folders =======

2014-07-08 16:27 - 2014-07-05 19:48 - 00016714 _____ () C:\Users\Yasmin\Downloads\FRST.txt
2014-07-08 16:26 - 2014-07-05 19:48 - 00000000 ____D () C:\FRST
2014-07-08 16:25 - 2014-07-08 16:25 - 00001160 _____ () C:\Users\Yasmin\Desktop\mbam.txt
2014-07-08 16:17 - 2014-06-11 21:38 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-08 15:57 - 2014-07-05 14:14 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-08 15:56 - 2009-07-14 06:45 - 00024912 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-08 15:56 - 2009-07-14 06:45 - 00024912 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-08 15:55 - 2014-07-08 15:55 - 00001059 _____ () C:\Users\Yasmin\Desktop\AdwCleaner[R2].txt
2014-07-08 15:54 - 2014-06-15 14:17 - 00000000 ____D () C:\AdwCleaner
2014-07-08 15:52 - 2014-01-12 03:20 - 02087468 _____ () C:\Windows\WindowsUpdate.log
2014-07-08 15:48 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-08 15:48 - 2009-07-14 06:51 - 00062638 _____ () C:\Windows\setupact.log
2014-07-07 21:58 - 2010-11-21 08:50 - 00699370 _____ () C:\Windows\system32\perfh007.dat
2014-07-07 21:58 - 2010-11-21 08:50 - 00149220 _____ () C:\Windows\system32\perfc007.dat
2014-07-07 21:58 - 2009-07-14 07:13 - 01619896 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-07 20:14 - 2014-01-13 20:52 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Skype
2014-07-07 19:07 - 2010-11-21 05:47 - 00155356 _____ () C:\Windows\PFRO.log
2014-07-07 19:02 - 2014-07-07 18:55 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-07 18:55 - 2014-07-07 18:54 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Yasmin\Downloads\revosetup95.exe
2014-07-07 18:46 - 2011-08-22 11:38 - 00000000 ____D () C:\Program Files\Common Files\mcafee
2014-07-06 23:20 - 2014-07-06 21:25 - 00000000 ____D () C:\Qoobox
2014-07-06 23:17 - 2014-07-06 21:25 - 00000000 ____D () C:\Windows\erdnt
2014-07-06 23:16 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-07-06 21:22 - 2014-07-06 18:36 - 05213907 ____R (Swearware) C:\Users\Yasmin\Desktop\ComboFix.exe
2014-07-05 20:03 - 2014-07-05 11:06 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\name_07050906
2014-07-05 19:53 - 2014-07-05 19:50 - 00037880 _____ () C:\Users\Yasmin\Downloads\Addition.txt
2014-07-05 19:48 - 2014-07-05 19:47 - 02084352 _____ (Farbar) C:\Users\Yasmin\Downloads\FRST64.exe
2014-07-05 15:20 - 2014-07-05 15:20 - 00017609 _____ () C:\Ergebnisse.txt
2014-07-05 14:14 - 2014-07-05 14:14 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-05 14:14 - 2014-07-05 14:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-05 14:14 - 2014-07-05 14:13 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-05 14:13 - 2014-07-05 14:13 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-05 14:10 - 2014-07-05 14:09 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Yasmin\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-05 14:04 - 2014-01-12 04:01 - 00064024 _____ () C:\Users\Yasmin\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-05 13:58 - 2009-07-14 06:45 - 00294736 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-05 13:56 - 2014-01-12 03:59 - 00000998 _____ () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-07-05 13:56 - 2011-08-22 11:52 - 00001289 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-05 13:56 - 2011-08-22 11:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-07-05 13:50 - 2014-07-05 13:49 - 01346519 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.214.exe
2014-07-05 13:35 - 2014-07-05 13:35 - 00001185 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-07-05 13:35 - 2014-07-05 13:35 - 00001173 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk
2014-07-05 13:35 - 2014-07-05 13:35 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2014-07-05 13:19 - 2014-07-05 13:19 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\CrashRpt
2014-07-05 13:15 - 2014-07-05 13:15 - 00000954 _____ () C:\Users\Public\Desktop\Audials 11.lnk
2014-07-05 13:15 - 2014-07-05 13:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audials 11
2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\ProgramData\RapidSolution
2014-07-05 13:14 - 2014-07-05 13:14 - 00000000 ____D () C:\Program Files (x86)\Audials
2014-07-05 13:11 - 2014-07-05 13:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\RapidSolution
2014-07-05 13:07 - 2014-07-05 13:07 - 00470552 _____ () C:\Users\Yasmin\Downloads\soft32_TeamViewer_1.0.exe
2014-07-05 11:20 - 2014-07-05 11:20 - 00003224 _____ () C:\Windows\System32\Tasks\cmelajsb
2014-07-05 11:20 - 2014-07-05 11:20 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\cmelajsb.bat
2014-07-05 11:18 - 2014-07-05 11:18 - 00003220 _____ () C:\Windows\System32\Tasks\elsbix
2014-07-05 11:18 - 2014-07-05 11:18 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\elsbix.bat
2014-07-05 11:16 - 2014-07-05 11:16 - 00003222 _____ () C:\Windows\System32\Tasks\difkadc
2014-07-05 11:16 - 2014-07-05 11:16 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\difkadc.bat
2014-07-05 11:14 - 2014-07-05 11:14 - 00003220 _____ () C:\Windows\System32\Tasks\ehhiar
2014-07-05 11:14 - 2014-07-05 11:14 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\ehhiar.bat
2014-07-05 11:12 - 2014-07-05 11:12 - 00003220 _____ () C:\Windows\System32\Tasks\mrxota
2014-07-05 11:12 - 2014-07-05 11:12 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\mrxota.bat
2014-07-05 11:11 - 2014-07-05 11:11 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\com
2014-07-05 11:10 - 2014-07-05 11:10 - 00003224 _____ () C:\Windows\System32\Tasks\qscfhzbe
2014-07-05 11:10 - 2014-07-05 11:10 - 00000266 _____ () C:\Users\Yasmin\AppData\Local\qscfhzbe.bat
2014-07-05 11:07 - 2014-07-05 11:07 - 00003220 _____ () C:\Windows\System32\Tasks\cfkxbi
2014-07-05 10:24 - 2011-08-22 11:38 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-07-04 23:44 - 2014-07-04 23:44 - 00000030 _____ () C:\Users\Yasmin\Downloads\streamurl.ram
2014-07-04 22:09 - 2014-07-04 22:09 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{37404FF7-030E-48E2-A558-14DFA93EEE9E}
2014-07-03 21:59 - 2014-07-03 21:58 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E9BB536-0BF2-446D-8D48-DC87C01C2FC3}
2014-06-29 12:28 - 2014-06-29 12:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E1CAE782-0FD8-41B0-9FD8-7E33BBD98301}
2014-06-28 23:52 - 2014-06-28 23:52 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{810DEC4A-80C1-4FD5-B28B-5BFC530AE508}
2014-06-27 21:32 - 2014-06-27 21:32 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{24E647D5-B426-4A01-AF7E-14A6AE314912}
2014-06-26 20:30 - 2014-06-26 20:30 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{D8B715AD-B34D-4D33-A09C-C33244F9D5C0}
2014-06-25 19:28 - 2014-06-25 19:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{E893FD49-F480-401D-914A-5942727764A4}
2014-06-24 21:22 - 2014-06-24 21:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{41D84405-36F0-449C-9EFA-213D56C3AA10}
2014-06-23 22:00 - 2014-06-23 22:00 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F110FA2D-C85B-4F52-B108-8E9ED1857A01}
2014-06-22 15:23 - 2014-06-22 15:23 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{75B97884-1D8B-4CCB-83FC-048BB61EB30E}
2014-06-21 20:24 - 2014-06-21 20:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{9C7EDFC2-FB6C-49EB-9193-23E5598340C5}
2014-06-20 23:27 - 2014-06-20 23:26 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B713B85D-3B2D-4962-8CA2-F1C383D94808}
2014-06-19 14:24 - 2014-06-19 14:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{FC9ED3F9-DD7E-411E-9269-3766501127B5}
2014-06-18 21:20 - 2014-06-18 21:20 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{EB3FAF98-E5F5-4F1E-8E10-ABA85A38A761}
2014-06-16 20:22 - 2014-06-16 20:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{3BF0F0AD-2D46-4BED-A50C-18E664F4F590}
2014-06-15 21:57 - 2014-06-15 21:57 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{19CDCCD7-B9FD-4316-A1B1-2D06A27CF368}
2014-06-15 20:58 - 2014-06-15 20:58 - 04631095 _____ () C:\Users\Yasmin\Documents\Unbenannt 1.odp
2014-06-15 15:42 - 2014-06-15 15:41 - 00000000 ___SD () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0
2014-06-15 15:41 - 2014-06-15 15:41 - 00001192 _____ () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0.lnk
2014-06-15 15:41 - 2014-06-15 15:40 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-06-15 15:38 - 2014-06-15 15:38 - 00000000 ____D () C:\Users\Yasmin\Desktop\OpenOffice 4.1.0 (de) Installation Files
2014-06-15 15:26 - 2014-06-15 15:00 - 164962843 _____ () C:\Users\Yasmin\Downloads\Apache_OpenOffice_4.1.0_Win_x86_install_de.exe
2014-06-15 15:21 - 2014-06-15 15:21 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer (1).exe
2014-06-15 15:01 - 2014-06-15 15:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero_AG
2014-06-15 15:01 - 2014-06-15 15:00 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Nero
2014-06-15 14:59 - 2014-06-15 14:59 - 00003106 _____ () C:\Windows\System32\Tasks\{DCDD5B02-D205-4113-8043-ABDAB776D6F9}
2014-06-15 14:59 - 2014-06-15 14:57 - 106801603 _____ () C:\Users\Yasmin\Downloads\Nicht bestätigt 864307.crdownload
2014-06-15 14:51 - 2014-06-15 14:51 - 00961360 _____ (Chip Digital GmbH) C:\Users\Yasmin\Downloads\OpenOffice - CHIP-Installer.exe
2014-06-15 14:29 - 2014-06-11 22:20 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-15 14:16 - 2014-06-15 14:15 - 01333465 _____ () C:\Users\Yasmin\Downloads\adwcleaner_3.212.exe
2014-06-15 14:02 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-06-14 18:11 - 2009-07-14 04:34 - 00000537 _____ () C:\Windows\win.ini
2014-06-14 17:59 - 2014-01-12 03:57 - 00000000 ____D () C:\Users\Yasmin
2014-06-14 17:56 - 2014-06-11 22:23 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMeterExpress
2014-06-14 17:56 - 2014-06-11 22:22 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\PriceMeter Express
2014-06-14 17:56 - 2014-06-11 22:19 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceMetér
2014-06-14 17:56 - 2014-05-07 19:09 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-14 17:56 - 2014-01-12 04:45 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\TOSHIBA_Corporation
2014-06-14 17:56 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-06-14 17:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-06-14 17:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-06-14 17:55 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-06-14 17:54 - 2014-06-11 22:31 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\OpenOffice
2014-06-14 17:54 - 2014-06-11 22:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Opera Software
2014-06-14 17:54 - 2014-02-21 01:06 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\SoftGrid Client
2014-06-14 17:54 - 2011-08-22 11:38 - 00000000 ____D () C:\ProgramData\McAfee
2014-06-14 17:48 - 2014-06-14 17:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-14 17:13 - 2014-06-14 17:12 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Adobe
2014-06-14 17:12 - 2014-01-12 16:08 - 00000000 ____D () C:\Users\Yasmin\AppData\Roaming\Adobe
2014-06-14 16:51 - 2014-01-12 04:01 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Toshiba
2014-06-14 15:53 - 2014-06-14 15:53 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6E519259-ADFA-4445-9FF2-A60967D85830}
2014-06-14 14:41 - 2014-06-14 14:41 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{51B5E13B-B124-4678-B7E1-59E1D21E084E}
2014-06-12 13:43 - 2014-06-12 13:43 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{6D0186BE-0396-43A5-8D71-4D0C5779FE26}
2014-06-12 12:58 - 2014-06-12 12:58 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0 (1).exe
2014-06-11 22:31 - 2014-06-11 22:31 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-06-11 22:24 - 2014-06-11 22:24 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\Opera Software
2014-06-11 21:38 - 2014-06-11 21:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-11 21:38 - 2014-06-11 21:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-11 21:38 - 2014-06-11 21:38 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-11 21:38 - 2014-06-11 21:38 - 00000000 ____D () C:\Windows\system32\Macromed
2014-06-11 21:16 - 2014-06-11 21:16 - 00468944 _____ () C:\Users\Yasmin\Downloads\soft32_Microsoft PowerPoint 2010_1.0.exe
2014-06-11 20:08 - 2014-06-11 20:07 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{F63CE874-95F4-4014-9FFA-E120BA697A33}
2014-06-11 17:31 - 2014-06-11 17:31 - 00047240 _____ (RapidSolution Software AG) C:\Windows\system32\Drivers\tbhsd.sys
2014-06-11 17:31 - 2014-06-11 17:31 - 00024744 _____ (Audials AG) C:\Windows\system32\Drivers\RrNetCapFilterDriver.sys
2014-06-10 20:28 - 2014-06-10 20:28 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{8DDAE57A-5162-4B54-83CA-34A6D1AD5A76}
2014-06-09 19:29 - 2014-06-09 19:29 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{B679CC51-C608-4AE5-8429-423D93E97BB1}
2014-06-08 15:04 - 2014-06-08 15:04 - 00000000 ____D () C:\Users\Yasmin\AppData\Local\{BE799AB3-FEC9-439F-9EE9-50C2DEB968DE}
2014-06-08 11:13 - 2014-06-11 19:43 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-11 19:43 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-11 20:02

==================== End Of Log ============================
         
--- --- ---

--- --- ---

--- --- ---


Mbam

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 08.07.2014
Suchlauf-Zeit: 15:57:35
Logdatei: mbam.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.07.08.04
Rootkit Datenbank: v2014.07.07.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Yasmin

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 282563
Verstrichene Zeit: 20 Min, 54 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 0
(No malicious items detected)

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 0
(No malicious items detected)

Dateien: 0
(No malicious items detected)

Physische Sektoren: 0
(No malicious items detected)


(end)
         
JRT

Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Yasmin on 08.07.2014 at 16:30:38,83
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{01F4689D-9EE5-45AC-92FB-22E936DE66B3}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{031FC851-4222-455C-AA4B-5EB5F5802E51}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{03912807-3A22-4FE2-8AFB-DBA93B1A52F6}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{05173330-94B6-42C4-96B4-3A7E7CFFB171}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{05915E00-ED26-4EFC-A667-69B687AB5B26}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{0C95668D-8E69-48D2-9804-95A0D51A76A5}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{0CBB26E7-1F9A-4F8E-8F7D-1A36EC950C05}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{0F2CD22F-46E5-4C0C-B075-0ED0C6D5CC66}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{11982317-4633-4194-9703-E5687E66E3C0}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{12AAC561-AFD9-4D4B-88DF-BC03D29D2DE7}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{13E179CA-D52D-4112-83CE-A2AD81DA5E75}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{14FBE841-44F8-4951-BF36-3329D8B0F89E}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{15B2E47D-8BBE-4292-9571-24F98E61B26A}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{15DEA250-6770-43C9-BBE7-A15631DD7A4F}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{1605570E-F265-4537-892C-BAF4A8959A1E}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{169018E4-E26B-4C7D-991D-748B64476810}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{16ED9A79-DEAD-4491-B11E-AE364FF9F754}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{18703BF3-925A-4048-8361-E321ED086303}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{18E5E849-801A-493A-A89D-70BE6406FF21}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{19CDCCD7-B9FD-4316-A1B1-2D06A27CF368}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{1A253856-F1E8-4568-BE2A-3C0EEB131058}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{1BFA21EA-0844-446E-BB8B-19DA9CDE9235}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{1C7794F2-5188-49CD-9D2E-3D124A66DE62}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{1DD6FC03-7FAF-4745-B087-88EEE0C3F35B}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{1E61FA61-83EC-4DF7-BD9F-456212236A7E}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{1EDB406F-B080-48F8-A7A4-669336E5C569}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{24E647D5-B426-4A01-AF7E-14A6AE314912}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{26D9C731-BE2A-4B37-853C-F18843B2D57F}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{26DACA7F-27DD-4B77-8422-8DD9B5D501AD}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{278E812D-78D1-40BC-A98C-FC7CB7DBB4D3}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{27E91624-A7A4-4A3B-8871-B90D79FB170A}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{2AA6BC0F-ECFE-479B-A838-56C342F235B6}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{2B2ACCC2-03C0-4FAD-9A67-72C3F3DD94C0}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{2B660AE8-3132-40CF-ADAD-D318E78C6135}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{2C26D848-0726-432B-9FF3-6973981872F1}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{2C2FFC3A-C97E-4326-81AB-73324EABC03D}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{2CA78C6D-4141-4B03-A24D-CDB6719DF53B}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{2DAEDF11-64A0-4A67-AB2F-3A9F0131EF75}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{3155A73D-E444-40EF-A2A8-6419CD2F9BBA}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{3248DC51-7280-4AE4-A67A-93DD8FEA2C6C}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{32F687CD-5AB3-4A7B-AC8C-AEB2AF12E4C7}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{37404FF7-030E-48E2-A558-14DFA93EEE9E}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{3A18D717-C485-4E3D-AB26-4572FDF4BCA5}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{3BF0F0AD-2D46-4BED-A50C-18E664F4F590}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{3E281AC7-30F7-4947-B991-CFDB1488ACAE}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{3F99EFB0-CFED-4D59-8255-F8C88D281A57}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{40317B7B-FF60-46CE-AFD0-F4FFEB439349}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{41D84405-36F0-449C-9EFA-213D56C3AA10}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{43EE14BC-6FBB-47D3-B0CD-85F55261DD4B}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{447C0671-870B-407C-8211-D06EB3E5FF28}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{45ACBBBC-0084-4079-8EAD-3240934481CA}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{4893FD4F-4D83-4A9C-90AA-834524E2A015}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{4B0C0035-442B-4D73-94DD-DE82FD32BBA4}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{4EFE1F6E-5772-40FA-A019-BC10317B1EA7}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{4F549286-2B1C-4FCC-95EF-B83528E22E8C}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{4FE1B648-AFFA-4589-B6F4-5EBCD1E32683}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{512DEA13-1FF2-4093-93FB-7621DBA3BCEB}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{51B5E13B-B124-4678-B7E1-59E1D21E084E}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{53971B5C-315D-44AD-B220-8807EAECA8D1}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{55C77714-63B1-44D0-8D43-FA859A3449D7}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{587872EA-2FA1-4AE9-899A-793487F6B9BE}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{5A614D0A-FF5B-45D8-B16D-EA754F8BBFDB}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{5AF9BD9D-C4D3-444C-8F21-1038A663509B}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{5D525624-F674-4CD4-9E66-19FE3DDB5F6E}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{5E263336-D1BA-44D7-B972-03A586700573}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{5F1050B8-1B3E-4291-B4DF-0255EB98CE0E}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{60DE3B45-7F02-40B6-839F-35325623B38D}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{62078431-3057-4D2F-A334-6BC214375EEC}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{62355EC8-25AA-41A8-8BBC-965872683B82}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{6409B39B-D4BE-4F07-B32F-AD0D9CF9C06D}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{64F0B40A-D957-468E-996C-22793CDEC6BB}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{6572E510-4C71-420D-A5A5-01DB32E2D582}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{65BB912D-11CD-41B6-8036-C084E78433CA}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{66B4BC5F-6919-4F52-AFB4-AF71BE240072}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{66F8F341-8208-4D00-9C17-3A61C4F88050}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{684E5F6C-69EA-4C09-9586-7C230EF42927}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{6D0186BE-0396-43A5-8D71-4D0C5779FE26}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{6E423027-85EF-4888-A2A7-4AEBF02F8A4B}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{6E519259-ADFA-4445-9FF2-A60967D85830}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{6E9BB536-0BF2-446D-8D48-DC87C01C2FC3}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{6EADF889-FA24-4D91-8396-2302A6F120B0}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{740E42C5-358A-41E9-A3A3-9182DB2E8505}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{74B17D7A-AFC1-4C50-9420-4DE5E99F6212}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{75B97884-1D8B-4CCB-83FC-048BB61EB30E}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{785E0FB4-7124-4612-BB59-C64AFE6EC45C}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{7AB836B5-DD7E-448A-B1EE-661C762A4812}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{7EE1AE3B-9FD1-4070-BCC2-20C3961C9D5C}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{7EEFA3BA-CDD7-4360-A6EF-B6FCD31BF5C5}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{810DEC4A-80C1-4FD5-B28B-5BFC530AE508}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{819795A9-6AFC-40A1-980A-1400BBB4B6FE}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{82EBA0EC-78CA-41EE-ADD9-A2396790867F}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{846697EB-B095-4034-93DD-D37F0109B617}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{852923AF-22C1-434C-92E5-03A3A024A487}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{86FF3BB0-CB57-4089-A96B-9FCAEA3E23B0}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{8A4131DB-79C2-43C4-8568-5EE7B940C019}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{8AE171D8-550A-4B55-B11E-75021755EE89}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{8B84EE17-2AF6-4CAD-9505-416F4486B04F}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{8C1AFCAC-F04E-43B1-ACE2-1576C8418C4F}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{8DDAE57A-5162-4B54-83CA-34A6D1AD5A76}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{8ECD87F2-83D9-46E3-BFB7-CBE98BC0C011}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{90A247D1-26EC-401E-988A-055662644AF8}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{9128FA43-3376-44AA-87C9-C1EF3604E985}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{9240A1A9-96FD-4D64-BBCC-EADD53C5FDCA}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{9280501E-1491-4CCC-8464-52D71275BE27}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{92909D5E-3F0C-4E5A-8532-3C848539E325}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{9416814D-8F05-441E-B7A2-DC4FCE6CFB7E}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{955697FB-5D54-4184-AE6A-C4D5C3C26F25}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{970A9DA1-29EA-48A7-A9DB-0F2A7F8C42D9}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{97E0DA87-8219-4B35-9207-659E3635874D}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{9940A864-C3CB-4123-A1FF-A38FC0CE834F}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{9C7EDFC2-FB6C-49EB-9193-23E5598340C5}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{9F7C0FBC-5BD0-499B-8484-74F69C8EC082}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{A0450E66-AB9C-44CB-A4E1-EA71F1F8D488}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{A09B5534-6543-4790-A9BD-D51EE5CEAABD}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{A25277D1-6374-468B-9781-5FFD9F47162A}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{A7478FA8-D20E-46F9-9282-6311A2588BDA}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{AB30E1EF-508A-4871-90A1-B6B5AF692241}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{ABD08CA5-4542-422D-BEB7-C8964A2D551A}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{AC89166E-757C-4DBC-B077-8BF37955B78B}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{ACEB128E-0725-4ECD-84A0-6AF3171270CB}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{ADB471F7-B107-4EF5-A735-B29678018445}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B03A38F6-50B2-4C13-A62A-AD4B3D50B9EE}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B13447A6-0C00-4CD7-8189-41AFE8B13C81}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B17628B5-4CEA-4821-8D31-78E702B2E077}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B2B9C21A-B008-4318-B2B3-9646A13004C5}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B5B73135-5D7D-4111-A776-47F505FEE543}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B65A5B5F-BB14-4816-A823-643B9563F2F1}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B679CC51-C608-4AE5-8429-423D93E97BB1}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B713B85D-3B2D-4962-8CA2-F1C383D94808}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B7A93844-0195-49B1-9BCF-90FB6A301A4A}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B905A3B3-D69D-4B11-AF37-E645E6B75A6C}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B90D8EBF-88BA-4898-8AF4-0F6F8AF9F88C}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{B980266A-CA3D-49CC-BE41-CD4940A6DA0D}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BB27BF72-F050-4847-B983-4274D3A75F43}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BB2CC748-4A6A-4D87-9CCC-E8B7D086D7CD}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BB6131C2-4EE9-4EE2-8CC6-B36895BA1CD9}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BBAB4503-8557-4966-BDDD-1A327C67F6EA}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BBAF2E4A-35B1-4B4B-9686-01E4124FC4AA}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BE036108-2517-48A6-9D52-716E67A6A211}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BE799AB3-FEC9-439F-9EE9-50C2DEB968DE}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{BEC65C83-DD24-4B35-A16F-5BFE1CD90CBA}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C022D95B-DB6F-436B-98A1-CDA88BFA5ED2}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C0F5E6BF-5EAC-4934-89C0-E99C782137B7}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C2019A68-C60F-43EA-9DE3-EDF97102D6CA}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C3659E30-5164-4C91-96A4-0541D5BEFFD2}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C37E7644-0272-4386-92C2-3C2874E2B867}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C3FE30AF-7F36-401B-8C2F-627441B90DCF}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C7A8E5F4-DBFF-44A9-A894-0D5661458100}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{C956742E-5EFA-4823-8AFA-EC8F20A640C5}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{CC29C4DB-F754-4569-B5F6-729DB8813CC9}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{CE854635-C891-4EDE-9861-AE0265325A83}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{CF34905A-5028-4671-8A5A-447B39459489}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{CF7D2ACF-448A-41B5-BF84-5362A8BE401C}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{D2DAB0AA-2A64-476B-BB7F-6860A45CB69E}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{D590CA53-B760-490D-AA85-D199A4A1F4EB}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{D5A893D9-C11E-4F46-B767-DCEBBA06356D}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{D7A13B7E-9439-403E-9047-DD065963BBFF}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{D80CFB59-0698-41C9-A943-BAE9171047BB}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{D8B715AD-B34D-4D33-A09C-C33244F9D5C0}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{D9CCFAAF-D7E4-4231-9C35-46E4AD5B00E5}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{DA52E3C0-4E3C-4F08-B048-2C475527C18F}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{DB85AE62-FB4D-4CD3-8D92-70708AACA449}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{DBA115D0-199D-4800-8192-1308AE3CAB39}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{DEF94305-E288-443B-8872-09C76CFAC60B}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{E1BFA2C5-0673-41DD-9C20-0B144E57FA19}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{E1CAE782-0FD8-41B0-9FD8-7E33BBD98301}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{E23FCE17-E953-4878-92E5-F00E65207F0A}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{E261E901-66DF-4EAC-8CC3-CCAFAEAF94E1}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{E3B5554C-F6DE-4C7C-AA68-76751477E5A8}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{E467674C-1BB9-479C-93E4-6CCA9D4BB5EC}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{E893FD49-F480-401D-914A-5942727764A4}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{EA6A6897-A949-49D1-8964-E7771C0D3A95}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{EB3FAF98-E5F5-4F1E-8E10-ABA85A38A761}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{EC2C2940-E6D2-41B9-9605-F2F43AEEE17D}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{EE03B039-8AD8-4950-8E41-F6EA1AEA5055}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{EEF60F01-9196-4953-8297-8EEA670583E3}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{EFB4FA9E-07B9-4960-BFEA-0DB82A358DC1}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{F09AC637-2DA5-429F-BE2D-5866D0FF0E0B}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{F110FA2D-C85B-4F52-B108-8E9ED1857A01}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{F63CE874-95F4-4014-9FFA-E120BA697A33}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{F6904E27-E387-4039-B0D5-F9686A790E2B}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{F6C1450B-9F15-4A6B-A2F5-E71C34FF35B1}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{F8680A6B-6E04-497A-A454-9D66301A9450}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FA6390DD-A1DC-4214-9147-49C9FBDF57A5}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FAC697A4-A264-409D-BF5E-E6AE2B2FC704}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FB267BA4-675D-4A67-A907-12DA5B82BA3D}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FC347101-2A51-4941-BD0E-8EAE6734E388}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FC9ED3F9-DD7E-411E-9269-3766501127B5}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FD19C800-2036-476F-8086-B858AFF47320}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FE2A955F-CE00-4345-82FB-830125192873}
Successfully deleted: [Empty Folder] C:\Users\Yasmin\appdata\local\{FFF8FA18-4B12-4922-8FF6-AB7047DF3B8E}



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 08.07.2014 at 16:47:11,77
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
AdwCleaner

Code:
ATTFilter
# AdwCleaner v3.214 - Bericht erstellt am 08/07/2014 um 15:53:27
# Aktualisiert 29/06/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Yasmin - YASMIN-TOSH
# Gestartet von : C:\Users\Yasmin\Downloads\adwcleaner_3.214.exe
# Option : Suchen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17126


-\\ Google Chrome v35.0.1916.114

[ Datei : C:\Users\Yasmin\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [24473 octets] - [15/06/2014 14:19:01]
AdwCleaner[R1].txt - [21733 octets] - [05/07/2014 13:51:01]
AdwCleaner[R2].txt - [854 octets]   - [08/07/2014 15:53:27]
AdwCleaner[S0].txt - [20206 octets] - [15/06/2014 14:21:27]
AdwCleaner[S1].txt - [17163 octets] - [05/07/2014 13:56:00]


########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [1095 octets] ##########
         
Gruß

Moin
ich melde mich kurz wieder
Wir haben Avira einmal durchlaufen lassen und es hat paar funde gefunden.
hier der Log

Code:
ATTFilter
Avira Free Antivirus
Erstellungsdatum der Reportdatei: Dienstag, 8. Juli 2014  19:32


Das Programm läuft als uneingeschränkte Vollversion.
Online-Dienste stehen zur Verfügung.

Lizenznehmer   : Avira Antivirus Free
Seriennummer   : 0000149996-AVHOE-0000001
Plattform      : Windows 7 Home Premium
Windowsversion : (Service Pack 1)  [6.1.7601]
Boot Modus     : Normal gebootet
Benutzername   : SYSTEM
Computername   : YASMIN-TOSH

Versionsinformationen:
BUILD.DAT      : 14.0.5.464     91868 Bytes  02.07.2014 13:06:00
AVSCAN.EXE     : 14.0.5.396   1042512 Bytes  02.07.2014 11:06:43
AVSCANRC.DLL   : 14.0.5.364     62544 Bytes  02.07.2014 11:06:43
LUKE.DLL       : 14.0.5.336     57936 Bytes  02.07.2014 11:06:46
AVSCPLR.DLL    : 14.0.5.376     89680 Bytes  02.07.2014 11:06:43
AVREG.DLL      : 14.0.5.356    261200 Bytes  02.07.2014 11:06:43
avlode.dll     : 14.0.5.396    588368 Bytes  02.07.2014 11:06:42
avlode.rdf     : 14.0.4.36      65096 Bytes  08.07.2014 17:27:44
XBV00008.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00009.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00010.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00011.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00012.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00013.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00014.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00015.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00016.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00017.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00018.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00019.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00020.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00021.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00022.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00023.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00024.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00025.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00026.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00027.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00028.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00029.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00030.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00031.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00032.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00033.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00034.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00035.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00036.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00037.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00038.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00039.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00040.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00041.VDF   : 8.11.153.142     2048 Bytes  06.06.2014 11:06:47
XBV00252.VDF   : 8.11.155.44     2048 Bytes  16.06.2014 11:06:47
XBV00253.VDF   : 8.11.155.44     2048 Bytes  16.06.2014 11:06:47
XBV00254.VDF   : 8.11.155.44     2048 Bytes  16.06.2014 11:06:47
XBV00255.VDF   : 8.11.155.44     2048 Bytes  16.06.2014 11:06:47
XBV00000.VDF   : 7.11.70.0   66736640 Bytes  04.04.2013 11:06:47
XBV00001.VDF   : 7.11.74.226  2201600 Bytes  30.04.2013 11:06:47
XBV00002.VDF   : 7.11.80.60   2751488 Bytes  28.05.2013 11:06:47
XBV00003.VDF   : 7.11.85.214  2162688 Bytes  21.06.2013 11:06:47
XBV00004.VDF   : 7.11.91.176  3903488 Bytes  23.07.2013 11:06:47
XBV00005.VDF   : 7.11.98.186  6822912 Bytes  29.08.2013 11:06:47
XBV00006.VDF   : 7.11.139.38 15708672 Bytes  27.03.2014 11:06:47
XBV00007.VDF   : 7.11.152.100  4193792 Bytes  02.06.2014 11:06:47
XBV00042.VDF   : 8.11.153.142   710656 Bytes  06.06.2014 11:06:47
XBV00043.VDF   : 8.11.155.44  1013760 Bytes  16.06.2014 11:06:47
XBV00044.VDF   : 8.11.155.46     3072 Bytes  16.06.2014 11:06:47
XBV00045.VDF   : 8.11.155.52    38912 Bytes  16.06.2014 11:06:47
XBV00046.VDF   : 8.11.155.54    29696 Bytes  16.06.2014 11:06:47
XBV00047.VDF   : 8.11.155.58    13824 Bytes  16.06.2014 11:06:47
XBV00048.VDF   : 8.11.155.62    20480 Bytes  17.06.2014 11:06:47
XBV00049.VDF   : 8.11.155.64     5632 Bytes  17.06.2014 11:06:47
XBV00050.VDF   : 8.11.155.66   139264 Bytes  17.06.2014 11:06:47
XBV00051.VDF   : 8.11.155.68     2048 Bytes  17.06.2014 11:06:47
XBV00052.VDF   : 8.11.155.70     6144 Bytes  17.06.2014 11:06:47
XBV00053.VDF   : 8.11.155.74   180224 Bytes  17.06.2014 11:06:47
XBV00054.VDF   : 8.11.155.78    18432 Bytes  17.06.2014 11:06:47
XBV00055.VDF   : 8.11.155.80     6144 Bytes  17.06.2014 11:06:47
XBV00056.VDF   : 8.11.155.82     4608 Bytes  18.06.2014 11:06:47
XBV00057.VDF   : 8.11.155.86    17408 Bytes  18.06.2014 11:06:47
XBV00058.VDF   : 8.11.155.100   144896 Bytes  18.06.2014 11:06:47
XBV00059.VDF   : 8.11.155.114    25088 Bytes  18.06.2014 11:06:47
XBV00060.VDF   : 8.11.155.128     2048 Bytes  18.06.2014 11:06:47
XBV00061.VDF   : 8.11.155.146    27648 Bytes  18.06.2014 11:06:47
XBV00062.VDF   : 8.11.155.148     2048 Bytes  18.06.2014 11:06:47
XBV00063.VDF   : 8.11.155.150   148992 Bytes  18.06.2014 11:06:47
XBV00064.VDF   : 8.11.155.152     5120 Bytes  18.06.2014 11:06:47
XBV00065.VDF   : 8.11.155.156    12800 Bytes  18.06.2014 11:06:47
XBV00066.VDF   : 8.11.155.158     2048 Bytes  18.06.2014 11:06:47
XBV00067.VDF   : 8.11.155.160     2048 Bytes  18.06.2014 11:06:47
XBV00068.VDF   : 8.11.155.164     7680 Bytes  18.06.2014 11:06:47
XBV00069.VDF   : 8.11.155.168    18432 Bytes  19.06.2014 11:06:47
XBV00070.VDF   : 8.11.155.172     2048 Bytes  19.06.2014 11:06:47
XBV00071.VDF   : 8.11.155.174     7680 Bytes  19.06.2014 11:06:47
XBV00072.VDF   : 8.11.155.176     2048 Bytes  19.06.2014 11:06:47
XBV00073.VDF   : 8.11.155.178     7680 Bytes  19.06.2014 11:06:47
XBV00074.VDF   : 8.11.155.180     5120 Bytes  19.06.2014 11:06:47
XBV00075.VDF   : 8.11.155.182     4608 Bytes  19.06.2014 11:06:47
XBV00076.VDF   : 8.11.155.184     6144 Bytes  19.06.2014 11:06:47
XBV00077.VDF   : 8.11.155.186     4608 Bytes  19.06.2014 11:06:47
XBV00078.VDF   : 8.11.155.188     5632 Bytes  19.06.2014 11:06:47
XBV00079.VDF   : 8.11.155.190     5120 Bytes  19.06.2014 11:06:47
XBV00080.VDF   : 8.11.155.192     2048 Bytes  19.06.2014 11:06:47
XBV00081.VDF   : 8.11.155.196    17408 Bytes  19.06.2014 11:06:47
XBV00082.VDF   : 8.11.155.200     2048 Bytes  19.06.2014 11:06:47
XBV00083.VDF   : 8.11.155.202     5632 Bytes  20.06.2014 11:06:47
XBV00084.VDF   : 8.11.155.204    14848 Bytes  20.06.2014 11:06:47
XBV00085.VDF   : 8.11.155.206     3072 Bytes  20.06.2014 11:06:47
XBV00086.VDF   : 8.11.155.208     2048 Bytes  20.06.2014 11:06:47
XBV00087.VDF   : 8.11.155.210    11264 Bytes  20.06.2014 11:06:47
XBV00088.VDF   : 8.11.155.214     4608 Bytes  20.06.2014 11:06:47
XBV00089.VDF   : 8.11.155.218     8704 Bytes  20.06.2014 11:06:47
XBV00090.VDF   : 8.11.155.222     2048 Bytes  20.06.2014 11:06:47
XBV00091.VDF   : 8.11.155.224     2048 Bytes  20.06.2014 11:06:47
XBV00092.VDF   : 8.11.155.228   151552 Bytes  20.06.2014 11:06:47
XBV00093.VDF   : 8.11.155.242    13312 Bytes  21.06.2014 11:06:47
XBV00094.VDF   : 8.11.156.2     12800 Bytes  21.06.2014 11:06:47
XBV00095.VDF   : 8.11.156.4     58368 Bytes  21.06.2014 11:06:47
XBV00096.VDF   : 8.11.156.18   146944 Bytes  21.06.2014 11:06:47
XBV00097.VDF   : 8.11.156.20     2048 Bytes  21.06.2014 11:06:47
XBV00098.VDF   : 8.11.156.22    49152 Bytes  22.06.2014 11:06:47
XBV00099.VDF   : 8.11.156.24     2048 Bytes  22.06.2014 11:06:47
XBV00100.VDF   : 8.11.156.26     9216 Bytes  22.06.2014 11:06:47
XBV00101.VDF   : 8.11.156.30     2048 Bytes  22.06.2014 11:06:47
XBV00102.VDF   : 8.11.156.32    12800 Bytes  22.06.2014 11:06:47
XBV00103.VDF   : 8.11.156.34    36352 Bytes  23.06.2014 11:06:47
XBV00104.VDF   : 8.11.156.36     2560 Bytes  23.06.2014 11:06:47
XBV00105.VDF   : 8.11.156.38     2048 Bytes  23.06.2014 11:06:47
XBV00106.VDF   : 8.11.156.40     7168 Bytes  23.06.2014 11:06:47
XBV00107.VDF   : 8.11.156.52     8704 Bytes  23.06.2014 11:06:47
XBV00108.VDF   : 8.11.156.72   204288 Bytes  23.06.2014 11:06:47
XBV00109.VDF   : 8.11.156.76     2048 Bytes  23.06.2014 11:06:47
XBV00110.VDF   : 8.11.156.88     2048 Bytes  23.06.2014 11:06:47
XBV00111.VDF   : 8.11.156.100     2048 Bytes  23.06.2014 11:06:47
XBV00112.VDF   : 8.11.156.114    37376 Bytes  24.06.2014 11:06:47
XBV00113.VDF   : 8.11.156.126     2048 Bytes  24.06.2014 11:06:47
XBV00114.VDF   : 8.11.156.144    28160 Bytes  24.06.2014 11:06:47
XBV00115.VDF   : 8.11.156.146     2048 Bytes  24.06.2014 11:06:47
XBV00116.VDF   : 8.11.156.150   145408 Bytes  24.06.2014 11:06:47
XBV00117.VDF   : 8.11.156.152    13824 Bytes  24.06.2014 11:06:47
XBV00118.VDF   : 8.11.156.154     2048 Bytes  24.06.2014 11:06:47
XBV00119.VDF   : 8.11.156.158    35328 Bytes  24.06.2014 11:06:47
XBV00120.VDF   : 8.11.156.160    18432 Bytes  24.06.2014 11:06:47
XBV00121.VDF   : 8.11.156.162     5632 Bytes  24.06.2014 11:06:47
XBV00122.VDF   : 8.11.156.166    10240 Bytes  24.06.2014 11:06:47
XBV00123.VDF   : 8.11.156.180    21504 Bytes  25.06.2014 11:06:47
XBV00124.VDF   : 8.11.156.190     3072 Bytes  25.06.2014 11:06:47
XBV00125.VDF   : 8.11.156.206   147968 Bytes  25.06.2014 11:06:47
XBV00126.VDF   : 8.11.156.208     2048 Bytes  25.06.2014 11:06:47
XBV00127.VDF   : 8.11.156.220     2048 Bytes  25.06.2014 11:06:47
XBV00128.VDF   : 8.11.156.232    29696 Bytes  25.06.2014 11:06:47
XBV00129.VDF   : 8.11.156.242     2048 Bytes  25.06.2014 11:06:47
XBV00130.VDF   : 8.11.157.0    181248 Bytes  26.06.2014 11:06:47
XBV00131.VDF   : 8.11.157.4     15872 Bytes  26.06.2014 11:06:47
XBV00132.VDF   : 8.11.157.6      2560 Bytes  26.06.2014 11:06:47
XBV00133.VDF   : 8.11.157.24   151552 Bytes  26.06.2014 11:06:47
XBV00134.VDF   : 8.11.157.26     9728 Bytes  26.06.2014 11:06:47
XBV00135.VDF   : 8.11.157.28     5632 Bytes  26.06.2014 11:06:47
XBV00136.VDF   : 8.11.157.30     2048 Bytes  26.06.2014 11:06:47
XBV00137.VDF   : 8.11.157.32    25600 Bytes  26.06.2014 11:06:47
XBV00138.VDF   : 8.11.157.38    42496 Bytes  26.06.2014 11:06:47
XBV00139.VDF   : 8.11.157.46     2048 Bytes  27.06.2014 11:06:47
XBV00140.VDF   : 8.11.157.50    15360 Bytes  27.06.2014 11:06:47
XBV00141.VDF   : 8.11.157.76     2048 Bytes  27.06.2014 11:06:47
XBV00142.VDF   : 8.11.157.78   166400 Bytes  27.06.2014 11:06:47
XBV00143.VDF   : 8.11.157.88     2048 Bytes  27.06.2014 11:06:47
XBV00144.VDF   : 8.11.157.98    17408 Bytes  27.06.2014 11:06:47
XBV00145.VDF   : 8.11.157.100     2048 Bytes  27.06.2014 11:06:47
XBV00146.VDF   : 8.11.157.110   158208 Bytes  27.06.2014 11:06:47
XBV00147.VDF   : 8.11.157.112   166912 Bytes  27.06.2014 11:06:47
XBV00148.VDF   : 8.11.157.114     2048 Bytes  27.06.2014 11:06:47
XBV00149.VDF   : 8.11.157.118    11264 Bytes  27.06.2014 11:06:47
XBV00150.VDF   : 8.11.157.120     2048 Bytes  27.06.2014 11:06:47
XBV00151.VDF   : 8.11.157.126   156160 Bytes  28.06.2014 11:06:47
XBV00152.VDF   : 8.11.157.128     2048 Bytes  28.06.2014 11:06:47
XBV00153.VDF   : 8.11.157.130     6144 Bytes  28.06.2014 11:06:47
XBV00154.VDF   : 8.11.157.132    14336 Bytes  28.06.2014 11:06:47
XBV00155.VDF   : 8.11.157.134     2048 Bytes  28.06.2014 11:06:47
XBV00156.VDF   : 8.11.157.138     3584 Bytes  29.06.2014 11:06:47
XBV00157.VDF   : 8.11.157.140     2048 Bytes  29.06.2014 11:06:47
XBV00158.VDF   : 8.11.157.142    26624 Bytes  29.06.2014 11:06:47
XBV00159.VDF   : 8.11.157.144     2048 Bytes  29.06.2014 11:06:47
XBV00160.VDF   : 8.11.157.146     2048 Bytes  29.06.2014 11:06:47
XBV00161.VDF   : 8.11.157.148    12800 Bytes  29.06.2014 11:06:47
XBV00162.VDF   : 8.11.157.150    55808 Bytes  30.06.2014 11:06:47
XBV00163.VDF   : 8.11.157.152     2048 Bytes  30.06.2014 11:06:47
XBV00164.VDF   : 8.11.157.162    10240 Bytes  30.06.2014 11:06:47
XBV00165.VDF   : 8.11.157.170     2048 Bytes  30.06.2014 11:06:47
XBV00166.VDF   : 8.11.157.178     5632 Bytes  30.06.2014 11:06:47
XBV00167.VDF   : 8.11.157.186     2048 Bytes  30.06.2014 11:06:47
XBV00168.VDF   : 8.11.157.196    37888 Bytes  30.06.2014 11:06:47
XBV00169.VDF   : 8.11.157.202     8192 Bytes  30.06.2014 11:06:47
XBV00170.VDF   : 8.11.157.204     2048 Bytes  30.06.2014 11:06:47
XBV00171.VDF   : 8.11.157.208     7168 Bytes  30.06.2014 11:06:47
XBV00172.VDF   : 8.11.157.210    16384 Bytes  30.06.2014 11:06:47
XBV00173.VDF   : 8.11.157.214     2048 Bytes  30.06.2014 11:06:47
XBV00174.VDF   : 8.11.157.218   162304 Bytes  01.07.2014 11:06:47
XBV00175.VDF   : 8.11.157.220     2048 Bytes  01.07.2014 11:06:47
XBV00176.VDF   : 8.11.157.222    18432 Bytes  01.07.2014 11:06:47
XBV00177.VDF   : 8.11.157.224     2048 Bytes  01.07.2014 11:06:47
XBV00178.VDF   : 8.11.157.226     2048 Bytes  01.07.2014 11:06:47
XBV00179.VDF   : 8.11.157.228    23040 Bytes  01.07.2014 11:06:47
XBV00180.VDF   : 8.11.157.234   152064 Bytes  01.07.2014 11:06:47
XBV00181.VDF   : 8.11.157.236     6656 Bytes  01.07.2014 11:06:47
XBV00182.VDF   : 8.11.157.238     2048 Bytes  01.07.2014 11:06:47
XBV00183.VDF   : 8.11.157.240     6144 Bytes  01.07.2014 11:06:47
XBV00184.VDF   : 8.11.157.242     2048 Bytes  01.07.2014 11:06:47
XBV00185.VDF   : 8.11.157.246     5632 Bytes  01.07.2014 11:06:47
XBV00186.VDF   : 8.11.157.248     2048 Bytes  01.07.2014 11:06:47
XBV00187.VDF   : 8.11.157.250     2560 Bytes  02.07.2014 11:06:47
XBV00188.VDF   : 8.11.157.254     3072 Bytes  02.07.2014 17:27:44
XBV00189.VDF   : 8.11.158.2    153600 Bytes  02.07.2014 17:27:44
XBV00190.VDF   : 8.11.158.4    178176 Bytes  02.07.2014 17:27:44
XBV00191.VDF   : 8.11.158.6     17920 Bytes  02.07.2014 17:27:44
XBV00192.VDF   : 8.11.158.14     2048 Bytes  02.07.2014 17:27:44
XBV00193.VDF   : 8.11.158.22     7680 Bytes  02.07.2014 17:27:44
XBV00194.VDF   : 8.11.158.30     2048 Bytes  02.07.2014 17:27:44
XBV00195.VDF   : 8.11.158.38     2560 Bytes  02.07.2014 17:27:44
XBV00196.VDF   : 8.11.158.50   166912 Bytes  02.07.2014 17:27:44
XBV00197.VDF   : 8.11.158.56     2560 Bytes  02.07.2014 17:27:44
XBV00198.VDF   : 8.11.158.62    38912 Bytes  03.07.2014 17:27:44
XBV00199.VDF   : 8.11.158.64     2048 Bytes  03.07.2014 17:27:44
XBV00200.VDF   : 8.11.158.68   174592 Bytes  03.07.2014 17:27:45
XBV00201.VDF   : 8.11.158.72     2048 Bytes  03.07.2014 17:27:45
XBV00202.VDF   : 8.11.158.74    12288 Bytes  03.07.2014 17:27:45
XBV00203.VDF   : 8.11.158.76     2048 Bytes  03.07.2014 17:27:45
XBV00204.VDF   : 8.11.158.78    14848 Bytes  03.07.2014 17:27:45
XBV00205.VDF   : 8.11.158.80    11264 Bytes  03.07.2014 17:27:45
XBV00206.VDF   : 8.11.158.84   185856 Bytes  03.07.2014 17:27:45
XBV00207.VDF   : 8.11.158.86     2048 Bytes  03.07.2014 17:27:45
XBV00208.VDF   : 8.11.158.88     3584 Bytes  03.07.2014 17:27:45
XBV00209.VDF   : 8.11.158.90     2048 Bytes  03.07.2014 17:27:45
XBV00210.VDF   : 8.11.158.92     9216 Bytes  03.07.2014 17:27:45
XBV00211.VDF   : 8.11.158.96    12800 Bytes  03.07.2014 17:27:45
XBV00212.VDF   : 8.11.158.98     6656 Bytes  03.07.2014 17:27:45
XBV00213.VDF   : 8.11.158.102    20992 Bytes  04.07.2014 17:27:45
XBV00214.VDF   : 8.11.158.108   161280 Bytes  04.07.2014 17:27:45
XBV00215.VDF   : 8.11.158.114    13312 Bytes  04.07.2014 17:27:45
XBV00216.VDF   : 8.11.158.116     2048 Bytes  04.07.2014 17:27:45
XBV00217.VDF   : 8.11.158.124     2048 Bytes  04.07.2014 17:27:45
XBV00218.VDF   : 8.11.158.134    42496 Bytes  04.07.2014 17:27:46
XBV00219.VDF   : 8.11.158.136   163328 Bytes  04.07.2014 17:27:46
XBV00220.VDF   : 8.11.158.138     2048 Bytes  04.07.2014 17:27:46
XBV00221.VDF   : 8.11.158.144    12288 Bytes  04.07.2014 17:27:46
XBV00222.VDF   : 8.11.158.146     2048 Bytes  04.07.2014 17:27:46
XBV00223.VDF   : 8.11.158.148     7680 Bytes  04.07.2014 17:27:46
XBV00224.VDF   : 8.11.158.154    22016 Bytes  05.07.2014 17:27:46
XBV00225.VDF   : 8.11.158.156     6656 Bytes  05.07.2014 17:27:46
XBV00226.VDF   : 8.11.158.158    10240 Bytes  05.07.2014 17:27:46
XBV00227.VDF   : 8.11.158.160     2048 Bytes  05.07.2014 17:27:46
XBV00228.VDF   : 8.11.158.162     9216 Bytes  05.07.2014 17:27:46
XBV00229.VDF   : 8.11.158.164     2048 Bytes  05.07.2014 17:27:47
XBV00230.VDF   : 8.11.158.166    36864 Bytes  06.07.2014 17:27:47
XBV00231.VDF   : 8.11.158.168    12288 Bytes  06.07.2014 17:27:47
XBV00232.VDF   : 8.11.158.174     8704 Bytes  06.07.2014 17:27:47
XBV00233.VDF   : 8.11.158.178     9216 Bytes  06.07.2014 17:27:47
XBV00234.VDF   : 8.11.158.182    36352 Bytes  07.07.2014 17:27:47
XBV00235.VDF   : 8.11.158.184     5632 Bytes  07.07.2014 17:27:47
XBV00236.VDF   : 8.11.158.186     4096 Bytes  07.07.2014 17:27:47
XBV00237.VDF   : 8.11.158.188   173056 Bytes  07.07.2014 17:27:47
XBV00238.VDF   : 8.11.158.190     2048 Bytes  07.07.2014 17:27:47
XBV00239.VDF   : 8.11.158.192     8704 Bytes  07.07.2014 17:27:47
XBV00240.VDF   : 8.11.158.194    29184 Bytes  07.07.2014 17:27:47
XBV00241.VDF   : 8.11.158.196     2048 Bytes  07.07.2014 17:27:47
XBV00242.VDF   : 8.11.158.198     7168 Bytes  07.07.2014 17:27:47
XBV00243.VDF   : 8.11.158.200     8704 Bytes  07.07.2014 17:27:47
XBV00244.VDF   : 8.11.158.204    33792 Bytes  07.07.2014 17:27:47
XBV00245.VDF   : 8.11.158.206     2048 Bytes  07.07.2014 17:27:47
XBV00246.VDF   : 8.11.158.208     2048 Bytes  07.07.2014 17:27:47
XBV00247.VDF   : 8.11.158.210    17408 Bytes  07.07.2014 17:27:47
XBV00248.VDF   : 8.11.158.214    18432 Bytes  08.07.2014 17:27:47
XBV00249.VDF   : 8.11.159.14   191488 Bytes  08.07.2014 17:27:48
XBV00250.VDF   : 8.11.159.40    35328 Bytes  08.07.2014 17:27:48
XBV00251.VDF   : 8.11.159.66     6144 Bytes  08.07.2014 17:27:48
LOCAL001.VDF   : 8.11.159.66 107874816 Bytes  08.07.2014 17:29:04
Engineversion  : 8.3.20.30 
AEVDF.DLL      : 8.3.0.4       118976 Bytes  02.07.2014 11:06:41
AESCRIPT.DLL   : 8.1.4.218     532680 Bytes  08.07.2014 17:27:43
AESCN.DLL      : 8.3.1.2       135360 Bytes  02.07.2014 11:06:41
AESBX.DLL      : 8.2.20.24    1409224 Bytes  02.07.2014 11:06:41
AERDL.DLL      : 8.2.0.138     704888 Bytes  02.07.2014 11:06:41
AEPACK.DLL     : 8.4.0.42      786632 Bytes  08.07.2014 17:27:43
AEOFFICE.DLL   : 8.3.0.8       205000 Bytes  08.07.2014 17:27:43
AEHEUR.DLL     : 8.1.4.1132   6820040 Bytes  02.07.2014 11:06:41
AEHELP.DLL     : 8.3.1.0       278728 Bytes  02.07.2014 11:06:41
AEGEN.DLL      : 8.1.7.28      450752 Bytes  02.07.2014 11:06:41
AEEXP.DLL      : 8.4.2.6       237760 Bytes  02.07.2014 11:06:41
AEEMU.DLL      : 8.1.3.2       393587 Bytes  02.07.2014 11:06:41
AEDROID.DLL    : 8.4.2.24      442568 Bytes  02.07.2014 11:06:41
AECORE.DLL     : 8.3.1.4       241864 Bytes  02.07.2014 11:06:41
AEBB.DLL       : 8.1.1.4        53619 Bytes  02.07.2014 11:06:41
AVWINLL.DLL    : 14.0.5.320     24144 Bytes  02.07.2014 11:06:44
AVPREF.DLL     : 14.0.5.320     50256 Bytes  02.07.2014 11:06:43
AVREP.DLL      : 14.0.5.320    219216 Bytes  02.07.2014 11:06:43
AVARKT.DLL     : 14.0.5.368    226384 Bytes  02.07.2014 11:06:42
AVEVTLOG.DLL   : 14.0.5.320    182352 Bytes  02.07.2014 11:06:42
SQLITE3.DLL    : 14.0.5.320    452176 Bytes  02.07.2014 11:06:47
AVSMTP.DLL     : 14.0.5.320     76368 Bytes  02.07.2014 11:06:44
NETNT.DLL      : 14.0.5.320     13392 Bytes  02.07.2014 11:06:46
RCIMAGE.DLL    : 14.0.5.320   4998224 Bytes  02.07.2014 11:06:46
RCTEXT.DLL     : 14.0.5.322     73808 Bytes  02.07.2014 11:06:46

Konfiguration für den aktuellen Suchlauf:
Job Name..............................: Vollständige Systemprüfung
Konfigurationsdatei...................: C:\Program Files (x86)\Avira\AntiVir Desktop\sysscan.avp
Protokollierung.......................: standard
Primäre Aktion........................: Interaktiv
Sekundäre Aktion......................: Ignorieren
Durchsuche Masterbootsektoren.........: ein
Durchsuche Bootsektoren...............: ein
Bootsektoren..........................: C:, D:, Q:, 
Durchsuche aktive Programme...........: ein
Laufende Programme erweitert..........: ein
Durchsuche Registrierung..............: ein
Suche nach Rootkits...................: ein
Integritätsprüfung von Systemdateien..: aus
Prüfe alle Dateien....................: Alle Dateien
Durchsuche Archive....................: ein
Rekursionstiefe einschränken..........: 20
Archiv Smart Extensions...............: ein
Makrovirenheuristik...................: ein
Dateiheuristik........................: erweitert

Beginn des Suchlaufs: Dienstag, 8. Juli 2014  19:32

Der Suchlauf über die Bootsektoren wird begonnen:
Bootsektor 'HDD0(C:, D:, Q:)'
    [INFO]      Es wurde kein Virus gefunden!

Der Suchlauf nach versteckten Objekten wird begonnen.

Der Suchlauf über gestartete Prozesse wird begonnen:
Durchsuche Prozess 'svchost.exe' - '52' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '36' Modul(e) wurden durchsucht
Durchsuche Prozess 'atiesrxx.exe' - '26' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '96' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '119' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '85' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '170' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '88' Modul(e) wurden durchsucht
Durchsuche Prozess 'atieclxx.exe' - '34' Modul(e) wurden durchsucht
Durchsuche Prozess 'spoolsv.exe' - '79' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '61' Modul(e) wurden durchsucht
Durchsuche Prozess 'SkypeC2CAutoUpdateSvc.exe' - '30' Modul(e) wurden durchsucht
Durchsuche Prozess 'SkypeC2CPNRSvc.exe' - '25' Modul(e) wurden durchsucht
Durchsuche Prozess 'RIconMan.exe' - '42' Modul(e) wurden durchsucht
Durchsuche Prozess 'sftvsa.exe' - '32' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '35' Modul(e) wurden durchsucht
Durchsuche Prozess 'TeamViewer_Service.exe' - '98' Modul(e) wurden durchsucht
Durchsuche Prozess 'TODDSrv.exe' - '23' Modul(e) wurden durchsucht
Durchsuche Prozess 'TosCoSrv.exe' - '26' Modul(e) wurden durchsucht
Durchsuche Prozess 'WLIDSVC.EXE' - '74' Modul(e) wurden durchsucht
Durchsuche Prozess 'sftlist.exe' - '77' Modul(e) wurden durchsucht
Durchsuche Prozess 'WLIDSvcM.exe' - '17' Modul(e) wurden durchsucht
Durchsuche Prozess 'wmiprvse.exe' - '49' Modul(e) wurden durchsucht
Durchsuche Prozess 'CVHSVC.EXE' - '83' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '37' Modul(e) wurden durchsucht
Durchsuche Prozess 'taskhost.exe' - '69' Modul(e) wurden durchsucht
Durchsuche Prozess 'Dwm.exe' - '33' Modul(e) wurden durchsucht
Durchsuche Prozess 'TosNcCore.exe' - '34' Modul(e) wurden durchsucht
Durchsuche Prozess 'TosReelTimeMonitor.exe' - '63' Modul(e) wurden durchsucht
Durchsuche Prozess 'TemproTray.exe' - '70' Modul(e) wurden durchsucht
Durchsuche Prozess 'TPwrMain.exe' - '38' Modul(e) wurden durchsucht
Durchsuche Prozess 'SmoothView.exe' - '15' Modul(e) wurden durchsucht
Durchsuche Prozess 'TCrdMain.exe' - '87' Modul(e) wurden durchsucht
Durchsuche Prozess 'RAVCpl64.exe' - '46' Modul(e) wurden durchsucht
Durchsuche Prozess 'RAVBg64.exe' - '45' Modul(e) wurden durchsucht
Durchsuche Prozess 'SynTPEnh.exe' - '61' Modul(e) wurden durchsucht
Durchsuche Prozess 'Skype.exe' - '135' Modul(e) wurden durchsucht
Durchsuche Prozess 'AudialsNotifier.exe' - '145' Modul(e) wurden durchsucht
Durchsuche Prozess 'TosDIMonitor.exe' - '93' Modul(e) wurden durchsucht
Durchsuche Prozess 'SynTPHelper.exe' - '17' Modul(e) wurden durchsucht
Durchsuche Prozess 'SearchIndexer.exe' - '57' Modul(e) wurden durchsucht
Durchsuche Prozess 'KeNotify.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'ToshibaServiceStation.exe' - '97' Modul(e) wurden durchsucht
Durchsuche Prozess 'MOM.exe' - '72' Modul(e) wurden durchsucht
Durchsuche Prozess 'wmpnetwk.exe' - '121' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '72' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '59' Modul(e) wurden durchsucht
Durchsuche Prozess 'CCC.exe' - '195' Modul(e) wurden durchsucht
Durchsuche Prozess 'DllHost.exe' - '45' Modul(e) wurden durchsucht
Durchsuche Prozess 'TMachInfo.exe' - '51' Modul(e) wurden durchsucht
Durchsuche Prozess 'PresentationFontCache.exe' - '35' Modul(e) wurden durchsucht
Durchsuche Prozess 'CFIWmxSvcs64.exe' - '17' Modul(e) wurden durchsucht
Durchsuche Prozess 'CFSvcs.exe' - '59' Modul(e) wurden durchsucht
Durchsuche Prozess 'NASvc.exe' - '46' Modul(e) wurden durchsucht
Durchsuche Prozess 'TosSmartSrv.exe' - '40' Modul(e) wurden durchsucht
Durchsuche Prozess 'TosSENotify.exe' - '42' Modul(e) wurden durchsucht
Durchsuche Prozess 'wuauclt.exe' - '39' Modul(e) wurden durchsucht
Durchsuche Prozess 'explorer.exe' - '167' Modul(e) wurden durchsucht
Durchsuche Prozess 'TeamViewer.exe' - '120' Modul(e) wurden durchsucht
Durchsuche Prozess 'tv_w32.exe' - '37' Modul(e) wurden durchsucht
Durchsuche Prozess 'tv_x64.exe' - '31' Modul(e) wurden durchsucht
Durchsuche Prozess 'avgnt.exe' - '98' Modul(e) wurden durchsucht
Durchsuche Prozess 'avguard.exe' - '107' Modul(e) wurden durchsucht
Durchsuche Prozess 'avshadow.exe' - '29' Modul(e) wurden durchsucht
Durchsuche Prozess 'sched.exe' - '60' Modul(e) wurden durchsucht
Durchsuche Prozess 'avscan.exe' - '119' Modul(e) wurden durchsucht
Durchsuche Prozess 'vssvc.exe' - '47' Modul(e) wurden durchsucht
Durchsuche Prozess 'svchost.exe' - '28' Modul(e) wurden durchsucht
Durchsuche Prozess 'smss.exe' - '2' Modul(e) wurden durchsucht
Durchsuche Prozess 'csrss.exe' - '18' Modul(e) wurden durchsucht
Durchsuche Prozess 'wininit.exe' - '26' Modul(e) wurden durchsucht
Durchsuche Prozess 'csrss.exe' - '18' Modul(e) wurden durchsucht
Durchsuche Prozess 'winlogon.exe' - '32' Modul(e) wurden durchsucht
Durchsuche Prozess 'services.exe' - '33' Modul(e) wurden durchsucht
Durchsuche Prozess 'lsass.exe' - '69' Modul(e) wurden durchsucht
Durchsuche Prozess 'lsm.exe' - '16' Modul(e) wurden durchsucht

Der Suchlauf auf Verweise zu ausführbaren Dateien (Registry) wird begonnen:
Die Registry wurde durchsucht ( '11115' Dateien ).


Der Suchlauf über die ausgewählten Dateien wird begonnen:

Beginne mit der Suche in 'C:\' <WINDOWS>
C:\AdwCleaner\Quarantine\C\Program Files (x86)\fst_de_37\freeSoftToday_widget.exe.vir
  [FUND]      Enthält Erkennungsmuster der Adware ADWARE/EoRezo.A.514
C:\AdwCleaner\Quarantine\C\Program Files (x86)\fst_de_37\fst_de_37.exe.vir
  [FUND]      Enthält Erkennungsmuster der Adware ADWARE/EoRezo.A.445
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\RSHP.exe.vir
  [FUND]      Enthält Erkennungsmuster der Adware ADWARE/Agent.oez.1
C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir
  [FUND]      Enthält Erkennungsmuster der Adware ADWARE/Agent.ALJT.1
C:\AdwCleaner\Quarantine\C\ProgramData\WPM\wprotectmanager.exe.vir
  [FUND]      Enthält Erkennungsmuster der Adware ADWARE/WProtManager.E
C:\Users\Yasmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9YP48W4V\5555-1001_NewPlayer[1].exe
    [0] Archivtyp: NSIS
    --> ProgramFilesDir/[PluginsDir]/e.dll
        [FUND]      Enthält Erkennungsmuster der Adware ADWARE/AgentCV.A.6945
        [WARNUNG]   Infizierte Dateien in Archiven können nicht repariert werden
C:\Users\Yasmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EDVMW6BW\setup_fst_de[1].exe
    [0] Archivtyp: Inno Setup
    --> {pf}\fst_de_37\fst_de_37.exe
        [FUND]      Enthält Erkennungsmuster der Adware ADWARE/EoRezo.A.445
        [WARNUNG]   Infizierte Dateien in Archiven können nicht repariert werden
    --> {pf}\fst_de_37\freeSoftToday_widget.exe
        [FUND]      Enthält Erkennungsmuster der Adware ADWARE/EoRezo.A.514
        [WARNUNG]   Infizierte Dateien in Archiven können nicht repariert werden
C:\Users\Yasmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VZEQBGKD\Setup[1].exe
  [FUND]      Enthält Erkennungsmuster der Adware ADWARE/InstallCore.Gen9
Beginne mit der Suche in 'D:\' <Data>
Beginne mit der Suche in 'Q:\'
Der zu durchsuchende Pfad Q:\ konnte nicht geöffnet werden!
Systemfehler [5]: Zugriff verweigert

Beginne mit der Desinfektion:
C:\Users\Yasmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VZEQBGKD\Setup[1].exe
  [FUND]      Enthält Erkennungsmuster der Adware ADWARE/InstallCore.Gen9
  [HINWEIS]   Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '50f0e7e9.qua' verschoben!
C:\Users\Yasmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EDVMW6BW\setup_fst_de[1].exe
  [FUND]      Enthält Erkennungsmuster der Adware ADWARE/EoRezo.A.514
  [HINWEIS]   Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '4867c84e.qua' verschoben!
C:\Users\Yasmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9YP48W4V\5555-1001_NewPlayer[1].exe
  [FUND]      Enthält Erkennungsmuster der Adware ADWARE/AgentCV.A.6945
  [HINWEIS]   Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '1df99356.qua' verschoben!
C:\AdwCleaner\Quarantine\C\ProgramData\WPM\wprotectmanager.exe.vir
  [FUND]      Enthält Erkennungsmuster der Adware ADWARE/WProtManager.E
  [HINWEIS]   Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '7c11dd53.qua' verschoben!
C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir
  [FUND]      Enthält Erkennungsmuster der Adware ADWARE/Agent.ALJT.1
  [HINWEIS]   Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '398af052.qua' verschoben!
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\RSHP.exe.vir
  [FUND]      Enthält Erkennungsmuster der Adware ADWARE/Agent.oez.1
  [HINWEIS]   Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '46a4c228.qua' verschoben!
C:\AdwCleaner\Quarantine\C\Program Files (x86)\fst_de_37\fst_de_37.exe.vir
  [FUND]      Enthält Erkennungsmuster der Adware ADWARE/EoRezo.A.445
  [HINWEIS]   Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '0a28ee42.qua' verschoben!
C:\AdwCleaner\Quarantine\C\Program Files (x86)\fst_de_37\freeSoftToday_widget.exe.vir
  [FUND]      Enthält Erkennungsmuster der Adware ADWARE/EoRezo.A.514
  [HINWEIS]   Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '7621ae12.qua' verschoben!


Ende des Suchlaufs: Dienstag, 8. Juli 2014  21:46
Benötigte Zeit:  1:53:05 Stunde(n)

Der Suchlauf wurde vollständig durchgeführt.

  26434 Verzeichnisse wurden überprüft
 534526 Dateien wurden geprüft
      9 Viren bzw. unerwünschte Programme wurden gefunden
      0 Dateien wurden als verdächtig eingestuft
      0 Dateien wurden gelöscht
      0 Viren bzw. unerwünschte Programme wurden repariert
      8 Dateien wurden in die Quarantäne verschoben
      0 Dateien wurden umbenannt
      0 Dateien konnten nicht durchsucht werden
 534517 Dateien ohne Befall
   9600 Archive wurden durchsucht
      3 Warnungen
      8 Hinweise
 672780 Objekte wurden beim Rootkitscan durchsucht
      0 Versteckte Objekte wurden gefunden
         

Geändert von JJ11 (08.07.2014 um 18:38 Uhr)

Alt 09.07.2014, 16:29   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Fake Flash-Player Update gedownloadet :(( - Standard

Fake Flash-Player Update gedownloadet :((



sind schon in Quarantäne oder in den temps


Fertig

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun

Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Fake Flash-Player Update gedownloadet :((
askbar, install.exe, installmanager.exe, launch, preferences, protectwindowsmanager.exe, pup.optional.betterdeals.a, pup.optional.blockandsurf.a, pup.optional.browserapp.a, pup.optional.bundleinstaller.a, pup.optional.ciuvo.a, pup.optional.conduit.a, pup.optional.downloader, pup.optional.extutil.a, pup.optional.freesoft, pup.optional.freesofttoday.a, pup.optional.freesoftwaretoday.a, pup.optional.iepluginservice.a, pup.optional.managera.a, pup.optional.newplayer.a, pup.optional.optimuminstaller.a, pup.optional.outbrowse, pup.optional.pricemeter.a, pup.optional.regcleanpro, pup.optional.searchhijacker.a, pup.optional.searchprotect.a, pup.optional.selectngo.a, pup.optional.skytech.a, pup.optional.superfish.a, pup.optional.v9.a, pup.optional.wpm.a, registrierungsdatenbank, speedchecker, windowsmangerprotect




Ähnliche Themen: Fake Flash-Player Update gedownloadet :((


  1. Notfall-Update schließt kritische Lücke in Flash Player
    Nachrichten - 24.06.2015 (0)
  2. Aufforderung zum Flash Player/Chrome Update
    Plagegeister aller Art und deren Bekämpfung - 11.11.2014 (17)
  3. Pop ups von Flash Player Updates etc. + Flash Player funktioniert nicht mehr
    Plagegeister aller Art und deren Bekämpfung - 24.07.2014 (8)
  4. Flash Player Update Virus
    Log-Analyse und Auswertung - 11.06.2014 (3)
  5. fake flash player update "install_flashplayer12x32au_mssd_awc_aih.exe " 812mb
    Log-Analyse und Auswertung - 05.02.2014 (10)
  6. Problem mit dem Update von Adobe Flash Player
    Log-Analyse und Auswertung - 27.01.2014 (1)
  7. Trojaner nach Adobe Flash Player Update
    Log-Analyse und Auswertung - 24.01.2014 (11)
  8. trotz flash player update funktioniert youtube etc nicht
    Log-Analyse und Auswertung - 15.01.2014 (2)
  9. Systembefall nach vermeindlichem Flash-Player Update
    Plagegeister aller Art und deren Bekämpfung - 27.08.2013 (9)
  10. seltsame popups, angeblich flash player update nötig - was tun?
    Plagegeister aller Art und deren Bekämpfung - 20.05.2013 (3)
  11. Schon wieder Notfall-Update für Flash-Player
    Nachrichten - 27.02.2013 (0)
  12. adobe flash player update Trojaner, FP_AX_CAB_INSTALLER.DMP
    Plagegeister aller Art und deren Bekämpfung - 31.10.2012 (13)
  13. Flash-Player-Update stopft bereits ausgenutzte Lücke
    Nachrichten - 16.02.2012 (0)
  14. Flash Player Update funktioniert nicht
    Alles rund um Windows - 03.09.2011 (6)
  15. Sicherheits-Update für Flash Player
    Nachrichten - 10.08.2011 (0)
  16. Flash player update
    Netzwerk und Hardware - 27.12.2010 (19)
  17. Virus nach Flash-Player Update?
    Log-Analyse und Auswertung - 05.12.2010 (28)

Zum Thema Fake Flash-Player Update gedownloadet :(( - Moin Moin, Eine Freundinn von mir hat auf einer Streaming Seite ein Fake Flash-Player Update gedownloadet. Da sie dachte das dieses Update wichtig wäre. Da hat sie mich um rat - Fake Flash-Player Update gedownloadet :((...
Archiv
Du betrachtest: Fake Flash-Player Update gedownloadet :(( auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.