![]() |
|
Log-Analyse und Auswertung: Wörter blau und doppelt unterstrichen + Werbung + Java Update und der Browser ka..t total abWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Wörter blau und doppelt unterstrichen + Werbung + Java Update und der Browser ka..t total ab Also wie oben schon beschrieben habe ich das Problem und ich habe keine Ahnung wie ich den Mist weg bekomme und brauche eure Hilfe habe bissen was gelesen und mir schon Combofix laufen lassen aber was jetz? danke schon mal im vor raus und ich versuche alles so hin zubekommen wie ihr das mir sagt bin leider nicht so das Computergen Combofix Logfile: Code:
ATTFilter ComboFix 14-10-29.01 - Keule 02.11.2014 14:52:31.1.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.4087.1671 [GMT 1:00] ausgeführt von:: c:\users\Keule\Downloads\ComboFix.exe AV: Microsoft Security Essentials *Enabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1} SP: Microsoft Security Essentials *Enabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files (x86)\GaoSaVe c:\program files (x86)\GaoSaVe\02eIJHxfgf9jbC.dat c:\program files (x86)\GaoSaVe\02eIJHxfgf9jbC.dll c:\program files (x86)\GaoSaVe\02eIJHxfgf9jbC.tlb c:\program files (x86)\GaoSaVe\02eIJHxfgf9jbC.x64.dll c:\program files (x86)\GS_Booster c:\program files (x86)\GS_Booster\Assistant.dll c:\program files (x86)\GS_Booster\Assistant_x64.dll c:\program files (x86)\GS_Booster\AssistantSvc.dll c:\program files (x86)\YoutubEADBlocke c:\program files (x86)\YoutubEADBlocke\7xI8qvuBtkhlXn.dat c:\program files (x86)\YoutubEADBlocke\7xI8qvuBtkhlXn.dll c:\program files (x86)\YoutubEADBlocke\7xI8qvuBtkhlXn.tlb c:\program files (x86)\YoutubEADBlocke\7xI8qvuBtkhlXn.x64.dll c:\programdata\374311380 c:\programdata\374311380\BIT1773.tmp c:\programdata\ExsteraSavinogs c:\programdata\ExsteraSavinogs\attGlhRBdgFAtN.dat c:\programdata\ExsteraSavinogs\attGlhRBdgFAtN.dll c:\programdata\ExsteraSavinogs\attGlhRBdgFAtN.exe c:\programdata\ExsteraSavinogs\attGlhRBdgFAtN.tlb c:\programdata\ExsteraSavinogs\attGlhRBdgFAtN.x64.dll c:\programdata\GaoSaVe c:\programdata\GaoSaVe\Is80A34cf8betU7.dat c:\programdata\GaoSaVe\Is80A34cf8betU7.exe c:\programdata\GoSavee c:\programdata\GoSavee\zop6uX7dGN6fgP.dat c:\programdata\GoSavee\zop6uX7dGN6fgP.dll c:\programdata\GoSavee\zop6uX7dGN6fgP.exe c:\programdata\GoSavee\zop6uX7dGN6fgP.tlb c:\programdata\GoSavee\zop6uX7dGN6fgP.x64.dll c:\programdata\Trusted Publisher\GS_Booster c:\programdata\Trusted Publisher\GS_Booster\576482620.ini c:\programdata\Trusted Publisher\GS_Booster\576482620\BITD186.tmp c:\programdata\Trusted Publisher\GS_Booster\GS_Booster.exe c:\programdata\YoutubEADBlocke c:\programdata\YoutubEADBlocke\GomOV8hlyVOe5P2.dat c:\programdata\YoutubEADBlocke\GomOV8hlyVOe5P2.exe c:\users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\Administrator\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\Gast\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\Gast\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\Gast\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\Gast\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\Gast\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\Gast\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\Gast\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\Gast\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\Gast\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\Gast\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\Gast\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\Gast\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\Gast\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\Gast\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\Gast\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\HomeGroupUser$\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\Keule\AppData\Local\Adobe\AdbeRdr11007_de_DE.exe c:\users\Keule\AppData\Local\Adobe\gccheck.exe c:\users\Keule\AppData\Local\Adobe\gtbcheck.exe c:\users\Keule\AppData\Local\Adobe\SecurityScan_Release.exe c:\users\Keule\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\Keule\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\Keule\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\Keule\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\Keule\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\Keule\AppData\Local\Chromatic Browser\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\Keule\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\Keule\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\Keule\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\Keule\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\Keule\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\Keule\AppData\Local\Chromatic Browser\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\Keule\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\Keule\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\Keule\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\Keule\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\Keule\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\Keule\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\Keule\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\Keule\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\Keule\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\Keule\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\Keule\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\Keule\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\Keule\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\Keule\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\Keule\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\Keule\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\Keule\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\Keule\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\Keule\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\Keule\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\Keule\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\Keule\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\Keule\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\Keule\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\Keule\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\Keule\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\Keule\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\Keule\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\Keule\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\Keule\AppData\Local\Google\Chrome\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\Keule\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\Keule\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\Keule\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\Keule\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\Keule\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\Keule\AppData\Local\Google\Chrome\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\Keule\AppData\Local\nsd62C7.tmp c:\users\Keule\AppData\Local\nss2CC.tmp c:\users\Keule\AppData\Local\nsw72FC.tmp c:\users\Keule\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl c:\users\Keule\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\background.html c:\users\Keule\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\content.js c:\users\Keule\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\KJnLDxJBQ.js c:\users\Keule\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\lsdb.js c:\users\Keule\AppData\Local\Torch\User Data\Default\Extensions\bllnompkjpnjehbgijoelehahhdocijl\2.0\manifest.json c:\users\Keule\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg c:\users\Keule\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\background.html c:\users\Keule\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\content.js c:\users\Keule\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\D0pc.js c:\users\Keule\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\lsdb.js c:\users\Keule\AppData\Local\Torch\User Data\Default\Extensions\emakkfldeggiinnfcdjkakdfcppbfhdg\114\manifest.json c:\users\Keule\AppData\Roaming\Mozilla\Firefox\Profiles\3oaghyg8.default\extensions\LauhZhnPw@A.org c:\users\Keule\AppData\Roaming\Mozilla\Firefox\Profiles\3oaghyg8.default\extensions\LauhZhnPw@A.org\bootstrap.js c:\users\Keule\AppData\Roaming\Mozilla\Firefox\Profiles\3oaghyg8.default\extensions\LauhZhnPw@A.org\chrome.manifest c:\users\Keule\AppData\Roaming\Mozilla\Firefox\Profiles\3oaghyg8.default\extensions\LauhZhnPw@A.org\content\bg.js c:\users\Keule\AppData\Roaming\Mozilla\Firefox\Profiles\3oaghyg8.default\extensions\LauhZhnPw@A.org\install.rdf c:\windows\SysWow64\SETDEE.tmp c:\windows\SysWow64\SETFDD3.tmp . . ((((((((((((((((((((((( Dateien erstellt von 2014-10-02 bis 2014-11-02 )))))))))))))))))))))))))))))) . . 2014-11-02 03:10 . 2014-11-02 03:10 -------- d-----w- c:\programdata\Creative 2014-11-02 01:05 . 2014-10-14 19:59 11627712 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{02E4C712-2C9D-432B-ABA7-4A3621EFDF4D}\mpengine.dll 2014-11-01 17:54 . 2014-11-01 17:54 -------- d-----w- c:\program files (x86)\Common Files\Creative 2014-11-01 17:54 . 2014-11-01 17:54 -------- d--h--w- c:\program files (x86)\Creative Installation Information 2014-11-01 17:52 . 2014-11-01 17:54 -------- d-----w- c:\program files\Creative 2014-11-01 17:52 . 2014-11-01 17:54 -------- d-----w- c:\program files (x86)\Creative 2014-11-01 17:50 . 2003-11-10 17:13 69715 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll 2014-11-01 17:50 . 2003-11-10 17:12 266240 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll 2014-11-01 17:50 . 2003-11-10 17:12 192512 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll 2014-11-01 17:50 . 2003-11-10 17:11 5632 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe 2014-11-01 17:50 . 2003-11-10 17:14 729088 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll 2014-11-01 17:50 . 2014-11-01 17:50 188548 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll 2014-11-01 17:50 . 2014-11-01 17:50 311428 ----a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll 2014-11-01 16:40 . 2014-10-14 19:59 11627712 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2014-10-31 15:53 . 2014-10-31 15:53 111016 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2014-10-31 15:53 . 2014-10-31 15:53 -------- d-----w- c:\program files\Java 2014-10-31 09:52 . 2013-04-02 22:51 1643520 ----a-w- c:\windows\system32\DWrite.dll 2014-10-31 09:52 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll 2014-10-30 19:16 . 2014-10-31 13:38 -------- d-----w- c:\program files (x86)\Landwirtschafts Simulator 2015 2014-10-26 15:30 . 2014-10-16 12:27 614544 ----a-w- c:\windows\SysWow64\nvStreaming.exe 2014-10-23 11:15 . 2014-10-23 11:15 -------- d-----w- c:\programdata\Ads Remover 2014-10-23 01:03 . 2014-10-25 06:01 -------- d-----w- c:\program files (x86)\grassmow 2014-10-15 12:33 . 2014-07-07 02:06 284672 ----a-w- c:\windows\system32\EncDump.dll 2014-10-15 12:32 . 2014-09-19 01:47 48128 ----a-w- c:\program files\Internet Explorer\DiagnosticsHub_is.dll 2014-10-15 12:29 . 2014-09-18 02:00 3241472 ----a-w- c:\windows\system32\msi.dll 2014-10-15 12:28 . 2014-09-05 02:11 6584320 ----a-w- c:\windows\system32\mstscax.dll 2014-10-15 12:28 . 2014-09-05 01:52 5703168 ----a-w- c:\windows\SysWow64\mstscax.dll 2014-10-15 12:27 . 2014-09-13 01:58 77312 ----a-w- c:\windows\system32\packager.dll 2014-10-15 12:27 . 2014-09-13 01:40 67072 ----a-w- c:\windows\SysWow64\packager.dll 2014-10-14 17:58 . 2014-10-14 17:58 -------- d-----w- c:\program files (x86)\predm 2014-10-14 17:54 . 2014-10-14 17:54 -------- d-----w- c:\program files (x86)\Isaveir 2014-10-14 17:53 . 2014-10-14 17:53 -------- d-----w- c:\program files (x86)\Reimageplus.com 2014-10-14 17:52 . 2014-10-14 17:52 -------- d-----w- c:\program files (x86)\DigiISaverr 2014-10-14 13:02 . 2014-10-14 18:00 -------- d-----w- c:\program files (x86)\Optimizer Pro 2014-10-14 02:02 . 2014-10-14 02:02 1500072 ----a-w- c:\users\Keule\AppData\Roaming\BIXK.exe 2014-10-14 02:02 . 2014-10-14 02:02 1978792 ----a-w- c:\users\Keule\AppData\Roaming\VPOY.exe 2014-10-14 01:01 . 2014-10-14 17:54 -------- d-----w- c:\users\Keule\AppData\Roaming\InetStat 2014-10-13 13:59 . 2014-10-14 18:06 -------- d-----w- c:\users\Keule\AppData\Roaming\StormFall 2014-10-13 13:59 . 2014-10-13 13:59 -------- d-----w- c:\users\Keule\AppData\Local\StormFall 2014-10-13 13:59 . 2014-10-13 13:59 -------- d-----w- c:\users\Keule\AppData\Roaming\GoodGameEmpire 2014-10-13 13:59 . 2014-10-13 13:59 -------- d-----w- c:\users\Keule\AppData\Local\GGEmpire 2014-10-13 13:08 . 2014-10-13 13:08 -------- d-----w- c:\users\Keule\AppData\Roaming\ap_logs 2014-10-13 13:08 . 2014-10-13 13:08 -------- d-----w- c:\users\Keule\AppData\Roaming\AnyProtectEx 2014-10-13 13:08 . 2014-10-13 13:08 -------- d-----w- c:\users\Keule\AppData\Roaming\ap_movie 2014-10-13 13:05 . 2014-10-13 13:05 -------- d-----w- c:\users\Keule\AppData\Roaming\FirefoxToolbar 2014-10-13 13:00 . 2014-10-31 16:09 -------- d-----w- c:\users\Keule\AppData\Roaming\Systweak 2014-10-13 13:00 . 2014-08-29 15:02 20296 ----a-w- c:\windows\system32\roboot64.exe 2014-10-13 12:54 . 2014-10-13 12:54 -------- d-----w- c:\users\Keule\AppData\Local\com 2014-10-13 12:53 . 2014-10-13 12:53 1545616 ----a-w- c:\users\Keule\AppData\Roaming\NZKWOXW.exe 2014-10-13 12:52 . 2014-10-13 12:52 2038672 ----a-w- c:\users\Keule\AppData\Roaming\PBOY.exe 2014-10-13 12:52 . 2014-10-13 12:52 -------- d-----w- c:\users\Keule\AppData\Local\globalUpdate 2014-10-13 12:52 . 2014-10-31 16:01 -------- d--h--w- c:\users\Public\Temp 2014-10-13 12:51 . 2014-10-13 12:51 -------- d-----w- c:\programdata\WindowsMangerProtect 2014-10-13 12:51 . 2014-10-14 18:05 -------- d-----w- c:\program files (x86)\SupTab 2014-10-13 12:51 . 2014-10-13 12:52 -------- d-----w- c:\programdata\IePluginServices 2014-10-13 12:50 . 2014-10-14 17:54 -------- d-----w- c:\users\Keule\AppData\Local\Genesis_10131250 2014-10-13 12:49 . 2014-10-11 09:04 4834816 ----a-w- c:\windows\score.exe 2014-10-13 12:46 . 2014-10-31 15:53 -------- d-----w- c:\programdata\Oracle 2014-10-13 12:44 . 2014-10-13 12:44 -------- d-----w- c:\programdata\APN 2014-10-07 16:53 . 2014-10-07 16:53 -------- d-----w- c:\program files (x86)\WEB.DE MailCheck 2014-10-07 16:51 . 2014-10-07 16:51 -------- d-----w- c:\users\Keule\AppData\Roaming\OpenCandy 2014-10-07 16:40 . 2014-10-07 16:40 -------- d-sh--w- c:\users\Keule\AppData\Local\EmieUserList 2014-10-07 16:40 . 2014-10-07 16:40 -------- d-sh--w- c:\users\Keule\AppData\Local\EmieSiteList 2014-10-07 14:18 . 2014-09-10 14:30 1188440 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{45481A36-8256-44F1-B6EE-318B8DD213AA}\gapaengine.dll 2014-10-07 14:09 . 2014-06-27 02:08 2777088 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2014-10-07 14:09 . 2014-06-27 01:45 2285056 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2014-10-07 14:05 . 2014-10-07 14:40 -------- d-----w- c:\program files (x86)\Microsoft Security Client 2014-10-07 14:05 . 2014-10-30 16:45 -------- d-----w- c:\program files\Microsoft Security Client 2014-10-07 13:59 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDYAK.DLL 2014-10-07 13:59 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDTAT.DLL 2014-10-07 13:59 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDRU1.DLL 2014-10-07 13:59 . 2014-07-09 02:03 6656 ----a-w- c:\windows\system32\KBDRU.DLL 2014-10-07 13:59 . 2014-07-09 02:03 7168 ----a-w- c:\windows\system32\KBDBASH.DLL 2014-10-07 13:59 . 2014-07-09 01:31 7168 ----a-w- c:\windows\SysWow64\KBDYAK.DLL 2014-10-07 13:59 . 2014-07-09 01:31 6656 ----a-w- c:\windows\SysWow64\KBDBASH.DLL 2014-10-07 13:39 . 2013-11-23 18:26 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2014-10-07 13:39 . 2013-11-23 17:47 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2014-10-07 13:38 . 2014-06-24 03:29 2565120 ----a-w- c:\windows\system32\d3d10warp.dll 2014-10-07 13:38 . 2014-06-24 02:59 1987584 ----a-w- c:\windows\SysWow64\d3d10warp.dll 2014-10-07 13:38 . 2013-11-26 08:16 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll 2014-10-07 13:38 . 2013-11-22 22:48 3928064 ----a-w- c:\windows\system32\d2d1.dll 2014-10-07 13:34 . 2014-09-15 00:08 11578928 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3BAD4BE0-ACCE-4A1F-8107-385584CDC03D}\mpengine.dll 2014-10-07 13:34 . 2014-02-04 02:32 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2014-10-07 13:34 . 2014-02-04 02:04 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll 2014-10-07 06:55 . 2014-10-14 17:50 -------- d-----w- c:\programdata\50CCouupons 2014-10-06 23:29 . 2014-10-06 23:29 -------- d-----w- c:\windows\Migration 2014-10-06 23:13 . 2013-10-14 16:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE 2014-10-06 20:54 . 2014-10-06 20:54 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2014-10-06 20:17 . 2014-10-06 20:17 -------- d-----w- c:\program files (x86)\Common Files\Skype 2014-10-06 20:17 . 2014-10-06 20:17 -------- d-----r- c:\program files (x86)\Skype 2014-10-06 19:03 . 2014-10-15 15:40 -------- d-----w- c:\windows\system32\MRT 2014-10-06 18:45 . 2014-03-09 21:48 171160 ----a-w- c:\windows\system32\infocardapi.dll 2014-10-06 18:45 . 2014-03-09 21:47 99480 ----a-w- c:\windows\SysWow64\infocardapi.dll 2014-10-06 18:45 . 2014-06-30 22:24 8856 ----a-w- c:\windows\system32\icardres.dll 2014-10-06 18:45 . 2014-06-30 22:14 8856 ----a-w- c:\windows\SysWow64\icardres.dll 2014-10-06 18:45 . 2014-03-09 21:48 1389208 ----a-w- c:\windows\system32\icardagt.exe 2014-10-06 18:45 . 2014-03-09 21:47 619672 ----a-w- c:\windows\SysWow64\icardagt.exe 2014-10-06 18:45 . 2014-06-06 06:16 35480 ----a-w- c:\windows\SysWow64\TsWpfWrp.exe 2014-10-06 18:45 . 2014-06-06 06:12 35480 ----a-w- c:\windows\system32\TsWpfWrp.exe 2014-10-06 18:38 . 2013-10-04 02:28 190464 ----a-w- c:\windows\system32\SmartcardCredentialProvider.dll 2014-10-06 18:37 . 2014-07-07 02:06 728064 ----a-w- c:\windows\system32\kerberos.dll 2014-10-06 18:36 . 2014-03-04 09:44 362496 ----a-w- c:\windows\system32\wow64win.dll 2014-10-06 18:35 . 2013-07-26 02:24 197120 ----a-w- c:\windows\system32\shdocvw.dll 2014-10-06 18:34 . 2014-06-16 02:10 985536 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2014-10-06 18:16 . 2012-11-23 03:13 68608 ----a-w- c:\windows\system32\taskhost.exe 2014-10-06 18:16 . 2013-10-12 02:29 859648 ----a-w- c:\windows\system32\IKEEXT.DLL 2014-10-06 18:16 . 2013-07-20 10:33 102608 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll 2014-10-06 18:16 . 2013-07-20 10:33 124112 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2014-10-06 18:16 . 2013-10-12 02:30 830464 ----a-w- c:\windows\system32\nshwfp.dll 2014-10-06 18:16 . 2013-10-12 02:29 324096 ----a-w- c:\windows\system32\FWPUCLNT.DLL 2014-10-06 18:16 . 2013-10-12 02:03 656896 ----a-w- c:\windows\SysWow64\nshwfp.dll 2014-10-06 18:16 . 2013-10-12 02:01 216576 ----a-w- c:\windows\SysWow64\FWPUCLNT.DLL 2014-10-06 18:15 . 2013-08-28 01:12 461312 ----a-w- c:\windows\system32\scavengeui.dll 2014-10-06 17:44 . 2014-07-14 02:02 1216000 ----a-w- c:\windows\system32\rpcrt4.dll 2014-10-06 17:44 . 2014-07-14 01:40 664064 ----a-w- c:\windows\SysWow64\rpcrt4.dll 2014-10-06 17:02 . 2014-05-14 16:23 44512 ----a-w- c:\windows\system32\wups2.dll 2014-10-06 17:02 . 2014-05-14 16:23 58336 ----a-w- c:\windows\system32\wuauclt.exe 2014-10-06 17:02 . 2014-05-14 16:21 2620928 ----a-w- c:\windows\system32\wucltux.dll 2014-10-06 17:02 . 2014-05-14 16:23 2477536 ----a-w- c:\windows\system32\wuaueng.dll 2014-10-06 17:02 . 2014-05-14 16:23 38880 ----a-w- c:\windows\system32\wups.dll 2014-10-06 17:02 . 2014-05-14 16:23 700384 ----a-w- c:\windows\system32\wuapi.dll 2014-10-06 17:02 . 2014-05-14 16:20 97792 ----a-w- c:\windows\system32\wudriver.dll 2014-10-06 17:02 . 2014-05-14 16:17 92672 ----a-w- c:\windows\SysWow64\wudriver.dll 2014-10-06 17:02 . 2014-05-14 16:23 36320 ----a-w- c:\windows\SysWow64\wups.dll 2014-10-06 17:02 . 2014-05-14 16:23 581600 ----a-w- c:\windows\SysWow64\wuapi.dll . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-11-02 14:04 . 2010-12-01 20:48 25640 ----a-w- c:\windows\gdrv.sys 2014-10-30 11:25 . 2010-12-01 20:37 275080 ------w- c:\windows\system32\MpSigStub.exe 2014-10-29 21:30 . 2011-05-02 18:17 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2014-10-29 21:30 . 2011-05-02 18:17 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2014-10-24 12:52 . 2012-08-03 11:14 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-10-24 12:52 . 2011-05-20 06:00 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-10-16 16:54 . 2012-10-10 20:23 987008 ----a-w- c:\windows\system32\nvumdshimx.dll 2014-10-16 16:54 . 2012-10-10 20:22 16886168 ----a-w- c:\windows\SysWow64\nvd3dum.dll 2014-10-16 16:54 . 2010-08-05 10:15 3237528 ----a-w- c:\windows\system32\nvapi64.dll 2014-10-16 16:54 . 2010-08-05 10:15 2849224 ----a-w- c:\windows\SysWow64\nvapi.dll 2014-10-16 16:54 . 2010-08-05 10:15 20968040 ----a-w- c:\windows\system32\nvwgf2umx.dll 2014-10-16 14:11 . 2010-07-29 17:52 6883136 ----a-w- c:\windows\system32\nvcpl.dll 2014-10-16 14:11 . 2010-07-29 17:52 3533632 ----a-w- c:\windows\system32\nvsvc64.dll 2014-10-16 14:11 . 2010-07-29 17:52 384200 ----a-w- c:\windows\system32\nvmctray.dll 2014-10-16 14:11 . 2010-07-29 17:52 933064 ----a-w- c:\windows\system32\nvvsvc.exe 2014-10-16 14:11 . 2010-07-29 17:52 61640 ----a-w- c:\windows\system32\nvshext.dll 2014-10-16 14:11 . 2010-07-29 17:52 2559808 ----a-w- c:\windows\system32\nvsvcr.dll 2014-10-15 15:36 . 2010-12-13 22:20 103265616 ----a-w- c:\windows\system32\MRT.exe 2014-10-15 00:48 . 2012-11-02 09:39 4047877 ----a-w- c:\windows\system32\nvcoproc.bin 2014-09-26 20:23 . 2014-09-23 19:39 893552 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll 2014-09-26 20:22 . 2014-09-23 19:39 42168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll 2014-09-25 21:48 . 2011-05-20 06:07 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2014-09-23 20:40 . 2011-05-02 18:17 1236816 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2014-09-17 04:51 . 2014-09-20 15:14 31520 ----a-w- c:\windows\system32\nvhdap64.dll 2014-09-17 04:51 . 2014-09-20 15:14 197408 ----a-w- c:\windows\system32\drivers\nvhda64v.sys 2014-09-17 04:51 . 2014-06-30 13:39 1538880 ----a-w- c:\windows\system32\nvhdagenco6420103.dll 2014-09-13 23:48 . 2014-09-20 15:14 1876296 ----a-w- c:\windows\system32\nvdispco6434411.dll 2014-09-13 23:48 . 2014-09-20 15:14 1539272 ----a-w- c:\windows\system32\nvdispgenco6434411.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-17 221184] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-08-21 959176] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-10-07 507776] "Sound Blaster Tactic3D Control Panel"="c:\program files (x86)\Creative\Sound Blaster Tactic(3D)\Sound Blaster Tactic(3D) Control Panel\Tactic3D.exe" [2014-07-03 2091008] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-12-14 1207312] McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.150\SSScheduler.exe [2014-4-9 332016] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "ISUSScheduler"="c:\program files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start "SSBkgdUpdate"="c:\program files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot "PPort11reminder"="c:\program files (x86)\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "c:\programdata\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini" "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" "PaperPort PTD"="c:\program files (x86)\ScanSoft\PaperPort\pptd40nt.exe" "IndexSearch"="c:\program files (x86)\ScanSoft\PaperPort\IndexSearch.exe" "IAStorIcon"=c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe "BrMfcWnd"=c:\program files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN "ControlCenter3"=c:\program files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun . R1 ttnfd;ttnfd;c:\windows\system32\drivers\ttnfd.sys;c:\windows\SYSNATIVE\drivers\ttnfd.sys [x] R2 4d349a54;GS_Sustainer;c:\windows\system32\rundll32.exe;c:\windows\SYSNATIVE\rundll32.exe [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe;c:\windows\SYSNATIVE\AppleChargerSrv.exe [x] R3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files (x86)\MAGIX\Common\Database\bin\fbserver.exe;c:\program files (x86)\MAGIX\Common\Database\bin\fbserver.exe [x] R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys;c:\windows\SYSNATIVE\DRIVERS\ggflt.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtpt64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtpt64.sys [x] R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x] R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmdm64.sys;c:\windows\SYSNATIVE\DRIVERS\lgvmdm64.sys [x] R3 LU1103A;LU1103A Filter;c:\windows\system32\DRIVERS\LU1103A.sys;c:\windows\SYSNATIVE\DRIVERS\LU1103A.sys [x] R3 massfilter;Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys;c:\windows\SYSNATIVE\drivers\massfilter.sys [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.150\McCHSvc.exe;c:\program files\McAfee Security Scan\3.8.150\McCHSvc.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x] R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [x] R4 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [x] R4 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [x] S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AppleCharger.sys [x] S2 DES2 Service;DES2 Service for Energy Saving.;c:\program files (x86)\GIGABYTE\EnergySaver2\des2svr.exe;c:\program files (x86)\GIGABYTE\EnergySaver2\des2svr.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe;c:\windows\SysWOW64\XSrvSetup.exe [x] S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x] S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x] S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x] S2 scores;scores;c:\windows\score.exe;c:\windows\score.exe [x] S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys;c:\windows\SYSNATIVE\Drivers\SSPORT.sys [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x] S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x] S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 UHSfiltv;UHSfiltv;c:\windows\system32\drivers\UHSfiltv.sys;c:\windows\SYSNATIVE\drivers\UHSfiltv.sys [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . Inhalt des "geplante Tasks" Ordners . 2014-11-02 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-03 12:52] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576] "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-05-29 2352072] "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-05-29 1279480] "CDAServer"="c:\program files\Common Files\Common Desktop Agent\CDASrv.exe" [2012-03-09 462712] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-08-22 1331288] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:Tabs mDefault_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1413205223&from=cor&uid=WDCXWD5000AAKS-00UU3A0_WD-WCAYU769767297672&q={searchTerms} mDefault_Page_URL = about:blank mStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1413205223&from=cor&uid=WDCXWD5000AAKS-00UU3A0_WD-WCAYU769767297672&q={searchTerms} uSearchAssistant = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRaxo67ounJhqib0rXFhtLLIHmXcfrN_YrkL6AMkVAcJ3mJAY1Ayjpk-WfuaqVGtz6fJmRxfeCOZSdomfgPS2wNnpl4XeKqfnsJTm0zZrENyNgq6uhaz1aeluITl54regma3BYnkMSwmB4RUtMGSJVhFHPFcKAurHMgCnPKKY_--Evw,,&q={searchTerms} IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000 Trusted Zone: samsungsetup.com\www TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\Keule\AppData\Roaming\Mozilla\Firefox\Profiles\3oaghyg8.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms} . - - - - Entfernte verwaiste Registrierungseinträge - - - - . URLSearchHooks-{872b5b88-9db5-4310-bdd0-ac189557e5f5} - (no file) BHO-{06c21f1b-d05e-4d1f-bb5f-82f7d4769403} - c:\programdata\GoSavee\zop6uX7dGN6fgP.dll BHO-{08754b90-6d07-43f4-9b52-22ed6be00e58} - c:\program files (x86)\GaoSaVe\02eIJHxfgf9jbC.dll BHO-{30e9882a-f8ec-4bce-97ad-c575c594c0b2} - c:\program files (x86)\YoutubEADBlocke\7xI8qvuBtkhlXn.dll BHO-{f12d44d6-38fe-45aa-9262-ec4ab9f1fda0} - c:\programdata\ExsteraSavinogs\attGlhRBdgFAtN.dll Toolbar-10 - (no file) Wow6432Node-HKLM-Run-mbot_de_150 - (no file) Wow6432Node-HKLM-Run-ConvertAd - c:\users\Keule\AppData\Local\ConvertAd\ConvertAd.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start BHO-{06c21f1b-d05e-4d1f-bb5f-82f7d4769403} - c:\programdata\GoSavee\zop6uX7dGN6fgP.x64.dll BHO-{08754b90-6d07-43f4-9b52-22ed6be00e58} - c:\program files (x86)\GaoSaVe\02eIJHxfgf9jbC.x64.dll BHO-{30e9882a-f8ec-4bce-97ad-c575c594c0b2} - c:\program files (x86)\YoutubEADBlocke\7xI8qvuBtkhlXn.x64.dll BHO-{f12d44d6-38fe-45aa-9262-ec4ab9f1fda0} - c:\programdata\ExsteraSavinogs\attGlhRBdgFAtN.x64.dll Toolbar-10 - (no file) WebBrowser-{872B5B88-9DB5-4310-BDD0-AC189557E5F5} - (no file) AddRemove-ArmA 2 - c:\program files\Bohemia Interactive\ArmA 2\UnInstall.exe AddRemove-ARMA 2 Operation Arrowhead - c:\program files\Bohemia Interactive\ArmA 2\UnInstall_OA.exe AddRemove-Battlelog Web Plugins - c:\program files (x86)\Battlelog Web Plugins\uninstall.exe AddRemove-S-576482620 - c:\programdata\trusted publisher\gs_booster\gs_booster.exe AddRemove-SEMC OMSI Module - c:\program files (x86)\Sony Ericsson\Update Engine\uninst.exe AddRemove-Update Engine - c:\program files (x86)\Sony Ericsson\Update Engine\uninst.exe AddRemove-{4820778D-AB0D-6D18-C316-52A6A0E1D507} - c:\programdata\YoutubEADBlocke\GomOV8hlyVOe5P2.exe AddRemove-{5F189DF5-2D05-472B-9091-84D9848AE48B}{4d349a54} - c:\progra~2\GS_BOO~1\ASSIST~1.DLL AddRemove-{64A4ABCA-CF3D-C548-2DC4-72A55DC5882A} - c:\programdata\GoSavee\zop6uX7dGN6fgP.exe AddRemove-{C637A71C-A4B2-4B47-1B2A-1042A8D525A3} - c:\programdata\ExsteraSavinogs\attGlhRBdgFAtN.exe AddRemove-{C87834EB-A2A0-B9D4-AA9A-C263D1191051} - c:\programdata\GaoSaVe\Is80A34cf8betU7.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_167_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_167_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_167_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_167_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_167.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.15" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_167.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_167.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_167.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\windows\SysWOW64\PnkBstrA.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-11-02 16:55:54 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-11-02 15:55 . Vor Suchlauf: 8 Verzeichnis(se), 23.816.654.848 Bytes frei Nach Suchlauf: 12 Verzeichnis(se), 24.813.117.440 Bytes frei . - - End Of File - - 8721B54A74F18AE2BD81C45AE42E7257 Geändert von Keule2388 (02.11.2014 um 17:37 Uhr) Grund: ComboFix 14-10-29.01 - Keule 02.11.2014 14:52:31.1.4 - x64 |