Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Dauerhaftes Werbung öffnen macht Surfen fast unmöglich

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 09.07.2014, 16:01   #1
majin85
 
Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Standard

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich



Hi Trojaner-Board Team,

mein PC wird seit längerem von Werbung auf Internetseiten zugemüllt, das das Surfen im Internet fast unmöglich macht. An dem PC wurde auch länger nichts gemacht, da er meist nur zum Spielen benutzt wurde nur langsam wird das unerträglich mit der Werbung. Auf sehr vielen Empfehlungen wurde ich auf diese Seite hier verwiesen, da man nur gutes von eurem Team hört.

MfG Majin85

Alt 09.07.2014, 16:01   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Standard

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich



hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________

__________________

Alt 09.07.2014, 16:13   #3
majin85
 
Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Standard

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich




FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-07-2014
Ran by Michi (administrator) on MICHI-PC on 09-07-2014 16:08:45
Running from C:\Users\Michi\Desktop
Platform: Windows Vista (TM) Ultimate Service Pack 2 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool 
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool 
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
(Realtek) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe
() C:\Program Files (x86)\Verbindungsassistent\WTGService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe
() C:\Program Files (x86)\AVG Secure Search\vprot.exe
() C:\Program Files (x86)\Drakonia Configurator\hid.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\Drakonia Configurator\trayicon.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaUI.exe
() C:\Program Files (x86)\MSI\DualCoreCenter\DualCoreCenter.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [WinSys2] => C:\Windows\system32\startup.exe [52072 2008-01-30] ()
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation)
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DATAMNGR] => C:\PROGRA~2\WI371A~1\Datamngr\DATAMN~1.EXE
HKLM-x32\...\Run: [DelReg] => C:\Program Files (x86)\MSI\DualCoreCenter\DelReg.exe [196608 2008-05-13] ()
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Secure Search\vprot.exe [2571288 2014-06-22] ()
HKLM-x32\...\Run: [GamingMouse] => C:\Program Files (x86)\Drakonia Configurator\hid.exe [246784 2012-06-07] ()
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-06-10] (Geek Software GmbH)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [fst_de_16] => [X]
HKLM-x32\...\Run: [t4pc_en_3] => [X]
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: F - F:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {0c06a6e8-491c-11e1-b54f-806e6f6e6963} - F:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {0c06a733-491c-11e1-b54f-00218508a415} - F:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {1fae0cfc-7b48-11e1-8f4f-00218508a415} - G:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {63a44bda-6498-11e1-9987-00218508a415} - F:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {63a44bdb-6498-11e1-9987-00218508a415} - F:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {6b7f28c9-6317-11e1-b602-00218508a415} - F:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {6b7f28ca-6317-11e1-b602-00218508a415} - H:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {740ac0ff-ba1b-11e2-8ff3-00218508a415} - G:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {bbd552c5-f997-11e0-9681-00218508a415} - F:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {bbd552de-f997-11e0-9681-00218508a415} - G:\AutoRun.exe
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found
AppInit_DLLs:  C:\PROGRA~3\PERFOR~1\PERFOR~2.DLL => C:\ProgramData\Performancer\Performancer_x64.dll [4302848 2014-06-06] ()
AppInit_DLLs-x32: c:\progra~2\suptab\search~1.dll => "c:\progra~2\suptab\search~1.dll" File Not Found
AppInit_DLLs-x32:  c:\progra~3\perfor~1\perfor~1.dll => c:\ProgramData\Performancer\Performancer.dll [4129280 2014-06-06] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\DualCoreCenter.lnk
ShortcutTarget: DualCoreCenter.lnk -> C:\Program Files (x86)\MSI\DualCoreCenter\StartUpDualCoreCenter.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files (x86)\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
ShellIconOverlayIdentifiers: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = Babylon Search
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}
URLSearchHook: HKCU - (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = 
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms}
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms}
SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=MSD3_14_10_CH&cd=2XzuyEtN2Y1L1QzutDtDtBtCzzyDtDzz0AyEtCyDtAyC0A0FtN0D0Tzu0SyBzyyBtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyC0D0DtCyE0CyEtDtG0FyE0D0FtG0ByCtDyBtGtD0FtByDtGtBtBtC0FtByC0F0E0DyDyD0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyD0CtC0Ezz0EzytG0EtDyCtAtGzyzyyDyEtG0CtC0D0CtGyDtByB0F0E0FzyyB0AtCzytA2Q&cr=955174791&ir=
SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ATU2&o=14670&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=T8&apn_dtid=YYYYYYYYDE&apn_uid=a7e0a2c2-b71e-4c4e-a9d7-675ba3e934eb&apn_sauid=512B1239-32D0-4290-B3A3-B971CE7EF391
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = 
SearchScopes: HKCU - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://search.babylon.com/?q={searchTerms}&AF=17350&babsrc=SP_ss&mntrId=547436af000000000000000000000000
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms}
BHO: ProShopperu - {03ADD959-BBFF-DB15-3889-E3B782F798B3} - C:\ProgramData\ProShopperu\vd.x64.dll ()
BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -  No File
BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WI371A~1\Datamngr\x64\BROWSE~1.DLL No File
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: CoupScuanner - {EE8576D7-0A5F-FD10-841C-3FF359D97D4E} - C:\ProgramData\CoupScuanner\pUyJz3N_N.x64.dll ()
BHO: saavernett - {FB5E2C20-9D02-6288-3506-3C27D46DC1B2} - C:\ProgramData\saavernett\e.x64.dll ()
BHO-x32: ProShopperu - {03ADD959-BBFF-DB15-3889-E3B782F798B3} - C:\ProgramData\ProShopperu\vd.dll ()
BHO-x32: Plus-HD-2.2 - {11111111-1111-1111-1111-110311301136} - C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-bho.dll (Plus HD)
BHO-x32: HDvid Codec V1 - {11111111-1111-1111-1111-110311431162} - C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-bho.dll (installdaddy)
BHO-x32: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -  No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI371A~1\Datamngr\ToolBar\searchqudtx.dll No File
BHO-x32: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WI371A~1\Datamngr\BROWSE~1.DLL No File
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: CoupScuanner - {EE8576D7-0A5F-FD10-841C-3FF359D97D4E} - C:\ProgramData\CoupScuanner\pUyJz3N_N.dll ()
BHO-x32: saavernett - {FB5E2C20-9D02-6288-3506-3C27D46DC1B2} - C:\ProgramData\saavernett\e.dll ()
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI371A~1\Datamngr\ToolBar\searchqudtx.dll No File
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: HKLM-x32 {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll (AVG Secure Search)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default
FF SearchEngineOrder.1: Ask.com
FF DefaultSearchEngine: Ask.com
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.7\\npsitesafety.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ ()
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\ask-search.xml
FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\askcom.xml
FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\babylon.xml
FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\delta.xml
FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\Search_Results.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
FF Extension: Plus-HD-2.2 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com [2013-06-27]
FF Extension: Babylon - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\ffxtlbr@babylon.com [2012-01-31]
FF Extension: HDvid Codec 3 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc3@hdvidcodec.com [2013-08-09]
FF Extension: No Name - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\staged [2014-06-08]
FF Extension: Searchqu Toolbar - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} [2011-11-22]
FF Extension: HDvid Codec 3 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc3@hdvidcodec.com.xpi [2013-06-30]
FF Extension: HDvid Codec - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc@hdvc.com.xpi [2013-04-17]
FF Extension: Yontoo - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\plugin@yontoo.com.xpi [2013-05-23]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-11-02]

Chrome: 
=======
CHR HomePage: hxxp://www.google.com
CHR StartupUrls: "hxxp://www.google.com/"
CHR Plugin: (Shockwave Flash) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll (AVG Technologies)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Extension: (saavernett) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj [2014-06-08]
CHR Extension: (Adblock for Youtube™) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2013-12-04]
CHR Extension: (W3schools this!) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb [2014-05-18]
CHR Extension: (HDvid Codec 3) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnllcmllkjofnojidnaknldfehfhehoo [2013-08-09]
CHR Extension: (One Piece: Monkey D. Luffy (1366x768) Black) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebbcomiedmflgiplmdflpmkhkmkekcih [2013-07-20]
CHR Extension: (AdBlock) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-12-04]
CHR Extension: (Extensions new tab) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk [2014-06-20]
CHR Extension: (Twitch Stream) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce [2014-07-06]
CHR Extension: (Wikipedia search) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc [2014-06-08]
CHR Extension: (Postcron) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed [2014-06-16]
CHR Extension: (Plus-HD-2.2) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo [2013-07-20]
CHR Extension: (HDvid Codec) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpkbnefaikfaeadgidhpoanckoiaheli [2013-07-20]
CHR Extension: (Text Highlighter) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd [2014-05-18]
CHR Extension: (AVG Security Toolbar) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2013-07-20]
CHR Extension: (Google Wallet) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-18]
CHR HKLM-x32\...\Chrome\Extension: [dnllcmllkjofnojidnaknldfehfhehoo] - C:\Program Files (x86)\HDvidCodec.com\HDvidCodec10.crx [2013-06-30]
CHR HKLM-x32\...\Chrome\Extension: [kpkbnefaikfaeadgidhpoanckoiaheli] - C:\Program Files (x86)\HDvidCodec.com\HDvidCodec10.crx [2013-06-30]
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\18.1.0.443\avg.crx [2014-04-27]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-06-26] (BitRaider, LLC)
R2 dfc86759; c:\ProgramData\Performancer\PerformancerSvc.dll [186192 2014-06-06] () [File not signed]
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [704112 2014-05-08] (Cherished Technololgy LIMITED)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation)
S3 OnlineStorageService; C:\Program Files\Trend Micro SafeSync\hrfscore.exe [7908664 2012-07-12] (Trend Micro Inc.)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-08-22] (Overwolf Ltd)
S2 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [621632 2011-03-04] ()
R2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek) [File not signed]
R2 vToolbarUpdater18.1.7; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe [1813528 2014-06-22] (AVG Secure Search)
R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\wtgservice.exe [329168 2011-10-18] ()
S2 NewPlayer; C:\Program Files (x86)\NewPlayer\NewPlayerLwr161.exe [X]

==================== Drivers (Whitelisted) ====================

R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-06-22] (AVG Technologies)
R3 DualCoreCenter; C:\Program Files (x86)\MSI\DualCoreCenter\NTGLM7X64.sys [44344 2010-02-08] (MICRO-STAR INT'L CO., LTD.)
S3 GameKB; C:\Windows\System32\drivers\GameKB.sys [27648 2012-05-11] () [File not signed]
S3 hwdatacard; C:\Windows\SysWOW64\DRIVERS\ewusbmdm.sys [115328 2008-07-24] (Huawei Technologies Co., Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 MSIGreenPower; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\NTGLM7X64.sys [40248 2008-03-12] (MICRO-STAR INT'L CO., LTD.) [File not signed]
S3 MSIGreenPowerRushTop; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushTop64.sys [74072 2008-04-23] (Your Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7369v290\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [File not signed]
R3 NVR0Dev; C:\Windows\nvoclk64.sys [18216 2006-10-13] (NVidia Corp.)
R3 RushTopDevice2; C:\Program Files (x86)\MSI\DualCoreCenter\RushTop64.sys [76088 2009-03-18] (Your Corporation)
S3 RushTopDevice_J; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushJ64.sys [31544 2008-06-05] (Your Corporation) [File not signed]
R1 {9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64; C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64.sys [60088 2014-05-16] (StdLib)
S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S1 lhbjqqty; \??\C:\Windows\system32\drivers\lhbjqqty.sys [X]
S3 MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [X]
S1 neqnrghc; \??\C:\Windows\system32\drivers\neqnrghc.sys [X]
S3 netr28ux; system32\DRIVERS\netr28ux.sys [X]
S3 NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S1 rnigwgbp; \??\C:\Windows\system32\drivers\rnigwgbp.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-09 16:08 - 2014-07-09 16:09 - 00030116 _____ () C:\Users\Michi\Desktop\FRST.txt
2014-07-09 16:07 - 2014-07-09 16:08 - 00000000 ____D () C:\FRST
2014-07-09 16:05 - 2014-07-09 16:05 - 02084352 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe
2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip
2014-07-09 13:46 - 2014-06-07 06:02 - 17854464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 13:46 - 2014-06-07 04:59 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 13:46 - 2014-06-07 04:52 - 01348608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 13:46 - 2014-06-07 04:51 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 13:46 - 2014-06-07 04:51 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 13:46 - 2014-06-07 04:47 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 13:46 - 2014-06-07 04:45 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-07-09 13:46 - 2014-06-07 04:45 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 13:46 - 2014-06-07 04:45 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 13:46 - 2014-06-07 04:42 - 02148352 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 13:46 - 2014-06-07 04:42 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 13:46 - 2014-06-07 04:42 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 13:46 - 2014-06-07 04:42 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 13:46 - 2014-06-07 04:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 13:46 - 2014-06-07 04:41 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-07-09 13:46 - 2014-06-07 04:40 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 13:46 - 2014-06-07 04:39 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-07-09 13:46 - 2014-06-07 04:35 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 13:46 - 2014-06-07 02:05 - 12353024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-09 13:46 - 2014-06-07 01:12 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-09 13:46 - 2014-06-07 01:04 - 01106432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-09 13:46 - 2014-06-07 01:03 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-09 13:46 - 2014-06-07 01:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-09 13:46 - 2014-06-07 01:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-07-09 13:46 - 2014-06-07 00:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-07-09 13:46 - 2014-06-07 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-09 13:46 - 2014-06-07 00:54 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 13:46 - 2014-06-07 00:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-09 13:46 - 2014-06-07 00:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-07-09 13:46 - 2014-06-07 00:53 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-09 13:46 - 2014-06-07 00:52 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-09 13:46 - 2014-06-07 00:51 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-07-09 13:46 - 2014-06-07 00:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-09 13:45 - 2014-06-07 05:13 - 10890752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 13:45 - 2014-06-07 04:50 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-07-09 13:45 - 2014-06-07 04:41 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-07-09 13:45 - 2014-06-07 01:25 - 09711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-09 13:45 - 2014-06-07 00:58 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-09 13:45 - 2014-06-07 00:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-09 13:45 - 2014-06-07 00:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-09 13:45 - 2014-06-07 00:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-09 13:45 - 2014-06-07 00:53 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-07-09 13:44 - 2014-06-07 02:33 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 13:44 - 2014-06-06 10:59 - 00506880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-09 13:44 - 2014-06-06 09:13 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 13:44 - 2014-05-30 09:10 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-06 10:48 - 2014-07-06 10:48 - 00000000 ____D () C:\ProgramData\ProShopperu
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX
2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx
2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR
2014-06-26 15:21 - 2014-07-07 13:06 - 00000000 ____D () C:\ProgramData\BitRaider
2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk
2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment
2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk
2014-06-20 12:02 - 2014-06-20 12:03 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver
2014-06-20 10:16 - 2014-06-20 10:16 - 00000000 ____D () C:\ProgramData\CoupScuanner
2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk
2014-06-16 10:58 - 2014-06-16 10:57 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk
2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk
2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt
2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt
2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt
2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt
2014-06-15 11:44 - 2014-06-29 23:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe
2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe
2014-06-12 13:30 - 2014-04-26 20:21 - 00622592 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-12 13:30 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-12 13:30 - 2014-04-05 06:26 - 01417664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-12 13:30 - 2014-04-05 04:32 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-06-12 13:30 - 2014-03-10 08:26 - 01869824 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-12 13:30 - 2014-03-10 08:26 - 01794560 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-12 13:30 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-12 13:30 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll

==================== One Month Modified Files and Folders =======

2014-07-09 16:09 - 2014-07-09 16:08 - 00030116 _____ () C:\Users\Michi\Desktop\FRST.txt
2014-07-09 16:08 - 2014-07-09 16:07 - 00000000 ____D () C:\FRST
2014-07-09 16:05 - 2014-07-09 16:05 - 02084352 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe
2014-07-09 16:03 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-09 16:03 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-09 15:57 - 2013-05-06 22:53 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-09 15:56 - 2013-08-09 21:56 - 00001212 _____ () C:\Windows\Tasks\HDvid Codec V1-updater.job
2014-07-09 15:56 - 2013-08-09 21:56 - 00001116 _____ () C:\Windows\Tasks\HDvid Codec V1-enabler.job
2014-07-09 15:55 - 2013-08-09 21:55 - 00001206 _____ () C:\Windows\Tasks\HDvid Codec V1-codedownloader.job
2014-07-09 14:17 - 2013-05-14 23:00 - 01578094 _____ () C:\Windows\WindowsUpdate.log
2014-07-09 14:06 - 2013-06-27 23:26 - 00001906 _____ () C:\Windows\Tasks\Plus-HD-2.2-chromeinstaller.job
2014-07-09 14:06 - 2013-06-27 23:26 - 00001830 _____ () C:\Windows\Tasks\Plus-HD-2.2-firefoxinstaller.job
2014-07-09 14:06 - 2013-06-27 23:26 - 00001194 _____ () C:\Windows\Tasks\Plus-HD-2.2-updater.job
2014-07-09 14:05 - 2013-06-27 23:26 - 00001198 _____ () C:\Windows\Tasks\Plus-HD-2.2-codedownloader.job
2014-07-09 14:05 - 2013-06-27 23:26 - 00001098 _____ () C:\Windows\Tasks\Plus-HD-2.2-enabler.job
2014-07-09 14:05 - 2013-05-06 22:53 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-09 14:03 - 2014-03-13 18:14 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-09 14:03 - 2006-11-02 17:40 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-09 14:03 - 2006-11-02 17:21 - 00255776 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-09 13:59 - 2006-11-02 17:40 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-09 13:59 - 2006-11-02 17:06 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-09 13:57 - 2013-07-22 05:26 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-09 13:54 - 2006-11-02 14:35 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip
2014-07-09 00:35 - 2012-08-16 08:22 - 00001692 _____ () C:\Users\Michi\Desktop\bla.txt
2014-07-07 13:06 - 2014-06-26 15:21 - 00000000 ____D () C:\ProgramData\BitRaider
2014-07-07 12:56 - 2011-10-18 16:41 - 00055560 _____ () C:\Users\Michi\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-07 12:54 - 2011-10-19 16:48 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-07-06 10:48 - 2014-07-06 10:48 - 00000000 ____D () C:\ProgramData\ProShopperu
2014-07-06 10:48 - 2014-06-08 19:55 - 00000000 ____D () C:\ProgramData\297d856b205d5963
2014-07-05 16:05 - 2011-11-22 11:56 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\vlc
2014-07-05 01:02 - 2012-02-02 03:37 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\TS3Client
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX
2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx
2014-07-04 17:09 - 2011-10-18 16:41 - 00000000 ____D () C:\Users\Michi
2014-07-03 14:42 - 2012-05-11 00:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Skype
2014-06-30 06:36 - 2011-10-20 02:44 - 00175616 _____ () C:\Users\Michi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-29 23:08 - 2014-06-15 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2014-06-27 11:36 - 2013-08-30 14:25 - 00000000 ____D () C:\Users\Michi\Desktop\TS Icons
2014-06-27 11:19 - 2012-02-02 03:35 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR
2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
2014-06-26 14:06 - 2013-07-20 12:23 - 00014744 _____ () C:\Users\Michi\Documents\Install STAR WARS The Old Republic.log
2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2014-06-26 14:05 - 2014-05-18 13:49 - 00000000 _____ () C:\END
2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2014-06-23 08:33 - 2013-05-06 15:32 - 00001217 _____ () C:\Users\Michi\Desktop\WoW PWS.lnk
2014-06-22 19:39 - 2014-04-27 17:13 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-06-22 19:39 - 2013-06-26 20:25 - 00050464 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-06-22 19:39 - 2013-06-26 20:25 - 00000000 ____D () C:\Program Files (x86)\AVG Secure Search
2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk
2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment
2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk
2014-06-20 12:03 - 2014-06-20 12:02 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver
2014-06-20 10:16 - 2014-06-20 10:16 - 00000000 ____D () C:\ProgramData\CoupScuanner
2014-06-17 17:56 - 2012-12-13 10:46 - 00000000 ____D () C:\Filme
2014-06-17 17:56 - 2012-08-25 14:45 - 00000000 ____D () C:\Users\Michi\Desktop\Wma
2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk
2014-06-16 11:00 - 2014-02-03 14:46 - 00155136 _____ () C:\Windows\SysWOW64\unrar.dll
2014-06-16 11:00 - 2014-02-03 14:46 - 00034308 _____ () C:\Windows\SysWOW64\bassmod.dll
2014-06-16 10:57 - 2014-06-16 10:58 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk
2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk
2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt
2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt
2014-06-16 07:18 - 2013-05-12 09:58 - 00000000 ____D () C:\Windows\SysWOW64\directx
2014-06-16 07:18 - 2012-01-27 19:49 - 00000000 ____D () C:\Games
2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt
2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt
2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe
2014-06-15 11:25 - 2013-05-12 18:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Wargaming.net
2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-09 14:08

==================== End Of Log ============================
         
--- --- ---
FRST Additions Logfile:
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-07-2014
Ran by Michi at 2014-07-09 16:09:51
Running from C:\Users\Michi\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.8.800.175 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.7.700.224 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
aTube Catcher (HKLM-x32\...\aTube Catcher) (Version: 3.8.7955 - DsNET Corp)
AVG Security Toolbar (HKLM-x32\...\AVG Secure Search) (Version: 18.1.7.644 - AVG Technologies)
Bing Maps 3D (HKLM\...\{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}) (Version: 4.0.903.16005 - Microsoft Corporation)
BitRaider Web Client (HKLM-x32\...\BitRaider Web Client) (Version: 1.1.9.9 - BitRaider, LLC)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
CoupScuanner (HKLM-x32\...\{80E8B0A0-117D-1402-7CDE-688156237115}) (Version:  - CCoupScAnneR)
Drakonia Configurator (HKLM-x32\...\{A7B243AA-6D4C-4575-A873-6F01A1EFC5E2}}_is1) (Version:  - )
DriverTuner 3.1.0.0 (HKLM-x32\...\{520C1D80-935C-42B9-9340-E883849D804F}_is1) (Version: 3.1.0.0 - LionSea SoftWare)
DualCoreCenter (HKLM-x32\...\DualCoreCenter_is1) (Version:  - MSI, Inc.)
EasyViewer (HKLM-x32\...\InstallShield_{EECD7B96-1416-4D3A-B12D-0D2512120C36}) (Version: 1.3.0.9 - MSI)
EasyViewer (x32 Version: 1.3.0.9 - MSI) Hidden
ffdshow v1.2.4422 [2012-04-09] (HKLM-x32\...\ffdshow_is1) (Version: 1.2.4422.0 - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.137 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
HDvid Codec V1 (HKLM-x32\...\HDvid Codec V1) (Version: 1.27.153.8 - installdaddy) <==== ATTENTION
HDVidCodec (HKLM-x32\...\1ClickDownload) (Version: 2.1 Build 26473 - hdvidcodec.com) <==== ATTENTION
iLivid (HKLM-x32\...\iLivid) (Version: 1.92.0.117387 - Bandoo Media Inc.) <==== ATTENTION
iLivid (x32 Version: 1.92.0.117387 - Bandoo Media Inc.) Hidden <==== ATTENTION
Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.550 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 5.9.6 - )
NVIDIA 3D Vision Controller Driver (x32 Version: 280.19 - NVIDIA Corporation) Hidden
NVIDIA 3D Vision Treiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 311.06 - NVIDIA Corporation)
NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.12.5896 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation)
NVIDIA GeForce Experience 1.8.2.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.2.1 - NVIDIA Corporation)
NVIDIA Grafiktreiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.06 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) Hidden
NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 311.06 (Version: 311.06 - NVIDIA Corporation) Hidden
NVIDIA Update 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden
NVIDIA Update Core (Version: 11.10.13 - NVIDIA Corporation) Hidden
OpenOffice.org 3.4 (HKLM-x32\...\{4C552FD3-2CCD-4E00-AC64-0681DBB3F8B5}) (Version: 3.4.9590 - OpenOffice.org)
Overwolf (HKLM-x32\...\{48615A7B-F026-4F62-A3F1-49001B8E21CB}) (Version: 0.44.256 - Overwolf)
PDF24 Creator 5.6.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version:  - PDF24.org)
Performancer (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{dfc86759}) (Version:  - 24soft) <==== ATTENTION
Plus-HD-2.2 (HKLM-x32\...\Plus-HD-2.2) (Version: 1.27.153.6 - Plus HD) <==== ATTENTION
ProShopperu (HKLM-x32\...\{8F213470-964F-4092-6B31-BC7570F31B5A}) (Version:  - ProShopper) <==== ATTENTION
Ralink RT2860 Wireless LAN Card (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.5.12.0 - Ralink)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 6.250.908.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6873 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver and Utility (HKLM-x32\...\{9C049499-055C-4a0c-A916-1D8CA1FF45EB}) (Version: 1.00.0182 - REALTEK Semiconductor Corp.)
saavernett (HKLM-x32\...\{614925F9-841A-53FE-A28F-DC30FA07239B}) (Version:  - saveRnEt)
Samsung_MonSetup (HKLM-x32\...\{8EA79DBF-D637-448A-89D6-410A087A4493}) (Version: 1.00.0000 - Samsung)
Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version: 7.0.0.45 - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
System Requirements Lab (HKLM-x32\...\SystemRequirementsLab) (Version:  - )
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH)
Trend Micro SafeSync (HKLM\...\HFRS_is1) (Version: 5.1.0.1173 - Trend Micro)
Ultimate Extras sounds from Microsoft® Tinker™ (HKLM\...\UltSounds2) (Version:  - Microsoft Corporation)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
Verbindungsassistent (HKLM-x32\...\Verbindungsassistent) (Version: 2.1 - Verbindungsassistent)
VideoGenie (HKLM-x32\...\{FC54FD8D-789C-406D-BB88-F7C4421B7E83}_is1) (Version: 1.0.0.12 - MSI)
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
VLC classic (HKLM-x32\...\VLC classic) (Version: 1.14 - vlcplayerdownload.com)
W322U (HKLM-x32\...\{B64CEFD3-B6AB-40CD-8333-EDDBDB951751}) (Version: 1.00.0000 - Tenda)
Winamp (HKLM-x32\...\Winamp) (Version: 5.621  - Nullsoft, Inc)
Winamp Erkennungs-Plug-in (HKCU\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Windows iLivid Toolbar (HKLM-x32\...\Windows Searchqu Toolbar) (Version: 3.0.0.117530 - Bandoo Media, Inc) <==== ATTENTION
Windows-Soundschemas (HKLM\...\UltSounds) (Version:  - Microsoft Corporation)
WinRAR 4.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH)

==================== Restore Points  =========================

30-06-2014 13:35:10 Geplanter Prüfpunkt
02-07-2014 17:26:26 Geplanter Prüfpunkt
03-07-2014 14:40:32 Geplanter Prüfpunkt
04-07-2014 09:27:42 Windows Update
04-07-2014 15:07:27 Installiert SHARKOON Skiller
04-07-2014 15:08:55 Gerätetreiber-Paketinstallation: Sharkoon Eingabegeräte (Human Interface Devices)
05-07-2014 16:59:42 Geplanter Prüfpunkt
06-07-2014 18:15:02 Entfernt SHARKOON Skiller
07-07-2014 11:06:44 Windows Update
08-07-2014 00:05:18 Geplanter Prüfpunkt
08-07-2014 13:17:40 Geplanter Prüfpunkt
09-07-2014 11:53:30 Windows Update

==================== Hosts content: ==========================

2006-11-02 14:34 - 2006-09-18 23:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
::1             localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {00C5BFF5-EEAF-4637-93EA-ADF6229D3234} - System32\Tasks\Plus-HD-2.2-firefoxinstaller => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-firefoxinstaller.exe [2013-06-27] (Plus HD) <==== ATTENTION
Task: {07B42F71-7E37-4EC3-8E83-4BE1FFE5C03D} - System32\Tasks\eType Setup => C:\Users\Michi\AppData\Local\Temp\eType Setup403431.exe <==== ATTENTION
Task: {0871AFF5-575C-40FC-A05F-24E29DC1452B} - System32\Tasks\HDvid Codec V1-codedownloader => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-codedownloader.exe [2013-08-09] (installdaddy) <==== ATTENTION
Task: {09D6CD90-BE85-4FF1-9D62-B51B87202CCF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-06] (Google Inc.)
Task: {09EAFC8C-A951-41B9-8D2B-A1F18FBB21EC} - System32\Tasks\Plus-HD-2.2-chromeinstaller => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-chromeinstaller.exe [2013-06-27] (Plus HD) <==== ATTENTION
Task: {0D36FC03-8888-410A-9037-DF358381DDF0} - System32\Tasks\HDvid Codec V1-updater => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-updater.exe [2013-08-09] (installdaddy) <==== ATTENTION
Task: {27664485-6DD3-4E67-A392-23E241238E1D} - System32\Tasks\Plus-HD-2.2-codedownloader => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-codedownloader.exe [2013-06-27] (Plus HD) <==== ATTENTION
Task: {27DC0BEB-20BB-4BAF-A4D6-C38628372658} - System32\Tasks\Plus-HD-2.2-enabler => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-enabler.exe [2013-06-27] (Plus HD) <==== ATTENTION
Task: {3027772B-B827-4998-B62C-4E4C617B5DFA} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {34F4AFBD-4B27-4161-BB74-EC0D1F6139BC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-06] (Google Inc.)
Task: {720B96CE-CD10-4370-A0B1-73D2741DFC9D} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files (x86)\TuneUp Utilities 2010\OneClick.exe
Task: {8E146441-DDF2-4E33-AEA7-A1CECCAEBA5B} - System32\Tasks\HDvid Codec V1-enabler => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-enabler.exe [2013-08-09] (installdaddy) <==== ATTENTION
Task: {9475DD97-BB54-4FD8-A31A-032B4833F6AA} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {996457A5-8249-47C5-B620-CA695B7E6DA1} - System32\Tasks\WOT WFRI1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {9A441CE9-6C4F-4991-954B-EDCB9256D04F} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => Rundll32.exe %windir%\system32\pla.dll,PlaConvertLogEntries
Task: {AA105019-BFFB-4713-B627-81B47F4419F0} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {ADDB4957-FD21-4041-ADF2-C1DAF0991DA8} - System32\Tasks\Plus-HD-2.2-updater => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-updater.exe [2013-06-27] (Plus HD) <==== ATTENTION
Task: {C0B38178-CA76-4475-90EB-B2F41221156B} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {C28278BF-1ABF-4595-BB2A-15201DDF25E3} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {C41E9FD5-A5DB-4DEF-9715-E4F7BAFEE730} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {E7D52131-C543-4A8D-8669-9FEC0C9AEE08} - System32\Tasks\{6E07F2B2-386B-4ABF-9A74-F6643ABA3D4E} => Chrome.exe Skype auf Ihren Computer herunterladen ? Mac, Windows, Linux*?*Skype
Task: {F5B3AF16-E40C-4C45-B115-2698E999BB9F} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HDvid Codec V1-codedownloader.job => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\HDvid Codec V1-enabler.job => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\HDvid Codec V1-updater.job => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-2.2-chromeinstaller.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-chromeinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-2.2-codedownloader.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-2.2-enabler.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-2.2-firefoxinstaller.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-firefoxinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-2.2-updater.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-updater.exe <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2014-06-06 09:51 - 2014-06-06 09:51 - 04302848 _____ () C:\ProgramData\Performancer\Performancer_x64.dll
2014-06-22 19:39 - 2014-06-22 19:39 - 00159768 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe
2011-10-18 16:53 - 2011-10-18 17:02 - 00329168 _____ () C:\Program Files (x86)\Verbindungsassistent\wtgservice.exe
2011-12-30 03:30 - 2011-05-28 23:05 - 00164864 _____ () C:\Program Files\WinRAR\rarext.dll
2011-07-18 23:04 - 2011-07-18 23:04 - 00301568 _____ () C:\Program Files (x86)\Notepad++\NppShell_04.dll
2013-06-26 20:25 - 2014-06-22 19:39 - 02571288 _____ () C:\Program Files (x86)\AVG Secure Search\vprot.exe
2013-06-29 11:36 - 2012-06-07 10:24 - 00246784 _____ () C:\Program Files (x86)\Drakonia Configurator\hid.exe
2013-06-29 11:36 - 2012-06-14 10:44 - 00240640 _____ () C:\Program Files (x86)\Drakonia Configurator\trayicon.exe
2013-05-08 09:35 - 2010-06-29 18:20 - 41382002 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\DualCoreCenter.exe
2014-06-06 09:51 - 2014-06-06 09:51 - 04129280 _____ () c:\ProgramData\Performancer\Performancer.dll
2014-06-06 09:51 - 2014-06-06 09:51 - 00186192 _____ () c:\ProgramData\Performancer\PerformancerSvc.dll
2014-06-22 19:39 - 2014-06-22 19:39 - 00519704 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\log4cplusU.dll
2013-06-29 11:36 - 2011-11-22 14:18 - 00061440 _____ () C:\Program Files (x86)\Drakonia Configurator\HidDevice.dll
2013-06-29 11:36 - 2011-11-22 14:18 - 00249856 _____ () C:\Program Files (x86)\Drakonia Configurator\language.dll
2013-10-08 02:19 - 2011-05-04 19:53 - 01058664 _____ () C:\Program Files (x86)\Ralink\Common\RaWLAPI.dll
2013-05-08 09:35 - 2009-03-17 16:36 - 00147456 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\RushTop.dll
2013-05-08 09:35 - 2007-01-05 11:59 - 00077824 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\CpuUsage.dll
2013-05-08 09:35 - 2008-09-08 15:02 - 00094208 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\VGADLL.dll
2014-05-18 12:42 - 2014-05-08 01:29 - 00065352 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\chrome_elf.dll
2014-05-18 12:42 - 2014-05-08 01:29 - 04081480 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\pdf.dll
2014-05-18 12:42 - 2014-05-08 01:29 - 00390472 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ppGoogleNaClPluginChrome.dll
2014-05-18 12:42 - 2014-05-08 01:29 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ffmpegsumo.dll
2014-05-18 12:42 - 2014-05-08 01:29 - 13695816 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:679ABA25

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service"

==================== EXE Association (whitelisted) =============


==================== MSCONFIG/TASK MANAGER disabled items =========


==================== Faulty Device Manager Devices =============

Name: Microsoft-ISATAP-Adapter #2
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Microsoft-ISATAP-Adapter #3
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Microsoft-ISATAP-Adapter #4
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Microsoft-ISATAP-Adapter #5
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Microsoft-ISATAP-Adapter #6
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: PolicyAgent4

Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4

Error: (07/09/2014 02:06:55 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: EmdCache4

Error: (07/09/2014 02:04:56 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: PolicyAgent4

Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: EmdCache4

Error: (07/09/2014 01:35:21 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: PolicyAgent4

Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4

Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: EmdCache4


System errors:
=============
Error: (07/09/2014 02:05:53 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: 30000Realtek11nSU

Error: (07/09/2014 02:04:57 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: 30000Ralink UPnP Media Server

Error: (07/09/2014 02:02:23 PM) (Source: disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (07/09/2014 02:02:23 PM) (Source: Ntfs) (EventID: 137) (User: )
Description: Der Transaktionsressourcen-Manager auf Volume "F:" konnte aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (07/09/2014 02:02:19 PM) (Source: disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (07/09/2014 02:02:11 PM) (Source: disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (07/09/2014 02:02:07 PM) (Source: disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (07/09/2014 01:35:21 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: 30000Ralink UPnP Media Server

Error: (07/09/2014 01:33:54 PM) (Source: disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (07/09/2014 01:33:54 PM) (Source: Ntfs) (EventID: 137) (User: )
Description: Der Transaktionsressourcen-Manager auf Volume "F:" konnte aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.


Microsoft Office Sessions:
=========================
Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: PolicyAgent4

Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4

Error: (07/09/2014 02:06:55 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: EmdCache4

Error: (07/09/2014 02:04:56 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: PolicyAgent4

Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: EmdCache4

Error: (07/09/2014 01:35:21 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: PolicyAgent4

Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4

Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: EmdCache4


CodeIntegrity Errors:
===================================
  Date: 2014-07-08 13:48:59.581
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-07-08 13:48:59.269
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-07-08 13:48:58.941
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-07-08 13:48:58.613
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-07-08 13:48:57.988
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-07-08 13:48:57.675
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-07-07 03:40:54.653
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-07-07 03:40:54.325
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-07-07 03:40:53.995
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

  Date: 2014-07-07 03:40:53.661
  Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info =========================== 

Percentage of memory in use: 53%
Total physical RAM: 4094.46 MB
Available physical RAM: 1923.58 MB
Total Pagefile: 8425.43 MB
Available Pagefile: 5869.19 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:232.88 GB) (Free:36.72 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive e: (F) (Fixed) (Total:149.05 GB) (Free:38.31 GB) NTFS
Drive f: () (Fixed) (Total:298.09 GB) (Free:98.98 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: A2DEA2DE)
Partition 1: (Active) - (Size=233 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 8136E346)
Partition 1: (Active) - (Size=298 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (Size: 149 GB) (Disk ID: 3FC1A37E)
Partition 1: (Not Active) - (Size=149 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
--- --- ---



Hi, super das ging ja schnell das du dich meiner annimmst eben noch andere Themen von dir gelesen
__________________

Alt 09.07.2014, 16:14   #4
majin85
 
Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Standard

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich




FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-07-2014
Ran by Michi (administrator) on MICHI-PC on 09-07-2014 16:08:45
Running from C:\Users\Michi\Desktop
Platform: Windows Vista (TM) Ultimate Service Pack 2 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool 
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool 
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Cherished Technololgy LIMITED) C:\ProgramData\IePluginServices\PluginService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
(Realtek) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe
() C:\Program Files (x86)\Verbindungsassistent\WTGService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe
() C:\Program Files (x86)\AVG Secure Search\vprot.exe
() C:\Program Files (x86)\Drakonia Configurator\hid.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\Drakonia Configurator\trayicon.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaUI.exe
() C:\Program Files (x86)\MSI\DualCoreCenter\DualCoreCenter.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [WinSys2] => C:\Windows\system32\startup.exe [52072 2008-01-30] ()
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation)
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DATAMNGR] => C:\PROGRA~2\WI371A~1\Datamngr\DATAMN~1.EXE
HKLM-x32\...\Run: [DelReg] => C:\Program Files (x86)\MSI\DualCoreCenter\DelReg.exe [196608 2008-05-13] ()
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Secure Search\vprot.exe [2571288 2014-06-22] ()
HKLM-x32\...\Run: [GamingMouse] => C:\Program Files (x86)\Drakonia Configurator\hid.exe [246784 2012-06-07] ()
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-06-10] (Geek Software GmbH)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [fst_de_16] => [X]
HKLM-x32\...\Run: [t4pc_en_3] => [X]
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: F - F:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {0c06a6e8-491c-11e1-b54f-806e6f6e6963} - F:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {0c06a733-491c-11e1-b54f-00218508a415} - F:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {1fae0cfc-7b48-11e1-8f4f-00218508a415} - G:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {63a44bda-6498-11e1-9987-00218508a415} - F:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {63a44bdb-6498-11e1-9987-00218508a415} - F:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {6b7f28c9-6317-11e1-b602-00218508a415} - F:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {6b7f28ca-6317-11e1-b602-00218508a415} - H:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {740ac0ff-ba1b-11e2-8ff3-00218508a415} - G:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {bbd552c5-f997-11e0-9681-00218508a415} - F:\AutoRun.exe
HKU\S-1-5-21-503261611-1707939866-3478010161-1000\...\MountPoints2: {bbd552de-f997-11e0-9681-00218508a415} - G:\AutoRun.exe
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File Not Found
AppInit_DLLs:  C:\PROGRA~3\PERFOR~1\PERFOR~2.DLL => C:\ProgramData\Performancer\Performancer_x64.dll [4302848 2014-06-06] ()
AppInit_DLLs-x32: c:\progra~2\suptab\search~1.dll => "c:\progra~2\suptab\search~1.dll" File Not Found
AppInit_DLLs-x32:  c:\progra~3\perfor~1\perfor~1.dll => c:\ProgramData\Performancer\Performancer.dll [4129280 2014-06-06] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\DualCoreCenter.lnk
ShortcutTarget: DualCoreCenter.lnk -> C:\Program Files (x86)\MSI\DualCoreCenter\StartUpDualCoreCenter.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files (x86)\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
ShellIconOverlayIdentifiers: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = Babylon Search
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}
URLSearchHook: HKCU - (No Name) - {D8278076-BC68-4484-9233-6E7F1628B56C} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = 
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms}
SearchScopes: HKLM-x32 - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms}
SearchScopes: HKCU - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms}
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=MSD3_14_10_CH&cd=2XzuyEtN2Y1L1QzutDtDtBtCzzyDtDzz0AyEtCyDtAyC0A0FtN0D0Tzu0SyBzyyBtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyC0D0DtCyE0CyEtDtG0FyE0D0FtG0ByCtDyBtGtD0FtByDtGtBtBtC0FtByC0F0E0DyDyD0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyD0CtC0Ezz0EzytG0EtDyCtAtGzyzyyDyEtG0CtC0D0CtGyDtByB0F0E0FzyyB0AtCzytA2Q&cr=955174791&ir=
SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ATU2&o=14670&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=T8&apn_dtid=YYYYYYYYDE&apn_uid=a7e0a2c2-b71e-4c4e-a9d7-675ba3e934eb&apn_sauid=512B1239-32D0-4290-B3A3-B971CE7EF391
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = 
SearchScopes: HKCU - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://search.babylon.com/?q={searchTerms}&AF=17350&babsrc=SP_ss&mntrId=547436af000000000000000000000000
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=119&systemid=406&sr=0&q={searchTerms}
BHO: ProShopperu - {03ADD959-BBFF-DB15-3889-E3B782F798B3} - C:\ProgramData\ProShopperu\vd.x64.dll ()
BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -  No File
BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WI371A~1\Datamngr\x64\BROWSE~1.DLL No File
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: CoupScuanner - {EE8576D7-0A5F-FD10-841C-3FF359D97D4E} - C:\ProgramData\CoupScuanner\pUyJz3N_N.x64.dll ()
BHO: saavernett - {FB5E2C20-9D02-6288-3506-3C27D46DC1B2} - C:\ProgramData\saavernett\e.x64.dll ()
BHO-x32: ProShopperu - {03ADD959-BBFF-DB15-3889-E3B782F798B3} - C:\ProgramData\ProShopperu\vd.dll ()
BHO-x32: Plus-HD-2.2 - {11111111-1111-1111-1111-110311301136} - C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-bho.dll (Plus HD)
BHO-x32: HDvid Codec V1 - {11111111-1111-1111-1111-110311431162} - C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-bho.dll (installdaddy)
BHO-x32: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -  No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI371A~1\Datamngr\ToolBar\searchqudtx.dll No File
BHO-x32: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WI371A~1\Datamngr\BROWSE~1.DLL No File
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: CoupScuanner - {EE8576D7-0A5F-FD10-841C-3FF359D97D4E} - C:\ProgramData\CoupScuanner\pUyJz3N_N.dll ()
BHO-x32: saavernett - {FB5E2C20-9D02-6288-3506-3C27D46DC1B2} - C:\ProgramData\saavernett\e.dll ()
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI371A~1\Datamngr\ToolBar\searchqudtx.dll No File
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: HKLM-x32 {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll (AVG Secure Search)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default
FF SearchEngineOrder.1: Ask.com
FF DefaultSearchEngine: Ask.com
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.7\\npsitesafety.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ ()
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\ask-search.xml
FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\askcom.xml
FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\babylon.xml
FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\delta.xml
FF SearchPlugin: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\Search_Results.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
FF Extension: Plus-HD-2.2 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com [2013-06-27]
FF Extension: Babylon - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\ffxtlbr@babylon.com [2012-01-31]
FF Extension: HDvid Codec 3 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc3@hdvidcodec.com [2013-08-09]
FF Extension: No Name - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\staged [2014-06-08]
FF Extension: Searchqu Toolbar - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\{99079a25-328f-4bd4-be04-00955acaa0a7} [2011-11-22]
FF Extension: HDvid Codec 3 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc3@hdvidcodec.com.xpi [2013-06-30]
FF Extension: HDvid Codec - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc@hdvc.com.xpi [2013-04-17]
FF Extension: Yontoo - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\plugin@yontoo.com.xpi [2013-05-23]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-11-02]

Chrome: 
=======
CHR HomePage: hxxp://www.google.com
CHR StartupUrls: "hxxp://www.google.com/"
CHR Plugin: (Shockwave Flash) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll (AVG Technologies)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Extension: (saavernett) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj [2014-06-08]
CHR Extension: (Adblock for Youtube™) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2013-12-04]
CHR Extension: (W3schools this!) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb [2014-05-18]
CHR Extension: (HDvid Codec 3) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnllcmllkjofnojidnaknldfehfhehoo [2013-08-09]
CHR Extension: (One Piece: Monkey D. Luffy (1366x768) Black) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebbcomiedmflgiplmdflpmkhkmkekcih [2013-07-20]
CHR Extension: (AdBlock) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-12-04]
CHR Extension: (Extensions new tab) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk [2014-06-20]
CHR Extension: (Twitch Stream) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce [2014-07-06]
CHR Extension: (Wikipedia search) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc [2014-06-08]
CHR Extension: (Postcron) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed [2014-06-16]
CHR Extension: (Plus-HD-2.2) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo [2013-07-20]
CHR Extension: (HDvid Codec) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpkbnefaikfaeadgidhpoanckoiaheli [2013-07-20]
CHR Extension: (Text Highlighter) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd [2014-05-18]
CHR Extension: (AVG Security Toolbar) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2013-07-20]
CHR Extension: (Google Wallet) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-18]
CHR HKLM-x32\...\Chrome\Extension: [dnllcmllkjofnojidnaknldfehfhehoo] - C:\Program Files (x86)\HDvidCodec.com\HDvidCodec10.crx [2013-06-30]
CHR HKLM-x32\...\Chrome\Extension: [kpkbnefaikfaeadgidhpoanckoiaheli] - C:\Program Files (x86)\HDvidCodec.com\HDvidCodec10.crx [2013-06-30]
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\18.1.0.443\avg.crx [2014-04-27]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-06-26] (BitRaider, LLC)
R2 dfc86759; c:\ProgramData\Performancer\PerformancerSvc.dll [186192 2014-06-06] () [File not signed]
R2 IePluginServices; C:\ProgramData\IePluginServices\PluginService.exe [704112 2014-05-08] (Cherished Technololgy LIMITED)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation)
S3 OnlineStorageService; C:\Program Files\Trend Micro SafeSync\hrfscore.exe [7908664 2012-07-12] (Trend Micro Inc.)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-08-22] (Overwolf Ltd)
S2 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [621632 2011-03-04] ()
R2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek) [File not signed]
R2 vToolbarUpdater18.1.7; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe [1813528 2014-06-22] (AVG Secure Search)
R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\wtgservice.exe [329168 2011-10-18] ()
S2 NewPlayer; C:\Program Files (x86)\NewPlayer\NewPlayerLwr161.exe [X]

==================== Drivers (Whitelisted) ====================

R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-06-22] (AVG Technologies)
R3 DualCoreCenter; C:\Program Files (x86)\MSI\DualCoreCenter\NTGLM7X64.sys [44344 2010-02-08] (MICRO-STAR INT'L CO., LTD.)
S3 GameKB; C:\Windows\System32\drivers\GameKB.sys [27648 2012-05-11] () [File not signed]
S3 hwdatacard; C:\Windows\SysWOW64\DRIVERS\ewusbmdm.sys [115328 2008-07-24] (Huawei Technologies Co., Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 MSIGreenPower; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\NTGLM7X64.sys [40248 2008-03-12] (MICRO-STAR INT'L CO., LTD.) [File not signed]
S3 MSIGreenPowerRushTop; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushTop64.sys [74072 2008-04-23] (Your Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7369v290\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [File not signed]
R3 NVR0Dev; C:\Windows\nvoclk64.sys [18216 2006-10-13] (NVidia Corp.)
R3 RushTopDevice2; C:\Program Files (x86)\MSI\DualCoreCenter\RushTop64.sys [76088 2009-03-18] (Your Corporation)
S3 RushTopDevice_J; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushJ64.sys [31544 2008-06-05] (Your Corporation) [File not signed]
R1 {9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64; C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64.sys [60088 2014-05-16] (StdLib)
S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S1 lhbjqqty; \??\C:\Windows\system32\drivers\lhbjqqty.sys [X]
S3 MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [X]
S1 neqnrghc; \??\C:\Windows\system32\drivers\neqnrghc.sys [X]
S3 netr28ux; system32\DRIVERS\netr28ux.sys [X]
S3 NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S1 rnigwgbp; \??\C:\Windows\system32\drivers\rnigwgbp.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-09 16:08 - 2014-07-09 16:09 - 00030116 _____ () C:\Users\Michi\Desktop\FRST.txt
2014-07-09 16:07 - 2014-07-09 16:08 - 00000000 ____D () C:\FRST
2014-07-09 16:05 - 2014-07-09 16:05 - 02084352 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe
2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip
2014-07-09 13:46 - 2014-06-07 06:02 - 17854464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 13:46 - 2014-06-07 04:59 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 13:46 - 2014-06-07 04:52 - 01348608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 13:46 - 2014-06-07 04:51 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 13:46 - 2014-06-07 04:51 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 13:46 - 2014-06-07 04:47 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 13:46 - 2014-06-07 04:45 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-07-09 13:46 - 2014-06-07 04:45 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 13:46 - 2014-06-07 04:45 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 13:46 - 2014-06-07 04:42 - 02148352 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 13:46 - 2014-06-07 04:42 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 13:46 - 2014-06-07 04:42 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 13:46 - 2014-06-07 04:42 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 13:46 - 2014-06-07 04:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 13:46 - 2014-06-07 04:41 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-07-09 13:46 - 2014-06-07 04:40 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 13:46 - 2014-06-07 04:39 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-07-09 13:46 - 2014-06-07 04:35 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 13:46 - 2014-06-07 02:05 - 12353024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-09 13:46 - 2014-06-07 01:12 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-09 13:46 - 2014-06-07 01:04 - 01106432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-09 13:46 - 2014-06-07 01:03 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-09 13:46 - 2014-06-07 01:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-09 13:46 - 2014-06-07 01:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-07-09 13:46 - 2014-06-07 00:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-07-09 13:46 - 2014-06-07 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-09 13:46 - 2014-06-07 00:54 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 13:46 - 2014-06-07 00:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-09 13:46 - 2014-06-07 00:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-07-09 13:46 - 2014-06-07 00:53 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-09 13:46 - 2014-06-07 00:52 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-09 13:46 - 2014-06-07 00:51 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-07-09 13:46 - 2014-06-07 00:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-09 13:45 - 2014-06-07 05:13 - 10890752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 13:45 - 2014-06-07 04:50 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-07-09 13:45 - 2014-06-07 04:41 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-07-09 13:45 - 2014-06-07 01:25 - 09711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-09 13:45 - 2014-06-07 00:58 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-09 13:45 - 2014-06-07 00:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-09 13:45 - 2014-06-07 00:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-09 13:45 - 2014-06-07 00:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-09 13:45 - 2014-06-07 00:53 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-07-09 13:44 - 2014-06-07 02:33 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 13:44 - 2014-06-06 10:59 - 00506880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-09 13:44 - 2014-06-06 09:13 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 13:44 - 2014-05-30 09:10 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-06 10:48 - 2014-07-06 10:48 - 00000000 ____D () C:\ProgramData\ProShopperu
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX
2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx
2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR
2014-06-26 15:21 - 2014-07-07 13:06 - 00000000 ____D () C:\ProgramData\BitRaider
2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk
2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment
2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk
2014-06-20 12:02 - 2014-06-20 12:03 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver
2014-06-20 10:16 - 2014-06-20 10:16 - 00000000 ____D () C:\ProgramData\CoupScuanner
2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk
2014-06-16 10:58 - 2014-06-16 10:57 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk
2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk
2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt
2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt
2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt
2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt
2014-06-15 11:44 - 2014-06-29 23:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe
2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe
2014-06-12 13:30 - 2014-04-26 20:21 - 00622592 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-12 13:30 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-12 13:30 - 2014-04-05 06:26 - 01417664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-12 13:30 - 2014-04-05 04:32 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-06-12 13:30 - 2014-03-10 08:26 - 01869824 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-12 13:30 - 2014-03-10 08:26 - 01794560 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-12 13:30 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-12 13:30 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll

==================== One Month Modified Files and Folders =======

2014-07-09 16:09 - 2014-07-09 16:08 - 00030116 _____ () C:\Users\Michi\Desktop\FRST.txt
2014-07-09 16:08 - 2014-07-09 16:07 - 00000000 ____D () C:\FRST
2014-07-09 16:05 - 2014-07-09 16:05 - 02084352 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe
2014-07-09 16:03 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-09 16:03 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-09 15:57 - 2013-05-06 22:53 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-09 15:56 - 2013-08-09 21:56 - 00001212 _____ () C:\Windows\Tasks\HDvid Codec V1-updater.job
2014-07-09 15:56 - 2013-08-09 21:56 - 00001116 _____ () C:\Windows\Tasks\HDvid Codec V1-enabler.job
2014-07-09 15:55 - 2013-08-09 21:55 - 00001206 _____ () C:\Windows\Tasks\HDvid Codec V1-codedownloader.job
2014-07-09 14:17 - 2013-05-14 23:00 - 01578094 _____ () C:\Windows\WindowsUpdate.log
2014-07-09 14:06 - 2013-06-27 23:26 - 00001906 _____ () C:\Windows\Tasks\Plus-HD-2.2-chromeinstaller.job
2014-07-09 14:06 - 2013-06-27 23:26 - 00001830 _____ () C:\Windows\Tasks\Plus-HD-2.2-firefoxinstaller.job
2014-07-09 14:06 - 2013-06-27 23:26 - 00001194 _____ () C:\Windows\Tasks\Plus-HD-2.2-updater.job
2014-07-09 14:05 - 2013-06-27 23:26 - 00001198 _____ () C:\Windows\Tasks\Plus-HD-2.2-codedownloader.job
2014-07-09 14:05 - 2013-06-27 23:26 - 00001098 _____ () C:\Windows\Tasks\Plus-HD-2.2-enabler.job
2014-07-09 14:05 - 2013-05-06 22:53 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-09 14:03 - 2014-03-13 18:14 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-09 14:03 - 2006-11-02 17:40 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-09 14:03 - 2006-11-02 17:21 - 00255776 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-09 13:59 - 2006-11-02 17:40 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-09 13:59 - 2006-11-02 17:06 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-09 13:57 - 2013-07-22 05:26 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-09 13:54 - 2006-11-02 14:35 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip
2014-07-09 00:35 - 2012-08-16 08:22 - 00001692 _____ () C:\Users\Michi\Desktop\bla.txt
2014-07-07 13:06 - 2014-06-26 15:21 - 00000000 ____D () C:\ProgramData\BitRaider
2014-07-07 12:56 - 2011-10-18 16:41 - 00055560 _____ () C:\Users\Michi\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-07 12:54 - 2011-10-19 16:48 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-07-06 10:48 - 2014-07-06 10:48 - 00000000 ____D () C:\ProgramData\ProShopperu
2014-07-06 10:48 - 2014-06-08 19:55 - 00000000 ____D () C:\ProgramData\297d856b205d5963
2014-07-05 16:05 - 2011-11-22 11:56 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\vlc
2014-07-05 01:02 - 2012-02-02 03:37 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\TS3Client
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX
2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx
2014-07-04 17:09 - 2011-10-18 16:41 - 00000000 ____D () C:\Users\Michi
2014-07-03 14:42 - 2012-05-11 00:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Skype
2014-06-30 06:36 - 2011-10-20 02:44 - 00175616 _____ () C:\Users\Michi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-29 23:08 - 2014-06-15 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2014-06-27 11:36 - 2013-08-30 14:25 - 00000000 ____D () C:\Users\Michi\Desktop\TS Icons
2014-06-27 11:19 - 2012-02-02 03:35 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR
2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
2014-06-26 14:06 - 2013-07-20 12:23 - 00014744 _____ () C:\Users\Michi\Documents\Install STAR WARS The Old Republic.log
2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2014-06-26 14:05 - 2014-05-18 13:49 - 00000000 _____ () C:\END
2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2014-06-23 08:33 - 2013-05-06 15:32 - 00001217 _____ () C:\Users\Michi\Desktop\WoW PWS.lnk
2014-06-22 19:39 - 2014-04-27 17:13 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-06-22 19:39 - 2013-06-26 20:25 - 00050464 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-06-22 19:39 - 2013-06-26 20:25 - 00000000 ____D () C:\Program Files (x86)\AVG Secure Search
2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk
2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment
2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk
2014-06-20 12:03 - 2014-06-20 12:02 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver
2014-06-20 10:16 - 2014-06-20 10:16 - 00000000 ____D () C:\ProgramData\CoupScuanner
2014-06-17 17:56 - 2012-12-13 10:46 - 00000000 ____D () C:\Filme
2014-06-17 17:56 - 2012-08-25 14:45 - 00000000 ____D () C:\Users\Michi\Desktop\Wma
2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk
2014-06-16 11:00 - 2014-02-03 14:46 - 00155136 _____ () C:\Windows\SysWOW64\unrar.dll
2014-06-16 11:00 - 2014-02-03 14:46 - 00034308 _____ () C:\Windows\SysWOW64\bassmod.dll
2014-06-16 10:57 - 2014-06-16 10:58 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk
2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk
2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt
2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt
2014-06-16 07:18 - 2013-05-12 09:58 - 00000000 ____D () C:\Windows\SysWOW64\directx
2014-06-16 07:18 - 2012-01-27 19:49 - 00000000 ____D () C:\Games
2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt
2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt
2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe
2014-06-15 11:25 - 2013-05-12 18:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Wargaming.net
2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-09 14:08

==================== End Of Log ============================
         
--- --- ---


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-07-2014
Ran by Michi at 2014-07-09 16:09:51
Running from C:\Users\Michi\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

Adobe Flash Player 11 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 11.8.800.175 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.7.700.224 - Adobe Systems Incorporated)
Adobe Reader X (10.1.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
aTube Catcher (HKLM-x32\...\aTube Catcher) (Version: 3.8.7955 - DsNET Corp)
AVG Security Toolbar (HKLM-x32\...\AVG Secure Search) (Version: 18.1.7.644 - AVG Technologies)
Bing Maps 3D (HKLM\...\{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}) (Version: 4.0.903.16005 - Microsoft Corporation)
BitRaider Web Client (HKLM-x32\...\BitRaider Web Client) (Version: 1.1.9.9 - BitRaider, LLC)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
CoupScuanner (HKLM-x32\...\{80E8B0A0-117D-1402-7CDE-688156237115}) (Version: - CCoupScAnneR)
Drakonia Configurator (HKLM-x32\...\{A7B243AA-6D4C-4575-A873-6F01A1EFC5E2}}_is1) (Version: - )
DriverTuner 3.1.0.0 (HKLM-x32\...\{520C1D80-935C-42B9-9340-E883849D804F}_is1) (Version: 3.1.0.0 - LionSea SoftWare)
DualCoreCenter (HKLM-x32\...\DualCoreCenter_is1) (Version: - MSI, Inc.)
EasyViewer (HKLM-x32\...\InstallShield_{EECD7B96-1416-4D3A-B12D-0D2512120C36}) (Version: 1.3.0.9 - MSI)
EasyViewer (x32 Version: 1.3.0.9 - MSI) Hidden
ffdshow v1.2.4422 [2012-04-09] (HKLM-x32\...\ffdshow_is1) (Version: 1.2.4422.0 - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.137 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
HDvid Codec V1 (HKLM-x32\...\HDvid Codec V1) (Version: 1.27.153.8 - installdaddy) <==== ATTENTION
HDVidCodec (HKLM-x32\...\1ClickDownload) (Version: 2.1 Build 26473 - hdvidcodec.com) <==== ATTENTION
iLivid (HKLM-x32\...\iLivid) (Version: 1.92.0.117387 - Bandoo Media Inc.) <==== ATTENTION
iLivid (x32 Version: 1.92.0.117387 - Bandoo Media Inc.) Hidden <==== ATTENTION
Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.550 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\...\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 5.9.6 - )
NVIDIA 3D Vision Controller Driver (x32 Version: 280.19 - NVIDIA Corporation) Hidden
NVIDIA 3D Vision Treiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 311.06 - NVIDIA Corporation)
NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 6.14.12.5896 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation)
NVIDIA GeForce Experience 1.8.2.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.8.2.1 - NVIDIA Corporation)
NVIDIA Grafiktreiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.06 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) Hidden
NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.1106 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 311.06 (Version: 311.06 - NVIDIA Corporation) Hidden
NVIDIA Update 11.10.13 (Version: 11.10.13 - NVIDIA Corporation) Hidden
NVIDIA Update Core (Version: 11.10.13 - NVIDIA Corporation) Hidden
OpenOffice.org 3.4 (HKLM-x32\...\{4C552FD3-2CCD-4E00-AC64-0681DBB3F8B5}) (Version: 3.4.9590 - OpenOffice.org)
Overwolf (HKLM-x32\...\{48615A7B-F026-4F62-A3F1-49001B8E21CB}) (Version: 0.44.256 - Overwolf)
PDF24 Creator 5.6.0 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
Performancer (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{dfc86759}) (Version: - 24soft) <==== ATTENTION
Plus-HD-2.2 (HKLM-x32\...\Plus-HD-2.2) (Version: 1.27.153.6 - Plus HD) <==== ATTENTION
ProShopperu (HKLM-x32\...\{8F213470-964F-4092-6B31-BC7570F31B5A}) (Version: - ProShopper) <==== ATTENTION
Ralink RT2860 Wireless LAN Card (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.5.12.0 - Ralink)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 6.250.908.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6873 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver and Utility (HKLM-x32\...\{9C049499-055C-4a0c-A916-1D8CA1FF45EB}) (Version: 1.00.0182 - REALTEK Semiconductor Corp.)
saavernett (HKLM-x32\...\{614925F9-841A-53FE-A28F-DC30FA07239B}) (Version: - saveRnEt)
Samsung_MonSetup (HKLM-x32\...\{8EA79DBF-D637-448A-89D6-410A087A4493}) (Version: 1.00.0000 - Samsung)
Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version: 7.0.0.45 - Bioware/EA)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
System Requirements Lab (HKLM-x32\...\SystemRequirementsLab) (Version: - )
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.15 - TeamSpeak Systems GmbH)
Trend Micro SafeSync (HKLM\...\HFRS_is1) (Version: 5.1.0.1173 - Trend Micro)
Ultimate Extras sounds from Microsoft® Tinker™ (HKLM\...\UltSounds2) (Version: - Microsoft Corporation)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM-x32\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation)
Verbindungsassistent (HKLM-x32\...\Verbindungsassistent) (Version: 2.1 - Verbindungsassistent)
VideoGenie (HKLM-x32\...\{FC54FD8D-789C-406D-BB88-F7C4421B7E83}_is1) (Version: 1.0.0.12 - MSI)
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
VLC classic (HKLM-x32\...\VLC classic) (Version: 1.14 - vlcplayerdownload.com)
W322U (HKLM-x32\...\{B64CEFD3-B6AB-40CD-8333-EDDBDB951751}) (Version: 1.00.0000 - Tenda)
Winamp (HKLM-x32\...\Winamp) (Version: 5.621 - Nullsoft, Inc)
Winamp Erkennungs-Plug-in (HKCU\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
Windows iLivid Toolbar (HKLM-x32\...\Windows Searchqu Toolbar) (Version: 3.0.0.117530 - Bandoo Media, Inc) <==== ATTENTION
Windows-Soundschemas (HKLM\...\UltSounds) (Version: - Microsoft Corporation)
WinRAR 4.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH)

==================== Restore Points =========================

30-06-2014 13:35:10 Geplanter Prüfpunkt
02-07-2014 17:26:26 Geplanter Prüfpunkt
03-07-2014 14:40:32 Geplanter Prüfpunkt
04-07-2014 09:27:42 Windows Update
04-07-2014 15:07:27 Installiert SHARKOON Skiller
04-07-2014 15:08:55 Gerätetreiber-Paketinstallation: Sharkoon Eingabegeräte (Human Interface Devices)
05-07-2014 16:59:42 Geplanter Prüfpunkt
06-07-2014 18:15:02 Entfernt SHARKOON Skiller
07-07-2014 11:06:44 Windows Update
08-07-2014 00:05:18 Geplanter Prüfpunkt
08-07-2014 13:17:40 Geplanter Prüfpunkt
09-07-2014 11:53:30 Windows Update

==================== Hosts content: ==========================

2006-11-02 14:34 - 2006-09-18 23:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {00C5BFF5-EEAF-4637-93EA-ADF6229D3234} - System32\Tasks\Plus-HD-2.2-firefoxinstaller => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-firefoxinstaller.exe [2013-06-27] (Plus HD) <==== ATTENTION
Task: {07B42F71-7E37-4EC3-8E83-4BE1FFE5C03D} - System32\Tasks\eType Setup => C:\Users\Michi\AppData\Local\Temp\eType Setup403431.exe <==== ATTENTION
Task: {0871AFF5-575C-40FC-A05F-24E29DC1452B} - System32\Tasks\HDvid Codec V1-codedownloader => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-codedownloader.exe [2013-08-09] (installdaddy) <==== ATTENTION
Task: {09D6CD90-BE85-4FF1-9D62-B51B87202CCF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-06] (Google Inc.)
Task: {09EAFC8C-A951-41B9-8D2B-A1F18FBB21EC} - System32\Tasks\Plus-HD-2.2-chromeinstaller => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-chromeinstaller.exe [2013-06-27] (Plus HD) <==== ATTENTION
Task: {0D36FC03-8888-410A-9037-DF358381DDF0} - System32\Tasks\HDvid Codec V1-updater => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-updater.exe [2013-08-09] (installdaddy) <==== ATTENTION
Task: {27664485-6DD3-4E67-A392-23E241238E1D} - System32\Tasks\Plus-HD-2.2-codedownloader => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-codedownloader.exe [2013-06-27] (Plus HD) <==== ATTENTION
Task: {27DC0BEB-20BB-4BAF-A4D6-C38628372658} - System32\Tasks\Plus-HD-2.2-enabler => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-enabler.exe [2013-06-27] (Plus HD) <==== ATTENTION
Task: {3027772B-B827-4998-B62C-4E4C617B5DFA} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {34F4AFBD-4B27-4161-BB74-EC0D1F6139BC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-06] (Google Inc.)
Task: {720B96CE-CD10-4370-A0B1-73D2741DFC9D} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance => C:\Program Files (x86)\TuneUp Utilities 2010\OneClick.exe
Task: {8E146441-DDF2-4E33-AEA7-A1CECCAEBA5B} - System32\Tasks\HDvid Codec V1-enabler => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-enabler.exe [2013-08-09] (installdaddy) <==== ATTENTION
Task: {9475DD97-BB54-4FD8-A31A-032B4833F6AA} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {996457A5-8249-47C5-B620-CA695B7E6DA1} - System32\Tasks\WOT WFRI1 => Iexplore.exe hxxp://mmotraffic.com/catalog/goplay/1327/MTE3NjYvLy8xMzI3/
Task: {9A441CE9-6C4F-4991-954B-EDCB9256D04F} - System32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries => Rundll32.exe %windir%\system32\pla.dll,PlaConvertLogEntries
Task: {AA105019-BFFB-4713-B627-81B47F4419F0} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {ADDB4957-FD21-4041-ADF2-C1DAF0991DA8} - System32\Tasks\Plus-HD-2.2-updater => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-updater.exe [2013-06-27] (Plus HD) <==== ATTENTION
Task: {C0B38178-CA76-4475-90EB-B2F41221156B} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {C28278BF-1ABF-4595-BB2A-15201DDF25E3} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {C41E9FD5-A5DB-4DEF-9715-E4F7BAFEE730} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {E7D52131-C543-4A8D-8669-9FEC0C9AEE08} - System32\Tasks\{6E07F2B2-386B-4ABF-9A74-F6643ABA3D4E} => Chrome.exe Skype auf Ihren Computer herunterladen ? Mac, Windows, Linux*?*Skype
Task: {F5B3AF16-E40C-4C45-B115-2698E999BB9F} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HDvid Codec V1-codedownloader.job => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\HDvid Codec V1-enabler.job => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\HDvid Codec V1-updater.job => C:\Program Files (x86)\HDvid Codec V1\HDvid Codec V1-updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-2.2-chromeinstaller.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-chromeinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-2.2-codedownloader.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-2.2-enabler.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-2.2-firefoxinstaller.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-firefoxinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Plus-HD-2.2-updater.job => C:\Program Files (x86)\Plus-HD-2.2\Plus-HD-2.2-updater.exe <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2014-06-06 09:51 - 2014-06-06 09:51 - 04302848 _____ () C:\ProgramData\Performancer\Performancer_x64.dll
2014-06-22 19:39 - 2014-06-22 19:39 - 00159768 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe
2011-10-18 16:53 - 2011-10-18 17:02 - 00329168 _____ () C:\Program Files (x86)\Verbindungsassistent\wtgservice.exe
2011-12-30 03:30 - 2011-05-28 23:05 - 00164864 _____ () C:\Program Files\WinRAR\rarext.dll
2011-07-18 23:04 - 2011-07-18 23:04 - 00301568 _____ () C:\Program Files (x86)\Notepad++\NppShell_04.dll
2013-06-26 20:25 - 2014-06-22 19:39 - 02571288 _____ () C:\Program Files (x86)\AVG Secure Search\vprot.exe
2013-06-29 11:36 - 2012-06-07 10:24 - 00246784 _____ () C:\Program Files (x86)\Drakonia Configurator\hid.exe
2013-06-29 11:36 - 2012-06-14 10:44 - 00240640 _____ () C:\Program Files (x86)\Drakonia Configurator\trayicon.exe
2013-05-08 09:35 - 2010-06-29 18:20 - 41382002 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\DualCoreCenter.exe
2014-06-06 09:51 - 2014-06-06 09:51 - 04129280 _____ () c:\ProgramData\Performancer\Performancer.dll
2014-06-06 09:51 - 2014-06-06 09:51 - 00186192 _____ () c:\ProgramData\Performancer\PerformancerSvc.dll
2014-06-22 19:39 - 2014-06-22 19:39 - 00519704 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\log4cplusU.dll
2013-06-29 11:36 - 2011-11-22 14:18 - 00061440 _____ () C:\Program Files (x86)\Drakonia Configurator\HidDevice.dll
2013-06-29 11:36 - 2011-11-22 14:18 - 00249856 _____ () C:\Program Files (x86)\Drakonia Configurator\language.dll
2013-10-08 02:19 - 2011-05-04 19:53 - 01058664 _____ () C:\Program Files (x86)\Ralink\Common\RaWLAPI.dll
2013-05-08 09:35 - 2009-03-17 16:36 - 00147456 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\RushTop.dll
2013-05-08 09:35 - 2007-01-05 11:59 - 00077824 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\CpuUsage.dll
2013-05-08 09:35 - 2008-09-08 15:02 - 00094208 _____ () C:\Program Files (x86)\MSI\DualCoreCenter\VGADLL.dll
2014-05-18 12:42 - 2014-05-08 01:29 - 00065352 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\chrome_elf.dll
2014-05-18 12:42 - 2014-05-08 01:29 - 04081480 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\pdf.dll
2014-05-18 12:42 - 2014-05-08 01:29 - 00390472 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ppGoogleNaClPluginChrome.dll
2014-05-18 12:42 - 2014-05-08 01:29 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ffmpegsumo.dll
2014-05-18 12:42 - 2014-05-08 01:29 - 13695816 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:679ABA25

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service"

==================== EXE Association (whitelisted) =============


==================== MSCONFIG/TASK MANAGER disabled items =========


==================== Faulty Device Manager Devices =============

Name: Microsoft-ISATAP-Adapter #2
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Microsoft-ISATAP-Adapter #3
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Microsoft-ISATAP-Adapter #4
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Microsoft-ISATAP-Adapter #5
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

Name: Microsoft-ISATAP-Adapter #6
Description: Microsoft-ISATAP-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: PolicyAgent4

Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4

Error: (07/09/2014 02:06:55 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: EmdCache4

Error: (07/09/2014 02:04:56 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: PolicyAgent4

Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: EmdCache4

Error: (07/09/2014 01:35:21 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: PolicyAgent4

Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4

Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: EmdCache4


System errors:
=============
Error: (07/09/2014 02:05:53 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: 30000Realtek11nSU

Error: (07/09/2014 02:04:57 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: 30000Ralink UPnP Media Server

Error: (07/09/2014 02:02:23 PM) (Source: disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (07/09/2014 02:02:23 PM) (Source: Ntfs) (EventID: 137) (User: )
Description: Der Transaktionsressourcen-Manager auf Volume "F:" konnte aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.

Error: (07/09/2014 02:02:19 PM) (Source: disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (07/09/2014 02:02:11 PM) (Source: disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (07/09/2014 02:02:07 PM) (Source: disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (07/09/2014 01:35:21 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: 30000Ralink UPnP Media Server

Error: (07/09/2014 01:33:54 PM) (Source: disk) (EventID: 7) (User: )
Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR1.

Error: (07/09/2014 01:33:54 PM) (Source: Ntfs) (EventID: 137) (User: )
Description: Der Transaktionsressourcen-Manager auf Volume "F:" konnte aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.


Microsoft Office Sessions:
=========================
Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: PolicyAgent4

Error: (07/09/2014 02:06:56 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4

Error: (07/09/2014 02:06:55 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: EmdCache4

Error: (07/09/2014 02:04:56 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: PolicyAgent4

Error: (07/09/2014 01:51:55 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: EmdCache4

Error: (07/09/2014 01:35:21 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: PolicyAgent4

Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll4

Error: (07/08/2014 01:49:12 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: EmdCache4


CodeIntegrity Errors:
===================================
Date: 2014-07-08 13:48:59.581
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2014-07-08 13:48:59.269
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2014-07-08 13:48:58.941
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2014-07-08 13:48:58.613
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2014-07-08 13:48:57.988
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2014-07-08 13:48:57.675
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2014-07-07 03:40:54.653
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2014-07-07 03:40:54.325
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2014-07-07 03:40:53.995
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.

Date: 2014-07-07 03:40:53.661
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\nvoclock.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.


==================== Memory info ===========================

Percentage of memory in use: 53%
Total physical RAM: 4094.46 MB
Available physical RAM: 1923.58 MB
Total Pagefile: 8425.43 MB
Available Pagefile: 5869.19 MB
Total Virtual: 8192 MB
Available Virtual: 8191.85 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:232.88 GB) (Free:36.72 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive e: (F) (Fixed) (Total:149.05 GB) (Free:38.31 GB) NTFS
Drive f: () (Fixed) (Total:298.09 GB) (Free:98.98 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 233 GB) (Disk ID: A2DEA2DE)
Partition 1: (Active) - (Size=233 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 8136E346)
Partition 1: (Active) - (Size=298 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (Size: 149 GB) (Disk ID: 3FC1A37E)
Partition 1: (Not Active) - (Size=149 GB) - (Type=07 NTFS)

==================== End Of Log ============================




Hi, super das ging ja schnell das du dich meiner annimmst eben noch andere Themen von dir gelesen

Alt 10.07.2014, 14:48   #5
schrauber
/// the machine
/// TB-Ausbilder
 

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Standard

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich



Adware & Co. deinstallieren
  • Lade Dir bitte von hier Revo Uninstaller herunter.
  • Installiere und starte das Programm.
  • Suche im Uninstallerfeld nach den Programmen, die unter:

    diesen Zusatz haben:
  • Wähle die Programme nacheinander aus und klicke jedesmal auf Uninstall.
  • Wähle anschließend den Modus "Moderat" aus.
  • Reste löschen:
    Klicke auf dann auf und dann auf .

Solltest Du ein Programm nicht finden oder nicht deinstallieren können, mache bitte mit dem nächsten Schritt weiter:




Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 10.07.2014, 18:02   #6
majin85
 
Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Standard

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich



Code:
ATTFilter
ComboFix 14-07-08.04 - Michi 10.07.2014  17:45:19.1.2 - x64
Microsoft® Windows Vista™ Ultimate   6.0.6002.2.1252.49.1031.18.4094.2263 [GMT 2:00]
ausgeführt von:: c:\users\Michi\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\374311380
c:\programdata\CoupScuanner
c:\programdata\CoupScuanner\pUyJz3N_N.dat
c:\programdata\CoupScuanner\pUyJz3N_N.dll
c:\programdata\CoupScuanner\pUyJz3N_N.exe
c:\programdata\CoupScuanner\pUyJz3N_N.tlb
c:\programdata\CoupScuanner\pUyJz3N_N.x64.dll
c:\programdata\saavernett
c:\programdata\saavernett\e.dat
c:\programdata\saavernett\e.dll
c:\programdata\saavernett\e.exe
c:\programdata\saavernett\e.tlb
c:\programdata\saavernett\e.x64.dll
c:\users\Michi\4.0
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_kfakeonomonapccoamcmdgpoaicnpnoo_0
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_kfakeonomonapccoamcmdgpoaicnpnoo_0\27
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_kfakeonomonapccoamcmdgpoaicnpnoo_0\28
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj\1.3\background.html
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj\1.3\content.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj\1.3\lsdb.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj\1.3\manifest.json
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\bddaegpgigdnchenjnkebdfhiiiliggj\1.3\OCp.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk\221\background.html
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk\221\content.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk\221\lsdb.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk\221\manifest.json
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\iimnlpkklbehlibkphacaolndffafifk\221\ubvQ4l5vHye.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce\154\background.html
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce\154\content.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce\154\idlITjgkPxk.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce\154\lsdb.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inhigcbmfmhcacgjnbaehgnfbepeopce\154\manifest.json
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc\135\background.html
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc\135\content.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc\135\DBgumc7XK.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc\135\lsdb.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmmlmagkbjnbhonjmeihmahmeabaafc\135\manifest.json
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed\146\background.html
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed\146\content.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed\146\KTzl66zMp.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed\146\lsdb.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kahoebmmfnjmjcbclecdkhiapmefpaed\146\manifest.json
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\background.html
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\crossriderManifest.json
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\manifest.xml
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins.json
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\1_base.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\102_dealply_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\103_intext_5_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\104_jollywallet_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\105_corticas_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\119_similar_web_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\120_luck_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\123_intext_adv_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\13_CrossriderAppUtils.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\14_CrossriderUtils.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\155_ibario_pops_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\158_50onred_ads_only_no_fb_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\17_jQuery.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\177_crossriderDashboard.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\178_revizer_ws_dynamic_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\179_revizer_p_dynamic_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\180_bpo_serp_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\182_openUrl.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\183_tabsWrapper.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\184_noproblemppc_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\189_active_sanity.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\19_CHAppAPIWrapper.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\191_ciuvo_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\194_retargeting_bi_m.js.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\195_icm_convertmedia_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\21_debug.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\22_resources.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\28_initializer.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\4_jquery_1_7_1.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\47_resources_background.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\64_appApiMessage.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\7_hooks.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\72_appApiValidation.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\78_CrossriderInfo.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\80_CHPopupAppAPI.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\9_search_engine_hook.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\91_monetizationLoader.js.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\93_superfish_no_coupons_m.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\97_resourceApiWrapper.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\userCode\background.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\userCode\extension.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\icons\actions\1.png
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\icons\icon128.png
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\icons\icon16.png
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\icons\icon48.png
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\api\chrome.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\api\cookie.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\api\message.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\api\pageAction.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\api\pageActionBG.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\background.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\app_api.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\bg_app_api.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\consts.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\cookie_store.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\crossriderAPI.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\delegate.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\events.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\extensionDataStore.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\installer.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\logFile.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\logging.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\onBGDocumentLoad.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\popupResource\newPopup.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\popupResource\popup.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\reports.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\storageWrapper.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\updateManager.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\util.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\lib\xhr.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\js\main.js
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\manifest.json
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\popup.html
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\version.json
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\000962.sst
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\000976.log
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\CURRENT
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\LOCK
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\LOG
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\LOG.old
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\MANIFEST-000974
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bddaegpgigdnchenjnkebdfhiiiliggj_0.localstorage-journal
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bddaegpgigdnchenjnkebdfhiiiliggj_0.localstorage
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kfakeonomonapccoamcmdgpoaicnpnoo_0.localstorage-journal
c:\users\Michi\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\Michi\AppData\Local\Temp\__tmp_2bbca911
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome.manifest
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\asyncDB.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\background.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\browserAction.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\contextMenu.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\dbManager.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\dom_bg.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\fileManager.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\firefox.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\firefoxNotifications.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\firefoxOmnibox.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\message.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\request.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\tabs.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\api\webRequest.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\background.html
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\baseObject.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\browser.xul
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\console.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\consts.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\delegate.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\httpObserver.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\IDBWrapper.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\installer.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\pluginsManager.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\prefs.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\progressListenerObserver.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\registry.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\reloadObserver.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\reports.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\requestObject.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\searchSettings.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\uninstallObserver.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\updateManager.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\utils.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\core\xhr.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\dialog.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\extensionCode\backgroundCode.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\extensionCode\pageCode.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\main.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\options.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\options.xul
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\chrome\content\search_dialog.xul
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\defaults\preferences\prefs.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\install.rdf
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\locale\en-US\translations.dtd
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\button1.png
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\button2.png
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\button3.png
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\button4.png
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\button5.png
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\crossrider_statusbar.png
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\icon128.png
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\icon16.png
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\icon24.png
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\icon48.png
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\panelarrow-up.png
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\popup.html
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\skin.css
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\4fdacf00-e9c4-4ad5-b4cf-bf9800f184f6@36857116-74e0-4973-936f-860cd2a102a9.com\skin\update.css
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\3u34e@hzpblpx.net\bootstrap.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\3u34e@hzpblpx.net\chrome.manifest
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\3u34e@hzpblpx.net\content\bg.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\3u34e@hzpblpx.net\install.rdf
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\hbbzzk@e-f.edu\bootstrap.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\hbbzzk@e-f.edu\chrome.manifest
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\hbbzzk@e-f.edu\content\bg.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\hbbzzk@e-f.edu\install.rdf
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\p26qgdb9@leftct.co.uk\bootstrap.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\p26qgdb9@leftct.co.uk\chrome.manifest
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\p26qgdb9@leftct.co.uk\content\bg.js
c:\users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\staged\p26qgdb9@leftct.co.uk\install.rdf
F:\install.exe
.
.
(((((((((((((((((((((((   Dateien erstellt von 2014-06-10 bis 2014-07-10  ))))))))))))))))))))))))))))))
.
.
2014-07-10 15:53 . 2014-07-10 15:53	--------	d-----w-	c:\users\hedev\AppData\Local\temp
2014-07-10 15:53 . 2014-07-10 15:53	--------	d-----w-	c:\users\Default\AppData\Local\temp
2014-07-10 15:25 . 2014-07-10 15:25	--------	d-----w-	c:\program files (x86)\ProShopperu
2014-07-10 13:38 . 2014-07-10 13:38	--------	d-----w-	c:\program files (x86)\VS Revo Group
2014-07-10 12:25 . 2014-07-10 12:25	75888	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0440037D-239D-487B-8CB8-4B647E3AEC36}\offreg.dll
2014-07-10 12:15 . 2014-06-05 10:54	10779000	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0440037D-239D-487B-8CB8-4B647E3AEC36}\mpengine.dll
2014-07-09 14:07 . 2014-07-09 14:10	--------	d-----w-	C:\FRST
2014-07-09 12:15 . 2014-06-05 10:54	10779000	----a-w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-07-09 11:45 . 2014-06-07 02:50	237056	----a-w-	c:\windows\system32\url.dll
2014-07-09 11:44 . 2014-06-07 01:41	1871872	----a-w-	c:\program files\Common Files\Microsoft Shared\ink\tipskins.dll
2014-07-09 11:44 . 2014-06-07 00:33	2777088	----a-w-	c:\windows\system32\win32k.sys
2014-07-09 11:44 . 2014-06-07 01:41	120832	----a-w-	c:\program files\Common Files\Microsoft Shared\ink\TipBand.dll
2014-07-09 11:44 . 2014-06-07 01:41	206336	----a-w-	c:\program files\Common Files\Microsoft Shared\ink\tabskb.dll
2014-07-09 11:44 . 2014-06-07 00:22	10240	----a-w-	c:\program files (x86)\Common Files\Microsoft Shared\ink\TabTip32.exe
2014-07-09 11:44 . 2014-06-06 08:59	506880	----a-w-	c:\windows\SysWow64\qedit.dll
2014-07-09 11:44 . 2014-06-06 07:13	620032	----a-w-	c:\windows\system32\qedit.dll
2014-07-09 11:44 . 2014-05-30 07:10	404992	----a-w-	c:\windows\system32\drivers\afd.sys
2014-07-04 18:44 . 2014-07-04 18:44	1931296	----a-w-	c:\windows\CODEJO~2.OCX
2014-07-04 18:44 . 2014-07-04 18:44	1931296	----a-w-	c:\windows\Codejock.Controls.v15.3.1.ocx
2014-07-04 18:44 . 2014-07-04 18:44	136008	----a-w-	c:\windows\msinet.ocx
2014-07-04 09:33 . 2014-05-02 06:23	1031560	------w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{159D589E-ABD8-4EBC-A12A-A4C12597CC6D}\gapaengine.dll
2014-06-26 19:46 . 2014-06-26 19:46	--------	d-----w-	c:\users\Michi\AppData\Local\SWTOR
2014-06-26 13:21 . 2014-07-07 11:06	--------	d-----w-	c:\programdata\BitRaider
2014-06-26 12:05 . 2014-06-26 12:05	--------	d-----w-	c:\program files (x86)\Electronic Arts
2014-06-20 10:02 . 2014-06-20 10:03	--------	d-----w-	c:\program files (x86)\MonitorDriver
2014-06-12 11:30 . 2014-04-05 04:26	1417664	----a-w-	c:\windows\system32\drivers\tcpip.sys
2014-06-12 11:30 . 2014-04-05 02:32	40448	----a-w-	c:\windows\system32\drivers\tcpipreg.sys
2014-06-12 11:30 . 2014-04-26 18:21	622592	----a-w-	c:\windows\system32\usp10.dll
2014-06-12 11:30 . 2014-04-26 16:01	502784	----a-w-	c:\windows\SysWow64\usp10.dll
2014-06-12 11:30 . 2014-03-10 06:26	1794560	----a-w-	c:\windows\system32\msxml6.dll
2014-06-12 11:30 . 2014-03-10 06:26	1869824	----a-w-	c:\windows\system32\msxml3.dll
2014-06-12 11:30 . 2014-03-10 01:22	1401344	----a-w-	c:\windows\SysWow64\msxml6.dll
2014-06-12 11:30 . 2014-03-10 01:22	1248768	----a-w-	c:\windows\SysWow64\msxml3.dll
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-07-09 11:54 . 2006-11-02 12:35	96441528	----a-w-	c:\windows\system32\mrt.exe
2014-06-22 17:39 . 2013-06-26 18:25	50464	----a-w-	c:\windows\system32\drivers\avgtpx64.sys
2014-06-16 09:00 . 2014-02-03 12:46	155136	----a-w-	c:\windows\SysWow64\unrar.dll
2014-05-16 16:34 . 2014-05-18 11:55	60088	----a-w-	c:\windows\system32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64.sys
2014-05-04 18:20 . 2014-05-04 18:20	1931296	----a-w-	c:\windows\SysWow64\Codejock.Controls.v15.3.1.ocx
2014-05-02 06:23 . 2013-07-18 07:39	1031560	------w-	c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-04-25 12:49 . 2013-07-31 17:48	20312	----a-w-	c:\windows\system32\roboot64.exe
2014-04-14 18:13 . 2014-04-16 21:44	96168	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoPaired]
@="{A203F945-39E9-4286-AFA2-F3ADFCD5FAAA}"
[HKEY_CLASSES_ROOT\CLSID\{A203F945-39E9-4286-AFA2-F3ADFCD5FAAA}]
2012-07-12 11:22	1186616	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension32.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoPriority]
@="{6F1BB626-1107-4b82-B322-54C5E64461B8}"
[HKEY_CLASSES_ROOT\CLSID\{6F1BB626-1107-4b82-B322-54C5E64461B8}]
2012-07-12 11:22	1186616	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension32.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoProblem]
@="{7479C9AF-DA81-4944-92E5-23E49390BB2B}"
[HKEY_CLASSES_ROOT\CLSID\{7479C9AF-DA81-4944-92E5-23E49390BB2B}]
2012-07-12 11:22	1186616	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension32.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoSynced]
@="{7479C9AF-DA81-4944-92E5-23E49390BB2A}"
[HKEY_CLASSES_ROOT\CLSID\{7479C9AF-DA81-4944-92E5-23E49390BB2A}]
2012-07-12 11:22	1186616	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension32.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoSyncing]
@="{7479C9AF-DA81-4944-92E5-23E49390BB29}"
[HKEY_CLASSES_ROOT\CLSID\{7479C9AF-DA81-4944-92E5-23E49390BB29}]
2012-07-12 11:22	1186616	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension32.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoUnavailable]
@="{66669544-5639-4922-99C8-CE7A86651364}"
[HKEY_CLASSES_ROOT\CLSID\{66669544-5639-4922-99C8-CE7A86651364}]
2012-07-12 11:22	1186616	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension32.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-07-11 74752]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"DelReg"="c:\program files (x86)\MSI\DualCoreCenter\DelReg.exe" [2008-05-13 196608]
"vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2014-06-22 2571288]
"GamingMouse"="c:\program files (x86)\Drakonia Configurator\hid.exe" [2012-06-07 246784]
"PDFPrint"="c:\program files (x86)\PDF24\pdf24.exe" [2013-06-10 162856]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"removeSearchqudatamngr"="RD" [X]
"removeSearchqutoolbar"="RD" [X]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
DualCoreCenter.lnk - c:\program files (x86)\MSI\DualCoreCenter\StartUpDualCoreCenter.exe [2013-5-8 192512]
Ralink Wireless Utility.lnk - c:\program files (x86)\Ralink\Common\RaUI.exe -s [2013-10-8 12909928]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
.
--- Andere Dienste/Treiber im Speicher ---
.
*Deregistered* - NVR0Dev
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
Themes
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-05-18 10:42	1077576	----a-w-	c:\program files (x86)\Google\Chrome\Application\34.0.1847.137\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-06 20:53]
.
2014-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-06 20:53]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoPaired]
@="{A203F945-39E9-4286-AFA2-F3ADFCD5FAAA}"
[HKEY_CLASSES_ROOT\CLSID\{A203F945-39E9-4286-AFA2-F3ADFCD5FAAA}]
2012-07-12 11:23	1748280	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoPriority]
@="{6F1BB626-1107-4b82-B322-54C5E64461B8}"
[HKEY_CLASSES_ROOT\CLSID\{6F1BB626-1107-4b82-B322-54C5E64461B8}]
2012-07-12 11:23	1748280	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoProblem]
@="{7479C9AF-DA81-4944-92E5-23E49390BB2B}"
[HKEY_CLASSES_ROOT\CLSID\{7479C9AF-DA81-4944-92E5-23E49390BB2B}]
2012-07-12 11:23	1748280	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoSynced]
@="{7479C9AF-DA81-4944-92E5-23E49390BB2A}"
[HKEY_CLASSES_ROOT\CLSID\{7479C9AF-DA81-4944-92E5-23E49390BB2A}]
2012-07-12 11:23	1748280	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoSyncing]
@="{7479C9AF-DA81-4944-92E5-23E49390BB29}"
[HKEY_CLASSES_ROOT\CLSID\{7479C9AF-DA81-4944-92E5-23E49390BB29}]
2012-07-12 11:23	1748280	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00HumyoUnavailable]
@="{66669544-5639-4922-99C8-CE7A86651364}"
[HKEY_CLASSES_ROOT\CLSID\{66669544-5639-4922-99C8-CE7A86651364}]
2012-07-12 11:23	1748280	----a-w-	c:\program files\Trend Micro SafeSync\HrfsShellExtension.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinSys2"="c:\windows\system32\startup.exe" [2008-01-30 52072]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-03-29 13513288]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-02-05 2234144]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mStart Page = about:blank
mDefault_Page_URL = about:blank
mDefault_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}
mSearch Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.2.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{D8278076-BC68-4484-9233-6E7F1628B56C} - (no file)
BHO-{99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~2\WI371A~1\Datamngr\ToolBar\searchqudtx.dll
BHO-{9D717F81-9148-4f12-8568-69135F087DB0} - c:\progra~2\WI371A~1\Datamngr\BROWSE~1.DLL
BHO-{EE8576D7-0A5F-FD10-841C-3FF359D97D4E} - c:\programdata\CoupScuanner\pUyJz3N_N.dll
BHO-{FB5E2C20-9D02-6288-3506-3C27D46DC1B2} - c:\programdata\saavernett\e.dll
Toolbar-{99079a25-328f-4bd4-be04-00955acaa0a7} - c:\progra~2\WI371A~1\Datamngr\ToolBar\searchqudtx.dll
Toolbar-10 - (no file)
Toolbar-!{82E1477C-B154-48D3-9891-33D83C26BCD3} - (no file)
Toolbar-!{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
Wow6432Node-HKLM-Run-fst_de_16 - (no file)
Wow6432Node-HKLM-Run-t4pc_en_3 - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
BHO-{9D717F81-9148-4f12-8568-69135F087DB0} - c:\progra~2\WI371A~1\Datamngr\x64\BROWSE~1.DLL
BHO-{EE8576D7-0A5F-FD10-841C-3FF359D97D4E} - c:\programdata\CoupScuanner\pUyJz3N_N.x64.dll
BHO-{FB5E2C20-9D02-6288-3506-3C27D46DC1B2} - c:\programdata\saavernett\e.x64.dll
Toolbar-10 - (no file)
Toolbar-!{95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
AddRemove-{614925F9-841A-53FE-A28F-DC30FA07239B} - c:\programdata\saavernett\e.exe
AddRemove-{80E8B0A0-117D-1402-7CDE-688156237115} - c:\programdata\CoupScuanner\pUyJz3N_N.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_175_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_175.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Zeit der Fertigstellung: 2014-07-10  17:56:42
ComboFix-quarantined-files.txt  2014-07-10 15:56
.
Vor Suchlauf: 16 Verzeichnis(se), 46.926.602.240 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 46.855.999.488 Bytes frei
.
- - End Of File - - 7D978701524027D4F03507464F71E6BE
5C616939100B85E558DA92B899A0FC36
         

Alt 11.07.2014, 12:14   #7
schrauber
/// the machine
/// TB-Ausbilder
 

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Standard

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 11.07.2014, 14:28   #8
majin85
 
Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Standard

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich



Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 11.07.2014
Suchlauf-Zeit: 13:20:40
Logdatei: mbam.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.07.11.04
Rootkit Datenbank: v2014.07.09.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows Vista Service Pack 2
CPU: x64
Dateisystem: NTFS
Benutzer: Michi

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 303003
Verstrichene Zeit: 11 Min, 29 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 1
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 1832, Löschen bei Neustart, [f848b9e53942201664eadd809d64758b]

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 47
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, In Quarantäne, [f848b9e53942201664eadd809d64758b], 
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [29173d617dfe49ede4002069857d47b9], 
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [29173d617dfe49ede4002069857d47b9], 
PUP.Optional.WebCake.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{7169BBB3-3289-4696-B35D-4A88BCF6FB12}, In Quarantäne, [fc44efafaad189ade4028cfd17ebac54], 
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}, In Quarantäne, [d16f3a64fb802a0cf8cd24668b77b14f], 
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\SearchQUIEHelper.DNSGuard, In Quarantäne, [d16f3a64fb802a0cf8cd24668b77b14f], 
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\SearchQUIEHelper.DNSGuard.1, In Quarantäne, [d16f3a64fb802a0cf8cd24668b77b14f], 
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SearchQUIEHelper.DNSGuard, In Quarantäne, [d16f3a64fb802a0cf8cd24668b77b14f], 
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SearchQUIEHelper.DNSGuard.1, In Quarantäne, [d16f3a64fb802a0cf8cd24668b77b14f], 
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}, In Quarantäne, [d16f3a64fb802a0cf8cd24668b77b14f], 
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\CLASSES\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}, In Quarantäne, [4ef2c0de9ae1a39390366d1d1ee48f71], 
PUP.Optional.Datamngr.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}, In Quarantäne, [4ef2c0de9ae1a39390366d1d1ee48f71], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc.1, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.mysearchdialESrvc, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.mysearchdialESrvc.1, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}, In Quarantäne, [59e70f8ff586f2441cd45930a2605ca4], 
PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}, In Quarantäne, [dd637a24f883979ffb4cc59246bca35d], 
PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{99079A25-328F-4BD4-BE04-00955ACAA0A7}, In Quarantäne, [dd637a24f883979ffb4cc59246bca35d], 
PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{99079A25-328F-4BD4-BE04-00955ACAA0A7}, In Quarantäne, [dd637a24f883979ffb4cc59246bca35d], 
PUP.Optional.Bandoo.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9D717F81-9148-4f12-8568-69135F087DB0}, In Quarantäne, [f54b811d1b60a09669a0a1e94db5b14f], 
PUP.Optional.Bandoo.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{9D717F81-9148-4F12-8568-69135F087DB0}, In Quarantäne, [f54b811d1b60a09669a0a1e94db5b14f], 
PUP.Optional.Babylon.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, In Quarantäne, [56eaafefc1ba0c2aaec240108e742ad6], 
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, In Quarantäne, [e55baef0e497ce68752be8685aa82dd3], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, In Quarantäne, [e55baef0e497ce68752be8685aa82dd3], 
PUP.Optional.Delta.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{82E1477C-B154-48D3-9891-33D83C26BCD3}, In Quarantäne, [19277e208eed0c2a16cebcccb84a39c7], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [0c34fda14635b581b34581d3cf337c84], 
Adware.EoRezo, HKLM\SOFTWARE\WOW6432NODE\FreeSoftToday, In Quarantäne, [122e0797304bab8b54ef98637a89cf31], 
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [3b057925394265d138ade920679d7d83], 
PUP.Optional.HDVidCodec.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\dnllcmllkjofnojidnaknldfehfhehoo, In Quarantäne, [bf81138b80fbcc6a41ebd62028db59a7], 
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM, In Quarantäne, [0d33217dbac151e571c0f3039b6806fa], 
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, In Quarantäne, [69d7d6c836452313a8eac7f2ba48eb15], 
PUP.Optional.NewPlayer.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NEWPLAYER, In Quarantäne, [81bf5c421863f6403d78487c1ae8df21], 
PUP.Optional.Feven.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Fpro_1.2, In Quarantäne, [ac94e5b90675fb3bd03612b339c9ac54], 
PUP.Optional.MPlayerplus.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\MPlayerplus_01, In Quarantäne, [d769e7b784f7fe384fc57b4a3ec4ee12], 
PUP.Optional.PlusHD.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-2.2, In Quarantäne, [1c242c721d5e5fd74b344c86986a8779], 
PUP.Optional.InstallCore.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [340c6e30a9d2a393211ccc139e64916f], 
PUP.Optional.InstallCore.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [45fbf5a999e2251147fe995c38cbe917], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\installdaddy, In Quarantäne, [3f01910df28949ed121c12e407fce11f], 
PUP.Optional.PlusHD.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Plus HD, In Quarantäne, [46fa0a946e0dc96d2d53834f52b05da3], 
PUP.Optional.BProtector.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, In Quarantäne, [49f747577cffce6842346395fb08f907], 
PUP.Optional.Softonic.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [310fd1cded8e6cca230e4b83e31fa65a], 
PUP.Optional.SweetIM.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, In Quarantäne, [f34d88165c1f75c11719ce282ad912ee], 
PUP.Optional.SystemSpeedup, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\ssd, In Quarantäne, [75cb3b639cdf73c34f42c6f3cc3603fd], 

Registrierungswerte: 7
PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{99079A25-328F-4BD4-BE04-00955ACAA0A7}, Searchqu Toolbar, In Quarantäne, [dd637a24f883979ffb4cc59246bca35d]
PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{99079a25-328f-4bd4-be04-00955acaa0a7}, In Quarantäne, [023e8e10e7940531c87f7cdb5fa38c74], 
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM|simapp_id, {8F553BE8-012D-11E3-BC1C-00218508A415}, In Quarantäne, [0d33217dbac151e571c0f3039b6806fa]
PUP.Optional.NewPlayer.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NEWPLAYER|ImagePath, C:\Program Files (x86)\NewPlayer\NewPlayerLwr161.exe, In Quarantäne, [81bf5c421863f6403d78487c1ae8df21]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0V1D1S1R1D0V1O, In Quarantäne, [45fbf5a999e2251147fe995c38cbe917]
PUP.BProtector, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, hxxp://search.babylon.com/?babsrc=HP_ss_gin2g&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926, In Quarantäne, [ad93b0eee09b2511ed36eb0a17ec3fc1]
PUP.Optional.SweetIM.A, HKU\S-1-5-21-503261611-1707939866-3478010161-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, {8F553BE8-012D-11E3-BC1C-00218508A415}, In Quarantäne, [f34d88165c1f75c11719ce282ad912ee]

Registrierungsdaten: 2
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}),Ersetzt,[c27e6a34304b2c0ad36716862cd857a9]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1400408601&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}),Ersetzt,[8ab6485697e467cfc850dbb617ed9e62]

Ordner: 23
PUP.Optional.FileScout.A, C:\Users\Michi\AppData\Roaming\File Scout, In Quarantäne, [d0704757215a0135ce5ba1fc9270ae52], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com, Löschen bei Neustart, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\components, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content, Löschen bei Neustart, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs, Löschen bei Neustart, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\defaults, Löschen bei Neustart, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\defaults\preferences, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Datamngr.A, C:\Users\Michi\AppData\LocalLow\DataMngr, In Quarantäne, [37098b130d6e191d25650e95a26041bf], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb, Löschen bei Neustart, [fa46d9c5324937ffcf4e1e8616ec3fc1], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb\0.1_0, In Quarantäne, [fa46d9c5324937ffcf4e1e8616ec3fc1], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd, Löschen bei Neustart, [de6206987cfff244bf5fe0c455ad629e], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\0.1_0, In Quarantäne, [de6206987cfff244bf5fe0c455ad629e], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\LocalLow\BabylonToolbar, Löschen bei Neustart, [3907c3db8cef40f6e4168727ae5424dc], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\LocalLow\BabylonToolbar\BabylonToolbar, In Quarantäne, [3907c3db8cef40f6e4168727ae5424dc], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchquband, In Quarantäne, [b987504e7ffc2a0c60bc595655adc53b], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar, Löschen bei Neustart, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\weather, In Quarantäne, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, Löschen bei Neustart, [75cb8d11ccaf4fe7b93c2989689a30d0], 
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [75cb8d11ccaf4fe7b93c2989689a30d0], 
PUP.Optional.SearchProtect.A, C:\Users\Michi\AppData\Local\SearchProtect, Löschen bei Neustart, [162a6f2f6219d75fbf37625003ff7090], 
PUP.Optional.SearchProtect.A, C:\Users\Michi\AppData\Local\SearchProtect\Logs, In Quarantäne, [162a6f2f6219d75fbf37625003ff7090], 
PUP.Optional.SystemSpeedup, C:\Users\Michi\AppData\Roaming\Systweak\ssd, In Quarantäne, [5de38618a2d9ff3722eaeec822e06f91], 

Dateien: 159
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, Löschen bei Neustart, [f848b9e53942201664eadd809d64758b], 
PUP.Optional.Skytech.A, C:\Users\Michi\AppData\Roaming\sweet-page\UninstallManager.exe, In Quarantäne, [fd43633b2655cf6754314745669bbd43], 
PUP.Optional.InstallCore, C:\Users\Michi\Downloads\google_chrome_de.exe, In Quarantäne, [1a262a745427a1953e7aa6e0c3413dc3], 
PUP.Optional.BrowserDefender.A, C:\Windows\System32\Tasks\BrowserDefendert, In Quarantäne, [e45c534b8cef0a2c7babdce0ff03847c], 
PUP.Optional.Yontoo.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\plugin@yontoo.com.xpi, In Quarantäne, [af918e10017a72c435208b322ad8cd33], 
PUP.Optional.Ciuvo.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage, In Quarantäne, [d16f2c726b10a294e425caf60ef42dd3], 
PUP.Optional.Ciuvo.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_api.ciuvo.com_0.localstorage-journal, In Quarantäne, [60e0207ee09b5cda59b0863afb07a35d], 
PUP.Optional.LiveLyrics.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.livelyrics00.live-lyrics.com_0.localstorage, In Quarantäne, [79c70e906f0c6acc8e77626521e13fc1], 
PUP.Optional.LiveLyrics.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.livelyrics00.live-lyrics.com_0.localstorage-journal, In Quarantäne, [ab95702e3e3da88e4db8dee9d72b40c0], 
PUP.Optional.Superfish.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, In Quarantäne, [8cb42a74681368ce689ee1e61ae84bb5], 
PUP.Optional.Superfish.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, In Quarantäne, [0739336b39421620e52153747989e020], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\babylon.xml, In Quarantäne, [b38dcfcf0279082edd745d77a161e61a], 
PUP.Optional.BProtector.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\bProtector_extensions.sqlite, In Quarantäne, [56ea742aa2d9082e510c488c8a78d62a], 
PUP.Optional.BProtector.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\bProtector_prefs.js, In Quarantäne, [a69a306ef5869f973628696b7092c838], 
PUP.Optional.Delta.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\delta.xml, In Quarantäne, [6dd3415d1c5f68ce4b39686c5aa88878], 
PUP.Optional.HDVidCodec.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\hdvc3@hdvidcodec.com.xpi, In Quarantäne, [0838247a215afe386e3fc014986aca36], 
PUP.Optional.Babylon.A, C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml, In Quarantäne, [2f1145595c1f65d12c4c2eabf80a32ce], 
PUP.Optional.Searchqu.A, C:\Users\Michi\AppData\Roaming\Mozilla\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}, In Quarantäne, [f54b2678d6a55bdb5f53896cc53ef40c], 
PUP.Optional.BProtector.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data, In Quarantäne, [d8688519205b8babcea9a45421e238c8], 
PUP.Optional.BProtector.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences, In Quarantäne, [87b9d5c9c7b42f070474e90f02011be5], 
PUP.Optional.MySpeedDial.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pflphaooapbgpeakohlggbpidpppgdff_0.localstorage, In Quarantäne, [dc64336b4a314fe7396043cecf3512ee], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\chrome.manifest, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\install.rdf, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\components\acplus-autocomplete.js, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\babylon.css, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\babylon.xul, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\mtstart.js, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\server.js, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\tmplt.js, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\arwDwn.gif, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\bbyln.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\help_16.gif, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\home.gif, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\logo.PNG, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\privecy_16_hot.gif, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\tellafriend.gif, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\vssver.scc, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ae.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\bg.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ch.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cn.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\cz.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\de.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\eg.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\en.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\es.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\fr.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\gr.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\he.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\il.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\it.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ja.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\jp.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\nl.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\no.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pl.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\pt.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ro.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ru.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sa.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\se.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\sv.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\Thumbs.db, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\tr.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\ua.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs\us.png, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\defaults\preferences\babylon.js, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\defaults\preferences\dflt.js, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\extensions\ffxtlbr@babylon.com\defaults\preferences\instlPref.js, In Quarantäne, [a59b336bbfbc57df5c24049eb25039c7], 
PUP.Optional.Datamngr.A, C:\Users\Michi\AppData\LocalLow\DataMngr\{7CA1F051-A4FB-4143-B263-02B41E571EED}, In Quarantäne, [37098b130d6e191d25650e95a26041bf], 
PUP.Optional.Datamngr.A, C:\Users\Michi\AppData\LocalLow\DataMngr\{7CA1F051-A4FB-4143-B263-02B41E571EED}64, In Quarantäne, [37098b130d6e191d25650e95a26041bf], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb\0.1_0\background.js, In Quarantäne, [fa46d9c5324937ffcf4e1e8616ec3fc1], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb\0.1_0\icon-128.png, In Quarantäne, [fa46d9c5324937ffcf4e1e8616ec3fc1], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb\0.1_0\icon-16.png, In Quarantäne, [fa46d9c5324937ffcf4e1e8616ec3fc1], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb\0.1_0\icon-48.png, In Quarantäne, [fa46d9c5324937ffcf4e1e8616ec3fc1], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb\0.1_0\manifest.json, In Quarantäne, [fa46d9c5324937ffcf4e1e8616ec3fc1], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmgpbjjcdccinnndjdgmegndbmhbgglb\0.1_0\script.js, In Quarantäne, [fa46d9c5324937ffcf4e1e8616ec3fc1], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\0.1_0\background.js, In Quarantäne, [de6206987cfff244bf5fe0c455ad629e], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\0.1_0\icon-128.png, In Quarantäne, [de6206987cfff244bf5fe0c455ad629e], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\0.1_0\icon-16.png, In Quarantäne, [de6206987cfff244bf5fe0c455ad629e], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\0.1_0\icon-48.png, In Quarantäne, [de6206987cfff244bf5fe0c455ad629e], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\0.1_0\manifest.json, In Quarantäne, [de6206987cfff244bf5fe0c455ad629e], 
PUP.Optional.CrossRider.A, C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\majjphhgppkndjjkmhhnbgafooenebhd\0.1_0\script.js, In Quarantäne, [de6206987cfff244bf5fe0c455ad629e], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\dtx.ini, In Quarantäne, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\geodata.xml, In Quarantäne, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\geoip.xml, In Quarantäne, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\guid.dat, In Quarantäne, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\log.txt, In Quarantäne, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\preferences.dat, In Quarantäne, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\stats.dat, In Quarantäne, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\uninstallIE.dat, In Quarantäne, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\version.xml, In Quarantäne, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\weatherbutton_prefs.xml, In Quarantäne, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\weather\7e66f0f9544a85ed2e152a7b26998de4, In Quarantäne, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\weather\c6249801542ff6b529bec9bbf3b3eda5, In Quarantäne, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\weather\forecasts_cache.xml, In Quarantäne, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.SearchQu.A, C:\Users\Michi\AppData\LocalLow\searchqutoolbar\weather\observations_cache.xml, In Quarantäne, [043c633b760542f4ec314d6206fce31d], 
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, In Quarantäne, [75cb8d11ccaf4fe7b93c2989689a30d0], 
PUP.Optional.SystemSpeedup, C:\Users\Michi\AppData\Roaming\Systweak\ssd\SSDPTstub.exe, In Quarantäne, [5de38618a2d9ff3722eaeec822e06f91], 
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.admin", false);), Ersetzt,[6dd38e10a0db3cfab80c7a50b054fb05]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.aflt", "babsst");), Ersetzt,[f34dfca2df9c2115fbc95971e0246f91]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.babExt", "");), Ersetzt,[ba86019d1467c076f9cbd0fa29db8080]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.babTrack", "affID=17350");), Ersetzt,[de6237679be0b284c9fb0dbd857ff60a]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.bbDpng", 29);), Ersetzt,[5de38f0f473478be725228a2669e56aa]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.dfltLng", "en");), Ersetzt,[55eb9b03f48744f21aaaf5d53acafb05]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.dfltSrch", true);), Ersetzt,[122ef7a7b0cb62d45f652c9e9b69bb45]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.hmpg", true);), Ersetzt,[2818c0de6d0e70c601c3e1e97a8ab848]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.id", "547436af000000000000000000000000");), Ersetzt,[2818910dcbb09c9a8044606a8084e11f]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.instlDay", "15370");), Ersetzt,[67d91a842d4e2016566e646607fd41bf]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.instlRef", "sst");), Ersetzt,[d36d425c582358decdf7dcee4cb832ce]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.keyWordUrl", "hxxp://search.babylon.com/?AF=17350&babsrc=adbartrp&mntrId=547436af000000000000000000000000&q=");), Ersetzt,[7bc5138b0774c076655f26a47f855ba5]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.lastDP", 29);), Ersetzt,[96aa36686a1141f5487c6c5eb64ec53b]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.171:40:12");), Ersetzt,[dc64227ca3d862d4774dd9f1b74d20e0]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "7.0");), Ersetzt,[7ec22876057653e3d4f0bd0de71d7f81]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.newTab", true);), Ersetzt,[231dc1ddbcbf2115daeac7034eb6fa06]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_bb");), Ersetzt,[00400a9481fa5ed818ac01c930d41be5]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.noFFXTlbr", false);), Ersetzt,[67d96935d2a93ff76d5741891de7be42]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");), Ersetzt,[99a7aef0e09b3204cbf908c2db29a060]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.propectorlck", 108390239);), Ersetzt,[310f148a87f45dd91ba9b515e81cbd43]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.prtnrId", "babylon");), Ersetzt,[350b3f5f4c2f39fd1aaaf9d1fb09b64a]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.ptch_0717", true);), Ersetzt,[8ab6415da1dabb7b665e06c4e61e49b7]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.smplGrp", "azb");), Ersetzt,[08383f5f4932ee48c2024b7f7c88d030]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.srcExt", "ss");), Ersetzt,[e55b5648b3c847ef368eb01ac1438f71]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.tlbrId", "base");), Ersetzt,[d46c504ed5a6f2448f35903a897b17e9]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.vrsn", "1.5.3.17");), Ersetzt,[9ba51a841c5f84b26460973302028080]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.vrsni", "1.5.3.17");), Ersetzt,[c779d8c6ef8cd1658341be0cd92b7090]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.171:40:12");), Ersetzt,[c779bde15f1c3afc9b293e8c46be3bc5]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.aflt", "babsst");), Ersetzt,[bb85a7f70c6f45f19e26cefc6c987c84]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babExt", "");), Ersetzt,[a89826785e1d47eff0d481498d77fd03]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babTrack", "affID=17350");), Ersetzt,[1c248d117902171ffcc87852ac58e020]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.hardId", "547436af000000000000000000000000");), Ersetzt,[86ba0599037883b30eb66f5bf80c2ed2]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.id", "547436af000000000000000000000000");), Ersetzt,[f0505c4298e3c274a4206b5fda2a4fb1]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.instlDay", "15370");), Ersetzt,[9ca4d5c990ebc472af157159966e4db3]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.instlRef", "sst");), Ersetzt,[9da3b6e88af1f83e11b37e4cba4a8d73]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.newTab", false);), Ersetzt,[7fc10995265572c44c78aa20a85c12ee]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");), Ersetzt,[2818a8f6304bac8a2a9ab317fe06ef11]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");), Ersetzt,[d36dacf2aad11521f6ce4486ed17a957]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.smplGrp", "none");), Ersetzt,[be82633b0378a29401c3be0c699b09f7]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.srcExt", "ss");), Ersetzt,[9ba55648a8d35cda4d77a723828247b9]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.tlbrId", "base");), Ersetzt,[8fb15747b6c5ea4ca3219733020216ea]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");), Ersetzt,[54ec5d414f2c77bf4c7835950004eb15]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");), Ersetzt,[f749afeff388d165992b7e4ce91b20e0]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.171:40:12");), Ersetzt,[eb556c3247349c9aaf15bc0e16ee5ca4]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.id", "547436af000000000000000000000000");), Ersetzt,[37092f6f1b6086b060e64684e81ca45c]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.hardId", "547436af000000000000000000000000");), Ersetzt,[1c244c5247348da98eb8fad0b252cd33]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.instlDay", "15370");), Ersetzt,[b48c2d7183f882b46bdbefdb6b99cd33]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");), Ersetzt,[1c24386624577abcc18538927d87a45c]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");), Ersetzt,[9fa19e00b2c9c0769da9af1bf3118e72]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.171:40:12");), Ersetzt,[df61d5c9bebdb680b096c6042adab44c]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");), Ersetzt,[82be3f5f92e995a1093d6763e51f53ad]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");), Ersetzt,[69d7722c205bec4acb7b6c5e61a3b44c]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.aflt", "babsst");), Ersetzt,[7ec2930b592269cd192d5a70e51f867a]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.smplGrp", "none");), Ersetzt,[231d5747592287af1c2a31998d776c94]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.tlbrId", "base");), Ersetzt,[350ba0fe86f543f3370fc109d430b848]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.newTab", false);), Ersetzt,[1729f5a9522995a196b05476956f36ca]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babTrack", "affID=17350");), Ersetzt,[2e129d0194e7de58b98d606aa75d629e]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.babExt", "");), Ersetzt,[40001f7f7ffcd95d51f59f2b010351af]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.srcExt", "ss");), Ersetzt,[98a8227cf586eb4b7ec85b6f09fb53ad]
PUP.Optional.Babylon.A, C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js, Gut: (), Schlecht: (user_pref("extensions.BabylonToolbar_i.instlRef", "sst");), Ersetzt,[99a7abf3037804320442c3072cd808f8]

Physische Sektoren: 0
(No malicious items detected)


(end)
         
Code:
ATTFilter
# AdwCleaner v3.215 - Bericht erstellt am 11/07/2014 um 13:52:28
# Aktualisiert 09/07/2014 von Xplode
# Betriebssystem : Windows (TM) Vista Ultimate Service Pack 2 (64 bits)
# Benutzername : Michi - MICHI-PC
# Gestartet von : C:\Users\Michi\Desktop\adwcleaner_3.215.exe
# Option : Löschen

***** [ Dienste ] *****

Dienst Gelöscht : vToolbarUpdater18.1.7

***** [ Dateien / Ordner ] *****

[!] Ordner Gelöscht : C:\ProgramData\apn
[!] Ordner Gelöscht : C:\ProgramData\Ask
[!] Ordner Gelöscht : C:\ProgramData\AVG Secure Search
[!] Ordner Gelöscht : C:\ProgramData\Babylon
[!] Ordner Gelöscht : C:\ProgramData\IBUpdaterService
[!] Ordner Gelöscht : C:\ProgramData\Tarma Installer
[!] Ordner Gelöscht : C:\ProgramData\WPM
[!] Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
[!] Ordner Gelöscht : C:\Program Files (x86)\AVG Secure Search
[!] Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
[!] Ordner Gelöscht : C:\Program Files (x86)\predm
[!] Ordner Gelöscht : C:\Program Files (x86)\SupTab
[!] Ordner Gelöscht : C:\Program Files (x86)\webget
[!] Ordner Gelöscht : C:\Program Files (x86)\WinZip Registry Optimizer
[!] Ordner Gelöscht : C:\Program Files (x86)\Common Files\AVG Secure Search
[!] Ordner Gelöscht : C:\Users\Michi\AppData\Local\AVG Secure Search
[!] Ordner Gelöscht : C:\Users\Michi\AppData\Local\globalUpdate
[!] Ordner Gelöscht : C:\Users\Michi\AppData\Local\Ilivid Player
[!] Ordner Gelöscht : C:\Users\Michi\AppData\Local\PackageAware
[!] Ordner Gelöscht : C:\Users\Michi\AppData\LocalLow\AVG Secure Search
[!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Activeris
[!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Babylon
[!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Nico Mak Computing
[!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\sweet-page
[!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Systweak
[!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Uniblue
[!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
[!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HDvidCodec.com
[!] Ordner Gelöscht : C:\Users\Michi\Documents\Optimizer Pro
[!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Searchqutoolbar
[!] Ordner Gelöscht : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
[!] Ordner Gelöscht : C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
Datei Gelöscht : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc@hdvc.com.xpi
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Windows\System32\roboot64.exe
Datei Gelöscht : C:\Users\Michi\AppData\Roaming\aps.uninstall.scan.results
Datei Gelöscht : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\Askcom.xml
Datei Gelöscht : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\ask-search.xml
Datei Gelöscht : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\searchplugins\Search_Results.xml
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Search_Results.xml
Datei Gelöscht : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\user.js
Datei Gelöscht : C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.softonic.de_0.localstorage
Datei Gelöscht : C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.softonic.de_0.localstorage-journal

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\kpkbnefaikfaeadgidhpoanckoiaheli
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\babylon.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\*\shell\filescout
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\DNSBHO.dll
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DnsBHO.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\DnsBHO.BHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CCoupScAnneR.CCoupScAnneR
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CCoupScAnneR.CCoupScAnneR.3.2
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\saveRnEt.saveRnEt
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\saveRnEt.saveRnEt.1.3
Schlüssel Gelöscht : HKCU\Software\5e2d9ddb73abd17
Schlüssel Gelöscht : HKLM\SOFTWARE\5e2d9ddb73abd17
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE8576D7-0A5F-FD10-841C-3FF359D97D4E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FB5E2C20-9D02-6288-3506-3C27D46DC1B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{841D5A49-E48D-413C-9C28-EB3D9081D705}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE8576D7-0A5F-FD10-841C-3FF359D97D4E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB5E2C20-9D02-6288-3506-3C27D46DC1B2}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EE8576D7-0A5F-FD10-841C-3FF359D97D4E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FB5E2C20-9D02-6288-3506-3C27D46DC1B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\AVG Secure Search
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\TutoTag
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\HDvid Codec V1
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\searchqutoolbar
Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Schlüssel Gelöscht : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Schlüssel Gelöscht : HKLM\Software\AVG Secure Search
Schlüssel Gelöscht : HKLM\Software\AVG Security Toolbar
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\PIP
Schlüssel Gelöscht : HKLM\Software\SupDp
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\Tutorials
Schlüssel Gelöscht : HKLM\Software\Uniblue
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{614925F9-841A-53FE-A28F-DC30FA07239B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{614925F9-841A-53FE-A28F-DC30FA07239B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\1ClickDownload
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\HDvid Codec V1
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ilivid
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Plus-HD-2.2
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Windows Searchqu Toolbar
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF

***** [ Browser ] *****

-\\ Internet Explorer v9.0.8112.16561


-\\ Mozilla Firefox v

[ Datei : C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\prefs.js ]

Zeile gelöscht : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Zeile gelöscht : user_pref("browser.search.defaultengine", "Ask.com");
Zeile gelöscht : user_pref("extensions.asktb.abar-war-timeout", "4000");
Zeile gelöscht : user_pref("extensions.asktb.apn_dbr", "ff_7.0.1");
Zeile gelöscht : user_pref("extensions.asktb.autofill-competitor-query-enabled", true);
Zeile gelöscht : user_pref("extensions.asktb.autofill-text-highlight-enabled", true);
Zeile gelöscht : user_pref("extensions.asktb.cbid", "T8");
Zeile gelöscht : user_pref("extensions.asktb.config-updated", true);
Zeile gelöscht : user_pref("extensions.asktb.crumb", "2011.10.19+14.29.27-toolbar011iad-DE-RHVzc2VsZG9yZixHZXJtYW55");
Zeile gelöscht : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://de.ask.com/web?q={query}&qsrc={qsrc}&o={o}&l={l}");
Zeile gelöscht : user_pref("extensions.asktb.displaybehavior", "");
Zeile gelöscht : user_pref("extensions.asktb.displaytext", "");
Zeile gelöscht : user_pref("extensions.asktb.dtid", "YYYYYYYYDE");
Zeile gelöscht : user_pref("extensions.asktb.dyn-weather-do-locid-lookup-weatherWidget", false);
Zeile gelöscht : user_pref("extensions.asktb.dyn-weather-locid-weatherWidget", "GMXX0028");
Zeile gelöscht : user_pref("extensions.asktb.dyn-weather-tempunit-weatherWidget", "C");
Zeile gelöscht : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=");
Zeile gelöscht : user_pref("extensions.asktb.guid", "a7e0a2c2-b71e-4c4e-a9d7-675ba3e934eb");
Zeile gelöscht : user_pref("extensions.asktb.hpr", "YES");
Zeile gelöscht : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com\", \"www.facebook.com\", \"www.playsushi.com\", \"WWW.google.com\", \"hxxps://websearch.ask.com\", [...]
Zeile gelöscht : user_pref("extensions.asktb.if", "first");
Zeile gelöscht : user_pref("extensions.asktb.InstallDir", "C:\\Program Files (x86)\\Ask.com\\");
Zeile gelöscht : user_pref("extensions.asktb.l", "dis");
Zeile gelöscht : user_pref("extensions.asktb.last-config-req", "1369332374986");
Zeile gelöscht : user_pref("extensions.asktb.last-v", "3.13.1.100007");
Zeile gelöscht : user_pref("extensions.asktb.locale", "de_DE");
Zeile gelöscht : user_pref("extensions.asktb.location", "Dusseldorf,Germany");
Zeile gelöscht : user_pref("extensions.asktb.lstation", "");
Zeile gelöscht : user_pref("extensions.asktb.new-tab-opt-out", true);
Zeile gelöscht : user_pref("extensions.asktb.o", "14670");
Zeile gelöscht : user_pref("extensions.asktb.pstate", "");
Zeile gelöscht : user_pref("extensions.asktb.qsrc", "2871");
Zeile gelöscht : user_pref("extensions.asktb.sa", "YES");
Zeile gelöscht : user_pref("extensions.asktb.saguid", "512B1239-32D0-4290-B3A3-B971CE7EF391");
Zeile gelöscht : user_pref("extensions.asktb.search-suggestions-enabled", true);
Zeile gelöscht : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false);
Zeile gelöscht : user_pref("extensions.asktb.socialmini-first", true);
Zeile gelöscht : user_pref("extensions.asktb.socialmini-interval", "1200000");
Zeile gelöscht : user_pref("extensions.asktb.socialmini-max-char-ticker", "33");
Zeile gelöscht : user_pref("extensions.asktb.socialmini-max-items", "30");
Zeile gelöscht : user_pref("extensions.asktb.socialmini-native-on", true);
Zeile gelöscht : user_pref("extensions.asktb.socialmini-speed", "10000");
Zeile gelöscht : user_pref("extensions.asktb.socialmini-transition-first-open", false);
Zeile gelöscht : user_pref("extensions.asktb.themeid", "");
Zeile gelöscht : user_pref("extensions.asktb.timeinstalled", "19.10.2011 23:31:29");
Zeile gelöscht : user_pref("extensions.asktb.to", "");
Zeile gelöscht : user_pref("extensions.enabledAddons", "ffxtlbr@babylon.com:1.2.0,{99079a25-328f-4bd4-be04-00955acaa0a7}:4.5.1.00,{20a82645-c095-46ed-80e3-08825760534b}:0.0.0,plugin@yontoo.com:1.20.02,toolbar@ask.com:[...]
Zeile gelöscht : user_pref("browser.search.order.1", "Ask.com");
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Ask.com");

-\\ Google Chrome v34.0.1847.137

[ Datei : C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Gelöscht [Search Provider] : hxxp://websearch.ask.com/redirect?client=ff&src=crm&tb=ATU2&o=14670&locale=de_DE&apn_uid=a7e0a2c2-b71e-4c4e-a9d7-675ba3e934eb&apn_ptnrs=T8&apn_sauid=512B1239-32D0-4290-B3A3-B971CE7EF391&apn_dtid=YYYYYYYYDE&q={searchTerms}&
Gelöscht [Search Provider] : hxxp://dts.search-results.com/sr?src=crb&appid=119&systemid=406&sr=0&q={searchTerms}
Gelöscht [Search Provider] : hxxp://search.babylon.com/?q={searchTerms}&AF=17350&babsrc=SP_ss&mntrId=547436af000000000000000000000000
Gelöscht [Search Provider] : hxxp://isearch.avg.com/search?cid={2C3F8576-8701-4723-926B-6B262FF0542D}&mid=7b9e35bc36b947d19a48d168c3ec4de6-06ce4fc639803a2e3563922518183d8e94088cb9&lang=de&ds=AVG&pr=pr&d=2013-06-26 20:25:58&v=15.3.0.11&pid=avg&sg=0&sap=dsp&q={searchTerms}
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.search.ask.com/web?p2=%5EB7J%5EYYYYYY%5EYY%5EDE&gct=&o=APN11289&tpid=CME-V7&itbv=12.2.2.604&doi=2013-08-09&apn_uid=94769293-32CE-4BF7-A9CD-DE4FF8C9D886&apn_ptnrs=%5EB7J&apn_dtid=%5EYYYYYY%5EYY%5EDE&apn_dbr=cr_26.0.1410.64&psv=barid%253D%257B8F553BE8%252D012D%252D11E3%252DBC1C%252D00218508A415%257D%2526cargo%253DCME%252DV7%2526spr%253Da&trgb=CR&q={searchTerms}
Gelöscht [Search Provider] : hxxp://www.softonic.de/s/{searchTerms}
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://eu.wowarmory.com/search.xml?searchQuery={searchTerms}&searchType=all
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.search.ask.com/web?p2=%5EB7J%5EYYYYYY%5EYY%5EDE&gct=&o=APN11289&tpid=CME-V7&itbv=12.2.2.604&doi=2013-08-09&apn_uid=94769293-32CE-4BF7-A9CD-DE4FF8C9D886&apn_ptnrs=%5EB7J&apn_dtid=%5EYYYYYY%5EYY%5EDE&apn_dbr=cr_26.0.1410.64&psv=barid%253D%257B8F553BE8%252D012D%252D11E3%252DBC1C%252D00218508A415%257D%2526cargo%253DCME%252DV7%2526spr%253Da&trgb=CR&q={searchTerms}
Gelöscht [Search Provider] : hxxp://www.softonic.de/s/{searchTerms}
Gelöscht [Search Provider] : hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=MSD3_14_10_CH&cd=2XzuyEtN2Y1L1QzutDtDtBtCzzyDtDzz0AyEtCyDtAyC0A0FtN0D0Tzu0SyBzyyBtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2SyC0D0DtCyE0CyEtDtG0FyE0D0FtG0ByCtDyBtGtD0FtByDtGtBtBtC0FtByC0F0E0DyDyD0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyD0CtC0Ezz0EzytG0EtDyCtAtGzyzyyDyEtG0CtC0D0CtGyDtByB0F0E0FzyyB0AtCzytA2Q&cr=955174791&ir=
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=547444334C134AAD&affID=119779&tt=250613_gr2&tsp=4926
Gelöscht [Search Provider] : hxxp://www.sweet-page.com/web/?type=dspp&ts=1400416170&from=cor&uid=HDT722525DLA380_VDS41LT8CJ0V2HCJ0V2HX&q={searchTerms}
Gelöscht [Extension] : dmgpbjjcdccinnndjdgmegndbmhbgglb
Gelöscht [Extension] : kfakeonomonapccoamcmdgpoaicnpnoo
Gelöscht [Extension] : majjphhgppkndjjkmhhnbgafooenebhd
Gelöscht [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof

*************************

AdwCleaner[R0].txt - [30501 octets] - [11/07/2014 13:50:31]
AdwCleaner[S0].txt - [28095 octets] - [11/07/2014 13:52:28]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [28156 octets] ##########
         
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows (TM) Vista Ultimate x64
Ran by Michi on 11.07.2014 at 14:05:07,84
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-503261611-1707939866-3478010161-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21D59046-8568-4E51-BD32-79BD751DCCE6}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{499B15AC-881F-4224-9373-E2AF2D95108B}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5C2A9ED0-361D-4678-BBB6-FA668315952D}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{82FE22F6-6581-4ED3-B962-D0114CFC8F04}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A178FE10-2662-4286-93AB-0477A425A351}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Empty Folder] C:\Users\Michi\appdata\local\{06D80EF3-6DA1-4A64-9A84-2F974DC1CB73}
Successfully deleted: [Empty Folder] C:\Users\Michi\appdata\local\{46C35DA7-197F-4A20-9D60-1018CC587641}
Successfully deleted: [Empty Folder] C:\Users\Michi\appdata\local\{955019F8-861E-4937-B119-2AE7C58D254D}



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 11.07.2014 at 14:15:05,92
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-07-2014
Ran by Michi (administrator) on MICHI-PC on 11-07-2014 14:22:08
Running from C:\Users\Michi\Desktop
Platform: Windows Vista (TM) Ultimate Service Pack 2 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe
() C:\Program Files (x86)\Drakonia Configurator\hid.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
() C:\Program Files (x86)\Drakonia Configurator\trayicon.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaUI.exe
(Realtek) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWLan.exe
() C:\Program Files (x86)\Verbindungsassistent\WTGService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
() C:\Program Files (x86)\MSI\DualCoreCenter\DualCoreCenter.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\SysWOW64\conime.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [WinSys2] => C:\Windows\system32\startup.exe [52072 2008-01-30] ()
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation)
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DelReg] => C:\Program Files (x86)\MSI\DualCoreCenter\DelReg.exe [196608 2008-05-13] ()
HKLM-x32\...\Run: [GamingMouse] => C:\Program Files (x86)\Drakonia Configurator\hid.exe [246784 2012-06-07] ()
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-06-10] (Geek Software GmbH)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\DualCoreCenter.lnk
ShortcutTarget: DualCoreCenter.lnk -> C:\Program Files (x86)\MSI\DualCoreCenter\StartUpDualCoreCenter.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files (x86)\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
ShellIconOverlayIdentifiers: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} -  No File
Toolbar: HKLM - No Name - !{98889811-442D-49dd-99D7-DC866BE87DBC} -  No File
Toolbar: HKLM-x32 - No Name - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} -  No File
Toolbar: HKLM-x32 - No Name - !{82E1477C-B154-48D3-9891-33D83C26BCD3} -  No File
Toolbar: HKLM-x32 - No Name - !{95B7759C-8C7F-4BF1-B163-73684A933233} -  No File
Toolbar: HKLM-x32 - No Name - !{98889811-442D-49dd-99D7-DC866BE87DBC} -  No File
DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: HKLM-x32 {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ ()
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF Extension: HDvid Codec 3 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc3@hdvidcodec.com [2013-08-09]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-11-02]

Chrome: 
=======
CHR HomePage: hxxp://www.google.com
CHR StartupUrls: "hxxp://www.google.com/"
CHR Plugin: (Shockwave Flash) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Extension: (Adblock for Youtube™) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2013-12-04]
CHR Extension: (One Piece: Monkey D. Luffy (1366x768) Black) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebbcomiedmflgiplmdflpmkhkmkekcih [2013-07-20]
CHR Extension: (AdBlock) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-12-04]
CHR Extension: (Google Wallet) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-18]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-06-26] (BitRaider, LLC)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation)
S3 OnlineStorageService; C:\Program Files\Trend Micro SafeSync\hrfscore.exe [7908664 2012-07-12] (Trend Micro Inc.)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-08-22] (Overwolf Ltd)
S2 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [621632 2011-03-04] ()
R2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek) [File not signed]
R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\wtgservice.exe [329168 2011-10-18] ()

==================== Drivers (Whitelisted) ====================

R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-06-22] (AVG Technologies)
S1 Beep; No ImagePath
R3 DualCoreCenter; C:\Program Files (x86)\MSI\DualCoreCenter\NTGLM7X64.sys [44344 2010-02-08] (MICRO-STAR INT'L CO., LTD.)
S3 GameKB; C:\Windows\System32\drivers\GameKB.sys [27648 2012-05-11] () [File not signed]
S3 hwdatacard; C:\Windows\SysWOW64\DRIVERS\ewusbmdm.sys [115328 2008-07-24] (Huawei Technologies Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-11] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 MSIGreenPower; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\NTGLM7X64.sys [40248 2008-03-12] (MICRO-STAR INT'L CO., LTD.) [File not signed]
S3 MSIGreenPowerRushTop; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushTop64.sys [74072 2008-04-23] (Your Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7369v290\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [File not signed]
R3 NVR0Dev; C:\Windows\nvoclk64.sys [18216 2006-10-13] (NVidia Corp.)
R3 RushTopDevice2; C:\Program Files (x86)\MSI\DualCoreCenter\RushTop64.sys [76088 2009-03-18] (Your Corporation)
S3 RushTopDevice_J; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushJ64.sys [31544 2008-06-05] (Your Corporation) [File not signed]
R1 {9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64; C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64.sys [60088 2014-05-16] (StdLib)
S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S1 lhbjqqty; \??\C:\Windows\system32\drivers\lhbjqqty.sys [X]
S3 MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [X]
S1 neqnrghc; \??\C:\Windows\system32\drivers\neqnrghc.sys [X]
S3 netr28ux; system32\DRIVERS\netr28ux.sys [X]
S3 NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S1 rnigwgbp; \??\C:\Windows\system32\drivers\rnigwgbp.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-11 14:22 - 2014-07-11 14:22 - 00018828 _____ () C:\Users\Michi\Desktop\FRST.txt
2014-07-11 14:17 - 2014-07-11 14:21 - 00000000 ____D () C:\Users\Michi\Desktop\FRST-OlderVersion
2014-07-11 14:15 - 2014-07-11 14:15 - 00002007 _____ () C:\Users\Michi\Desktop\JRT.txt
2014-07-11 14:05 - 2014-07-11 14:05 - 00000000 ____D () C:\Windows\ERUNT
2014-07-11 14:03 - 2014-07-11 14:03 - 01016261 _____ (Thisisu) C:\Users\Michi\Desktop\JRT.exe
2014-07-11 14:01 - 2014-07-11 14:01 - 00028265 _____ () C:\Users\Michi\Desktop\AdwCleaner[S0].txt
2014-07-11 13:51 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-11 13:50 - 2014-07-11 13:54 - 00000000 ____D () C:\AdwCleaner
2014-07-11 13:48 - 2014-07-11 13:48 - 00047922 _____ () C:\Users\Michi\Desktop\mbam.txt.txt
2014-07-11 13:42 - 2014-07-11 13:42 - 01348263 _____ () C:\Users\Michi\Desktop\adwcleaner_3.215.exe
2014-07-11 13:18 - 2014-07-11 13:58 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-11 13:15 - 2014-07-11 13:15 - 00000941 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-11 13:15 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-11 13:15 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-11 13:15 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-11 13:13 - 2014-07-11 13:13 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Michi\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-10 18:12 - 2014-07-11 13:55 - 00046394 _____ () C:\Windows\PFRO.log
2014-07-10 17:56 - 2014-07-10 17:56 - 00052795 _____ () C:\ComboFix.txt
2014-07-10 17:41 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-10 17:41 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-10 17:41 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-10 17:41 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-10 17:41 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-10 17:41 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-10 17:41 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-10 17:41 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-10 17:33 - 2014-07-10 17:56 - 00000000 ____D () C:\Qoobox
2014-07-10 17:32 - 2014-07-10 17:54 - 00000000 ____D () C:\Windows\erdnt
2014-07-10 17:30 - 2014-07-10 17:30 - 05217324 ____R (Swearware) C:\Users\Michi\Desktop\ComboFix.exe
2014-07-10 17:25 - 2014-07-10 17:25 - 00000000 ____D () C:\Program Files (x86)\ProShopperu
2014-07-10 15:38 - 2014-07-10 15:38 - 00001099 _____ () C:\Users\Michi\Desktop\Revo Uninstaller.lnk
2014-07-10 15:38 - 2014-07-10 15:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-10 15:37 - 2014-07-10 15:38 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Michi\Downloads\revosetup95.exe
2014-07-09 16:07 - 2014-07-11 14:22 - 00000000 ____D () C:\FRST
2014-07-09 16:05 - 2014-07-11 14:17 - 02084864 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe
2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip
2014-07-09 13:46 - 2014-06-07 06:02 - 17854464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 13:46 - 2014-06-07 04:59 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 13:46 - 2014-06-07 04:52 - 01348608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 13:46 - 2014-06-07 04:51 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 13:46 - 2014-06-07 04:51 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 13:46 - 2014-06-07 04:47 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 13:46 - 2014-06-07 04:45 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-07-09 13:46 - 2014-06-07 04:45 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 13:46 - 2014-06-07 04:45 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 13:46 - 2014-06-07 04:42 - 02148352 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 13:46 - 2014-06-07 04:42 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 13:46 - 2014-06-07 04:42 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 13:46 - 2014-06-07 04:42 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 13:46 - 2014-06-07 04:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 13:46 - 2014-06-07 04:41 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-07-09 13:46 - 2014-06-07 04:40 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 13:46 - 2014-06-07 04:39 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-07-09 13:46 - 2014-06-07 04:35 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 13:46 - 2014-06-07 02:05 - 12353024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-09 13:46 - 2014-06-07 01:12 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-09 13:46 - 2014-06-07 01:04 - 01106432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-09 13:46 - 2014-06-07 01:03 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-09 13:46 - 2014-06-07 01:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-09 13:46 - 2014-06-07 01:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-07-09 13:46 - 2014-06-07 00:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-07-09 13:46 - 2014-06-07 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-09 13:46 - 2014-06-07 00:54 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 13:46 - 2014-06-07 00:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-09 13:46 - 2014-06-07 00:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-07-09 13:46 - 2014-06-07 00:53 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-09 13:46 - 2014-06-07 00:52 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-09 13:46 - 2014-06-07 00:51 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-07-09 13:46 - 2014-06-07 00:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-09 13:45 - 2014-06-07 05:13 - 10890752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 13:45 - 2014-06-07 04:50 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-07-09 13:45 - 2014-06-07 04:41 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-07-09 13:45 - 2014-06-07 01:25 - 09711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-09 13:45 - 2014-06-07 00:58 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-09 13:45 - 2014-06-07 00:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-09 13:45 - 2014-06-07 00:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-09 13:45 - 2014-06-07 00:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-09 13:45 - 2014-06-07 00:53 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-07-09 13:44 - 2014-06-07 02:33 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 13:44 - 2014-06-06 10:59 - 00506880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-09 13:44 - 2014-06-06 09:13 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 13:44 - 2014-05-30 09:10 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX
2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx
2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR
2014-06-26 15:21 - 2014-07-07 13:06 - 00000000 ____D () C:\ProgramData\BitRaider
2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk
2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment
2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk
2014-06-20 12:02 - 2014-06-20 12:03 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver
2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk
2014-06-16 10:58 - 2014-06-16 10:57 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk
2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk
2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt
2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt
2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt
2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt
2014-06-15 11:44 - 2014-06-29 23:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe
2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe
2014-06-12 13:30 - 2014-04-26 20:21 - 00622592 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-12 13:30 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-12 13:30 - 2014-04-05 06:26 - 01417664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-12 13:30 - 2014-04-05 04:32 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-06-12 13:30 - 2014-03-10 08:26 - 01869824 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-12 13:30 - 2014-03-10 08:26 - 01794560 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-12 13:30 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-12 13:30 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll

==================== One Month Modified Files and Folders =======

2014-07-11 14:22 - 2014-07-11 14:22 - 00018828 _____ () C:\Users\Michi\Desktop\FRST.txt
2014-07-11 14:22 - 2014-07-09 16:07 - 00000000 ____D () C:\FRST
2014-07-11 14:21 - 2014-07-11 14:17 - 00000000 ____D () C:\Users\Michi\Desktop\FRST-OlderVersion
2014-07-11 14:17 - 2014-07-09 16:05 - 02084864 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe
2014-07-11 14:15 - 2014-07-11 14:15 - 00002007 _____ () C:\Users\Michi\Desktop\JRT.txt
2014-07-11 14:05 - 2014-07-11 14:05 - 00000000 ____D () C:\Windows\ERUNT
2014-07-11 14:03 - 2014-07-11 14:03 - 01016261 _____ (Thisisu) C:\Users\Michi\Desktop\JRT.exe
2014-07-11 14:01 - 2014-07-11 14:01 - 00028265 _____ () C:\Users\Michi\Desktop\AdwCleaner[S0].txt
2014-07-11 14:01 - 2013-05-14 23:00 - 01702468 _____ () C:\Windows\WindowsUpdate.log
2014-07-11 13:58 - 2014-07-11 13:18 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-11 13:57 - 2013-05-06 22:53 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-11 13:57 - 2013-05-06 22:53 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-11 13:56 - 2014-03-13 18:14 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-11 13:56 - 2006-11-02 17:40 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-11 13:56 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-11 13:56 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-11 13:55 - 2014-07-10 18:12 - 00046394 _____ () C:\Windows\PFRO.log
2014-07-11 13:54 - 2014-07-11 13:50 - 00000000 ____D () C:\AdwCleaner
2014-07-11 13:54 - 2006-11-02 17:40 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-11 13:48 - 2014-07-11 13:48 - 00047922 _____ () C:\Users\Michi\Desktop\mbam.txt.txt
2014-07-11 13:42 - 2014-07-11 13:42 - 01348263 _____ () C:\Users\Michi\Desktop\adwcleaner_3.215.exe
2014-07-11 13:35 - 2006-11-02 15:33 - 00000000 ____D () C:\Windows\security
2014-07-11 13:15 - 2014-07-11 13:15 - 00000941 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-11 13:13 - 2014-07-11 13:13 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Michi\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-10 20:54 - 2012-02-02 03:37 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\TS3Client
2014-07-10 17:56 - 2014-07-10 17:56 - 00052795 _____ () C:\ComboFix.txt
2014-07-10 17:56 - 2014-07-10 17:33 - 00000000 ____D () C:\Qoobox
2014-07-10 17:56 - 2006-11-02 15:33 - 00000000 __RHD () C:\Users\Default
2014-07-10 17:54 - 2014-07-10 17:32 - 00000000 ____D () C:\Windows\erdnt
2014-07-10 17:53 - 2011-10-18 16:41 - 00000000 ____D () C:\Users\Michi
2014-07-10 17:53 - 2006-11-02 14:34 - 00000215 _____ () C:\Windows\system.ini
2014-07-10 17:31 - 2012-08-16 08:22 - 00001696 _____ () C:\Users\Michi\Desktop\bla.txt
2014-07-10 17:30 - 2014-07-10 17:30 - 05217324 ____R (Swearware) C:\Users\Michi\Desktop\ComboFix.exe
2014-07-10 17:25 - 2014-07-10 17:25 - 00000000 ____D () C:\Program Files (x86)\ProShopperu
2014-07-10 17:25 - 2014-06-08 19:55 - 00000000 ____D () C:\ProgramData\297d856b205d5963
2014-07-10 15:38 - 2014-07-10 15:38 - 00001099 _____ () C:\Users\Michi\Desktop\Revo Uninstaller.lnk
2014-07-10 15:38 - 2014-07-10 15:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-10 15:38 - 2014-07-10 15:37 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Michi\Downloads\revosetup95.exe
2014-07-09 14:03 - 2006-11-02 17:21 - 00255776 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-09 13:59 - 2006-11-02 17:06 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-09 13:57 - 2013-07-22 05:26 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-09 13:54 - 2006-11-02 14:35 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip
2014-07-07 13:06 - 2014-06-26 15:21 - 00000000 ____D () C:\ProgramData\BitRaider
2014-07-07 12:56 - 2011-10-18 16:41 - 00055560 _____ () C:\Users\Michi\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-07 12:54 - 2011-10-19 16:48 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-07-05 16:05 - 2011-11-22 11:56 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\vlc
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX
2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx
2014-07-03 14:42 - 2012-05-11 00:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Skype
2014-06-30 06:36 - 2011-10-20 02:44 - 00175616 _____ () C:\Users\Michi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-29 23:08 - 2014-06-15 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2014-06-27 11:36 - 2013-08-30 14:25 - 00000000 ____D () C:\Users\Michi\Desktop\TS Icons
2014-06-27 11:19 - 2012-02-02 03:35 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR
2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
2014-06-26 14:06 - 2013-07-20 12:23 - 00014744 _____ () C:\Users\Michi\Documents\Install STAR WARS The Old Republic.log
2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2014-06-23 08:33 - 2013-05-06 15:32 - 00001217 _____ () C:\Users\Michi\Desktop\WoW PWS.lnk
2014-06-22 19:39 - 2013-06-26 20:25 - 00050464 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk
2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment
2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk
2014-06-20 12:03 - 2014-06-20 12:02 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver
2014-06-17 17:56 - 2012-12-13 10:46 - 00000000 ____D () C:\Filme
2014-06-17 17:56 - 2012-08-25 14:45 - 00000000 ____D () C:\Users\Michi\Desktop\Wma
2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk
2014-06-16 11:00 - 2014-02-03 14:46 - 00155136 _____ () C:\Windows\SysWOW64\unrar.dll
2014-06-16 11:00 - 2014-02-03 14:46 - 00034308 _____ () C:\Windows\SysWOW64\bassmod.dll
2014-06-16 10:57 - 2014-06-16 10:58 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk
2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk
2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt
2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt
2014-06-16 07:18 - 2013-05-12 09:58 - 00000000 ____D () C:\Windows\SysWOW64\directx
2014-06-16 07:18 - 2012-01-27 19:49 - 00000000 ____D () C:\Games
2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt
2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt
2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe
2014-06-15 11:25 - 2013-05-12 18:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Wargaming.net
2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe

Some content of TEMP:
====================
C:\Users\Michi\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-11 14:03

==================== End Of Log ============================
         
--- --- ---

--- --- ---


kleines Update : hat sich einiges getan zwar noch ungewohnt das die Seiten nicht mehr wie Flummis hin und herspringen wegen Werbung aber 100 mal besser

Alt 12.07.2014, 08:42   #9
schrauber
/// the machine
/// TB-Ausbilder
 

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Standard

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 12.07.2014, 15:04   #10
majin85
 
Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Standard

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich



Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=6d9eb5f82028744ab91f518581738a66
# engine=19142
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-07-12 12:39:32
# local_time=2014-07-12 02:39:32 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 8540205 46482088 0 0
# scanned=344891
# found=91
# cleaned=0
# scan_time=14135
sh=C7C0F42A23562AA6DCCD60326FD8CC2AA41B5448 ft=1 fh=c053642cee9f3def vn="Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface32.dll.vir"
sh=9DC13DB9C123270C2356ED410128E11D5ADF7C6E ft=1 fh=023ab782f0a9b07d vn="Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupTab.dll.vir"
sh=48EF8B4E06E0F1D3C06C4D6E1EA2B6CE48AA5231 ft=1 fh=ac26df35aa8ade69 vn="Variante von Win32/Adware.Yontoo.B Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll.vir"
sh=8EB72E101395FEBB37131078A884E25D05BB51C9 ft=1 fh=c71c00113a7cc125 vn="Variante von Win32/AdWare.MultiPlug.T Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\CoupScuanner\pUyJz3N_N.dll.vir"
sh=458A7DCB3C85CBE3C93EB7876FA0E6CD7E07F0F6 ft=1 fh=c71c0011129d357b vn="Variante von Win32/AdWare.MultiPlug.T Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\CoupScuanner\pUyJz3N_N.exe.vir"
sh=21FA935C037CDD4DA753895AA750262A3056B871 ft=1 fh=c71c001127f5a6d6 vn="Variante von Win64/Adware.MultiPlug.C Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\CoupScuanner\pUyJz3N_N.x64.dll.vir"
sh=8EB72E101395FEBB37131078A884E25D05BB51C9 ft=1 fh=c71c00113a7cc125 vn="Variante von Win32/AdWare.MultiPlug.T Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saavernett\e.dll.vir"
sh=458A7DCB3C85CBE3C93EB7876FA0E6CD7E07F0F6 ft=1 fh=c71c0011129d357b vn="Variante von Win32/AdWare.MultiPlug.T Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saavernett\e.exe.vir"
sh=21FA935C037CDD4DA753895AA750262A3056B871 ft=1 fh=c71c001127f5a6d6 vn="Variante von Win64/Adware.MultiPlug.C Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\ProgramData\saavernett\e.x64.dll.vir"
sh=4E63B8B2C46C7F59B8A1BF9D001290A2CC6C0B76 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.A evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_kfakeonomonapccoamcmdgpoaicnpnoo_0\28.vir"
sh=B5ED1E639B7D9AD3C0F3C81E5AA2E9F88DDFEB65 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\102_dealply_m.js.vir"
sh=464E61CE0A166C746C8BE32F8BD662B0EDF79938 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\103_intext_5_m.js.vir"
sh=8BFBBD749FDAA46297DA7F28A30E29C55FD72880 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\104_jollywallet_m.js.vir"
sh=0B21E41A47E579081215969619861996F43524B1 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\105_corticas_m.js.vir"
sh=FE3704EEF2BFB9DCA552518E7AEC9D6AFC1ED15C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\119_similar_web_m.js.vir"
sh=35CE3B76158991DDEA79CAF0C1F826A7EE18A820 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\120_luck_m.js.vir"
sh=E106EF12FBA54AD37717391E3A2A8B7416B0A30E ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\123_intext_adv_m.js.vir"
sh=AE2D5CE395EE9CD2595F77F616E574F4794B1152 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\155_ibario_pops_m.js.vir"
sh=0CEB1A073B87956FD1F21F8425B8F76015B1BCD8 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\158_50onred_ads_only_no_fb_m.js.vir"
sh=CFFCA6A4EE3A0DF2319440491BB297ADEC6EEF37 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\178_revizer_ws_dynamic_m.js.vir"
sh=ADB54DE323736C99B4191A45B478B70DF1B7B945 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\179_revizer_p_dynamic_m.js.vir"
sh=C9A8D5AE55FA65E00EE75767C5D2E9B56041858D ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\180_bpo_serp_m.js.vir"
sh=24E6E5A06D24A5CC24C0B705FDB089FD4FEC70AC ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\184_noproblemppc_m.js.vir"
sh=913EFB9D675CDABC6594788C8F6F1BA8FB057815 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\189_active_sanity.js.vir"
sh=9F07ACC96BC246F25975479E9382CDF88E7D8711 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\191_ciuvo_m.js.vir"
sh=CE36251B85631AF0D145BF086D14272593AB253A ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\194_retargeting_bi_m.js.js.vir"
sh=28EF3B09E284C4A1F530AE035D9CF94E12BD2A97 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\195_icm_convertmedia_m.js.vir"
sh=F545986C4CEA1996E51779B9B8DE73F3C8DF8834 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\91_monetizationLoader.js.js.vir"
sh=0C5AC30A082628E85A9A8B68EF5E5EAFA46F0CC7 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfakeonomonapccoamcmdgpoaicnpnoo\1.26.128_0\extensionData\plugins\93_superfish_no_coupons_m.js.vir"
sh=CC3F181DE2519244625F872A480F9F4C09B16161 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kfakeonomonapccoamcmdgpoaicnpnoo\000962.sst.vir"
sh=D68C30132B7F1BB2FA423C602ADC4148C4E5FD46 ft=1 fh=c71c00112ae35862 vn="Variante von Win32/SProtector.D evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Users\Michi\AppData\Local\Temp\__tmp_2bbca911.vir"
sh=E496D28CA82F39CF482A036A14A71B87FEFA0D8A ft=1 fh=032f2ea9d03063a8 vn="Variante von Win32/DomaIQ.AZ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\File System\000\t\00\00000000"
sh=F99A0B474808C529DBAD311AFB32B17176239448 ft=1 fh=6874c078921d81a0 vn="Variante von Win32/DomaIQ.BF evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000000"
sh=A1AF264931EC92BF3175733E0FFA32E38C7D48B2 ft=1 fh=782af8a2f4ac8179 vn="Win32/Toolbar.SearchSuite.H evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\BrowserConnection.dll"
sh=140FD043B720BE515D9CB555505EBB10BD16025A ft=1 fh=42d2be50ff62fe5d vn="Variante von Win32/Toolbar.SearchSuite.C evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\datamngr.dll"
sh=56AF5F152A3DA847A0E698CADE0A165165532F2E ft=1 fh=5c910fc021e270b2 vn="Variante von Win32/Toolbar.SearchSuite.A evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\datamngrUI.exe"
sh=73558B9668C2DF9D35BD8F88A6B52A6E6BF7BF87 ft=1 fh=99fe90114de7e059 vn="Variante von Win32/Toolbar.SearchSuite.R evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\DnsBHO.dll"
sh=FF958F72167B24E3A5CAB3B33B2144B60A692E89 ft=1 fh=a92b7986aaff0d8d vn="Variante von Win32/Toolbar.SearchSuite evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\IEBHO.dll"
sh=BFDC3839ACE19D582651CBDBCA401D85ACB87CEE ft=1 fh=c71c0011ea55d4ef vn="Variante von Win32/Toolbar.Visicom.C evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\dtUser.exe"
sh=E02E52D8D6D4809A43A0747AD2D43EA571EFAF81 ft=1 fh=28dc55d634c41655 vn="Variante von Win32/Toolbar.Visicom.B evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\searchresultsDx.dll"
sh=7223962B03D4EFEBB2183F1AD27EF47048F0B796 ft=1 fh=4e6c4908f37e801e vn="Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\SRTOOL~1\searchresultstb.dll"
sh=BBEADC524F11590D67F811E03A2713C5A3F4587C ft=1 fh=a93cd89afdab983e vn="Variante von Win64/Toolbar.SearchSuite.A evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\x64\datamngr.dll"
sh=9743EF8EBC72394672B55A25BDC80BFACFCB30B8 ft=1 fh=b915534fd2914b03 vn="Variante von Win64/Toolbar.SearchSuite.A evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\Search Results Toolbar\Datamngr\x64\IEBHO.dll"
sh=23B3E5F508EB6FC76D67A873A5AAC2D34C3CE5E1 ft=1 fh=b86fe1495473b541 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Communicator\mgcommon.dll"
sh=7DB65607A18C67C0C8C0310E0FF23A202AB3F070 ft=1 fh=9f565fd3b0ad3b83 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Communicator\mgcommunication.dll"
sh=3176C30E3A30990C42C968951B6BB2ADFD0B1C00 ft=1 fh=12a0591694d39321 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Communicator\mgsimcommon.dll"
sh=08647AB20AED7B8385931FDF5B4A48165131A061 ft=1 fh=b4c21070436958b0 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Communicator\mgxml_wrapper.dll"
sh=C6A9FB024D614702667E0768E0B673BA3A31F504 ft=1 fh=aa62bac49704426f vn="Variante von Win32/SweetIM.F evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe"
sh=C8F1E3F28152C6C010B7AE8FA4D167E3C388FF0C ft=1 fh=84ff0b58ed098a1d vn="Win32/SweetIM.K evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Communicator\resources\sqlite\mgSqlite3.dll"
sh=D09F832544B921CD7C61A7DB193F29EF6638AD88 ft=1 fh=58a116a27a6d5dbb vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\ContentPackagesActivationHandler.exe"
sh=C6E3F8034D197C34D61701AC146694B6DBEC36CD ft=1 fh=7f9fa2fc68c7b7f4 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgAdaptersProxy.dll"
sh=FC883B83DA2A9ED93AC2A4CEC9936268A6B264C2 ft=1 fh=80a06d85550fdea2 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgArchive.dll"
sh=F3001B5F58A6C6AB8DD7E6E63CB89D20F74EF228 ft=1 fh=f50ea5fcbc656251 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgcommon.dll"
sh=2CF3C9FBCBEBAA6D75DE43CCC487D62954538F81 ft=1 fh=446d6a4df1e456fa vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgcommunication.dll"
sh=60FCD298549E0383DFACBE66420DC922D6BAAF84 ft=1 fh=73f28a50980afe65 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgconfig.dll"
sh=531A5D492B39076AA7990DD76F41B762258B86A7 ft=1 fh=a45064434f491236 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgFlashPlayer.dll"
sh=AE57E26160449200540B1FD8E839F1BD5A30327A ft=1 fh=c29c62a52f555ace vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mghooking.dll"
sh=B6E78443D25AF8B978DC24D515DF7B2F673629CC ft=1 fh=ece232c764d65d89 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgICQAuto.dll"
sh=42B14A7D72C6EDAF5140A2C7B95149B92473853C ft=1 fh=6f2c94e91302d1a2 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgICQMessengerAdapter.dll"
sh=B28C9BCA89A124EBD2EAAF5073370E7E0E87DB4E ft=1 fh=c56c5ff3b0e7703d vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mglogger.dll"
sh=87FF2D9A36B50B5A7DF4D08F87B92BEA86D7DAB7 ft=1 fh=71dc135578fffed6 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgMediaPlayer.dll"
sh=C86CF9524D11A2392A491EA15ED12D2CA890F249 ft=1 fh=ae21d71fff630a17 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgMsnAuto.dll"
sh=055E7A147AB9DCB141FDF58A0D3CCD825AE8B361 ft=1 fh=ac8cec2f7886b930 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgMsnMessengerAdapter.dll"
sh=73987118D6F1799B0B29DB00BF7248B20347BB46 ft=1 fh=d25a2527398bc729 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgsimcommon.dll"
sh=C786E62AB09C10B6277F3E9CFC34207FE56E1FFA ft=1 fh=6c27d70c5686a2b1 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgSweetIM.dll"
sh=07695C8842935A01310F52C83BAB364950419841 ft=1 fh=e250219d9f9cd5af vn="Variante von Win32/SweetIM.F evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgUpdateSupport.dll"
sh=093FB06E67DB8C5562A823E389853340405B8724 ft=1 fh=1b5e6676818f2ad9 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgxml_wrapper.dll"
sh=A679EB39BB32DD88C09E150B0E5F7BAED12467A6 ft=1 fh=0ba701bbd4ac4b73 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgYahooAuto.dll"
sh=9B45902B8B791A84EC6F7D1AD2E8099410D1A467 ft=1 fh=3191d44e293b78d5 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\mgYahooMessengerAdapter.dll"
sh=AE3254BDF03A347110068EF29CB15C7B554491F0 ft=1 fh=30381f993c8268c2 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe"
sh=C8F1E3F28152C6C010B7AE8FA4D167E3C388FF0C ft=1 fh=84ff0b58ed098a1d vn="Win32/SweetIM.K evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Messenger\resources\sqlite\mgSqlite3.dll"
sh=106F591B2BD500597B72796DE6CF1882C4F19F0A ft=1 fh=4ffdf32f906db695 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\ClearHist.exe"
sh=A50D4E8729EC3B275F6AFD9EE573E2A28546F01D ft=1 fh=b0987145db4c1583 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgcommon.dll"
sh=851CA33721CF5E710133B4D36EAF921ACEB4CD50 ft=1 fh=15365fabb2edd5be vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgconfig.dll"
sh=8B5C441500E865FC80A55583FC68036FAF7DAD06 ft=1 fh=c81a85374d8cfdb7 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll"
sh=95581618E0DAA5F92543B429C7EB383C6D63B3AE ft=1 fh=0132ebbe85145cfb vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe"
sh=41C2EC5BB47E9A40E309ABAA048BA1F742E43574 ft=1 fh=f7ee8c0d578659e0 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mghooking.dll"
sh=E32CD33BD92D0676F8F81103174AF5E4E9E3F38E ft=1 fh=0e4e3ab2b3f109e4 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mglogger.dll"
sh=F5348CC7962B088ACCCD2F67138D43FB88DF67F2 ft=1 fh=5a321158315b5fe9 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll"
sh=26B6B3788EF0A2A83A43DFE5E13F51B3E491A6F4 ft=1 fh=073310618d11024b vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll"
sh=10B68A9C897C5854EA80624B01EE8BECF7017F01 ft=1 fh=6858221c6d206eb6 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll"
sh=B0C53EBE6A8C5B9B987F00F739D032767B291118 ft=1 fh=a07a814e5747bf62 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll"
sh=B24958E90C37A562509F135AA942B997B52209B7 ft=1 fh=ecb2fb245305d5cc vn="Win32/Adware.1ClickDownload.K Anwendung" ac=I fn="F:\Program Files (x86)\TornTV.com\uninst.exe"
sh=E1C99225C4C16710DE3AF3D52300E1E943F7C84F ft=1 fh=f891ef12b7700e02 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\ProgramData\SweetIM\Messenger\update\sweetimsetup.exe"
sh=E15DF75E5B81A209E0E453092C9610C3F8DC7073 ft=1 fh=8918dac93ad3a346 vn="Win32/Toolbar.SearchSuite.M evtl. unerwünschte Anwendung" ac=I fn="F:\ProgramData\Wincert\win32cert.dll"
sh=9B56D5787C88CF939DABA1E9273775A1D33EF25F ft=1 fh=8aacdf233e2d6e39 vn="Win32/Toolbar.SearchSuite.M evtl. unerwünschte Anwendung" ac=I fn="F:\ProgramData\Wincert\win32prop.dll"
sh=2FA019C3D1CC2BC1905FBD6765DA3CFBE851DD64 ft=1 fh=f275e610e24fd946 vn="Win64/Toolbar.SearchSuite.B evtl. unerwünschte Anwendung" ac=I fn="F:\ProgramData\Wincert\win64cert.dll"
sh=34ABB88310B01A075382292FDE9F2B6E727E5D66 ft=1 fh=1bef8d0f51d0bf3a vn="Win64/Toolbar.SearchSuite.B evtl. unerwünschte Anwendung" ac=I fn="F:\ProgramData\Wincert\win64prop.dll"
sh=A4C87DB6A390CE18CAF367CC3C8AE182C34B6488 ft=0 fh=0000000000000000 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Windows\Installer\17fc195.msi"
sh=F2CF5D55F2843F59864F93643E6931E32A54430F ft=0 fh=0000000000000000 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="F:\Windows\Installer\17fc19a.msi"
sh=195E06474CD71867AEE3CC9C415F095328EA3935 ft=0 fh=0000000000000000 vn="Win32/SweetIM.K evtl. unerwünschte Anwendung" ac=I fn="F:\Windows\Installer\17fc19f.msi"
         
Code:
ATTFilter
 Results of screen317's Security Check version 0.99.85  
 Windows Vista Service Pack 2 x64 (UAC is enabled)  
 Internet Explorer 9  
 Internet Explorer 8  
``````````````Antivirus/Firewall Check:`````````````` 
Microsoft Security Essentials   
  (On Access scanning disabled!) 
 Error obtaining update status for antivirus!  
`````````Anti-malware/Other Utilities Check:````````` 
 Java 7 Update 55  
 Java version out of Date! 
 Adobe Flash Player 	14.0.0.145  
 Adobe Reader 10.1.10 Adobe Reader out of Date!  
 Google Chrome 26.0.1410.64  
 Google Chrome 34.0.1847.137  
````````Process Check: objlist.exe by Laurent````````  
 Microsoft Security Essentials MSMpEng.exe 
 Microsoft Security Essentials msseces.exe 
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbam.exe  
 Malwarebytes Anti-Malware mbamscheduler.exe   
 system32 FirewallControlPanel.exe   
 Trend Micro SafeSync hrfscore.exe   
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  % 
````````````````````End of Log``````````````````````
         
FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-07-2014
Ran by Michi (administrator) on MICHI-PC on 12-07-2014 14:56:12
Running from C:\Users\Michi\Desktop
Platform: Windows Vista (TM) Ultimate Service Pack 2 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe
() C:\Program Files (x86)\Drakonia Configurator\hid.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaUI.exe
() C:\Program Files (x86)\Drakonia Configurator\trayicon.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
(Realtek) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWLan.exe
() C:\Program Files (x86)\Verbindungsassistent\WTGService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\conime.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro SafeSync\hrfscore.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [WinSys2] => C:\Windows\system32\startup.exe [52072 2008-01-30] ()
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation)
HKLM-x32\...\Run: [WinampAgent] => C:\Program Files\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DelReg] => C:\Program Files (x86)\MSI\DualCoreCenter\DelReg.exe [196608 2008-05-13] ()
HKLM-x32\...\Run: [GamingMouse] => C:\Program Files (x86)\Drakonia Configurator\hid.exe [246784 2012-06-07] ()
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-06-10] (Geek Software GmbH)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\DualCoreCenter.lnk
ShortcutTarget: DualCoreCenter.lnk -> C:\Program Files (x86)\MSI\DualCoreCenter\StartUpDualCoreCenter.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files (x86)\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
ShellIconOverlayIdentifiers: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoPaired -> {A203F945-39E9-4286-AFA2-F3ADFCD5FAAA} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoPriority -> {6F1BB626-1107-4b82-B322-54C5E64461B8} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoProblem -> {7479C9AF-DA81-4944-92E5-23E49390BB2B} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoSynced -> {7479C9AF-DA81-4944-92E5-23E49390BB2A} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoSyncing -> {7479C9AF-DA81-4944-92E5-23E49390BB29} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)
ShellIconOverlayIdentifiers-x32: 00HumyoUnavailable -> {66669544-5639-4922-99C8-CE7A86651364} => C:\Program Files\Trend Micro SafeSync\HrfsShellExtension32.dll (Trend Micro Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} -  No File
Toolbar: HKLM - No Name - !{98889811-442D-49dd-99D7-DC866BE87DBC} -  No File
Toolbar: HKLM-x32 - No Name - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} -  No File
Toolbar: HKLM-x32 - No Name - !{82E1477C-B154-48D3-9891-33D83C26BCD3} -  No File
Toolbar: HKLM-x32 - No Name - !{95B7759C-8C7F-4BF1-B163-73684A933233} -  No File
Toolbar: HKLM-x32 - No Name - !{98889811-442D-49dd-99D7-DC866BE87DBC} -  No File
DPF: HKLM-x32 {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: HKLM-x32 {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/VirtualEarth3D,version=4.0 - C:\Program Files (x86)\Virtual Earth 3D\ ()
FF Plugin-x32: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF Extension: HDvid Codec 3 - C:\Users\Michi\AppData\Roaming\Mozilla\Firefox\Profiles\wvkdq1fa.default\Extensions\hdvc3@hdvidcodec.com [2013-08-09]
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-11-02]

Chrome: 
=======
CHR HomePage: hxxp://www.google.com
CHR StartupUrls: "hxxp://www.google.com/"
CHR Plugin: (Shockwave Flash) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.202\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.137\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.3.0\\npsitesafety.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Extension: (Adblock for Youtube™) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2013-12-04]
CHR Extension: (One Piece: Monkey D. Luffy (1366x768) Black) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebbcomiedmflgiplmdflpmkhkmkekcih [2013-07-20]
CHR Extension: (AdBlock) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-12-04]
CHR Extension: (Google Wallet) - C:\Users\Michi\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-18]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-06-26] (BitRaider, LLC)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation)
R3 OnlineStorageService; C:\Program Files\Trend Micro SafeSync\hrfscore.exe [7908664 2012-07-12] (Trend Micro Inc.)
S3 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-08-22] (Overwolf Ltd)
S2 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [621632 2011-03-04] ()
R2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek) [File not signed]
R2 WTGService; C:\Program Files (x86)\Verbindungsassistent\wtgservice.exe [329168 2011-10-18] ()

==================== Drivers (Whitelisted) ====================

R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-06-22] (AVG Technologies)
S1 Beep; No ImagePath
R3 DualCoreCenter; C:\Program Files (x86)\MSI\DualCoreCenter\NTGLM7X64.sys [44344 2010-02-08] (MICRO-STAR INT'L CO., LTD.)
S3 GameKB; C:\Windows\System32\drivers\GameKB.sys [27648 2012-05-11] () [File not signed]
S3 hwdatacard; C:\Windows\SysWOW64\DRIVERS\ewusbmdm.sys [115328 2008-07-24] (Huawei Technologies Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-12] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 MSIGreenPower; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\NTGLM7X64.sys [40248 2008-03-12] (MICRO-STAR INT'L CO., LTD.) [File not signed]
S3 MSIGreenPowerRushTop; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushTop64.sys [74072 2008-04-23] (Your Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7369v290\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [File not signed]
R3 RushTopDevice2; C:\Program Files (x86)\MSI\DualCoreCenter\RushTop64.sys [76088 2009-03-18] (Your Corporation)
S3 RushTopDevice_J; C:\Program Files (x86)\MSI\DualCoreCenter\Green Power Center\RushJ64.sys [31544 2008-06-05] (Your Corporation) [File not signed]
R1 {9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64; C:\Windows\System32\drivers\{9edd0ea8-2819-47c2-8320-b007d5996f8a}Gt64.sys [60088 2014-05-16] (StdLib)
S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S1 lhbjqqty; \??\C:\Windows\system32\drivers\lhbjqqty.sys [X]
S3 MSI_MSIBIOS_010507; \??\C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [X]
S1 neqnrghc; \??\C:\Windows\system32\drivers\neqnrghc.sys [X]
S3 netr28ux; system32\DRIVERS\netr28ux.sys [X]
S3 NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S1 rnigwgbp; \??\C:\Windows\system32\drivers\rnigwgbp.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-12 14:56 - 2014-07-12 14:56 - 00018863 _____ () C:\Users\Michi\Desktop\FRST.txt
2014-07-12 14:53 - 2014-07-12 14:54 - 00001245 _____ () C:\Users\Michi\Desktop\checkup.txt.txt
2014-07-12 14:47 - 2014-07-12 14:47 - 00854390 _____ () C:\Users\Michi\Desktop\SecurityCheck.exe
2014-07-12 10:34 - 2014-07-12 10:34 - 02347384 _____ (ESET) C:\Users\Michi\Downloads\esetsmartinstaller_deu.exe
2014-07-11 23:41 - 2014-07-12 14:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-11 23:41 - 2014-07-11 23:42 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-11 14:17 - 2014-07-12 10:35 - 00000000 ____D () C:\Users\Michi\Desktop\FRST-OlderVersion
2014-07-11 14:15 - 2014-07-11 14:15 - 00002007 _____ () C:\Users\Michi\Desktop\JRT.txt
2014-07-11 14:05 - 2014-07-11 14:05 - 00000000 ____D () C:\Windows\ERUNT
2014-07-11 14:03 - 2014-07-11 14:03 - 01016261 _____ (Thisisu) C:\Users\Michi\Desktop\JRT.exe
2014-07-11 14:01 - 2014-07-11 14:01 - 00028265 _____ () C:\Users\Michi\Desktop\AdwCleaner[S0].txt
2014-07-11 13:51 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-11 13:50 - 2014-07-11 13:54 - 00000000 ____D () C:\AdwCleaner
2014-07-11 13:48 - 2014-07-11 13:48 - 00047922 _____ () C:\Users\Michi\Desktop\mbam.txt.txt
2014-07-11 13:42 - 2014-07-11 13:42 - 01348263 _____ () C:\Users\Michi\Desktop\adwcleaner_3.215.exe
2014-07-11 13:18 - 2014-07-12 14:26 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-11 13:15 - 2014-07-11 13:15 - 00000941 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-11 13:15 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-11 13:15 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-11 13:15 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-11 13:13 - 2014-07-11 13:13 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Michi\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-10 18:12 - 2014-07-11 13:55 - 00046394 _____ () C:\Windows\PFRO.log
2014-07-10 17:56 - 2014-07-10 17:56 - 00052795 _____ () C:\ComboFix.txt
2014-07-10 17:41 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-10 17:41 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-10 17:41 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-10 17:41 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-10 17:41 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-10 17:41 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-10 17:41 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-10 17:41 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-10 17:33 - 2014-07-10 17:56 - 00000000 ____D () C:\Qoobox
2014-07-10 17:32 - 2014-07-10 17:54 - 00000000 ____D () C:\Windows\erdnt
2014-07-10 17:30 - 2014-07-10 17:30 - 05217324 ____R (Swearware) C:\Users\Michi\Desktop\ComboFix.exe
2014-07-10 17:25 - 2014-07-10 17:25 - 00000000 ____D () C:\Program Files (x86)\ProShopperu
2014-07-10 15:38 - 2014-07-10 15:38 - 00001099 _____ () C:\Users\Michi\Desktop\Revo Uninstaller.lnk
2014-07-10 15:38 - 2014-07-10 15:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-10 15:37 - 2014-07-10 15:38 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Michi\Downloads\revosetup95.exe
2014-07-09 16:07 - 2014-07-12 14:56 - 00000000 ____D () C:\FRST
2014-07-09 16:05 - 2014-07-11 14:17 - 02084864 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe
2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip
2014-07-09 13:46 - 2014-06-07 06:02 - 17854464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 13:46 - 2014-06-07 04:59 - 02339328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 13:46 - 2014-06-07 04:52 - 01348608 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 13:46 - 2014-06-07 04:51 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 13:46 - 2014-06-07 04:51 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 13:46 - 2014-06-07 04:47 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 13:46 - 2014-06-07 04:45 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-07-09 13:46 - 2014-06-07 04:45 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 13:46 - 2014-06-07 04:45 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 13:46 - 2014-06-07 04:42 - 02148352 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 13:46 - 2014-06-07 04:42 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 13:46 - 2014-06-07 04:42 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 13:46 - 2014-06-07 04:42 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 13:46 - 2014-06-07 04:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 13:46 - 2014-06-07 04:41 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-07-09 13:46 - 2014-06-07 04:40 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 13:46 - 2014-06-07 04:39 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-07-09 13:46 - 2014-06-07 04:35 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 13:46 - 2014-06-07 02:05 - 12353024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-09 13:46 - 2014-06-07 01:12 - 01810432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-09 13:46 - 2014-06-07 01:04 - 01106432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-09 13:46 - 2014-06-07 01:03 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-09 13:46 - 2014-06-07 01:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-09 13:46 - 2014-06-07 01:00 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-07-09 13:46 - 2014-06-07 00:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-07-09 13:46 - 2014-06-07 00:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-09 13:46 - 2014-06-07 00:54 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 13:46 - 2014-06-07 00:54 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-09 13:46 - 2014-06-07 00:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-07-09 13:46 - 2014-06-07 00:53 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-09 13:46 - 2014-06-07 00:52 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-09 13:46 - 2014-06-07 00:51 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-07-09 13:46 - 2014-06-07 00:47 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-09 13:45 - 2014-06-07 05:13 - 10890752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 13:45 - 2014-06-07 04:50 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-07-09 13:45 - 2014-06-07 04:41 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-07-09 13:45 - 2014-06-07 01:25 - 09711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-09 13:45 - 2014-06-07 00:58 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-09 13:45 - 2014-06-07 00:57 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-09 13:45 - 2014-06-07 00:54 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-09 13:45 - 2014-06-07 00:53 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-09 13:45 - 2014-06-07 00:53 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-07-09 13:44 - 2014-06-07 02:33 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 13:44 - 2014-06-06 10:59 - 00506880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-09 13:44 - 2014-06-06 09:13 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 13:44 - 2014-05-30 09:10 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX
2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx
2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR
2014-06-26 15:21 - 2014-07-07 13:06 - 00000000 ____D () C:\ProgramData\BitRaider
2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk
2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment
2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk
2014-06-20 12:02 - 2014-06-20 12:03 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver
2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk
2014-06-16 10:58 - 2014-06-16 10:57 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk
2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk
2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt
2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt
2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt
2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt
2014-06-15 11:44 - 2014-06-29 23:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe
2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe
2014-06-12 13:30 - 2014-04-26 20:21 - 00622592 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-12 13:30 - 2014-04-26 18:01 - 00502784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-12 13:30 - 2014-04-05 06:26 - 01417664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-12 13:30 - 2014-04-05 04:32 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-06-12 13:30 - 2014-03-10 08:26 - 01869824 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-12 13:30 - 2014-03-10 08:26 - 01794560 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-12 13:30 - 2014-03-10 03:22 - 01401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-12 13:30 - 2014-03-10 03:22 - 01248768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll

==================== One Month Modified Files and Folders =======

2014-07-12 14:57 - 2013-05-06 22:53 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-12 14:56 - 2014-07-12 14:56 - 00018863 _____ () C:\Users\Michi\Desktop\FRST.txt
2014-07-12 14:56 - 2014-07-09 16:07 - 00000000 ____D () C:\FRST
2014-07-12 14:54 - 2014-07-12 14:53 - 00001245 _____ () C:\Users\Michi\Desktop\checkup.txt.txt
2014-07-12 14:47 - 2014-07-12 14:47 - 00854390 _____ () C:\Users\Michi\Desktop\SecurityCheck.exe
2014-07-12 14:42 - 2014-07-11 23:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-12 14:26 - 2014-07-11 13:18 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-12 13:56 - 2013-05-06 22:53 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-12 13:51 - 2013-05-14 23:00 - 01758503 _____ () C:\Windows\WindowsUpdate.log
2014-07-12 13:33 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-12 13:33 - 2006-11-02 17:21 - 00003760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-12 10:35 - 2014-07-11 14:17 - 00000000 ____D () C:\Users\Michi\Desktop\FRST-OlderVersion
2014-07-12 10:34 - 2014-07-12 10:34 - 02347384 _____ (ESET) C:\Users\Michi\Downloads\esetsmartinstaller_deu.exe
2014-07-12 07:33 - 2014-03-13 18:14 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-12 07:33 - 2006-11-02 17:40 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-12 02:48 - 2006-11-02 17:40 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-11 23:42 - 2014-07-11 23:41 - 00003736 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-11 23:42 - 2013-05-07 09:14 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-11 23:42 - 2011-10-19 14:08 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-11 22:39 - 2012-02-02 03:37 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\TS3Client
2014-07-11 15:20 - 2012-08-16 08:22 - 00001696 _____ () C:\Users\Michi\Desktop\bla.txt
2014-07-11 14:17 - 2014-07-09 16:05 - 02084864 _____ (Farbar) C:\Users\Michi\Desktop\FRST64.exe
2014-07-11 14:15 - 2014-07-11 14:15 - 00002007 _____ () C:\Users\Michi\Desktop\JRT.txt
2014-07-11 14:05 - 2014-07-11 14:05 - 00000000 ____D () C:\Windows\ERUNT
2014-07-11 14:03 - 2014-07-11 14:03 - 01016261 _____ (Thisisu) C:\Users\Michi\Desktop\JRT.exe
2014-07-11 14:01 - 2014-07-11 14:01 - 00028265 _____ () C:\Users\Michi\Desktop\AdwCleaner[S0].txt
2014-07-11 13:55 - 2014-07-10 18:12 - 00046394 _____ () C:\Windows\PFRO.log
2014-07-11 13:54 - 2014-07-11 13:50 - 00000000 ____D () C:\AdwCleaner
2014-07-11 13:48 - 2014-07-11 13:48 - 00047922 _____ () C:\Users\Michi\Desktop\mbam.txt.txt
2014-07-11 13:42 - 2014-07-11 13:42 - 01348263 _____ () C:\Users\Michi\Desktop\adwcleaner_3.215.exe
2014-07-11 13:35 - 2006-11-02 15:33 - 00000000 ____D () C:\Windows\security
2014-07-11 13:15 - 2014-07-11 13:15 - 00000941 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-11 13:15 - 2014-07-11 13:15 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-11 13:13 - 2014-07-11 13:13 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Michi\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-10 17:56 - 2014-07-10 17:56 - 00052795 _____ () C:\ComboFix.txt
2014-07-10 17:56 - 2014-07-10 17:33 - 00000000 ____D () C:\Qoobox
2014-07-10 17:56 - 2006-11-02 15:33 - 00000000 __RHD () C:\Users\Default
2014-07-10 17:54 - 2014-07-10 17:32 - 00000000 ____D () C:\Windows\erdnt
2014-07-10 17:53 - 2011-10-18 16:41 - 00000000 ____D () C:\Users\Michi
2014-07-10 17:53 - 2006-11-02 14:34 - 00000215 _____ () C:\Windows\system.ini
2014-07-10 17:30 - 2014-07-10 17:30 - 05217324 ____R (Swearware) C:\Users\Michi\Desktop\ComboFix.exe
2014-07-10 17:25 - 2014-07-10 17:25 - 00000000 ____D () C:\Program Files (x86)\ProShopperu
2014-07-10 17:25 - 2014-06-08 19:55 - 00000000 ____D () C:\ProgramData\297d856b205d5963
2014-07-10 15:38 - 2014-07-10 15:38 - 00001099 _____ () C:\Users\Michi\Desktop\Revo Uninstaller.lnk
2014-07-10 15:38 - 2014-07-10 15:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-10 15:38 - 2014-07-10 15:37 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Michi\Downloads\revosetup95.exe
2014-07-09 14:03 - 2006-11-02 17:21 - 00255776 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-09 13:59 - 2006-11-02 17:06 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-09 13:57 - 2013-07-22 05:26 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-09 13:54 - 2006-11-02 14:35 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-07-09 13:49 - 2014-07-09 13:49 - 00008123 _____ () C:\Users\Michi\Downloads\Rechnung zu Order-ID 381518 vom 08.07.2014 143859.zip
2014-07-07 13:06 - 2014-06-26 15:21 - 00000000 ____D () C:\ProgramData\BitRaider
2014-07-07 12:56 - 2011-10-18 16:41 - 00055560 _____ () C:\Users\Michi\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-07 12:54 - 2011-10-19 16:48 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-07-05 16:05 - 2011-11-22 11:56 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\vlc
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\Codejock.Controls.v15.3.1.ocx
2014-07-04 20:44 - 2014-07-04 20:44 - 01931296 _____ (Codejock Software) C:\Windows\CODEJO~2.OCX
2014-07-04 20:44 - 2014-07-04 20:44 - 00136008 _____ (Microsoft Corporation) C:\Windows\msinet.ocx
2014-07-03 14:42 - 2012-05-11 00:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Skype
2014-06-30 06:36 - 2011-10-20 02:44 - 00175616 _____ () C:\Users\Michi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-29 23:08 - 2014-06-15 11:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2014-06-27 11:36 - 2013-08-30 14:25 - 00000000 ____D () C:\Users\Michi\Desktop\TS Icons
2014-06-27 11:19 - 2012-02-02 03:35 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-06-26 21:46 - 2014-06-26 21:46 - 00000000 ____D () C:\Users\Michi\AppData\Local\SWTOR
2014-06-26 15:21 - 2014-06-26 15:21 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2014-06-26 14:06 - 2014-06-26 14:06 - 00001280 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
2014-06-26 14:06 - 2013-07-20 12:23 - 00014744 _____ () C:\Users\Michi\Documents\Install STAR WARS The Old Republic.log
2014-06-26 14:05 - 2014-06-26 14:05 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2014-06-26 13:08 - 2014-06-26 13:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2014-06-23 08:33 - 2013-05-06 15:32 - 00001217 _____ () C:\Users\Michi\Desktop\WoW PWS.lnk
2014-06-22 19:39 - 2013-06-26 20:25 - 00050464 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2014-06-22 12:45 - 2014-06-22 12:45 - 00000590 _____ () C:\Users\Michi\Desktop\WoW Storm.lnk
2014-06-22 11:42 - 2014-06-22 11:42 - 00000000 ____D () C:\Users\Public\Documents\Blizzard Entertainment
2014-06-20 12:03 - 2014-06-20 12:03 - 00350228 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI2BE2.txt
2014-06-20 12:03 - 2014-06-20 12:03 - 00001477 _____ () C:\Users\Public\Desktop\Launch Monitor Driver Installer.lnk
2014-06-20 12:03 - 2014-06-20 12:02 - 00000000 ____D () C:\Program Files (x86)\MonitorDriver
2014-06-17 17:56 - 2012-12-13 10:46 - 00000000 ____D () C:\Filme
2014-06-17 17:56 - 2012-08-25 14:45 - 00000000 ____D () C:\Users\Michi\Desktop\Wma
2014-06-16 11:03 - 2014-06-16 11:03 - 00000552 _____ () C:\Users\Michi\Desktop\World of Tanks 0.9.1 ProMod.lnk
2014-06-16 11:00 - 2014-02-03 14:46 - 00155136 _____ () C:\Windows\SysWOW64\unrar.dll
2014-06-16 11:00 - 2014-02-03 14:46 - 00034308 _____ () C:\Windows\SysWOW64\bassmod.dll
2014-06-16 10:57 - 2014-06-16 10:58 - 00000605 _____ () C:\Users\Michi\Desktop\WoT.lnk
2014-06-16 10:57 - 2014-06-16 10:57 - 00000600 _____ () C:\Users\Michi\Desktop\WoTLauncher.lnk
2014-06-16 07:18 - 2014-06-16 07:18 - 00357398 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI195F.txt
2014-06-16 07:18 - 2014-06-16 07:18 - 00011222 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI195F.txt
2014-06-16 07:18 - 2013-05-12 09:58 - 00000000 ____D () C:\Windows\SysWOW64\directx
2014-06-16 07:18 - 2012-01-27 19:49 - 00000000 ____D () C:\Games
2014-06-16 07:07 - 2014-06-16 07:07 - 00355094 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI10A2.txt
2014-06-16 07:07 - 2014-06-16 07:07 - 00011126 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI10A2.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00357696 _____ () C:\Users\Michi\AppData\Local\dd_vcredistMSI172C.txt
2014-06-15 11:45 - 2014-06-15 11:45 - 00012006 _____ () C:\Users\Michi\AppData\Local\dd_vcredistUI172C.txt
2014-06-15 11:41 - 2014-06-15 11:41 - 09304408 _____ (Wargaming.net ) C:\Users\Michi\Downloads\WoT_internet_install_eu.exe
2014-06-15 11:25 - 2013-05-12 18:26 - 00000000 ____D () C:\Users\Michi\AppData\Roaming\Wargaming.net
2014-06-15 09:05 - 2014-06-15 09:05 - 02390528 _____ (OldSkool) C:\Users\Michi\Downloads\ProMod.exe

Some content of TEMP:
====================
C:\Users\Michi\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-12 07:41

==================== End Of Log ============================
         
--- --- ---

--- --- ---



Hi Schrauber

nein, bis jetzt keine Probleme das läuft es alles wie geschmiert
Hätte vielleicht im Anschluss wenn wir mit der Reise durch meinen verwurschteten PC fertig noch ein paar Fragen Ansonsten ist alles Top
- keine Ping Pong Seiten mehr die springen
- keine extrem lästige Werbung mehr die das Lesen unmöglich macht
- und alles wird super schnell geladen Ihr macht eurem Ruf echt alle Ehre

Alt 13.07.2014, 13:59   #11
schrauber
/// the machine
/// TB-Ausbilder
 

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Standard

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich



Java und Adobe updaten.

Was ist Laufwerk F?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 13.07.2014, 19:05   #12
majin85
 
Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Standard

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich



Java-Version installiert (Version 7 Update 60)

Adobe ist auf dem neusten stand jetzt auch ( wird mir zumindest gesagt )

Ehm Laufwerk F ist ne alte Festplatte aus meinem alten Laptop habe die einfach mit in PC geschoben gab bis jetzt keine Probleme

Alt 14.07.2014, 15:52   #13
schrauber
/// the machine
/// TB-Ausbilder
 

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Standard

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich



Formatier F, die is voll mit Rotz

Fertig

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun

Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 14.07.2014, 18:21   #14
majin85
 
Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Standard

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich



Hey Schrauber,

also an sich alles Top rennt perfekt alles

Gerade mal geschaut wegen solchen Registry Cleanern. Da habe ich eins gefunden.

Auslogics heißt das, wollte ich Deinstallieren nur scheitert das irgendwie

Ansonsten kann ich dir gar nicht genug Danken und danke für die Tipps im Anschluss werde ich Befolgen

Alt 14.07.2014, 19:17   #15
schrauber
/// the machine
/// TB-Ausbilder
 

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Standard

Dauerhaftes Werbung öffnen macht Surfen fast unmöglich



Deinstallier mal mit Revo Uninstaller
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Dauerhaftes Werbung öffnen macht Surfen fast unmöglich
adware.eorezo, pup.bprotector, pup.optional.babylon.a, pup.optional.bandoo.a, pup.optional.bprotector.a, pup.optional.crossrider.a, pup.optional.datamngr.a, pup.optional.delta.a, pup.optional.feven.a, pup.optional.filescout.a, pup.optional.hdvidcodec.a, pup.optional.iepluginservice.a, pup.optional.installcore.a, pup.optional.mplayerplus.a, pup.optional.mysearchdial.a, pup.optional.newplayer.a, pup.optional.plushd.a, pup.optional.searchqu, pup.optional.softonic.a, pup.optional.suptab.a, pup.optional.sweetim.a, pup.optional.sweetpage.a, pup.optional.systemspeedup, pup.optional.webcake.a, trojaner-board



Ähnliche Themen: Dauerhaftes Werbung öffnen macht Surfen fast unmöglich


  1. Windows 10: Virusprogramm macht es mir beinahen unmöglich etwas anzuclicken. Offline kein Problem
    Log-Analyse und Auswertung - 30.09.2015 (21)
  2. Verseuchtes WinXP macht die Nutzung unmöglich
    Plagegeister aller Art und deren Bekämpfung - 23.09.2015 (26)
  3. Mailware im Browser ,surfen fast unmöglich
    Log-Analyse und Auswertung - 03.08.2015 (15)
  4. kleines blaues Fenster macht bedienung des PC unmöglich
    Plagegeister aller Art und deren Bekämpfung - 12.06.2015 (3)
  5. Neuer Laptop und unmengen an Popups! Surfen fast nicht mehr möglich!
    Plagegeister aller Art und deren Bekämpfung - 23.05.2015 (37)
  6. Es öffnen sich fast immer neue Tabs mit Werbung sei es, wenn ich webseiten öffne oder in textfelder klicke (wie hier)
    Plagegeister aller Art und deren Bekämpfung - 13.05.2015 (4)
  7. Windows Vista erneutes Werbung öffnen macht Surfen wieder unmöglich
    Plagegeister aller Art und deren Bekämpfung - 09.01.2015 (15)
  8. Virusvermutung: Uhrzeit verstellt sich immer und surfen ist unmöglich!
    Log-Analyse und Auswertung - 17.10.2014 (5)
  9. Windows7: Toolbars, Werbung Istart. Surfen unmöglich
    Log-Analyse und Auswertung - 13.09.2014 (13)
  10. Aller Art von Passwörer werden ständig vertaucht.Mails unter meiner Adrese verschickt.Texten fast unmöglich .egun is das
    Plagegeister aller Art und deren Bekämpfung - 24.08.2014 (5)
  11. Windows 7: Beim Surfen öffnen sich ungewollt neu tabs/Fenster mit Werbung
    Log-Analyse und Auswertung - 08.05.2014 (10)
  12. Werbe-Popupfenster machen "surfen" im Internet unmöglich
    Plagegeister aller Art und deren Bekämpfung - 19.08.2013 (9)
  13. Ihavenet macht mein Firefox-Googeln fast unmöglich
    Plagegeister aller Art und deren Bekämpfung - 14.12.2012 (18)
  14. Java/DLdr.Agent macht Internet Zugang unmöglich
    Plagegeister aller Art und deren Bekämpfung - 16.11.2010 (4)
  15. Computer total langsam, chatten fast unmöglich.
    Log-Analyse und Auswertung - 14.10.2008 (13)
  16. Microsoft Hilfe- und Supportcenter öffnet ohne Grund und macht ein Arbeiten unmöglich
    Log-Analyse und Auswertung - 26.08.2008 (1)
  17. Beim Surfen (IE 7 // Firefox) öffnen sich automatisch Werbung-/Erotikseiten =(
    Log-Analyse und Auswertung - 22.08.2008 (17)

Zum Thema Dauerhaftes Werbung öffnen macht Surfen fast unmöglich - Hi Trojaner-Board Team, mein PC wird seit längerem von Werbung auf Internetseiten zugemüllt, das das Surfen im Internet fast unmöglich macht. An dem PC wurde auch länger nichts gemacht, da - Dauerhaftes Werbung öffnen macht Surfen fast unmöglich...
Archiv
Du betrachtest: Dauerhaftes Werbung öffnen macht Surfen fast unmöglich auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.